Datenschutzerklärung
Dieser Text ist ein Entwurf, der vor dem Start vom Betreiber und der Rechtsberatung geprüft werden muss.
Version: draft-2
Controller
[Vom Betreiber zu ergänzen] [Vom Betreiber zu ergänzen], [Vom Betreiber zu ergänzen], [Vom Betreiber zu ergänzen] [Vom Betreiber zu ergänzen], [Vom Betreiber zu ergänzen].
Contact: support@mygritwall.com.
What this website does and does not do
The pages of MyGritWall you are reading are served without cookies and without analytics or advertising trackers. Fonts and images are served from the same origin, so your browser contacts no third-party servers while loading these pages.
Public challenge, community and recap pages show only information that its owners chose to make public.
Server logs and hosting
The website runs on infrastructure of Amazon Web Services in the EU region Frankfurt, delivered through a content delivery network. When a page is requested, technical data such as IP address, requested URL, time and user agent is processed to deliver the page, keep it secure and find faults. The legal basis is our legitimate interest in a secure and functioning website (Art. 6 (1) (f) GDPR).
Links to the application
Buttons such as "Open in app" lead to the MyGritWall application. Data processed there (account, challenges, posts, proof) is described in the privacy information of the application.
Health-related tracking in the application
Some challenges are about health, for example weight, sleep, fitness, sobriety or mood. In the MyGritWall application, check-ins, logged values, proof and posts in such challenges are data concerning health. We process them only with your explicit consent (Art. 9 (2) (a) GDPR), which the application asks for once, in plain words, before you first create, join or log in a health-related challenge.
You can say no and still use MyGritWall; you only cannot log in health-related challenges. You can withdraw your consent at any time in Settings, Privacy and data, and choose to delete your health-related data or keep it only for you. We never sell this data and never use it for advertising. Organization admins never see your logged values.
What is shared
Only me: only you see your check-ins, values, proof and posts.
Invite only: the people invited to the challenge see your posts and your place in its progress. Designated verifiers see proof.
Organization only: members of the organization see your posts as the challenge allows. Organization admins see counts and completion rates only, never logged values. Joining an organization challenge is always voluntary, and nothing reports who did not join.
Public: anyone can see public posts, unless the owner of the challenge limits its posts to its participants. Logged health values and proof are never put on a public share card unless you choose that card yourself.
You can always make one post more private than its challenge, never more public.
Joining a challenge and its rules
Some challenges ask the people who run them to approve each join. Your request (your name, profile picture, the time of the request and, if the challenge has rules, the version you accepted) is then shown to the challenge owner and its admins, and for a community or organization challenge also to the people who manage it there. They decide whether you join. You can cancel a request at any time.
When a challenge has rules, we record which version of the rules you accepted and when. The challenge owner and its admins can see this record. We process it to let you take part under the rules you accepted (Art. 6 (1) (b) GDPR). It is part of your participation: it is included in your data export and deleted with your account.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection under Articles 15 to 21 GDPR. Contact us at support@mygritwall.com.
You may lodge a complaint with a supervisory authority: [Vom Betreiber zu ergänzen].