Table of Contents
Preamble
With this privacy policy we would like to explain what types of your personal data (also referred to below simply as "data") we process, for what purposes and to what extent, in the context of providing our application.
The terms used are not gender-specific.
Last updated: 20 September 2026
Controller
Yusuf Senel
Log-System Development
Von-Hünefeld-Str. 8
40764 Langenfeld
Germany
E-mail address: contact@omequiz.de
Overview of processing operations
The following overview summarises the types of data processed and the purposes of their processing, and refers to the data subjects concerned.
Types of data processed
- Inventory data
- Contact data
- Content data
- Usage data
- Voice and communication data (e.g. when using voice chat; where applicable short-lived audio and text data in reports and moderation)
- Meta, communication and procedural data
- Log data
Categories of data subjects
- Communication partners
- Users
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations
- Communication
- Security measures
- Reach measurement
- Tracking
- Conversion measurement
- Audience building
- Organisational and administrative procedures
- Feedback
- Marketing
- Delivery of advertising (in particular Google AdSense), including personalised advertising subject to consent
- Profiles with user-related information
- Sign-in procedures
- Provision of our online offering and usability
- Information technology infrastructure
- Public relations
- Handling of abuse and reports, moderation (including technical analysis of speech where necessary)
Relevant legal bases
Relevant legal bases under the GDPR
Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection rules in your or our country of residence or establishment may apply.
- Consent (Art. 6 (1) sentence 1 lit. a GDPR) – The data subject has given consent to the processing of their personal data for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6 (1) sentence 1 lit. b GDPR) – Processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 (1) sentence 1 lit. c GDPR) – Processing is necessary for compliance with a legal obligation to which we are subject (e.g. retention obligations, orders by public authorities).
- Legitimate interests (Art. 6 (1) sentence 1 lit. f GDPR) – Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject requiring protection of personal data do not override those interests.
National data protection rules in Germany
In addition to the data protection rules of the GDPR, national data protection rules apply in Germany. These include in particular the Federal Data Protection Act (Bundesdatenschutzgesetz – BDSG). It contains, among other things, special rules on the right of access and erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and automated decision-making in individual cases including profiling.
Storing information on, and reading it from, terminal equipment (Section 25 TDDDG)
Storing information on your device and accessing information already stored there — cookies, local storage and comparable techniques — is governed in Germany by Section 25 of the Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG; called TTDSG until 1 May 2024). Such access takes place only with your consent under Section 25 (1) TDDDG, unless it is strictly necessary to provide the service you have expressly requested (Section 25 (2) TDDDG). Any subsequent processing of the personal data obtained in this way is governed by the GDPR.
Security measures
In accordance with the statutory requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, circumstances and purposes of processing as well as the varying likelihood and severity of the risk to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
Securing online connections with TLS/SSL encryption (HTTPS)
To protect users' data transmitted through our online services against unauthorised access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet.
International data transfers
Data processing in third countries
Where we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), this is always done in accordance with the statutory requirements.
For data transfers to the USA we rely primarily on the Data Privacy Framework (DPF), which was recognised as a secure legal framework by an adequacy decision of the EU Commission dated 10 July 2023. In addition, we have concluded standard contractual clauses with the respective providers.
Further information on the DPF can be found at: https://www.dataprivacyframework.gov/
General information on data storage and erasure
We erase personal data that we process in accordance with the statutory provisions as soon as the underlying consent is withdrawn or no further legal basis for the processing exists.
Retention and erasure of data
The following general periods apply to retention and archiving under German law:
- 10 years – retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets (§ 147 (1) no. 1 in conjunction with (3) AO, § 14b (1) UStG, § 257 (1) no. 1 in conjunction with (4) HGB)
- 8 years – accounting vouchers such as invoices and expense receipts (§ 147 (1) nos. 4 and 4a in conjunction with (3) sentence 1 AO and § 257 (1) no. 4 in conjunction with (4) HGB)
- 6 years – other business documents (§ 147 (1) nos. 2, 3, 5 in conjunction with (3) AO, § 257 (1) nos. 2 and 3 in conjunction with (4) HGB)
- 3 years – regular statutory limitation period (§§ 195, 199 BGB)
Rights of data subjects
Your rights under the GDPR
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you.
- Right to withdraw consent: You have the right to withdraw consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain access to that data.
- Right to rectification: You have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: You have the right to request that data concerning you be erased without undue delay.
- Right to data portability: You have the right to receive data concerning you in a structured, commonly used and machine-readable format.
- Complaint to a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement.
The supervisory authority responsible for us
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2-4, 40213 Düsseldorf, Germany
https://www.ldi.nrw.de
Notice of your right to object (Art. 21 GDPR)
Where we process data on the basis of legitimate interests (Art. 6 (1) lit. f GDPR), you may object to that processing at any time on grounds relating to your particular situation. For us this concerns above all the security and moderation processing. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves to establish, exercise or defend legal claims. An objection requires no particular form — contact@omequiz.de is enough.
Provision of the online offering and web hosting
We process users' data in order to be able to provide them with our online services. For this purpose we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.
Types of data processed
- Usage data (page views, time on page, click paths)
- Meta, communication and procedural data (IP addresses, timestamps)
- Log data (log files, access data)
- Content data (messages, posts)
Web hosting provider: netcup
Services in the area of providing information technology infrastructure and related services.
Service provider: netcup GmbH, Daimlerstraße 25, D-76185 Karlsruhe, Germany
Website: https://www.netcup.de/
Privacy policy: https://www.netcup.de/kontakt/datenschutzerklaerung.php
Cloudflare: network, protection and object storage
Our service is delivered through Cloudflare's network. Every request to omequiz therefore passes their servers before it reaches ours. Cloudflare filters out overload and attack traffic, serves unchanging content, and terminates the encrypted connection.
Data processed: IP address, the address requested, the time, the browser identifier and the other technical details a request carries.
Purpose: availability and security of the service, and defence against overload and attack traffic.
Legal basis: legitimate interests (Art. 6(1)(f) GDPR).
Two things that appear elsewhere in this policy originate here. A visitor's IP address reaches us only by way of Cloudflare — we deliberately do not read the other headers a request may carry about its origin, because the sender can set those freely. And the country we store with a round comes from there as well; it names a country, not a place.
Cloudflare also operates our object storage (Cloudflare R2). Uploaded profile pictures, images for community quizzes and the evidence described in the moderation section are held there.
In both roles Cloudflare acts as a processor on our behalf.
Service provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA
Website: https://www.cloudflare.com
Privacy policy: https://www.cloudflare.com/privacypolicy/
Basis for third-country transfers: Data Privacy Framework (DPF) or standard contractual clauses
Collection of access data and log files
Access to our online offering is logged in the form of so-called "server log files". Log file information is stored for a maximum of 30 days and then deleted or anonymised.
IP addresses for abuse prevention (Art. 13 GDPR)
So that sign-in, registration and the open game functions cannot be abused by automated means, we process the IP address of your connection. This section describes exactly what happens, separated into three forms, because they differ considerably in duration and in how far they reach.
1) Short-term counting (rate limiting)
For sign-in, registration, password resets, confirmation emails, the public programming interface and the solo and daily rounds, we count how many requests come from an address. The address serves as a key in a temporary cache.
- Categories: IP address in plain text, together with the email address entered when signing in
- Purpose: protection against automated sign-in attempts, mass registrations and overload
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR)
- Duration: between 60 seconds and 2 hours depending on the function; the entry then expires by itself
2) Pseudonymous identifier of the last sign-in
On every sign-in we compute a cryptographic check value from your IP address (HMAC-SHA256 under a server key known only to us) and store it with your account. We do not store the address itself, only this check value. Without the server key it cannot be turned back into an address — and for the same reason we cannot show you a list of your previous IP addresses: we do not have them.
Exactly one value is stored, and it is overwritten at every new sign-in. No history of your visits and no movement profile is created.
- Categories: pseudonymous check value of the IP address last used to sign in
- Purpose: the precondition for being able to block an address at all in the event of abuse
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR)
- Duration: until the next sign-in (overwritten), at the latest until the account is deleted
3) Block list for individual cases
In serious cases — such as hate speech or persistent spam — a person on the moderation team may, in addition to an account or server measure, order that the address last used to sign in be refused temporarily. Here too, only the check value goes on the block list, never the address.
- Categories: pseudonymous check value, the moderator's grounds, the time, the person who ordered it
- Purpose: preventing an immediate return after a measure
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR)
- Duration: 30 days; the entry then loses effect and is deleted by a regular clean-up run
4) Incident record when a block is applied
If an address is temporarily blocked for making too many requests, we create a record of it. This is the only item in this section that holds the IP address in the clear. The reason is the purpose: a check value answers "is this the same address", but not "which address" — and only the second can be investigated, for instance to notify a provider's abuse contact or to report an incident to the authorities.
Our application logs then contain only an eight-character reference, no longer the address. No email address is stored here.
- Categories: IP address in the clear, the account concerned (if signed in), browser identifier, endpoint, number of requests, time
- Purpose: investigating and preventing abuse
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR)
- Duration: 7 days, then deleted automatically by a regular clean-up run
5) Recognition after an account deletion
Deleting an account also deletes the bans, warnings and reports attached to it — and the same person could sign up again a minute later as if nothing had happened. So that a ban cannot be evaded by deleting and re-registering, we retain a small record when an account is deleted.
It contains no email address, no IP address and no sign-in provider id in the clear, only a check value of each (HMAC-SHA256 under the same server key as in section 2). That answers whether a new sign-in uses the same email address or the same Google or Discord account — and nothing more. Added to it are the country and, where Cloudflare supplies one, a check value of the TLS fingerprint of the deleting connection, the browser identifier, and the moderation history in numbers: whether a ban existed, until when and why, the number of warnings, of moderation actions and of reports against the account. The display name is kept only if the account had such a history.
At every sign-in and every registration the new identity is checked the same way. If it matches a deleted account whose ban is still running, the sign-in is refused. If it matches a deleted account with a moderation history, this is noted in the new account's moderation log so the moderation team knows.
- Categories: check values of the email address, the sign-in provider id and the last sign-in address; country, browser identifier and TLS fingerprint check value of the deleting connection; the moderation history in numbers; the display name only where such a history exists
- Purpose: preventing the evasion of bans and moderation measures by deleting and re-registering
- Legal basis: legitimate interests (Art. 6(1)(f) GDPR); Art. 17(3)(e) GDPR insofar as the record serves the establishment, exercise or defence of legal claims
- Duration: 180 days after the deletion; where a ban was running at the time of deletion, until 30 days after it ends, at most three years. Then deleted automatically by a regular clean-up run.
Our balancing of interests, stated openly
Our interest is protecting players from harassment and protecting the service from automated abuse. Your interests stand against that, and we name the other side of the scale explicitly:
- An IP address can belong to several people. On mobile connections and behind a shared network address (carrier-grade NAT), uninvolved people can be caught by a block.
- German consumer connections change their address regularly. After some time a block may therefore affect a different connection than the one intended.
For those two reasons we have kept the processing as narrow as each purpose allows. For the block list and for the identifier held with your account we do not store the address at all, only an irreversible check value, and we keep no history there, only a single overwritten value. Every block is limited to 30 days from the outset; we do not operate permanent IP blocks.
The one exception is the incident record under item 4. There the address is held in the clear, because a check value is no use for an investigation. We pay for that exception with the shortest retention we set: 7 days. It also does not arise from an ordinary visit, but only when an address has made enough requests to trip a protective limit.
Reach and limits
The comparison against the block list (section 3) happens only when signing in to an existing account; nothing is compared when the site is opened. The comparison against the identifiers of deleted accounts (section 5) happens at sign-in and at registration. If a check fails, access is allowed rather than refused.
No automated decision in individual cases
An entry on the block list is not made automatically, but only on the express instruction of a person on the moderation team. What is automated is merely the enforcement of a decision already taken.
Your rights
The rights described in the section "Rights of data subjects" apply, in particular the right to object under Art. 21 GDPR. If you cannot sign in and suspect a block, please contact the address given in the legal notice.
On access requests under Art. 15 GDPR in detail: for items 1 to 3 we cannot name an IP address, because we store none there, only check values — we can relate an entry to you only if you tell us which connection is affected. For item 4 we can give you the information as long as the record still exists, that is within 7 days. After that it is deleted and we cannot restore it either.
Use of cookies
The term "cookies" covers functions that store information on users' devices and read information from them. We use cookies in accordance with the statutory provisions. Where required, we obtain users' consent in advance.
Storage period
- Temporary cookies (session cookies): deleted at the latest after a user has left the online offering.
- Permanent cookies: remain stored even after the device has been closed (up to 2 years).
Advertising (Google AdSense): For the display of ads, cookies and similar technologies (local storage, identifiers) may be set or read that are not strictly necessary for merely providing the page. We use personalised advertising and certain non-personalised advertising cookies (e.g. frequency capping, reporting, fraud prevention) only subject to consent within the meaning of Art. 6 (1) lit. a GDPR and the ePrivacy requirements, where consent is required. Details can be found in the section "Google AdSense and advertising (Art. 13 GDPR)".
Cookie settings
You can adjust your cookie settings at any time:
https://omequiz.de/cookie-settings
Registration, sign-in and user account
Users can create a user account. During registration users are informed of the required mandatory details, which are processed for the purpose of providing the user account on the basis of performance of contractual obligations.
Types of data processed
- Inventory data (name, contact information, customer number)
- Contact data (e-mail addresses)
- Content data (messages, posts)
- Usage data
- Log data (logins, access data)
Special features
- Registration with pseudonyms possible
- Setting the visibility of profiles
- Two-factor authentication available
- Erasure of data after termination
Linking with darkquiz (optional)
omequiz and the personality test darkquiz (darkquiz.com) are operated by the same provider. In your omequiz settings you can connect your darkquiz account via "link darkquiz". You are redirected to darkquiz and confirm the link there on a consent screen; your "Dark Triad" type (archetype and overall score) is then shown in your omequiz profile.
Important notes
- The connection is made via a secure access token, not via your e-mail address — it therefore also works with different e-mail addresses. No test answers are transferred.
- The link is optional and can be revoked at any time — in your omequiz settings or in your darkquiz account.
- Legal basis: your consent (Art. 6 (1) lit. a GDPR).
Community features
The community features we provide allow users to enter into conversations or otherwise exchange information with one another.
Important notes
- Posts and entries are processed for community purposes
- Storage of the time and IP address for security purposes
- Right to delete content in the event of legal infringements
- Limited deletion of conversation posts in order to preserve the logic of the conversation
- Protecting your own data is the responsibility of users
Voice transmission, reports and moderation (Art. 13 GDPR)
The following information supplements our general notes and fulfils the information obligations under Art. 13 (1) and (2) GDPR for the processing described there.
1) Processing in the context of voice/video communication (lobby, quiz, comparable game rooms)
- Purposes of processing: provision of the real-time communication you have chosen within the quiz/community offering; technical forwarding and synchronisation of the media streams.
- Legal basis: Art. 6 (1) lit. b GDPR (performance of the user agreement for the platform), to the extent that the use of these features forms part of the contract. Where technically necessary security and integrity measures additionally arise (e.g. protection against misuse of the infrastructure), Art. 6 (1) lit. f GDPR may apply; our legitimate interest lies in secure and stable operation of the platform.
- Categories of personal data: voice data (audio), where applicable image data (video), technical connection and metadata (e.g. timestamps, room/game reference, technical session identifiers), user or participant identifiers.
- Categories of recipients: providers of real-time communication infrastructure (processors), hosting/infrastructure service providers, where necessary for operation.
- Storage period / criteria: real-time transmission; no permanent storage of the voice/image streams for this purpose, unless described under points 2 or 3 below.
2) Processing of user reports and in the moderation procedure
- Purposes: handling a specific report; checking for breaches of these terms of use or applicable law; documentation for carrying out measures (e.g. warning, ban); where applicable cooperation with law enforcement or supervisory authorities, where a legal obligation exists.
- Legal bases (depending on the case):
- Art. 6 (1) lit. b GDPR, where processing is necessary to enforce or perform the user agreement (including enforcement of house rules);
- Art. 6 (1) lit. f GDPR: legitimate interest in detecting and preventing abuse, in the integrity of the platform and the protection of affected users, and in defending against legal claims; balancing of interests: your interests in confidentiality are taken into account; processing is limited to what is necessary for the review;
- Art. 6 (1) lit. c GDPR, where we are legally obliged to store or disclose data.
- Categories of personal data: where applicable audio recordings or excerpts (evidence), automatically generated transcripts (text), user IDs of the reporting and the reported user, game/lobby reference, timestamps, report ID, and any further details you provide about the report.
- Categories of recipients: object storage (Cloudflare R2 — see the Cloudflare section above), where applicable a provider of transcription infrastructure (processor), authorised internal bodies (moderation/administration).
- Storage period / criteria (Art. 13 (2) lit. a GDPR): erasure as soon as the data is no longer necessary for handling the specific case, as a rule within 90 days of the moderation case being concluded (conclusion = final decision and implementation of the measure, provided no further review is pending), unless longer retention is required for legal reasons. Longer storage only to the extent necessary and proportionate for the establishment, exercise or defence of legal claims (Art. 17 (3) lit. e GDPR), for compliance with a legal obligation (e.g. an official order, criminal prosecution) or for evidentiary reasons in the case of serious breaches; the duration then follows the respective statutory requirements and the principle of storage limitation (Art. 5 (1) lit. c, e GDPR).
3) Automated checking of chat messages and of camera and screen sharing
- What is checked: Chat messages are automatically checked for insulting and hateful content before delivery. When a camera or screen share is active, individual still frames (not the running stream) are automatically checked for plainly sexual or otherwise prohibited depictions — when the transmission starts, as occasional samples at longer intervals while it runs, and on cause when a report is filed against you.
- Purpose: Protecting other participants, in particular minors, from unwanted confrontation with sexual depictions and from harassment. Purely human supervision of live transmissions is not practically feasible; without automated pre-screening the protection would not be effective.
- Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest lies in protecting users and the integrity of the platform; that interest is also supported by the obligation to act against illegal content (Digital Services Act). Balancing of interests: only individual, low-resolution still frames are analysed, with no continuous recording; frames that are not objected to are not stored but discarded immediately after analysis. The check is clearly signposted before a transmission begins.
- No biometric identification: The classification used categorises image content. It does not serve to uniquely identify a person and creates no biometric templates. Processing of special categories of personal data under Art. 9 GDPR therefore does not take place.
- Retention: Only objected-to still frames are stored, solely for review by moderation, in an area that is not publicly retrievable. Erasure after the moderation case is closed, as described under 2).
4) Automated individual decision-making (Art. 22 GDPR)
If a still frame is classified as plainly prohibited, or if chat messages are blocked repeatedly, your account is provisionally suspended until a member of the moderation team has reviewed the case. This provisional measure is initially taken without individual human review and therefore constitutes an automated decision within the meaning of Art. 22 (1) GDPR. It is necessary in order to stop an ongoing harm to other users immediately.
You expressly have the safeguards under Art. 22 (3) GDPR:
– Human intervention: every provisional suspension is put to a member of the moderation team, who can overturn the decision.
– Expressing your point of view: you can set out your account of events at contact@omequiz.de.
– Contesting the decision: you may object to the decision, and it will then be reviewed again.
Warnings without suspension likewise create a review case for moderation. Automated processing that decides alone and finally on the continued existence of your account does not take place.
5) Statement of reasons for measures (Art. 17 DSA)
If your account is suspended or content is removed, you receive a statement of reasons setting out: the nature and duration of the measure, the underlying facts, whether and to what extent automated means were used, and the redress options available to you, including the possibility of having the decision reviewed.
6) Short-term buffer for audio and video (solely for handling reports)
- What happens: While a transmission is running, a short, continuously self-overwriting buffer is held on our servers — roughly six minutes of audio and two minutes of video. Older sections are deleted as newer ones arrive. No permanent recording is created.
- Purpose: A report is by its nature about something that has already happened. Without this buffer there would be nothing left to examine at the moment a report is filed, and complaints about harassment or sexual depictions would in practice be unverifiable.
- Legal basis: Art. 6 (1) (f) GDPR. Legitimate interest: protecting participants — in particular minors — from sexual depictions and harassment, and the obligation to act against illegal content (Digital Services Act).
- Balancing of interests: the intrusion is limited by several measures which together are decisive:
- No access without cause: the buffer is looked at by nobody. It leaves the server only when a report has been filed.
- Very short retention: anything not reported is irretrievably overwritten within minutes.
- No automated analysis of the buffer: there is no continuous transcription and no continuous content analysis of it.
- Access protection: reported recordings are stored in an area that is not publicly retrievable; playback is only possible through time-limited, signed links for authorised moderators.
- Notice in advance: the check is signposted before a transmission begins, and remains visibly marked while one is running.
- Voluntary: camera, screen sharing and microphone are optional. Anyone who does not switch them on is not affected by this processing — the quiz works entirely without them.
- Retention: the buffer: a few minutes, then overwritten. Where a report is filed: erasure as described under 2), normally within 90 days of the case being closed.
7) Participation times in game rooms
- What is stored: for each participation in a game room, the room identifier, user identifier, time of joining and leaving, and the manner of leaving (left voluntarily, removed, connection lost). No content.
- Purpose: when a report is filed it must be possible to establish who was actually present at the relevant time. Without this, neither the allegation nor an unfounded report can be assessed — and both failures fall on the people involved.
- Legal basis: Art. 6 (1) (f) GDPR; legitimate interest in being able to investigate reports and in protecting people against unfounded accusations.
- Retention: 90 days, then automatic erasure. If an account is deleted, the associated records are deleted with it immediately.
8) Retention for ongoing proceedings
In narrowly defined cases we temporarily suspend the retention periods above for an individual account. This applies only where we are legally required to do so, or where the data is needed for a specific proceeding — for example a court order, a criminal complaint (such as incitement to hatred or threats), an official request for information from an authority, or ongoing civil litigation.
- What is suspended: automatic erasure of moderation data, participation times, chat messages and reported recordings, as well as deletion of the account itself.
- Legal basis: Art. 17 (3) lit. b and lit. e GDPR — the right to erasure does not apply where processing is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims. The data is placed under restriction of processing within the meaning of Art. 18 GDPR: it is stored but not otherwise used — not for running the service, not for analysis, only for the proceeding in question.
- Limits: every suspension is documented with its cause, case reference and a written justification, and carries a review date at which it is reassessed. Once the cause falls away, the ordinary retention periods apply again automatically. Indefinite retention does not take place (Art. 5 (1) lit. e GDPR).
- Your rights: if you request erasure during this period, we will tell you that we cannot currently act on it and inform you of your right to lodge a complaint with a supervisory authority (Art. 12 (4) GDPR). We may not always be permitted to disclose the details of an ongoing proceeding; the body conducting it is responsible for that.
9) When you delete your account
Deleting your account removes your personal data — profile, game history, messages, friendships, and all moderation recordings stored about you, including the associated files.
One exception: if you have reported another person, that report remains with our moderation team — without your name; the link to your account is severed. A report is evidence concerning a third party; it must not disappear simply because the person who filed it deleted their account. Otherwise any complaint could be undone after the fact. For the same reason completed game rounds and moderation decisions are kept as records, in each case without your identifier.
10) Your rights (cross-reference)
Regarding access, rectification, erasure, restriction, data portability, withdrawal of consent given and objection to processing based on Art. 6 (1) lit. f GDPR, we refer to the section "Rights of data subjects" in this privacy policy and to Art. 21 GDPR (objection on grounds relating to your particular situation, where applicable).
11) Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.
Single sign-on
"Single sign-on" refers to procedures that allow users to sign in to our online offering using a user account with a provider (e.g. Google).
Google single sign-on
Authentication services for user sign-in, provision of single sign-on functions.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://www.google.de
Privacy policy: https://policies.google.com/privacy
Basis for third-country transfers: Data Privacy Framework (DPF)
Contact and enquiry management
When you contact us (e.g. via a contact form, e-mail, telephone or social media), the details of the enquiring persons are processed to the extent necessary to answer the contact enquiries.
Types of data processed
- Inventory data (name, contact information)
- Contact data (e-mail, telephone numbers)
- Content data (messages)
- Usage data
- Meta and procedural data
Web analytics, monitoring and optimisation
Web analytics serves to evaluate the visitor flows of our online offering and may cover behaviour, interests or demographic information about visitors.
Google Analytics
We use Google Analytics to measure and analyse the use of our online offering on the basis of a pseudonymous user identification number.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://marketingplatform.google.com/intl/de/about/analytics/
Privacy policy: https://policies.google.com/privacy
Basis for third-country transfers: Data Privacy Framework (DPF)
Important: Google Analytics does not log or store individual IP addresses for EU users. IP masking (pseudonymisation of the IP address) is enabled.
Objection (opt-out)
Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de
Google AdSense and advertising (Art. 13 GDPR)
Current status: no advertising is being delivered yet.
Our participation in Google AdSense is under review; the site has not been approved yet. For as long as that is the case, no advertising script is loaded on this website and no advertising cookies or identifiers are set or read. The information below describes what happens once advertising is actually delivered — we are telling you in advance so that you know beforehand rather than afterwards.
Nothing loads before your decision: Google's advertising script is only loaded in your browser after you have agreed to the "marketing" category. Without your agreement it is not requested at all. In addition, from the outset we signal to Google via Consent Mode v2 that advertising and analytics storage are denied until you decide otherwise.
On our online offering we use Google AdSense, an advertising programme of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). Google displays text, graphical or interactive advertisements; the selection of ads can be contextual (page content) and — if you consent — interest- or usage-based (personalised). The advertising serves to finance the free offering.
Legal classification: Google requires publishers to comply with the EU User Consent Policy (see https://www.google.com/about/company/user-consent-policy.html). Under that policy, a Google-certified consent management platform (CMP) conforming to the IAB Transparency and Consent Framework (TCF) is required for users in the European Economic Area (EEA), the United Kingdom and Switzerland before ads may be delivered. We use Google's own consent message for this; it is configured for our website and will be activated once advertising is delivered. In it you can consent, refuse, or manage options. Our own cookie banner is unaffected and continues to govern analytics and functional purposes; you can change your choice at any time via "Cookie settings".
Purposes of processing: delivery and measurement of advertisements; non-personalisation or personalisation depending on your consent; reports on delivery and effectiveness; fraud and abuse prevention; technical provision of the ad format.
Legal bases: Where consent is required (above all non-essential cookies/storage, personalised advertising, the ad technology providers concerned within the CMP list), the legal basis is Art. 6 (1) lit. a GDPR. Where data processing for non-personalised ads is nevertheless possible without consent to personalisation on the basis of legitimate interests, Art. 6 (1) lit. f GDPR may apply (interest in a financed, secure offering); you have the right to object under Art. 21 GDPR, where applicable.
Categories of personal data (examples): IP address (where applicable truncated/pseudonymised), device and browser information, identifiers (e.g. cookie IDs, advertising IDs), usage and event data in connection with the ad (impressions, clicks), approximate location based on the IP, interests or audience characteristics, where processed for personalised advertising.
Categories of recipients: Google (Ireland and, where applicable, further group companies), advertisers and ad technology providers (ATP), which you can view in the CMP dialogue or in the Google AdSense/advertising settings; mediation networks chosen by Google.
Third-country transfers: processing may also take place in the USA (including Google LLC). We base the transfer on the adequacy decision for the Data Privacy Framework (DPF) and/or standard contractual clauses of the EU Commission as well as, where applicable, additional measures, as described in Google's privacy policy: https://policies.google.com/privacy
Storage period: follows Google's criteria and the technologies used; further information: https://policies.google.com/technologies/ads
Your rights; withdrawal and settings: You can withdraw consent you have given at any time with effect for the future (via cookie settings / CMP). In addition, Google offers settings for personalised ads at https://adssettings.google.com/authenticated (when signed in with a Google account) and general information at https://policies.google.com/technologies/ads
Minimum age: Our offering is aimed at persons aged 16 and over (see terms of use); children below the threshold applicable in your country should not give consent without the approval of a parent or guardian.
Presence on social networks (social media)
We maintain online presences within social networks and process user data in this context in order to communicate with the users active there or to offer information about us.
Platforms used
- Instagram: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
Website: https://www.instagram.com
Privacy policy: https://privacycenter.instagram.com/policy/
- LinkedIn: LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland
Website: https://www.linkedin.com
Privacy policy: https://www.linkedin.com/legal/privacy-policy
- YouTube: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy policy: https://policies.google.com/privacy
All platforms are certified under the Data Privacy Framework (DPF).
Plug-ins and embedded functions and content
We embed functional and content elements into our online offering that are obtained from the servers of their respective providers (third parties).
Google Fonts
Obtaining fonts for the purpose of a technically secure, maintenance-free and efficient use of fonts.
Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Website: https://fonts.google.com/
Privacy policy: https://policies.google.com/privacy
Basis for third-country transfers: Data Privacy Framework (DPF)
Important: IP addresses are neither logged nor stored on Google servers.
Font Awesome
The Font Awesome icons are hosted on our own server; no data is transmitted to third parties.
Changes and updates
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary.
We will inform you as soon as the changes require an action on your part (e.g. consent) or another individual notification.
Definitions
This section provides an overview of the terminology used in this privacy policy.
Personal data
Any information relating to an identified or identifiable natural person.
Processing
Any operation performed on personal data, with or without automated means (collection, analysis, storage, transmission, erasure).
Controller
The natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Erstellt mit Datenschutz-Generator.de von Dr. Thomas Schwenke