SRSRE Labsbeta presented by Solutions Readiness Engineering
Sign in

Privacy notice

How SRE Labs handles the data it holds about you.

What we hold

SRE Labs is an internal tool for authoring and running SRE lab guides. For each account we store your name and email, your role grants and viewing tier, content you author or comment on, class-session roster entries, and usage telemetry (which guides and sections you open) used to improve the material. When you use a lab we also record the remote sessions you open to its devices — terminal, remote desktop and other consoles: which device, when, and by whom — and, only in a class that records consoles, a screen recording of those sessions. Security-relevant actions are recorded in an audit log.

Why we are allowed to hold it

Different parts of this rest on different grounds, and we do not ask for consent where consent would not be a real choice.

  • Running the labs you are enrolled on — your account, roster entries, progress through a guide, checkpoint answers and the position you resume from. We hold these because they are what the service does: a lab platform cannot show you where you got to without recording where you got to. In GDPR terms this is performance of a contract, and legitimate interests for the operational parts around it.
  • Improving the material — aggregate usage statistics: which guides are opened, how long sections take, where people stop. This runs on legitimate interests. We have weighed it against your privacy and applied the limits described under “Who can see your activity” below.
  • Watching and recording lab consoles — legitimate interests: helping you while you work, and looking into misuse of lab equipment. Watching is always visible to you while it happens, and recording is off unless the proctor turns it on for your class.
  • Security and audit records — legitimate interests, and in places a legal or contractual obligation.
  • The optional visitor cookie — consent, because it genuinely is optional. That is the only thing on this page we ask you to agree to, and you can withdraw it below as easily as you gave it.

Where we rely on legitimate interests you have the right to object — see “Your rights”.

Who can see your activity

Recording something is not the same as showing it to people, and the limits below are built into the software rather than being a matter of staff discretion.

  • Your proctor, while a class session is running, can see which section you are on and how long you have been on it, so they can help. The live lab page tells you this while it is happening. After the session ends, that per-person detail is no longer shown — staff see aggregates.
  • Guide authors and administrators see usage statistics for the material, not a per-person activity feed.
  • End-of-lab survey answers are not attributable to you by name. Staff cannot see who gave which response — the software refuses to serve respondent identity at all. Written (free-text) questions are off unless an administrator turns them on; when they are on, your class’s proctor sees the written answers however few people reply, so in a small class they may be able to tell who wrote what. Please don’t include names or other personal details in them.
  • Checkpoint answers within a lab are visible to your proctor for that session, because helping you when you are stuck is the point of them.
  • Your lab consoles — the terminal, remote desktop and other remote sessions you open to lab devices. Your class session’s proctors and the site’s administrators can watch one live, read-only, to help you. A line on the console says so for as long as they are watching, and each watch is recorded in the audit log: who, which console, and when it started and ended. On a phone, the standing notice is a single line you can dismiss.
  • Remote desktops take one person at a time. A lab’s Windows desktop allows a single remote desktop connection, so if a member of staff opens the same desktop, your connection is closed and your screen tells you why; you can reconnect to take it back. Staff are offered the read-only watch first.

Console recordings

A proctor can choose to record the lab consoles in their class. Recording is off unless they turn it on, and when it is on the live lab page tells you so.

  • What is recorded: what appears on screen in terminal and remote desktop sessions opened through SRE Labs on a pod in that class, including sessions staff open on the same pod. Keystrokes are not recorded separately, but anything you type that shows on screen will be in the recording, so do not type personal details or your own passwords into a lab device. Out-of-band virtual machine consoles are not recorded.
  • Where it is kept: on the lab controller that runs the pod, not in SRE Labs itself. Recordings are deleted automatically after 7 days, or sooner if the controller’s recording storage fills.
  • Who can play one: that class session’s proctors and the site’s administrators. Every playback is recorded in the audit log.

Cookies

  • Sign-in cookies (Auth.js session): strictly necessary to keep you signed in — always set, no consent needed.
  • Anonymous visitor id (labdeck_anon_id): the one optional cookie — remembers reading progress for signed-out visitors and feeds usage statistics. Set only after you accept the cookie prompt. Declining also deletes the id and every progress/analytics record keyed to it.
  • Consent choice (labdeck_cookie_consent): remembers your accept/decline decision so we don't re-ask.

We honour Global Privacy Control and Do Not Track. If your browser sends either signal we treat it as a decision already made: no optional cookie is set, no anonymous id is created, and you are not shown the consent prompt at all rather than being asked to repeat yourself.

Your current choice: not made yet

How long we keep it

  • Audit log (who did what — security and admin actions): kept for 400 days, then automatically deleted.
  • Usage analytics (page/section views, downloads): kept for 180 days, then automatically deleted. Day-level visitor records that power returning-visitor cohorts are pruned even sooner — within about 35 days.
  • Console recordings: kept for 7 days on the lab controller (less if its recording storage fills), then automatically deleted.
  • Account & authored content: kept for the life of your account. When your account is erased, authored content is retained but de-identified rather than deleted.

IP addresses

We record the network address your requests come from against security-relevant events — signing in, changing a password, administrative actions — and use it to enforce rate limits and to investigate abuse. An IP address is personal data, so it is not kept indefinitely: it is deleted with the audit record it belongs to, on the schedule above.

Who else processes your data

SRE Labs runs on infrastructure we operate ourselves, and your content and account data stay on it. One external service is involved: outbound email — account verification, invitations, password resets and notifications — is delivered through Amazon Simple Email Service, which necessarily processes your email address and the content of those messages in order to deliver them. Some labs also sign you in to a vendor’s own cloud dashboard, such as the Cisco Meraki dashboard for a Cloud Fabric pod. When you open one, we send that dashboard your display name and a per-class account identifier that is not your email address, and the vendor records the changes you make in the lab’s organization under that name, under its own privacy terms. We do not use third-party analytics, advertising or error-reporting services, and we do not sell or share your data for marketing.

Retention for legal obligations

When an account is erased, we scrub personal data from the live system immediately, but keep the account's existing audit-trail entries in named form for a legal-hold window of 90 days to satisfy security and compliance obligations. After that window those audit entries are anonymized automatically.

Backups and version history

Operational backups may retain data, including erased data, for up to 30 days after it is deleted from the live system: nightly encrypted backups are kept on a 30-day rolling window, after which erased data has aged out of every backup. Backups are not rewritten when an account is erased; if a backup is ever restored, erasures and retention pruning are re-applied to the restored data before it returns to service.

Guide content is versioned in an append-only history whose entries carry only a pseudonymous account identifier — never your name or email. Author attribution is resolved from your live account when history is displayed, so erasing your account anonymizes your entire content history, including in backups.

If you are in the EU or UK, or in California

EU/UK (GDPR). You have the right to access your data, correct it, have it erased, restrict or object to processing where we rely on legitimate interests, and to portability. The tools for access and erasure are on your profile page; for the others, contact us and we will action it. You can also complain to your national supervisory authority. Our systems run in the United States, so using this service means your data is transferred there, and the email service named above processes your address in a US region.

California (CCPA/CPRA). You have the right to know what we collect and why, to request deletion and correction, and not to be discriminated against for exercising either. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. There is no advertising on this service and no third-party tracker. We honour Global Privacy Control as an opt-out signal regardless, as described under Cookies.

Your rights

You can access a copy of your data at any time, and request deletion of your account.

Sign in and visit your profile page to export your data or request account deletion. To protect against accidental or fraudulent deletion, an administrator reviews every erasure request before it is carried out.

This site uses one optional cookie — an anonymous visitor id that remembers your reading progress and feeds usage statistics. Sign-in cookies are strictly necessary and always on. Privacy notice