Privacy Policy

Preamble

With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to as "data") we process for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and especially on our websites, in mobile applications, and within external online presences, such as our social media profiles (nachfolgend zusammenfassend bezeichnet als "online offer").

The terms used are not gender-specific.

Last updated: June 6, 2025

Table of Contents

Controller

Daily Quest Nova UG (limited liability)
Kolonnenstr. 8
10827 Berlin

Email address: info@daily-quest.de

Overview of Processing

The following overview summarizes the types of data processed and the purposes of their processing and refers to the data subjects.

Types of Data Processed

  • Inventory data
  • Payment data
  • Contact data
  • Content data
  • Contract data
  • Usage data
  • Meta, communication, and process data
  • Event data (Facebook)
  • Log data

Legal Bases

Under the GDPR, we are required to explain the legal bases of our data processing. The following legal bases apply:

  • Consent (Art. 6(1)(a) GDPR) - The data subject has given consent to the processing of their personal data for one or more specific purposes.
  • Contract fulfillment and pre-contractual inquiries (Art. 6(1)(b) GDPR) - Processing is necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6(1)(c) GDPR) - Processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6(1)(f) GDPR) - Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.

Security Measures

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the varying likelihood and severity of the risk to the rights and freedoms of natural persons.

These measures include, in particular, securing the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data as well as access, input, disclosure, ensuring availability, and separation of the data.

Transmission of Personal Data

In the course of our processing of personal data, it may happen that the data is transmitted to other entities, companies, legally independent organizational units, or persons. Recipients of this data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website.

International Data Transfers

If we process data in a third country (i.e., outside the European Union (EU), the European Economic Area (EEA)) or if the processing takes place in the context of the use of third-party services or disclosure or transfer of data to other persons, entities, or companies, this is only done in accordance with legal requirements.

General Information on Data Storage and Deletion

We delete personal data that we process in accordance with legal requirements as soon as the underlying consents are revoked or other legal grounds for processing no longer exist. This applies to cases where the original purpose of processing no longer exists or the data is no longer needed.

Rights of Data Subjects

Under the GDPR, you have various rights as a data subject, which arise in particular from Articles 15 to 21 of the GDPR:

  • Right to object: You have the right to object to the processing of your personal data at any time.
  • Right to withdraw consent: You have the right to withdraw your consent at any time.
  • Right to access: You have the right to request confirmation as to whether data concerning you is being processed and to request information about this data.
  • Right to rectification: You have the right to request the completion or correction of your data.
  • Right to erasure and restriction of processing: You have the right to request the immediate deletion of your data or alternatively a restriction of the processing of the data.
  • Right to data portability: You have the right to receive your data in a structured, commonly used, and machine-readable format.
  • Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority.

Business Services

We process the data of our customers and clients (hereinafter uniformly referred to as "customers") in order to provide them with our services. The data processed, the type, scope, and purpose of their processing, and the necessity of their processing are determined by the underlying contractual relationship.

Payment Processing

In the context of contractual and other legal relationships, due to legal obligations, or otherwise based on our legitimate interests, we offer efficient and secure payment options to the data subjects and use other service providers in addition to banks and credit institutions (collectively "payment service providers").

Provision of Online Services and Web Hosting

We process user data to provide our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or device.

Use of Cookies

Our website uses only "strictly necessary cookies" that are essential for the website to function properly. These cookies do not require prior consent from users, and therefore we do not use a consent banner.

Registration, Login, and User Account

Users can create a user account. During registration, users are informed of the required mandatory information and processed for the purpose of providing the user account based on contractual fulfillment.

Single-Sign-On Authentication

"Single-Sign-On" or "Single-Sign-On authentication" refers to procedures that allow users to log in to our online services using a user account with a Single-Sign-On provider (e.g., a social network).

Contact and Inquiry Management

When contacting us (z. B. by mail, contact form, email, telephone, or via social media) and in the context of existing user and business relationships, the information of the inquiring persons is processed to the extent necessary to respond to the contact requests and any requested measures.

Web Analytics, Monitoring, and Optimization

Web analytics serves to evaluate the visitor flows of our online offer and can include behavior and interests of visitors on an anonymous basis. With the help of reach analysis, we can, for example, identify at what time our online offer or its functions are most frequently used.