Skip to content
You're previewing the new Puzzel.org Back to the current site
Legal

The short answer: we don't want your students' data.

Plain language first, with the full document one toggle away — because your data protection officer needs that version and you don't.

Effective 15 November 2024
In one line
Players are never identified unless you ask them to be
No student accounts exist. Registration fields are yours to choose.
Money
Subscriptions pay for this
No ads, no data business — and at least 10% of profits go to charity.
Where
Your region, your choice
Europe or the United States — set per account, separately for files and data.
Cookies
Functional only
A session cookie so your work isn't lost. No third-party tracking.
1

Who we are and what this covers

Puzzel.org is built and run by Daan Weustenraad in the Netherlands. This policy covers the website, the activities you build and the play screens your players see — and it is written to comply with the GDPR.

Questions or requests: daan@puzzel.org — answered by the person who built it.
Complaints can also go to the data protection authority in your country.
2

What we collect from you

An account needs a first name and an email address. Beyond that, we store what you make and how often it is used — nothing more than the platform needs to function.

First name and email address — to sign you in and reach you about your account.
The activities you create — stored so you can reopen, share and delete them.
Usage data — how often your activities are played, which also powers your results.
Functional cookies only — your active session, controllable in your browser.
3

What we collect from your players

Nothing, unless you switch it on. Registration fields are optional and chosen by you — and there is no automated decision-making or profiling, on anyone.

No player accounts — a link or QR code is enough.
Only the registration fields you enabled reach the results report.
No advertising identifiers and no third-party trackers on the play screen.
4

Where your data lives

Data is stored with Google Firebase, with SendGrid handling account email. You choose your storage region — Europe or the United States — separately for uploaded files and account data. Transfers outside the EEA are covered by standard contractual clauses.

Google Firebase — authentication and storage of your data.
SendGrid — account and platform email, nothing you didn't sign up for.
Legal authorities — only when required by law.
5

Your rights

Everything the GDPR gives you, without a form maze: ask and it happens. Most of it you can do yourself from your dashboard.

Access, correct or export your personal data.
Delete your data — or your whole account, right from the dashboard.
Restrict or object to processing, and withdraw consent at any time.
Not happy with how we handled it? Lodge a complaint with your supervisory authority.
Something here still unclear? Ask instead — legal pages that need a follow-up email are badly written.