Website Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains which personal data is processed when you visit happygamedesign.info and when you contact me.
It applies to this website and its subpages. Use of the Lido Simulator app is covered by the separate policy linked from the relevant project page: App Privacy Policy.
1. Controller and contact
The controller responsible for processing personal data on this website is:
Arno Littmann
Happy Game Design
Friedrich-Ebert-Str. 66
42719 Solingen
Germany
Email: info@happygamedesign.info
You can contact me at this address with privacy questions or to exercise your rights.
2. Website provision and hosting
This website is hosted by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
STRATO provides the technical infrastructure for operating the website and email service. STRATO processes personal data as a processor under an agreement pursuant to Article 28 GDPR.
Technically necessary data is processed when you access the website. This includes in particular:
- the IP address of the accessing device,
- the date and time of access,
- the page or file requested,
- the HTTP status and amount of data transferred,
- information about the browser and operating system used,
- where applicable, the previously visited page, if your browser transmits it.
This processing serves to deliver the website, ensure stable operation, analyse errors and detect and prevent attacks and misuse.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is to provide a functional and secure website.
According to STRATO, IP addresses are stored for no more than seven days to detect and prevent attacks. This is distinct from the access logs available in the hosting customer area, which STRATO says can be accessed for the past six weeks. The availability of these logs does not mean that full IP addresses are stored for that length of time.
I do not combine technical access data with contact enquiries to create personal usage profiles.
Further information is available in STRATO’s privacy information.
3. Cookies, browser storage and external content
The website, including the contact form, currently sets no cookies and uses neither Local Storage nor Session Storage.
No services for personal audience measurement, advertising tracking or social media plugins are integrated.
Images, font files, stylesheets and navigation scripts are served from our own web hosting space. YouTube videos and App Store listings are only linked, rather than embedded as external content.
4. Contact by email and contact form
If you email me or use the contact form, I process the information you provide to handle and answer your enquiry.
The contact form processes:
- your email address,
- the selected topic,
- the subject line,
- your message,
- your name, if you choose to provide it.
Email address, topic, subject and message are required to use the form. Without them, the enquiry cannot be submitted through the form. Providing your name is optional.
For direct emails, sender and technical communication data transmitted by your email provider and any attachments are also processed.
Please do not send passwords, payment details or other sensitive information that is not necessary for your enquiry.
Purpose and legal bases
The data is processed to handle your enquiry and communicate with you.
If your enquiry concerns a contract or steps prior to a contract, the legal basis is Article 6(1)(b) GDPR.
For other enquiries, processing is based on Article 6(1)(f) GDPR. The legitimate interest is to answer questions, support requests and feedback.
Transmission and recipients
The contact form is processed on STRATO’s web hosting space. The message is sent through the hosting email service to my STRATO mailbox.
No external form or CAPTCHA services are used. Your message is not additionally stored in a website database.
Transmission between your browser and the website is encrypted using HTTPS. For email communication, the security of the onward transmission also depends on the email services involved.
Retention period
Contact enquiries and related correspondence are retained for as long as needed to handle the enquiry and any necessary follow-up questions.
The data is then deleted unless statutory retention obligations or other legal grounds require further storage. Data needed to establish, exercise or defend legal claims is retained for the necessary period. In these cases, processing is restricted to the relevant retention purpose.
5. Protecting the contact form against spam and misuse
The contact form uses technical measures to prevent automated submissions, excessive sending attempts and duplicate submissions of the same form.
For this purpose, the following are processed in particular:
- randomly generated form identifiers,
- timestamps,
- a verification value derived from the IP address using a secret key.
This verification value allows sending attempts from the same IP address to be recognised within a limited period. It is pseudonymised and is not treated as anonymous information.
The full IP address and the contents of your message are not saved in this additional spam-protection storage. The hosting provider’s separate processing of technical access data is unaffected.
The protection data is stored in a private server directory outside the publicly accessible website directory. It is taken into account for no more than one hour to limit and identify submissions. Expired entries are cleaned up when a subsequent submission reaches the sending-limit check; without another submission, they may remain stored until that cleanup.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is to protect the contact form and email service from spam and misuse and ensure their availability.
6. Links to other websites
This website contains links to external services, in particular the Apple App Store and YouTube.
These services are not loaded as embedded content merely by visiting the project pages. If you follow an external link, you leave this website. The relevant provider processes data under its own privacy policy.
7. Disclosure of data
Personal data is only disclosed where necessary for the purposes described and where there is a legal basis.
Recipients may include the hosting and email service provider and, where legally required, the competent authorities.
Contact details are not shared for advertising purposes, and personal data is not sold.
8. Your rights
Subject to the relevant legal requirements, you have the following rights:
- Access to information about the processing of your personal data under Article 15 GDPR,
- Rectification of inaccurate data and completion of incomplete data under Article 16 GDPR,
- Erasure of your data under Article 17 GDPR,
- Restriction of processing under Article 18 GDPR,
- Data portability under Article 20 GDPR, where the applicable requirements are met,
- Objection to certain processing under Article 21 GDPR,
- Complaint to a data protection supervisory authority under Article 77 GDPR.
Where processing is based on consent, you may withdraw it at any time with effect for the future. The lawfulness of processing before withdrawal is unaffected.
To exercise your rights, please contact info@happygamedesign.info .
Right to object
Where I process your personal data on the basis of Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation.
I will then stop processing the data concerned unless I can demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.
Right to complain
You may complain to a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the alleged infringement.
The supervisory authority responsible for my place of business is in particular:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
PO Box 20 04 44
40102 Düsseldorf
Phone: +49 (0)211 38424-0
Website: www.ldi.nrw.de
You do not need to contact me before lodging a complaint.
9. Automated decisions
No automated decision-making, including profiling, within the meaning of Article 22 GDPR takes place.
The contact form’s technical sending limits serve solely to protect against spam and misuse.
10. Changes to this Privacy Policy
I update this Privacy Policy when the website’s functions, the processing of personal data or the relevant legal requirements change.
The version published on this website at the relevant time applies.