This is a courtesy translation. The German version at /datenschutz is the binding one; in case of any discrepancy, the German text prevails.
The controller responsible for processing personal data on this website and in this service is:
Jens Bösche
Am Piepenbrink 16A
29379 Wittingen
Deutschland
kappaxbeta@gmail.com
We have not appointed a data protection officer, as the statutory thresholds for doing so are not met. For any privacy matter, please contact us at the address above.
This service is built so that as little personal data as possible comes into existence in the first place. That is not a statement of intent — each of the following can be checked:
The application and the database run on servers we rent in Germany. No transfer to a third country takes place for hosting.
We have a data processing agreement under Art. 28 GDPR with both providers. Neither has access to the content of the data; they process it solely in order to operate the servers.
TLS certificates for encrypted transport are obtained automatically from Let’s Encrypt (Internet Security Research Group, USA). Only domain names are transmitted in that process — no visitor data.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technically secure and reliable operation of this service.
When a page is requested, the web server automatically records log data transmitted by your browser:
This data is technically necessary to deliver the page and additionally serves to detect and defend against abuse and attacks. It is not combined with other data sources and is not evaluated for analytics. The legal basis is Art. 6(1)(f) GDPR. Logs are deleted, or their IP addresses anonymised, after 14 days at the latest.
We use strictly necessary cookies only. There is therefore no consent banner: under § 25(2) no. 2 TDDDG, no consent is required for cookies that are strictly necessary to provide a service the user has expressly requested. No cookies are set for analytics or advertising.
You can delete or block cookies in your browser at any time. If you do, you will not be able to sign in or use the protected areas of the service.
We measure how often which pages are opened, in order to understand what is being found and what is not. We use no third-party analytics tool and no cookie for this. One record is stored per page view, containing:
To group repeat views within a single day, we compute a cryptographic hash from your IP address, your user agent, the current date and a secret key known only to us. Only that hash is stored.
Your IP address is not stored.Because the date is part of the calculation, the hash changes completely at midnight UTC. The same person receives a different value the next day, and the two cannot be linked. Recognition across days, and therefore the building of any usage profile, is technically impossible; “unique visitors” here is a daily figure and cannot be anything else.
The country code is determined offline, from an address-registry allocation table built into our application. Your IP address is not transmitted to anyone for this purpose and is not passed to any geolocation service. The result is a country and never anything more precise.
Views of our administrative area are not counted. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is in designing this service to meet actual demand. Given the design described above, the impact on your rights is low.
If you create an account, we process your email address and your password. The password is stored only as a hash; we do not know it in plain text. In addition, we process the details you enter in your profile, such as a display name and your choice of character, along with the spaces you are a member of and your role in them.
If you invite others to a space by email, we process the address you provide in order to deliver the invitation. Please only invite people who are happy to receive one.
The legal basis is Art. 6(1)(b) GDPR, as this processing is necessary to perform the user agreement.
Rooms can be entered via a guest link without creating an account. In that case we process the name you give yourself, the character you choose, and a technical identifier that identifies your session for its duration. We do not ask for an email address.
Guest access is time-limited and is deleted automatically once it expires. The legal basis is Art. 6(1)(b) GDPR.
What you create in the service is stored: pages and their content, rooms you build, chat messages, game state and comparable input. This content is visible to the members of the space in question and to guests who have been granted access. Please note that chat messages and things you build are visible to everyone present.
The service stores changes as an append-only log (“event sourcing”). An entry is never overwritten; a further entry is appended instead. That is the reason content survives a lapsed subscription.
This does not affect your right to erasure. If you request deletion, we delete your account and overwrite the personal details in the affected log entries so that they can no longer be attributed to you. The entry itself remains in anonymised form, because removing it would destroy the state of rooms shared with other people. Please contact us at the address in section 1.
If you write to us via the contact form or the event enquiry form, we process the details you provide there — in particular your name, email address and the content of your message — in order to deal with your enquiry.
The legal basis is Art. 6(1)(b) GDPR where the enquiry is aimed at entering into a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in answering enquiries. We delete enquiries once they have been dealt with, unless statutory retention obligations apply.
For paid subscriptions we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You enter payment details — card details in particular — directly with Stripe. We neither receive nor store them.
In our own database we store only the Stripe customer id, the subscription id and its status, so that we know which features are unlocked. Stripe may also transfer personal data to the USA; that transfer is based on standard contractual clauses and certification under the EU-US Data Privacy Framework.
The legal basis is Art. 6(1)(b) GDPR. Invoice-related data is retained under Art. 6(1)(c) GDPR for the statutory periods of up to ten years.
System messages such as sign-up confirmations, password resets and invitations are sent via a mail server we run ourselves on our own infrastructure. No external mail delivery provider is involved. There is no open or click tracking, and we do not send a newsletter.
Beyond the parties named in sections 3 and 11, we do not pass your data to third parties. Disclosure occurs only where we are legally obliged to make it. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR, and your data is not sold.
You have the following rights in relation to us:
Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR — which covers the server logs and the analytics — you have the right to object at any time on grounds relating to your particular situation (Art. 21 GDPR). An informal message to kappaxbeta@gmail.com is sufficient.
You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority competent for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://www.lfd.niedersachsen.de
We update this policy when the service or the legal position changes. The version available here is the one that applies.
Last updated: August 2026