Privacy Notice — versions

Versions of this document

Every change to the text creates a new version with its own checksum. This list shows which text applied when. If you gave consent in the app, the checksum of the version shown to you at the time is recorded there – you can look it up here.

Version

Date

What changed

Checksum (sha256)

Text

4.4.1 (current)

26.09.2026

The legal-basis column now lists legal bases only; two abbreviations written out.

sha256-86314e8a0d0c2db9cebfd8a710dde551b8d9254cb7ab9e815460e487ba3ae4fe

Full text

4.4.0

25.09.2026

English version fully translated, including all tables. Internal references removed in both languages and § 11 on versioning reworded for clarity.

sha256-f040ae33275600c56a426223d84c28563de9e4a7c466022b64a3c41fb2a3da3d

Full text

4.3.0

23.09.2026

§ 2 now says where to find the park's name and contact details: at the app's consent step and in the confirmation email.

sha256-d64eea08d51e3fad5758d68597827b423a16d769706d46dacf6db1778dac9538

Full text

4.2.0

23.09.2026

Internal cross-references removed; no change in substance.

sha256-fe1c0edd47620f92a8090c964a49123d8fea2b223f54595441fbbd3ecfff5ae5

on request

4.1.0

22.09.2026

English version aligned with the German one: Accesso removed, Clerk and SendGrid added as the email route.

sha256-7bcc81255ffaa19e6ee8b6266c96b963545b229306428bbf4ce6f72a66b0fcb1

on request

3.1.0

16.09.2026

The email delivery route is described. Open review notes replaced by written-out reasoning.

sha256-c02d14fcd08f9f9e38812cf2a19bf6b0b0a5bca021881b2068103cb21104775f

on request

3.0.1

16.09.2026

Details of the data protection officer added.

sha256-2fd8df9cc9b2d6b409277ee966dcd953b5eb8b9d3c6c6ddea4c4843019c238df

on request

3.0.0

16.09.2026

Cloudinary is no longer a recipient. The AI image feature is described with its actual processing route (Google Vertex AI, USA). Retention periods set, data protection officer appointed.

sha256-7ae68a5c75c2ab0f4fb647aa296ab0c0ef2bb696cb252fc7dd14bb2592f86ea0

on request

2.0.0

10.08.2026

Earliest archived version.

sha256-93a985452608670763c655eee65d3058da93f9c2c6b7a269487d6f127e70f9e3

on request

Full texts of early working versions containing internal review notes are available on request from max@ultido.com; their checksum is shown in the list.

Version 4.4.1 · as of 26.09.2026

Checksum: sha256-86314e8a0d0c2db9cebfd8a710dde551b8d9254cb7ab9e815460e487ba3ae4fe

1. Controller and contact

Controller for the platform: ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its Managing Director Maximilian Lucas Arbeiter. Commercial Register: Local Court of Cologne, HRB 128940.
Email: max@ultido.com · Phone: +49 221 16535560.
Data Protection Officer: Maximilian Lucas Arbeiter, reachable at max@ultido.com or by post at the address above, marked "Data Protection Officer".

2. Two controllers

  • ULTIDO GmbH is controller for: game profile/account, game progress, cross-park persona, AI image feature, reward delivery including the reward email, platform operation.

  • The respective park is controller for email marketing (marketing lead). At collection, Ultido acts as the park's processor (Art. 28); once you confirm the double opt-in, the record is handed over to the park, which processes it further as a controller in its own right. The app names the park and its contact details at the consent step, before you consent; the double-opt-in confirmation email repeats them.

3. Data processed, purposes, legal bases

Data category

Purpose

Legal basis

Controller

Email address

Account creation, reward delivery, reward email (transactional)

Art. 6(1)(b) (contract)

Ultido

Game profile, game progress, persona

Providing the service, recognition across parks

Art. 6(1)(b)

Ultido

Age-threshold indicator (yes/no)

Youth protection for the optional consents (no date of birth)

Art. 6(1)(c) with Art. 8

Ultido

Marketing consent + email

The park's email marketing (after double opt-in)

Art. 6(1)(a) + § 7 UWG

Park (Ultido as processor at collection)

Photo (original)

Transient AI stylisation via Google Vertex AI (only where the AI feature is enabled)

Art. 6(1)(a) + § 22 KUG

Ultido

Stylised image (output)

Display/download in the service, AI labelling

Art. 6(1)(a)/(b)

Ultido

AI routing log (filter → backend, no image content)

Evidence of transience and transfer route per output

Art. 6(1)(f)

Ultido

Cookies / local storage (strictly necessary only; optional ones only with consent)

Session, security; optionally statistics

§ 25 TDDDG; Art. 6(1)(f) or (a)

Ultido

Usage/log data, IP, user agent

Security, operation, abuse prevention

Art. 6(1)(f) (legitimate interest)

Ultido

Consent log

Evidence of consents

Art. 6(1)(c) with Art. 7(1)

Ultido

Legitimate interest (Art. 6(1)(f)): secure platform operation free of abuse, and the ability to evidence consents and processing routes.

4. Recipients and processors (Art. 28)

We use the following categories of processors (complete, versioned register: Subprocessor Register):

Provider

Purpose

Data category

Region / place of processing

Vercel Inc.

Hosting/serverless (region fra1)

App data, lead at collection where applicable

EU region; US parent

Clerk Inc.

Authentication/identity

Email, account ID, consent flags

USA (no EU residency available)

Supabase

Database, backend and media storage (eu-central-1, Frankfurt)

App data, consent log, lead, stylised images

EU region; US parent

Google Cloud (Vertex AI)

AI stylisation (only where the AI feature is enabled)

Photo (transient)

us-central1, USA

CCM19

Consent management (cookies)

Consent status, technical data

Germany

Clerk Inc. (email delivery)

Delivery of all profile emails – double opt-in, account creation, password reset – and of the reward emails, technically via SendGrid (Twilio Inc.) as sub-processor

Email, name

USA

SnapNext GmbH + Co. KG

Operation/development of the live platform, email and office infrastructure

App/operational data depending on the activity

Germany (Pulheim); sub-processors used: see register

Agreements under Art. 28 GDPR are in place with all processors. Changes to the register are versioned and notified to the park controllers with notice.

5. International transfers (Chapter V GDPR) – including the AI route

Our application hosting and database run in EU regions (Vercel fra1, Supabase eu-central-1). In addition, the following third-country transfers take place:

  • Authentication (Clerk): processing in the USA. Basis: EU-US Data Privacy Framework (adequacy decision, Implementing Decision (EU) 2023/1795); in addition EU Standard Contractual Clauses (Art. 46(2)(c), SCC 2021/914) as fallback in the DPA; the provider's EU representative: VeraSafe Ireland Ltd.

  • Email delivery (Clerk/SendGrid): confirmation, account and reward emails are sent via Clerk, which uses SendGrid (Twilio Inc., USA) for this. Email address and name are transferred. Basis: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses via the Clerk DPA.

  • AI image stylisation: where the AI feature is enabled, the photo is processed via Google Vertex AI in the region us-central1 (USA), safeguarded by the EU Standard Contractual Clauses of the Google Cloud data processing addendum. The original photo is processed only transiently and not stored; the processing route is logged per image (routing log, no image content).

  • Planned second inference route: for some style classes, an in-house inference infrastructure operated in the EU is planned for the medium term. This route is not in operation; no processing takes place over it. Before it goes live, provider and region will be named in this notice and in the subprocessor register, and the parks will be informed under the 30-day rule.

  • Other US-parented providers (Vercel, Supabase): processing in EU regions; where transfers to the USA occur, they rely on DPF certification (Vercel) or Standard Contractual Clauses (Supabase, which holds no DPF listing of its own).

A transfer impact assessment is maintained for US transfers; DPF certifications are checked live before we rely on them. Copies of the safeguards are available on request.

6. Retention

Category

Period

Account/game profile (including persona)

Duration of use; deletion after 24 months of inactivity or on request

Marketing lead (double opt-in confirmed)

Until withdrawal; after handover, deletion/blocking by the park

Marketing lead (double opt-in not confirmed)

Deleted when the confirmation link expires – 7 days

Original photo (AI)

Transient – not stored

Stylised image (output)

30 days of display/download, then deleted

AI routing log (no image content)

12 months

Log/security data

90 days

Consent log

Duration of the relationship + 3 years (limitation period)

7. Your rights

You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). You can withdraw any consent at any time with effect for the future (Art. 7(3)) – we make withdrawal as easy as giving consent. Requests to max@ultido.com. If a request concerns the park's marketing data, we forward it to the responsible park or tell you who is responsible.
Right to lodge a complaint: you can complain to a data protection supervisory authority – competent for ULTIDO GmbH: the Data Protection and Freedom of Information Commissioner of North Rhine-Westphalia (LDI NRW), or the authority where you live (e.g. AEPD in Spain, APD/GBA in Belgium).

8. Obligation to provide data

Your email address is required for creating the account and delivering the reward; without it the service cannot be used. Marketing consent (b) and AI consent (c) are voluntary; refusing them has no disadvantage for your account or reward.

9. Automated decision-making / profiling

There is no automated decision-making with legal effect within the meaning of Art. 22. The cross-park persona serves to recognise you and personalise the game experience, not to evaluate you with legal effect.

10. Minors

The optional consents (b)/(c) are preceded by an age check (threshold check, no date of birth). The age of consent follows the park's country (Art. 8 GDPR): Germany 16, Spain 14, Belgium 13. Below the threshold, the newsletter and the AI image feature are not available; play and reward can be used regardless.

11. Changes and versioning

We update this notice when processing changes. The published version, with its version number and date at the end of the page, governs. Every version receives a checksum; earlier versions remain traceable with their checksum in the change history, so that every consent given can be matched to the version of the text you were shown.

Version 4.4.0 · as of 25.09.2026

Checksum: sha256-f040ae33275600c56a426223d84c28563de9e4a7c466022b64a3c41fb2a3da3d

1. Controller and contact

Controller for the platform: ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its Managing Director Maximilian Lucas Arbeiter. Commercial Register: Local Court of Cologne, HRB 128940.
Email: max@ultido.com · Phone: +49 221 16535560.
Data Protection Officer: Maximilian Lucas Arbeiter, reachable at max@ultido.com or by post at the address above, marked "Data Protection Officer".

2. Two controllers

  • ULTIDO GmbH is controller for: game profile/account, game progress, cross-park persona, AI image feature, reward delivery including the reward email, platform operation.

  • The respective park is controller for email marketing (marketing lead). At collection, Ultido acts as the park's processor (Art. 28); once you confirm the double opt-in, the record is handed over to the park, which processes it further as a controller in its own right. The app names the park and its contact details at the consent step, before you consent; the double-opt-in confirmation email repeats them.

3. Data processed, purposes, legal bases

Data category

Purpose

Legal basis

Controller

Email address

Account creation, reward delivery, reward email (transactional)

Art. 6(1)(b) (contract)

Ultido

Game profile, game progress, persona

Providing the service, recognition across parks

Art. 6(1)(b)

Ultido

Age-threshold indicator (yes/no)

Youth protection for the optional consents (no date of birth)

Art. 6(1)(c) with Art. 8; Art. 5(1)(c)

Ultido

Marketing consent + email

The park's email marketing (after double opt-in)

Art. 6(1)(a) + § 7 UWG

Park (Ultido as processor at collection)

Photo (original)

Transient AI stylisation via Google Vertex AI (only where the AI feature is enabled)

Art. 6(1)(a) + § 22 KUG

Ultido

Stylised image (output)

Display/download in the service, AI labelling

Art. 6(1)(a)/(b)

Ultido

AI routing log (filter → backend, no image content)

Evidence of transience and transfer route per output

Art. 6(1)(f); Art. 5(2)

Ultido

Cookies / local storage (strictly necessary only; optional ones only with consent)

Session, security; optionally statistics

§ 25 TDDDG; Art. 6(1)(f) or (a)

Ultido

Usage/log data, IP, user agent

Security, operation, abuse prevention

Art. 6(1)(f) (legitimate interest)

Ultido

Consent log

Evidence of consents

Art. 6(1)(c) with Art. 7(1)

Ultido

Legitimate interest (Art. 6(1)(f)): secure platform operation free of abuse, and the ability to evidence consents and processing routes.

4. Recipients and processors (Art. 28)

We use the following categories of processors (complete, versioned register: Subprocessor Register):

Provider

Purpose

Data category

Region / place of processing

Vercel Inc.

Hosting/serverless (region fra1)

App data, lead at collection where applicable

EU region; US parent

Clerk Inc.

Authentication/identity

Email, account ID, consent flags

USA (no EU residency available)

Supabase

Database, backend and media storage (eu-central-1, Frankfurt)

App data, consent log, lead, stylised images

EU region; US parent

Google Cloud (Vertex AI)

AI stylisation (only where the AI feature is enabled)

Photo (transient)

us-central1, USA

CCM19

Consent management (cookies)

Consent status, technical data

Germany

Clerk Inc. (email delivery)

Delivery of all profile emails – double opt-in, account creation, password reset – and of the reward emails, technically via SendGrid (Twilio Inc.) as sub-processor

Email, name

USA

SnapNext GmbH + Co. KG

Operation/development of the live platform, email and office infrastructure

App/operational data depending on the activity

Germany (Pulheim); sub-processors used: see register

Agreements under Art. 28 GDPR are in place with all processors. Changes to the register are versioned and notified to the park controllers with notice.

5. International transfers (Chapter V GDPR) – including the AI route

Our application hosting and database run in EU regions (Vercel fra1, Supabase eu-central-1). In addition, the following third-country transfers take place:

  • Authentication (Clerk): processing in the USA. Basis: EU-US Data Privacy Framework (adequacy decision, Implementing Decision (EU) 2023/1795); in addition EU Standard Contractual Clauses (Art. 46(2)(c), SCC 2021/914) as fallback in the DPA; the provider's EU representative: VeraSafe Ireland Ltd.

  • Email delivery (Clerk/SendGrid): confirmation, account and reward emails are sent via Clerk, which uses SendGrid (Twilio Inc., USA) for this. Email address and name are transferred. Basis: EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses via the Clerk DPA.

  • AI image stylisation: where the AI feature is enabled, the photo is processed via Google Vertex AI in the region us-central1 (USA), safeguarded by the EU Standard Contractual Clauses of the Google Cloud data processing addendum. The original photo is processed only transiently and not stored; the processing route is logged per image (routing log, no image content).

  • Planned second inference route: for some style classes, an in-house inference infrastructure operated in the EU is planned for the medium term. This route is not in operation; no processing takes place over it. Before it goes live, provider and region will be named in this notice and in the subprocessor register, and the parks will be informed under the 30-day rule.

  • Other US-parented providers (Vercel, Supabase): processing in EU regions; where transfers to the USA occur, they rely on DPF certification (Vercel) or Standard Contractual Clauses (Supabase, which holds no DPF listing of its own).

A transfer impact assessment is maintained for US transfers; DPF certifications are checked live before we rely on them. Copies of the safeguards are available on request.

6. Retention

Category

Period

Account/game profile (including persona)

Duration of use; deletion after 24 months of inactivity or on request

Marketing lead (double opt-in confirmed)

Until withdrawal; after handover, deletion/blocking by the park

Marketing lead (double opt-in not confirmed)

Deleted when the confirmation link expires – 7 days

Original photo (AI)

Transient – not stored

Stylised image (output)

30 days of display/download, then deleted

AI routing log (no image content)

12 months

Log/security data

90 days

Consent log

Duration of the relationship + 3 years (limitation period)

7. Your rights

You have the right of access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20) and objection (21). You can withdraw any consent at any time with effect for the future (Art. 7(3)) – we make withdrawal as easy as giving consent. Requests to max@ultido.com. If a request concerns the park's marketing data, we forward it to the responsible park or tell you who is responsible.
Right to lodge a complaint: you can complain to a data protection supervisory authority – competent for ULTIDO GmbH: the Data Protection and Freedom of Information Commissioner of North Rhine-Westphalia (LDI NRW), or the authority where you live (e.g. AEPD in Spain, APD/GBA in Belgium).

8. Obligation to provide data

Your email address is required for creating the account and delivering the reward; without it the service cannot be used. Marketing consent (b) and AI consent (c) are voluntary; refusing them has no disadvantage for your account or reward.

9. Automated decision-making / profiling

There is no automated decision-making with legal effect within the meaning of Art. 22. The cross-park persona serves to recognise you and personalise the game experience, not to evaluate you with legal effect.

10. Minors

The optional consents (b)/(c) are preceded by an age check (threshold check, no date of birth). The age of consent follows the park's country (Art. 8 GDPR): Germany 16, Spain 14, Belgium 13. Below the threshold, the newsletter and the AI image feature are not available; play and reward can be used regardless.

11. Changes and versioning

We update this notice when processing changes. The published version, with its version number and date at the end of the page, governs. Every version receives a checksum; earlier versions remain traceable with their checksum in the change history, so that every consent given can be matched to the version of the text you were shown.

Version 4.3.0 · as of 23.09.2026

Checksum: sha256-d64eea08d51e3fad5758d68597827b423a16d769706d46dacf6db1778dac9538

(Mirror of the German master. In case of doubt, the German version governs for DE deployments.)

1. Controller and contact

Controller for the platform: ULTIDO GmbH, Rommerskirchener Straße 21, 50259 Pulheim, Germany, represented by its Managing Director Maximilian Lucas Arbeiter; Commercial Register: Local Court of Cologne, HRB 128940. Email: max@ultido.com, Phone: +49 221 16535560. Data Protection Officer: Maximilian Lucas Arbeiter, max@ultido.com.

2. Two controllers

Ultido is controller for game profile/account, game state, cross-park persona, AI image feature, reward delivery (transactional reward email), platform operation. The respective park is controller for email marketing; at collection Ultido acts as the park's processor (Art. 28), and after double-opt-in confirmation the record is handed over to the park (controller-to-controller). The app names the park and its contact details at the consent step, before you consent; the double-opt-in confirmation email repeats them.

3. Data, purposes, legal bases

As per the German table: email = Art. 6(1)(b); profile/state/persona = Art. 6(1)(b); age-gate flag = Art. 6(1)(c) w/ Art. 8 (no date of birth stored); marketing = Art. 6(1)(a) + §7 UWG, park as controller; photo = Art. 6(1)(a) + §22 KUG, transient, Vertex path where the AI feature is enabled; AI routing log (no image content) = Art. 6(1)(f); cookies = § 25 TDDDG (consent for non-essential); logs/IP = Art. 6(1)(f); consent log = Art. 6(1)(c) w/ Art. 7.

4. Recipients and processors

Vercel (hosting, EU region fra1), Clerk (authentication and all profile emails – double opt-in, account creation, password reset – plus reward emails, technically via SendGrid / Twilio Inc.; US – EU residency is not available), Supabase (database, backend and media storage, eu-central-1), Google Cloud Vertex AI (AI styling where the feature is enabled, transient, us-central1/US), CCM19 (consent management, Germany), SnapNext GmbH + Co. KG (operation/development of the live platform under an Art. 28 agreement, Germany, with its own listed sub-processors). Cloudinary has been decommissioned and no longer receives any data. Full versioned register: subprocessors page / Doc. 8.

5. International transfers

Application hosting and database run in EU regions. Third-country transfers: authentication via Clerk in the US (EU-US Data Privacy Framework, Implementing Decision (EU) 2023/1795, plus SCCs 2021/914 as fallback; EU representative VeraSafe Ireland Ltd.). Where the AI feature is enabled, image styling runs on Google Vertex AI in us-central1 (USA), safeguarded by the EU Standard Contractual Clauses of the Google Cloud data processing addendum; the photo is transient and the processing path is logged per image (no image content). A second, self-hosted inference path in the EU is planned but not in operation – no processing takes place over it; provider and region will be named here and in the subprocessor register before it goes live. Other US-parented providers process in EU regions; where US transfers occur they rely on DPF (Vercel) or SCCs (Supabase, which holds no DPF listing of its own). A transfer impact assessment is maintained.

6. Retention

Account: duration of use, deletion after 24 months of inactivity or on request; confirmed marketing lead: until withdrawal (post-handover: park); unconfirmed lead: deleted after 7 days; original photo: transient, never stored; styled image: 30 days; AI routing log: 12 months; security logs: 90 days; consent log: relationship + 3 years (limitation period).

7. Your rights

Access (15), rectification (16), erasure (17), restriction (18), portability (20), objection (21); withdraw consent at any time (Art. 7(3)), as easily as it was given. Requests to max@ultido.com; marketing-related requests are forwarded to the responsible park. You may lodge a complaint with a supervisory authority – for ULTIDO GmbH: the Data Protection Authority of North Rhine-Westphalia (LDI NRW), or your local authority (e.g. AEPD in Spain, APD/GBA in Belgium).

8. Obligation to provide

Email is required for the account and reward; without it the Service cannot be used. Marketing and AI consents are voluntary with no disadvantage if refused.

9. Automated decision-making / profiling

No Art. 22 automated decisions with legal effect. The cross-park persona serves recognition/personalisation only.

10. Minors

An age-threshold check (no date of birth) precedes the optional consents. Consent age follows the park's country (Art. 8 GDPR): Germany 16, Spain 14, Belgium 13. Below the threshold, newsletter and AI image are unavailable; play and reward are unaffected. Details: Doc. 6.

11. Changes & versioning

We update this Notice when processing changes; the published, versioned copy governs ("Version X.Y · as of DD.MM.YYYY" + content hash per handoff_web/index.json). Previous versions are archived append-only.