Privacy.
Information on how we handle your personal data.
1) Controller and general information
1.1 We are pleased that you are visiting our website and thank you for your interest. Below we inform you about how your personal data is handled when you use our website. Personal data is any data by which you can be personally identified.
1.2 The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is Marco Uzelino, MaRoJa Escape GmbH, Unterer Geisberg 6, 96129 Strullendorf, Germany, tel.: +49 (0) 951 16090000, email: info@cine-room.de. The controller responsible for the processing of personal data is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1.3 For security reasons and to protect the transmission of personal data and other confidential content, this website uses SSL or TLS encryption. You can recognise an encrypted connection by the string „https://“ and the lock symbol in your browser bar.
2) Data collection when visiting our website (server log files)
When you use our website purely for informational purposes, i.e. if you do not register or otherwise provide us with information, we only collect the data that your browser transmits to our server or to the server of our hosting provider (so-called „server log files“). When you access our website, we collect the following data, which is technically necessary for us to display the website to you:
- the website accessed
- date and time of access
- amount of data sent in bytes
- source/reference from which you reached the page
- browser used
- operating system used
- IP address used (where applicable in anonymised form)
Processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in the secure, stable and functional provision of our website. The data is not passed on or otherwise used. We reserve the right to check the server log files retrospectively should there be concrete indications of unlawful use.
3) Hosting
Our website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA (“Vercel”). When you visit our website, your personal data (e.g. IP address, access data, see server log files) is processed on Vercel's servers or content delivery network.
Processing is carried out in accordance with Art. 6(1)(f) GDPR on the basis of our legitimate interest in a secure and efficient provision of our website. We have concluded a data processing agreement (DPA) with Vercel in accordance with Art. 28 GDPR. As Vercel may also process data in the USA, any transfer to the USA takes place on the basis of the European Commission's standard contractual clauses or – insofar as the provider is certified – the EU-US Data Privacy Framework. Further information can be found in Vercel's privacy policy at: https://vercel.com/legal/privacy-policy.
4) Fonts
To display fonts consistently, we use so-called web fonts. These fonts are embedded locally on our server (self-hosting) and delivered from there. A connection to third-party servers (such as Google Fonts) does not take place; in particular, no data (such as your IP address) is transmitted to Google.
5) Cookies and consent management
Our website uses cookies and similar technologies. Cookies are small text files that are stored on your device. Technically necessary cookies that are required to operate the website are set on the basis of Art. 6(1)(f) GDPR. All other cookies or processing (in particular by optional services) only take place with your consent in accordance with Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG.
To obtain and manage your consent, we use the consent management tool “Cookiebot”, which is integrated via Google Tag Manager. The provider is Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark (Cookiebot is part of the Usercentrics Group). When you access our website, a connection to Cookiebot's servers is established in order to obtain your consent and document it in a data protection-compliant manner. The following data, among others, is processed: your IP address (in anonymised form), the date and time of consent, browser and device information, the URL from which the consent was sent, as well as an anonymous, encrypted key and your consent status. For this purpose, Cookiebot stores a cookie in your browser (usually for 12 months) in order to be able to assign your consent or its withdrawal. Processing takes place within the European Union.
The legal basis is Art. 6(1)(c) GDPR (fulfilment of the legal obligation to obtain and document consent) as well as Art. 6(1)(f) GDPR (legitimate interest in legally compliant consent management). Via the Cookiebot banner, you can grant, adjust or withdraw your consent at any time with effect for the future. Further information can be found in Cookiebot's privacy policy at: https://www.cookiebot.com/en/privacy-policy/.
6) Google Tag Manager
On this website we use Google Tag Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Tag Manager is a tool that allows us to manage website tags via an interface. Google Tag Manager itself does not set any cookies and does not collect any personal data for analysis purposes; it merely serves to manage and trigger other services. On this website, Google Tag Manager is delivered via its own first-party server (a subdomain of the operator's domain).
Insofar as services requiring consent are triggered via Google Tag Manager, these are only activated after your consent in accordance with Art. 6(1)(a) GDPR. Further information can be found in Google's privacy policy at: https://policies.google.com/privacy.
7) Contacting us
7.1 Contact form and email
If you contact us via the contact form or by email, we process the data you provide (in particular name, email address, subject and your message) in order to handle and answer your enquiry. Processing is based on Art. 6(1)(b) GDPR insofar as your enquiry is aimed at concluding or performing a contract, otherwise on the basis of our legitimate interest in answering enquiries in accordance with Art. 6(1)(f) GDPR or your consent in accordance with Art. 6(1)(a) GDPR. Your data will be deleted as soon as the respective conversation has ended and no statutory retention obligations prevent this.
7.2 Delivery via Resend
For the technical delivery of the messages sent via the contact form, we use the Resend service of Resend, Inc. (USA) (“Resend”). The data you enter in the form is transmitted to Resend and delivered from there to us by email. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in reliable and secure email delivery) or Art. 6(1)(b) GDPR. Any transfer to the USA takes place on the basis of the European Commission's standard contractual clauses or the EU-US Data Privacy Framework. Further information: https://resend.com/legal/privacy-policy.
7.3 Spam protection with Cloudflare Turnstile
To protect our contact form against abusive automated use (spam, bots), we use the Cloudflare Turnstile service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (“Cloudflare”). Turnstile checks whether an input is made by a human or automatically. Technical data (including IP address as well as browser and device information) is transmitted to Cloudflare. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protection against spam and abuse. Any transfer to the USA takes place on the basis of the European Commission's standard contractual clauses or the EU-US Data Privacy Framework. Further information: https://www.cloudflare.com/privacypolicy/.
8) Booking and vouchers (QuinBook)
For the online booking of our escape games as well as for the purchase and redemption of vouchers, we use the QuinBook booking system of Woizzer AG, Shanghaiallee 9, 20457 Hamburg, Germany (“QuinBook”). When you make a booking or a voucher purchase, the data required for this (e.g. name, email address, telephone number, where applicable billing address as well as booking and payment data) is transmitted to QuinBook and processed there for the purpose of handling your booking, authentication, processing payments and improving QuinBook's services.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract or implementation of pre-contractual measures). Further information on terms of use and data protection can be found at: https://quinbook.com/en/privacy.
Payment service providers: Payment as part of the booking or voucher purchase is made via the payment service providers PayPal and Stripe. Other payment methods (e.g. Apple Pay or Klarna) are processed via Stripe. During payment, the data required for payment processing (e.g. name, billing and payment information) is transmitted to the respective payment service provider and processed by them under their own responsibility. The legal basis is Art. 6(1)(b) GDPR. The providers are:
- PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg. Privacy: https://www.paypal.com/de/legalhub/privacy-full
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Privacy: https://stripe.com/privacy
The data protection provisions of the respective payment service provider apply in addition.
9) Customer reviews (Trustindex)
To display customer reviews, we embed the review widget of the provider Trustindex Innovation Kft., Budapest, Hungary (“Trustindex”) on our website. The widget is only loaded after your explicit consent. When the widget is loaded, technically necessary data – in particular your IP address as well as browser and device information – is transmitted to Trustindex's servers (within the EU) in order to display the reviews.
The legal basis is Art. 6(1)(a) GDPR (consent). Your consent is voluntary and can be withdrawn at any time with effect for the future. Without consent, only a notice with the option to load the reviews is displayed at the relevant place. Further information: https://www.trustindex.io/terms-and-conditions-and-privacy-policy/.
10) Recipients and transfer to third countries
Your personal data is only passed on to third parties insofar as this is necessary for the performance of the contract, we are legally obliged to do so, this serves to protect legitimate interests or you have consented. As processors, we use in particular the service providers named in this policy. Insofar as data is transferred to providers based outside the EU/EEA (in particular to the USA), we ensure an adequate level of data protection through appropriate safeguards – above all the European Commission's standard contractual clauses or certification under the EU-US Data Privacy Framework.
11) Rights of the data subject
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw consent granted (Art. 7(3) GDPR) with effect for the future
To exercise your rights, a message by post (contact details under point 1) or by email to info@cine-room.de is sufficient. In addition, you have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR).
12) Right to object
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object to this processing at any time for reasons arising from your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
13) Duration of storage of personal data
The duration of storage of personal data is determined by the respective legal basis, the purpose of processing and – where applicable – the respective statutory retention period. In the case of processing on the basis of consent, the data is stored until the data subject withdraws their consent. If statutory retention periods exist, the data is routinely deleted after these periods have expired, provided it is no longer required for the performance or initiation of a contract and/or there is no legitimate interest in its continued storage.
As of: July 2026
