Legal
Privacy Policy
Last updated: October 2026. This policy applies to the website lensgames.de. Our games at lenserver.de have their own privacy notices. Deutsche Fassung.
1. Controller
Dr. Lennard LowegBeethovenstr. 20
65189 Wiesbaden, Germany
Email: games (at) lensgames (dot) de
2. The essentials
- This website sets no cookies and uses no analytics, tracking or advertising services.
- We do not load any external content such as fonts, maps, videos or social media plugins from third parties.
- Messages sent via the contact form are not stored on the web server; they are only forwarded to us by email.
3. Hosting and delivery of the website
Our own server
The website is served from a server we operate ourselves in Germany. The web application itself keeps no access logs (no storage of IP addresses or pages visited). Technical error messages are kept in the system log for no more than 14 days; they never contain content from the contact form.
Cloudflare
To connect our server securely to the internet, to protect it against attacks (e.g. DDoS) and to deliver the site over an encrypted connection, we use services of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (“Cloudflare”). All requests to this website are routed through Cloudflare’s servers. In doing so, Cloudflare processes technically necessary connection data, in particular your IP address, date and time, the requested URL and browser and device information.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in providing the website securely, reliably and quickly. We have concluded a data processing agreement with Cloudflare pursuant to Art. 28 GDPR. Cloudflare is certified under the EU-U.S. Data Privacy Framework, so transfers to the USA are covered by an adequacy decision of the European Commission (Art. 45 GDPR). The EU Standard Contractual Clauses apply in addition. More information: Cloudflare privacy policy.
4. Contact form and contact by email
When you contact us via the contact form or by email, we process the information you provide (name, email address, optionally the selected topic, and the content of your message) solely to handle and answer your request.
- Legal basis: Art. 6(1)(b) GDPR where your request relates to a contract or pre-contractual measures; otherwise Art. 6(1)(f) GDPR (legitimate interest in answering inquiries).
- How it works: Your input is transmitted to our server over an encrypted connection (HTTPS) and immediately forwarded to our mailbox as an email. The form data is not stored on the web server, neither in a database nor in a file.
- Spam protection: To protect against automated submissions we only use checks on our own server: a field that is invisible to humans, a check of how long the form took to fill in, and a limit on the number of messages per IP address. For the latter, your IP address is briefly held in memory and automatically discarded after 15 minutes at the latest; it is never stored permanently. No cookies are set and no external services such as Google reCAPTCHA are used.
- Email service providers: Emails to our address are forwarded via Cloudflare’s “Email Routing” service (see above) to our mailbox at Google (Gmail). Messages from the contact form are delivered via Gmail’s sending service. For users in Europe the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data may be transferred to Google LLC in the USA; Google is certified under the EU-U.S. Data Privacy Framework.
- Retention: We delete your message once your request has been fully dealt with and no statutory retention obligations apply – as a rule no later than 12 months after our last contact.
- Providing your name, email address and message is necessary for us to handle your request and reply to you. Your data is not passed on to any other third parties.
5. Supporting us via Ko-fi
You can support our work voluntarily via the platform Ko-fi, operated by Ko-fi Labs Limited, United Kingdom. On this website we only place ordinary links to ko-fi.com/lensgames; we do not embed any Ko-fi buttons, scripts or widgets. No data is transferred to Ko-fi unless you click such a link.
If you send a tip, Ko-fi and the payment provider you choose there (e.g. PayPal or Stripe) process your data under their own responsibility; please refer to Ko-fi’s privacy policy. We receive the information Ko-fi passes on to creators (e.g. the name you provide, the amount and an optional message) and use it only to process and acknowledge your support and to meet our statutory accounting and tax obligations (Art. 6(1)(b) and (c) GDPR). Such records are kept for the statutory retention periods. An adequacy decision of the European Commission exists for the United Kingdom.
6. Your rights
Within the scope of the law, you have the right to:
- access the personal data we hold about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR).
To exercise your rights, an informal message to the email address above is sufficient.
7. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit(Hessian Commissioner for Data Protection and Freedom of Information)
Gustav-Stresemann-Ring 1
65189 Wiesbaden, Germany
datenschutz.hessen.de
8. Encryption
This website is delivered exclusively over an encrypted connection (HTTPS/TLS), indicated by “https://” and the padlock icon in your browser’s address bar.