{
	"legaldoc_privacy": "<p><strong>Puzzel.org privacy policy</strong></p><p>Effective date: 18 September 2026</p><h2>1. Introduction</h2><p>Puzzel.org (\"we\", \"us\" or \"our\") is built and run by Daan Weustenraad in the Netherlands, and we take protecting your privacy seriously. This policy explains what information we collect when you use our services, what we use it for, who we share it with and how we protect it. It is written to comply with the General Data Protection Regulation (GDPR).</p><h2>2. Information we collect</h2><p>If you create an account, we collect the following types of information:</p><ul><li><strong>Personal identification information</strong> — your first name and email address.</li><li><strong>Usage data</strong> — how often your activities are used.</li><li><strong>Technical data</strong> — your browser remembers your active session, so you can pick up the activities you have built where you left off, and similar functional data.</li></ul><h2>3. Why we process your data</h2><p>We process and store your information for one reason: to keep the platform working and as easy to use as possible. It is not used for anything beyond what the platform needs to function.</p><h2>4. Legal basis for processing</h2><p>We process personal data on the following legal grounds:</p><ul><li><strong>Consent</strong> — where you have given your consent, we process your data on that basis.</li><li><strong>Contract</strong> — where processing is needed to fulfil a contract with you.</li><li><strong>Legal obligation</strong> — where we are required to comply with the law.</li></ul><h2>5. How long we keep your data</h2><p>We keep your personal data only for as long as we need it for the purposes we collected it for, including any legal, accounting or reporting requirements.</p><h2>6. Who we share your data with</h2><p>We may share your information with:</p><ul><li><strong>Google Firebase</strong> — provides authentication and the storage of your data.</li><li><strong>Google Classroom</strong> — only when a teacher assigns an activity with grades: the score a student earned, sent to their own submission in that teacher's class (see section 7).</li><li><strong>Your school's learning platform</strong> — only when a teacher adds an activity with grades through LTI: the score a student earned, sent to that course's gradebook (see section 7).</li><li><strong>SendGrid</strong> — sends you email about possible problems with your account and about platform updates.</li><li><strong>Vercel</strong> — hosts and delivers the website and runs its server code.</li><li><strong>Amazon S3</strong> — stores the images, audio and documents you upload.</li><li><strong>Stripe</strong> — handles subscription payments and invoices.</li><li><strong>OpenAI and Google Gemini</strong> — generate content when a teacher uses the AI assistant. In a Wordle with the word check switched on, a guess that isn't in our own word lists is sent to OpenAI as a single word, with nothing that identifies the player.</li><li><strong>Pixabay</strong> — supplies the stock photos a teacher can search from the builder; it receives only the search words.</li><li><strong>Legal authorities</strong> — when required by law, or to protect our legal rights.</li></ul><h2>7. Google Classroom and school gradebooks</h2><p>A teacher can connect Puzzel.org to Google Classroom to put an activity in one of their classes and have each student's score written back to it. Nothing here happens unless a teacher connects it and assigns an activity; playing a Puzzel.org activity from an ordinary link works exactly as described in the rest of this policy.</p><p><strong>What we access, and why</strong></p><ul><li><strong>From the teacher's Google account</strong>, with the teacher's permission on Google's own screen: their Google account ID and email address, to show which account is connected; the list of classes they teach, so they can pick one; and permission to create assignments and set grades in those classes. We do not read class rosters, other students' names or email addresses, or any other coursework.</li><li><strong>From a student who opens an assignment</strong>: the Google account they sign in with — its account ID, name and email address — to check that they are in the class the activity was assigned to, and to put their score on their own submission.</li></ul><p><strong>What we store</strong></p><ul><li>For a teacher: the Google account ID and email address, the permissions they granted, and an encrypted token that lets Puzzel.org set grades in their classes without asking again. The token never leaves our servers.</li><li>For each assignment: which activity it belongs to, the Google class and assignment it created, and for each student who played it the Google account ID, the Classroom submission ID, the score last sent and when. The student's name and email address are stored with their result, as for any player who signs in with Google.</li></ul><p><strong>How scores are calculated and shared</strong>: a score is calculated on our servers from the answers given in the activity — never taken from the student's browser — and the only thing we send to Google is that score, to a submission that already exists in the teacher's class. We do not sell Google user data, use it for advertising, or use it to train AI models, and we transfer it to nobody else.</p><p><strong>How long we keep it</strong>: a student's record on an assignment is removed when the teacher stops syncing that assignment or deletes the activity. When a teacher disconnects Google Classroom, or deletes their account, their token is revoked at Google and deleted. Grades already written to Google Classroom stay there: they belong to the school's gradebook, and the teacher or school manages them in Google Classroom.</p><p><strong>Schools</strong>: when a school uses Puzzel.org with Google Classroom, the school decides what happens with its students' data and Puzzel.org processes it on the school's behalf, only to calculate and deliver scores.</p><p><strong>Your school's own learning platform (LTI)</strong>: a school can also connect Puzzel.org to its own learning platform — such as Moodle, Canvas or Brightspace — through the LTI 1.3 standard. A school administrator registers Puzzel.org once, signed in with a Puzzel.org account. When a student opens a Puzzel.org activity from a course, the platform tells us who they are: the ID the platform uses for them and, if the school's settings share them, their name and email address. We use this only to sign them in to that activity; no Puzzel.org account is created for them. When a teacher has chosen to send scores, we store for each student that platform ID, the address of the gradebook column and the score last sent, and we send the platform only the score, calculated on our servers as described above. We never ask the platform for class lists or other coursework. A student's record on a placement is removed when the teacher stops syncing it or deletes the activity; scores already written stay in the school's gradebook. As with Google Classroom, the school decides what happens with its students' data, and Puzzel.org processes it on the school's behalf.</p><p>Puzzel.org's use and transfer to any other app of information received from Google APIs will adhere to the <a href=\"https://developers.google.com/terms/api-services-user-data-policy\">Google API Services User Data Policy</a>, including the Limited Use requirements.</p><h2>8. International data transfers</h2><p>If we transfer your data outside the European Economic Area (EEA), we make sure an adequate level of protection applies — for example through standard contractual clauses.</p><h2>9. Data security</h2><p>We use appropriate technical and organisational measures to safeguard your data, including restricted access, secure servers and every measure Google Firebase itself takes to comply with regulations: <a href=\"https://firebase.google.com/support/privacy\" rel=\"noopener noreferrer\" target=\"_blank\">https://firebase.google.com/support/privacy</a></p><h2>10. Your rights</h2><p>Under the GDPR you have the following rights:</p><ul><li><strong>Access</strong> — request a copy of your personal data.</li><li><strong>Rectification</strong> — request that inaccurate data is corrected.</li><li><strong>Erasure</strong> — request that your data is deleted.</li><li><strong>Restriction</strong> — request that we limit how we process your data.</li><li><strong>Portability</strong> — receive your data in a structured, commonly used format.</li><li><strong>Objection</strong> — object to processing that is based on legitimate interests.</li><li><strong>Withdrawing consent</strong> — where consent is the basis for processing, withdraw it at any time.</li></ul><h2>11. Automated decision-making and profiling</h2><p>We do not use automated decision-making or profiling that significantly affects you.</p><h2>12. Cookies and tracking</h2><p>Our website uses functional browser storage only, to keep track of your active session — when you are logged in, or when you are creating or playing activities. The one cookie we set is a short-lived one while an activity is opened from a school's learning platform. There are no tracking or advertising cookies. You can clear this storage in your browser settings.</p><h2>13. Changes to this privacy policy</h2><p>We may update this policy from time to time. We will let you know about any material changes with a notice on the website.</p><h2>14. Contact</h2><p>If you have questions or concerns about this policy, or want to exercise any of your rights, contact us at:</p><p><strong>Email:</strong> <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a></p><h2>15. Complaints</h2><p>If you believe we have not complied with applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority in your country.</p>",
	"legaldoc_terms": "<p><strong>Effective date:</strong> 18 September 2026</p><h2>1. Introduction</h2><p>These terms and conditions (the \"Terms\") govern your access to and use of the Puzzel.org website, services and products (together, the \"Services\"). By using the Services you agree to be bound by these Terms. If you do not agree with them, do not use the Services.</p><h2>2. Eligibility</h2><p>To use the Services, you must agree to comply with these Terms and with applicable laws.</p><h2>3. Use of the Services</h2><p>You agree to:</p><ul><li>use the Services only for lawful purposes;</li><li>not misuse the Services or attempt to interfere with them;</li><li>not reverse-engineer, decompile or exploit any part of the Services.</li></ul><h2>4. Account registration</h2><p>If you create an account, you must provide accurate and complete information.</p><h2>5. Fees and payments</h2><ul><li>Any fees that apply to the Services will be clearly communicated.</li><li>Payments must be made on time; otherwise your account privileges may be suspended.</li></ul><h2>6. Intellectual property</h2><ul><li>All original content on the Services, including text, graphics, logos and software, is the property of Puzzel.org or its licensors and is protected by intellectual property laws.</li><li>You keep full ownership of, and all intellectual property rights in, any content you upload to or create on the platform (your \"User Content\").</li><li>By uploading or creating content on the platform, you grant Puzzel.org a non-exclusive, worldwide, royalty-free licence to use, display and distribute that content solely for the purpose of operating the Services.</li><li>Puzzel.org will not claim ownership of your User Content, and will not use it for any purpose outside providing the Services without your explicit consent.</li></ul><h2>7. User Content</h2><ul><li>You keep ownership of any content you submit to the Services.</li><li>By submitting content, you grant us a worldwide, royalty-free licence to use, reproduce, modify and display it for the purpose of providing and improving the Services.</li><li>You represent that you have the rights to any content you submit.</li></ul><h2>8. Google Classroom and other school gradebooks</h2><p>If you connect the Services to Google Classroom or another school gradebook:</p><ul><li>you confirm you are allowed to do so for the classes you choose, and that your school has approved the connection where it requires that;</li><li>for the scores sent to your classes, your school (or you, if you teach independently) decides what happens with students' data, and Puzzel.org processes that data on its behalf, only to calculate scores and deliver them to the assignments you created;</li><li>grades are calculated automatically from the answers given in the activity. Check them before you rely on them — you can change any grade in your gradebook, and a later, better run by a student can replace a grade Puzzel.org sent;</li><li>you can stop sending scores at any time, per assignment or by disconnecting your gradebook.</li></ul><h2>9. Termination</h2><p>We may suspend or terminate your access to the Services if:</p><ul><li>you violate these Terms; or</li><li>your actions harm the Services or other users.</li></ul><p>You may also close your account at any time: delete it from your account dashboard, or ask us to by emailing <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a>.</p><h2>10. Limitation of liability</h2><p>To the fullest extent permitted by law:</p><ul><li>Puzzel.org is not liable for indirect, incidental or consequential damages arising from your use of the Services;</li><li>our liability for direct damages is limited to the amount you paid us in the past 12 months.</li></ul><h2>11. Indemnification</h2><p>You agree to indemnify Puzzel.org and hold it harmless from any claims, losses or damages arising out of your violation of these Terms or your misuse of the Services.</p><h2>12. Changes to these Terms</h2><p>We may update these Terms from time to time. We will notify you of significant changes by a notice on the website. If you continue to use the Services after a change, you accept the updated Terms.</p><h2>13. Governing law</h2><p>These Terms are governed by the laws of the Netherlands. Any dispute will be resolved in the courts of the Netherlands.</p><h2>14. Dispute resolution</h2><p>Disputes may be resolved through <strong>negotiation</strong>: attempt to resolve the dispute informally first.</p><h2>15. Contact</h2><p>If you have questions or concerns about these Terms, email us at <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a>.</p><h2>16. Miscellaneous</h2><ul><li>If any part of these Terms is found to be invalid, the remaining provisions remain enforceable.</li><li>These Terms constitute the entire agreement between you and Puzzel.org.</li></ul>",
	"legaldoc_vendor": "<h3>Company Name</h3><p>Puzzel.org</p><h3>Owner / Main contact / POC</h3><p>Daan Weustenraad — daan@puzzel.org</p><h3>Location/Address</h3><p>Sneekermeer 13, 3825XT, Amersfoort, the Netherlands — <a href=\"https://puzzel.org\" rel=\"noopener noreferrer\" target=\"_blank\">https://puzzel.org</a></p><h3>Product/Service Description (School-subscription)</h3><p>The school subscription gives access to the online platform for creating educational, interactive activities, including uploading your own content.</p><p>It runs for one year and includes:</p><ul><li>an unlimited number of activities</li><li>every feature on the platform</li><li>5 teacher accounts included</li><li>up to 5,000 player sessions a month (both can be scaled up to any number of teachers or player sessions)</li></ul><h3>Does the application need access to school systems or infrastructure (wireless, network, phones, servers, and so on)?</h3><p>Yes — an active internet connection, over either Wi-Fi or a mobile network.</p><h3>How will you access this product / solution? (Local Computer use only, Solution uses internet based login, Solution uses School login?)</h3><p>The solution uses an internet-based login.</p><h3>Do you recommend hard-wired networking connection, or is wireless sufficient?</h3><p>Wireless is sufficient. Pages are light — mostly under 1 MB each.</p><h3>What are your system requirements (minimal and recommended) for the following:</h3><p>Any current browser: Chrome, Firefox, Safari and Edge all work. Internet Explorer is too old and is not supported. No plugins such as Flash are needed.</p><h3>On what Display size/resolution does your platform work?</h3><p>The website is fully responsive, so it works on mobile devices as well as desktop computers.</p><p>Building activities is best done on a desktop computer or a tablet: the larger screen keeps an overview of what you are building.</p><h3>Recommended graphics card and memory?</h3><p>Not a factor — the website runs on any reasonably modern hardware.</p><h3>Does your application require any (app) installation?</h3><p>No. It is a complete web application and runs entirely in the browser.</p><h3>Will this product / solution be used with any data or information?</h3><p>Not by default. The platform uses no tracking cookies or ads at all. Staying signed in uses the browser's own storage, not a cookie.</p><p>When creating an activity, the owner can switch on 'Keep track of stats' and 'Force registration' to collect individual activity results. Each registration field is chosen by hand, so the form can be kept as privacy-friendly as possible.</p><h3>Which data fields or types of data might be used with this product? (First name, last name, date of birth, student ID, email address, dates, keywords, text, photos, video, audio, biometric data, and so on.)</h3><p>Each of these is entirely optional:</p><ul><li>Activity results</li><li>Educational content</li><li>First name / last name / email address / student ID</li></ul><h3>If known, what data types will be used with this resource? (HIPAA, FERPA, PII, PCI, CUI, Research Data, OTHER)</h3><p>Optionally, PII: first name and last name, email address, student ID.</p><h3>What is the anticipated timeframe for implementing this solution?</h3><p>It can be used immediately — all the puzzle generators are publicly available. Upgrading to a paid subscription also takes effect immediately.</p><h3>What needs to be unblocked/whitelisted with our filter/firewall for this service to work?</h3><p>For Puzzel.org to work fully, allow the following hosts:</p><ul><li>puzzel.org — the application itself</li><li>puzzelorg-cdn.s3.us-west-1.amazonaws.com — images and audio uploaded by accounts stored in the US</li><li>puzzelorg-image-cdn.s3.eu-north-1.amazonaws.com — images and audio uploaded by accounts stored in the EU</li><li>*.googleapis.com — sign-in and token refresh (Firebase Authentication)</li><li>puzzelorg.firebaseapp.com — the sign-in pop-up for Google and Microsoft accounts</li><li>wss://puzzelorg.firebaseio.com — realtime database, accounts stored in the US</li><li>wss://puzzelorg-2.europe-west1.firebasedatabase.app — realtime database, accounts stored in the EU</li><li>checkout.stripe.com — only while buying or renewing a subscription</li></ul><p>The realtime database connects over a websocket, which is the rule a strict content filter tends to drop silently: if activities open but results never save, that is the rule to look at first. Only the region your account uses is needed — a US account never contacts the EU database, and the other way round. Stripe can stay blocked on classroom devices.</p><h3>Are any of your servers overseas? If so, what nations?</h3><p>Data is stored in the EU or in the United States: a new account gets the region its browser timezone suggests, and Europe and Africa get the EU. Two settings decide where, independently of each other:</p><ul><li>Account data: a Google Firebase realtime database in europe-west1, Belgium, or in us-central1, United States.</li><li>Files: an Amazon S3 bucket in us-west-1 (California) or eu-north-1 (Stockholm). Existing files keep working after a switch.</li></ul><p>A new account starts in the region its browser timezone suggests — Europe and Africa get the EU database — and either setting can be changed afterwards. Moving account data to the other region runs as a background migration and needs a paid subscription. The application is hosted and delivered through the CDN of <a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a>.</p><h3>Does your program utilize a caching server?</h3><p>Only for static content pages.</p><h3>Does your service require e-mail interaction with students?</h3><p>No. All communication runs through the activity owner, who in most cases is the teacher.</p><h3>Does your software support any integrations?</h3><p>Four routes in:</p><ul><li>Your school's learning platform, over LTI 1.3. The admin pastes one link into the tool setup — Moodle, Canvas and Brightspace do that automatically; Schoology, Blackboard and itslearning are set up with us first. A teacher then picks one of their own activities into a course, and the score a student earns is written back to that course's gradebook.</li><li>Google Classroom: a teacher assigns an activity to one of their classes, and the score is returned to the student's own submission.</li><li>Anything else: copy the embed code and paste it into any page — no integration work needed. This is how Puzzel.org is mainly used.</li><li>A REST API can create activities from your own systems, capped at 10 requests a day per key.</li></ul><h3>Do teachers have individual logins?</h3><p>Yes. Each teacher creates their own login with their email address. That individual login can later be connected to a school-account subscription, where available.</p><h3>Does your product come with unlimited technical support?</h3><p>Yes — by email, <a href=\"mailto:daan@puzzel.org\" rel=\"noopener noreferrer\" target=\"_blank\">daan@puzzel.org</a>.</p><p>(Provided you put some effort into trying features and reading the existing documentation.) Available between 9 AM and 10 PM (CET).</p><h3>Do we have a portal to manage our students?</h3><p>Yes and no. Students can register (if you force registration) and, when they solve activities while signed in, you have access to their activity results. You have no control over their accounts, though.</p><p>You can delete any of their results at any time.</p><h3>Do you have customizable roles in the administrative console?</h3><p>No. There is little hierarchy in Puzzel.org: only the school-account owner has extra rights, namely to invite other teachers to join the main school account (which gives them Premium access).</p><h3>Do you offer training and of what does it consist?</h3><p>No, but there is a good amount of documentation in the features and activity-builder sections, and questions are always welcome by email. The platform is also designed to be easy to pick up.</p><h3>Does any of our data have to be imported into your program?</h3><p>No. Importing data is not a requirement at all.</p><h3>Describe the process and timeline you will use to notify the school should a data breach be discovered. Please include the point of contact who will notify the school, what the notification will contain, and how and in what format it will be sent.</h3><p>Account holders are notified by email. The point of contact at Puzzel.org is Daan Weustenraad (see details above). The notification describes the breach, who was affected and what the consequences are.</p><h3>The infrastructure (hosts, network equipment, etc.) hosting the application must be located in a locked cage-type environment. A Tier 2 data center (or better) or Cloud Service Provider, such as AWS, Google, or Azure physical infrastructure is preferred.</h3><p>The application is hosted by <a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a>, one of the larger application delivery networks, and is therefore secured in the best possible way. Accounts, activities and results sit in a Google Firebase realtime database; uploaded images and audio are stored in Amazon S3.</p><p><a href=\"https://firebase.google.com/support/privacy\" rel=\"noopener noreferrer\" target=\"_blank\">More about Google Firebase</a></p><p>The full list of sub-processors — no other party receives account or player data:</p><ul><li><a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a> — application hosting and delivery</li><li><a href=\"https://firebase.google.com\" rel=\"noopener noreferrer\" target=\"_blank\">Google Firebase</a> — authentication and the realtime database holding account data</li><li><a href=\"https://aws.amazon.com/s3/\" rel=\"noopener noreferrer\" target=\"_blank\">Amazon S3</a> — storage for uploaded images and audio</li><li><a href=\"https://stripe.com\" rel=\"noopener noreferrer\" target=\"_blank\">Stripe</a> — subscription payments and invoicing</li><li><a href=\"https://openai.com\" rel=\"noopener noreferrer\" target=\"_blank\">OpenAI</a> — generates content when a teacher uses the AI assistant, and checks whether a Wordle guess is a real word</li><li><a href=\"https://ai.google.dev\" rel=\"noopener noreferrer\" target=\"_blank\">Google Gemini</a> — generates images and reads the documents and pictures a teacher imports with the AI assistant</li><li><a href=\"https://sendgrid.com\" rel=\"noopener noreferrer\" target=\"_blank\">Twilio SendGrid</a> — sends the platform's email: welcome and payment mails, invitations and product updates</li><li><a href=\"https://pixabay.com\" rel=\"noopener noreferrer\" target=\"_blank\">Pixabay</a> — supplies the free stock photos a teacher can search from the builder</li></ul><h3>The infrastructure hosting the application must keep the data separate from other customers' data. This can be done through physical (airgap, separate servers, etc.) or logical (VLAN, subnets, security tags, virtual hosts, etc.) means. Describe how this is accomplished.</h3><p>Logically, through authentication. While signed in to your account, you only reach the data stored by you as the activity owner, or on behalf of your activities (the activity players' data). This is fully enforced by the Firebase Security Rules implementation.</p><p><a href=\"https://firebase.google.com/docs/rules\" rel=\"noopener noreferrer\" target=\"_blank\">More on Firebase Security Rules</a></p><h3>The data must always be encrypted while in transit, while in use and at rest, without exception. Describe how this is accomplished.</h3><p>Traffic is HTTPS end to end, and account data is encrypted in transit and at rest by Google Firebase.</p><p><em>'Firebase services encrypt data in transit using HTTPS and logically isolate customer data.'</em> — Firebase</p><p><a href=\"https://firebase.google.com/support/privacy#data_encryption\" rel=\"noopener noreferrer\" target=\"_blank\">More on Data Encryption</a></p><p>Two exceptions to know about. Uploaded images and audio are stored in Amazon S3 and served from a public URL — treat them as public and keep anything confidential out of activity media. The AI assistant is used per query: what a teacher types is sent to OpenAI or Google Gemini to generate content. One thing a player types can reach OpenAI: in a Wordle with the word check switched on, a guess that isn't in our own word lists is sent as a single word, with nothing that identifies the player.</p><h3>How will you authenticate users? What options exist (Local/manual, SSO, SAML, Clever, etc.)?</h3><p>Authentication runs through Google Firebase. Teachers sign in with an email address and password, or with the Google or Microsoft account your school already manages. Players stay anonymous unless a teacher switches registration on for an activity.</p><p>Embedded activities support OIDC single sign-on: your portal passes a signed token, which is checked against your identity provider's published keys before a player is let in. Issuers are allow-listed per account and set up on request. There is no Clever, ClassLink or SAML connector today.</p><p><a href=\"https://firebase.google.com/docs/auth\" rel=\"noopener noreferrer\" target=\"_blank\">https://firebase.google.com/docs/auth</a></p><h3>Provide information on the account termination process</h3><p>A user account can be deleted at any time. This completely wipes every record of its activities and their activity results.</p><h3>Please describe who has access to the account data?</h3><p>Only the activity owner has access to their own data. Puzzel.org staff can access an account for debugging purposes, but never without an explicit request from the account holder.</p><h3>Do you accept payment by PO?</h3><p>Yes, when the PO can be paid by card or bank transfer. Cheques cannot be accepted, as Puzzel.org is not based in the US. Payments run through Stripe, so card details never reach Puzzel.org's own systems. If you need a formal document before ordering, the quote builder produces a PDF quote with your school's details on it.</p><h3>Does this product or solution have the ability to accept payments of any type?</h3><p>Yes. Credit or debit card, PayPal, Apple Pay and Google Pay are accepted in every currency; when paying in euros, iDEAL, Bancontact, Giropay and other local methods are offered as well, and bank transfer is available. Every payment runs through Stripe. The full list for your country is shown on the pricing page.</p>"
}
