Legal
Privacy Policy
Last updated
How MazeCrafts Studio GmbH collects, uses and protects personal data when you browse mazecrafts.biz, license a kit or run an event with our player app.
1. Controller and contact details
The controller for the processing described in this notice, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:
MazeCrafts Studio GmbH
Ritterstraße 12
10969 Berlin
Germany
Registered with the Amtsgericht Berlin-Charlottenburg under HRB 214 887 B. Managing directors: Ada Kowalski and Ben Ortiz. VAT identification number DE352188104.
All privacy enquiries, including requests to exercise your rights, should be addressed to [email protected] or by post to the address above marked “Data Protection”. You may also call +49 30 5678 1120 during Berlin office hours. We have not appointed an external data protection officer; our internal data protection coordinator answers at the same address and is responsible for maintaining the record of processing activities required by Article 30 GDPR.
2. Scope of this notice
This notice covers three related activities. First, your use of the public website at mazecrafts.biz, including the demo booking form and the kit library. Second, the commercial relationship that follows if your organisation licenses a maze, a printable puzzle kit or a mobile escape room from us. Third, the MazeCrafts player app and facilitator console used to run a licensed event.
Where your employer has licensed MazeCrafts and you take part as a player, your employer normally decides which teams play, which fields are shown on the leaderboard and how long results are kept. In that configuration your employer is the controller and MazeCrafts acts as a processor under Article 28 GDPR, governed by the data processing agreement annexed to the licence. This notice then applies only to the limited data we process for our own purposes, such as service security, aggregate product analytics and billing.
3. Categories of personal data
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email address, employer, job title, hashed password, workspace role, login timestamps | Provided by you or your workspace administrator |
| Billing data | Company billing address, VAT identification number, purchase order reference, invoice history, payment card token (we never see full card numbers) | Provided by you; payment tokens created by our payment processor |
| Player telemetry | Team and player display name, puzzle attempts, hint usage, completion times, device type, coarse locale, session identifiers | Generated as an event is played |
| Facilitator uploads | Custom clue text, images, team rosters, briefing notes and white-label logos uploaded to the facilitator console | Provided by your facilitator |
| Marketing data | Contact details submitted through the demo form, campaign source, email engagement, call notes, consent records | Provided by you; enriched from your public company profile |
| Technical data | Truncated IP address, user agent, referrer, request timing, error traces | Collected automatically by our web servers |
4. Purposes and lawful bases
4.1 Performance of a contract — Article 6(1)(b) GDPR
We process account, billing, telemetry and upload data to create and administer your workspace, deliver licensed files, ship physical props, run events, produce engagement reports, invoice you and provide support. Without this data we cannot perform the licence.
4.2 Consent — Article 6(1)(a) GDPR
Non-essential cookies, product newsletters and case-study photography rely on your consent, which you may withdraw at any time without affecting the lawfulness of processing already carried out. Withdrawal links appear in every marketing email and in the cookie banner.
4.3 Legitimate interests — Article 6(1)(f) GDPR
We rely on legitimate interests to keep the service secure and available, to detect licence abuse, to produce aggregate and de-identified product statistics, to contact professional buyers at organisations that resemble our existing customers, and to defend legal claims. We have documented a balancing test for each of these purposes and will share a summary on request.
4.4 Legal obligations — Article 6(1)(c) GDPR
Invoices and related accounting records are retained to satisfy sections 147 of the German Fiscal Code (AO) and 257 of the Commercial Code (HGB).
5. Processors and recipients
We keep the vendor list short on purpose. Every processor below is bound by a written agreement meeting Article 28(3) GDPR, and each is subject to annual review.
| Processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Card and SEPA payment processing, invoicing, fraud screening | Ireland, with support access from the United States | EU Standard Contractual Clauses plus supplementary technical measures |
| Hetzner Online GmbH | Application hosting, database and encrypted backups | Nuremberg and Falkenstein, Germany | Processing remains within the EEA |
| Postmark (Wildbit, LLC) | Transactional email delivery and bounce handling | United States | EU Standard Contractual Clauses; EU-U.S. Data Privacy Framework where certified |
| Plausible Insights OÜ | Cookieless, aggregate website analytics | Estonia, servers in Germany | Processing remains within the EEA |
| HubSpot Ireland Limited | Sales pipeline, demo requests, marketing email | Ireland, with support access from the United States | EU Standard Contractual Clauses; regional data hosting in the EU |
Beyond these processors we disclose personal data only to our tax advisers, auditors and lawyers under professional confidentiality, to logistics partners for the sole purpose of delivering physical props, and to public authorities where we are legally compelled. We do not sell personal data and we do not operate real-time bidding or data-broker integrations.
6. International transfers
Our primary infrastructure is located in Germany. Where a processor accesses data from outside the European Economic Area, that transfer is covered by the European Commission’s Standard Contractual Clauses of 4 June 2021, supported by a transfer impact assessment and, where appropriate, additional measures such as encryption in transit and at rest, pseudonymisation of telemetry and strict role-based access. You may request a redacted copy of the relevant clauses at [email protected].
7. Retention
- Account data: for the duration of the workspace, then 90 days after closure to allow for reactivation and export.
- Player telemetry: 13 months in identifiable form, then irreversibly aggregated for benchmark statistics.
- Facilitator uploads: deleted 60 days after the licensed event ends, or immediately on request by the workspace administrator.
- Billing records: ten years from the end of the calendar year in which the invoice was issued.
- Marketing data: until consent is withdrawn or after 24 months of no engagement, whichever comes first.
- Server logs: 30 days, with truncated IP addresses.
8. Your rights
Subject to the conditions in the GDPR you have the right to request access to your personal data (Article 15), rectification of inaccurate data (Article 16), erasure (Article 17), restriction of processing (Article 18), portability in a structured, machine-readable format (Article 20) and to object to processing based on legitimate interests (Article 21). Where processing rests on consent, you may withdraw it at any time (Article 7(3)).
We answer verified requests within one month and will tell you promptly if we need the two-month extension permitted by Article 12(3). We do not charge a fee for a first request and we will not degrade the service because you exercised a right.
You also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. Our lead authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany. You may alternatively complain to the authority in your habitual residence or place of work.
9. Children’s data
MazeCrafts is a business product sold to organisations for use by their workforce. The player app is not directed at children, and licence terms prohibit enrolling players under the age of 16. We do not knowingly collect data from children. If you believe a child’s data has reached us, write to [email protected] and we will delete it within five business days.
10. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR. Puzzle difficulty adapts to team performance during a session, but this affects only gameplay and never employment, evaluation or eligibility outcomes. Engagement reports are descriptive statistics, not assessments of individuals, and we contractually prohibit their use for performance management.
11. Security
Technical and organisational measures under Article 32 GDPR include TLS 1.3 for all transport, AES-256 encryption of backups, hashed and salted credentials, mandatory multi-factor authentication for staff, least-privilege access reviewed quarterly, network segregation between production and analytics, tamper-evident audit logging, annual penetration testing by an external firm, documented backup restoration drills and a 72-hour breach notification runbook aligned with Article 33.
12. Cookies and similar technologies
Details of every cookie we set, its lifetime and how to withdraw consent are listed in our Cookie Policy. Essential cookies are used on the basis of section 25(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG); all other technologies are set only after you opt in.
13. Changes to this notice
We review this notice at least annually and whenever we add a processor or a materially new purpose. The version date appears at the top of this page. If a change reduces your rights or expands our purposes, we will notify workspace administrators by email at least 14 days before it takes effect.
Questions about this document?
Our legal team answers within two business days. Procurement teams can request a signable PDF with company details pre-filled.
[email protected]
MazeCrafts Studio GmbH, Ritterstraße 12, 10969 Berlin, Germany
VAT DE352188104 · HRB 214 887 B