Privacy Policy.
1. Data controller
The controller responsible for processing personal data on this website is:
Christine Möllers (freelance artist)
Briesestraße 2
12053 Berlin
Email: hello@pluri.world
2. Data collected
We only collect data you actively provide to us (e.g. via the contact form or sign-up list: name, email address) as well as technical data that is automatically generated when you use our website (e.g. IP address, browser type/version, operating system, referrer URL, hostname of the accessing computer, time of server request). This technical data is not linked to your person and is used solely to ensure the functionality and security of our website.
3. Purpose of processing
Your data is used exclusively to process your enquiries. Contact enquiries are processed on the basis of Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). Data is not passed on to third parties.
Sign-up list ("Newsletter")
Email addresses for the sign-up list are only stored with your explicit consent (Art. 6(1)(a) GDPR) and can be unsubscribed at any time by emailing hello@pluri.world. Consent is given by submitting the sign-up form and then confirming your sign-up via the link in our confirmation email (double opt-in).
4. Legal basis
- Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures) for purchases and enquiries
- Art. 6(1)(a) GDPR (consent) for the sign-up list
- Art. 6(1)(f) GDPR (legitimate interest) for technical data and social media profiles
5. Storage period
- Contact data will be deleted after your enquiry has been fully processed, at the latest after 90 days.
- Purchase data will be stored for 10 years in accordance with statutory retention obligations.
- Email addresses on the sign-up list will be stored until consent is withdrawn.
6. Third-party providers
We use Vercel Inc. to host this website. IP addresses and technical data may be transferred to servers in Washington, D.C., USA. Vercel guarantees an adequate level of data protection through EU standard contractual clauses. Vercel Privacy Policy
Ticket sales (pretix)
To sell our access codes we use the ticketing service pretix by rami.io GmbH, Berthold-Mogel-Straße 1, 69126 Heidelberg, Germany. When you place an order, we process your email address, where applicable your name and billing address, and the order data in order to fulfil the contract (Art. 6(1)(b) GDPR). rami.io GmbH processes this data on our behalf (data processing). We retain invoice data in accordance with the statutory retention periods (§ 147 of the German Fiscal Code, AO).
The pretix ticket shop is embedded via a JavaScript widget. As soon as you interact with the widget (e.g. add a ticket to your basket), pretix sets a technically necessary cookie to enable the ordering process and to remember which basket belongs to you. pretix does not store IP addresses, browser information or other unnecessary metadata beyond the duration of your request. More information on data protection at pretix: pretix Privacy Policy
Access-code check (Upstash)
So that a purchased game code can only be redeemed once (protection against sharing and multiple use), on redemption we store solely an irreversible hash of the code together with a timestamp at Upstash, Inc. (USA) in a Redis database. No plaintext codes, no names, no email or IP addresses are stored; the hash cannot be traced back to you. Legal basis is our legitimate interest in preventing misuse (Art. 6(1)(f) GDPR). The data is deleted automatically after around 13 months at the latest. Where data is transferred to the USA, an adequate level of data protection is ensured through the EU-U.S. Data Privacy Framework and EU standard contractual clauses. Upstash Privacy Policy
Slot planner (Upstash)
On the Rixdorf route page you can voluntarily enter a preferred start time so that not too many teams are out on the route at once. In doing so we store solely anonymous counts per date and time (how many teams are registered for a given start time) at Upstash, Inc. (USA) in a Redis database. No names, email or IP addresses and no other personal data are stored; it cannot be traced back to individual persons. The legal basis is our legitimate interest in keeping the route's load considerate towards local residents (Art. 6(1)(f) GDPR). The counts are automatically deleted after around four months at the latest.
Payment processing (Mollie)
Payment is handled by the payment service provider Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. The data required for the payment (e.g. name, payment details, amount) is transmitted directly to Mollie (Art. 6(1)(b) GDPR). More information: Mollie Privacy Policy
For managing our newsletter sign-up list we use Brevo (Brevo SAS). Brevo Privacy Policy
To send emails from our contact form we use Resend (Plus Five Five, Inc., USA). The data you enter in the form (name, email address, message) is transmitted in order to process your enquiry (Art. 6(1)(b) and (f) GDPR). Where data is transferred to the USA, an adequate level of data protection is ensured through EU standard contractual clauses. Resend Privacy Policy
For privacy-friendly, aggregate reach measurement we use Vercel Web Analytics (Vercel Inc.). It collects only aggregated usage data (e.g. pages viewed, device type, approximate region) — without cookies, without cross-device tracking and without identifying individual visitors. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimising reach measurement). Vercel Privacy Policy
Locally hosted web fonts (GDPR compliant)
This website uses the fonts "DM Sans", "Anton", "Space Mono" and "Bowlby One SC", which are stored on our own server and loaded via next/font. No user data is transmitted to external providers like Google Fonts.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and the right to object to the processing of your data. Please contact us at: hello@pluri.world. You also have the right to lodge a complaint with the competent data protection supervisory authority.
8. Cookies
This website uses only technically necessary cookies that are required for the operation of the website. No tracking or advertising cookies are set. As soon as you begin a purchase in the pretix ticket shop, pretix sets a technically necessary cookie to associate your ordering process and basket. Because these cookies are strictly necessary for the service you requested, no consent is required (§ 25(2) TDDDG, formerly TTDSG). Beyond cookies, the Localnauts Player App stores your game progress and any photos taken locally on your device (IndexedDB) — solely so that you can pause and resume the game. This local storage is likewise strictly necessary for the function you are actively using, so no consent is required. No data is transmitted to us or to third parties in the process.
9. Declaration of consent
By submitting the contact form or signing up to the sign-up list, you agree that your data will be processed in accordance with this privacy policy.
10. Social media
We maintain profiles on social networks to share information about localnauts.com and connect with interested visitors. Specifically:
- Instagram (Meta Platforms Ireland Ltd.) — Instagram Privacy Policy
- LinkedIn (LinkedIn Ireland Unlimited Company) — LinkedIn Privacy Policy
- YouTube (Google Ireland Ltd.) — Google/YouTube Privacy Policy
When you visit our social media profiles, the respective platforms collect and process data. We have no influence over this data processing. The legal basis for operating our profiles is Art. 6(1)(f) GDPR (legitimate interest in public communication and reach).
11. Localnauts Player App (localnauts.com/play)
The Localnauts Player App is a browser-based web app accessed after purchase via a personal access code. It works without registration and without a user account. No personal game data is stored on our servers — your game progress stays locally on your device (details below).
- Location data (GPS): The app uses the browser's Geolocation API to check whether the group is near a station. The location calculation is performed exclusively locally in the browser using the Haversine formula. To determine your position, the browser may use GPS as well as nearby Wi-Fi and mobile-network signals; this is handled by your device and browser, not by us. Location data is neither stored on our servers nor transmitted to third parties. GPS use requires active permission from the user and can be revoked at any time in the browser or your device settings. Legal basis: Art. 6(1)(a) GDPR (consent).
- Photos and images: Photos taken with the camera function remain exclusively on the device. There is no upload to our servers and no transfer to third parties. So that you can pause the game and resume it later, your game progress — including the photos taken — is stored locally in the device's browser in an IndexedDB database. This data remains on the device until the game is finished or reset, or until you clear the website data in your browser. The collage feature generates the image entirely client-side in the browser (Canvas API). You can save each photo to your device right after taking it via 'Save to Photos'; at the end of the game you can also download the collage, logbook and diploma. Please save anything you want to keep before finishing or resetting the game or clearing your browser data.
- Microphone (optional speaking task): At one station there is a voluntary repeat-after-me task for which the microphone may be used. The recording happens exclusively locally in the browser and is not stored or uploaded. Using the microphone requires the user's active permission and is not necessary to continue playing. Legal basis: Art. 6(1)(a) GDPR (consent).
- No user account, no personal data storage: The app does not collect any names, email addresses or other personal data. Game progress, team names and answers are stored exclusively locally on your device (IndexedDB in the browser) — solely so that you can pause and resume the game. This data is not transmitted to us or to third parties and can be removed at any time by clearing the website data in your browser.
- Access code: The access code is verified at startup via a secure server request. So that a code can only be used once, only an irreversible hash value is stored (see the 'Access-code check (Upstash)' section above) — no names, no email or IP addresses. The access code itself is not personal data within the meaning of the GDPR.
.png&w=640&q=75)