Privacy policy
Welcome to the website of pgnApp, pgnApp Simone Knopf, Lammstr. 9, 76437 Rastatt (hereinafter “pgnApp” or “we”). On this page we would like to inform you about which data pgnApp processes and for what purposes.
1. Name and contact details of the responsible person
Responsible for data processing
pgnApp
Simone Knopf
Lammstr. 9
76437 Rastatt
Phone: +49 177 912 5062
E-Mail: support@pgn-app.com
(hereinafter referred to as “pgnApp” or “we”)
2. Security of your data
Your personal data provided to us is secured by taking technical and organizational security measures so that it is as inaccessible as possible to unauthorized third parties. There is always a residual risk in electronic data processing and no one hundred percent security can be guaranteed.
3. Legal bases for the processing of personal data
The legal bases for the processing of personal data are exceptional circumstances that permit the processing of personal data and are essentially set out in Art. 6 GDPR. The following is an overview of the legal bases.
- Consent given (Art. 6 para. 1 lit. a GDPR) Consent requires that the person giving consent does so in an informed manner and on a voluntary basis. Consent on the basis of Art. 6 para. 1 lit. a GDPR can be revoked at any time and in principle without giving reasons.
- Contract-related data processing (Art. 6 para. 1 lit. b GDPR) The processing of personal data for the initiation or execution of contracts is defined in Art. 6 para. 1 lit. b GDPR.
- Legal obligation (Art. 6 para. 1 lit. c GDPR) Data processing due to a legal obligation can be found in Art. 6 para. 1 lit. c GDPR, for example, we must retain data to comply with certain retention periods under commercial and tax law.
- Legitimate interests (Art. 6 para. 1 lit. f GDPR) The processing of personal data is necessary for the purposes of the legitimate interests pursued by the controller or by a third party and is therefore permitted under Art. 6 (1) (f) GDPR.
4. Your rights under the General Data Protection Regulation (GDPR)
Every natural person has certain rights, which are set out in particular in Articles 15 to 21 and 77 of the GDPR. You have the following rights, which you can assert against us.
- Right to withdraw consent granted in accordance with Art. 7 GDPR You can withdraw your consent to us at any time without giving reasons. The effectiveness of the revocation is not retroactive.
- Right to information according to Art. 15 GDPR (restrictions possible according to § 34 BDSG) You have the right to request information about your processed data and the purposes of the processing at any time.
- Right to rectification in accordance with Art. 16 GDPR You have the right to demand that we rectify any data we process about you that is incorrect or incomplete.
- Right to erasure in accordance with Art. 17 GDPR (restrictions possible in accordance with Section 35 BDSG) You have the right to request the erasure of your personal data that we process about you. If complete erasure is not possible, for example because we have to comply with statutory retention obligations or we can assert legitimate interests for other reasons, we will restrict the use and processing of your data until these reasons no longer apply.
- Right to restriction of processing in accordance with Art. 18 GDPR You are legally entitled to request the restriction of the processing of your personal data. If you wish to do so, please contact the address published under “1. Name and contact details of the responsible person”. You have a right to restriction of processing in the following cases:
- For the duration of the verification of the accuracy of your personal data stored by us, if you dispute its accuracy.
- In the event of unlawful processing of your personal data instead of deletion.
- Instead of deletion in case of necessity on your part for the exercise, defense or assertion of your legal claims if the personal data is no longer required on our part.
- During the period of determining whose interests outweigh yours in the event of an objection pursuant to Art. 21 (1) GDPR.
- After the processing of your personal data has been restricted by you, this data – with the exception of its storage – may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
- Right to data portability in accordance with Art. 20 GDPR You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machinereadable format. If you request the direct transfer of the data to another controller, this will be done subject to technical feasibility.
- Right to object to certain processing operations and direct marketing in accordance with Art. 21 GDPR
If data processing is carried out on the basis of Art. 6 para. 1 lit. e or f GDPR, you have the right to object to the processing of your personal data at any time for reasons arising from your particular situation; this also applies to profiling based on these provisions. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing serves the establishment, exercise or defense of legal claims (objection pursuant to Art. 21 (1) GDPR). If your personal data are processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is associated with such direct marketing. If you object, your personal data will subsequently no longer be used for the purpose of direct marketing (objection pursuant to Art. 21 (2) GDPR). - Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR in conjunction with Section 19 BDSG Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes the General Data Protection Regulation.
5. Hosting
The content and data collected on our website are hosted externally. The personal data collected on this website is stored on the servers of the hoster(s). This may include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website access, images and other data generated via a website. External hosting is carried out for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 para. 1 lit. b GDPR) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 para. 1 lit. f GDPR). If a corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user’s terminal device (e.g. device fingerprinting) within the meaning of the TTDSG. Consent can be revoked at any time.
Our host(s) will only process your data to the extent that this is necessary to fulfill its performance obligations and follow our instructions with regard to this data.
6. Storage period
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. I f you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, the deletion will take place after these reasons no longer apply.
7. Data collection when visiting our website
Cookies
Our Internet pages use so-called “cookies”. Cookies are small data packets and do not cause any damage to your end device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (permanent cookies). Session cookies are automatically deleted at the end of your visit. Permanent cookies remain stored on your end device until you delete them yourself or they are automatically deleted by your web browser.
Cookies may originate from us (first-party cookies) or from third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services from third-party companies within websites (e.g. cookies for processing payment services).
Cookies have various functions. Many cookies are technically necessary, as certain website functions would not work without them (e.g. the shopping cart function or the display of videos). Other cookies can be used to evaluate user behavior or for advertising purposes. Cookies that are required to carry out the electronic communication process, to provide certain functions that you have requested (e.g. for the shopping cart function) or to optimize the website (e.g. cookies to measure the web audience) (necessary cookies) are stored on the basis of Art. 6 para. 1 lit. f GDPR, unless another legal basis is specified. The website operator has a legitimate interest in the storage of necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable recognition technologies has been requested, the processing is carried out exclusively on the basis of this consent (Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG); the consent can be revoked at any time.
You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be restricted. You can find out which cookies and services are used on this website in this privacy policy.
Visit for information purposes If you only use our website for informational purposes, i.e. if you do not register, consent to the setting of non-functional cookies as part of the cookie banner query or otherwise provide us with information, we only collect data that your browser transmits to our server (so-called “server log files”) in addition to the data collected by functional cookies when you visit our website. When you visit our website, we collect the following data, which is technically necessary for us to display the website to you:
- Our visited website
- Date and time at the time of access
- Amount of data sent in bytes
- Source/reference from which you reached the page
- Browser used
- Operating system used
- IP address used (if applicable: in anonymized form)
- (if applicable) Data entered
The processing is carried out in accordance with Art. 6 para. 1 lit. f GDPR on the basis of our legitimate interest in improving the display, stability and functionality of our website. The data will not be passed on to third parties or used in any other way contrary to this purpose without your consent. However, we reserve the right to check the server log files retrospectively if there are concrete indications of illegal use of the websites.
8. Contacting us
Personal data is collected when you contact us (e.g. by telephone, contact form or email). Which data is collected in the case of a contact form can be seen from the respective contact form. This data is stored and used exclusively for the purpose of responding to your request or for contacting you and the associated technical administration. The data collected will not be passed on to third parties. The legal basis for the processing of the data is your implied consent pursuant to Art. 6 para. 1 lit. a GDPR to the use of the transmitted data for contacting you. If your contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b GDPR. Your data will be deleted after the final processing of your request and the expiry of the commercial and tax retention obligations.
9. Data processing for contract initiation and processing and when opening a customer account
If you contact us as an interested party, customer, service provider or supplier, we collect your personal data (e.g. your name or the name of contact persons, address and contact details, payment information, etc.) in accordance with Art. 6 para. 1 lit. b GDPR and process this data to initiate or execute a contract as soon as you provide us with this data in person, by telephone, by post or electronically by including you in our electronic customer and supplier database. Furthermore, we collect your data on the basis of your consent in accordance with Art. 6 para. 1 lit. a GDPR when you open an account on our website. Which data is collected can be seen from the respective query by our employees or from the respective input forms. You can delete your account from our database or from the website or withdraw your consent at any time by sending a message to the above address of the controller. We store and use the data you provide for the purpose of initiating and processing the contract. After complete processing of the contract or deletion of your customer account, your data will be stored with regard to the retention periods under tax and commercial law and deleted after expiry of these periods, unless you have expressly consented to further use of your data or we have reserved the right to further use of your data as permitted by law.
10. Data processing for order processing
In order to process your order, we work together with service providers who support us in whole or in part in the execution of concluded contracts. Certain personal data is transmitted to these service providers in accordance with the following information.
- The data required for payment to payment service providers.
- To shipping service providers the data required for shipping.
The legal basis for the transfer of data is the initiation or execution of the contract in accordance with Art. 6 para. 1 lit. b GDPR.
11. Images and pgn data
Images (chess forms) and pgn data uploaded by you are used for the provision of the commissioned service (in accordance with Art. 6 para. 1 lit. b GDPR) and for the optimization of the software (in accordance with Art. 6 para. 1 lit. f GDPR). The data will not be passed on to unauthorized third parties.
12. Shared folders
You have the option of sharing folders with other users. Your e-mail address and the contents of the folder will be made known to the user you have specified and made available for editing.
If a user shares a folder, they enter the e-mail address of the person with whom they are sharing their folder. The system checks whether an account exists for the specified e-mail address and informs the user of the result (error message if no account exists). This allows a user to recognize whether you have an account based on your e-mail address.
13. Cookies used
Name of the Cookie | Storage duration | Cookie provider | Legal basis |
borlabs-cookie | 60 days | pgn-app.com | functional |
wp-wpml_current_languag | session | pgn-app.com | functional |
__stripe_mid | 1 year | stripe.com | functional |
__stripe_sid | 1 year | stripe.com | functional |
ts | 400 days | paypal.com | functional |
ts_c | 400 days | paypal.com | functional |
tsrce | 1 day | paypal.com | functional |
wp_woocommerce_session_ | 2 days | pgn-app.com | functional |
woocommerce_cart_hash | session | pgn-app.com | functional |
woocommerce_items_in_cart | session | pgn-app.com | functional |
store_notice[notice id] | session | pgn-app.com | functional |
hmt_id | 30 days | hcaptcha.com | anonymous statistics, accessibility |
INGRESSCOOKIE, __cfduid, __cflb, session, sessionid | up to 30 days | hcaptcha.com | Load balancing, forwarding |
hc_accessibility | up to 30 days | hcaptcha.com | barrier-free access |