PRIVACY POLICY

Minigolf gamification system (system name)

1. General information

  1. This Privacy Policy sets out the rules for processing personal data in connection with the use of the IT system (system name), intended for player registration and sports tournament management.
  2. The controller of personal data is (full client name), with its registered office at (…), Tax ID: (…), REGON: (…) (hereinafter: the “Controller”).
  3. The Controller may be contacted regarding personal data protection matters at the following e-mail address: (…) and telephone number (…).

2. Scope of the System's functionality

The System enables, in particular:

  1. running minigolf games,
  2. saving results and creating rankings,
  3. user registration in two modes:
    • basic (anonymous) mode – using a nickname / pseudonym,
    • extended account – including contact details (e-mail address, phone number) in order to participate in the loyalty program and receive communications,
  4. taking photos during the game and sharing them on social media.

3. Scope of processed data

a) Identification data (basic mode)

  • nickname / pseudonym,
  • user identifier,
  • game results and ranking position.

b) Identification and contact data (extended account)

  • first name (optionally surname),
  • e-mail address,
  • phone number,
  • application identifier (push token – in the case of a mobile app).

c) Data related to activity in the System

  • game history,
  • results obtained,
  • ranking,
  • information about loyalty points earned.

d) Marketing data

  • marketing consents (split by channel),
  • history of granted and withdrawn consents,
  • communication preferences (preference center).

e) Image data (optional)

  • photos taken during the game – only to the extent described in section VII.

f) Technical data

  • IP address,
  • device and browser data,
  • system logs.

4. Purposes and legal bases for processing

Personal data is processed with a clear separation of purposes:

1. Game operation and rankings

PurposeLegal basis
Account creation and game operationArt. 6(1)(b) GDPR
Saving results and creating rankingsArt. 6(1)(b) GDPR
Technical and service communications (e.g. password reset, system error information)Art. 6(1)(b) GDPR
Ensuring security and preventing abuseArt. 6(1)(f) GDPR

Service communications do not constitute marketing and do not require separate consent.

2. Loyalty program

PurposeLegal basis
Participation in the loyalty programArt. 6(1)(b) GDPR
Accumulation and redemption of pointsArt. 6(1)(b) GDPR

3. Marketing and promotional communication

PurposeLegal basis
Newsletter distribution (e-mail)Art. 6(1)(a) GDPR
SMS distributionArt. 6(1)(a) GDPR
Push notificationsArt. 6(1)(a) GDPR
Marketing profiling (if used)Art. 6(1)(a) GDPR

Marketing consents:

  1. are voluntary,
  2. are granted separately for each channel (e-mail / SMS / push),
  3. may be withdrawn at any time,
  4. a preference center is available to manage communication independently.

5. Data recipients

  1. Personal data may be transferred to:
    1. the IT system provider (processor),
    2. the hosting provider,
    3. providers of e-mail, SMS and push delivery tools,
    4. analytics tool providers,
    5. accounting entities (if applicable),
    6. payment operators (if a payment function is introduced).
  2. Data is not transferred outside the European Economic Area unless the tools used provide for such transfer while ensuring appropriate safeguards.

6. Data retention period

Data categoryRetention period
User accountuntil account deletion or 3 years from the last activity
Results and rankingsup to 5 years
Loyalty program datauntil the end of the program + 3 years
Marketing datauntil consent is withdrawn
Technical logsup to 24 months
Photos (if stored on the server)until consent is withdrawn or a maximum of 3 years

7. Photos and image

The System may operate in two variants:

1) Variant 1 – local photos

The photo is taken solely on the user's device and is not sent to the Controller's server. In such a case, the Controller does not process image data.

2) Variant 2 – upload to server

If the photo upload functionality is enabled:

  1. the photo constitutes personal data (image),
  2. processing is based on Art. 6(1)(a) GDPR (consent),
  3. the user declares that they have the consent of persons visible in the photo,
  4. the Controller may moderate content (UGC),
  5. it is possible to report infringement of image rights.

8. Minors

If the System may be used by persons under 18 years of age:

  1. an extended account may require confirmation of consent by a legal guardian,
  2. marketing is not directed to minors,
  3. social features may be limited,
  4. age verification mechanisms are applied.

9. Rights of data subjects

Each person has the right to:

  1. access data,
  2. rectify data,
  3. erase data,
  4. restrict processing,
  5. data portability,
  6. object to processing,
  7. withdraw consent at any time,
  8. lodge a complaint with the President of the Personal Data Protection Office.

10. Automated decision-making

Data is not used for automated decision-making within the meaning of Art. 22 GDPR, unless the user gives separate consent to marketing profiling.

11. Data security

The Controller applies appropriate technical and organizational measures, in particular:

  1. transmission encryption (SSL),
  2. password encryption,
  3. access control,
  4. operation logging,
  5. backups,
  6. security testing,
  7. the data minimization principle.

12. Cookies

  1. The System uses cookies:
    1. necessary – ensuring proper functioning of the System,
    2. analytics – used for statistical analysis,
    3. marketing – used for advertising purposes.
  2. Analytics and marketing cookies are used only after obtaining the user's consent.
  3. During the first login to the System, a cookie banner is displayed allowing the user to:
    1. grant consent,
    2. reject optional cookies,
    3. change settings at any time.
  4. The user may independently change cookie settings.

13. Changes to the Policy

  1. The Controller may update the Policy in the event of changes in the law or the System's functionality.
  2. Current and archived versions of the Policy are always available in the System.