Data Processing Agreement
Legal Disclaimer: This Privacy Policy has been drafted to comply with the requirements of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, the Russian Federal Law on Personal Data (FZ-152), the Children's Online Privacy Protection Act (COPPA), and the CAN-SPAM Act. This document constitutes a legally binding agreement. Users in regulated jurisdictions have additional rights as detailed in Sections 19–27. This policy does not rely on "continued use as consent" for any processing requiring explicit consent under applicable law.
This document governs all collection and Processing of Personal Data by Prazdnik.top in connection with the Quiz platform. Questions: finunigpt@gmail.com · To opt out of marketing: unsubscribe here
Definitions and Interpretive Framework
This section defines key words used throughout. "We" = Prazdnik.top. "You" = anyone who uses the platform. "Personal Data" = anything that can identify you. "Lead Data" = info you fill into event forms. Terms are read broadly in our favour, but your rights under GDPR, CCPA, and other laws are explicitly preserved and detailed in Sections 19–27.
For the purposes of this Policy, the following capitalised terms bear the meanings ascribed herein:
"Data Controller" / "We" / "Us" — Prazdnik.top, its proprietors, successors, assigns, and affiliated entities.
"Platform" — The interactive live quiz service at prazdnik.top, all subdomains, APIs, WebSocket endpoints, administrative interfaces, and all ancillary software.
"User" / "Data Subject" / "You" — Any natural person who accesses, browses, registers upon, or otherwise uses the Platform in any capacity.
"Personal Data" — Any information relating to an identified or identifiable natural person, including names, email addresses, account credentials, network identifiers, geolocation data, device fingerprints, and behavioural telemetry.
"Lead Data" — Personal Data submitted through any lead capture form, in-game survey, or registration interface on the Platform.
"Processing" — Any operation performed on Personal Data, including collection, storage, use, disclosure, erasure, profiling, and analysis.
"Sensitive Data" — Data revealing racial/ethnic origin, political opinions, religious beliefs, health, biometric data, sexual orientation, or criminal convictions; subject to heightened protection.
"Session" — A discrete interaction period with the Platform from first network contact to disconnection or session timeout.
"Event Data" — The complete record of all User interactions during a Session: answer choices, timing, scores, navigation, and all platform actions.
"Aggregate Intelligence" — Statistical or analytical outputs derived from Personal Data of multiple subjects, rendered genuinely non-identifiable, which the Controller may use commercially without restriction.
"Consent" — Under GDPR: a freely given, specific, informed, unambiguous affirmative action (explicit opt-in). Under CCPA: notice + right to opt-out. The Controller shall not treat continued use of the Platform as consent to any processing that requires explicit consent under applicable law.
Identity and Contact Details of the Data Controller
Data Controller: Prazdnik.top
Primary Contact / Data Protection Inquiries: finunigpt@gmail.com
Unsubscribe from Marketing: prazdnik.top/unsubscribe or reply "UNSUBSCRIBE" to any marketing email
Response Commitment: Within 30 calendar days of receipt (extendable by 60 days with notice). Identity verification required before disclosure of personal data.
The Data Controller does not currently maintain a mandatory Data Protection Officer (DPO). If required by law (GDPR Art. 37), a DPO will be appointed and contact details published here.
Scope, Applicability, and Lawful Basis for Consent
This policy applies worldwide. Where the law requires your explicit agreement (GDPR, CCPA) we ask for it — we do not treat simply visiting the site as consent to marketing. Strictly necessary processing (running the service) happens regardless of consent and doesn't require it.
This Policy governs all Processing of Personal Data conducted by or on behalf of the Data Controller in connection with the Platform, irrespective of the User's geographic location.
Lawful basis for processing: The Data Controller relies on multiple lawful bases as appropriate (detailed per activity in §6). Where explicit consent is the lawful basis, it is obtained through an affirmative opt-in mechanism (checkbox at registration; separate checkbox at lead capture). Strictly necessary processing (contract performance, legal obligation, security) does not require consent and is not affected by its withdrawal.
Withdrawal of consent: You may withdraw consent at any time by contacting us at finunigpt@gmail.com or using the unsubscribe mechanism at /unsubscribe. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Note: If You do not wish to have your data processed, do not use the Platform. For data already collected, you may exercise deletion rights as described in §11 and §19–20.
Categories of Personal Data Collected and Processed
We collect: what you type in (name, email, password), what your browser sends automatically (IP, device type), and what you do (answers, timing, scores). If you fill a contact form at an event, we collect all of that too.
4.1 Identity & Account Data
- Display names, usernames, email addresses, and authentication credentials;
- Account tier, subscription status, and marketing consent preference;
- User-generated content: quiz titles, questions, answer options, uploaded media.
4.2 Technical & Network Data
- Full IP addresses (IPv4/IPv6), including proxy/gateway addresses;
- HTTP request headers (User-Agent, Referer, Accept-Language etc.);
- Browser name/version, operating system, device category, screen resolution;
- Network latency measurements; geolocation derived from IP (country/city/ISP).
4.3 Behavioural & Event Data
- Millisecond-precision timestamps of all interactions;
- Answer selections, submission times, and time-to-answer;
- Scores, rankings, streak counts, and point trajectories;
- All WebSocket messages (both directions) including game state synchronisation.
4.4 Lead Capture Data
Where a quiz host enables lead capture, the Platform collects all data submitted by players through the lead form (name, email, phone, employer, job title, address, free-text responses). Lead capture requires explicit checkbox consent from players before submission.
4.5 Derived Data
Behavioural profiles, engagement scores, and predictive attributes derived from analysis of the above categories.
| Category | Source | Lawful Basis | Retention |
|---|---|---|---|
| Account credentials | Direct | Contract performance | Account lifetime + 3 yrs |
| IP & network data | Automatic | Legitimate interests (security) | 24 months |
| Event / behavioural data | Automatic | Legitimate interests / Consent | 36 months individual; indefinite anonymised |
| Lead capture data | Direct (with consent checkbox) | Consent + Contract | Until deletion request or 5 yrs max (GDPR) |
| Marketing consent preference | Direct | Consent | Until withdrawn or account deleted |
Automated Data Collection and Tracking Technologies
The Platform employs the following automated collection mechanisms, which operate as part of its core functionality:
5.1 Server-Side Logging
All HTTP and WebSocket requests are logged including URI, method, status code, processing time, IP address, and full request headers. Lawful basis: Legitimate interests (security, diagnostics, fraud prevention).
5.2 Real-Time Event Streaming
All WebSocket messages in both directions are captured, constituting a granular record of game participation. This is technically necessary for game operation. Lawful basis: Contract performance.
5.3 Browser Storage
The Platform uses localStorage to store: JWT authentication tokens (strictly necessary), language preference (functional), and session continuation tokens (strictly necessary). No third-party tracking or advertising cookies are currently deployed. See §13 and §24 for full cookie disclosure.
5.4 Automated Profiling
The Data Controller reserves the right to subject collected data to automated profiling including engagement scoring, audience segmentation, and predictive modelling. Where such profiling produces decisions with legal or significant effects on individuals, EU/EEA/UK users retain rights under GDPR Art. 22 (see §19). A Data Protection Impact Assessment for profiling activities is documented in §26.
Purposes of Processing and Legal Bases
| Purpose | GDPR Legal Basis (Art. 6) | CCPA Category |
|---|---|---|
| Providing quiz service & account management | Art. 6(1)(b) — Contract performance | Service-necessary |
| Security, fraud prevention, abuse detection | Art. 6(1)(f) — Legitimate interests | Service-necessary |
| Platform analytics & product improvement | Art. 6(1)(f) — Legitimate interests | Disclosed; opt-out available |
| Automated behavioural profiling | Art. 6(1)(f) — Legitimate interests + Art. 22 safeguards | Disclosed; opt-out available |
| Marketing communications (email/SMS) | Art. 6(1)(a) — Explicit consent (separate checkbox) | Opt-in; opt-out via /unsubscribe |
| Lead data processing (host-configured) | Art. 6(1)(a) — Explicit consent at lead form | Consent + right to delete |
| Legal compliance & regulatory obligations | Art. 6(1)(c) — Legal obligation | Required by law |
| Aggregate intelligence (anonymised) | Art. 6(1)(f) — Legitimate interests; not personal data once anonymised | Anonymised; not subject to CCPA |
| Business transactions (M&A, asset sales) | Art. 6(1)(f) — Legitimate interests | Disclosed |
The legitimate interests balancing tests for each Art. 6(1)(f) basis are documented in §27.
Lead Capture Data: Processing Rights and Consent
If you fill in a contact form before a game, your data goes to us AND the quiz host. Where the host provides a consent text for the form, you must actively tick a checkbox to agree. Without consent we store the data but do not use it for marketing. You can ask us to delete it at any time.
7.1 Consent Mechanism
When a quiz host enables a consent notice on their lead capture form, players are presented with a checkbox that must be actively ticked before submitting. Unchecked submissions are accepted (the host may require data for event logistics) but are flagged as non-consented in the export and will not be used for direct marketing by the Controller.
7.2 Direct Marketing Use
Lead Data from consented submissions may be used for direct marketing communications. Lead Data from non-consented submissions is used only for service delivery (e.g. providing event results to the host) and not for unsolicited marketing. All marketing communications include an unsubscribe mechanism per §22.
7.3 Data Enrichment
The Data Controller reserves the right to enrich consented Lead Data with information from publicly available sources and commercial data providers. Enrichment is not applied to non-consented submissions.
7.4 Onward Transfer to Hosts
Lead Data is made available to the quiz host who collected it. Hosts act as independent Data Controllers in respect of their use of Lead Data and are responsible for their own compliance with applicable privacy laws. The Controller encourages hosts to provide their own privacy notice at the event.
7.5 Retention
Lead Data is retained for up to five (5) years from collection, or until a verified deletion request is received, whichever is earlier. For EU/EEA/UK subjects, retention does not exceed what is necessary for the purposes stated at collection (GDPR data minimisation principle).
Your Rights: You may request deletion of your Lead Data at any time by emailing finunigpt@gmail.com with the subject "Lead Data Deletion Request." We will respond within 30 days.
Disclosure, Transfer, and Third-Party Processing
The Data Controller may disclose Personal Data to:
- Quiz Hosts: All data generated in their session (scores, names, Lead Data) is accessible to the host;
- Infrastructure Subprocessors: Cloud hosting and database providers (see §25);
- Legal and Professional Advisers: Bound by professional confidentiality obligations;
- Competent Authorities: Where required by applicable law, court order, or regulatory request;
- Business Transaction Counterparties: Acquirers, investors, or merger counterparties, subject to confidentiality obligations;
- Analytics Partners (anonymised only): De-identified Aggregate Intelligence may be shared or licensed commercially.
The Data Controller does not sell individually identified Personal Data to third-party advertisers. Anonymised or de-identified data is not "Personal Data" under applicable law and may be shared without restriction once genuinely non-identifiable.
International Data Transfers
Personal Data may be transferred to, and processed in, countries outside the European Economic Area (EEA) or the User's home jurisdiction. Where such transfers involve EU/EEA/UK Personal Data, the Data Controller relies on one or more of the following transfer mechanisms:
- European Commission adequacy decisions (where applicable);
- Standard Contractual Clauses (SCCs) as adopted by the European Commission;
- UK International Data Transfer Agreements (IDTAs) for UK transfers post-Brexit;
- Explicit consent of the Data Subject (GDPR Art. 49(1)(a));
- Necessity for the performance of a contract with the Data Subject (GDPR Art. 49(1)(b)).
For transfers to the Russian Federation, compliance with FZ-152 requirements for cross-border transfers is addressed in §21.
Data Retention, Archival, and Destruction
- Account Data: Account lifetime + 3 years (statutory limitation periods);
- Network Logs: 12–24 months (security and fraud investigation purposes);
- Event / Behavioural Data: 36 months in attributable form; indefinitely in anonymised form;
- Lead Data: Up to 5 years from collection, or until verified deletion request;
- Marketing Consent Records: Duration of account + 3 years (proof of consent);
- Backup Systems: Backups may persist beyond production retention for up to 90 additional days.
Upon expiry of applicable retention periods, the Data Controller will securely destroy or irreversibly anonymise Personal Data unless retention is required by law.
Rights of Data Subjects (All Jurisdictions)
You can ask us what we have on you, fix it, delete it, or stop certain uses. Email finunigpt@gmail.com. We respond within 30 days. To stop marketing emails, visit /unsubscribe. Jurisdiction-specific rights (GDPR, CCPA) are in Sections 19 and 20.
How to exercise: Email finunigpt@gmail.com with subject "Data Rights Request — [Right]." We will verify your identity and respond within 30 calendar days (extendable by 60 days for complex requests). To unsubscribe from marketing: prazdnik.top/unsubscribe.
Important: Deletion of individually identified data does not require deletion of genuinely anonymised statistical derivatives. These are the Controller's intellectual property. Withdrawal of consent does not affect the lawfulness of prior processing.
Security Measures and Breach Notification
Technical measures: Password hashing (bcrypt/Argon2), TLS encryption for all data in transit, role-based access controls, server-side input validation, session tokens with short expiry, and periodic security reviews.
Organisational measures: Access to production data limited to essential personnel; incident response plan maintained; vendor security assessments for subprocessors.
Breach Notification (GDPR Art. 33–34): In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of Data Subjects, the Data Controller will notify the relevant supervisory authority within 72 hours of becoming aware, and will notify affected individuals without undue delay where the risk is high. Breach notifications will be sent to the email address on file.
The Data Controller accepts no liability for breaches resulting from circumstances beyond its reasonable control, including advanced persistent threats or force majeure, provided it has implemented the security measures described above.
Cookies, Persistent Identifiers, and Local Storage
| Storage Key | Type | Purpose | Basis | Duration |
|---|---|---|---|---|
| qf_jwt | localStorage | Authentication token | Strictly necessary | Session / manual logout |
| qf_user | localStorage | Cached user profile | Strictly necessary | Session / logout |
| qf_lang | localStorage | Language preference | Functional | Persistent |
| qf_session_{pin} | localStorage | Game session continuation | Strictly necessary | Until game ends or manual clear |
| pp_cookie_accept | localStorage | Cookie notice dismissal | Functional | Persistent |
No third-party advertising cookies or external tracking pixels are currently deployed. Should any be added in future, this Policy will be updated and a new cookie consent prompt shown. Users may clear all stored data through their browser's developer tools → Application → Local Storage, though this will require re-authentication.
Behavioural Analytics and Aggregated Intelligence
The Data Controller analyses behavioural data from quiz sessions for: product improvement, ML model training, engagement research, and generation of anonymised industry reports. This processing relies on Legitimate Interests (see §27 for balancing test). EU/EEA/UK Users have the right to object per GDPR Art. 21.
Once data is genuinely anonymised and no longer capable of identifying any individual (tested against re-identification risk), it is classified as Aggregate Intelligence — the sole intellectual property of the Data Controller — and is not subject to Data Subject deletion rights.
Children — General Provisions
The Platform is not directed at children under 16 years (or the applicable age of digital consent in the User's jurisdiction, e.g. 13 in the US under COPPA). The Data Controller does not knowingly collect Personal Data from minors without verifiable parental or guardian consent. See §23 for full COPPA compliance details.
If we become aware that Personal Data of a minor has been collected without appropriate consent, we will delete it promptly. Contact us at finunigpt@gmail.com to report suspected collection from a minor.
Amendments and Versioning
The Data Controller may amend this Policy at any time. Material changes affecting existing Users will be communicated by email (to registered account holders) and/or by a prominent notice on the Platform's main page at least 14 days before taking effect, except where changes are required immediately by law.
Where changes affect the lawful basis for processing personal data of EU/EEA/UK subjects, we will re-obtain consent if necessary. The version date at the top of this Policy is the definitive indicator of currency.
Governing Law and Dispute Resolution
This Policy shall be governed by the laws of the jurisdiction in which the Data Controller is registered, without regard to conflict-of-laws rules. Disputes shall be resolved by negotiation in the first instance, then by the competent courts of the Controller's domicile.
Nothing in this Policy limits a Data Subject's right to lodge a complaint with a competent supervisory authority (e.g. the ICO in the UK, the relevant EU DPA, Roskomnadzor in Russia, or the California Privacy Protection Agency). Where this Policy is translated, the English version governs in case of conflict.
Severability, Entire Agreement, and Waiver
If any provision of this Policy is found invalid or unenforceable, it shall be severed to the minimum extent necessary and the remainder continues in full force. This Policy constitutes the entire agreement between the parties on data privacy matters and supersedes all prior communications.
Acknowledgement: By creating an account on the Platform (via affirmative opt-in), You acknowledge having read and understood this Policy. By submitting a lead capture form with the consent checkbox ticked, You confirm consent to the processing described in §7. Where you use the Platform without creating an account, strictly necessary processing applies per contract performance and legitimate interests only.
GDPR Addendum — EU / EEA / UK Users
This section supplements the general Policy for Users in the European Economic Area (including EU member states) and the United Kingdom. In the event of any conflict, this section prevails for such Users.
19.1 Lawful Bases (GDPR Art. 6)
All processing activities have an identified lawful basis as set out in §6. The Controller does not rely on "continued use as implied consent" for any processing activity. Consent-based processing (marketing, profiling beyond legitimate interests) requires a separate, freely given, specific, and revocable opt-in.
19.2 Rights Under GDPR (Arts. 15–22)
- Art. 15 — Right of Access: Request a copy of your personal data within 1 month;
- Art. 16 — Right to Rectification: Correct inaccurate personal data;
- Art. 17 — Right to Erasure ("Right to be Forgotten"): Deletion where no overriding legitimate interest or legal obligation exists;
- Art. 18 — Right to Restriction: Limit processing pending verification of accuracy or legitimate grounds;
- Art. 20 — Right to Data Portability: Receive data in JSON/CSV format where technically feasible;
- Art. 21 — Right to Object: Object to processing based on Art. 6(1)(f) legitimate interests at any time — we will cease unless compelling legitimate grounds override your interests;
- Art. 22 — Rights re. Automated Decision-Making: You are not subject to purely automated decisions with legal effect without human review, except where you have given explicit consent or it is necessary for a contract;
- Art. 7(3) — Withdrawal of Consent: Withdraw consent at any time without affecting prior lawful processing.
19.3 Lead Capture — GDPR Compliance
Lead capture forms where a consent notice is configured present a separate, unticked checkbox. Consent is purpose-specific and documented with a timestamp. Withdrawal is available at any time per §7 and §11.
19.4 International Transfers (EU)
Transfers of EU personal data outside the EEA rely on SCCs, adequacy decisions, or derogations per GDPR Art. 49 as appropriate (see §9).
19.5 Supervisory Authority
EU/EEA Data Subjects have the right to lodge a complaint with the supervisory authority in their EU member state of habitual residence or place of work. UK Data Subjects may complain to the Information Commissioner's Office (ICO): ico.org.uk, Tel: +44 303 123 1113.
CCPA / CPRA Addendum — California Residents
This section applies to California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
20.1 Categories of Personal Information Collected
In the preceding 12 months we have collected: identifiers (name, email, IP address); internet/network activity (usage data, event logs); geolocation data (inferred from IP); inferences drawn from the above (behavioural profiles). We do not collect sensitive personal information as defined by CPRA without explicit opt-in consent.
20.2 Categories of Sources
Directly from consumers (registration, lead forms, game participation) and automatically (device/network data during platform use).
20.3 Business or Commercial Purpose
Service provision, security, analytics, marketing (only with consent), and legitimate business operations.
20.4 Categories of Third Parties with Whom PI is Shared
Infrastructure subprocessors, quiz hosts (for their event data), legal advisers, law enforcement (when required), business transaction counterparties. We do not sell personal information as defined by CCPA.
20.5 Your CCPA/CPRA Rights
- Right to Know (§1798.110): Request disclosure of categories and specific pieces of personal information collected;
- Right to Delete (§1798.105): Request deletion subject to legal exceptions;
- Right to Correct (§1798.106, CPRA): Request correction of inaccurate personal information;
- Right to Opt-Out of Sale/Sharing (§1798.120): We do not sell PI. Behavioural data shared with analytics partners is based on legitimate interests; you may opt out by emailing us or visiting /unsubscribe;
- Right to Limit Use of Sensitive PI (CPRA): Sensitive PI is not collected beyond service necessity;
- Right to Non-Discrimination (§1798.125): We will not discriminate against you for exercising CCPA/CPRA rights — no denial of service, price differences, or reduced quality;
- Right to Opt-Out of Automated Decision-Making (CPRA): Contact us to opt out of profiling with significant effects.
20.6 How to Submit a CCPA Request
Email finunigpt@gmail.com with subject "CCPA Request — [Right]." We respond within 45 calendar days (extendable by 45 days with notice). Requests may be submitted on behalf of a minor child by a parent or guardian.
20.7 Authorised Agent
You may designate an authorised agent to submit requests on your behalf. We will require written authorisation and may verify your identity directly.
Do Not Sell My Personal Information: Prazdnik.top does not sell personal information. To opt out of behavioural analytics sharing: prazdnik.top/unsubscribe or email finunigpt@gmail.com.
Russian Federal Law No. 152-FZ Addendum
This section applies to citizens and residents of the Russian Federation and supplements the general Policy in accordance with Federal Law No. 152-FZ "On Personal Data" (as amended).
21.1 Operator Identity
The operator (оператор персональных данных) for the purposes of FZ-152 is Prazdnik.top. Contact: finunigpt@gmail.com.
21.2 Purpose Limitation
Personal data of Russian citizens is processed strictly for the purposes stated in this Policy: provision of quiz services, security, and (with separate consent) direct marketing. Processing is not carried out for any purposes incompatible with those stated.
21.3 Data Localisation
In accordance with FZ-152 Art. 18.1, the Data Controller acknowledges the requirement to record, systematise, accumulate, store, clarify (update, modify), and retrieve Personal Data of Russian citizens using databases located within the Russian Federation when such data is initially collected. The Controller takes reasonable steps to comply with this requirement for Russian citizens' registration data. Where full compliance is not immediately achievable due to technical infrastructure constraints, the Controller commits to transitioning to compliant infrastructure as technically feasible and notifying Roskomnadzor in accordance with applicable requirements.
21.4 Cross-Border Transfer
Cross-border transfer of personal data of Russian citizens is conducted in accordance with FZ-152 Art. 12. Prior to cross-border transfer, the Controller ensures that the receiving country provides adequate protection of personal data rights, or obtains written consent of the data subject for the transfer.
21.5 Rights of Russian Data Subjects
Citizens of the Russian Federation have the right to: access their personal data; request correction of inaccurate data; request withdrawal of consent and cessation of processing; request deletion of personal data; lodge complaints with Roskomnadzor (rkn.gov.ru). Requests are processed within the timeframes required by FZ-152 (as a rule, within 30 days).
21.6 Consent
Consent for processing personal data of Russian citizens for marketing purposes is obtained separately via an affirmative checkbox at registration. Consent may be withdrawn at any time by contacting finunigpt@gmail.com.
CAN-SPAM Act Compliance — Email Marketing
All commercial email communications sent by Prazdnik.top comply with the CAN-SPAM Act of 2003 (US), GDPR (EU/UK), and the Privacy and Electronic Communications Regulations (PECR) (UK):
- Opt-in required: Marketing emails are only sent to users who have explicitly opted in via the marketing consent checkbox at registration or another affirmative mechanism;
- Sender identification: All marketing emails clearly identify Prazdnik.top as the sender in the "From" field;
- Subject line accuracy: Subject lines accurately reflect the email content — no deceptive headers;
- Unsubscribe mechanism: Every marketing email contains a clear, working unsubscribe link (one-click opt-out at /unsubscribe) and the option to reply "UNSUBSCRIBE";
- Opt-out honoured within 10 business days: Unsubscribe requests are processed within 10 business days and the user will not receive further commercial emails after that period;
- No sale of unsubscribed addresses: Email addresses on the opt-out list will not be transferred or sold to third parties for marketing purposes;
- Physical address: Correspondence address: Prazdnik.top, contact via finunigpt@gmail.com.
Transactional emails (password resets, account security alerts, game invitations) are not subject to the opt-in requirement and will be sent regardless of marketing consent.
Unsubscribe instantly: prazdnik.top/unsubscribe — or email finunigpt@gmail.com with "UNSUBSCRIBE" in the subject.
COPPA Compliance and Children's Privacy
23.1 Age Restriction
The Platform is not directed at children under 13 (US) or under 16 (EU/EEA/UK) years of age. Users must be of the applicable age of digital consent in their jurisdiction to register an account. The registration form does not knowingly collect data from underage users. If we discover that a child under 13 (US) or under 16 (EU) has provided personal information without appropriate parental consent, we will delete it immediately.
23.2 Educational Use — Host Responsibilities
Quiz hosts who operate the Platform for educational purposes involving minors take on the following obligations:
- Obtain and maintain documented parental/guardian consent for all minor participants before enabling their participation;
- Ensure lead capture forms are not enabled for sessions involving minors unless parental consent specifically covers lead data collection;
- Provide participants and their parents with notice of data collection and the terms of this Policy;
- Comply with COPPA (if serving US children under 13), GDPR Art. 8 (if serving EU/EEA/UK children under 16), and any other applicable child-protection legislation.
Host liability: Hosts who fail to obtain appropriate parental consent for minor participants assume full legal liability for any resulting violations of COPPA, GDPR Art. 8, or equivalent laws. Prazdnik.top is not liable for host failures to secure such consent.
23.3 Parental Rights
Parents or guardians of a child may: review personal information collected from their child; request deletion of that information; refuse further collection; and withdraw consent at any time. Requests should be directed to finunigpt@gmail.com with subject "Parental/Guardian Data Request."
Cookie Policy and Consent Management
The Platform uses browser localStorage (not HTTP cookies) for session management. A cookie/storage consent notice is displayed on first visit to all public-facing pages. Users may dismiss the notice or clear their browser's localStorage at any time.
24.1 Strictly Necessary Storage (no consent required)
Authentication tokens (qf_jwt), user profile cache (qf_user), and session continuation tokens (qf_session_*) are strictly necessary for the service to function. These cannot be disabled without preventing use of the service.
24.2 Functional Storage (consent or legitimate interests)
Language preference (qf_lang) and cookie notice dismissal (pp_cookie_accept) are functional and improve the user experience. Legal basis: legitimate interests (minimal privacy impact, clearly beneficial to users).
24.3 No Third-Party Tracking
No analytics cookies, advertising pixels, or social media tracking tags are currently deployed. The Platform does not use Google Analytics, Facebook Pixel, or equivalent third-party trackers. If this changes, users will be notified and new consent obtained.
24.4 How to Withdraw
Clear your browser's localStorage via: Browser → Developer Tools → Application → Local Storage → Clear All. Note: this will log you out of all active sessions.
Subprocessors and Third-Party Data Processors
The Data Controller engages the following categories of subprocessors that may process personal data on our behalf. All subprocessors are bound by data processing agreements that include GDPR-compliant protections where applicable.
| Category | Purpose | Data Transferred | Location |
|---|---|---|---|
| Cloud Hosting / VPS Provider | Platform infrastructure, database hosting | All platform data | As per hosting provider (disclosed on request) |
| Email Delivery Service | Transactional & password-reset emails | Email address, username | EU/US (per provider) |
| Domain Registrar / DNS Provider | Domain name services | No personal data | N/A |
| CDN / Static Asset Delivery | Font delivery (Outfit font) | IP address (standard CDN log) | Global |
For a current list of named subprocessors, or to request Data Processing Agreement (DPA) documentation, contact finunigpt@gmail.com. Subprocessors are reviewed periodically; updates are reflected in this Policy.
Data Protection Impact Assessment (DPIA)
In accordance with GDPR Art. 35, the Data Controller has conducted a Data Protection Impact Assessment for the following high-risk processing activities:
26.1 Automated Profiling and Behavioural Analysis
Activity: Systematic profiling of users based on game participation and interaction patterns to create engagement scores and behavioural profiles.
Risks identified: Potential for inaccurate scoring affecting user treatment; risk of re-identification from combined datasets.
Mitigations applied: Profiles are used for product improvement and aggregated analytics only — not for decisions with legal effect on individuals; anonymisation applied before commercial use; aggregation thresholds prevent individual re-identification; users retain the right to object per GDPR Art. 21.
DPIA Outcome: Processing is proportionate and necessary; risks are adequately mitigated. A supervisory authority consultation (GDPR Art. 36) is not required.
26.2 Lead Capture Data Processing
Activity: Collection of detailed contact information from event participants through lead capture forms.
Risks identified: Broad consent scope; potential for unanticipated downstream use by hosts.
Mitigations applied: Separate per-form consent checkbox; purpose-specific consent text; 5-year retention limit; deletion on request; host contractual obligations.
DPIA Outcome: Processing lawful with mitigations; no Art. 36 consultation required.
Legitimate Interests Balancing Tests (GDPR Art. 6(1)(f))
For each processing activity relying on legitimate interests, the Data Controller has applied the three-part test: (1) Purpose test — is the interest legitimate? (2) Necessity test — is processing necessary? (3) Balancing test — do the Controller's interests override Data Subject interests?
| Activity | (1) Purpose Test | (2) Necessity | (3) Balancing Outcome |
|---|---|---|---|
| Security logging & fraud prevention | Legitimate — protecting users and the platform from fraud, abuse, and attacks | Yes — logs are essential for incident detection and response; no less intrusive alternative | Passes. Users expect security monitoring. Minimal additional privacy impact. Interest clearly outweighs individual rights in this context. |
| Product analytics (anonymised) | Legitimate — understanding how users interact with features to improve the product | Yes — cannot improve the product without usage data; data is aggregated/anonymised | Passes. Once anonymised, not personal data. Individual impact negligible. Strong product improvement interest. |
| Behavioural profiling (individual) | Legitimate — personalisation and commercial analytics | Partially — individual profiles beyond anonymised aggregates are not strictly necessary for service | Conditional pass. Users retain Art. 21 right to object. Profiling is limited to product improvement; not used for automated decisions with legal effect. Privacy impact mitigated by DPIA (§26). Overriding interest exists but right to object must be honoured. |
| Business continuity (M&A data transfers) | Legitimate — standard business need to retain data through corporate transactions | Yes — continuity of service and business operations | Passes. Data Subjects are notified of Controller changes; confidentiality obligations imposed on acquirers; no additional processing beyond what was already disclosed. |
Right to Object: EU/EEA/UK Users may object to any legitimate-interests processing at any time per GDPR Art. 21. Email finunigpt@gmail.com with subject "Art. 21 Objection." We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.