// privacy
Privacy policy
How Cuiz Game Design handles personal data under the GDPR. Last updated 31 August 2026.
1. Who is responsible
The data controller is Cuiz Game Design, Dieselvej 14, 4. th, 2450 København SV, Denmark, registered in the Danish Central Business Register under CVR-nr. 42254495 (EU VAT DK42254495). Contact: help@cuizgamedesigndk.com or +45 20673491.
We are not required to appoint a Data Protection Officer under Article 37 GDPR and have not appointed one. Data-protection questions go to the address above and are handled by the business owner.
2. What we collect, why, and on what basis
2.1 Game pitch submissions
Data: studio or developer name, your name, contact email, game title, genre, target platforms, build and pitch-deck links, current state of the project, IP and rights position, existing commitments, the text of your pitch, a submission-completeness score computed from those fields, and technical metadata about the submission (timestamp, a truncated network address kept for abuse control, and the reference we issue you).
Purpose: to read and assess your pitch, to reply to you, and to keep a record of what was submitted if a publishing conversation follows.
Legal basis: Article 6(1)(b) — steps taken at your request before entering into a contract — and Article 6(1)(f), our legitimate interest in assessing incoming pitches and running a publishing business. We do not rely on consent for this, which is why the form asks you to acknowledge a notice rather than to consent. Where you tick the separate, optional marketing box, that specific processing rests on Article 6(1)(a) consent and you can withdraw it at any time without affecting anything else.
Retention: declined pitches are erased within 12 months of the decision. Where a publishing conversation or agreement follows, the record is kept for the life of that relationship plus the retention periods Danish bookkeeping law imposes on the resulting business records (currently five years from the end of the financial year).
2.2 Contact messages
Data: your name, email, studio or company, topic, message text, and the same technical metadata as above.
Purpose: to read your message and reply to it.
Legal basis: Article 6(1)(f), our legitimate interest in answering business correspondence, and Article 6(1)(b) where the message concerns a possible contract.
Retention: erased within 24 months unless the correspondence becomes part of a contractual record.
2.3 Server logs and abuse control
Data: the web server records requests, including a network address, the requested address, the response status, timestamp and user-agent string. Form submissions are counted per browser to prevent flooding.
Purpose: keeping the site available, diagnosing faults, and preventing abuse.
Legal basis: Article 6(1)(f), our legitimate interest in the security and availability of our own systems.
Retention: access logs are rotated and deleted within 14 days. Abuse counters expire within two hours.
2.4 Cookies and similar technologies
Strictly necessary cookies and one local-storage entry are used to keep your cookie choice and to make the forms work securely. Analytics and advertising-measurement technologies are used only if you turn them on, and nothing non-essential is set before you do. The complete list is in the cookie policy, and you can change your choice at any time from “Cookie settings” in the footer.
| Name | Type | Category | Retention |
|---|---|---|---|
| cuiz.consent.v1 | localStorage | Strictly necessary | Until you clear it, or until the consent version changes. |
| cuiz_csrf | Cookie | Strictly necessary | Session cookie - removed when you close the browser. |
| cuiz_rl | Cookie | Strictly necessary | 2 hours. |
| _uetsid / _uetvid / MUID | Cookie | Advertising measurement | _uetsid 24 hours, _uetvid up to 13 months, MUID up to 13 months. |
3. What we do not do
- We do not sell personal data, and we do not share it for anyone else’s marketing.
- We do not use automated decision-making or profiling that produces legal effects. A human reads every pitch, and the completeness meter on the pitch form is arithmetic on the fields you filled in, not a decision.
- We do not knowingly collect data from children. This is a business-to-business site.
- This site accepts no file uploads and takes no payment.
4. Who else processes your data
We use service providers who process personal data on our documented instructions, under written processing agreements meeting Article 28 GDPR. Naming them is required, and it is also the reason we never claim your data “stays with us and nobody else” — a processor is not a third party acting for itself, but it is a real recipient and you are entitled to know who it is.
| Processor | Purpose | Location |
|---|---|---|
| Namecheap, Inc. | Virtual private server hosting this website, its database and its application logs | United States |
| Namecheap Private Email | Mailbox for help@cuizgamedesigndk.com and delivery of form notifications | United States |
4.1 Transfers outside the EEA
Both processors above operate the relevant infrastructure in the United States, so personal data submitted through this site is transferred outside the European Economic Area. This is a Chapter V transfer and we disclose it rather than describe our hosting as European.
Safeguard: Standard Contractual Clauses, Module Two (controller to processor), Commission Implementing Decision (EU) 2021/914, as set out in the provider’s published data processing addendum (https://www.namecheap.com/legal/universal/data-processing-addendum/).
Adequacy: No adequacy decision is relied upon for this transfer. Article 13(1)(f) requires us to state the existence or absence of an adequacy decision, not only the safeguard we rely on, so we state it plainly: we rely on the contractual clauses above, not on an adequacy decision.
You may request a copy of the relevant safeguards by writing to help@cuizgamedesigndk.com.
5. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have data erased where the conditions in Article 17 are met;
- have processing restricted while a dispute is resolved;
- receive data you gave us in a portable format, and have it transmitted to another controller where technically feasible;
- object to processing based on legitimate interests, including at any time to direct marketing;
- withdraw consent where processing is based on consent, without affecting processing that already happened.
Write to help@cuizgamedesigndk.com with “Data request” in the subject. We answer within one month, as Article 12(3) requires, and will tell you if a complex request needs the permitted extension. Quoting your pitch reference makes an erasure request much faster.
You can also complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk.
6. Security
The site is served over HTTPS. Form submissions are protected by an anti-forgery token and rate limiting, the API validates every field on the server rather than trusting the browser, and application logs are written without the contents of your message. Access to submissions is limited to the people who need it to do the work. No system is immune to every attack, and we will not claim otherwise; if a breach affects your rights we will notify you and Datatilsynet as Articles 33 and 34 require.
7. Changes
If this policy changes materially — a new processor, a new purpose, a new transfer — we update the date at the top and describe what changed. This version is dated 31 August 2026.