Privacy Notice

1. Controller and contact

Controller for the platform: ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its Managing Director Maximilian Lucas Arbeiter. Commercial Register: Local Court of Cologne, HRB 128940.
Email: max@ultido.com · Phone: +49 221 16535560.
Data Protection Officer: Maximilian Lucas Arbeiter, reachable at max@ultido.com or by post at the address above, marked "Data Protection Officer".

2. Two controllers

  • ULTIDO GmbH is controller for: game profile/account, game progress, cross-park persona, AI image feature, reward delivery including the reward email, platform operation.

  • The respective park is controller for email marketing (marketing lead). At collection, Ultido acts as the park's processor (Art. 28); once you confirm the double opt-in, the record is handed over to the park, which processes it further as a controller in its own right. The app names the park and its contact details at the consent step, before you consent; the double-opt-in confirmation email repeats them.

3. Data processed, purposes, legal bases

Data category

Purpose

Legal basis

Controller

Email address

Account creation, reward delivery, reward email (transactional)

Art. 6(1)(b) (contract)

Ultido

Game profile, game progress, persona

Providing the service, recognition across parks

Art. 6(1)(b)

Ultido

Age-threshold indicator (yes/no)

Youth protection for the optional consents (no date of birth)

Art. 6(1)(c) with Art. 8

Ultido

Marketing consent + email

The park's email marketing (after double opt-in)

Art. 6(1)(a) + § 7 UWG

Park (Ultido as processor at collection)

Photo (original)

Transient AI stylisation via Google Vertex AI (only where the AI feature is enabled)

Art. 6(1)(a) + § 22 KUG

Ultido

Stylised image (output)

Display/download in the service, AI labelling

Art. 6(1)(a)/(b)

Ultido

AI routing log (filter → backend, no image content)

Evidence of transience and transfer route per output

Art. 6(1)(f)

Ultido

Cookies / local storage (strictly necessary only; optional ones only with consent)

Session, security; optionally statistics

§ 25 TDDDG; Art. 6(1)(f) or (a)

Ultido

Usage/log data, IP, user agent

Security, operation, abuse prevention

Art. 6(1)(f) (legitimate interest)

Ultido

Consent log

Evidence of consents

Art. 6(1)(c) with Art. 7(1)

Ultido

Legitimate interest (Art. 6(1)(f)): secure platform operation free of abuse, and the ability to evidence consents and processing routes.

4. Recipients and processors (Art. 28)

We use the following categories of processors (complete, versioned register: Subprocessor Register):

Provider

Purpose

Data category

Region / place of processing

Vercel Inc.

Hosting/serverless (region fra1)

App data, lead at collection where applicable

EU region; US parent

Clerk Inc.

Authentication/identity

Email, account ID, consent flags

USA (no EU residency available)

Supabase

Database, backend and media storage (eu-central-1, Frankfurt)

App data, consent log, lead, stylised images

EU region; US parent

Google Cloud (Vertex AI)

AI stylisation (only where the AI feature is enabled)

Photo (transient)

us-central1, USA

CCM19

Consent management (cookies)

Consent status, technical data

Germany

Clerk Inc. (email delivery)

Delivery of all profile emails – double opt-in, account creation, password reset – and of the reward emails, technically via SendGrid (Twilio Inc.) as sub-processor

Email, name

USA

SnapNext GmbH + Co. KG

Operation/development of the live platform, email and office infrastructure

App/operational data depending on the activity

Germany (Pulheim); sub-processors used: see register

Agreements under Art. 28 GDPR are in place with all processors. Changes to the register are versioned and notified to the park controllers with notice.

5. International transfers (Chapter V GDPR) – including the AI route

Our application hosting and database run in EU regions (Vercel fra1, Supabase eu-central-1). In addition, the following third-country transfers take place:

  • Authentication (Clerk): processing in the USA. Basis: EU-US Data Privacy Framework (adequacy decision, Implementing Decision (EU) 2023/1795); in addition EU Standard Contractual Clauses (Art. 46(2)(c), SCC 2021/914) as fallback in the DPA; the provider's EU representative: VeraSafe Ireland Ltd.

  • Email delivery (Clerk/SendGrid): confirmation, account and reward emails are sent via Clerk, which uses SendGrid (Twilio Inc., USA) for this. Email address and name are transferred. Basis: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses via the Clerk DPA.

  • AI image stylisation: where the AI feature is enabled, the photo is processed via Google Vertex AI in the region us-central1 (USA), safeguarded by the EU Standard Contractual Clauses of the Google Cloud data processing addendum. The original photo is processed only transiently and not stored; the processing route is logged per image (routing log, no image content).

  • Planned second inference route: for some style classes, an in-house inference infrastructure operated in the EU is planned for the medium term. This route is not in operation; no processing takes place over it. Before it goes live, provider and region will be named in this notice and in the subprocessor register, and the parks will be informed under the 30-day rule.

  • Other US-parented providers (Vercel, Supabase): processing in EU regions; where transfers to the USA occur, they rely on DPF certification (Vercel) or Standard Contractual Clauses (Supabase, which holds no DPF listing of its own).

A transfer impact assessment is maintained for US transfers; DPF certifications are checked live before we rely on them. Copies of the safeguards are available on request.

6. Retention

Category

Period

Account/game profile (including persona)

Duration of use; deletion after 24 months of inactivity or on request

Marketing lead (double opt-in confirmed)

Until withdrawal; after handover, deletion/blocking by the park

Marketing lead (double opt-in not confirmed)

Deleted when the confirmation link expires – 7 days

Original photo (AI)

Transient – not stored

Stylised image (output)

30 days of display/download, then deleted

AI routing log (no image content)

12 months

Log/security data

90 days

Consent log

Duration of the relationship + 3 years (limitation period)

7. Your rights

You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). You can withdraw any consent at any time with effect for the future (Art. 7(3)) – we make withdrawal as easy as giving consent. Requests to max@ultido.com. If a request concerns the park's marketing data, we forward it to the responsible park or tell you who is responsible.
Right to lodge a complaint: you can complain to a data protection supervisory authority – competent for ULTIDO GmbH: the Data Protection and Freedom of Information Commissioner of North Rhine-Westphalia (LDI NRW), or the authority where you live (e.g. AEPD in Spain, APD/GBA in Belgium).

8. Obligation to provide data

Your email address is required for creating the account and delivering the reward; without it the service cannot be used. Marketing consent (b) and AI consent (c) are voluntary; refusing them has no disadvantage for your account or reward.

9. Automated decision-making / profiling

There is no automated decision-making with legal effect within the meaning of Art. 22. The cross-park persona serves to recognise you and personalise the game experience, not to evaluate you with legal effect.

10. Minors

The optional consents (b)/(c) are preceded by an age check (threshold check, no date of birth). The age of consent follows the park's country (Art. 8 GDPR): Germany 16, Spain 14, Belgium 13. Below the threshold, the newsletter and the AI image feature are not available; play and reward can be used regardless.

11. Changes and versioning

We update this notice when processing changes. The published version, with its version number and date at the end of the page, governs. Every version receives a checksum; earlier versions remain traceable with their checksum in the change history, so that every consent given can be matched to the version of the text you were shown.

Change history

Every version of this text is archived together with its checksum. All versions

Version

Date

Change

4.4.1

26.09.2026

The legal-basis column now lists legal bases only; two abbreviations written out.

4.4.0

25.09.2026

English version fully translated, including all tables. Internal references removed in both languages and § 11 on versioning reworded for clarity.

4.3.0

23.09.2026

§ 2 now says where to find the park's name and contact details: at the app's consent step and in the confirmation email.

4.2.0

23.09.2026

Internal cross-references removed; no change in substance.

4.1.0

22.09.2026

English version aligned with the German one: Accesso removed, Clerk and SendGrid added as the email route.

3.1.0

16.09.2026

The email delivery route is described. Open review notes replaced by written-out reasoning.

3.0.1

16.09.2026

Details of the data protection officer added.

3.0.0

16.09.2026

Cloudinary is no longer a recipient. The AI image feature is described with its actual processing route (Google Vertex AI, USA). Retention periods set, data protection officer appointed.

2.0.0

10.08.2026

Earliest archived version.

Version 4.4.1 · Last updated 26.09.2026