Privacy Policy
Introduction
This privacy policy informs you about the types of personal data (hereafter also "data") we process, for what purposes and to what extent, within our online offering Spielepause. Spielepause is a free, non-commercial daily-puzzle site that runs entirely in your browser. There are no user accounts, no sign-up and no advertising; we process as little data as possible.
Last updated: 23 September 2026.
Controller
Christian Götze, Rathenaustr. 3, 16761 Hennigsdorf, Deutschland
E-mail: spielepause@post.christiangoetze.de
Phone: +49 33022015238
Imprint: https://spielepause.de/impressum
A data protection officer is not legally required (§ 38 BDSG).
Overview of processing
The following overview summarises the types of data processed and the purposes of their processing.
Types of data processed: meta/communication data (e.g. IP addresses — in full in the server log files, truncated in the analytics — access times, browser type); anonymous game usage data (game mode, result, number of guesses — with no personal reference); competition data (first name or nickname and results, only if you take part in a competition); content data (only if you contact us by e-mail); image data (photographs of real places in which people may appear incidentally).
Categories of data subjects: users (visitors and players of this site); communication partners (people who write to us by e-mail); people appearing in photographs.
Purposes of processing: provision of the online offering and web hosting; IT security; anonymous analytics and game statistics; responding to enquiries.
Relevant legal bases
We process personal data on the basis of the General Data Protection Regulation (GDPR); additionally, national requirements in Germany apply, in particular the Federal Data Protection Act (BDSG) and the Telecommunications-Digital-Services Data Protection Act (TDDDG).
Legitimate interests (Art. 6 (1) (f) GDPR): processing is necessary to safeguard our legitimate interests, provided the interests or fundamental rights and freedoms of the data subject do not override them.
Pre-contractual enquiries (Art. 6 (1) (b) GDPR): when responding to contact enquiries.
Photographs in the game "Reiseigel"
The game "Reiseigel" shows photographs of real places. The photographs come from Wikimedia Commons under free licences (CC0, CC BY or CC BY-SA). We did not take them ourselves.
Some photographs may show people — passers-by in a street, visitors at a viewpoint. We select photographs so that no person is the subject of the picture; anyone shown is always incidental to the place itself. We do not use photographs in which individual people are recognisably the subject, nor photographs of religious ceremonies, processions, demonstrations or assemblies.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is running a free puzzle game about real places; the photograph shows the place, not the person.
Information under Art. 14 GDPR: this data did not come from the people shown but from the publicly accessible media collection Wikimedia Commons (commons.wikimedia.org). We know neither the identities nor the contact details of the people shown. Informing them individually would therefore be impossible within the meaning of Art. 14 (5) (b) GDPR, so we make the information publicly available here instead.
Retention: the photographs remain part of the game for as long as the game is offered. They are not analysed, not combined with other data, and no facial recognition takes place.
Objection and erasure: if you appear in one of the photographs and do not want it shown here, write to us — we will remove it without question and without you having to give a reason. Photo credits with author, licence and source are at https://spielepause.de/bildnachweise.
Security measures
In accordance with legal requirements, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
TLS encryption (https): to protect the data transmitted via our online offering we use TLS encryption, recognisable by the "https://" prefix in your browser's address bar.
Automated decision-making: to defend against attacks, IP addresses may be blocked automatically for a limited period (typically 24 to 96 hours; see "Provision of the online offering and web hosting"). A review of the block is possible on request. Otherwise, no automated decision-making takes place.
Transfer to recipients and processors
To operate this online offering we use a hosting provider that acts for us under a data processing agreement (Art. 28 GDPR; see below). In addition, IP addresses of detected attackers may be transmitted to CrowdSec SAS as part of our IT security measures; CrowdSec processes this data as an independent controller. E-mails to our contact address arrive in a mailbox operated by Proton AG in Geneva, Switzerland; Switzerland is covered by an adequacy decision of the EU Commission (Art. 45 GDPR). No further transfer to third countries outside the EEA takes place.
Provision of the online offering and web hosting
We operate this online offering on a server in a data centre in Falkenstein, Germany.
Collection of access data and log files: when our online offering is accessed, access data is recorded server-side in server log files (incl. the full IP address, date and time of the request, URL accessed, HTTP method, amount of data transferred, status message, browser type and version, referrer URL). This serves secure, fault-free operation, IT security and error analysis. The log files are stored exclusively on our own server in Germany and — apart from the reporting of attacker IP addresses described below — are not transmitted to any external provider. The access log is rotated daily and deleted automatically; an entry is gone after 31 days at the latest.
Defence against attacks (intrusion detection): to detect and defend against attacks we use the open-source software CrowdSec. CrowdSec evaluates the above log files and can block suspicious IP addresses for a limited period (typically 24 to 96 hours). Under the standard configuration, information about detected attacks (in particular the attacker's IP address and the type of detection) is transmitted to the central CrowdSec API of CrowdSec SAS, 24 Rue Saint Lazare, 75009 Paris, France. The transfer is solely for IT security purposes and relates to IP addresses associated with an attack attempt, not to regular visitors. CrowdSec privacy policy: https://www.crowdsec.net/privacy-policy.
DNS resolution: the DNS zones of our domain are hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany; the authoritative name servers are operated in Germany. No transfer to third countries outside the EEA takes place in this context. Legal basis: legitimate interest in the reliable availability of our online offering (Art. 6 (1) (f) GDPR).
Hosting provider used: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (servers in Falkenstein/Germany); privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz.
Backups: every night a backup of the server's data is written to a separate storage volume of our hosting provider in the same data centre in Germany (Falkenstein). It includes the analytics database and the competition data (see "Analytics (Matomo)" and "Competitions (Wettkampf)"). Each backup is kept for 14 days and then deleted automatically; it is used only to restore the service after a fault. A record already deleted from the live database may therefore remain in a backup for up to 14 more days.
Analytics (Matomo)
For statistical analysis of the use of our online offering we use Matomo, an open-source web analytics software. Matomo runs exclusively on our own infrastructure at https://matomo.cgoetze.de; the data collected is processed solely on our own server in Germany and not transmitted to third parties. No transfer to third countries outside the EEA takes place.
Cookieless processing without consent: Matomo is configured in a privacy-friendly way. No cookies are set and no information already stored on your device is accessed. As no information within the meaning of § 25 (1) TDDDG is stored on or read from your device, neither consent nor a consent banner is required. Your IP address is anonymised before any storage (truncation of the last bytes). There is no cross-site tracking and no profiling; no individual user profiles are created and no user ID is used.
Storage period: individual visit data is deleted automatically after 90 days. The detailed reports derived from it are deleted after twelve months; only aggregated monthly and yearly statistics without any personal reference are kept. The nightly backup (see "Provision of the online offering and web hosting") holds a copy for up to 14 more days.
In addition to page views, aggregate content-free interaction events may be recorded as Matomo actions (fixed enums only, e.g. opening the how-to, sharing/copying a result summary without the share text itself, practice mode — game id only). Guesses, grids and free text are never sent to Matomo.
Objection and "Do Not Track": our Matomo installation respects your browser's "Do Not Track" setting. If your browser sends a "Do Not Track" signal, you are not included in the analytics. You may also object to the processing at any time with effect for the future (Art. 21 GDPR).
Legal basis: legitimate interests (Art. 6 (1) (f) GDPR — interest in privacy-friendly statistical analysis and optimisation of the online offering).
Local storage and anonymous game statistics
Local storage in the browser (localStorage): your game progress, statistics and settings (e.g. light/dark mode) are stored solely in your browser ("localStorage") and never transmitted to us — the one exception being your results in a competition you joined (see "Competitions (Wettkampf)"). This storage is strictly necessary under § 25 (2) no. 2 TDDDG to provide the game you requested and therefore takes place without consent. You can delete this data at any time by clearing this site's data in your browser.
Anonymous game statistics (separate from Matomo): when a game ends, the site sends an anonymous metric to our server (only: game mode, win/loss and number of guesses). This contains no personal data, no identifiers and no cookies, and serves solely the aggregated analysis of game usage (Prometheus/Grafana). Legal basis: legitimate interests (Art. 6 (1) (f) GDPR).
Competitions (Wettkampf)
If you start or join a "Wettkampf" (an optional competition over one to six games for one day), we process the first name you enter together with your game results for those games. This data is stored on our own server in Germany (Redis) so that the shared leaderboard can be shown to the other participants who have the competition link. We do not ask for or store your surname, e-mail address or any other contact data, and we create no user profiles.
Visibility: the first name and results you submit are visible to everyone who has the link to that competition. Please therefore use only a first name or nickname and no further personal data.
Storage period: competition data is ephemeral. It is deleted automatically from the live database at the latest about two days after the competition day (technically via an expiry set on each entry). It can remain in the nightly backups for up to 14 more days and is then deleted there too; the backups are used only to restore the service after a fault (see "Provision of the online offering and web hosting").
Abuse protection: so that the competition function cannot be misused automatically, the server counts requests per IP address — when a competition is created, joined, viewed or a result is submitted, on every throw in "Rutschrobbe", and when a question in "Märchenmietze" is reported as wrong (the report itself contains only the question's identifier). For this, your IP address (together with the competition code when a leaderboard is viewed) is stored as a counter key for at most one hour and then deleted automatically; like all competition data it can remain in a nightly backup for up to 14 days. Legal basis: legitimate interest in the security and availability of the offering (Art. 6 (1) (f) GDPR).
Legal bases: the processing is carried out to provide the competition function you actively requested and in our legitimate interest in offering this social feature (Art. 6 (1) (b) and (f) GDPR). Participation is entirely voluntary; if you do not start or join a competition, no first name and no results are processed.
Contact
If you contact us by e-mail, we process the information you provide to the extent necessary to respond to your enquiry. The information is deleted as soon as it is no longer required for the purpose, generally no later than 6 months after the enquiry has been dealt with, unless statutory retention obligations apply. Legal bases: pre-contractual enquiries (Art. 6 (1) (b) GDPR) and legitimate interest in answering enquiries (Art. 6 (1) (f) GDPR). No contact form or external e-mail dispatch service is used.
Your e-mail arrives in a mailbox operated by Proton AG, Geneva, Switzerland. Switzerland is covered by an adequacy decision of the EU Commission (Art. 45 GDPR).
Cookies and similar technologies
Spielepause uses no cookies. Local browser storage (localStorage) is used solely for game progress, statistics and your settings and stays local in your browser (see "Local storage and anonymous game statistics"). Analytics via Matomo is cookieless and consent-free (see "Analytics (Matomo)"). No tracking in the sense of cross-device recognition or profiling takes place.
Deletion of data
The data we process is deleted in accordance with statutory requirements as soon as the permissions required for processing cease to apply (e.g. when the purpose of processing no longer applies). If data is not deleted because it is required for other legally permissible purposes, its processing is restricted to those purposes.
Changes and updates to this privacy policy
Please review the content of our privacy policy regularly. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary.
Rights of data subjects
Right to object (Art. 21 GDPR): you have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is carried out on the basis of Art. 6 (1) (f) GDPR.
Right of access (Art. 15 GDPR): you have the right to obtain confirmation as to whether data concerning you is processed and to access that data.
Right to rectification (Art. 16 GDPR): you have the right to request the rectification or completion of data concerning you.
Right to erasure (Art. 17 GDPR) and to restriction of processing (Art. 18 GDPR).
Right to data portability (Art. 20 GDPR).
Complaint to a supervisory authority (Art. 77 GDPR): the authority responsible for us is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg, Stahnsdorfer Damm 77, 14532 Kleinmachnow; e-mail: poststelle@lda.brandenburg.de.
Definitions
Personal data: any information relating to an identified or identifiable natural person.
Controller: the natural or legal person that alone or jointly with others determines the purposes and means of processing personal data.
Processing: any operation involving personal data, whether collecting, analysing, storing, transmitting or deleting it.
Processor: a person that processes personal data on behalf of the controller (e.g. a hosting provider).