Privacy Notice
1. Controller and contact
Controller for the platform: ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its Managing Director Maximilian Lucas Arbeiter. Commercial Register: Local Court of Cologne, HRB 128940.
Email: max@ultido.com · Phone: +49 221 16535560.
Data Protection Officer: Maximilian Lucas Arbeiter, reachable at max@ultido.com or by post at the address above, marked "Data Protection Officer".
2. Two controllers
ULTIDO GmbH is controller for: game profile/account, game progress, cross-park persona, AI image feature, reward delivery including the reward email, platform operation.
The respective park is controller for email marketing (marketing lead). At collection, Ultido acts as the park's processor (Art. 28); once you confirm the double opt-in, the record is handed over to the park, which processes it further as a controller in its own right. The app names the park and its contact details at the consent step, before you consent; the double-opt-in confirmation email repeats them.
3. Data processed, purposes, legal bases
Data category | Purpose | Legal basis | Controller |
|---|---|---|---|
Email address | Account creation, reward delivery, reward email (transactional) | Art. 6(1)(b) (contract) | Ultido |
Game profile, game progress, persona | Providing the service, recognition across parks | Art. 6(1)(b) | Ultido |
Age-threshold indicator (yes/no) | Youth protection for the optional consents (no date of birth) | Art. 6(1)(c) with Art. 8 | Ultido |
Marketing consent + email | The park's email marketing (after double opt-in) | Art. 6(1)(a) + § 7 UWG | Park (Ultido as processor at collection) |
Photo (original) | Transient AI stylisation via Google Vertex AI (only where the AI feature is enabled) | Art. 6(1)(a) + § 22 KUG | Ultido |
Stylised image (output) | Display/download in the service, AI labelling | Art. 6(1)(a)/(b) | Ultido |
AI routing log (filter → backend, no image content) | Evidence of transience and transfer route per output | Art. 6(1)(f) | Ultido |
Cookies / local storage (strictly necessary only; optional ones only with consent) | Session, security; optionally statistics | § 25 TDDDG; Art. 6(1)(f) or (a) | Ultido |
Usage/log data, IP, user agent | Security, operation, abuse prevention | Art. 6(1)(f) (legitimate interest) | Ultido |
Consent log | Evidence of consents | Art. 6(1)(c) with Art. 7(1) | Ultido |
Legitimate interest (Art. 6(1)(f)): secure platform operation free of abuse, and the ability to evidence consents and processing routes.
4. Recipients and processors (Art. 28)
We use the following categories of processors (complete, versioned register: Subprocessor Register):
Provider | Purpose | Data category | Region / place of processing |
|---|---|---|---|
Vercel Inc. | Hosting/serverless (region fra1) | App data, lead at collection where applicable | EU region; US parent |
Clerk Inc. | Authentication/identity | Email, account ID, consent flags | USA (no EU residency available) |
Supabase | Database, backend and media storage (eu-central-1, Frankfurt) | App data, consent log, lead, stylised images | EU region; US parent |
Google Cloud (Vertex AI) | AI stylisation (only where the AI feature is enabled) | Photo (transient) | us-central1, USA |
CCM19 | Consent management (cookies) | Consent status, technical data | Germany |
Clerk Inc. (email delivery) | Delivery of all profile emails – double opt-in, account creation, password reset – and of the reward emails, technically via SendGrid (Twilio Inc.) as sub-processor | Email, name | USA |
SnapNext GmbH + Co. KG | Operation/development of the live platform, email and office infrastructure | App/operational data depending on the activity | Germany (Pulheim); sub-processors used: see register |
Agreements under Art. 28 GDPR are in place with all processors. Changes to the register are versioned and notified to the park controllers with notice.
5. International transfers (Chapter V GDPR) – including the AI route
Our application hosting and database run in EU regions (Vercel fra1, Supabase eu-central-1). In addition, the following third-country transfers take place:
Authentication (Clerk): processing in the USA. Basis: EU-US Data Privacy Framework (adequacy decision, Implementing Decision (EU) 2023/1795); in addition EU Standard Contractual Clauses (Art. 46(2)(c), SCC 2021/914) as fallback in the DPA; the provider's EU representative: VeraSafe Ireland Ltd.
Email delivery (Clerk/SendGrid): confirmation, account and reward emails are sent via Clerk, which uses SendGrid (Twilio Inc., USA) for this. Email address and name are transferred. Basis: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses via the Clerk DPA.
AI image stylisation: where the AI feature is enabled, the photo is processed via Google Vertex AI in the region us-central1 (USA), safeguarded by the EU Standard Contractual Clauses of the Google Cloud data processing addendum. The original photo is processed only transiently and not stored; the processing route is logged per image (routing log, no image content).
Planned second inference route: for some style classes, an in-house inference infrastructure operated in the EU is planned for the medium term. This route is not in operation; no processing takes place over it. Before it goes live, provider and region will be named in this notice and in the subprocessor register, and the parks will be informed under the 30-day rule.
Other US-parented providers (Vercel, Supabase): processing in EU regions; where transfers to the USA occur, they rely on DPF certification (Vercel) or Standard Contractual Clauses (Supabase, which holds no DPF listing of its own).
A transfer impact assessment is maintained for US transfers; DPF certifications are checked live before we rely on them. Copies of the safeguards are available on request.
6. Retention
Category | Period |
|---|---|
Account/game profile (including persona) | Duration of use; deletion after 24 months of inactivity or on request |
Marketing lead (double opt-in confirmed) | Until withdrawal; after handover, deletion/blocking by the park |
Marketing lead (double opt-in not confirmed) | Deleted when the confirmation link expires – 7 days |
Original photo (AI) | Transient – not stored |
Stylised image (output) | 30 days of display/download, then deleted |
AI routing log (no image content) | 12 months |
Log/security data | 90 days |
Consent log | Duration of the relationship + 3 years (limitation period) |
7. Your rights
You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). You can withdraw any consent at any time with effect for the future (Art. 7(3)) – we make withdrawal as easy as giving consent. Requests to max@ultido.com. If a request concerns the park's marketing data, we forward it to the responsible park or tell you who is responsible.
Right to lodge a complaint: you can complain to a data protection supervisory authority – competent for ULTIDO GmbH: the Data Protection and Freedom of Information Commissioner of North Rhine-Westphalia (LDI NRW), or the authority where you live (e.g. AEPD in Spain, APD/GBA in Belgium).
8. Obligation to provide data
Your email address is required for creating the account and delivering the reward; without it the service cannot be used. Marketing consent (b) and AI consent (c) are voluntary; refusing them has no disadvantage for your account or reward.
9. Automated decision-making / profiling
There is no automated decision-making with legal effect within the meaning of Art. 22. The cross-park persona serves to recognise you and personalise the game experience, not to evaluate you with legal effect.
10. Minors
The optional consents (b)/(c) are preceded by an age check (threshold check, no date of birth). The age of consent follows the park's country (Art. 8 GDPR): Germany 16, Spain 14, Belgium 13. Below the threshold, the newsletter and the AI image feature are not available; play and reward can be used regardless.
11. Changes and versioning
We update this notice when processing changes. The published version, with its version number and date at the end of the page, governs. Every version receives a checksum; earlier versions remain traceable with their checksum in the change history, so that every consent given can be matched to the version of the text you were shown.
Change history
Every version of this text is archived together with its checksum. All versions
Version | Date | Change |
|---|---|---|
4.4.1 | 26.09.2026 | The legal-basis column now lists legal bases only; two abbreviations written out. |
4.4.0 | 25.09.2026 | English version fully translated, including all tables. Internal references removed in both languages and § 11 on versioning reworded for clarity. |
4.3.0 | 23.09.2026 | § 2 now says where to find the park's name and contact details: at the app's consent step and in the confirmation email. |
4.2.0 | 23.09.2026 | Internal cross-references removed; no change in substance. |
4.1.0 | 22.09.2026 | English version aligned with the German one: Accesso removed, Clerk and SendGrid added as the email route. |
3.1.0 | 16.09.2026 | The email delivery route is described. Open review notes replaced by written-out reasoning. |
3.0.1 | 16.09.2026 | Details of the data protection officer added. |
3.0.0 | 16.09.2026 | Cloudinary is no longer a recipient. The AI image feature is described with its actual processing route (Google Vertex AI, USA). Retention periods set, data protection officer appointed. |
2.0.0 | 10.08.2026 | Earliest archived version. |
Version 4.4.1 · Last updated 26.09.2026