Privacy
How the SIB Maker Lab handles personal data: honestly split between what runs today and what is prepared and only starts with the respective function.
This notice describes the processing operations in the SIB Maker Lab and feeds into HWR Berlin’s record of processing activities under Art. 30 GDPR. Data protection questions are answered by HWR; the contact details are below.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is the operator of the lab:
Startup Incubator Berlin — the startup centre of the Berlin School of Economics and Law (HWR Berlin).
SIB Maker Lab · at CIC Berlin · Lohmühlenstraße 65 · 12435 Berlin, Germany.
The full details of the operator HWR Berlin (address, representation) are in the Imprint. Lab contact: maker@startup-incubator.berlin.
Data protection officer
The official data protection officer of HWR Berlin is Klaus Hoogestraat (ITM Management & Consulting GmbH), e-mail datenschutz@hwr-berlin.de. He is also responsible for the processing carried out at the SIB Maker Lab.
Processing at a glance
The table below lists the processing of personal data in the workshop. The upper block is running today; the lower one is prepared and starts with the respective function. Where a period is not yet fixed we describe it honestly instead of inventing precision.
| Processing | Purpose | Legal basis | Retention |
|---|---|---|---|
| Running today | |||
| Access request and induction sign-up | Receiving and answering your enquiry and arranging first contact with the lab (e. g. appointment and induction). The form at /einweisung-anmelden/?lang=en collects only your name, e-mail address, affiliation and the areas you ask for, exactly what you type in. Your IP address, browser identification and location do not become part of the record. To prevent bulk submissions, a marker derived from your address exists for ten minutes; it carries no content and enters no record. If you sign up for an induction this way, the corresponding user account is created after approval by the lab (approval is not automatic); the record then passes into the account and the induction register. | Art. 6(1)(f) GDPR (legitimate interest in handling your enquiry); for enquiries concerning a contract or use, and for the induction sign-up, Art. 6(1)(b) (steps prior to the use relationship). | For as long as handling your request requires, at most 90 days after the decision. If an enquiry is left unanswered it is deleted after 365 days. Deletion is permanent and bypasses the trash, unless statutory retention periods apply. |
| Induction register | Evidence that a person has been inducted on particular machines or induction levels — a precondition for safe operation and for unlocking machine booking. Stored are name, user account, device or model, date and an optional note. | Art. 6(1)(f) GDPR (safety and operational diligence); possibly (c) where legal duties apply. | As long as the induction is valid or evidence must be kept; deleted afterwards. |
| Machine booking | Coordinating reservations of machines and time slots and preventing double bookings. Stored are user account, machine, period, intended work and booking status. | Art. 6(1)(b) GDPR (performing the booking) or (f). | For the duration of the booking and its handling; deleted afterwards unless evidence must be kept. |
| Workshop user account | Signing in to the internal area in order to book and to take part in the community. The account is limited to this subdomain and holds name and e-mail address. For the community a few attributes are added: joining date, language, time of last sign-in, the review state of a new account’s posts (number of approvals) and, where imposed, a time-limited mute that is communicated to you. | Art. 6(1)(b) GDPR (use relationship) or (f). | For the duration of use; deletable at any time on request. For the deletion of community accounts see below: posts stay readable, the link to the account is removed. |
| Community posts under real names | Exchange between members in the internal community areas: questions and answers, notes on machines and materials, knowledge pages. Every post appears under your real name (the display name of your account) and carries its time and account attribution; for each post the system keeps a history trail, and the first posts of a new account are reviewed before publication. Details in the section Community and reporting below the table. | Art. 6(1)(b) GDPR (community use relationship); for review, history trail and moderation (f) (safe operation in line with the rules). | As long as the post stands. After an account deletion the post stays readable and the attribution is removed: your name is replaced by “Former member”. |
| Attendance confirmations for workshop windows | Planning the open workshop windows: your attendance confirmation is stored as an account marker on the respective date. Other members only see the number of confirmations and free places, never the names. | Art. 6(1)(b) GDPR (community use relationship). | Until you withdraw the confirmation, at most for as long as the date is kept. When an account is deleted, your confirmations are removed. |
| Reporting content | Review of reported posts by the moderation team. A report is tied to an account, there are no anonymous reports: this way it can be answered and cannot be used anonymously against others. Stored are the reference to the reported content, the selected reason, your free text, your account including e-mail address, the processing state and the decision (deciding account, reasoning, time). Both sides receive the decision by e-mail; who reported is visible to the moderation team only. | Art. 6(1)(f) GDPR (legitimate interest in safe operation in line with the rules and in traceable moderation). | Open reports remain until the decision. Decided reports are deleted automatically after 180 days. |
| Material consumption and print jobs | Tracking which print jobs have run on the workshop machines: the basis for stock planning and reordering. For each job we store the machine, the material type, the time, a job identifier and the file name of the print job; the file name is not shown in the community areas. The material type is reported by the machine or derived from the file name, and stays “unknown” if neither yields a value. Quantity: Where a printer is connected on the lab network, the lab reads the material quantity from the print file once the job has finished, provided the file carries it. This is the estimate from print preparation (the slicer), not a measured consumption; if a job is cancelled, the value is scaled accordingly. On all other machines (Ultimaker, resin printer, laser cutter, soldering stations) a quantity only comes about if the team enters it by hand. If no value is available, the field stays empty; empty means “not recorded”, not “zero”. Person: The machine reports no name. A personal reference only arises if a booking of that machine on your account is running while the job runs; the job is then linked to that booking. Without a booking the job stays without a person; the team can only add a person by hand. No charging takes place at present. | Art. 6(1)(f) GDPR (legitimate interest in orderly operation, stock management and traceable machine use); where a job is linked through your booking, Art. 6(1)(b) GDPR (performance of the usage relationship). | The job record is kept for stock and operational evaluation. The personal part of it is above all the link to your booking: it is released once it is no longer needed for operation and evidence, and earlier at your request; the record then remains without a personal reference. A fixed period has not been set yet and will be stated here as soon as it is. |
| Transactional e-mails from the lab | Confirmations about induction, unlocking and supervised appointments, plus the decision e-mails from the reporting procedure (see above). No newsletter, no advertising. | Art. 6(1)(b) GDPR (performing the use relationship). | Sent as the occasion requires; no permanent mailing list. |
| Printer status via Prusa Connect | Retrieving the operating state of the Prusa printers (state, progress, file name, material type) every five minutes so that a busy machine is not booked twice. The request is made by the server, not by your browser — your device never contacts Prusa. A personal reference only arises through the link to a booking in the lab. | Art. 6(1)(f) GDPR (operational safety and avoiding double bookings). | The state is continuously overwritten; job data as above under material consumption. |
| Server logs of the host | Technical operation, stability and security of the website (serving pages, preventing abuse). | Art. 6(1)(f) GDPR (legitimate interest in secure, undisturbed operation). | Short term; log data is deleted or anonymised after a short period. |
| Prepared — starts with the respective function | |||
| Community event e-mails | Occasion-based notices by e-mail: to the functional address maker@startup-incubator.berlin when a post enters review (so no review is left waiting); to you when your post has been approved; to you when your question receives its first answer (with an unsubscribe note). No newsletter, no advertising. | Art. 6(1)(b) GDPR for the e-mails to you (performing the use relationship); Art. 6(1)(f) for the review notice to the functional address (ensuring moderation). | Sent as the occasion requires; no mailing list. |
| Project showcase (image & name) | Presenting projects made in the lab (on the website or on a board). | Art. 6(1)(a) GDPR (your consent) — voluntary and revocable at any time. | Until you withdraw your consent; the publication is then removed. |
Community and reporting
The internal community areas are accessible to signed-in members only. What is stored there is described here in detail; the rules of conduct are in the community rules.
Real name and history trail. In the community you write under your real name, there are no pseudonyms; this rule is stated in the community rules before you write your first post. Every post (question, answer, machine note, knowledge page) carries its time and account attribution. In addition the system keeps a history trail per post: for each event it records the time, the acting account, the kind of change and, where given, a short note. The trail is only appended to, never overwritten, and is limited in length per post; it makes changes and moderation decisions traceable. For knowledge pages the system also records who created a page and who last changed it, together with the individual versions.
Review of new accounts. The first posts of a new account are reviewed by the moderation team before publication. This review ends after three approvals or with the induction; team and moderation accounts do not pass through it. For this purpose the number of approvals is kept on the account.
Reports. Every member can report posts for review. A report stores the reference to the reported content, the selected reason, your free text, your account including e-mail address and, later, the decision with the deciding account, the reasoning and the time. The identity of the reporting person is visible to the moderation team only; it is not disclosed to the person whose post was reported. Both sides receive the decision by e-mail. To prevent abuse, the number of reports per account and hour is limited; repeatedly rejected reports temporarily restrict the immediate effect of further reports from the same account. Decided reports are deleted automatically after 180 days.
My data: access and portability. Under “My data” in the community hub you can download, at any time and as a machine-readable file, what is stored about your account: account data (display name, e-mail address, joining date, language, time of last sign-in, review state), your posts and answers, machine notes, knowledge pages including versions, attendance confirmations and the reports you filed (Art. 15 and 20 GDPR). If a part cannot be read at that moment, the file says so explicitly instead of pretending to be complete.
Deletion here means pseudonymisation. You file the deletion request in the same place; it is carried out by the team. Your posts then stay readable and the link to your account is removed: your name is replaced by “Former member”. The community attributes of the account are deleted, your reports are decoupled from account and e-mail address, attendance confirmations are removed and joining records are anonymised. This rule is announced in the community rules before the first post; the legal basis for keeping the pseudonymised posts is Art. 6(1)(f) GDPR (legitimate interest in preserving coherent conversations that other members rely on).
No external services, no tracking cookies
These pages load no third-party content: fonts and graphics are stored locally, no external maps, analytics or advertising services are embedded, and no tracking cookies are set. The route to CIC Berlin is offered only as a clickable link to OpenStreetMap — a map loads only when you open it yourself. That applies to your browser: server-side the lab retrieves the printer state from Prusa Connect (see table); your device is not involved.
Recipients & processors
To operate the website we use a hosting provider, engaged as a processor under a data processing agreement pursuant to Art. 28 GDPR. Your data is not shared for advertising purposes and not sold. No transfer to third countries is intended. The hosting provider is ALL-INKL.COM — Neue Medien Münnich, Friedrichstraße 24, 02826 Görlitz, Germany. The operating state of the Prusa printers is retrieved server-side from Prusa Research a.s. (Czech Republic); no user data is transmitted to Prusa in the process.
Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on a legitimate interest (Art. 21). Where processing is based on your consent, you can withdraw it at any time with effect for the future (Art. 7(3)).
For access and portability there is a self-service path in the community: under “My data” you download what is stored about your account, and you file the deletion request there as well (see above, Community and reporting).
To exercise a right, a message to maker@startup-incubator.berlin or to the controller is also enough. To protect your data, confirmation of your identity may be required.
Right to complain
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI), datenschutz-berlin.de.
Changes to this notice
This notice is updated whenever new functions go into operation. As of August 2026.
