{
	"legaldoc_privacy": "<p><strong>Puzzel.org privacy policy</strong></p><p>Effective date: 15 November 2024</p><h2>1. Introduction</h2><p>Puzzel.org (\"we\", \"us\" or \"our\") is built and run by Daan Weustenraad in the Netherlands, and we take protecting your privacy seriously. This policy explains what information we collect when you use our services, what we use it for, who we share it with and how we protect it. It is written to comply with the General Data Protection Regulation (GDPR).</p><h2>2. Information we collect</h2><p>If you create an account, we collect the following types of information:</p><ul><li><strong>Personal identification information</strong> — your first name and email address.</li><li><strong>Usage data</strong> — how often your activities are used.</li><li><strong>Technical data</strong> — a cookie that stores your active session, so you can pick up the activities you have built where you left off, and similar functional data.</li></ul><h2>3. Why we process your data</h2><p>We process and store your information for one reason: to keep the platform working and as easy to use as possible. It is not used for anything beyond what the platform needs to function.</p><h2>4. Legal basis for processing</h2><p>We process personal data on the following legal grounds:</p><ul><li><strong>Consent</strong> — where you have given your consent, we process your data on that basis.</li><li><strong>Contract</strong> — where processing is needed to fulfil a contract with you.</li><li><strong>Legal obligation</strong> — where we are required to comply with the law.</li></ul><h2>5. How long we keep your data</h2><p>We keep your personal data only for as long as we need it for the purposes we collected it for, including any legal, accounting or reporting requirements.</p><h2>6. Who we share your data with</h2><p>We may share your information with:</p><ul><li><strong>Google Firebase</strong> — provides authentication and the storage of your data.</li><li><strong>SendGrid</strong> — sends you email about possible problems with your account and about platform updates.</li><li><strong>Legal authorities</strong> — when required by law, or to protect our legal rights.</li></ul><h2>7. International data transfers</h2><p>If we transfer your data outside the European Economic Area (EEA), we make sure an adequate level of protection applies — for example through standard contractual clauses.</p><h2>8. Data security</h2><p>We use appropriate technical and organisational measures to safeguard your data, including restricted access, secure servers and every measure Google Firebase itself takes to comply with regulations: <a href=\"https://firebase.google.com/support/privacy\" rel=\"noopener noreferrer\" target=\"_blank\">https://firebase.google.com/support/privacy</a></p><h2>9. Your rights</h2><p>Under the GDPR you have the following rights:</p><ul><li><strong>Access</strong> — request a copy of your personal data.</li><li><strong>Rectification</strong> — request that inaccurate data is corrected.</li><li><strong>Erasure</strong> — request that your data is deleted.</li><li><strong>Restriction</strong> — request that we limit how we process your data.</li><li><strong>Portability</strong> — receive your data in a structured, commonly used format.</li><li><strong>Objection</strong> — object to processing that is based on legitimate interests.</li><li><strong>Withdrawing consent</strong> — where consent is the basis for processing, withdraw it at any time.</li></ul><h2>10. Automated decision-making and profiling</h2><p>We do not use automated decision-making or profiling that significantly affects you.</p><h2>11. Cookies and tracking</h2><p>Our website uses functional cookies only, to keep track of your active session — when you are logged in, or when you are creating or playing activities. You can control your cookie preferences in your browser settings.</p><h2>12. Changes to this privacy policy</h2><p>We may update this policy from time to time. We will let you know about any material changes with a notice on the website.</p><h2>13. Contact</h2><p>If you have questions or concerns about this policy, or want to exercise any of your rights, contact us at:</p><p><strong>Email:</strong> <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a></p><h2>14. Complaints</h2><p>If you believe we have not complied with applicable data protection law, you have the right to lodge a complaint with the relevant supervisory authority in your country.</p>",
	"legaldoc_terms": "<p><strong>Effective date:</strong> 15 November 2024</p><h2>1. Introduction</h2><p>These terms and conditions (the \"Terms\") govern your access to and use of the Puzzel.org website, services and products (together, the \"Services\"). By using the Services you agree to be bound by these Terms. If you do not agree with them, do not use the Services.</p><h2>2. Eligibility</h2><p>To use the Services, you must agree to comply with these Terms and with applicable laws.</p><h2>3. Use of the Services</h2><p>You agree to:</p><ul><li>use the Services only for lawful purposes;</li><li>not misuse the Services or attempt to interfere with them;</li><li>not reverse-engineer, decompile or exploit any part of the Services.</li></ul><h2>4. Account registration</h2><p>If you create an account, you must provide accurate and complete information.</p><h2>5. Fees and payments</h2><ul><li>Any fees that apply to the Services will be clearly communicated.</li><li>Payments must be made on time; otherwise your account privileges may be suspended.</li></ul><h2>6. Intellectual property</h2><ul><li>All original content on the Services, including text, graphics, logos and software, is the property of Puzzel.org or its licensors and is protected by intellectual property laws.</li><li>You keep full ownership of, and all intellectual property rights in, any content you upload to or create on the platform (your \"User Content\").</li><li>By uploading or creating content on the platform, you grant Puzzel.org a non-exclusive, worldwide, royalty-free licence to use, display and distribute that content solely for the purpose of operating the Services.</li><li>Puzzel.org will not claim ownership of your User Content, and will not use it for any purpose outside providing the Services without your explicit consent.</li></ul><h2>7. User Content</h2><ul><li>You keep ownership of any content you submit to the Services.</li><li>By submitting content, you grant us a worldwide, royalty-free licence to use, reproduce, modify and display it for the purpose of providing and improving the Services.</li><li>You represent that you have the rights to any content you submit.</li></ul><h2>8. Termination</h2><p>We may suspend or terminate your access to the Services if:</p><ul><li>you violate these Terms; or</li><li>your actions harm the Services or other users.</li></ul><p>You may also close your account at any time: delete it from your account dashboard, or ask us to by emailing <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a>.</p><h2>9. Limitation of liability</h2><p>To the fullest extent permitted by law:</p><ul><li>Puzzel.org is not liable for indirect, incidental or consequential damages arising from your use of the Services;</li><li>our liability for direct damages is limited to the amount you paid us in the past 12 months.</li></ul><h2>10. Indemnification</h2><p>You agree to indemnify Puzzel.org and hold it harmless from any claims, losses or damages arising out of your violation of these Terms or your misuse of the Services.</p><h2>11. Changes to these Terms</h2><p>We may update these Terms from time to time. We will notify you of significant changes by a notice on the website. If you continue to use the Services after a change, you accept the updated Terms.</p><h2>12. Governing law</h2><p>These Terms are governed by the laws of the Netherlands. Any dispute will be resolved in the courts of the Netherlands.</p><h2>13. Dispute resolution</h2><p>Disputes may be resolved through <strong>negotiation</strong>: attempt to resolve the dispute informally first.</p><h2>14. Contact</h2><p>If you have questions or concerns about these Terms, email us at <a href=\"mailto:daan@puzzel.org\">daan@puzzel.org</a>.</p><h2>15. Miscellaneous</h2><ul><li>If any part of these Terms is found to be invalid, the remaining provisions remain enforceable.</li><li>These Terms constitute the entire agreement between you and Puzzel.org.</li></ul>",
	"legaldoc_vendor": "<h3>Company Name</h3><p>Puzzel.org</p><h3>Owner / Main contact / POC</h3><p>Daan Weustenraad — daan@puzzel.org</p><h3>Location/Address</h3><p>Sneekermeer 13, 3825XT, Amersfoort, the Netherlands — <a href=\"https://puzzel.org\" rel=\"noopener noreferrer\" target=\"_blank\">https://puzzel.org</a></p><h3>Product/Service Description (School-subscription)</h3><p>The school subscription gives access to the online platform for creating educational, interactive activities, including uploading your own content.</p><p>It runs for one year and includes:</p><ul><li>an unlimited number of activities</li><li>every feature on the platform</li><li>5 teacher accounts included</li><li>up to 5,000 player sessions a month (both can be scaled up to any number of teachers or player sessions)</li></ul><h3>Will the application/solution require access to a University or USG Resource? (Banner, OneUsg, Wireless, Network, Phones, Servers, etc)?</h3><p>Yes — an active internet connection, over either Wi-Fi or a mobile network.</p><h3>How will you access this product / solution? (Local Computer use only, Solution uses internet based login, Solution uses School login?)</h3><p>The solution uses an internet-based login.</p><h3>Do you recommend hard-wired networking connection, or is wireless sufficient?</h3><p>Wireless is sufficient. Pages are light — mostly under 1 MB each.</p><h3>What are your system requirements (minimal and recommended) for the following:</h3><p>Any current browser: Chrome, Firefox, Safari and Edge all work. Internet Explorer is too old and is not supported. No plugins such as Flash are needed.</p><h3>On what Display size/resolution does your platform work?</h3><p>The website is fully responsive, so it works on mobile devices as well as desktop computers.</p><p>Building activities is best done on a desktop computer or a tablet: the larger screen keeps an overview of what you are building.</p><h3>Recommended graphics card and memory?</h3><p>Not a factor — the website runs on any reasonably modern hardware.</p><h3>Does your application require any (app) installation?</h3><p>No. It is a complete web application and runs entirely in the browser.</p><h3>Will this product / solution be used with any data or information?</h3><p>Not by default. The platform uses no tracking cookies or ads at all — only a session cookie that keeps the user signed in.</p><p>When creating an activity, the owner can switch on 'Keep track of stats' and 'Force registration' to collect individual activity results. Each registration field is chosen by hand, so the form can be kept as privacy-friendly as possible.</p><h3>Please identify the data fields or information (or types of data ) that might or will be used with this product / solution? (FN, LN, DOB, Eagle ID, Email, Date, Keywords, Text, Photos, Video, Audio, Biometric data, etc.)</h3><p>Each of these is entirely optional:</p><ul><li>Activity results</li><li>Educational content</li><li>First name / last name / email address / student ID</li></ul><h3>If known, what data types will be used with this resource? (HIPAA, FERPA, PII, PCI, CUI, Research Data, OTHER)</h3><p>Optionally, PII: first name and last name, email address, student ID.</p><h3>What is the anticipated timeframe for implementing this solution?</h3><p>It can be used immediately — all the puzzle generators are publicly available. Upgrading to a paid subscription also takes effect immediately.</p><h3>What needs to be unblocked/whitelisted with our filter/firewall for this service to work?</h3><p>For Puzzel.org to work fully, allow the following hosts:</p><ul><li>puzzel.org — the application itself</li><li>puzzelorg-cdn.s3.us-west-1.amazonaws.com — images and audio uploaded by accounts stored in the US</li><li>puzzelorg-image-cdn.s3.eu-north-1.amazonaws.com — images and audio uploaded by accounts stored in the EU</li><li>*.googleapis.com — sign-in and token refresh (Firebase Authentication)</li><li>puzzelorg.firebaseapp.com — the sign-in pop-up for Google and Microsoft accounts</li><li>wss://puzzelorg.firebaseio.com — realtime database, accounts stored in the US</li><li>wss://puzzelorg-2.europe-west1.firebasedatabase.app — realtime database, accounts stored in the EU</li><li>fonts.googleapis.com, fonts.gstatic.com — web fonts</li><li>checkout.stripe.com — only while buying or renewing a subscription</li></ul><p>The realtime database connects over a websocket, which is the rule a strict content filter tends to drop silently: if activities open but results never save, that is the rule to look at first. Only the region your account uses is needed — a US account never contacts the EU database, and the other way round. Stripe can stay blocked on classroom devices.</p><h3>Are any of your servers overseas? If so, what nations?</h3><p>Data is stored in the United States by default, with an EU option. Two settings decide where, independently of each other:</p><ul><li>Account data: a Google Firebase realtime database in the United States (the default) or in europe-west1, Belgium.</li><li>Files: an Amazon S3 bucket in us-west-1 (California) or eu-north-1 (Stockholm). Existing files keep working after a switch.</li></ul><p>A new account starts in the region its browser timezone suggests — Europe and Africa get the EU database — and either setting can be changed afterwards. Moving account data to the other region runs as a background migration and needs a paid subscription. The application is hosted and delivered through the CDN of <a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a>.</p><h3>Does your program utilize a caching server?</h3><p>Only for static content pages.</p><h3>Does your service require e-mail interaction with students?</h3><p>No. All communication runs through the activity owner, who in most cases is the teacher.</p><h3>Does your software support any integrations?</h3><p>Three routes in:</p><ul><li>Canvas: an LTI launch lets a teacher pick one of their own activities and drops it into the page as an embed.</li><li>Anything else: copy the embed code and paste it into any page — no integration work needed. This is how Puzzel.org is mainly used.</li><li>A REST API can create activities from your own systems, capped at 10 requests a day per key.</li></ul><h3>Do teachers have individual logins?</h3><p>Yes. Each teacher creates their own login with their email address. That individual login can later be connected to a school-account subscription, where available.</p><h3>Does your product come with unlimited technical support?</h3><p>Yes — by email, <a href=\"mailto:daan@puzzel.org\" rel=\"noopener noreferrer\" target=\"_blank\">daan@puzzel.org</a>.</p><p>(Provided you put some effort into trying features and reading the existing documentation.) Available between 9 AM and 10 PM (CET).</p><h3>Do we have a portal to manage our students?</h3><p>Yes and no. Students can register (if you force registration) and, when they solve activities while signed in, you have access to their activity results. You have no control over their accounts, though.</p><p>You can delete any of their results at any time.</p><h3>Do you have customizable roles in the administrative console?</h3><p>No. There is little hierarchy in Puzzel.org: only the school-account owner has extra rights, namely to invite other teachers to join the main school account (which gives them Premium access).</p><h3>Do you offer training and of what does it consist?</h3><p>No, but there is a good amount of documentation in the features and activity-builder sections, and questions are always welcome by email. The platform is also designed to be easy to pick up.</p><h3>Does any of our data have to be imported into your program?</h3><p>No. Importing data is not a requirement at all.</p><h3>Describe the process and timeline you will utilize to notify the School should a data breach be discovered. Please include the company POC who will notify PWCS and what the notification will be. Please describe how the notification will take place and in what format.</h3><p>Account holders are notified by email. The point of contact at Puzzel.org is Daan Weustenraad (see details above). The notification describes the breach, who was affected and what the consequences are.</p><h3>The infrastructure (hosts, network equipment, etc.) hosting the application must be located in a locked cage-type environment. A Tier 2 data center (or better) or Cloud Service Provider, such as AWS, Google, or Azure physical infrastructure is preferred.</h3><p>The application is hosted by <a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a>, one of the larger application delivery networks, and is therefore secured in the best possible way. Accounts, activities and results sit in a Google Firebase realtime database; uploaded images and audio are stored in Amazon S3.</p><p><a href=\"https://firebase.google.com/support/privacy\" rel=\"noopener noreferrer\" target=\"_blank\">More about Google Firebase</a></p><p>The full list of sub-processors — no other party receives account or player data:</p><ul><li><a href=\"https://vercel.com\" rel=\"noopener noreferrer\" target=\"_blank\">Vercel</a> — application hosting and delivery</li><li><a href=\"https://firebase.google.com\" rel=\"noopener noreferrer\" target=\"_blank\">Google Firebase</a> — authentication and the realtime database holding account data</li><li><a href=\"https://aws.amazon.com/s3/\" rel=\"noopener noreferrer\" target=\"_blank\">Amazon S3</a> — storage for uploaded images and audio</li><li><a href=\"https://stripe.com\" rel=\"noopener noreferrer\" target=\"_blank\">Stripe</a> — subscription payments and invoicing</li><li><a href=\"https://openai.com\" rel=\"noopener noreferrer\" target=\"_blank\">OpenAI</a> — generates content when a teacher uses the AI assistant</li><li><a href=\"https://pixabay.com\" rel=\"noopener noreferrer\" target=\"_blank\">Pixabay</a> — supplies the free stock photos a teacher can search from the builder</li></ul><h3>The infrastructure hosting the application must keep the data separate from other customers' data. This can be done through physical (airgap, separate servers, etc.) or logical (VLAN, subnets, security tags, virtual hosts, etc.) means. Describe how this is accomplished.</h3><p>Logically, through authentication. While signed in to your account, you only reach the data stored by you as the activity owner, or on behalf of your activities (the activity players' data). This is fully enforced by the Firebase Security Rules implementation.</p><p><a href=\"https://firebase.google.com/docs/rules\" rel=\"noopener noreferrer\" target=\"_blank\">More on Firebase Security Rules</a></p><h3>The data must always be encrypted while in transit, while in use and at rest, without exception. Describe how this is accomplished.</h3><p>Traffic is HTTPS end to end, and account data is encrypted in transit and at rest by Google Firebase.</p><p><em>'Firebase services encrypt data in transit using HTTPS and logically isolate customer data.'</em> — Firebase</p><p><a href=\"https://firebase.google.com/support/privacy#data_encryption\" rel=\"noopener noreferrer\" target=\"_blank\">More on Data Encryption</a></p><p>Two exceptions to know about. Uploaded images and audio are stored in Amazon S3 and served from a public URL — treat them as public and keep anything confidential out of activity media. And when a teacher uses the AI assistant, what they type is sent to OpenAI to generate content; player data never is.</p><h3>How will you authenticate users? What options exist (Local/manual, SSO, SAML, Clever, etc.)?</h3><p>Authentication runs through Google Firebase. Teachers sign in with an email address and password, or with the Google or Microsoft account your school already manages. Players stay anonymous unless a teacher switches registration on for an activity.</p><p>Embedded activities support OIDC single sign-on: your portal passes a signed token, which is checked against your identity provider's published keys before a player is let in. Issuers are allow-listed per account and set up on request. There is no Clever, ClassLink or SAML connector today.</p><p><a href=\"https://firebase.google.com/docs/auth\" rel=\"noopener noreferrer\" target=\"_blank\">https://firebase.google.com/docs/auth</a></p><h3>Provide information on the account termination process</h3><p>A user account can be deleted at any time. This completely wipes every record of its activities and their activity results.</p><h3>Please describe who has access to the account data?</h3><p>Only the activity owner has access to their own data. Puzzel.org staff can access an account for debugging purposes, but never without an explicit request from the account holder.</p><h3>Do you accept payment by PO?</h3><p>Yes, when the PO can be paid by card or bank transfer. Cheques cannot be accepted, as Puzzel.org is not based in the US. Payments run through Stripe, so card details never reach Puzzel.org's own systems. If you need a formal document before ordering, the quote builder produces a PDF quote with your school's details on it.</p><h3>Does this product or solution have the ability to accept payments of any type?</h3><p>Yes. Credit or debit card, PayPal, Apple Pay and Google Pay are accepted in every currency; when paying in euros, iDEAL, Bancontact, Giropay and other local methods are offered as well, and bank transfer is available. Every payment runs through Stripe. The full list for your country is shown on the pricing page.</p>"
}
