PRIVACY POLICY
Minigolf gamification system (system name)
1. General information
- This Privacy Policy sets out the rules for processing personal data in connection with the use of the IT system (system name), intended for player registration and sports tournament management.
- The controller of personal data is (full client name), with its registered office at (…), Tax ID: (…), REGON: (…) (hereinafter: the “Controller”).
- The Controller may be contacted regarding personal data protection matters at the following e-mail address: (…) and telephone number (…).
2. Scope of the System's functionality
The System enables, in particular:
- running minigolf games,
- saving results and creating rankings,
- user registration in two modes:
- basic (anonymous) mode – using a nickname / pseudonym,
- extended account – including contact details (e-mail address, phone number) in order to participate in the loyalty program and receive communications,
- taking photos during the game and sharing them on social media.
3. Scope of processed data
a) Identification data (basic mode)
- nickname / pseudonym,
- user identifier,
- game results and ranking position.
b) Identification and contact data (extended account)
- first name (optionally surname),
- e-mail address,
- phone number,
- application identifier (push token – in the case of a mobile app).
c) Data related to activity in the System
- game history,
- results obtained,
- ranking,
- information about loyalty points earned.
d) Marketing data
- marketing consents (split by channel),
- history of granted and withdrawn consents,
- communication preferences (preference center).
e) Image data (optional)
- photos taken during the game – only to the extent described in section VII.
f) Technical data
- IP address,
- device and browser data,
- system logs.
4. Purposes and legal bases for processing
Personal data is processed with a clear separation of purposes:
1. Game operation and rankings
| Purpose | Legal basis |
|---|---|
| Account creation and game operation | Art. 6(1)(b) GDPR |
| Saving results and creating rankings | Art. 6(1)(b) GDPR |
| Technical and service communications (e.g. password reset, system error information) | Art. 6(1)(b) GDPR |
| Ensuring security and preventing abuse | Art. 6(1)(f) GDPR |
Service communications do not constitute marketing and do not require separate consent.
2. Loyalty program
| Purpose | Legal basis |
|---|---|
| Participation in the loyalty program | Art. 6(1)(b) GDPR |
| Accumulation and redemption of points | Art. 6(1)(b) GDPR |
3. Marketing and promotional communication
| Purpose | Legal basis |
|---|---|
| Newsletter distribution (e-mail) | Art. 6(1)(a) GDPR |
| SMS distribution | Art. 6(1)(a) GDPR |
| Push notifications | Art. 6(1)(a) GDPR |
| Marketing profiling (if used) | Art. 6(1)(a) GDPR |
Marketing consents:
- are voluntary,
- are granted separately for each channel (e-mail / SMS / push),
- may be withdrawn at any time,
- a preference center is available to manage communication independently.
5. Data recipients
- Personal data may be transferred to:
- the IT system provider (processor),
- the hosting provider,
- providers of e-mail, SMS and push delivery tools,
- analytics tool providers,
- accounting entities (if applicable),
- payment operators (if a payment function is introduced).
- Data is not transferred outside the European Economic Area unless the tools used provide for such transfer while ensuring appropriate safeguards.
6. Data retention period
| Data category | Retention period |
|---|---|
| User account | until account deletion or 3 years from the last activity |
| Results and rankings | up to 5 years |
| Loyalty program data | until the end of the program + 3 years |
| Marketing data | until consent is withdrawn |
| Technical logs | up to 24 months |
| Photos (if stored on the server) | until consent is withdrawn or a maximum of 3 years |
7. Photos and image
The System may operate in two variants:
1) Variant 1 – local photos
The photo is taken solely on the user's device and is not sent to the Controller's server. In such a case, the Controller does not process image data.
2) Variant 2 – upload to server
If the photo upload functionality is enabled:
- the photo constitutes personal data (image),
- processing is based on Art. 6(1)(a) GDPR (consent),
- the user declares that they have the consent of persons visible in the photo,
- the Controller may moderate content (UGC),
- it is possible to report infringement of image rights.
8. Minors
If the System may be used by persons under 18 years of age:
- an extended account may require confirmation of consent by a legal guardian,
- marketing is not directed to minors,
- social features may be limited,
- age verification mechanisms are applied.
9. Rights of data subjects
Each person has the right to:
- access data,
- rectify data,
- erase data,
- restrict processing,
- data portability,
- object to processing,
- withdraw consent at any time,
- lodge a complaint with the President of the Personal Data Protection Office.
10. Automated decision-making
Data is not used for automated decision-making within the meaning of Art. 22 GDPR, unless the user gives separate consent to marketing profiling.
11. Data security
The Controller applies appropriate technical and organizational measures, in particular:
- transmission encryption (SSL),
- password encryption,
- access control,
- operation logging,
- backups,
- security testing,
- the data minimization principle.
12. Cookies
- The System uses cookies:
- necessary – ensuring proper functioning of the System,
- analytics – used for statistical analysis,
- marketing – used for advertising purposes.
- Analytics and marketing cookies are used only after obtaining the user's consent.
- During the first login to the System, a cookie banner is displayed allowing the user to:
- grant consent,
- reject optional cookies,
- change settings at any time.
- The user may independently change cookie settings.
13. Changes to the Policy
- The Controller may update the Policy in the event of changes in the law or the System's functionality.
- Current and archived versions of the Policy are always available in the System.