supinionDeutsch

Privacy Policy

Last updated: 28 September 2026

This policy explains which personal data is processed when you use supinion, what we use it for and how long we keep it. The German version of this policy is legally binding; this English version is provided for convenience.

It has three parts:

After that come the sections that apply to all parts: recipients, transfers to third countries, retention, security and your rights.

1. Controller

TELEPANO, owner: Noel Weinberg
operating the brand 1337 Studios; supinion is a service of 1337 Studios.
Eurotec-Ring 15
47445 Moers
Germany
Phone: +49 2841 8887410
Email: hi@supinion.com

We have not appointed a data protection officer because we are not required to (Section 38 BDSG). Please send data protection questions to hi@supinion.com.

2. The short version

3. When we are the controller – and when we act as a processor

We are the controller for the website (Part A), for accounts, sign-in and payment (Part B) and for handling reports (section C.7).

Presentations, slides, images and audience responses are processed on behalf of whoever uses supinion – for example a school, a company or an event organiser. That organisation is the controller within the meaning of Art. 4(7) GDPR. On request to hi@supinion.com, we conclude a data processing agreement with it under Art. 28 GDPR. If you have questions about a specific poll, please contact the person or organisation that ran it; we forward requests we receive to them.


Part A – Website

A.1 Visiting the website

When you visit the website, your browser transmits technically necessary information to our server, including your IP address, the requested address and browser details. We need this information to deliver the page.

A.2 No trackers in your browser, no embedded third-party content

We do not load any analytics or marketing services into your browser, load no third-party scripts and embed no third-party content (no videos, maps, fonts or social media buttons from other servers). We measure the reach of our public pages exclusively on the server, without cookies and without your IP address (A.7). That is why there is no cookie banner: we only set strictly necessary cookies (see B.3).

Some links to supinion contain an addition such as ?ref=… indicating where a visit came from (for example a template or a recommendation). We count these sources on the server, without a cookie and without storing anything on your device.

A.4 Storage in your browser

Besides cookies (B.3), supinion keeps a few entries in your browser's storage. Entries in local storage (localStorage) remain until you delete the website data in your browser; entries in session storage (sessionStorage) disappear as soon as you close the tab. None of these entries is transmitted to us; they are only read in your browser.

EntryStoragePurposeDuration
youpi-langlocalStoragethe language you explicitly chose (de or en)until deleted in the browser
youpi:presentTiplocalStorageremembers that you have already seen the tip about presentinguntil deleted in the browser
youpi:nick:<access code>localStorageremembers that you were already asked for a name in this session; the name itself is not stored in ituntil deleted in the browser
youpi:beforeBuysessionStorageyour plan status before a purchase, to detect the activation after you return from Stripeuntil the tab is closed
youpi:<access code>:<slide>sessionStorageyour own answers on a slide, so they stay visible after reloading the pageuntil the tab is closed

The legal basis for storing and reading these entries is Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act): they are strictly necessary for supinion to work the way you use it.

A.5 Contact by email

If you email us, we process your address and the content of your message to answer you. The legal basis is Art. 6(1)(b) GDPR where your request concerns a contract or its preparation, otherwise Art. 6(1)(f) GDPR (answering enquiries).

A.6 Enquiries from schools and universities, EDU verification

For school and campus licences you can send an enquiry using a form. We process your name, organisation, email address, size and message.

For the EDU plan we check eligibility as follows: if the email address of your account clearly belongs to a school or university, we unlock EDU automatically and only store this note with your workspace. Otherwise you tell us your school and, if you like, add a note, and we check manually. For this we also process the name and email address from your account. You do not upload any files.

A.7 Audience measurement with Matomo

To understand how often the public pages of the website are visited and which channels visitors come from, we use the open-source software Matomo. Measurement happens exclusively on the server: our server reports a page view directly to our Matomo installation at stats.telepano.de. No script runs in your browser for this, no cookies are set and nothing is stored on or read from your device.


Part B – App (accounts)

B.1 Account and sign-in by code

supinion works without passwords. To sign in, you enter your email address and receive a 6-digit code by email.

B.2 Trying supinion without an account

You can try supinion without creating an account. For this we create a guest account with a placeholder address – we do not need your email address.

B.3 Cookies

We only set strictly necessary cookies. They cannot be read by scripts (HttpOnly) and are not sent along to other websites (SameSite=Lax).

CookiePurposeLifetime
youpi_sessionkeeps you signed inexpires after 90 days without use, at the latest after 400 days; guest accounts 7 days
youpi_precognises a device within a live session (random token, see Part C)24 hours

The legal basis for setting them is Section 25(2) no. 2 TDDDG; for the subsequent processing Art. 6(1)(b) GDPR (account) or Art. 6(1)(f) GDPR (participation, see C.2).

B.4 Presentations, images and results

Whatever you create in supinion – presentations, slides, uploaded images (for example from a PDF import), logos and the results of your live sessions – is stored so that we can provide the app. Where an organisation uses supinion, we do this as its processor (section 3).

B.5 Teams and invitations

If you invite others to your workspace, we process their email address to send the invitation. Invitations that are not accepted are deleted after 30 days. The legal basis is Art. 6(1)(b) GDPR towards the inviting workspace and Art. 6(1)(f) GDPR towards the invited person (legitimate interest in working together as a team).

B.6 Payment

Paid plans can be purchased by organisations and – once we enable sales to consumers, with a billing address in the EU – by private individuals. For organisations we process the organisation's name, address, country, VAT ID and billing email for invoicing.

Buying as a private individual. If you buy as a private individual, we process your first and last name instead of an organisation name, plus address and email address. For each purchase we also keep as evidence: contract number, plan, price including VAT, time of the order and of the conclusion of the contract, the end of the withdrawal period and – if you ticked it – the date and time of your request that we begin before the withdrawal period ends. After a withdrawal, the time, the compensation for the service provided and the refund amount are added. Refunds go back to your payment method via Stripe.

Cancellations and withdrawals. When you submit a statement via "Cancel contracts here" or "Withdraw from contract", we store its content (type of cancellation, reason and requested date where given), your name, your email address, what you stated about the contract, the date and time of receipt and the outcome. No sign-in is required; we match the statement to your contract by email address and contract number. We send the acknowledgement of receipt to the address given. We do not store IP addresses. To prevent mass requests we count requests in memory only, with a key that changes daily (see rate-limit keys).

The payment itself is handled by Stripe Payments Europe, Ltd. (Ireland) – with the payment methods offered there (such as card). You enter payment details (such as card number or IBAN) directly with Stripe; we do not receive them. Stripe describes its own role as acting as controller or processor depending on the activity, including as controller for fraud detection and legal compliance. More information: https://stripe.com/privacy and https://stripe.com/legal/privacy-center.

To process each payment event from Stripe reliably exactly once, we keep a marker per event for 90 days.

B.7 Sending emails

Sign-in codes, invitations and account notices are sent via SMTP from noreply@supinion.com. Delivery is handled on our behalf by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (data centres in Germany). The legal basis is Art. 6(1)(b) GDPR.

B.8 Deleting your account

You can delete your account yourself in the app; for safety you confirm this by typing in your email address. This deletes your own workspaces with all their content, including plans unlocked with redeemed codes.

Two exceptions: deletion is blocked while a subscription that has not been cancelled is running or while other members are still in your team. In that case, cancel the subscription first or transfer or empty the team. Invoice records that must be kept by law remain until the retention periods expire (B.6). Deleted data disappears from server backups after 14 days at the latest (section 6).


B.9 Trial only once per email address

So that the 14-day trial cannot be used repeatedly by deleting and re-creating an account, we store a pseudonymised checksum of the email address when an account is created (an HMAC with a server key, not the address itself). The checksum is kept after the account is deleted and erased after 24 months. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing misuse of the free trial.

B.10 Newsletter

If you tick the box for news when getting started or in your settings, we first send you an email with a confirmation link (double opt-in). You only receive news after confirming, at most once a month.

B.11 Feedback and ideas

With the “Feedback” button you can send us ideas, bugs or praise, optionally with a screenshot.

Part C – Audience members

C.1 Who is responsible

The poll you are taking part in is run by a person or organisation – for example your school, your employer or an event organiser. They are responsible for your answers. We operate the technology on their behalf. We pursue purposes of our own only when protecting against abuse (C.4) and when handling reports (C.7).

C.2 What data is processed

C.3 Anonymisation after 24 hours

24 hours after the session ends, the participant identifier is removed from the answers. The deletion job runs every hour, so the identifier is gone 25 hours after the session ends at the latest. If the presenter does not end a session, it ends automatically once nobody has been active and no device has been connected for 12 hours; after a restart of our server, 24 hours after the last activity at the latest.

After that, no answer can be attributed to a device or cookie – including by us. The answers from one device stay linked to each other as one record, for example for quiz points.

A name you entered stays with the results until they are deleted (C.5). If you entered a recognisable name, the results are not anonymous in that respect; please contact the organisation running the session to have it deleted.

C.4 Word filter and moderation

A word filter automatically holds back posts containing offensive terms. They are not deleted, only not displayed. Presenters can also moderate posts themselves. This does not involve any automated decision with legal effect within the meaning of Art. 22 GDPR. The legal basis is Art. 6(1)(f) GDPR (protecting participants from insults).

C.5 Retention

Session results are kept for 12 months after the session ends unless the presenter deletes them earlier. After that they are deleted automatically.

C.6 Children and young people

Schools also use supinion with pupils, including minors. They take part without an account; they only give a name if the teacher requires it, and then a nickname is enough. We ask schools to remind pupils not to include personal details in free-text answers.

C.7 Reporting content

Every audience view has a “Report content” option. When you report something, we store the reason (illegal, hate/incitement, insult/bullying, personal data, spam, other), your note, the affected session and slide and – only if you wish – your name and an email address for our reply.

How we handle reports is described on the page “Point of contact and reports”: https://www.supinion.com/en/contact-point


4. Recipients

RecipientTaskRole
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germanyserver operation (Falkenstein data centre, Germany), sending emails, storage of the encrypted off-site server backup, server for audience measurement (Matomo at stats.telepano.de, see A.7)processor
Stripe Payments Europe, Ltd. (Ireland)payment processingcontroller or processor depending on the activity (see B.6)

The off-site backup is encrypted with the tool age before transfer. The storage location only sees encrypted data.

To pay, the app redirects you to a Stripe page. Stripe's privacy policy applies there; on its pages Stripe sets its own cookies and processes, among other things, your IP address (https://stripe.com/privacy).

Beyond this, we only disclose data where we are legally obliged to (for example by order of an authority).

5. Transfers to third countries

Our server is located in Germany. We ourselves do not transfer data to countries outside the EU/EEA.

Stripe states that it transfers personal data to countries outside the EEA, including the USA and India. According to Stripe, it relies on its certification under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision, and on the EU Standard Contractual Clauses. Stripe is responsible for these transfers where it acts as controller.

Email delivery, the off-site backup and audience measurement also run at Hetzner Online GmbH in data centres in Germany.

6. Retention at a glance

DataRetention
Sign-in codes (as HMAC)1 day
Sign-in (youpi_session)90 days without use, at most 400 days; guests 7 days
Newsletter subscriptionuntil you unsubscribe or delete your account; unconfirmed 30 days
Feedback including page and browser identifier12 months, immediately on account deletion
Guest account without sign-up, including content7 days
Participant cookie youpi_p24 hours
Participant identifier (token hash) attached to answersuntil 24 hours after the session ends (hourly deletion job), then anonymised
Nickname or name in a quiztogether with the session results
Session results12 months after the session ends (can be deleted earlier)
Deleted presentationspermanently after 30 days
Unused images30 days
Open team invitations30 days
School and campus enquiries, EDU proofs12 months
Reports12 months after receipt
Name, note and contact address in reports90 days after the decision
Payment event markers90 days
Account datauntil the account is deleted
Referral sources (?ref=), counters and link to the account180 days
Checksum of the email address for the trial24 months
Billing dataduring the contract and 3 months afterwards; accounting records under Section 147 AO
Purchase records for consumer purchases, cancellation and withdrawal statementssee B.6
Audience measurement (Matomo), raw data180 days, then aggregated reports only
Server backups14 days
Rate-limit keysin memory only, daily salt

7. Security

Connections to supinion are encrypted with TLS (HTTPS, HSTS). Sign-in codes and session tokens are stored only as a check value or hash; IP addresses are not stored at all. Off-site backups are encrypted before transfer.

8. Your rights

You have the right to

Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

There is no automated decision-making, including profiling (Art. 22 GDPR); blocks following reports are decided by a human.

An email to hi@supinion.com is enough. As an audience member, please contact the organisation that ran the poll (C.1). Please note: after anonymisation (C.3) we can no longer attribute answers to anyone and therefore cannot provide information about them.

9. Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de.

10. Obligation to provide data

For an account we need your email address, because otherwise we cannot send you a sign-in code. All other account information is optional. As an audience member you do not have to provide any information about yourself. If the presenter requires a name (C.2), you cannot answer without one; a nickname is enough.

11. Changes

When supinion changes, we update this policy. The version published here applies.