Privacy Policy for digital products and services offered by Dr. Red Oy

At Dr. Red's Virtual Labs, accessible from https://vlabs.fi, one of our main priorities is the privacy of our visitors. This Privacy Policy document contains types of information that is collected and recorded by Dr. Red's Virtual Labs and how we use it.

This Privacy Policy applies only to our online activities and is valid for visitors to our website with regards to the information that they share and/or we collect in Dr. Red's Virtual Labs. This policy is not applicable to any information collected offline or via channels other than this website.

Data Controller

The data controller responsible for your personal data is:

Dr. Red Oy
Business ID: 3208108-7
Finland
Email: vlabs@drred.fi

Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR:

  • Contract: Processing your email address and account data is necessary to provide you with access to our services and fulfill our contractual obligations.
  • Legitimate interest: We use log files and technical data to maintain site security, prevent fraud, and improve our services.
  • Legal obligation: We retain billing and transaction records as required by Finnish accounting law.

By creating an account and using our services, you enter into a contract with us governed by our Terms and Conditions.

Information we collect

The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point we ask you to provide your personal information.

If you contact us directly or access the website with a browser, we may receive additional information about you such as your name, email address, phone number, the contents of the message and/or attachments you may send us, your IP address and any other information you may provide.

When you register for an Account, we only ask for your email address. If you become a paying customer, we may ask for further contact information, including items such as name, company name, address, and telephone number. We do not store your credit card information on this site but it is relayed to the company (Stripe Inc.) that processes payments.

How we use your information

We use the information we collect in various ways, including to:

  • Provide, operate, and maintain our website
  • Improve, personalize, and expand our website
  • Understand and analyze how you use our website
  • Develop new products, services, features, and functionality
  • Communicate with you, to provide you with updates and other information relating to the website, and for marketing and promotional purposes
  • Send you emails
  • Find and prevent fraud

Data Retention

We keep personal data only as long as it is needed. The periods below are enforced automatically by a nightly job:

  • Course results: A student's experiments, results and course enrolment are deleted 12 months after the course they belong to has closed. The teacher may delete them earlier. The course itself and its assignments are the teacher's material and are kept.
  • Purchased textbook access: Access bought on a textbook page lasts the period stated at purchase (12 months). The experiments and results carried out under it are removed one week after the access ends; an email is sent 14 days before. The purchase record is kept for the period required by accounting law.
  • Accounts: An account is removed 24 months after the last sign-in, the close of the last course the account was on, the end of a trial or the last purchase, whichever is latest. A warning email is sent 30 days before removal; signing in keeps the account. An account you have deleted yourself is removed 12 months after the deletion.
  • Technical records: Sign-in links and sessions are kept for at most 30 days, server logs for 90 days and the sign-in audit trail (including the IP address) for 12 months.
  • Transaction records: Retained for 6 years as required by Finnish accounting law.
  • Backups: Database backups are kept for up to 90 days.

You may request deletion of your account and personal data at any time by contacting us. An institution may request the erasure of all of its users' accounts and data at the end of its agreement; this is carried out within 30 days and confirmed in writing.

Log Files

Dr. Red's Virtual Labs follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this as a part of hosting services' analytics. The information collected by log files may include internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. The purpose of the information is for analyzing trends, administering the site, tracking users' movement on the website, and gathering demographic information.

Cookies and Web Beacons

Like any other website, Dr. Red's Virtual Labs uses 'cookies' to function properly. These cookies are used to store information including visitors' preferences, and the pages on the website that the visitor accessed or visited. The information is used to optimize the users' experience by customizing our web page content based on visitors' browser type and/or other information.

You can choose to disable cookies through your individual browser options. This may lead to pretty bad user experience on this site however. More information about cookie management with specific web browsers can be found at the browsers' respective websites.

Advertising Partners and Third Parties

As you will quickly notice, Dr. Red's Virtual Labs if free of third-party advertisements. We are just as annoyed by ads as you are. This also means that we are not sending your personal information to third parties while you are using our services except for during a payment process.

International Data Transfers

Your data may be processed outside the European Economic Area (EEA) by the following service providers:

  • Amazon Web Services (AWS): We use AWS to send transactional emails. AWS operates under EU-approved Standard Contractual Clauses (SCCs).
  • Stripe Inc: Payment processing is handled by Stripe. Stripe is certified under the EU-US Data Privacy Framework.

We ensure that any international transfers are protected by appropriate safeguards as required by GDPR.

GDPR Data Protection Rights

We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

  • The right to access – You have the right to request copies of your personal data.
  • The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
  • The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
  • The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Website: tietosuoja.fi
Email: tietosuoja@om.fi

CCPA Privacy Rights (Do Not Sell My Personal Information)

Under the CCPA, among other rights, California consumers have the right to:

  • Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers.
  • Request that a business delete any personal data about the consumer that a business has collected.
  • Request that a business that sells a consumer's personal data, not sell the consumer's personal data.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.

Children's Information

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

Dr. Red's Virtual Labs does not knowingly collect any Personal Identifiable Information from children under the age of 16. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on this page.

Last updated: September 2026