Legal
Privacy policy
This page explains which personal data is processed when you visit stressfrei20.com, why it is processed and what rights you have. We do not use analytics services, advertising or third-party tracking.
Last updated: 31 August 2026, 20:40 CEST
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Stressfrei20 - Sergej Gajdidej
c/o Online-Impressum #10015
Europaring 90
53757 Sankt Augustin, Germany
Phone: 015679821280
E-mail: privacy@stressfrei20.com
Availability by phone: Monday to Friday from 7:30 to 13:00. A call goes straight to voicemail. Please leave a message there and we will call you back promptly within those hours.
We have not appointed a data protection officer because the legal requirements for doing so do not apply to us. For any data protection question you can reach us directly using the contact details above.
2. What this website is
Stressfrei20.com is a private, non-commercial fan hub of the Stressfrei guild for the game AFK Arena. There are no visitor accounts, no advertising, no newsletter and no analytics or tracking services.
All content is loaded from our own servers. No fonts, scripts, images or embedded content are loaded from third-party providers. Your data is not sold and not shared for advertising purposes.
3. Visiting the website
3.1 Hosting
This website is operated through an external service provider. The provider is Hostinger International Limited, 61 Lordou Vironos str., 6023 Larnaca, Cyprus. The provider processes personal data exclusively on our behalf and on our instructions. The basis for this is a data processing agreement under Art. 28 GDPR, which with this provider is automatically part of its terms of service.
The provider in turn engages sub-processors and names them in its data processing agreement. As at 11 August 2026 the ones listed there are Amazon Web Services EMEA, Google Cloud EMEA, Cloudflare, MailChannels, Proofpoint, Anthropic Ireland and spectra tech. Which of them are involved in delivering this website in any given case is not disclosed by the provider; some of these companies are based in the United States. The authoritative version is whichever data processing agreement is current at the time.
The chosen server location is France and therefore within the European Union. According to what our hosting panel displays, backups are stored in Lithuania, likewise within the EU. We have no public statement from the provider about where backups are stored.
3.2 Server log files
Every time this website is accessed, the hosting provider automatically records data in what are known as server log files. This happens for every page, image or interface request and cannot technically be avoided when operating a website.
We do not analyse this log data in order to identify individual visitors, and we do not combine it with other data sources. The hosting provider additionally makes available an aggregated overview of this log data: the number of requests, the number of distinct IP addresses, the amount of data transferred, and rankings of the most frequent countries of origin and IP addresses. This is an evaluation of the server log files described above, carried out on the server; nothing is stored on or read from your device for this purpose.
The server additionally keeps a technical error log containing only technical messages from program execution. We do not write personal data into it.
3.3 Content delivery network (CDN)
We use our hosting provider's content delivery network to deliver this website. A CDN caches content on servers in various locations and answers requests from the location closest to you. This speeds up page loading and protects the website against overload and attacks. To do so, the CDN automatically checks every request for signs of malicious traffic.
According to the provider, the CDN network also includes locations outside the European Union and the European Economic Area; currently named are South Africa, Japan and Australia, and according to earlier statements by the provider also the USA, Brazil, India and Singapore. Processing of your IP address at a location outside the EU can therefore not be ruled out. See section 8 for details.
According to our own testing, the CDN does not set any cookies on your device during normal operation.
In addition we have set up a block by country of origin in the CDN. Requests from China, Hong Kong, Japan, North Korea and South Korea are refused before the website is delivered. The only thing evaluated for this is the country derived from your IP address; no assessment of individual people takes place, and we have not set up a block on individual IP addresses.
This block is a precaution. It does not stem from any specific incident, and we do not claim that there was one. The reasoning is simply this: the website is aimed at a guild in the German-speaking world, and the smaller the range it can be reached from, the less surface it offers to automated access. If you would like to reach the site from one of the countries named, write to us at privacy@stressfrei20.com and we will find a solution.
4. Storage on your device and consent
This website stores information on your device and reads it again. For this it uses cookies, your browser's local storage and session storage, as well as a file cache (cache storage). The legal basis for this access is sec. 25 TDDDG.
We carry out strictly necessary storage without consent (sec. 25(2)(2) TDDDG). This covers the cookie holding your language selection, the record of your cookie decision itself, the service worker cache and, exclusively for logged-in administrators, a session cookie.
All other storage consists of functional convenience settings and only takes place with your consent (sec. 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR). As long as you have not consented, such settings are kept in session storage only and are discarded when you close the browser tab. If you consent, they are stored permanently. If you decline, we delete functional entries that already exist, stop putting anything new into session storage as well, and switch the settings concerned off: colour theme, font, layout and sort orders are then shown greyed out and can no longer be changed. That is not a punishment for declining but its consequence: without storage a setting cannot be remembered.
You can withdraw your consent at any time with effect for the future. Use the "Change cookie choice" button on the cookie policy for this. You can also delete cookies and local storage in your browser settings at any time.
A complete list of all entries that arise when you visit this website, with storage location, lifetime and purpose, can be found in our cookie policy.
When you open the website your browser also registers a service worker. It stores static files such as stylesheets, scripts and icons in a cache on your device so that the site loads faster and stays usable on a poor connection. Only technical files are stored there, no content about you and nothing that would allow conclusions to be drawn about you. Because it serves solely to deliver the site, we set it up without consent; it therefore also stays in place if you choose "Only necessary". You can clear the cache at any time through your browser settings.
5. Website functions in detail
5.1 Language and display settings
Your language selection is stored in a cookie so that the correct language version is shown on later visits. Your browser additionally remembers the language you last chose locally. That copy is pure convenience and is not needed to deliver the right language version, so it is treated like the other functional settings. Further settings such as colour theme, font, navigation layout, sort orders and notices you have already seen are stored exclusively in your browser and are not transmitted to us.
For the display in the header the website generates a random display name following the pattern "User" plus seven digits, together with a random display picture, locally in your browser. Both are created exclusively on your device, stored there and never transmitted to us.
5.2 Member list, statistics and progress
On this website we publish information about the members of our guild. This information is publicly accessible without any login. It is entered and maintained by our administrators in the administration area.
When a member leaves the guild
When we remove a member from the list, they immediately disappear from the member page and from every chart on the statistics page. In the monthly overviews on the progress page the slot is marked as free: that month's game figures are no longer shown there, but the player name itself remains visible until we delete the monthly entry concerned by hand. A single word says how the departure came about: "Free (stopped NAME)" if someone gave up the game, "Free (left NAME)" if someone left the guild, and "Free (kicked NAME)" in all other cases. We publish nothing beyond that one word: the reason recorded internally stays in the administration area and appears nowhere on the website. The old monthly figures do remain in the database until then, but they no longer leave the server: the interfaces that supply these pages with data check every name against the current member list and strip the figures of members who have left before the response goes out.
The profile itself is retained in full for 14 days after removal so that an accidental removal can be undone. An automated run processes this period once a day, so the deletion takes place at the latest one day after the 14 days have expired. After that, only the player name, player ID, join date, leaving date and the reason for the removal remain in an internal list of former members which is not public. All other details are deleted from the profile, among them previous player names, the internal note and the documentation of a picture permission. Independently of that, a snapshot of your member data may remain in the administration change log for up to twelve months; what is recorded there, and for how long, is described in section 5.8.
If the same player ID is removed a second time, the 14-day period does not apply and the entry moves straight into the list of former members. From two entries for the same player ID onwards, the administration area shows a warning when a member is created; this does not technically prevent a renewed admission.
The legal basis for the list of former members is Art. 6(1)(f) GDPR. Our legitimate interest is recognising, when someone applies to join later, whether they have already been in the guild before. This is only possible via the player ID, because the player name can be changed in the game at any time. Equally, we do not want to unknowingly re-admit people we excluded for repeated breaches of the rules. For this reason no fixed deletion period is set up for this list: an application to join can arrive years later, and a deadline would defeat the purpose. You can object to this storage under Art. 21(1) GDPR. We will then examine in each individual case whether our interest prevails and will delete your entry if it does not.
The display picture taken from the player profile and any stored evidence of a picture permission are held as files on the server. They are deleted together with the rest of the profile once the 14 days have expired, and immediately in the case of a repeat removal.
So that this information does not become findable beyond the circle it is meant for, we instruct search engines not to include the member page, the progress page and the statistics page in their index. The statistics page is included because the chart tooltips name the members behind each band. The pages remain normally accessible to visitors but do not appear in search results, so the information cannot be collected through a search by name.
A special rule applies to display pictures. They too come from the player profile. If a picture shows a game character or another motif from the game, it is part of that profile. If, however, it shows the person themselves, we obtain that member's explicit permission beforehand and only then take the picture from the profile. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with sec. 22 KUG (German Act on the Protection of Copyright in Works of Art). Without permission we use a neutral default image. You can withdraw this permission at any time and we will then immediately replace the picture with a default one.
Are you a member and do not want this? You can object to the publication of your data at any time without any disadvantage to you. Simply contact privacy@stressfrei20.com or the guild leadership directly. We will then remove your details from the member list and delete your entries in all monthly overviews, so that your player name no longer appears there either. On request we will additionally delete your display picture and your entry in the internal list of former members. If you only want us to stop showing your details for the time being without deleting them, tell us: we will then freeze your profile, so it stays stored and still disappears from every public page straight away.
5.3 Display of active administrators
On all public pages we show which administrators are currently active. The user name, the role, an activity status ("Online" or "AFK") and the display picture with its frame are shown.
5.4 Code page: copying, reporting and sharing
Which codes you have already copied or reported is stored exclusively in your browser.
If you report a code as faulty, we transmit to our server the code concerned, the reason you selected from a fixed list, and a randomly generated identifier. This identifier is created in your browser, contains no information about you and is stored on our side only as an irreversible hash value. Its sole purpose is to prevent the same code from being reported more than once by the same person.
The share function lets you pass a code on to messengers or social networks. No content is transmitted automatically in the process. Only when you click one of these links does your browser establish a connection to the respective provider, and that provider's privacy terms apply. The same is true for the link to the game publisher's official redemption page. When you leave our site, at most our domain is transmitted as the origin, never the specific subpage you were viewing.
5.5 Submitting codes
You can suggest a new code to us using a form. Providing a name is voluntary; if you leave the field empty, the submission is recorded as "Anonym".
You are under no legal or contractual obligation to provide us with this data. Without giving a name you can submit the code just the same, and no disadvantage of any kind arises for you. The only thing strictly required is the code itself, because otherwise there is nothing for us to check. Your IP address arises technically with every transmission and cannot be opted out of.
5.6 Push notifications
On the code page you can subscribe to push notifications about new codes. This is entirely voluntary: you have to actively click the subscribe button and additionally confirm your browser's prompt. Without both, nothing is set up and nothing is transmitted.
Technical delivery necessarily runs through the push service of your browser vendor, for example Google, Mozilla, Apple or Microsoft. This service is already contacted by your browser when the subscription is created and thereby learns that a subscription exists for our website. We encrypt the content of our notifications in accordance with the RFC 8291 standard so that it only becomes readable again on your device; the push service cannot read it. What it can see is the subscription address as well as the time and size of the transmission. We have no influence over this processing by your browser vendor.
The code details travel encrypted inside the notification itself. If a reward image belongs to it, your device fetches that image from our server in the background when the notification arrives; the same applies to the code details if a notification exceptionally arrives without content. This produces the server log data described in section 3.2, even if you do not have the website open at that moment.
You can end the subscription at any time using the same button on the code page; we then delete the stored subscription address immediately. You can also revoke notifications in your browser or operating system settings.
5.7 Protected image delivery
Some images are delivered through a protected interface. To prevent overload from automated retrieval, we limit the number of requests per visitor.
5.8 Administration area
The administration area is accessible exclusively to guild administrators and cannot be used by visitors. When logging in we process the user name and the password; the password is stored only as a cryptographic hash value. A session cookie is set for the login.
Changes in the administration area are recorded in a change log so that it remains traceable who changed which content and when. Where an entry concerns a member or a monthly figure, it also records the details affected before and after the change. These entries remain even if the member was removed later; after twelve months at the latest a daily run deletes them. Independently of that, the guild leadership can delete the log itself at any time, either entry by entry or in full. Which fields are recorded in detail is set out in the internal privacy information shown to administrators in the administration area.
6. Contacting us by e-mail or phone
If you contact us by e-mail or phone, we process the information you provide in order to handle your enquiry.
7. Recipients of your data
We do not pass on personal data for advertising purposes and we do not sell it. Data is only transmitted in the following cases:
- Hosting provider: Hostinger International Limited as processor for operating, storing and delivering the website including the CDN, plus the sub-processors that provider engages (see section 3.1).
- Push services of browser vendors: only if you have subscribed to push notifications, and only with encrypted content.
- The public: the information described in sections 5.2, 5.3 and 5.5, to the extent that it is published on the website.
- Public authorities: where we are legally obliged to do so.
8. Transfers to third countries
Our server is located in France, a member state of the European Union. According to what our hosting panel displays, backups are held in Lithuania, likewise in the EU. However, the CDN described in section 3.3 also includes locations outside the EU and the EEA according to the provider. Processing of your IP address in a third country can therefore not be ruled out.
For such transfers our provider relies, according to its own statements, on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR), which form part of its data processing agreement. When subscribing to push notifications, the browser vendor's push service may likewise be operated outside the EU; the content of our notifications is encrypted for it.
9. Storage periods at a glance
| Data | Storage period |
|---|---|
| Server log files at the hoster | Visible in the hosting panel for up to 7 days; the provider does not publicly state any longer period. |
| Language cookie | Up to 12 months |
| Cookie decision | Until you change it or clear local storage |
| Functional settings in the browser | Without consent only for the current visit; with consent until you delete them |
| Service worker cache | Until you clear it in your browser; a new version of the website replaces it |
| Push subscription (visitors and administrators) | Until you unsubscribe or the push service reports the address as invalid |
| Code reports | Until we delete the report, at the latest when the code is revised or deleted |
| IP address of a code submission | When the submission is dismissed or the code is taken over, automatically after 7 days at the latest |
| Rest of a code submission (code, name, timestamp) | No automatic deletion period; deleted on request or by us |
| Member profile | For the duration of the membership; then a 14-day restore window, after which everything except five details is deleted (see next row) |
| List of former members (player name, player ID, joined, left, reason) | Permanently, because an application to join can arrive years later; not public |
| Monthly game figures on the progress page | No automatic deletion period; after a member leaves they are neither displayed nor sent out, but they are stored until the monthly entry is deleted manually |
| Display picture and evidence of a picture permission | Same as the member profile: deleted when the 14 days expire |
| Administration change log | 12 months |
| Last-activity time of logged-in administrators | Two hours after the last activity; immediately on logout |
| Enquiries by e-mail | Until conclusively handled |
10. Your rights
You have the following rights in relation to us:
- Access (Art. 15 GDPR): You can find out whether and which data we process about you.
- Rectification (Art. 16 GDPR): You can have inaccurate data corrected.
- Erasure (Art. 17 GDPR): You can request the erasure of your data.
- Restriction (Art. 18 GDPR): You can require us to only store your data and not use it any further, for instance while we check whether a detail is accurate or whether your objection prevails. For members we set a marker for this: the entry is kept in full but disappears immediately from the member list, the statistics and the progress page. Nothing is deleted in the process.
- Notification to recipients (Art. 19 GDPR): If we have passed your data on to others, we inform them of any rectification, erasure or restriction, as far as that is possible. On request we will tell you who those recipients are.
- Data portability (Art. 20 GDPR): You can receive the data you gave us yourself in a common format. This only covers processing based on your consent or on a contract, which for us means the picture permission, a push subscription and a name voluntarily given with a code submission. The details in the member list rest on a legitimate interest and are not covered.
- Withdrawal of consent (Art. 7(3) GDPR): You can withdraw consent you have given at any time with effect for the future. The lawfulness of processing carried out up to that point remains unaffected.
To exercise your rights, an informal message to privacy@stressfrei20.com is sufficient. We reply within one month at the latest (Art. 12(3) GDPR).
For some of the processing on this website we cannot identify you, and we do not store anything additional just so that we could. A code report hangs on a random identifier from your browser, a push subscription on a subscription address without a name, and the server log files sit with the hosting provider and cannot be searched by person. Where we are unable to make that connection, the rights to access, rectification, erasure, restriction and data portability do not apply, in accordance with Art. 11(2) GDPR.
That is not an excuse but solvable in most cases if you give us the missing clue. For a code submission the code and roughly the time are enough for us to find it. You end a push subscription yourself using the button on the code page, which deletes the stored subscription address immediately. Information about members, by contrast, we can always assign, because the player name and player ID are recorded there.
Before we hand out information or delete anything, we have to be sure that the request really comes from you; giving information to the wrong person would itself be a data breach. If we cannot place you anyway, we will ask you for a short confirmation in the game or for a screenshot of your player profile showing the edit icons that only appear on your own profile. We do not ask for more, and in particular not for any identity document. Whatever you send us for this confirmation is deleted as soon as your request has been dealt with.
Right to object under Art. 21 GDPR
Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation. If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. A message to privacy@stressfrei20.com is sufficient to object.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany.
The address named under section 1 and in the imprint is the delivery address of our imprint service. The competence of the supervisory authority, however, follows our actual place of residence, which is why the federal state named there differs.
11. Minors
This website is not specifically directed at children. Where processing is based on consent, in Germany such consent is only valid from the age of 16; for younger persons the authorisation of the holder of parental responsibility is required. If you are under 16, please do not send us data through the submission form and do not subscribe to notifications without your parents' permission. If we become aware that we are processing a child's data without the required authorisation, we will delete it.
12. No automated decision-making
Automated decision-making including profiling within the meaning of Art. 22 GDPR does not take place. We do not create user profiles and do not analyse your behaviour on this website.
13. Data security
This website is delivered exclusively over encrypted HTTPS; you can recognise this by the padlock symbol in your browser's address bar. In addition we use technical safeguards, among them a strict policy that prevents third-party content from being loaded, and two-factor authentication, which is available for the administration area accounts. Our hosting provider additionally scans the files stored on the server for malware automatically; this happens under the data processing agreement named in section 3.1. We secure our systems according to the state of the art; absolute protection of data transmissions on the internet is nevertheless not possible.
14. Obligation to provide data
You are not obliged to provide us with personal data. The website can be used in full without filling in a form or subscribing to notifications. However, without the technically unavoidable data described in section 3, the website cannot be accessed at all.
15. Changes to this privacy policy
We adapt this privacy policy when the functions of the website or the legal requirements change. The version published here applies in each case. You will find the date of the last change at the top of this page.
In the event of material changes, for example when a new processing activity is added or a purpose changes, we will actively point this out to you rather than relying on you to revisit this page. We record the change in the patch notes, and the update notice on the website points to them. Where a processing activity is based on your consent, we will obtain it again beforehand.