Privacy Policy
This page explains which personal data the portal processes, why, and which rights members have. The English version is the only binding version.
1. Controller
The operator named in the imprint is the controller for the processing described here. Questions about data protection go to the address given there.
2. Data processed
- Account data: user name, email address, password hash, date of birth, gender, country, language, time zone, avatar, optional photo.
- Usage data: quizzes and tournaments taken, answers given, times measured, rewards granted.
- Payment data: payments for premium, payout requests, payout details, invoice data.
- Identity data: for the identity check the documents and details described on the money laundering page.
- Technical data: sign in records with IP address and browser identification, security events, error logs.
- Communication: messages sent through the internal message system, reports about questions.
3. Purposes and legal bases
- Performance of the contract: account, participation, rewards, payouts, premium.
- Legal obligation: identity verification, records for tax and anti money laundering purposes, invoices.
- Legitimate interest: security of the portal, prevention of misuse and automated participation, technical error analysis.
- Consent: optional cookies and, where applicable, newsletters. Consent may be withdrawn at any time with effect for the future.
4. Recipients
Data is passed on only where necessary:
- payment providers for the processing of premium payments
- banks and payment services for payouts
- the hosting provider that operates the servers
- the mail provider for transactional email
Providers act as processors and are bound by contract.
- advertising networks whose adverts are shown on the free way; they receive the data their code collects in the browser and set their own cookies. This happens only after agreement in the cookie notice, and never for premium members.
5. Storage periods
- Account data: for the duration of the account and afterwards as long as statutory retention periods require.
- Ledger entries, invoices and identity records: for the statutory retention period, usually up to ten years.
- Sign in records and security events: normally twelve months.
- Identity documents: deleted once the retention period ends.
6. Public visibility
User name and avatar are visible to other members in rankings and results. Age, gender and country are shown only if the member has not hidden them in the profile. Hiding a detail also removes the member from the ranking that is built on that detail. Email address, date of birth and payment details are never public.
7. Rights
Members may request access, rectification, erasure, restriction of processing, data portability and may object to processing based on a legitimate interest. Requests go to the address in the imprint. Members may also lodge a complaint with a supervisory authority.
8. Transfers outside the European Union
Where a provider processes data outside the European Union, the transfer is based on the standard contractual clauses of the European Commission or an adequacy decision.
9. Automated decisions
The portal does not take automated decisions with legal effect. Risk scoring may flag an account for manual review, but a payout is never refused automatically without a human decision.
10. Security
Passwords are stored as hashes. Connections are encrypted. Identity documents are stored outside the public directory and are accessible only to reviewers. Access to administrative functions is limited by roles and recorded.
The English version of this page is the only binding one. Translations are provided for information. · Last updated: 2026-08-08