Privacy Policy | Quiz by Prazdnik.top
Legal Document v2.0 Compliant: GDPR · CCPA · COPPA · FZ-152 · CAN-SPAM
Privacy Policy &
Data Processing Agreement
Effective: 1 June 2025 Last Updated: 31 May 2026 Global Jurisdiction 27 Sections

Legal Disclaimer: This Privacy Policy has been drafted to comply with the requirements of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the CPRA, the Russian Federal Law on Personal Data (FZ-152), the Children's Online Privacy Protection Act (COPPA), and the CAN-SPAM Act. This document constitutes a legally binding agreement. Users in regulated jurisdictions have additional rights as detailed in Sections 19–27. This policy does not rely on "continued use as consent" for any processing requiring explicit consent under applicable law.

This document governs all collection and Processing of Personal Data by Prazdnik.top in connection with the Quiz platform. Questions: finunigpt@gmail.com  ·  To opt out of marketing: unsubscribe here

Section 1

Definitions and Interpretive Framework

Plain language
In plain terms

This section defines key words used throughout. "We" = Prazdnik.top. "You" = anyone who uses the platform. "Personal Data" = anything that can identify you. "Lead Data" = info you fill into event forms. Terms are read broadly in our favour, but your rights under GDPR, CCPA, and other laws are explicitly preserved and detailed in Sections 19–27.

For the purposes of this Policy, the following capitalised terms bear the meanings ascribed herein:

All Definitions (11) — click to collapse

"Data Controller" / "We" / "Us" — Prazdnik.top, its proprietors, successors, assigns, and affiliated entities.

"Platform" — The interactive live quiz service at prazdnik.top, all subdomains, APIs, WebSocket endpoints, administrative interfaces, and all ancillary software.

"User" / "Data Subject" / "You" — Any natural person who accesses, browses, registers upon, or otherwise uses the Platform in any capacity.

"Personal Data" — Any information relating to an identified or identifiable natural person, including names, email addresses, account credentials, network identifiers, geolocation data, device fingerprints, and behavioural telemetry.

"Lead Data" — Personal Data submitted through any lead capture form, in-game survey, or registration interface on the Platform.

"Processing" — Any operation performed on Personal Data, including collection, storage, use, disclosure, erasure, profiling, and analysis.

"Sensitive Data" — Data revealing racial/ethnic origin, political opinions, religious beliefs, health, biometric data, sexual orientation, or criminal convictions; subject to heightened protection.

"Session" — A discrete interaction period with the Platform from first network contact to disconnection or session timeout.

"Event Data" — The complete record of all User interactions during a Session: answer choices, timing, scores, navigation, and all platform actions.

"Aggregate Intelligence" — Statistical or analytical outputs derived from Personal Data of multiple subjects, rendered genuinely non-identifiable, which the Controller may use commercially without restriction.

"Consent" — Under GDPR: a freely given, specific, informed, unambiguous affirmative action (explicit opt-in). Under CCPA: notice + right to opt-out. The Controller shall not treat continued use of the Platform as consent to any processing that requires explicit consent under applicable law.

Section 2

Identity and Contact Details of the Data Controller

Data Controller: Prazdnik.top

Primary Contact / Data Protection Inquiries: finunigpt@gmail.com

Unsubscribe from Marketing: prazdnik.top/unsubscribe or reply "UNSUBSCRIBE" to any marketing email

Response Commitment: Within 30 calendar days of receipt (extendable by 60 days with notice). Identity verification required before disclosure of personal data.

The Data Controller does not currently maintain a mandatory Data Protection Officer (DPO). If required by law (GDPR Art. 37), a DPO will be appointed and contact details published here.

Section 3

Scope, Applicability, and Lawful Basis for Consent

Plain language
In plain terms

This policy applies worldwide. Where the law requires your explicit agreement (GDPR, CCPA) we ask for it — we do not treat simply visiting the site as consent to marketing. Strictly necessary processing (running the service) happens regardless of consent and doesn't require it.

This Policy governs all Processing of Personal Data conducted by or on behalf of the Data Controller in connection with the Platform, irrespective of the User's geographic location.

Lawful basis for processing: The Data Controller relies on multiple lawful bases as appropriate (detailed per activity in §6). Where explicit consent is the lawful basis, it is obtained through an affirmative opt-in mechanism (checkbox at registration; separate checkbox at lead capture). Strictly necessary processing (contract performance, legal obligation, security) does not require consent and is not affected by its withdrawal.

Withdrawal of consent: You may withdraw consent at any time by contacting us at finunigpt@gmail.com or using the unsubscribe mechanism at /unsubscribe. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

Note: If You do not wish to have your data processed, do not use the Platform. For data already collected, you may exercise deletion rights as described in §11 and §19–20.

Section 4

Categories of Personal Data Collected and Processed

Plain language
In plain terms

We collect: what you type in (name, email, password), what your browser sends automatically (IP, device type), and what you do (answers, timing, scores). If you fill a contact form at an event, we collect all of that too.

4.1 Identity & Account Data

  • Display names, usernames, email addresses, and authentication credentials;
  • Account tier, subscription status, and marketing consent preference;
  • User-generated content: quiz titles, questions, answer options, uploaded media.

4.2 Technical & Network Data

  • Full IP addresses (IPv4/IPv6), including proxy/gateway addresses;
  • HTTP request headers (User-Agent, Referer, Accept-Language etc.);
  • Browser name/version, operating system, device category, screen resolution;
  • Network latency measurements; geolocation derived from IP (country/city/ISP).

4.3 Behavioural & Event Data

  • Millisecond-precision timestamps of all interactions;
  • Answer selections, submission times, and time-to-answer;
  • Scores, rankings, streak counts, and point trajectories;
  • All WebSocket messages (both directions) including game state synchronisation.

4.4 Lead Capture Data

Where a quiz host enables lead capture, the Platform collects all data submitted by players through the lead form (name, email, phone, employer, job title, address, free-text responses). Lead capture requires explicit checkbox consent from players before submission.

4.5 Derived Data

Behavioural profiles, engagement scores, and predictive attributes derived from analysis of the above categories.

CategorySourceLawful BasisRetention
Account credentialsDirectContract performanceAccount lifetime + 3 yrs
IP & network dataAutomaticLegitimate interests (security)24 months
Event / behavioural dataAutomaticLegitimate interests / Consent36 months individual; indefinite anonymised
Lead capture dataDirect (with consent checkbox)Consent + ContractUntil deletion request or 5 yrs max (GDPR)
Marketing consent preferenceDirectConsentUntil withdrawn or account deleted
Section 5

Automated Data Collection and Tracking Technologies

The Platform employs the following automated collection mechanisms, which operate as part of its core functionality:

5.1 Server-Side Logging

All HTTP and WebSocket requests are logged including URI, method, status code, processing time, IP address, and full request headers. Lawful basis: Legitimate interests (security, diagnostics, fraud prevention).

5.2 Real-Time Event Streaming

All WebSocket messages in both directions are captured, constituting a granular record of game participation. This is technically necessary for game operation. Lawful basis: Contract performance.

5.3 Browser Storage

The Platform uses localStorage to store: JWT authentication tokens (strictly necessary), language preference (functional), and session continuation tokens (strictly necessary). No third-party tracking or advertising cookies are currently deployed. See §13 and §24 for full cookie disclosure.

5.4 Automated Profiling

The Data Controller reserves the right to subject collected data to automated profiling including engagement scoring, audience segmentation, and predictive modelling. Where such profiling produces decisions with legal or significant effects on individuals, EU/EEA/UK users retain rights under GDPR Art. 22 (see §19). A Data Protection Impact Assessment for profiling activities is documented in §26.

Section 6

Purposes of Processing and Legal Bases

PurposeGDPR Legal Basis (Art. 6)CCPA Category
Providing quiz service & account managementArt. 6(1)(b) — Contract performanceService-necessary
Security, fraud prevention, abuse detectionArt. 6(1)(f) — Legitimate interestsService-necessary
Platform analytics & product improvementArt. 6(1)(f) — Legitimate interestsDisclosed; opt-out available
Automated behavioural profilingArt. 6(1)(f) — Legitimate interests + Art. 22 safeguardsDisclosed; opt-out available
Marketing communications (email/SMS)Art. 6(1)(a) — Explicit consent (separate checkbox)Opt-in; opt-out via /unsubscribe
Lead data processing (host-configured)Art. 6(1)(a) — Explicit consent at lead formConsent + right to delete
Legal compliance & regulatory obligationsArt. 6(1)(c) — Legal obligationRequired by law
Aggregate intelligence (anonymised)Art. 6(1)(f) — Legitimate interests; not personal data once anonymisedAnonymised; not subject to CCPA
Business transactions (M&A, asset sales)Art. 6(1)(f) — Legitimate interestsDisclosed

The legitimate interests balancing tests for each Art. 6(1)(f) basis are documented in §27.

Section 7

Lead Capture Data: Processing Rights and Consent

Plain language
In plain terms

If you fill in a contact form before a game, your data goes to us AND the quiz host. Where the host provides a consent text for the form, you must actively tick a checkbox to agree. Without consent we store the data but do not use it for marketing. You can ask us to delete it at any time.

7.1 Consent Mechanism

When a quiz host enables a consent notice on their lead capture form, players are presented with a checkbox that must be actively ticked before submitting. Unchecked submissions are accepted (the host may require data for event logistics) but are flagged as non-consented in the export and will not be used for direct marketing by the Controller.

7.2 Direct Marketing Use

Lead Data from consented submissions may be used for direct marketing communications. Lead Data from non-consented submissions is used only for service delivery (e.g. providing event results to the host) and not for unsolicited marketing. All marketing communications include an unsubscribe mechanism per §22.

7.3 Data Enrichment

The Data Controller reserves the right to enrich consented Lead Data with information from publicly available sources and commercial data providers. Enrichment is not applied to non-consented submissions.

7.4 Onward Transfer to Hosts

Lead Data is made available to the quiz host who collected it. Hosts act as independent Data Controllers in respect of their use of Lead Data and are responsible for their own compliance with applicable privacy laws. The Controller encourages hosts to provide their own privacy notice at the event.

7.5 Retention

Lead Data is retained for up to five (5) years from collection, or until a verified deletion request is received, whichever is earlier. For EU/EEA/UK subjects, retention does not exceed what is necessary for the purposes stated at collection (GDPR data minimisation principle).

Your Rights: You may request deletion of your Lead Data at any time by emailing finunigpt@gmail.com with the subject "Lead Data Deletion Request." We will respond within 30 days.

Section 8

Disclosure, Transfer, and Third-Party Processing

The Data Controller may disclose Personal Data to:

  • Quiz Hosts: All data generated in their session (scores, names, Lead Data) is accessible to the host;
  • Infrastructure Subprocessors: Cloud hosting and database providers (see §25);
  • Legal and Professional Advisers: Bound by professional confidentiality obligations;
  • Competent Authorities: Where required by applicable law, court order, or regulatory request;
  • Business Transaction Counterparties: Acquirers, investors, or merger counterparties, subject to confidentiality obligations;
  • Analytics Partners (anonymised only): De-identified Aggregate Intelligence may be shared or licensed commercially.

The Data Controller does not sell individually identified Personal Data to third-party advertisers. Anonymised or de-identified data is not "Personal Data" under applicable law and may be shared without restriction once genuinely non-identifiable.

Section 9

International Data Transfers

Personal Data may be transferred to, and processed in, countries outside the European Economic Area (EEA) or the User's home jurisdiction. Where such transfers involve EU/EEA/UK Personal Data, the Data Controller relies on one or more of the following transfer mechanisms:

  • European Commission adequacy decisions (where applicable);
  • Standard Contractual Clauses (SCCs) as adopted by the European Commission;
  • UK International Data Transfer Agreements (IDTAs) for UK transfers post-Brexit;
  • Explicit consent of the Data Subject (GDPR Art. 49(1)(a));
  • Necessity for the performance of a contract with the Data Subject (GDPR Art. 49(1)(b)).

For transfers to the Russian Federation, compliance with FZ-152 requirements for cross-border transfers is addressed in §21.

Section 10

Data Retention, Archival, and Destruction

  • Account Data: Account lifetime + 3 years (statutory limitation periods);
  • Network Logs: 12–24 months (security and fraud investigation purposes);
  • Event / Behavioural Data: 36 months in attributable form; indefinitely in anonymised form;
  • Lead Data: Up to 5 years from collection, or until verified deletion request;
  • Marketing Consent Records: Duration of account + 3 years (proof of consent);
  • Backup Systems: Backups may persist beyond production retention for up to 90 additional days.

Upon expiry of applicable retention periods, the Data Controller will securely destroy or irreversibly anonymise Personal Data unless retention is required by law.

Section 11

Rights of Data Subjects (All Jurisdictions)

Plain language
In plain terms

You can ask us what we have on you, fix it, delete it, or stop certain uses. Email finunigpt@gmail.com. We respond within 30 days. To stop marketing emails, visit /unsubscribe. Jurisdiction-specific rights (GDPR, CCPA) are in Sections 19 and 20.

Access
Request a copy of data we hold about you
Rectification
Request correction of inaccurate data
Erasure
Request deletion (subject to legal exceptions)
Restriction
Request we limit how we use your data
Portability
Receive your data in a machine-readable format
Object
Object to processing for legitimate interests or marketing
Withdraw Consent
Withdraw consent at any time without penalty
Complain
Lodge a complaint with a supervisory authority

How to exercise: Email finunigpt@gmail.com with subject "Data Rights Request — [Right]." We will verify your identity and respond within 30 calendar days (extendable by 60 days for complex requests). To unsubscribe from marketing: prazdnik.top/unsubscribe.

Important: Deletion of individually identified data does not require deletion of genuinely anonymised statistical derivatives. These are the Controller's intellectual property. Withdrawal of consent does not affect the lawfulness of prior processing.

Section 12

Security Measures and Breach Notification

Technical measures: Password hashing (bcrypt/Argon2), TLS encryption for all data in transit, role-based access controls, server-side input validation, session tokens with short expiry, and periodic security reviews.

Organisational measures: Access to production data limited to essential personnel; incident response plan maintained; vendor security assessments for subprocessors.

Breach Notification (GDPR Art. 33–34): In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of Data Subjects, the Data Controller will notify the relevant supervisory authority within 72 hours of becoming aware, and will notify affected individuals without undue delay where the risk is high. Breach notifications will be sent to the email address on file.

The Data Controller accepts no liability for breaches resulting from circumstances beyond its reasonable control, including advanced persistent threats or force majeure, provided it has implemented the security measures described above.

Section 13

Cookies, Persistent Identifiers, and Local Storage

Storage KeyTypePurposeBasisDuration
qf_jwtlocalStorageAuthentication tokenStrictly necessarySession / manual logout
qf_userlocalStorageCached user profileStrictly necessarySession / logout
qf_langlocalStorageLanguage preferenceFunctionalPersistent
qf_session_{pin}localStorageGame session continuationStrictly necessaryUntil game ends or manual clear
pp_cookie_acceptlocalStorageCookie notice dismissalFunctionalPersistent

No third-party advertising cookies or external tracking pixels are currently deployed. Should any be added in future, this Policy will be updated and a new cookie consent prompt shown. Users may clear all stored data through their browser's developer tools → Application → Local Storage, though this will require re-authentication.

Section 14

Behavioural Analytics and Aggregated Intelligence

The Data Controller analyses behavioural data from quiz sessions for: product improvement, ML model training, engagement research, and generation of anonymised industry reports. This processing relies on Legitimate Interests (see §27 for balancing test). EU/EEA/UK Users have the right to object per GDPR Art. 21.

Once data is genuinely anonymised and no longer capable of identifying any individual (tested against re-identification risk), it is classified as Aggregate Intelligence — the sole intellectual property of the Data Controller — and is not subject to Data Subject deletion rights.

Section 15

Children — General Provisions

The Platform is not directed at children under 16 years (or the applicable age of digital consent in the User's jurisdiction, e.g. 13 in the US under COPPA). The Data Controller does not knowingly collect Personal Data from minors without verifiable parental or guardian consent. See §23 for full COPPA compliance details.

If we become aware that Personal Data of a minor has been collected without appropriate consent, we will delete it promptly. Contact us at finunigpt@gmail.com to report suspected collection from a minor.

Section 16

Amendments and Versioning

The Data Controller may amend this Policy at any time. Material changes affecting existing Users will be communicated by email (to registered account holders) and/or by a prominent notice on the Platform's main page at least 14 days before taking effect, except where changes are required immediately by law.

Where changes affect the lawful basis for processing personal data of EU/EEA/UK subjects, we will re-obtain consent if necessary. The version date at the top of this Policy is the definitive indicator of currency.

Section 17

Governing Law and Dispute Resolution

This Policy shall be governed by the laws of the jurisdiction in which the Data Controller is registered, without regard to conflict-of-laws rules. Disputes shall be resolved by negotiation in the first instance, then by the competent courts of the Controller's domicile.

Nothing in this Policy limits a Data Subject's right to lodge a complaint with a competent supervisory authority (e.g. the ICO in the UK, the relevant EU DPA, Roskomnadzor in Russia, or the California Privacy Protection Agency). Where this Policy is translated, the English version governs in case of conflict.

Section 18

Severability, Entire Agreement, and Waiver

If any provision of this Policy is found invalid or unenforceable, it shall be severed to the minimum extent necessary and the remainder continues in full force. This Policy constitutes the entire agreement between the parties on data privacy matters and supersedes all prior communications.

Acknowledgement: By creating an account on the Platform (via affirmative opt-in), You acknowledge having read and understood this Policy. By submitting a lead capture form with the consent checkbox ticked, You confirm consent to the processing described in §7. Where you use the Platform without creating an account, strictly necessary processing applies per contract performance and legitimate interests only.

Section 19

GDPR Addendum — EU / EEA / UK Users

EU GDPRUK GDPR

This section supplements the general Policy for Users in the European Economic Area (including EU member states) and the United Kingdom. In the event of any conflict, this section prevails for such Users.

19.1 Lawful Bases (GDPR Art. 6)

All processing activities have an identified lawful basis as set out in §6. The Controller does not rely on "continued use as implied consent" for any processing activity. Consent-based processing (marketing, profiling beyond legitimate interests) requires a separate, freely given, specific, and revocable opt-in.

19.2 Rights Under GDPR (Arts. 15–22)

  • Art. 15 — Right of Access: Request a copy of your personal data within 1 month;
  • Art. 16 — Right to Rectification: Correct inaccurate personal data;
  • Art. 17 — Right to Erasure ("Right to be Forgotten"): Deletion where no overriding legitimate interest or legal obligation exists;
  • Art. 18 — Right to Restriction: Limit processing pending verification of accuracy or legitimate grounds;
  • Art. 20 — Right to Data Portability: Receive data in JSON/CSV format where technically feasible;
  • Art. 21 — Right to Object: Object to processing based on Art. 6(1)(f) legitimate interests at any time — we will cease unless compelling legitimate grounds override your interests;
  • Art. 22 — Rights re. Automated Decision-Making: You are not subject to purely automated decisions with legal effect without human review, except where you have given explicit consent or it is necessary for a contract;
  • Art. 7(3) — Withdrawal of Consent: Withdraw consent at any time without affecting prior lawful processing.

19.3 Lead Capture — GDPR Compliance

Lead capture forms where a consent notice is configured present a separate, unticked checkbox. Consent is purpose-specific and documented with a timestamp. Withdrawal is available at any time per §7 and §11.

19.4 International Transfers (EU)

Transfers of EU personal data outside the EEA rely on SCCs, adequacy decisions, or derogations per GDPR Art. 49 as appropriate (see §9).

19.5 Supervisory Authority

EU/EEA Data Subjects have the right to lodge a complaint with the supervisory authority in their EU member state of habitual residence or place of work. UK Data Subjects may complain to the Information Commissioner's Office (ICO): ico.org.uk, Tel: +44 303 123 1113.

Section 20

CCPA / CPRA Addendum — California Residents

CCPA 2018CPRA 2023

This section applies to California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

20.1 Categories of Personal Information Collected

In the preceding 12 months we have collected: identifiers (name, email, IP address); internet/network activity (usage data, event logs); geolocation data (inferred from IP); inferences drawn from the above (behavioural profiles). We do not collect sensitive personal information as defined by CPRA without explicit opt-in consent.

20.2 Categories of Sources

Directly from consumers (registration, lead forms, game participation) and automatically (device/network data during platform use).

20.3 Business or Commercial Purpose

Service provision, security, analytics, marketing (only with consent), and legitimate business operations.

20.4 Categories of Third Parties with Whom PI is Shared

Infrastructure subprocessors, quiz hosts (for their event data), legal advisers, law enforcement (when required), business transaction counterparties. We do not sell personal information as defined by CCPA.

20.5 Your CCPA/CPRA Rights

  • Right to Know (§1798.110): Request disclosure of categories and specific pieces of personal information collected;
  • Right to Delete (§1798.105): Request deletion subject to legal exceptions;
  • Right to Correct (§1798.106, CPRA): Request correction of inaccurate personal information;
  • Right to Opt-Out of Sale/Sharing (§1798.120): We do not sell PI. Behavioural data shared with analytics partners is based on legitimate interests; you may opt out by emailing us or visiting /unsubscribe;
  • Right to Limit Use of Sensitive PI (CPRA): Sensitive PI is not collected beyond service necessity;
  • Right to Non-Discrimination (§1798.125): We will not discriminate against you for exercising CCPA/CPRA rights — no denial of service, price differences, or reduced quality;
  • Right to Opt-Out of Automated Decision-Making (CPRA): Contact us to opt out of profiling with significant effects.

20.6 How to Submit a CCPA Request

Email finunigpt@gmail.com with subject "CCPA Request — [Right]." We respond within 45 calendar days (extendable by 45 days with notice). Requests may be submitted on behalf of a minor child by a parent or guardian.

20.7 Authorised Agent

You may designate an authorised agent to submit requests on your behalf. We will require written authorisation and may verify your identity directly.

Do Not Sell My Personal Information: Prazdnik.top does not sell personal information. To opt out of behavioural analytics sharing: prazdnik.top/unsubscribe or email finunigpt@gmail.com.

Section 21

Russian Federal Law No. 152-FZ Addendum

FZ-152Roskomnadzor

This section applies to citizens and residents of the Russian Federation and supplements the general Policy in accordance with Federal Law No. 152-FZ "On Personal Data" (as amended).

21.1 Operator Identity

The operator (оператор персональных данных) for the purposes of FZ-152 is Prazdnik.top. Contact: finunigpt@gmail.com.

21.2 Purpose Limitation

Personal data of Russian citizens is processed strictly for the purposes stated in this Policy: provision of quiz services, security, and (with separate consent) direct marketing. Processing is not carried out for any purposes incompatible with those stated.

21.3 Data Localisation

In accordance with FZ-152 Art. 18.1, the Data Controller acknowledges the requirement to record, systematise, accumulate, store, clarify (update, modify), and retrieve Personal Data of Russian citizens using databases located within the Russian Federation when such data is initially collected. The Controller takes reasonable steps to comply with this requirement for Russian citizens' registration data. Where full compliance is not immediately achievable due to technical infrastructure constraints, the Controller commits to transitioning to compliant infrastructure as technically feasible and notifying Roskomnadzor in accordance with applicable requirements.

21.4 Cross-Border Transfer

Cross-border transfer of personal data of Russian citizens is conducted in accordance with FZ-152 Art. 12. Prior to cross-border transfer, the Controller ensures that the receiving country provides adequate protection of personal data rights, or obtains written consent of the data subject for the transfer.

21.5 Rights of Russian Data Subjects

Citizens of the Russian Federation have the right to: access their personal data; request correction of inaccurate data; request withdrawal of consent and cessation of processing; request deletion of personal data; lodge complaints with Roskomnadzor (rkn.gov.ru). Requests are processed within the timeframes required by FZ-152 (as a rule, within 30 days).

21.6 Consent

Consent for processing personal data of Russian citizens for marketing purposes is obtained separately via an affirmative checkbox at registration. Consent may be withdrawn at any time by contacting finunigpt@gmail.com.

Section 22

CAN-SPAM Act Compliance — Email Marketing

CAN-SPAM ActGDPR Art. 6(1)(a)PECR

All commercial email communications sent by Prazdnik.top comply with the CAN-SPAM Act of 2003 (US), GDPR (EU/UK), and the Privacy and Electronic Communications Regulations (PECR) (UK):

  • Opt-in required: Marketing emails are only sent to users who have explicitly opted in via the marketing consent checkbox at registration or another affirmative mechanism;
  • Sender identification: All marketing emails clearly identify Prazdnik.top as the sender in the "From" field;
  • Subject line accuracy: Subject lines accurately reflect the email content — no deceptive headers;
  • Unsubscribe mechanism: Every marketing email contains a clear, working unsubscribe link (one-click opt-out at /unsubscribe) and the option to reply "UNSUBSCRIBE";
  • Opt-out honoured within 10 business days: Unsubscribe requests are processed within 10 business days and the user will not receive further commercial emails after that period;
  • No sale of unsubscribed addresses: Email addresses on the opt-out list will not be transferred or sold to third parties for marketing purposes;
  • Physical address: Correspondence address: Prazdnik.top, contact via finunigpt@gmail.com.

Transactional emails (password resets, account security alerts, game invitations) are not subject to the opt-in requirement and will be sent regardless of marketing consent.

Unsubscribe instantly: prazdnik.top/unsubscribe — or email finunigpt@gmail.com with "UNSUBSCRIBE" in the subject.

Section 23

COPPA Compliance and Children's Privacy

COPPAGDPR Art. 8Global

23.1 Age Restriction

The Platform is not directed at children under 13 (US) or under 16 (EU/EEA/UK) years of age. Users must be of the applicable age of digital consent in their jurisdiction to register an account. The registration form does not knowingly collect data from underage users. If we discover that a child under 13 (US) or under 16 (EU) has provided personal information without appropriate parental consent, we will delete it immediately.

23.2 Educational Use — Host Responsibilities

Quiz hosts who operate the Platform for educational purposes involving minors take on the following obligations:

  • Obtain and maintain documented parental/guardian consent for all minor participants before enabling their participation;
  • Ensure lead capture forms are not enabled for sessions involving minors unless parental consent specifically covers lead data collection;
  • Provide participants and their parents with notice of data collection and the terms of this Policy;
  • Comply with COPPA (if serving US children under 13), GDPR Art. 8 (if serving EU/EEA/UK children under 16), and any other applicable child-protection legislation.

Host liability: Hosts who fail to obtain appropriate parental consent for minor participants assume full legal liability for any resulting violations of COPPA, GDPR Art. 8, or equivalent laws. Prazdnik.top is not liable for host failures to secure such consent.

23.3 Parental Rights

Parents or guardians of a child may: review personal information collected from their child; request deletion of that information; refuse further collection; and withdraw consent at any time. Requests should be directed to finunigpt@gmail.com with subject "Parental/Guardian Data Request."

Section 24

Cookie Policy and Consent Management

PECRePrivacy DirectiveGDPR

The Platform uses browser localStorage (not HTTP cookies) for session management. A cookie/storage consent notice is displayed on first visit to all public-facing pages. Users may dismiss the notice or clear their browser's localStorage at any time.

24.1 Strictly Necessary Storage (no consent required)

Authentication tokens (qf_jwt), user profile cache (qf_user), and session continuation tokens (qf_session_*) are strictly necessary for the service to function. These cannot be disabled without preventing use of the service.

24.2 Functional Storage (consent or legitimate interests)

Language preference (qf_lang) and cookie notice dismissal (pp_cookie_accept) are functional and improve the user experience. Legal basis: legitimate interests (minimal privacy impact, clearly beneficial to users).

24.3 No Third-Party Tracking

No analytics cookies, advertising pixels, or social media tracking tags are currently deployed. The Platform does not use Google Analytics, Facebook Pixel, or equivalent third-party trackers. If this changes, users will be notified and new consent obtained.

24.4 How to Withdraw

Clear your browser's localStorage via: Browser → Developer Tools → Application → Local Storage → Clear All. Note: this will log you out of all active sessions.

Section 25

Subprocessors and Third-Party Data Processors

The Data Controller engages the following categories of subprocessors that may process personal data on our behalf. All subprocessors are bound by data processing agreements that include GDPR-compliant protections where applicable.

CategoryPurposeData TransferredLocation
Cloud Hosting / VPS ProviderPlatform infrastructure, database hostingAll platform dataAs per hosting provider (disclosed on request)
Email Delivery ServiceTransactional & password-reset emailsEmail address, usernameEU/US (per provider)
Domain Registrar / DNS ProviderDomain name servicesNo personal dataN/A
CDN / Static Asset DeliveryFont delivery (Outfit font)IP address (standard CDN log)Global

For a current list of named subprocessors, or to request Data Processing Agreement (DPA) documentation, contact finunigpt@gmail.com. Subprocessors are reviewed periodically; updates are reflected in this Policy.

Section 26

Data Protection Impact Assessment (DPIA)

GDPR Art. 35

In accordance with GDPR Art. 35, the Data Controller has conducted a Data Protection Impact Assessment for the following high-risk processing activities:

26.1 Automated Profiling and Behavioural Analysis

Activity: Systematic profiling of users based on game participation and interaction patterns to create engagement scores and behavioural profiles.

Risks identified: Potential for inaccurate scoring affecting user treatment; risk of re-identification from combined datasets.

Mitigations applied: Profiles are used for product improvement and aggregated analytics only — not for decisions with legal effect on individuals; anonymisation applied before commercial use; aggregation thresholds prevent individual re-identification; users retain the right to object per GDPR Art. 21.

DPIA Outcome: Processing is proportionate and necessary; risks are adequately mitigated. A supervisory authority consultation (GDPR Art. 36) is not required.

26.2 Lead Capture Data Processing

Activity: Collection of detailed contact information from event participants through lead capture forms.

Risks identified: Broad consent scope; potential for unanticipated downstream use by hosts.

Mitigations applied: Separate per-form consent checkbox; purpose-specific consent text; 5-year retention limit; deletion on request; host contractual obligations.

DPIA Outcome: Processing lawful with mitigations; no Art. 36 consultation required.

Section 27

Legitimate Interests Balancing Tests (GDPR Art. 6(1)(f))

GDPR Art. 6(1)(f)

For each processing activity relying on legitimate interests, the Data Controller has applied the three-part test: (1) Purpose test — is the interest legitimate? (2) Necessity test — is processing necessary? (3) Balancing test — do the Controller's interests override Data Subject interests?

Activity(1) Purpose Test(2) Necessity(3) Balancing Outcome
Security logging & fraud prevention Legitimate — protecting users and the platform from fraud, abuse, and attacks Yes — logs are essential for incident detection and response; no less intrusive alternative Passes. Users expect security monitoring. Minimal additional privacy impact. Interest clearly outweighs individual rights in this context.
Product analytics (anonymised) Legitimate — understanding how users interact with features to improve the product Yes — cannot improve the product without usage data; data is aggregated/anonymised Passes. Once anonymised, not personal data. Individual impact negligible. Strong product improvement interest.
Behavioural profiling (individual) Legitimate — personalisation and commercial analytics Partially — individual profiles beyond anonymised aggregates are not strictly necessary for service Conditional pass. Users retain Art. 21 right to object. Profiling is limited to product improvement; not used for automated decisions with legal effect. Privacy impact mitigated by DPIA (§26). Overriding interest exists but right to object must be honoured.
Business continuity (M&A data transfers) Legitimate — standard business need to retain data through corporate transactions Yes — continuity of service and business operations Passes. Data Subjects are notified of Controller changes; confidentiality obligations imposed on acquirers; no additional processing beyond what was already disclosed.

Right to Object: EU/EEA/UK Users may object to any legitimate-interests processing at any time per GDPR Art. 21. Email finunigpt@gmail.com with subject "Art. 21 Objection." We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Link copied