Privacy Policy
1. Controller (Art. 13 GDPR)
Represented by: Managing Director Mehregan Etemadi Sangeneh
Im Eichengrund 1
26125 Oldenburg
Germany
Email: datenschutz@eazywon.com
2. General Basis for Data Processing
We process personal data exclusively within the framework of the legal requirements of the GDPR and the TDDDG (German Telecommunications Digital Services Data Protection Act). Processing serves the provision of a functional, secure, and entertainment-oriented online platform ("EazyWon") as well as the execution of game mechanics (battles, rankings, points system).
2a. Definition of Personal Data
Under Art. 4 (1) GDPR, personal data means any information relating to an identified or identifiable natural person. This includes, for example, information such as your first and last name, your address, your telephone number, your email address, and also your IP address.
Data from which no reference to your person can be established – for instance through anonymisation – is not personal data. Processing (e.g. collection, storage, reading, querying, use, transmission, erasure or destruction) within the meaning of Art. 4 (2) GDPR always requires a statutory legal basis or your consent. Personal data that has been processed must be erased as soon as the purpose of the processing has been achieved and no statutory retention obligations remain to be observed.
3. Categories of Data Processed
3.1 Registration and Profile Data
- First name
- Last name
- Email address
- Nickname
- Date of birth (to verify the minimum age)
- Password (stored exclusively in encrypted/hashed form)
- Country
- Favorite sport
- Favorite team (optional)
- Profile picture/avatar (optional, uploaded by the user)
- Profile description (bio, optional)
- Accepted version of the Terms with date and time of consent, and the number of notices about a new version
3.2 Usage Data (Game Operation)
- Tip data (predictions of sporting events)
- Battle results
- Battle Points / rankings
- In-platform game interactions
3.3 Communication Data
- In-platform chat messages (trash-talk)
- Content from user interactions
Chat/trash-talk messages are automatically screened for prohibited content before being sent; battle taunts may be automatically translated into the viewer's display language (see Section 7 – Mistral AI).
3.4 Technical Data
- IP address (technically required, may be truncated)
- Browser and device data
- Access timestamps
- Technical log data
3.5 Campaign and Referral Data
If you reach our platform via an advertising or campaign link, we process the campaign parameters contained in the address in order to identify which route leads to registrations:
- campaign identifiers from the URL (
utm_source,utm_medium,utm_campaign,utm_content,utm_term) - a click identifier of the respective ad network (e.g.
fbclidfrom Meta orgclidfrom Google) - the referring page, truncated to origin and path without query parameters; referrals from our own pages are discarded
These values are held in your browser's working memory only — no cookie is set and nothing is stored persistently in the browser. They are saved together with your account only once you submit a registration. If you abandon the form, nothing is stored.
Purpose: aggregated evaluation of our campaign reach (which campaign leads to
registrations).
Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in measuring our own
advertising).
Storage period: together with the user account; deleted with the account.
4. Purpose of Processing
- Provision of the platform and user accounts
- Operation of game mechanics (battles, points, rankings)
- Technical security and abuse prevention
- Stability and further development of the platform
- Communication with users (e.g., emails for registration or password reset)
- Running promotional campaigns, in particular determining winners, contacting them and delivering prizes
5. Legal Bases (GDPR)
Art. 6 (1)(b) GDPR — Processing for contract fulfillment (platform use, game operation, user account, record of the version of the Terms that applies to the account) as well as participation in promotional campaigns under the terms of participation published for them
Art. 6 (1)(f) GDPR — Legitimate interest in:
- Platform security
- Abuse and fraud prevention
- Stability and error analysis
- Limiting notices about new versions of the Terms and evidencing that they were offered
Art. 6 (1)(a) GDPR — Consent for optional communications (e.g., email notifications)
Art. 6 (1)(c) GDPR — where we store data to comply with statutory retention obligations. This applies in particular to records of prizes issued, which serve as accounting evidence.
6. Profiling / Game Mechanics (Art. 22 GDPR)
Automated evaluation of user data takes place to operate the game mechanics. This includes:
- Tipping behavior
- Game results
- Ranking calculation
- Battle Points system
This processing serves solely to represent the game mechanics within the platform. No legally binding automated decision-making within the meaning of Art. 22 GDPR takes place.
7. Data Processors (Art. 28 GDPR)
We use the following service providers. With all providers that process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR are in place. Which data is processed in each case, for what purpose and on what legal basis is set out below; each provider's privacy policy is linked.
Supabase Inc.
- Purpose: Backend, authentication and database operation (user accounts, game data)
- Data processed: registration/profile data, usage and game data, technical log data
- Legal basis: Art. 6 (1)(b) and (f) GDPR
- Hosting: Data is stored and primarily processed in the selected EU region (Frankfurt)
- Processor / subprocessors: Supabase Inc. (based in Singapore); use of subprocessors pursuant to the DPA
- Third country: Any transfers to third countries take place on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR
- DPA: concluded (as of 12 March 2026)
- Privacy policy: supabase.com/privacy
Brevo (Sendinblue SAS)
- Purpose: Sending transactional emails (email confirmation, password reset, account notifications)
- Data processed: email address, nickname, send/delivery metadata
- Legal basis: Art. 6 (1)(b) GDPR (or (a) for optional notifications)
- Processor: Sendinblue SAS, 9–17 rue Salneuve, 75017 Paris, France; data processed in the EU
- Subprocessors / third country: use of subprocessors pursuant to Brevo's data processing agreement; any transfers to third countries take place on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR
- DPA: concluded
- Privacy policy: brevo.com/legal/privacypolicy
Cloudflare Inc.
- Purpose: Content Delivery Network (CDN), security and performance services, protection against attacks and abuse, bot protection (Cloudflare Turnstile during registration), email routing
- Data processed: in particular IP address, browser/device data, access metadata
- Legal basis: Art. 6 (1)(f) GDPR (security/stability)
- Third country: Transfer to third countries (especially the USA) may occur, on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR and/or the EU-U.S. Data Privacy Framework
- DPA: concluded (as of 3 April 2026)
- Privacy policy: cloudflare.com/privacypolicy · Subprocessors: cloudflare.com/gdpr/subprocessors
Sentry (Functional Software, Inc.)
- Purpose: Error monitoring and performance tracking for platform stability
- Data processed: technical error/diagnostic data, truncated IP, user ID (no real name, no email)
- Legal basis: Art. 6 (1)(f) GDPR
- Data residency: Data is stored in the EU region (European Union)
- Processor / third country: Functional Software, Inc. (USA) as provider; access from or transfer to the USA may occur, safeguarded by the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses pursuant to Art. 46 GDPR
- Subprocessors: sentry.io/legal/subprocessors
- DPA: concluded (as of 29 May 2024)
- Privacy policy: sentry.io/privacy
Mistral AI
- Purpose: Automated live moderation of chat/trash-talk messages (detection of hate speech, harassment, threats as well as sexual, violent or criminal content) before sending, and translation of battle taunts into the viewer's display language (the original remains visible)
- Data processed: the respective message or taunt text (truncated to max. 2,000 / 500 characters)
- Legal basis: Art. 6 (1)(f) GDPR (community protection, abuse prevention, DSA obligations; for translations: mutual intelligibility between international players)
- Processor: Mistral AI, 15 rue des Halles, 75001 Paris, France
- Retention: for the duration of the agreement pursuant to the data processing agreement; after termination, deletion takes place within 30 days
- Subprocessors / third country: Mistral AI may engage subprocessors; any transfers to third countries take place exclusively on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 GDPR
- AI training: The transmitted content is not used to train Mistral AI's models (training disabled in the account settings / opt-out)
- DPA: concluded (as of 12 March 2026)
- Privacy policy: mistral.ai/terms · Subprocessors: trust.mistral.ai/subprocessors
7a. Disclosure to Third Parties
We disclose your personal data to third parties only if:
- a) you have given your explicit consent pursuant to Art. 6 (1)(a) GDPR.
- b) this is legally permissible and necessary pursuant to Art. 6 (1)(b) GDPR for the performance of a contractual relationship with you or the implementation of pre-contractual measures.
- c) there is a legal obligation for disclosure pursuant to Art. 6 (1)(c) GDPR. We are legally obliged to transmit data to government authorities, e.g. tax authorities, social security institutions, health insurers, supervisory authorities and law enforcement agencies.
- d) disclosure is necessary pursuant to Art. 6 (1)(f) GDPR to safeguard legitimate business interests as well as to assert, exercise or defend legal claims, and there is no reason to assume that you have an overriding interest worthy of protection in not disclosing your data.
- e) we use, pursuant to Art. 28 GDPR, external service providers (so-called processors) who have been obliged to handle your data carefully.
We use such service providers in the following areas:
- Hosting, authentication and database operation
- Sending transactional emails
- Content delivery, security and bot protection
- Error and performance monitoring
- Automated moderation of chat content
8. Storage Duration
We store personal data only as long as necessary for the respective purposes.
- Account data: until deletion of the user account
- Deletion after account deletion: within 30 days
- Chat messages: up to 90 days
- Server log data: maximum 30 days, unless security analysis is required
Records of prizes issued, including name, contact details, prize and date, are retained for eight years. This is based on § 147 (3) AO and § 257 (4) HGB. Data of participants who did not receive a prize is deleted no later than three months after the campaign has been concluded.
When a user account is deleted, chat messages are deleted together with the account within 30 days (see Terms § 9), regardless of the regular 90-day period.
Statutory retention obligations remain unaffected.
9. Cookies & Local Storage (TDDDG)
We use exclusively technically necessary cookies (e.g., session authentication) and local storage (e.g., language settings). These are required for the operation of the platform.
To protect registration against automated sign-ups (bot protection), we use Cloudflare Turnstile. In doing so, technical data (e.g., IP address and browser information) is processed by Cloudflare. Turnstile is required for the security of sign-up; for further information on Cloudflare see Section 7.
Legal basis: § 25 (2) TDDDG and Art. 6 (1)(f) GDPR (security).
9a. Advertising & Referral Programme
The platform may be ad-financed. Insofar as third-party advertisements (e.g. rewarded video ads) are integrated, the respective advertising service provider may process personal data (e.g. device and usage data). Such integration only takes place after your explicit consent via a consent banner (§ 25 (1) TDDDG, Art. 6 (1)(a) GDPR). Without consent, no advertising-related processing is carried out. The advertising service provider used will be named here as soon as advertising is activated.
As part of the referral programme, we process which users registered via which invitation link in order to correctly attribute bonus points (Art. 6 (1)(b) and (f) GDPR).
9b. Contact
If you contact us by email (e.g. at kontakt@eazywon.com or datenschutz@eazywon.com), we process the data you provide (in particular your email address and the content of your message) in order to handle your request. The legal basis is Art. 6 (1)(b) GDPR (pre-contractual/contractual communication) or Art. 6 (1)(f) GDPR (handling of general inquiries). The data is deleted once your request has been conclusively dealt with and no statutory retention obligations apply.
9c. Advertising Measurement with the Meta Pixel
We run advertisements on Meta's platforms (Facebook, Instagram). To identify which
advertisement leads to registrations, we use the Meta Pixel. This loads a
script provided by Meta (connect.facebook.net) which reports your visit and
certain actions to Meta.
Only with your consent: Without your explicit consent via our cookie notice, the pixel is not loaded at all — no script is requested from Meta, no identifier is set and no event is sent. You may withdraw your consent at any time via Cookie settings – the link is also at the bottom of every page of the app; when signed in, also in your settings. From the moment of withdrawal no further events are transmitted to Meta, and the pixel is not loaded again on subsequent visits. Events already transmitted cannot be recalled; the withdrawal does not affect the lawfulness of processing carried out on the basis of the consent up to the point of withdrawal.
Which events are reported:
- Page view — that our page was opened
- Registration completed — that a registration was submitted
- Email confirmed — that an email address was confirmed
- First tip — that a tip was placed for the first time, including the chosen market and the points at stake. This event is sent once per browser.
We transmit neither your name nor your email address nor your nickname to Meta. Meta may, however, link the event to an existing Meta account or to an identifier of its own and build usage profiles from it; we have no influence over this.
Controllership: For the processing carried out by the pixel we assume joint
controllership with Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland
(Art. 26 GDPR). Meta is solely responsible for any further processing within the Meta group.
Legal basis: Art. 6 (1)(a) GDPR; insofar as information is stored on or read
from your device, additionally § 25 (1) sentence 1 TDDDG (consent).
Third country: Data may be transferred to the USA. The basis is Art. 44 GDPR
together with Art. 45 GDPR (the European Commission's adequacy decision in favour of
recipients certified under the EU-U.S. Data Privacy Framework); Meta is certified under the
Data Privacy Framework.
Further information: Meta's privacy policy
10. Data Security
We employ technical and organizational measures to protect personal data from loss, manipulation, and unauthorized access.
- TLS encryption (HTTPS)
- Access controls (Row-Level Security in the database)
- Security measures of the service providers used
11. Rights of Data Subjects
Data subjects have the right at any time to:
- Information (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
Requests please to datenschutz@eazywon.com.
12. Right to Lodge a Complaint
Competent supervisory authority:
www.lfd.niedersachsen.de
13. Changes to this Privacy Policy
This privacy policy may be adjusted if legal, technical, or organizational changes arise. The current version is available on the platform at all times.