Document still in progress – not a final version, text may contain placeholders.

Internat Solling Deutsch · English
← back to the portal

Policy on the Use of Information Technology, Digital Services and Media

Internat Solling – binding upon pupils, teaching staff, employees, visitors and service providers

Short title: IT and Media Policy, Internat Solling

Issued by: Internat Solling, Einbecker Straße 1, 37603 Holzminden, represented by the head of school

Version: 1.0  |  Dated: 1 August 2026  |  In force from: school year 2026/2027

Adopted by: the head of school and the business director on 1 August 2026

Consulted: the data protection officer, dl-DATEN GmbH, Mr Herbert Werner, on 1 August 2026

Supersedes: the Conditions of Use for the IT Infrastructure Provided and for Pupils' Devices at Internat Solling, together with the Media Use Agreement (Annex 6B, dated August 2023)

Consequential amendment: Heimordnung (boarding house regulations, Annex 6A), item 05 – the reference there to the Media Use Agreement is to be replaced by a reference to this policy

Responsible for the content: IT department, support@internatsolling.de, telephone 05531 1287-800

This is a translation provided for convenience. In the event of any discrepancy between this English version and the German original, the German version shall prevail.

Part A – General provisions for all users

Part A applies to every person who uses the IT systems, networks, devices or digital services of Internat Solling. Parts B to D supplement it for particular groups. In the event of conflict, the more specific provision of the relevant Part shall prevail.

A.1 Scope, purpose and binding effect

  1. Material scope. This policy applies to all IT systems and services provided or administered by Internat Solling. These include wired and wireless networks, user accounts, email and collaboration services, the school administration system, learning platforms, printing and copying systems, fixed workstations, mobile devices, servers, storage services and all internal and external offerings accessible through them.
  2. Personal scope. This policy covers pupils, teaching staff, teaching and non-teaching employees, apprentices, interns, freelance and voluntary staff, visitors and the employees of external service providers.
  3. Territorial scope. The policy applies throughout the grounds of Internat Solling, including the Kams (boarding houses) and residential areas, and at school events held off site. Where school services are used from elsewhere (remote access, mobile use, working from home), the policy applies irrespective of the user's location.
  4. Age groups. Where this policy distinguishes between age groups, the designations customary at Internat Solling apply: Schützen (Years 5–7), Scholaren (Years 8–10) and Magister (Years 11–13).
  5. Purpose. The policy secures the orderly, safe and lawful operation of information technology, protects the rights of all those concerned – in particular the protection of minors and of personal data – and establishes clarity as to rights and obligations.
  6. Binding effect. The policy is accepted by signing the applicable Part. No user account will be activated without a signed acknowledgement. For visitors who use only the guest network, the notice under Annex E.4 takes the place of a signature.
  7. Relationship to other regulations. The Heimordnung (Annex 6A), the school and boarding contract, contracts of employment, staff instructions, the data protection framework, the communications framework and the digital use framework of Internat Solling apply in addition, each as amended from time to time. Times of leave and bedtimes, and the periods of quiet during the Arbeitsstunde (supervised study period) and after 22:00, and after 21:00 for Schützen, are governed by the Heimordnung; the technical restriction periods linked to them are set out in Annex E.6.
  8. Amendments. Amendments will be announced in an appropriate manner. Where they affect the rights and obligations of users, they take effect no earlier than one month after their announcement. Amendments going beyond editorial adjustments and the updating of Annexes E.6 and E.7 become effective only if they are reasonable, having regard to the interests of those affected; in such cases acknowledgement will be obtained afresh.

A.2 User accounts and access credentials

  1. Personal account. Every authorised person receives a personal user account for the duration of their association with the school. It is not transferable.
  2. Responsibility. The account holder is responsible for all actions carried out under their account. Anyone who discloses their access credentials is responsible for the consequences; liability is governed by section A.14.
  3. Confidentiality. Access credentials are to be kept secret. They must not be disclosed to anyone. The IT department and the head of school never ask for passwords; any such request is an indication of an attempted fraud and must be reported.
  4. Other people's accounts. Logging in with another person's credentials is prohibited, even with that person's consent. This applies equally to the accounts of fellow pupils, teaching staff and employees.
  5. Identity management. Accounts are administered centrally through the school's directory (Azure Active Directory) and permit single sign-on to the connected services. Educational and organisational roles and permissions are maintained in All4Schools.
  6. Password requirements. Passwords must be at least twelve characters long. Routine periodic changes are not required; a password must be changed as soon as there is any suspicion that it has become known to a third party. Passwords must not be reused for private services. Passwords are reset through the IT department.
  7. Multi-factor authentication. For the head of school, the administration and the IT department, login with a second factor is mandatory; the Microsoft Authenticator app and confirmation by SMS are approved for this purpose. For the remaining groups it will be introduced in stages as directed by the IT department. The second factor must be protected as carefully as a password; confirmation requests that the user has not initiated must be declined and reported.
  8. Loss and compromise. Any suspicion that access credentials have become known to a third party must be reported to the IT department without delay and, in the case of pupils, also to the Kamleitung (boarding house leader). The password must be changed immediately.
  9. Suspension, deactivation and deletion. On leaving the school, the account is deactivated. Deactivation takes effect on the last day of school or of employment; the contents of the account are finally deleted 30 days thereafter. Access within that period is not guaranteed. Securing one's own data is the responsibility of the person leaving and must be done before departure. Statutory and contractual retention obligations remain unaffected, in particular the archiving of official email correspondence.
  10. Teams, channels and groups. Class, course and residential group teams are set up centrally by the IT department. Pupils do not create teams. Archiving and deletion follow the lifecycle set out in Annex E.7.
  11. Shared accounts. Functional and shared accounts are created only where there is a proper reason for doing so, and are assigned to a responsible individual.

A.3 Network access, filtering and logging

  1. Provision. Internat Solling provides network access so far as technical and organisational means allow. There is no entitlement to continuous availability, to any particular bandwidth or to the accessibility of any individual service.
  2. One point of access, separate network zones. Internat Solling operates a single wireless network for all user groups. Users log in with their personal credentials. On the basis of the account, the device is automatically assigned to the network zone provided for the relevant group; administration, teaching, pupil and visitor zones are separated in this way. Moving to another network zone is not possible and must not be attempted. The login also determines which filtering, time and bandwidth rules under Annex E.6 apply.
  3. Device registration as a condition of access. Beyond personal login, access requires that the device be registered in the device management system. Unregistered devices are not granted access. For visitors, section D.1 applies.
  4. Content filtering. Access is subject to central content filtering through the school's firewall. This serves the protection of minors, compliance with legal requirements and operational security. For minors, filtering profiles of differing strictness apply according to age, as set out in Annex E.6. The school reserves the right to restrict access to individual sites and services at any time. Complete protection against unwanted content cannot be achieved by technical means; filtering replaces neither supervision nor personal responsibility.
  5. Location- and time-dependent profiles. On managed devices, different profiles are activated according to location and time of day (lesson, boarding, free time, examination). Detection takes place through the network environment and through beacons in the teaching rooms. The profiles that exist and their effects are set out in Annex E.6. Profile changes are logged; no movement profile is derived from them, nor is any provided for technically.
  6. Prohibition of circumvention. Measures intended to circumvent filtering, the firewall, logging, profile control or access restrictions are prohibited. These include in particular proxy services, VPN connections used for this purpose, alternative DNS configurations, tunnelling methods, anonymisation networks, the setting up of one's own access points, the sharing of a mobile data connection with other devices, and secondary devices carried in order to circumvent this policy. Attempts at circumvention are detected by the firewall and logged automatically. VPN connections required for professional purposes under Part C remain permitted.
  7. Bandwidth and time allowances. Age-dependent time windows and time allowances apply to streaming, social networks and games, as set out in Annex E.6. Services required for lessons are given priority. Where data volumes are conspicuously high, the IT department will investigate the cause and may limit the bandwidth of the connection concerned.
  8. Private networks and devices. The setting up of private wireless networks, hotspots, routers, switches, repeaters or cable connections is prohibited. Network cables and connectors of existing installations must not be disconnected, and equipment must not be switched off, switched on or restarted without authorisation. Connections via peer-to-peer and file-sharing services are prohibited.
  9. Logging. Use of the networks and systems is logged. The sole purposes are to ensure operation, to detect and remedy faults, to maintain IT security and to investigate breaches of this policy or of the law.
  10. Retention periods. The following periods apply:
    Type of dataRetention period
    Connection and proxy logs linking a person to the destination accessed7 days
    Security logs (firewall, login, malware, detected circumvention attempts), stored separately and strictly limited to their purpose30 days
    Device management logs, in particular profile changes and configuration changes30 days
    Time and volume counters with no reference to contentcurrent month and following month
    Access logs of external service providers to systems containing personal data2 years
    Logs relating to a specific documented incidentuntil the matter is concluded, and for no more than 6 months
    Change logs in the specialist applications (All4Schools, SharePoint)on expiry of the retention period for the record concerned
    Application and error logs of the ISL Portal30 days
    Access log of the ISL Portal recording account, action, time and IP address90 days
    Wi-Fi session history30 days
    Aggregated Wi-Fi category statistics with no personal reference90 days
    Backups of the portal30 days
    Central recycle bin pending final deletion30 days
    On expiry, the data are deleted automatically. Log data may be contained in backups beyond these periods; they are overwritten at the end of the relevant backup cycle. Data are not deleted separately from within existing backups.
  11. Analysis. Analysis is carried out in the first instance without reference to individuals. Analysis by reference to an individual is permitted only where there is a specific, documented suspicion of a serious breach, on the instruction of the head of school, with the involvement of the data protection officer and on the four-eyes principle. The matter is documented in writing. Where employees are concerned, the works council is involved in accordance with its rights of participation.
  12. No performance monitoring. Log data are not analysed for the purpose of monitoring the conduct or performance of employees, nor for the general assessment of pupils.
  13. Device registration. Devices are registered in the device management system and assigned to the person using them. Exchanging, lending or taking devices in order to use another person's allowance is prohibited. The permitted number of devices is set out in Annex E.6.

A.4 Approved channels of communication

  1. Approved channels. The following channels alone are approved for school, boarding and official communication: Which channel is to be used for which purpose is set out in the allocation table of the communications framework. The same matter is not communicated through several channels in parallel.
  2. Channels that are not approved. The following must not be used for school, boarding or official communication: WhatsApp, Facebook Messenger, Instagram, Snapchat, TikTok, Telegram, Discord and comparable services, nor private email accounts or private mobile telephone numbers.
  3. Reasons. No data processing agreements exist with the providers of these services; Internat Solling would be unable to discharge its obligations as controller there. Some of these services synchronise the device's address book with the provider without the consent of the contacts concerned; with WhatsApp this occurs as soon as the application is set up. Some providers process data outside the European Union. Above all, however, their use is not necessary for the performance of the school's tasks, because equivalent approved channels are available; there is therefore no sound legal basis under Article 6 GDPR. The State Commissioner for Data Protection of Lower Saxony considers the use of WhatsApp for official communication between teaching staff and pupils to be unlawful (guidance note of 3 September 2018).
  4. Extent. The prohibition applies to official and school communication. Private communication between pupils in their free time is not covered; no one is, however, obliged to be reachable through a service that is not approved, and no one may be pressed to join such a group.
  5. No official groups. Class, course, Kam and working groups are not run through services that are not approved. Existing groups of this kind are to be dissolved by the end of the first school term after this policy comes into force. This is conditional upon the relevant replacement channel having been set up beforehand and explained to those concerned. Information of binding effect for school or boarding purposes is distributed exclusively through approved channels. Anyone who uses a channel that is not approved cannot rely on not having received information.
  6. Communication hours. Binding communication takes place from Monday to Friday between 07:00 and 20:00. Outside these hours, and at weekends, on public holidays and during the holidays, no enquiries are addressed to teaching staff, employees or pupils, unless the matter is urgent or organisationally necessary. There is no obligation to be reachable outside agreed working hours. Information of significance for the following school day is made available by the start of the Arbeitsstunde at 17:15.
  7. Checking messages. Teaching staff and pupils check the approved channels at least once on every school day, by the end of the Arbeitsstunde.
  8. Emergencies. Where there is danger to life or limb, the emergency number 112 is to be called first. The head of boarding or the head of school is then informed through the Kam's on-call arrangements, and the business director in the case of operational emergencies. For technical emergencies outside service hours, the IT department can be reached by mobile telephone. The current numbers are set out in the digital contact and responsibilities list. An emergency justifies the use of any available channel; the matter is subsequently to be documented through an approved channel.
  9. Failure of approved channels. If a channel fails, the substitute routes of the communications framework apply: if Teams fails, the telephone system or official email; if the school administration system fails, official email; if the telephone system fails, Teams or official email. The failure of a channel does not justify resorting to a service that is not approved.
  10. Parents. Parents and legal guardians contact the school through the approved channels. If they approach a member of staff by any other route, the communication is transferred to an approved channel.

A.5 Conduct in digital spaces: netiquette, exclusion, cyberbullying

  1. Principle. Conduct in digital spaces is judged by the same standards as conduct face to face. Respect, restraint and consideration apply irrespective of whether a remark is made in a chat, a video meeting, an email or on a social network.
  2. Netiquette. The following is expected: messages with a proper form of address and in intelligible language; no insults, disparagement, threats or humiliation; no forwarding of another person's messages without their consent; no chain messages and no unnecessary mass distribution; restraint in the use of irony, which is frequently misunderstood in writing; no communication in a state of high emotion.
  3. Prohibited conduct. The following are prohibited in particular: the deliberate and repeated disparagement or exclusion of individuals; the creation of groups, profiles, lists or content that hold a person up to ridicule; the spreading of rumours, humiliating content or recordings made covertly; inviting others to take part in such conduct; the creation of false profiles in another person's name; and the creation, storage and distribution of depictions of real persons generated or altered by technical means, in particular sexualised depictions.
  4. Reporting. Anyone affected by or witnessing cyberbullying may approach any of the following; the order is a recommendation, not a requirement:
    1. the Kamleitung, as the nearest point of contact in the residential area,
    2. the pastoral teacher or the school social work team,
    3. the designated safeguarding contact under the safeguarding policy, in particular where adults are involved,
    4. the head of school or the head of boarding.
    Anyone who does not wish to report a matter in person may use the anonymous reporting channel of the ISL Portal. It records neither login data nor IP address and permits no inference as to the person reporting; no follow-up enquiry is, however, then possible. Serious or repeated incidents are referred to the internet safety team. Reports are treated in confidence. No one suffers any disadvantage for making a report. No duty to report is imposed on witnesses; all members of the community are, however, expected to raise or report incidents. For employees, the duty to report follows from their duties of care and supervision.
  5. Preserving evidence. Those affected should preserve content by taking screenshots before it is deleted and pass it to the responsible body. Further distribution for any other purpose is prohibited. This does not apply to content containing sexualised depictions of minors: such material must not be saved, copied or forwarded, because even storing it may be a criminal offence. Such content is only to be reported; the responsible body will undertake any further preservation.
  6. The school's procedure. Reports are dealt with under the established procedure: protection of the person affected, establishing the facts, discussion with those involved, involvement of the parents and legal guardians, measures under section A.15 and, where appropriate, a criminal complaint. Where there are indications of a risk to a child's welfare, the school's safeguarding policy under § 45 (2) sentence 2 no. 4 SGB VIII (German Social Code Book VIII, operating licence for residential care institutions) applies; the procedure is governed by § 8a SGB VIII (German Social Code Book VIII, protection mandate where a child's welfare is at risk). The names of the designated safeguarding contact and of the designated safeguarding specialist are published on the notice board and in the contact and responsibilities list.
  7. Note on the criminal law. Cyberbullying may constitute a criminal offence, including insult (§ 185 StGB, German Criminal Code), defamation (§ 186 StGB), malicious defamation (§ 187 StGB), stalking (§ 238 StGB), threatening behaviour (§ 241 StGB), violation of the most personal sphere of life through images (§ 201a StGB), violation of intimate privacy through images (§ 184k StGB) and violation of the confidentiality of the spoken word (§ 201 StGB). The creation, storage or distribution of sexualised depictions of minors, including computer-generated depictions, is a serious offence under § 184b StGB (German Criminal Code, distribution of child sexual abuse material) carrying a minimum sentence of one year's imprisonment; this applies even where those involved are themselves minors.

A.6 Photographic, audio and video recordings

  1. Principle. Recordings of persons may be made only with their consent. Separate consent is always required for publication or disclosure; permission to make a recording does not include permission to distribute it.
  2. Absolute prohibitions on recording. Photographic, audio and video recordings are prohibited without exception in the following areas, including recordings of oneself where other persons may be captured: In the dining hall and in common and communal rooms, recordings are permitted where every identifiable person consents. For publication or disclosure, item 1 applies without qualification.
  3. Lessons and events. Recordings in lessons are permitted only with the consent of the teacher and of all persons captured. The recording of video meetings is prohibited unless it has been expressly announced and permitted by all participants. At events, notice is given in advance of any recording by the school.
  4. Covert recordings and criminal liability. The making of covert recordings is prohibited under this policy and may in addition be a criminal offence: Teaching staff and employees are not public figures; recordings of them without their consent are not permitted.
  5. Consent of minors. The following applies to recordings and publications by the school: up to the age of 14, only the parents and legal guardians give consent; from the age of 14, the parents and legal guardians and the pupil consent jointly; from the age of majority, the person concerned consents alone. Consent is voluntary, may be withdrawn at any time with effect for the future, and specifies the purpose and the publication medium in each case individually. No disadvantage arises from a refusal. Annex E.2 is to be used.
  6. Withdrawal. Following a withdrawal of consent, the content concerned is removed within 14 days from the digital media operated by the school and marked as blocked in the central archive. Printed publications already issued are not recalled, but are not distributed again. The school has no influence over content already copied or further distributed by third parties; attention is drawn to this in the consent form. Posters and presentations carry a note about the right of withdrawal.
  7. No video surveillance. There is no video surveillance on the grounds of Internat Solling.

A.7 Social networks and public communication

  1. Private use. The private use of social networks is a matter for each individual. It reaches its limit where the rights of other members of the school community or the legitimate interests of Internat Solling are affected.
  2. Content concerning others. Posts, photographs, videos or audio recordings in which other members of the school community are identifiable may be published only with their consent. This applies equally to group photographs and to content made available only to a limited circle.
  3. Internal matters. Internal proceedings, the contents of meetings, personnel matters, disciplinary proceedings, health data and the personal circumstances of others are not discussed on social networks.
  4. Name and logo. The name, logo and figurative marks of Internat Solling may be used only with the prior consent of the head of school. Private accounts must not give the impression of being official channels of the school.
  5. Official channels. Internat Solling maintains accounts on Facebook, Instagram, YouTube and LinkedIn, and the websites www.internatsolling.de and www.sollingstipendium.de. They are managed exclusively by the public relations office; publications are approved by the head of school. No one else posts content to these channels.
  6. Press and public authorities. Enquiries from the press, public authorities and supervisory bodies are not to be answered personally. External statements are a matter for the head of school; enquiries are to be forwarded there without delay.
  7. Contact between employees and pupils. See section C.3.

A.8 Use of artificial intelligence

  1. Principle. Artificial intelligence systems are tools. Their use is permitted so far as it is covered by this policy, by the requirements of the academic departments and by the providers' terms of use. Responsibility for the result always remains with the person using the system.
  2. No personal data. No personal data may be entered into AI systems that have not been expressly approved. This applies in particular to names, contact details, marks, assessments, health information, information about family circumstances and passages of text from which a person can be identified.
  3. Approved systems. The Fobizz platform is approved, for teaching staff in preparing lessons and for pupils in accordance with section B.6. In neither case may personal data be entered. Further approvals are set out in Annex E.7. The list is maintained by the IT department and any changes are announced.
  4. Systems that are not approved. For all other systems the following applies: use only without any personal reference and without internal documents. The consumer versions of general language models are not approved for the processing of pupil, parent or employee data, since no data processing agreement exists for them. Services for circumventing the filtering are blocked by technical means, namely VPN, proxy and anonymisation services, as are file-sharing sites and file-sharing connections. The complete block list is maintained by the IT department.
  5. Duty to check. AI output may be factually wrong, out of date, distorted or invented. It must be checked before every use. Statements based on AI must not be adopted without checking in assessments, letters to parents, report comments, expert opinions or decisions.
  6. No automated decisions. Decisions on admission, promotion to the next year, assessment of performance, examination results and disciplinary measures are not taken by AI systems automatically, nor are they substantially prepared by such systems.
  7. Declaration in pupils' work. For homework, presentations, subject papers and project work by pupils, section B.6 applies in addition.
  8. Training. Internat Solling promotes the acquisition of sufficient knowledge of the use of AI systems among all persons who deploy such systems on its behalf. Attendance at the relevant training is mandatory for employees; attendance is documented. The basis for this is Article 4 of Regulation (EU) 2024/1689, as amended.
  9. Inventory. The IT department maintains a register of the AI systems in use and examines whether any of them falls within a regulated category of Regulation (EU) 2024/1689, in particular systems for admission, enrolment and assignment, for the evaluation of learning outcomes, for steering learning pathways on the basis of assessments, for evaluating the appropriate level of education of a person, and for monitoring and detecting prohibited behaviour during examinations. No such systems are currently in use. Before any such system is introduced, this classification will be carried out.

A.9 Handling of personal data

  1. Principle. The personal data of others are processed only so far as necessary for the task in hand. They are not disclosed to unauthorised persons, not transferred to private systems and not used for any other purpose.
  2. Controller. The controller within the meaning of the GDPR is Internat Solling, Einbecker Straße 1, 37603 Holzminden, represented by the head of school. Contact in data protection matters: support@internatsolling.de.
  3. Data protection officer. An external data protection officer has been appointed for Internat Solling: dl-DATEN GmbH, Mr Herbert Werner, Hoher Holzweg 17, 30966 Hemmingen, telephone +49 511 536770-80, datenschutz@dl-daten.de. Data subjects may approach him directly; the internal point of contact is support@internatsolling.de.
  4. Supervisory authority. The State Commissioner for Data Protection of Lower Saxony.
  5. Legal bases. Depending on the purpose, processing is based on the performance of the school and boarding contract, on legal obligations, on legitimate interests in the secure operation of IT, or on consent. For employee data, the provisions of the Bundesdatenschutzgesetz (German Federal Data Protection Act) apply. Details are set out in the school's data protection framework and privacy notices.
  6. Rights of data subjects. Access, rectification, erasure, restriction, data portability and objection are exercised through support@internatsolling.de. Requests are answered within one month. Complaints may be addressed to the State Commissioner for Data Protection of Lower Saxony.
  7. Storage locations. Official and school data are stored exclusively in the systems designated for the purpose, in particular in All4Schools, in the ISL Portal and in the Microsoft services provided. Storage on private storage services, in particular iCloud, Google Drive, Dropbox and private Microsoft accounts, and on private computers or unencrypted removable media, is prohibited, save as otherwise provided in Part C.
  8. Archiving of official email. Official email correspondence is archived in an audit-proof manner and deleted automatically on expiry of the retention period. Access to the archive is available only to the administration, the head of school and the data protection officer; every inspection is logged with the person, the time and the purpose. Archiving covers the mailboxes of the domain internatsolling.de. Mailboxes of the domains internatsolling.org, internatsolling.com and internatsolling.schule are not archived; the general retention obligations apply to them.
  9. Cloud storage. The cloud applications provided by the school store data within the European Union. Access from third countries is not thereby excluded in every case, because individual providers have corporate ties outside the Union; where services in addition process data outside the Union, this is indicated in Annex E.7. For the services provided by the school, the necessary data processing agreements are concluded and the transfer routes documented. Which service is approved for which types of data, and where processing takes place, is set out in Annex E.7. Where users set up further services on their own initiative, responsibility rests with them.
  10. Encryption and residual risk. When transmitting personal data, the encryption options available in the software used must be employed. Special categories of personal data and documents from counselling, health and disciplinary proceedings are transmitted only in encrypted form. Attention is drawn to the fact that, depending on the service used, data may be transmitted over the network unencrypted and may in the process be read by third parties. Complete protection of transmission routes cannot be guaranteed.
  11. Data backup. The school backs up the centrally operated systems in accordance with its backup framework. Each person is responsible for their own data on private devices, on removable media and in services set up on their own initiative. On the computers in the library and the computer rooms, local data are deleted on restart; work must therefore be saved in OneDrive or on the user's own storage medium.

A.10 Copyright, licences and third-party content

  1. Works protected by copyright must not be downloaded, reproduced, distributed or made publicly available without permission. This applies equally to music, films, series, images, texts, software, typefaces and teaching materials.
  2. File-sharing sites and file-sharing services must not be used.
  3. The software provided by the school is licensed and must neither be copied nor used beyond its intended purpose. Licences end when a person leaves the school.
  4. The statutory copyright exceptions apply to the use of third-party content in lessons. In case of doubt, material whose use is expressly permitted should be used.
  5. The IT department may prevent the execution of unapproved or potentially harmful programs by technical means.

A.11 Prohibited conduct

The following are prohibited in particular:

  1. spying out, intercepting or reading another person's data, and obtaining another person's access credentials, including by deception; such conduct is a criminal offence under §§ 202a to 202d StGB (German Criminal Code, data espionage, interception of data and handling of stolen data);
  2. interference with the school's networks, servers, devices, configurations and security mechanisms, and with the devices of others;
  3. the distribution of malware and the establishment or operation of infrastructure for improper purposes, in particular botnets, services for denial-of-service attacks, phishing sites and malware distribution points;
  4. the sending of unsolicited bulk messages;
  5. the downloading, creation, storage, sending or distribution of content that is pornographic, glorifies violence, incites hatred, or is racist, sexist, extremist, threatening or otherwise unlawful;
  6. the downloading and distribution of content harmful to minors, and making such content available to minors;
  7. the operation of one's own server and network services without authorisation;
  8. the commercial use of the infrastructure provided without authorisation;
  9. the use of the infrastructure for cryptocurrency mining;
  10. the circumvention of age and access restrictions and of the filtering and logging systems.

A.12 Care of devices and facilities

  1. Devices, cables and accessories provided are to be treated with care and used only for the purpose for which they were supplied. They must not be lent, exchanged or stored elsewhere.
  2. Cables and adapters must not be unplugged or used for other purposes. Structural and technical installations must not be altered.
  3. No food or drink is permitted at computer workstations, in particular in the library and the computer rooms. Food and drink brought in must remain sealed.
  4. On leaving a workstation, the session is to be locked or ended. Papers brought in are to be taken away again.
  5. Anyone who notices damage or a fault must report it without delay in accordance with section A.13, even where they did not cause it.
  6. Personal devices must be secured with current security updates, a screen lock and protection against malware. Devices without security updates may be excluded from the network.
  7. The security software deployed on school systems removes files identified as harmful irrespective of where they are stored, including on connected removable media.
  8. Chargers, extension leads and additional equipment in rooms are subject to the Heimordnung. Permitted items are the power supplies and charging cables of approved devices and one tested extension lead. Personal network equipment, printers and appliances with a high power draw are not permitted. The prohibition of electrical household appliances under the Heimordnung remains unaffected; it does not extend to the power supplies and extension leads referred to here.

A.13 Faults, security incidents and reporting routes

  1. Duty to report. Faults, damage, missing equipment, suspected malware, lost or stolen devices, manifestly incorrect permissions and any suspected breach of this policy must be reported without delay.
  2. Reporting routes.
    SituationFirst point of contactDeadline
    Technical fault, damage, defective deviceIT department, support@internatsolling.de, telephone 05531 1287-800without delay
    Lost or stolen devices, compromised access credentialsIT department and, in the case of pupils, also the Kamleitungimmediately
    Suspected malware, suspicious emailIT department; disconnect the device from the network and stop working on itimmediately
    Possible loss of personal datasupport@internatsolling.de, and also the IT departmentimmediately, and within 12 hours at the latest
    Cyberbullying, threatening or humiliating contentKamleitung, pastoral teacher, school social work team, designated safeguarding contact or head of school, in accordance with section A.5 item 4without delay
    Indication of a risk to a child's welfaredesignated safeguarding contact or designated safeguarding specialist under the safeguarding policy; for names see the notice board and the contact listimmediately
    Emergency involving danger to life or limbemergency number 112, then the head of boarding or the head of schoolimmediately
    The IT department can be reached from Monday to Friday between 08:00 and 15:00; in technical emergencies it can in addition be reached by mobile telephone.
  3. Reporting personal data breaches. The initial internal report is made within 12 hours of the breach becoming known, to support@internatsolling.de using the school's incident form. An initial assessment is made within four hours, documentation in the incident register within twelve hours, and the decision on notifying the supervisory authority within 24 hours. Notification to the supervisory authority under Article 33 GDPR is made without delay and, where feasible, within 72 hours of the breach becoming known, unless the breach is unlikely to result in a risk; it is made by the data protection officer on behalf of Internat Solling. Where there is a high risk, data subjects are notified without delay. Every incident is documented internally, even where there is no duty to notify. No one is penalised for reporting an incident; late reporting or a failure to report makes it considerably harder to limit the damage.
  4. Immediate measures. In order to maintain or restore operations, the IT department may block accounts, devices or services without prior notice. The person affected is informed afterwards.

A.14 Liability

  1. Internat Solling provides the infrastructure so far as its means allow. It is liable for faults, interruptions, loss of data or damage arising from its use only in cases of intent and gross negligence, and in cases of breach of material contractual obligations and of damage arising from injury to life, body or health. Any further liability is excluded.
  2. Anyone who culpably causes damage is liable under the general law. This includes consequential loss and the cost of restoring proper operation, as well as costs claimed against Internat Solling by third parties. In the case of minors, liability depends on their capacity of discernment; the parents and legal guardians may be liable where they have breached their duty of supervision.
  3. Users are themselves responsible for their activities online, in particular for chargeable orders and for entering into contracts.
  4. Internat Solling accepts no responsibility for private devices or for the data stored on them.

A.15 Consequences of breaches

  1. Stages. Breaches are met with a graduated response: a word of advice and a discussion, a formal warning, restriction of individual services, downgrading, suspension of access for a fixed period, and permanent suspension. The measure chosen depends on the seriousness of the breach, whether it was intentional, whether it was repeated, and its consequences. Independently of and in addition to this sequence, a claim for damages and a criminal complaint may be pursued.
  2. Downgrading. Downgrading means that, for a fixed period, the rules of use for the next lower age group under Annex E.6 apply to a pupil. It is imposed by the Kamleitung with the agreement of the head of boarding, normally lasts for up to four weeks and is recorded in writing. The parents and legal guardians are informed. On expiry of the period, the regular group rules apply again; any extension must be justified.
  3. Relationship to other measures. In the case of pupils, educational measures and disciplinary measures under the school regulations and the Heimordnung apply in addition. In the case of employees, measures under employment law are reserved.
  4. Procedure. Before a measure is imposed, the person concerned is heard and, in the case of minors, the parents and legal guardians are involved. Immediate measures to avert danger under A.13 item 4 remain unaffected.
  5. Documentation. Measures are recorded in writing and deleted on expiry of the applicable retention period.

Part B – Supplementary provisions for pupils

Part B applies in addition to Part A to all pupils of Internat Solling.

B.1 Account, devices and access

  1. Every pupil receives a personal user account for their time at Internat Solling. It is deactivated when they leave the school and deleted thereafter.
  2. Depending on the age group, a limited number of devices may be registered on the Wi-Fi network; the current number is set out in Annex E.6. Devices are registered permanently to the individual concerned. Only the IT department can remove a device from a profile, for instance following a defect or a replacement.
  3. Which devices are permitted for each age group is set out in Annex E.6. Desktop computers, secondary devices used to circumvent this policy and devices whose specification is plainly designed for gaming are not permitted.
  4. Simple network devices without their own login facility, in particular speaker systems, stereo systems, games consoles, streaming sticks and home automation devices, cannot be registered on the school Wi-Fi network. Whether and where leisure devices may be operated in the residential areas is governed by Annex E.6 and the Heimordnung.
  5. Workstation computers are available in the library. Data stored on these machines are deleted on restart. Work must be saved in OneDrive or on the pupil's own storage medium.
  6. Personal usage and the number of registered devices may be viewed at pass.internatsolling.de. The page is accessible only from the Wi-Fi network.
  7. Additional unthrottled data volume is granted only for school purposes. The application is not made by pupils themselves but by the relevant Kamleitung to the IT department.

B.2 Printing

  1. A monthly printing allowance according to year group is available through drucker.internatsolling.de.
  2. If the allowance has been used up and further pages are needed in the current month, the Kamleitung applies to the IT department.
  3. In the interests of protecting the environment and conserving resources, unnecessary printing and copying are to be avoided. Before printing, consider whether digital use would suffice, whether double-sided printing is possible and whether all the pages are really needed.

B.3 Software and services

  1. Software packages and services are provided through the personal account, in particular Microsoft 365 with email access, Teams, OneNote and OneDrive, the All4Schools school administration system and Adobe Creative Cloud. The scope depends on the licence assigned and is set out in Annex E.7.
  2. The licences apply only for the duration of a person's association with Internat Solling and for school purposes.
  3. For the services provided, Internat Solling has concluded the necessary agreements and documented where processing takes place; the details are set out in Annex E.7. With some providers, processing outside the European Union cannot be ruled out. Where a cloud function is optional, this is noted in Annex E.7; the decision whether to use it rests with the user and, in the case of minors, with the user together with their parents and legal guardians.
  4. Installing additional software on the school's devices on one's own initiative is prohibited.

B.4 Conduct in the residential areas and during free time

  1. Times of leave, bedtimes and periods of quiet are governed by the Heimordnung. The times of use, restriction periods and safekeeping arrangements linked to them are set out in Annexes E.6.2 to E.6.4.
  2. The prohibitions on recording under section A.6 item 2 apply in the residential areas without qualification and must be observed with particular care.
  3. Other pupils' devices are not to be used without their express permission, not even briefly. A device left unattended and unlocked does not constitute permission.
  4. Where another person's session has been left open on a shared computer, this is to be pointed out; the session must not be used.

B.5 Communication

  1. Only the channels set out in section A.4 item 1 are to be used for communication with teaching staff, Kamleitungen and the administration. For pupils these are Microsoft Teams, the school email address, All4Schools with the pupil portal, portal.internatsolling.de and the telephone in the Kam.
  2. No one is obliged to use a private messenger service for school purposes or to give out a private telephone number.
  3. Teaching staff and employees must not be contacted through their private accounts or private telephone numbers.
  4. Binding information is announced through the approved channels and is to be checked at least once on every school day, by the end of the Arbeitsstunde.
  5. Chats with teaching staff are for brief school-related queries within the communication hours. Personal and confidential matters are to be discussed in conversation, not in a chat.

B.6 Artificial intelligence in learning

  1. Principle. AI systems may support one's own thinking, but must not replace it. Work submitted as one's own must have been produced independently.
  2. Permitted use. Use is permitted in particular to have matters explained, to generate ideas, to practise, to obtain feedback on one's own texts and to prepare for research – unless the teacher directs otherwise for the task in question.
  3. Impermissible use. It is not permitted to submit as one's own work any text, translation, method of calculation, program code or image that has been substantially produced by an AI system. In class tests, examinations and public examinations, any use is prohibited unless it has been expressly permitted.
  4. Duty to declare. In coursework, extended essays, presentations, project work and seminar papers, the use of AI systems must be declared, even where it was merely supportive.
  5. Consequences. A breach is treated as an attempt to deceive and is dealt with under the applicable rules on the assessment of work.
  6. Form of declaration. The declaration is made on the form at Annex E.9 and attached to the work. The system used, the period of use and the nature of the assistance must be stated; the declaration of independent authorship must be signed. The form applies uniformly across all subjects.
  7. Age limits. Pupils who have reached the age of 14 may use approved AI systems independently for school purposes. Below the age of 14, use is permitted only under the guidance of a teacher during lessons. Providers' terms of use set their own minimum ages, which must also be observed.
  8. No personal data. No information about oneself or others that would allow a person to be identified may be entered into AI systems, and no recordings of other people may be uploaded.

B.7 Devices in lessons

  1. Compulsory device. A tablet is a compulsory device for all pupils. It is purchased by the parents and legal guardians; purchase through the school is possible and has the advantage of pre-configuration. The school does not provide the devices but administers them. Loan devices are provided only in cases of proven hardship and as a replacement during a repair.
  2. Minimum requirements. Tablet: current device generation, screen diagonal of at least 10.2 inches, storage of at least 128 gigabytes (256 gigabytes recommended), in each case with the current operating system version. Compulsory accessories: a stylus and keyboard, and a robust protective case. A notebook may be applied for from Year 8 and is recommended in the sixth form; minimum specification 8 gigabytes of memory, 256 gigabytes of storage, current operating system.
  3. Registration. Where an existing private device is to be used, the IT department must be contacted beforehand at support@internatsolling.de.
  4. Costs. A charge is levied for the administration of devices. For devices purchased through Internat Solling, the licence and administration fees are included in the purchase price. For devices purchased privately, a one-off administration fee of EUR 75.00 per device is charged.
  5. Resetting. Devices are reset completely when they are enrolled in the device management system and when they are removed from it. All data are lost in the process. A backup made before these steps must not afterwards be restored, because it contains the old management profile. Any data required must be saved separately beforehand.
  6. What the device management system can do. Through the device management system, the IT department can distribute applications and settings, remove unapproved applications, activate location- and time-dependent profiles, lock or reset a device in the event of loss or danger, and detect tampering with the management profile. It can see which applications are installed, which network connections exist and whether attempts at circumvention have taken place.
  7. What teaching staff can do in lessons. During lessons, teachers can permit or block applications and websites, restrict a device to a single application, see which applications and websites are open, and view the screen. Screen viewing is indicated visibly on the device. These powers apply only during lessons and must not be used as a disciplinary measure.
  8. What the device management system does not do. The device management system does not create location histories or movement profiles. Private messages, photographs, videos, notes, files and passwords are not visible to the IT department or to teaching staff. No monitoring of the device takes place outside lesson time.
  9. What parents and legal guardians can do. Through the parents' application of the device management system, parents and legal guardians can limit the time spent in individual applications, block applications and view usage times. They cannot view content, cannot lift restrictions imposed by the school and cannot remove the device from management.
  10. Examination mode. For examinations, an examination mode is activated automatically on the devices, which blocks applications that are not required, internet access and wireless file transfer.
  11. Maintenance and damage. The school bears the cost of faults arising from device management, school software or faulty updates. Damage from drops, water and mishandling, as well as loss and theft, are borne by the parents and legal guardians. Device insurance is recommended.

B.8 Support and remote maintenance

  1. The IT department assists in connecting notebooks, tablets and telephones brought from home to the Wi-Fi network.
  2. General support for private devices and private software is not provided. This restriction does not apply to devices owned by Internat Solling.
  3. Remote maintenance. For support on a device, it may be necessary for members of the IT department to log in to the device or to view its screen. The screen contents are visible in the process. Connection to a device on which a user is logged in takes place only after notice has been given and that person has confirmed. Screen contents are never observed without the user's knowledge. Remote maintenance sessions are logged; the time, duration, device and person carrying out the work are recorded. Independently of this, the IT department may lock or reset a device registered in the device management system where this is necessary to avert danger or in the event of loss; the person concerned and, in the case of minors, the parents and legal guardians are informed.

Part C – Supplementary provisions for teaching staff and employees

Part C applies in addition to Part A to all employees of Internat Solling and, with the necessary modifications, to freelance staff, volunteers, apprentices and interns.

C.1 Professional use, private use

  1. Restriction to professional purposes. Official accounts, devices, email mailboxes and network access are provided for professional purposes.
  2. Private use of the official mailbox: prohibited. The official email mailbox must not be used for private purposes. The reason is the audit-proof archiving of all official correspondence: private messages would be captured along with it and could not subsequently be separated out. At the same time, the prohibition ensures that the school can access the mailbox in cases of illness, leave or departure without taking note of private communications.
  3. Private use of the internet: tolerated within narrow limits. Occasional private use of the internet connection during breaks and outside working hours, to a minor extent, is permitted so long as it does not impair professional duties, incurs no cost and does not breach section A.11. The guest network is provided for purely private use. No entitlement arises from this tolerance; it may be withdrawn at any time. Log data are analysed exclusively in accordance with section A.3 item 9.
  4. Access to mailboxes. Access to an official mailbox by a third party takes place only where necessary for professional reasons, in particular during prolonged absence or after a person has left, and only with the approval of the head of school and the involvement of the data protection officer. Access is logged and notified to the person concerned. Where an absence can be planned for, an out-of-office message and cover arrangements must be set up.
  5. Leaving the school. Before leaving, official data are to be handed over, private content removed, and all devices, storage media and means of access provided by the school returned.

C.2 Handling the personal data of third parties

  1. Data concerning pupils, parents and legal guardians and colleagues are processed only in the systems designated for the purpose, in particular in All4Schools and in the services provided by the school.
  2. Transferring such data to private systems, private mailboxes, private cloud storage, note-taking applications or messenger services is prohibited.
  3. Private devices. The use of private devices for professional purposes is permitted where it has been approved in writing in advance by the head of school. The approval is valid for five years and must be obtained afresh where there are material changes. It is subject to the following conditions: The approval is granted informally in text form; the application and the approval are placed on the personnel file. The school obtains no access to the private device. It may withdraw the approval where the conditions cease to be met.
  4. Paper records and storage media containing personal data are to be kept under lock and key and must not be left unattended. Documents no longer required are to be destroyed in a manner compliant with data protection law.
  5. Special categories of personal data, in particular health data and information from counselling and child protection proceedings, are subject to a narrower circle of authorised users and are held exclusively in the parts of the systems designated for the purpose.
  6. The confidentiality undertaking at Annex E.3 is signed before duties are taken up. It continues in force beyond the end of the person's duties.

C.3 Professional distance and contact with pupils

  1. Communication with pupils takes place exclusively through the channels set out in section A.4 item 1.
  2. Private telephone numbers, private email addresses and private social network accounts are not given to pupils and are not used for contact with them.
  3. Contact requests from pupils on private networks are not accepted. Existing private connections with pupils who are minors are to be ended; exceptions arising from family relationships are to be notified to the head of school.
  4. Individual chats with pupils who are minors do not take place outside professional occasions. Individual communication required for professional reasons takes place through channels that leave a proper record.
  5. Where a pupil turns to a member of staff in a crisis through a channel that is not approved, help is not to be refused; the matter is subsequently documented through an approved channel and notified to the responsible body.
  6. These provisions serve to protect both sides and form part of the school's safeguarding framework.

C.4 Communication and external representation

  1. Statements on social networks are not made in the name of Internat Solling unless the person concerned has been authorised to do so.
  2. Official matters, the contents of meetings, personnel matters and the personal circumstances of members of the school community are not reported on publicly. The duty of confidentiality under the contract of employment applies in digital spaces as well.
  3. Photographs of pupils are not published on private accounts.
  4. Press enquiries and enquiries from public authorities are not to be answered personally, but forwarded to the head of school without delay.

C.5 Remote maintenance and support

  1. For remote maintenance and support on a device, it may be necessary for members of the IT department to log in to the device or to view its screen. The screen contents are visible in the process.
  2. Connection to a device on which a user is logged in takes place only after notice has been given and that person has confirmed. Confidential content must be closed before access is granted.
  3. Screen contents are never observed without the user's knowledge.
  4. Remote maintenance sessions are logged; the time, duration, device and person carrying out the work are recorded.

C.6 Artificial intelligence in professional use

The rules in section A.8 apply to the professional use of AI systems. In addition, the following applies:

  1. No pupils' names, mark lists, assessments, texts of expert opinions, letters to parents, health information or internal documents are to be entered into systems that have not been approved. Where AI systems are to be used in support of a task, the content must first be altered so that any reference to an individual is excluded.
  2. Report comments, assessments, expert opinions and letters to parents are not to be taken from AI output without checking. Responsibility for substance and language remains with the teacher.
  3. Where AI systems are used in support of assessment, the assessment decision remains exclusively with the teacher.
  4. Attendance at the training courses on AI competence is mandatory.

C.7 Supervision and example

  1. Teaching staff and teaching support staff work to ensure that pupils comply with this policy, and address breaches.
  2. When digital media are used in lessons, care is taken to ensure that content is age-appropriate and that the rules on recordings are observed.
  3. Anyone who becomes aware of indications of cyberbullying, sexualised abuse, self-endangerment or extremist content reports the matter in accordance with section A.13.

Part D – Provisions for visitors, external parties and service providers

Part D applies to persons who are temporarily present on the grounds or who work for Internat Solling without being pupils or employees. These include visitors, parents and legal guardians attending events, speakers, tradespeople, the employees of external service providers and applicants.

D.1 Visitor access to the network

  1. Visitors log in to the Internat Solling Wi-Fi network with a personal guest account and are automatically assigned to a network zone that gives no access to internal systems. Access is issued as a personal guest account by reception or the school office. The standard validity is seven days; it may be extended for longer assignments. On expiry, the account is blocked automatically.
  2. Access credentials are personal and must not be passed on.
  3. Content filtering applies in the guest network as well. Use is limited to the customary extent; there is no entitlement to availability or bandwidth.
  4. The prohibitions under section A.11 apply without qualification.
  5. In order to ensure operation, connection data are logged and deleted in accordance with the periods set out in section A.3 item 8.

D.2 Conduct on the grounds

  1. Photographic, audio and video recordings are permitted on the grounds only with the prior consent of the head of school or of the inviting body, and only with the consent of the persons captured. The prohibitions on recording under section A.6 item 2 apply without qualification. For parents and legal guardians attending events, section D.4 item 3 takes precedence.
  2. Minors are present on the grounds. Contact with pupils takes place only within the scope of the assignment concerned and never unsupervised.
  3. Information obtained about members of the school community is to be treated in confidence and not passed on.
  4. Work on technical installations, network installations and server rooms is carried out only by arrangement with the IT department.

D.3 Service providers with system access

  1. External service providers are granted access to systems only so far as necessary for the purpose of their assignment, for a limited period and on a named-person basis.
  2. Before access is granted, a data processing agreement must be concluded where personal data are processed, together with a confidentiality undertaking.
  3. There are no permanently open remote maintenance connections, nor will any be established. Access is opened only for a specific occasion and for the duration of the work, is accompanied by the IT department, is logged and is then closed again.
  4. Access to systems containing personal data is logged. The service provider names the individuals deployed.
  5. On completion of the work, data supplied are returned or deleted; deletion is confirmed.

D.4 Events

  1. At events, attention is drawn to the applicable rules on recordings.
  2. Certain events, in particular performances and concerts, are recorded. Notice of the recording is given in advance. An area not covered by the recording is designated in the event room. Publication takes place only on the basis of the consent given under Annex E.2.
  3. By way of exception to section D.2 item 1, parents and legal guardians attending events to which they have been invited may make recordings of their own child for private purposes without separate consent. Recordings in which other children or members of staff are identifiable must not be published, passed on or posted on social networks. The prohibitions on recording under section A.6 item 2 remain unaffected.

D.5 Acknowledgement

  1. Visitors who use only the guest network receive the short version at Annex E.4.
  2. External parties with access to systems, or who are regularly present in areas used by pupils, sign the undertaking at Annex E.8.

Part E – Annexes and forms

Annexes E.6 and E.7 are maintained on an ongoing basis by the IT department and may be amended without reissuing this policy. All other annexes form part of the policy.

The forms at Annexes E.1 to E.5, E.8 and E.9 are issued as separate printed masters. They form part of this policy.

E.1 to E.5 and E.8 and E.9 – Forms

The ISL Portal interface itself is in German; the linked forms open there.

All printed masters as a single document: Forms for the IT and Media Policy

E.6 Devices, times, safekeeping, allowances and profiles

This annex is maintained by the IT department and updated when changes occur, without reissuing this policy.

E.6.1 Permitted devices by age group

GroupPermitted devicesLeisure devices in the residential areas
Schützen, Years 5–71 tablet, 1 mobile telephone (restricted use); no private notebooks, no secondary devicesnot permitted
Scholaren, Years 8–101 tablet, 1 mobile telephone, 1 notebook on applicationonly in the communal areas of the Kam
Magister, Years 11–131 tablet, 1 mobile telephone, 1 notebook, 1 further device on applicationpermitted, outside the hours of night-time quiet
Teaching staff and employeesschool device and approved private devices under section C.2–
Visitors and external partiesown devices on the guest network–

E.6.2 Network access, restriction periods and time allowances

ProvisionSchützen (5–7)Scholaren (8–10)Magister (11–13)
Wi-Fi use07:30–21:0007:00–22:00no fixed restriction period
Device lock at night-time quietfrom 21:00from 22:00no lock; streaming blocked from 22:00
Social networksblockedon weekdays from 16:00 to 21:00, at weekends 14:00–21:00; blocked 22:00–07:00permitted, with a time allowance and content filtering
Streaming for leisure purposesnot permitted; educational content only16:00–22:00, no more than 2 hours a dayno more than 3 hours a day, bandwidth limited
Gamesblockedat weekends only, 15:00–21:00permitted; bandwidth reduced after 23:00
Messenger services that are not approvedblockedblocked during school hoursblocked during school hours
Filtering profilestrictmediumextended

From 22:00, streaming services are blocked generally on the boarding network. These times are subject to the times of leave and bedtimes set out in the Heimordnung; where the latter end earlier, the Heimordnung prevails.

Magister, Years 11 to 13. For the sixth form, the principle of personal responsibility applies. Devices are not handed in and there are no fixed restriction periods. The prohibitions on recording under section A.6, the rules on network access and on the prohibition of circumvention under section A.3, bandwidth management and night-time quiet under the Heimordnung apply without qualification. Streaming is throttled from 22:00 and the bandwidth for online games is reduced from 23:00. Anyone who repeatedly disturbs night-time quiet may be downgraded by the head of boarding, for a fixed period, to the arrangements applying to Scholaren; the measure is recorded in writing and notified to the parents and legal guardians.

E.6.3 Use of mobile telephones during the day

PeriodProvision
During lessonsMobile telephones, smartwatches and comparable devices are to be in flight mode and are not to be used. This applies to teaching staff as much as to pupils. In class tests and examinations, devices are placed in the box provided before the start; carrying a device on one's person or in a school bag is treated as an attempt to deceive.
Between the end of lessons and 17:15Use is permitted in one's own room, but not in teaching or communal areas.
Arbeitsstunde 17:15–18:45No use. The rule of absolute quiet under the Heimordnung applies.
From 18:45 until the applicable restriction periodUse in accordance with the time windows in table E.6.2.
Schützen, Years 5–7The mobile telephone is handed in to the Kamleitung and issued after supper until bedtime. At night the devices remain in the charging cabinet of the Kam.
Meals, assemblies, Hohe Halle (main hall), official gatheringsNo private use of entertainment or communication media, including with headphones or earphones.

E.6.4 Safekeeping outside the hours of use

GroupSafekeeping
Schützen, Years 5–7At night in the lockable charging cabinet of the Kam. Devices are issued and collected in by the Kamleitung.
Scholaren and Magister, from Year 8Kept in one's own room on one's own responsibility.
Examinations and class tests, all groupsPlaced in the box provided in the classroom before the start of the paper.
Day pupils in the lower yearsPlaced in the secure box, or on the table provided for the purpose, in the classroom at the start of lessons.
Departures in individual casesThe Kamleitung may make different arrangements on educational grounds or at the request of the parents and legal guardians. These are recorded in writing and notified to those concerned.

Liability. Devices taken in by the school are kept under lock and key. Internat Solling is liable for loss and damage only in cases of intent and gross negligence. Responsibility for devices that are not handed in but kept in a room rests with the person concerned.

Contacting Schützen. While a mobile telephone is handed in, parents and legal guardians may reach their child through the Kamleitung. In urgent cases, contact is established without delay.

E.6.5 Printing allowances

The allowances apply per calendar month and are reset at the turn of the month. Black-and-white and colour pages are counted separately; copies count as prints. A notice is issued when 80 per cent of the allowance has been reached.

GroupBlack and whiteColourTotal
Schützen, Years 5–710025125
Scholaren, Years 8–1017550225
Magister, Years 11–1322575300
Teaching staff12001501350
Voluntary service staff, casual employees and interns250100350

Different allowances apply to certain roles with particular requirements, especially in the arts. These are granted individually by the IT department and are not set out here.

Applications for additional printed pages for pupils are made to the IT department by the Kamleitung alone. Employees apply to the IT department directly.

E.6.6 Device profiles

ProfileTriggerEffect
Lessonbeacon in the teaching roomschool applications only; social networks and games blocked; file transfer and external messenger services disabled
Librarynetwork environmentresearch permitted, games and social networks blocked
Boardingnetwork environment of the residential areasleisure use in accordance with E.6.2
Examinationstart of the examinationall applications not required, internet access and wireless transfer blocked
Privatedisconnection from the school networkno school-side control; the rules of this policy continue to apply so far as school matters are concerned

E.7 Approved services and systems

This annex is maintained by the IT department.

ServiceApproved forPermitted types of dataPlace of processingNotes
Microsoft Teamsall groupsschool communication; no special categories, no records of behaviourEuropean Unionteams are created centrally; pupil chats only for school-related queries
Microsoft Exchange Onlineteaching staff, employees, pupilsofficial and school correspondenceEuropean Unionaudit-proof archiving, retention 10 years
OneDriveall groupsone's own working filesEuropean Unionnot a storage location for files containing special categories of data
SharePointadministration, academic departmentsmaster data, departmental filingEuropean Unionarchive function; new pupil files are created in All4Schools
Microsoft Formsemployeesinternal surveysEuropean Unionbeing phased out for pupil and parent surveys
All4Schoolsaccording to the roles frameworkschool administration data including absences, marks and reportsEuropean Unionsystem of record; data processing agreement concluded
WebUntisuntil replacement: all groupstimetable, class register, communication with parentsEuropean Uniontransitional system; to be replaced by All4Schools
ISL Portal (portal.internatsolling.de)pupils, parents and legal guardians, teaching staff, employees, committees, external parties according to rolemaster data, access credentials, form data including health information in emergency contact forms, development reports, financial and billing data, digital signatures, card identifiers, Wi-Fi data, consents, log dataoperated in-house on the school's serversdeveloped in-house; separate role and visibility rules for each module; retention periods for each module in accordance with Annex E.10
Adobe Creative Cloudpupils, teaching staffno personal data of third partiesEuropean Unioncloud function optional; storage outside the EU possible
Relution device managementall managed devicesdevice and configuration data, profile changes; no contentEuropean Unionscope of functions in accordance with section B.7
Fobizzteaching staff and pupils aged 14 and overno personal dataEuropean Unionlesson preparation
Email security and archivingall official mailboxesofficial correspondenceEuropean Unionaccess only in accordance with section A.9 item 7

The entry "European Union" denotes the place where the data are stored at rest. It does not mean that access from third countries is excluded: with providers established outside the European Union, or with corporate ties outside it, such access may arise under the law of that country, in particular in the course of support and security operations. Whether such access is lawful is governed by the transfer provisions of the GDPR and must be documented for each processing operation in the record of processing activities.

E.10 ISL Portal – modules and retention periods

The ISL Portal is developed in-house by Internat Solling and is the central platform for communication and administration. It comprises some 70 modules and is used by pupils, parents and legal guardians, teaching staff, employees and committees. Access is through the personal account or the school's directory. Each module has its own visibility rules; access exists only within the scope of the relevant role.

AreaContentRetention
Formssickness notifications, requests for leave of absence, emergency contact and health information, registrationsset for each form, automatic deletion
Contracts and consentsdigital contract processes with signature, consents and withdrawalsin accordance with contractual and statutory periods
Boarding and pastoral careroom allocation, weekend leave notifications, development reportsroom allocations 3 years; development reports 3 years after leaving
Sixth form guidancepredicted marks, course choices, guidance papers5 years after leaving the school
Network operationWLAN session data for ensuring network operation30 days; aggregated statistics without personal reference 90 days
Logsapplication and error logs, access log30 days; access log 90 days
Recycle bin and backupsdeleted entries, backups30 days each
File transferPIN-protected transfersautomatic deletion on expiry
Anonymous reporting channelreports with no personal referenceno login, no IP address, no personal reference
Finance and billingcost allocations, travel expenses, receiptsin accordance with commercial and tax law periods
Records of attendancebriefings, read receiptsimmutable record, no deletion during ongoing operation