1. Controller
[NAME / UNTERNEHMEN]
[ANSCHRIFT]
E-Mail: [DATENSCHUTZ-KONTAKT]
2. Provision, hosting and security
Grid Takeover is technically delivered using Cloudflare services. When you access the website, data required for the connection and secure delivery is processed. This may include, in particular, the IP address, date and time, requested resource, HTTP headers and technical browser and device information. This data is not stored as a Grid Takeover analytics profile.
The purpose of this processing is to provide the service securely, reliably and with good performance and to defend against abuse and attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of Grid Takeover. Depending on the service, Cloudflare acts as a processor. Cloudflare may also process metadata in the United States; Cloudflare provides, among other mechanisms, the EU-U.S. Data Privacy Framework and Standard Contractual Clauses for such transfers. The specific Cloudflare configuration and the applicable retention periods will be reviewed and documented before the public production launch.
3. Required and selected browser settings
Grid Takeover stores certain settings locally in the browser when this is necessary for a function you explicitly request or when you select the setting yourself. This may include language, sound and game settings. Such storage is not used for advertising or cross-device tracking.
Where these functions store or access information on your terminal device, this takes place only insofar as it is strictly necessary for the service you explicitly requested or directly serves the setting you selected. Section 25(2) TDDDG applies; where personal data is processed, Article 6(1)(b) or (f) GDPR may apply as the legal basis depending on the function.
4. Privacy-friendly audience and product analytics
Grid Takeover may use its own data-minimising audience and product analytics to understand use of the game, improve technical and gameplay features and assess the effectiveness of its own marketing campaigns. Only predefined events such as page view, match start, match end, shop view or checkout interest are recorded.
For this analysis, the two-letter country code, selected Grid Takeover language, requested page path, explicitly set campaign parameters such as utm_source, utm_medium and utm_campaign, and limited game metadata such as difficulty, result or number of moves may be processed. The country code is derived server-side by Cloudflare from the connection. Grid Takeover does not store the IP address in the analytics database for this purpose.
In particular, Grid Takeover does not store an email address, username, account or user ID, persistent anonymous device ID, browser fingerprint, city, postal code or coordinates, full referrer URL, or advertising click IDs such as gclid, fbclid or ttclid in this analysis. Grid Takeover Analytics does not set analytics cookies or identifiers in localStorage or sessionStorage. Events are immediately combined into daily statistical groups and are not linked into individual usage histories.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to develop Grid Takeover in an economically and technically meaningful way, identify errors and little-used features and evaluate the success of our own campaigns using aggregated data. By avoiding persistent identifiers and account linkage, this interest is pursued with maximum data minimisation. Aggregated analytics records are automatically deleted after no more than 400 days.
Because Grid Takeover does not store or access a non-essential tracking identifier on your terminal device for this first-party analytics configuration, no analytics consent for such an identifier is assumed to be required. If persistent attribution, third-party analytics, cross-device measurement or account-linked usage profiles are introduced in the future, this assessment must be repeated before activation and the consent and privacy setup must be adjusted.
5. Player profiles and accounts
If you create an account, the data processed may include your email address, public username, authentication and session data, verification status and data required for the profile, leaderboard and purchased or unlocked content. The processing is carried out to provide the account and related features you requested on the basis of Article 6(1)(b) GDPR. Security and abuse-prevention measures may additionally be based on Article 6(1)(f) GDPR.
Account data is generally stored for as long as the account exists and is then deleted unless statutory retention obligations or legitimate reasons require limited further storage. If Google Login is activated, Google is also involved as the identity provider you selected. The email service actually used and the final OAuth configuration will be specifically identified before the production launch.
5.1 User reports and moderation
If you report a username while signed in, we process in particular your account or user ID, the account or user ID of the reported profile, the username displayed at the time of the report, the report category you selected, any comment you choose to provide, the language selected for communication, and timestamps and processing status relating to the report. The email address associated with your account may be used to confirm receipt of the report and later communicate the outcome of the review. A comment is optional for predefined report categories; for “Other”, a short explanation is required.
This processing is used to review publicly visible usernames for violations of our rules, protect users and the service against abuse, identify repeated violations and document moderation decisions in a traceable manner. The legal basis is generally Article 6(1)(f) GDPR. Our legitimate interest is to operate a safe, rule-compliant and functional community and game service. Where processing is necessary in an individual case to comply with a specific legal obligation, Article 6(1)(c) GDPR may additionally apply.
To handle a report, notifications may be sent to the operator address responsible for moderation as well as automatic receipt and outcome messages to the reporting person. The email service in use processes the data required for this purpose; the specific provider will be identified in this privacy policy before the public production launch. Moderation decisions may additionally include an internal handling note. This internal note is not sent to the reporting person. An outcome message contains only a general review result and does not normally disclose specific sanctions or confidential internal moderation information about other users. Delivery status and timestamps may be stored to prevent duplicate notifications and to allow failed deliveries to be retried in a controlled manner.
Report data is stored only for as long as necessary to review and handle the report, identify and document repeated abuse, establish or defend legal claims, or comply with applicable legal obligations. It is then deleted or, where appropriate and permissible, anonymised. The specific retention periods and technical deletion mechanism will be finalised and documented before the public production launch. In any optional comment, please provide only information necessary for the review and avoid unnecessary personal data about yourself or third parties.
6. Advertising and consent management
If Google advertising or other advertising or tracking technologies requiring consent are activated on Grid Takeover, they are handled separately from the first-party identifier-free analytics described above. Storage on or access to your terminal device that requires consent takes place only after valid consent under Section 25(1) TDDDG and Article 6(1)(a) GDPR.
A consent solution is used for such processing. You can reopen your choices via the permanently available “Privacy & Cookie Settings” link and change or withdraw consent at any time with effect for the future. Before advertising is activated, the specific Google services, advertising partners, purposes, recipients and, where applicable, third-country transfers will be added here.
7. Contact
If you contact us, we process the information you provide in order to handle your request. Depending on the content, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Our legitimate interest is the proper handling of enquiries. The data is deleted when it is no longer required to handle the request and no statutory retention obligations apply.
8. Your rights
Subject to the statutory requirements, you have rights including access, rectification, erasure, restriction of processing and data portability. Where processing is based on Article 6(1)(f) GDPR, you may object to the processing on grounds relating to your particular situation. You may withdraw consent at any time with effect for the future.
Grid Takeover's own analytics database deliberately contains no user or device identifier. As a result, analytics counts that have already been aggregated generally cannot later be attributed to a particular person.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular the authority responsible for your habitual residence, place of work or the place of the alleged infringement.
10. Automated decisions
Grid Takeover does not make solely automated decisions based on the analytics data described above that produce legal effects concerning you or similarly significantly affect you.
Proposed usernames may be checked automatically during registration or a username change using technical rules for format, reserved terms and clearly prohibited content, and may be rejected. A user report does not automatically result in sanctions; moderation decisions are made as a separate process. These checks do not constitute solely automated decisions that produce legal effects concerning you or similarly significantly affect you.
11. Version
August 2026