1. Data Protection Officer
The Data Protection Officer of the University of Thessaly is:
Priority Quality Consultants S.A.
Email: dpo@uth.gr
Postal contact: University of Thessaly Argonafton & Filellinon 382 21 Volos Greece For the attention of the Data Protection Officer
University telephone: +30 24210 74000
2. What NursEscape is
NursEscape is a bilingual digital learning platform for delivering and managing digital escape-room experiences in nursing and the health professions.
The platform supports, among other things:
- user accounts,
- organisations and memberships,
- instructors and learners,
- courses and groups/cohorts,
- assignments,
- Room Packages and published versions,
- learner attempts,
- progress and saved state,
- scores and structured events where reported,
- results,
- certificates of completion,
- instructor analytics,
- public certificate verification,
- contact and administrative workflows.
NursEscape is not an open consumer self-registration platform. Learners are placed within defined educational and organizational contexts.
3. Categories of personal data we may process
4.1 Account and authentication data
May include:
- email address,
- normalized email,
- password hash,
- display name,
- preferred locale,
- account status,
- email-verification timestamp,
- last login,
- account creation/update timestamps.
NursEscape does not store a readable copy of your password. Authentication uses a password hash according to the production architecture.
4.2 Profile data
May include:
- optional avatar,
- timezone,
- display name,
- preferred language/locale.
4.3 Organisation and role data
May include:
- organisation membership,
- role,
- membership status,
- role-related permissions,
- associations with courses, groups and educational contexts.
Current production roles are:
- Learner,
- Instructor,
- Super Admin.
4.4 Educational organisation data
May include:
- course enrolment,
- group/cohort membership,
- assignments,
- invitations,
- invitation status,
- assignment-to-room relationships.
4.5 Learner activity / Room attempt data
Depending on the assignment and Room Package, this may include:
- assignment context,
- room and room version,
- attempt number,
- attempt status,
- progress,
- score,
- maximum score,
- saved room state,
- start time,
- last activity time,
- completion time,
- duration,
- structured room events,
- event payloads.
4.6 Results
May include:
- completion status,
- progress,
- score,
- percentage,
- duration,
- attempt count,
- course,
- assignment,
- room/version,
- related learner/session information.
4.7 Certificates of completion
Where applicable, the platform may process:
- learner-name snapshot,
- organisation,
- course,
- assignment,
- room/version,
- issue date/information,
- public verification code,
- verification status,
- internal score where needed for issuance criteria,
- revocation status/data.
The certificate is a snapshot of the relevant completion and may remain verifiable even if some account information changes later.
4.8 Public certificate verification
NursEscape supports public certificate verification using a public verification number and QR code.
4.9 Contact-form data
When you contact us through the public form, we may process:
- first name,
- last name,
- email,
- institution / organization, where optionally provided,
- subject,
- message content,
- language,
- privacy acknowledgement / consent timestamp where applicable,
- processing/status information,
- hashed IP identifier.
Please do not include health information, patient information or other sensitive personal data that are not necessary for the enquiry.
4.10 Security and audit data
For platform security, we may process:
- authentication-attempt data,
- pseudonymized/hashed email identifiers for rate limiting,
- hashed IP identifiers,
- user agent,
- timestamps,
- security/admin metadata,
- audit actions,
- session/security-related data.
4.11 Email delivery/log data
For operational email delivery, we may record:
- recipient email,
- subject,
- delivery status,
- send/delivery timestamps,
- technical delivery information.
4.12 Consent and document-version infrastructure
The production database contains technical structures for:
- Terms documents,
- Privacy documents,
- Research consent documents,
- document versions,
- re-consent requirements,
- acceptance timestamps.
The existence of this infrastructure does not mean that an active research-consent process currently exists for a specific NursEscape study.
Every real research use requires its own protocol, governance and ethics/data-protection review where applicable.
4. Special categories of personal data
NursEscape is not designed, as part of its general platform function, to require health data or other special-category data under Article 9 GDPR.
However, because Room Packages can define custom state/event payloads, careful authoring is required to prevent real patient data, health information or other sensitive information being stored without a clear, approved and lawful need.
5. Why we process personal data
6.1 Account management
To support:
- account creation/management,
- authentication,
- verification,
- role assignment,
- security,
- language/preferences.
6.2 Educational delivery
To support:
- enrolment,
- course/group management,
- assignment access,
- room delivery,
- attempt management,
- progress/state saving,
- completion,
- results.
6.3 Instructor educational management
To support:
- assignment administration,
- participation review,
- results dashboards,
- learner/session review,
- exports,
- educational follow-up.
6.4 Certificates of completion
To support:
- eligibility checks,
- certificate generation,
- PDF generation,
- public verification,
- revocation where necessary,
- integrity of the certificate record.
6.5 Communication
To:
- read and respond to enquiries,
- manage institutional/research/general enquiries,
- perform related administrative follow-up.
6.6 Security and abuse prevention
To support:
- rate limiting,
- authentication-abuse management,
- account protection,
- operational logging,
- audit,
- incident investigation,
- platform integrity.
6.7 Technical operation and support
To support:
- troubleshooting,
- service maintenance,
- error diagnosis,
- system administration,
- delivery of required transactional messages.
6.8 Future research
Research processing should not be treated as a universal purpose applying to all production data.
Every specific research study should define:
- research question,
- required data,
- participant population,
- lawful basis,
- Article 9 condition where applicable,
- ethics/governance,
- retention,
- access,
- publication/anonymisation plan.
6. Where personal data come from
Data may be obtained:
- directly from the user,
- from an Instructor or authorized administrator who places the user in an educational context,
- through institutional invitation/import processes,
- through use of the platform,
- from the Room Package through the NursEscape SDK,
- through security/authentication mechanisms,
- through certificate issuance processes.
7. Who can access personal data
Access is limited according to role and purpose.
Learners
Can access their own assignments, attempts, progress, results and certificates according to platform functionality.
Instructors
May access educational-management information and learner results within the organization/course context for which they are authorized.
Super Admins / authorized administrators
May access information necessary for platform administration, security, support and governance.
University personnel
Authorized University personnel may access information where necessary for administrative, technical, legal or security purposes.
Technical service providers
Where external providers process personal data on behalf of the University, they should act under appropriate data-processing arrangements and security/confidentiality measures.
8. Hosting and technical infrastructure
NursEscape is hosted on University of Thessaly infrastructure.
The public application address is:
nursescape.hil.nurs.uth.gr
9. Cookies and session information
The production application uses a first-party session cookie:
nursescape_session
with security attributes including:
Secure,HttpOnly,SameSite=Lax.
The cookie is necessary for authentication and operation of the authenticated platform.
Current application-source review has not identified:
- Google Analytics,
- Matomo,
- Google Tag Manager,
- reCAPTCHA,
- Hotjar,
- Microsoft Clarity,
- Meta/Facebook Pixel,
- embedded YouTube/Vimeo,
- remote Google Fonts.
10. Data retention
Personal data should be kept only for as long as necessary for the relevant purpose or as required by applicable institutional/legal rules.
Authentication-attempt records
The production technical implementation currently uses a 7-day retention period for authentication-attempt rate-limiting records.
Security tokens and sessions
Some security tokens and sessions have limited technical lifetimes determined by the authentication system.
Research data
There should be no universal retention period for “research data”. Each study should define retention through its protocol, ethics/governance and data-management plan.
11. Security of personal data
The University and platform apply technical and organisational measures intended to protect confidentiality, integrity and availability.
The production design includes measures such as:
- password hashing,
- role-based access control,
- organisation-based access boundaries,
- Secure / HttpOnly session cookie,
- sandboxed Room Package execution,
- separation of rooms from application cookies/session/parent DOM/internal endpoints,
- controlled room communication through the NursEscape SDK,
- hashed/pseudonymized identifiers for selected security/rate-limiting use cases,
- audit-oriented logging,
- versioned published room artifacts.
Security controls do not mean that any information system can guarantee absolute security or zero risk.
12. Independent Room Packages and privacy
Room Packages are independent frontend web applications running inside a sandboxed environment.
They do not receive access to:
- NursEscape cookies,
- the application session,
- the parent DOM,
- internal application endpoints.
They communicate with the platform through the NursEscape JavaScript SDK.
Depending on design, a room may save or report:
- state,
- progress,
- score,
- structured events,
- completion.
13. Certificates and public verification
Certificates of completion include a public verification mechanism.
Its purpose is to allow authenticity and status to be checked.
14. External links
The public site may link to:
- the University of Thessaly,
- the Healthcare Innovation Laboratory,
- social-media profiles,
- external maps,
- other third-party services.
When you follow an external link, the third party's own privacy practices apply.
NursEscape does not control the privacy practices of external websites.
15. Your rights
Depending on the processing activity, lawful basis and applicable GDPR limitations, you may have the right to:
- access your personal data,
- rectify inaccurate or incomplete data,
- request erasure where the legal conditions are met,
- restrict processing,
- object to processing where applicable,
- data portability where applicable,
- withdraw consent where processing is based on consent, without affecting the lawfulness of earlier processing,
- receive information about appropriate safeguards for international transfers where applicable.
Not every right applies in the same way to every processing activity.
For example, erasure may be limited where continued retention is required by law, public task or another valid legal basis.
16. How to exercise your rights
You may contact the Data Protection Officer of the University of Thessaly:
Email: dpo@uth.gr
or by post:
University of Thessaly Argonafton & Filellinon 382 21 Volos Greece For the attention of the Data Protection Officer
For operational questions about NursEscape, you may also contact:
hil@uth.gr
17. Right to lodge a complaint
You have the right to lodge a complaint with the competent supervisory authority:
Hellenic Data Protection Authority
Website: www.dpa.gr
This does not prevent you from contacting the University or its DPO first.
18. Research use and secondary use of educational data
NursEscape includes research-oriented technical infrastructure, but production educational data should not automatically be treated as available for secondary research use.
Any secondary research use should assess:
- purpose compatibility,
- lawful basis,
- ethics/governance,
- necessity,
- minimisation,
- pseudonymisation/anonymisation,
- participant information,
- retention,
- access,
- publication risk.
19. Changes to this Privacy Policy
This Privacy Policy may be updated when there are changes to:
- platform functionality,
- data categories,
- processing purposes,
- institutional deployments,
- third-party services,
- legal or institutional requirements.
The latest version will be published on this page with an update date and version number.
Where a change requires new information or re-consent, the platform may use versioned document/acceptance workflows.
20. Related policies
- Cookie Policy
- Terms of Use
- Accessibility Statement
- Contact