Last updated: 6 September 2026
The German version of this text is legally binding. Translations are provided for convenience only.
Privacy Policy
Preamble
In the following privacy policy, we aim to explain what types of your personal data (hereinafter also referred to as “data”) we process, for what purposes and to what extent. This Privacy Policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).
The terms used are not gender-specific.
Last updated: 6 September 2026
Table of contents
Data Controller
Puzzleverein Deutschland e.V.
Mirabellenbaumweg 8
71287 Weissach
Germany
Authorised representatives: Michael Smit
Email address: vorstand@puzzleverein.de
Contact details for the Data Protection Officer
datenschutz@puzzleverein.de
Overview of processing activities
The following overview summarises the types of data processed and the purposes of such processing, and refers to the data subjects.
Types of data processed
- Master data.
- Employee data.
- Payment data.
- Contact details.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
- Membership data.
Categories of data subjects
- Service recipients and clients.
- Employees.
- Prospective clients.
- Communication partners.
- Users.
- Members.
- Business and contractual partners.
- Third parties.
- Whistleblowers.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Office and organisational procedures.
- Organisational and administrative procedures.
- Feedback.
- Registration procedures.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Whistleblower protection.
- Business processes and operational procedures.
Relevant legal bases
Relevant legal bases under the GDPR: Below is an overview of the legal bases under the GDPR on which we process personal data. Please note that, in addition to the provisions of the GDPR, national data protection regulations may apply in your country or ours, depending on where you or we are resident or have our registered office. Should more specific legal bases apply in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6(1), first sentence, point (a) of the GDPR) – The data subject has given their consent to the processing of their personal data for a specific purpose or for several specific purposes.
- Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party, or for the implementation of pre-contractual measures taken at the data subject’s request.
- Legal obligation (Art. 6(1), first sentence, point (c) of the GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights and freedoms of the data subject which require the protection of personal data do not override those interests.
- Membership contract (Articles of Association) (Article 6(1), first sentence, point (b) of the GDPR).
National data protection regulations in Germany: In addition to the data protection provisions of the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG). In particular, the BDSG contains specific provisions on the right of access, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and the transfer of data, as well as automated decision-making in individual cases, including profiling. Furthermore, data protection laws of the individual federal states may apply.
Note on the applicability of the GDPR and the Swiss Data Protection Act (DSG): This privacy notice serves to provide information in accordance with both the Swiss Data Protection Act (DSG) and the General Data Protection Regulation (GDPR). For this reason, you to note that, due to the broader geographical scope and clarity of the GDPR, the terms used in the GDPR are employed. In particular, instead of the terms used in the Swiss Data Protection Act (DSG) such as ‘processing’ of ‘personal data’, ‘‘overriding interest’ and ‘personal data requiring special protection’, the terms used in the GDPR ‘processing’ of ‘personal data’, as well as ‘legitimate interest’ and ‘special categories of data’. However, the legal meaning of these terms continues to be determined in accordance with the Swiss Data Protection Act (DSG) within the scope of its application.
Security measures
In accordance with statutory requirements, and taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the varying likelihood and severity of threats to the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
These measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data, as well as access relating to it, input, disclosure, ensuring availability and segregation. Furthermore, we have established procedures to ensure that data subjects’ rights are upheld, that data is erased and that responses are made in the event of a data breach. We also take the protection of personal data into account right from the development or selection of hardware, software and procedures in accordance with the principle of data protection by design, through technical design and data protection-friendly default settings.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect users’ data transmitted via our online services from unauthorised access, we utilise TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user’s browser (or between two servers), thereby protecting the data from unauthorised access. TLS, as the more advanced and secure version of SSL, ensures that all data transfers meet the highest security standards. When a website is secured by an SSL/TLS certificate, this is indicated by the display of ‘HTTPS’ in the URL. This serves as an indicator to users that their data is being transmitted securely and in encrypted form.
General information on data storage and erasure
We erase personal data that we process, in accordance with statutory provisions as soon as the underlying consents are withdrawn or there are no longer any legal grounds for processing. This applies to cases where the original purpose of processing no longer applies or the data is no longer required. Exceptions to this rule apply where statutory obligations or specific interests require the retention or archiving of the data.
In particular, data which must be retained for commercial or tax law reasons, or where storage is necessary for the purposes of legal proceedings or to protect the rights of other natural or legal persons, must be archived accordingly.
Our privacy policy contains additional information on the retention and erasure of data, which applies specifically to certain processing operations.
Where there are multiple specifications regarding the retention period or deletion deadlines for a particular piece of data, the longest period shall always apply. Data which are no longer retained for the purpose originally intended, but rather due to legal requirements or other reasons, shall be processed by us exclusively for the purposes justifying their retention.
Retention and deletion of data: The following general time limits apply to the retention and archiving under German law:
- 10 years – Retention period for books and records, annual accounts, inventories, management reports, opening balance sheets, as well as the working instructions and other organisational documents necessary for their understanding (Section 147(1) No. 1 in conjunction with (3) of the German Fiscal Code (AO), Section 257(1)(1) in conjunction with (4) of the German Commercial Code (HGB)).
- 8 years – accounting documents, such as invoices and expense receipts (Section 147(1)(4) and (4a) in conjunction with para. 3, sentence 1 of the German Fiscal Code (AO), Section 14b(1) of the German Value Added Tax Act (UStG) and Section 257(1)(4) in conjunction with para. 4 of the German Commercial Code (HGB)).
- 6 years – Other business documents: incoming commercial or business correspondence, copies of outgoing commercial or business correspondence, other documents in so far as they are relevant for tax purposes, e.g. hourly wage slips, operational accounting sheets, costing documents, price labels, as well as payroll records, in so far as they are not already accounting vouchers, and cash register receipts (Section 147(1)(2), (3) and (5) in conjunction with paragraph 3 of the German Fiscal Code (AO), Section 257(1)(2) and (3) in conjunction with paragraph 4 of the German Commercial Code (HGB)).
- 3 years – data required to take into account potential warranty and compensation claims or similar contractual claims and rights, and to process related enquiries, based on previous business experience and standard industry practices, shall be stored for the duration the standard statutory limitation period of three years (§§ 195, 199 BGB).
Commencement of the limitation period at the end of the year: If a limitation period does not expressly commence on a specific date and is at least one year in duration, it automatically commences at the end of the calendar year in which the event triggering the limitation period occurred. In the case of ongoing contractual relationships within the framework of which data is stored, the event triggering the limitation period is the date on which the notice of termination or other termination of the legal relationship takes effect.
Rights of data subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Articles 15 to 21 of the GDPR:
- Right to object: You have the right, on grounds relating to your particular situation, to object at any time to the processing of your personal data carried out on the basis of Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions. If personal data concerning you is processed for the purposes of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing; this also applies to profiling insofar as it is related to such direct marketing.
- Right to withdraw consent: You have the right to withdraw any consent you have given at any time.
- Right of access: You have the right to request confirmation as to whether your personal data is being processed, and to obtain access to this data, as well as further information and a copy of the data in accordance with the statutory provisions.
- Right to rectification: In accordance with the statutory provisions, you have the right to request that data concerning you be completed or that any inaccurate data concerning you be rectified.
- Right to erasure and restriction of processing: In accordance with the statutory provisions, you have the right to request that data concerning you be erased without delay or, alternatively, in accordance with the statutory provisions, to request a restriction on the processing of the data.
- Right to data portability: You have the right, in accordance with the statutory provisions, to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to request that it be transferred to another data controller.
- Complaint to a supervisory authority: Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place where the alleged infringement occurred, if you consider that the processing of your personal data infringes the provisions of the GDPR.
Use of cookies
Our website uses a single cookie: the web server’s session cookie (PHPSESSID). It is technically necessary to enable login, language selection, time zone selection and the protection of forms against tampering across multiple page views. It contains only a random identifier, is not used for recognition beyond the session and is deleted when the browser is closed.
We do not use cookies for analytical, marketing or tracking purposes, nor do we store any data permanently in the browser. In accordance with Section 25(2)(2) of the TDDDG, no consent is required for the session cookie; therefore, we do not display a cookie notice.
We only load embedded third-party videos (see the section ‘Plug-ins, embedded functions and content’) once you have given your consent by clicking. We only retain this choice for the current browser session.
- Types of data processed: Meta, communication and procedural data (e.g. session ID, time stamps).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; security measures.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Section 25(2)(2) of the TDDDG.
Performance of tasks in accordance with the Articles of Association or Rules of Procedure
We process the data of our members, supporters, prospective members, business partners or other individuals (collectively ‘data subjects’) where we have a membership or other business relationship with them and are performing our duties, or where they are recipients of services and grants. Furthermore, we process data subjects’ data on the basis of our legitimate interests, e.g. in the case of administrative tasks or public relations work.
The data processed in this context, as well as the nature, scope, purpose and necessity of its processing, are determined by the underlying membership or contractual relationship, from which the necessity of providing any data also arises (we will otherwise indicate which data is required).
We delete data that is no longer required for the fulfilment of our statutory and business purposes. This is determined in accordance with the respective tasks and contractual relationships. We retain data for as long as it may be relevant to the conduct of business, as well as with regard to any warranty or liability obligations, based on our legitimate interest in regulating these matters. The necessity of retaining the data is reviewed on a regular basis; otherwise, the statutory retention obligations apply.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter of the contract, term, customer category); membership data (e.g. personal data such as name, age, gender, contact details (email address, telephone number), membership number, information on membership fees, participation in events, etc.). Payment data (e.g. bank details, invoices, payment history).
- Data subjects: Members.
- Purposes of processing and legitimate interests: Communication. Organisational and administrative procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR). Membership agreement (Articles of Association) (Article 6(1), first sentence, point (b) of the GDPR).
Further information on processing activities, procedures and services:
- Events and organisational operations: Planning, organisation and follow-up of events, as well as the general operation of activities in accordance with the Articles of Association. Planning involves the collection and processing of participant data, coordination of logistical requirements and setting the event agenda. The implementation comprises the management of participant registration, the updating of participant information during the event, and the recording of attendance and participant activities. Follow-up work involves analysing participant data to evaluate the success of the event, producing reports and archiving relevant information relating to the event. General organisational operations include the administration of member data, communication with members and prospective members, and the organisation of internal meetings and sessions; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR), membership agreement (Articles of Association) (Art. 6(1), first sentence, point (b) of the GDPR).
Business services
We process the personal data of our contractual and business partners, such as customers, clients, prospective clients, suppliers and other cooperation partners (collectively ‘contractual partners’), for the purpose of establishing, implementing and fulfilling contractual relationships and comparable legal relationships. This also includes pre-contractual measures carried out upon request, as well as communication in connection with the respective contractual relationship.
The processing serves, in particular, to fulfil our principal and ancillary contractual obligations. These include the provision of the agreed services, any obligations to provide updates and information, the handling of warranty claims and other service disruptions, the handling of withdrawals, terminations of continuing contractual relationships, reversals, refunds, and the processing of other contract-related declarations and enquiries. This covers both one-off contracts and ongoing contractual relationships.
In particular, we process master data such as name, address and, where applicable, company name; contact details such as email address and telephone number; and contract and service data such as the subject matter of the contract, contract term, orderor transaction numbers, usage and service data, payment and billing data, as well as communication content and histories. Where necessary, we also process data disclosed or transmitted to us in the course of carrying out an order.
Furthermore, we process the data to safeguard our rights and to fulfil legal obligations. This includes, in particular, retention obligations under commercial and tax law, documentation obligations and, where applicable, obligations to provide evidence and account for our actions. Furthermore, processing takes place on the basis of our legitimate interests in proper business management, internal administration, risk management and IT security, as well as in protecting our business operations and our contractual partners from misuse and threats to data, confidential information and other legal interests. This may also involve the use of external service providers such as IT and telecommunications providers, transport and logistics companies, payment service providers, banks, tax and legal advisers or other agents, insofar as this is necessary for the performance of the contract or to fulfil legal obligations.
Personal data will only be disclosed to third parties to the extent that this is necessary for the performance of the contract, for the implementation of pre-contractual measures, to safeguard legitimate interests or to fulfil legal obligations. We provide separate information regarding any further processing, in particular for marketing purposes, within the scope of this privacy policy.
We inform our contractual partners of the data required in each individual case at the time of data collection, for example by means of appropriate labelling on online forms or through personal contact.
Data will be deleted as soon as it is no longer required for the aforementioned purposes and provided there are no statutory retention obligations to the contrary. Statutory retention periods, in particular under commercial and tax law, may require data to be retained for a longer period. We will delete data transmitted in connection with a specific order once the order has been completed and any retention periods have expired, provided there are no further statutory or contractual obligations to retain the data.
The legal basis for the processing is Article 6(1)(b) of the GDPR for the implementation of pre-contractual measures and the fulfilment of the respective contractual relationship, as well as Article 6(1)(c) of the GDPR for the fulfilment of legal obligations. Where processing is based on legitimate interests, it is carried out on the basis of Article 6(1)(f) of the GDPR. Where processing is based on Article 6(1)(f) of the GDPR, it is carried out to safeguard our legitimate interests in the proper and efficient organisation of our business, internal administration and documentation of business transactions, the enforcement and defence of legal claims, ensuring IT and data security, the prevention of misuse and fraud, and the economic management and further development of our business operations. These interests consist, in particular, of ensuring secure and legally compliantbusiness operations, as well as in safeguarding our ability to act as a business.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contact details (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category).
- Data subjects: Service recipients and clients; prospective clients; business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures; organisational and administrative procedures. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6( 1, sentence 1, point (b) of the GDPR); legal obligation (Art. 6(1), sentence 1, point (c) of the GDPR). Legitimate interests (Art. 6(1), sentence 1, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Event management: We process the data of participants in the events, functions and similar activities that we offer or organise (hereinafter collectively referred to as “participants” and ‘events’) in order to enable them to take part in the events and make use of the services or activities associated with their participation.
Where, in this context, we process health-related data, religious, political or other special categories of data, this is done where it is obvious (e.g. in the case of thematically focused events, or where it serves the purposes of healthcare, safety, or is carried out with the consent of the data subjects).
The necessary details are identified as such within the context of the conclusion of a contract, orderor similar contract and comprise the details required for the provision of services and invoicing, as well as contact information to enable any necessary consultations. Where we have access to information relating to end customers, employees or other individuals, we process this in accordance with statutory and contractual requirements; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
Payment procedures
Within the framework of contractual and other legal relationships, on the basis of legal obligations or otherwise on the basis of our legitimate interests, we offer data subjects efficient and secure payment options and, for this purpose, engage further service providers in addition to banks and credit institutions (collectively ‘payment service providers’). Payment transactions are carried out exclusively via encrypted connections in accordance with the state of the art, ensuring that the data entered is protected against unauthorised access during transmission.
The data processed by the payment service providers includes master data, such as name and address; bank details, such as account numbers or credit card numbers, passwords, TANs and checksums, as well as details relating to the contract, the amount and the recipient. This information is required to carry out the transactions. However, the data entered is processed and stored solely by the payment service providers. This means that we do not receive any account- or credit card-related information, but only information confirming the payment or indicating that it has been declined. In certain circumstances, the data may be transmitted by the payment service providers to credit reference agencies . The purpose of this transfer is to verify identity and creditworthiness. In this regard, we refer you to the terms and conditions and privacy policies of the payment service providers.
Payment transactions are governed by the terms and conditions and privacy policies of the respective payment service providers, which are available on their respective websites or within the transaction applications. We also refer you to these for further information and for the exercise of your rights of withdrawal, access and other data subject rights.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); payment data (e.g. bank details, invoices, payment history); contract data (e.g. subject matter of the contract, term, customer category); usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Service recipients and clients. Business and contractual partners.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations. Business processes and operational procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Mollie: Payment services for the online payment of registration fees. The payment is processed on Mollie’s website; we only receive the payment status, amount and a transaction ID. The payee is the respective organiserof the event, who uses their own Mollie account under their own responsibility; Service provider: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands; Legal basis: performance of a contract and pre-contractual enquiries (Art. 6(1)(b) GDPR); Website: https://www.mollie.com/de; Privacy policy: https://www.mollie.com/de/privacy.
- Bank transfers and refunds: When payment is made by bank transfer, the organiser receives the payer’s name and account details via their bank statement and records receipt of payment on the platform. For refunds, we record the IBAN and the account holder; this information is not used for any further purpose once the refund has been processed and is otherwise subject to the organiser’s tax-related retention periods; Legal bases: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
Provision of the online service and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved). Log data (e.g. log files relating to logins, data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)). Security measures.
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Provision of online services on leased storage space: To provide our online services, we use storage space, computing capacity and software, which we rent or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Collection of access data and log files: Access to our online service is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the webpages and files accessed, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, where applicable, theIPaddresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, so-called DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability ; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is subsequently deleted or anonymised. Data that must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
- ALL-INKL: Services relating to the provision of information technology infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: ALL-INKL.COM – Neue Medien Münnich, Owner: René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://all-inkl.com/; Privacy policy: https://all-inkl.com/datenschutzinformationen/. Data Processing Agreement: Provided by the service provider.
Registration, login and user account
Users may create a user account. As part of the registration process, users are informed of the required mandatory details, which are processed for the purpose of providing the user account on the basis of contractual obligations. The data processed includes, in particular, login details (username, password and an email address).
When you use our registration and login functions, as well as when you use your user account, we store your IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as those of the users, in protection against misuse and other unauthorised use. As a general rule, this data is not disclosed to third parties, unless it is necessary to pursue our claims or there is a legal obligation to do so.
Users may be informed by email about matters relevant to their user account, such as technical changes.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Log data (e.g. log files relating to logins, data retrieval or access times)..
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; organisational and administrative procedures. Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’. Erasure following termination.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Deletion of data following termination: Once users have terminated their user account, their data relating to that account will be deleted, subject to any statutory authorisation, obligation or the user’s consent; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
- No obligation to retain data: It is the users’ responsibility to back up their data prior to the end of the contract in the event of termination. We are entitled to irrevocably delete all of the user’s data stored during the term of the contract; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
- Information provided upon registration: First name, surname, date of birth, nationality, email address, language and password (stored only as a hash). We require the date of birth and nationality for age and country classifications in competitions. Optionally, a different display name; Legal basis: Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
- Protection against misuse of the login: We store login and password reset attempts, along with themail address, IP address and timestamp for seven days to prevent repeated failed attempts. In the server’s error logs, the IP address is recorded only in truncated form; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Email notifications: We send confirmations, password links, invitations and notifications regarding your registrations are sent by email via the platform’s mail server or that of the relevant organiser. Sent messages remain in our outbound queue for 30 days; failed messages remain there for 90 days. We do not send out promotional newsletters; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR).
Events: Registration, participation and results
On this platform, organisers (clubs, federations, companies and individuals) advertise their events. The respective organiser is the data controller within the meaning of the GDPR for the data collected during registration for an event; they are named on the event page. We operate the platform on their behalf as a data processor (Article 28 of the GDPR). For events organised by Puzzleverein Deutschland e.V. itself, we are also the data controller.
When registering for a competition, we collect the team name, first name and surname, date of birth and nationality of the participants, as well as an optional comment. This information is required for the running of the competition, the allocation to age and country categories, and the processing of payments.
Publication of start lists and results: The names and nationalities of participants, as well as their times and placings, are published in start lists, on displays during the event and in results lists. This forms part of taking part in a sporting competition. The organiser may restrict the publication of rankings to registered users.
Information on accessibility: If the organiser offers support for people with disabilities, participants may voluntarily specify what support they require. This information constitutes health data (Art. 9 GDPR). We process it only with your explicit consent, solely for the preparing support on site, and will only be passed on to the organiser. It is only required until the end of the event and will be automatically deleted 30 days afterwards. Consent may be withdrawn at any time with future effect.
Invitations and team search: Organisers can create registrations in advance and invite participants by email with a confirmation link. Via the team search function, registered users can look for teammates and send each other messages; their display name and nationality are visible.
Member synchronisation: Organisers can upload their own list of members (name, email address, date of birth, nationality) to the platform so that members can benefit from reduced fees. Existing user accounts are matched or new accounts are created; those concerned are informed of this by email. The organiser is responsible for this transfer.
Images, videos and live streaming: Organisers can publish photo galleries and live text updates for the event. Photographs and videos are taken at events; the organiser sets out the rules for this in their terms and conditions. Anyone wishing to have an image removed should contact the organiser or us.
Organiser API: Organisers can use an application programming interface (API) with a personal key retrieve data relating to their own events and members, and carry out member verification. Data belonging to other organisers is not accessible via this interface.
- Types of data processed: Master data (e.g. name, date of birth, nationality); contact details (email address); contractual data (registrations, payment status); content data (comments, messages, images); health data (only where provided voluntarily for accessibility purposes); meta, communication and procedural data.
- Data subjects: Users; participants; members; volunteers and staff of the organisers.
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; organisational and administrative procedures; communication; publication of competition results.
- Retention and deletion: Registration data is retained for the duration of the event and the subsequent billing process; results are retained as part of the competition history. In all other respects, the section ‘General information on data storage and deletion’ applies.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); consent (Article 6(1), first sentence, point (a) and Article 9(2), point (a) of the GDPR) for information on accessibility.
Single Sign-On login
The terms ‘single sign-on’, ‘single sign-on login’ or ‘single sign-on authentication’ refer to procedures that allow users to log in to our online service using a user account held with a single sign-on provider (e.g. a social network) – including on our online service – using a single user account. A prerequisite for single sign-on authentication is that users are registered with the relevant single sign-on provider and enter the required login details in the online form provided for this purpose, or are already logged in with the single signand confirm the single sign-on login via the button.
Authentication takes place directly with the relevant single signprovider. As part of this authentication process, we receive a user ID indicating that the user is logged in to the relevant single sign-on provider under this user ID, along with an ID (known as a ‘user handle’) that cannot be used by us for any other purposes. Whether additional data is transmitted to us depends solely on the single sign-on procedure used, the data sharing options selected during authentication, and also on what data users have made available in the privacy or other settings of their user account with the single-on provider. Depending on the single sign-on provider and the user’s choices, this may involve various pieces of data; typically, these are the email address and the username. The password entered as part of the single sign-on process with the single sign-on provider is neither visible to us nor stored by us.
Users are asked to note that the details we hold about them may be automatically synchronised with their user account with the single sign-on provider; however, this is not always possible or does not always actually take place. If, for example, a user’s email address changes, they must update it manually in their user account with us.
We may use single sign-on authentication, provided this has been agreed with users, either as part of or prior to the performance of the contract, insofar as users have been asked to give their consent; otherwise, we use it on the basis of our legitimate interests and the users’ interests in an effective and secure login system.
Should users ever decide that they no longer wish to use the link between their user account and the single sign-on provider for the single sign-on process, they must remove this link within their user account with the singleprovider. If users wish to have their data deleted by us, they must cancel their registration with us.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of contractual services and fulfilment of contractual obligations; security measures; registration procedures. Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’. Erasure following termination.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR). Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing procedures, procedures and services:
- Login via Puzzleverein: Login using the Puzzleverein Deutschland e.V. member account via the OpenID Connect procedure. The login service is operated by the association itself at puzzleverein.de; no third party is involved. We receive a user ID, the email address and the name, and link these to the user account on this platform following confirmation; Service provider: Puzzleverein Deutschland e.V., Mirabellenbaumweg 8, 71287 Weissach, Germany; Legal basis: performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR); Website: https://puzzleverein.de.
Contact and enquiry management
When you contact us (e.g. by post, contact form, email, telephone or via social media), as well as within the context of existing user and business relationships, the details of the enquirers are processed to the extent necessary to respond to contact enquiries and any requested actions.
- Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing and legitimate interests: Communication; organisational and administrative procedures; Feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Art. 6( 1(1)(f) of the GDPR). Performance of a contract and pre-contractual enquiries (Art. 6(1)(1)(b) of the GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data provided to us in order to respond to and deal with your enquiry. This generally includes details such as your name, contact details and, where applicable, further informationthat is provided to us and is necessary for appropriate processing. We use this data exclusively for the stated purpose of establishing contact and communication; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR), legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Translation of content
Our online platform is multilingual. We have labels, country names and content texts entered by organisers (e.g. event descriptions, notices, questions and answers, invitation texts) automatically machine-translated. To this end, these texts are transmitted to the translation service. Data relating to participants, messages and emails are not translated; however, content texts may contain the names of contact persons entered by the organiser themselves.
- Types of data processed: Content data (e.g. texts provided by organisers).
- Data subjects: Organisers and the contact persons they have specified.
- Purposes of processing and legitimate interests: Provision of our online service in multiple languages.
- Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- DeepL: Machine translation. We use the paid interface (DeepL API Pro), whereby submitted texts are not stored after translation and are not used for training purposes; Service provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.deepl.com; Privacy policy: https://www.deepl.com/de/privacy; Data Processing Agreement: Provided by the service provider.
Plug-ins, embedded functions and content
We incorporate functional and content elements into our online offering which are sourced from the servers of their respective providers (hereinafter referred to as ‘third-party providers’). These may include, for example, graphics, videos or city maps (hereinafter collectively referred to as ‘content’ ).
This integration always requires the third-party providers of this content to process users’ IP addresses, as they would be unable to send the content to users’ browsers without an IP address. The IP address is therefore necessary for the display of this content or these functions. We endeavour to use only such content where the respective providers use the IP address solely for the purpose of delivering the content. Third-party providers may also use so-called pixel tags (invisible images, also known as ‘web beacons’) for statistical or marketing purposes. Through these ‘pixeltags’ can be used to analyse information such as visitor traffic on the pages of this website. The pseudonymous information may also be stored in cookies on the user’s device and may include, amongst other things, technical details about the browser and operating system, referring websites, the time of the visit and further details regarding the use of our online service, but may also be linked to such information from other sources.
Information on legal bases: Where we ask users for their consent to the use of third-party providers, the legal basis for data processing is that consent. Otherwise, user data is processed on the basis of our legitimate interests (i.e. an interest in providing efficient, cost-effective and user-friendly services). In this context, we would also like to draw your attention to the information on the use of cookies in this privacy policy.
- Types of data processed: Usage data (e.g. page views and time spent on site, click paths, usage intensity and frequency of use, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, timestamps, identification numbers, individuals involved).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing and legitimate interests: Provision of our online services and user-friendliness; audience measurement (e.g. access statistics, identification of returning visitors); tracking (e.g. interest-based/behavioural profiling, use of cookies); target group segmentation. Marketing.
- Retention and deletion: Deletion in accordance with the information provided in the section “General Information on Data Storage and Deletion’. Cookies may be stored for up to 2 years (unless otherwise stated, cookies and similar storage methods may be stored on users’ devices for a period of two years).
- Legal bases: Consent (Art. 6(1), first sentence, point (a) of the GDPR). Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- OpenStreetMap: Map display of the event venue. The map tiles are loaded from the OpenStreetMap Foundation’s servers when the event page is accessed; your IP address is transmitted in the process. No cookies are set and no user profiles are created; Service provider: OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.openstreetmap.org; Privacy policy: https://osmfoundation.org/wiki/Privacy_Policy; Legal basis for transfers to third countries: Adequacy decision by the European Commission regarding the United Kingdom.
- Nominatim (address search): Only in the organisers’ editing area: When entering an event venue, the address entered is sent to the OpenStreetMap Foundation’s geocoding service to determine the coordinates for the map; Service providers and legal bases: such as OpenStreetMap.
- YouTube videos: Video content. The videos are only loaded once you have given your consent by clicking on the placeholder (two-click solution); until then, no data is transferred to YouTube. We embed the videos in enhanced privacy mode (youtube-nocookie.com); Service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Legal basis: Consent (Art. 6(1)(a) GDPR); Website: https://www.youtube.com; Privacy policy: https://business.safety.google/privacy/; Legal basis for transfers to third countries: Data Privacy Framework (DPF). Right to object (opt-out): Opt-out plugin: https://tools.google.com/dlpage/gaoptout?hl=de, Settings for the display of adverts: https://myadcenter.google.com/personalizationoff.
Amendments and updates
We ask that you regularly review the content of our privacy policy. We will amend the privacy policy as soon as changes to our data processing activities make this necessary. We will inform you as soon as the changes require any action on your part (e.g. consent) or any otherindividual notification.
Where we provide addresses and contact details of companies and organisations in this privacy policy, please note that these details may change over time; we therefore ask you to check the information before making contact.
Definitions of terms
This section provides an overview of the terms used in this privacy policy. Where the terms are defined by law, their statutory definitions apply. The explanations below, however, are primarily intended to aid understanding.
- Employees: Employees are defined as persons who are in an employment relationship, whether as staff members, employees or in similar positions. An employment relationship is a legal relationship between an employer and an employee, established by an employment contract or agreement. It includes the employer’s obligation to pay the employee remuneration whilst the employee performs their work. The employment relationship comprises various phases, including the commencement phase, during which the employment contract is concluded; the performance phase, during which the employee carries out their work; and the termination phase, when the employment relationship ends, whether through dismissal,a settlement agreement or otherwise. Employee data refers to all information relating to these individuals and arising in the context of their employment. This includes aspects such as personal identification details, identification numbers, salary and bank details, working hours, holiday entitlements, health data and performance appraisals.
- Master data: Master data comprises essential information required for the identification and management of contractual partners, user accounts, profiles and similar assignments. This data may include, amongst other things, personal and demographic details such as names, contact details (addresses, telephone numbers, email addresses), dates of birth and specific identifiers (user IDs). Master data forms the basis for any formal interaction between individuals and services, organisations or systems by enabling unique identification and communication.
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds. This category of data may include text, images, videos, audio files and other multimedia content published on various platforms and media. Content data is not limited to the actual content itself, but also includes metadata that provides information about the content, such as tags, descriptions, author details and publication dates
- Contact data: Contact details are essential information that enables communication with individuals or organisations. They include, amongst other things, telephone numbers, postal addresses and email addresses, as well as communication channels such as social media handles and instant messaging identifiers.
- Meta-, communication and process data: Meta-, communication and process data are categories that contain information about the way in which data is processed, transmitted and managed. Meta-data, also known as ‘data about data’, comprises information that describes the context, origin and structure of other data. It may include details on file size, creation date, the author of a document and revision histories. Communication data records the exchange of information between users via various channels, such as email correspondence, call logs, social media messages and chat histories, including the individuals involved, timestamps and transmission routes. Procedural data describes the processes and workflows within systems or organisations, including workflow documentation, transaction and activity logs, and audit logs used to track and verify operations.
- Member data: Member data comprises information relating to individuals who are part of an organisation, an association, an online service or any other group. This data is used to manage memberships, facilitate communication and provide services or benefits associated with membership. Member data may include personal identification information, contact details, information on membership status and duration, membership fee payments, participation in events and activities, as well as preferences and interests. It may also include data on the use of services offered by the organisation. The collection and processing of this data is carried out in compliance with data protection regulations and serves both administrative purposes and to promote member engagement and satisfaction.
- Usage data: Usage data refers to information that records how users interact with digital products, services or platforms. This data encompasses a wide range of information that reveals how users utilise applications, which features they prefer, how long they remain on specific pages and the paths they take when navigating through an application. Usage data may also include frequency of use, timestamps of activities, IP addresses, device information and location data. It is particularly valuable for analysing user behaviour, optimising user experiences, personalising content and improving products or services. Furthermore, usage data plays a crucial role in identifying trends, preferences and potential problem areas within digital offerings
- Personal data: “Personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier (e.g. a cookie) or one or more specific characteristics that express the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Log data: Log data is information about events or activities that have been logged in a system or network. This data typically contains information such as timestamps, IP addresses, user actions, error messages and other details regarding the use or operation of a system. Log data is often used to analyse system problems, for security monitoring or to generate performance reports.
- Audience measurement: Audience measurement (also known as web analytics) is used to analyse visitor traffic to an online service and may include the behaviour or interests of visitors in relation to specific information, such as website content. With the help of web analytics, operators of online services can, for example, identify at what times users visit their websites and what content they are interested in. This enables them to, for , for example, better tailor the content of their websites to the needs of their visitors. For the purposes of reach analysis, pseudonymous cookies and web beacons are frequently used to recognise returning visitors and thus obtain more accurate analyses of the use of an online service.
- Tracking: The term ‘tracking’’ refers to the ability to track users’ behaviour across multiple online services. As a rule, information relating to behaviour and interests in connection with the online services used is stored in cookies or on the servers of the providers of tracking technologies (so-called profiling). This information can subsequently be used, for example, to display advertisements to users that are likely to match their interests.
- Data controller: The term “controller” refers to the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: “Processing” means any operation or set of operations which is carried out on personal data, whether or not by automated means. The term is broad and encompasses virtually every interaction with data, be it collection, analysis, storage, transmission or erasure.
- Contractual data: Contractual data is specific information relating to the formalisation of an agreement between two or more parties. It documents the terms under which services or products are provided, exchanged or sold. This data category is essential for the administration and fulfilment of contractual obligations and encompasses both the identification of the contracting parties and the specific terms and condiof the agreement. Contract data may include the start and end dates of the contract, the nature of the agreed services or products, pricing arrangements, payment terms, termination rights, renewal options and special conditions or clauses. They serve as the legal basis for the relationship between the parties and are crucial for clarifying rights and obligations, enforcing claims and resolving disputes.
- Payment data: Payment data comprises all information required to process payment transactions between buyers and sellers. This data is of crucial importance for e-commerce, online banking and any other form of financial transaction. It includes details such as credit card numbers, bank account details, payment amounts, transaction details, verification numbers and billing information. Payment data may also include information on payment status, chargebacks, authorisations and fees.
- Target audience creation: The term ‘Custom Audiences’ refers to the process of defining target audiences for advertising purposes, e.g. displaying adverts. For example, based on a user’s interest in specific products or topics online, it can be inferred that this user would be interested in adverts for similar products or the online shop in which they viewed the products. The term “Lookalike Audiences” (or similar target groups), on the other hand, refers to situations where content deemed suitable is displayed to users whose profiles or interests are presumed to correspond to those of the users on whose profiles the audience was originally based. Cookies and web beacons are generally used for the purpose of creating Custom Audiences and Lookalike Audiences.
Created using the free Datenschutz-Generator.de by Dr Thomas Schwenke