Privacy policy
We have written this privacy policy to explain, in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679, what information we collect, how we use data, and what rights you have as a visitor to this website. Some of this inevitably sounds technical. We have tried to describe the most important points as simply and clearly as possible.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:
We have not appointed a data protection officer, as the legal conditions requiring one are not met. For any question about data protection, please contact us at the email address above.
2. Legal bases for processing
We process personal data only on one of the following bases:
- Your consent, Article 6 (1) (a) GDPR, for example for sending our newsletter.
- Performance of a contract or steps taken prior to entering into a contract, Article 6 (1) (b) GDPR, for example when you send us an enquiry by email.
- A legal obligation to which we are subject, Article 6 (1) (c) GDPR, for example statutory retention periods.
- Our legitimate interests, Article 6 (1) (f) GDPR, for example the secure and stable operation of this website. In these cases your interests, fundamental rights and freedoms do not override ours.
3. Encrypted transmission using TLS
This website uses an encrypted connection (TLS, still commonly referred to as SSL) to transmit data securely. This reflects the principle of data protection by design under Article 25 (1) GDPR. You can recognise the encryption by the padlock symbol in your browser address bar and by the fact that our address begins with https.
4. Hosting
This website is hosted by an external service provider. In doing so, the provider processes the data that arises when the website is accessed, in particular the access data listed in section 5.
Provider: Namecheap, Inc.
4600 E Washington St, Suite 300, Phoenix, AZ 85034, USA
The legal basis is our legitimate interest in providing this website securely and reliably, Article 6 (1) (f) GDPR. A data processing agreement pursuant to Article 28 GDPR is in place with the provider. As the provider is based in the United States, data may be transferred there. Any such transfer takes place on the basis of the standard contractual clauses adopted by the European Commission.
5. Access data and server log files
Each time this website is accessed, data transmitted by your browser is collected automatically. This comprises:
- IP address
- Operating system
- Browser type and version
- Date and time of access
- Websites from which you reached our site
- Websites you access via our site
- Your internet service provider
This data is technically necessary in order to deliver the website, ensure its stability and defend against attacks. The legal basis is Article 6 (1) (f) GDPR. This data is not analysed for marketing purposes. It is not combined with other data sources.
Log files are deleted after 30 days, unless they are exceptionally required for longer in order to investigate a specific security incident.
6. Contacting us by email
If you write to us by email, we process your address and the content of your message in order to respond to your enquiry. The legal basis is Article 6 (1) (b) GDPR where your message relates to a contract, and otherwise our legitimate interest in responding to enquiries, Article 6 (1) (f) GDPR. We delete your message once it is no longer needed to answer your enquiry and no statutory retention obligations apply.
To run our mailbox we use the service Zoho Mail. For customers within the European Union the provider is Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands. Zoho processes the content and the metadata of your message exclusively on our behalf under an agreement pursuant to Article 28 GDPR. Our account is set up in Zoho's European data centre, so storage takes place within the European Union. Within the Zoho group of companies, data may be transferred to affiliates in the United States and in India. Zoho bases these transfers on the European Commission's standard contractual clauses.
7. Newsletter and free bonus content
Using a form on our website, you can request free bonus content and subscribe to our newsletter. In doing so, we process the following data:
- Your email address, mandatory
- Your first name, optional, so that we can address you personally
- IP address and time of your sign up and of your confirmation
Sign up follows the double opt in procedure. After submitting the form you will receive an email containing a confirmation link. Your address is only added to our list once you click that link. This ensures that nobody can sign up someone else's address. Storing the IP address and the time serves as evidence of your consent.
The purpose of the processing is to send you the bonus content and occasional news about new puzzle books and free extras. The legal basis is your consent under Article 6 (1) (a) GDPR. For documenting that consent we additionally rely on Article 6 (1) (c) and (f) GDPR.
You may withdraw your consent at any time with future effect. The simplest way is the unsubscribe link at the end of every email. Alternatively, an informal message to info@riddlehaus.net is sufficient. Withdrawal does not affect the lawfulness of processing carried out before it.
Your email address is required, because without it we cannot send you anything. Your first name is optional and serves only to address you personally. Leaving it out puts you at no disadvantage, you receive the bonus content and the newsletter just the same.
7.1 Measuring how our emails perform
Our emails contain counting pixels and tracked links. These record whether an email was opened and which links in it were clicked. We evaluate this in order to see which content is read and where we can improve. The legal basis is your consent under Article 6 (1) (a) GDPR, given together with your sign up. You may withdraw it at any time, most easily by unsubscribing from the newsletter.
7.2 Retention and proof of consent
Your data remains stored for as long as the subscription lasts. After you unsubscribe, we keep your address on a suppression list so that you receive no further emails from us. Sign ups that are never confirmed are deleted after 30 days.
The records evidencing your consent, that is the IP address and the timestamps of your sign up and confirmation, are kept beyond that for the standard limitation period of three years under Section 195 of the German Civil Code. The basis for this is our duty to demonstrate consent under Article 7 (1) GDPR and Section 7a of the German Act Against Unfair Competition.
7.3 Service provider for sending
We use the service Brevo to send these emails. The provider is:
Brevo GmbH
Köpenicker Straße 126
10179 Berlin, Germany
Commercial register Berlin-Charlottenburg, HRB 133191
Brevo processes your data exclusively on our behalf. The data processing agreement pursuant to Article 28 GDPR forms part of Brevo's terms of use. Processing takes place mainly in Germany and France. Brevo does, however, also use service providers outside the European Union. Where data is transferred to third countries, Brevo states that it relies on an adequacy decision of the European Commission, for the United States on the EU US Data Privacy Framework, or on the standard contractual clauses. Brevo's own privacy policy is available at www.brevo.com/de/legal/privacypolicy/.
8. Short links and QR codes in our books
The QR codes in our books point to short links at the address go.riddlehaus.net. These short links are provided through the service Hovercode and forward you to the relevant puzzle page. When a short link is opened, technical access data is processed, in particular the IP address, the time of access, the device type and an approximate location derived from the IP address.
The purpose is to carry out the redirect technically and to determine how often the codes are used overall. We do not attribute this data to any identified individual. The legal basis is our legitimate interest in providing working and measurable access to the puzzle content, Article 6 (1) (f) GDPR.
Provider: Hovercode
1 Sopwith Crescent, Wickford, SS11 8YU, United Kingdom
Hovercode processes the data on our behalf under an agreement pursuant to Article 28 GDPR. The transfer to the United Kingdom is based on the European Commission's adequacy decision of 19 December 2025, which extended Implementing Decision (EU) 2021/1772 until 27 December 2031. No additional safeguards are therefore required.
9. Interactive puzzle pages
We provide the hints, solutions and additional puzzles for our books through the service Genially. When you open such a page, the provider processes technical access data such as your IP address, the time of access and browser information in order to display the content. The legal basis is our legitimate interest in providing this content, Article 6 (1) (f) GDPR.
Provider: Genially Web S.L.
Plaza Ramón y Cajal, 4, Planta 4º, 14003 Córdoba, Spain
10. Cookies
On our own pages we use only technically necessary cookies that are required to operate the site. The legal basis is Section 25 (2) TDDDG in conjunction with Article 6 (1) (f) GDPR. No consent is required for these.
11. Retention periods
We store personal data only for as long as it is needed for the relevant purpose or as long as statutory retention periods require. After that the data is deleted or anonymised. The specific periods are stated with each processing activity above.
12. Your rights
You have the following rights in relation to us:
- Access to the personal data we process about you, Article 15 GDPR
- Rectification of inaccurate data and completion of incomplete data, Article 16 GDPR
- Erasure of your data, Article 17 GDPR
- Restriction of processing, Article 18 GDPR
- Data portability, Article 20 GDPR
- Objection to processing based on Article 6 (1) (f) GDPR, Article 21 GDPR
- Withdrawal of consent with future effect, Article 7 (3) GDPR
An informal message to info@riddlehaus.net is enough to exercise any of these rights.
A specific note on the right to object: where your data is processed on the basis of legitimate interests, you may object on grounds relating to your particular situation. Where processing is for direct marketing, you may object at any time without giving reasons.
13. Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right under Article 77 GDPR to lodge a complaint with a data protection supervisory authority if you consider that the processing of your data infringes the GDPR. The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
You may equally contact the supervisory authority for your own place of residence. An overview of all German supervisory authorities is available at www.bfdi.bund.de under Service, Addresses.
14. No automated decision making
We do not use automated decision making, including profiling, within the meaning of Article 22 GDPR.
15. Changes to this privacy policy
We update this privacy policy whenever our services or the legal requirements change. The version published at the time of your visit applies.
Last updated: 23 August 2026