Privacy Policy
This is an informational English translation. The German version is authoritative; in the event of any discrepancy, the German text prevails.
Protecting your personal data is important to us. In accordance with Art. 13 and 14 GDPR, we inform you below about which data we process when you use 20tps, for what purpose and on what legal basis.
1. Controller
The controller within the meaning of the GDPR is Kembel Entertainment UG (haftungsbeschränkt), named in the Legal Notice. For privacy-related questions, please contact us at the email address stated there.
2. Legal bases and storage periods
Depending on the purpose, we process personal data on the basis of Art. 6 (1) GDPR: to perform a contract or pre-contractual measures (b), to comply with legal obligations (c), on the basis of your consent (a), or to safeguard legitimate interests (f). We store data only for as long as is necessary for the respective purposes or as required by statutory retention periods (in particular commercial and tax periods of up to ten years); after that, it is deleted or restricted.
3. Hosting, server log files and internal operation
When you access our website and use our services, technical connection data is processed in server log files (in particular IP address, time and requested resource). This serves the technical provision, stability and security of the service (Art. 6 (1) (f) GDPR).
For technical operation, error logging and live features (e.g. console, server status, notifications) we use exclusively our own, self-operated systems; no disclosure to third parties takes place here. Error logs may, if you are signed in, include your user identifier, email address and IP address in order to attribute errors (Art. 6 (1) (f) GDPR).
To provide our services, we use data-centre and infrastructure providers with a server location in Germany or the EU as processors (Art. 28 GDPR), on whose servers our application and the servers you book are operated. Data processing agreements are in place with these providers; we make the concrete list available to business customers within the data processing agreement (DPA).
4. Content delivery network and DDoS protection (Cloudflare)
Our website is fronted by the service of Cloudflare, Inc., which delivers, accelerates and protects traffic against attacks (DDoS). This processes technical connection data (in particular your IP address) (Art. 6 (1) (f) GDPR). Cloudflare is a processor; for any transfer to third countries see the section "Transfers to third countries".
5. Customer account and registration
To use our services you create a customer account. We process the data you provide, in particular email address, name or display name, country (to determine VAT), VAT identification number where applicable, and timestamps of registration, sign-in and email confirmation. Processing is carried out to establish and perform the user contract (Art. 6 (1) (b) GDPR) and to comply with tax obligations (Art. 6 (1) (c) GDPR).
6. Payment processing and saved payment methods (Stripe)
We use Stripe to process payments and account top-ups and to manage payment methods technically. You enter payment data directly into Stripe's secure Elements fields. We do not store complete card, bank or account details. We do, however, store the payment-method reference generated by Stripe and the display and management data required for your account (for example payment type, card brand, last four digits, expiry date, status, and the time of authorisation), so that you can recognise, use and remove the method.
When you select “Save payment method” or add a method in your account, you instruct us to use that Stripe reference for later payments initiated by you and, where automatic renewal is enabled, for charges outside an active browser session (off-session). You can revoke this payment instruction for the future by removing the method or disabling automatic renewal. Removing a method linked to a service disables automatic renewal for that service; payments already initiated and statutory retention obligations remain unaffected. If your bank requires additional customer authentication (for example 3-D Secure), the automatic charge cannot be completed; we will ask you to authenticate the payment in a browser session or to retry it manually.
Processing is necessary to perform the contract and your payment instruction (Art. 6 (1) (b) GDPR) and, where applicable, to comply with statutory evidence and retention obligations (Art. 6 (1) (c) GDPR). Stripe may also process payment data outside the EEA, in particular in the United States; section 13 and Stripe's privacy notice apply in addition.
7. Accounting and invoices
For creating and retaining invoices and for accounting, we use accounting software as a processor (server location EU). We process the master and invoice data required for invoicing. The legal basis is compliance with statutory retention and record-keeping obligations (Art. 6 (1) (c) GDPR in conjunction with §§ 147 AO, 257 HGB) as well as the performance of the contract (Art. 6 (1) (b) GDPR).
8. Email delivery
For sending system and notification emails (e.g. email confirmation, password reset, notices about your services) we use an email delivery provider as a processor; processing takes place in the European Union. We process your email address and the respective message content (Art. 6 (1) (b) and (f) GDPR).
9. Object storage and backups
Content you upload (e.g. attachments in support requests, server icons) and backups are stored with object-storage providers. These are located, where possible, in the European Union; encrypted backups may additionally be stored in third countries (including New Zealand). Backups are encrypted client-side before transfer (zero-knowledge); the storage providers therefore only receive encrypted data and have no access to the content in plain text. The legal basis is the performance of the contract and our legitimate interest in secure data storage (Art. 6 (1) (b) and (f) GDPR). We name the concrete providers in the DPA.
10. Support and server provision
For support requests, we process the information and attachments you submit in order to handle your request (Art. 6 (1) (b) and (f) GDPR). To provide the booked service, we also process the content placed on the servers by you and your users (e.g. configurations, worlds, plugins, uploaded files) and technical operating and server logs (Art. 6 (1) (b) GDPR). You are responsible for ensuring that the content you process, and any third-party data (e.g. of your players), complies with data protection law.
11. Reach measurement and marketing
If you consent to the Statistics category in the consent banner, we use Google Analytics 4 (delivered via Google Tag Manager) to understand which pages are used. If you consent to the Marketing category, we additionally use advertising pixels from Meta, TikTok and X to measure whether an ad led to an order and to build audiences.
The legal basis is solely your consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). It is voluntary and can be withdrawn at any time with effect for the future — via "Cookie settings" in the footer of every page. Without consent, none of these services is loaded.
In addition, where you have consented to marketing, we transmit events to Meta and TikTok server-side (Conversions API and Events API respectively). Your email address and customer number are transmitted hashed (SHA-256) only, together with your IP address, browser identification and the identifiers set by the pixels. The purpose is the same measurement as in the browser; the events carry a shared identifier so they are not counted twice. If you withdraw your consent, we delete the data stored for this purpose without delay.
This measurement takes place on our public pages and inside the signed-in customer area. We record the pages you open as well as actions relating to an order — viewing a plan, opening an upgrade or renewal page, and completing an order, each with the plan and price shown. The purpose is to be able to present you with a suitable offer if you abandon a process, and to measure which advertising led to an order.
We do not record the content you manage on your server — in particular console output, files, player data and backups. Our internal administration area is excluded as well.
A complete and always current list of the services used — with provider, purpose, cookie names and storage period — is available in the detail view under "Cookie settings".
12. Cookies
Without your consent we use only cookies that are required for operation (§ 25 (2) TDDDG, Art. 6 (1) (f) GDPR):
- a session cookie for authentication (HttpOnly) so that you stay signed in, and a short-lived cookie for the administrator session;
- a cookie to store your language preference;
- a cookie storing your choice in the consent banner, so we do not have to ask again on every visit (duration: 6 months);
- if you access our site via a referral link (
?ref=…), a cookie to attribute a later order to the referring partner (duration: a few days).
All other cookies — in particular those of the services named in section 11 — are only set after you have consented.
We document your consent so that we can demonstrate it (Art. 7 (1) GDPR). We store a random identifier, the time, the categories chosen, the banner version and your browser identification — not your IP address.
13. Transfers to third countries
We process personal data within the EU wherever possible and, where available, choose EU locations or EU regions of our providers. Insofar as a transfer to a third country takes place – in particular via Stripe, the upstream CDN/security provider and when storing encrypted backups – we base it on an adequacy decision of the EU Commission (for the USA the EU-US Data Privacy Framework insofar as the provider is certified; for New Zealand the adequacy decision applicable there) or on the EU Commission's Standard Contractual Clauses together with supplementary safeguards.
With your consent to the Statistics or Marketing categories (section 11), data is additionally transferred to Google, Meta, TikTok and X. These providers also process data in the USA. Data protection there is not equivalent to EU law: US authorities may access the data without effective legal remedies being available to you. Where a provider is not certified under the EU-US Data Privacy Framework, we base the transfer on your explicit consent (Art. 49 (1) (a) GDPR); we point out this risk in the consent banner. If you do not consent, no such transfer takes place.
14. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Insofar as processing is based on consent, you may withdraw it at any time with effect for the future. A message to the contact address in the Legal Notice is sufficient to exercise your rights.
15. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW). You may also contact the supervisory authority of your habitual residence.
16. Minors
Our offering is also aimed at younger users. Minors may only create an account with the consent of their legal guardians; for consent-based processing we observe the age limit of Art. 8 GDPR.
17. Currency and changes
This privacy policy is currently valid. As our offering evolves or due to changed legal requirements, an update may become necessary.