Privacy Policy

Last Updated: August 20, 2025

Magicspot.de (“we,” “us,” or “our”) is committed to protecting your personal data and respecting your privacy in accordance with the GDPR and other applicable data protection laws. This Privacy Policy explains how we collect, process, store, and protect your personal data when you use our website (https://magicspot.de) and related services (collectively, the “Services”). By using our Services, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

MagicSpot GmbH i.G. is the data controller responsible for your personal data.

MagicSpot GmbH i.G.
An der Peterstirn 4
97422 Schweinfurt

2. Information We Collect

We collect and process the following categories of personal data:

  1. Personal Data You Provide
    • Email Address: Collected when you sign up for our Services, subscribe to our newsletter, or contact us directly.
    • Twitch OAuth Data: When you log in or register using your Twitch account, we collect your Twitch username, Twitch ID, and email address associated with your Twitch account (subject to your Twitch account settings and consent).
  2. Automatically Collected Data
    • Usage Data: Information about your interactions with our Services, including your IP address, browser type, device information, pages visited, and timestamps.
    • Cookies and Similar Technologies: We use cookies and similar technologies to enhance functionality, analyze usage, and deliver personalized advertisements. For more details, see our Cookie Policy.

We process your personal data based on the following legal grounds under GDPR:

  • Consent (Article 6(1)(a) GDPR): For processing related to marketing communications, personalized advertising, and non-essential cookies. You can withdraw your consent at any time (see Section 7).
  • Contractual Necessity (Article 6(1)(b) GDPR): For processing necessary to provide our Services, such as authenticating your account via Twitch OAuth or managing your account.
  • Legitimate Interests (Article 6(1)(f) GDPR): For analytics, improving our Services, and ensuring their security, provided your rights and freedoms do not override these interests.
  • Legal Obligation (Article 6(1)(c) GDPR): To comply with applicable laws or respond to legal requests.

4. Purposes of Processing

We process your personal data for the following purposes:

  • To Provide and Improve Our Services: To authenticate users via Twitch OAuth, manage accounts, and deliver content and features.
  • Contact Purposes: To send you service-related communications, newsletters, or updates, where you have provided consent or where permitted under applicable law.
  • Advertising Purposes: To deliver personalized advertisements based on your interests, where you have given consent. We may share data with third-party advertising partners for this purpose.
  • Analytics: To analyze user interactions, improve functionality, and enhance user experience.
  • Security: To protect the security and integrity of our Services.
  • Legal Compliance: To comply with legal obligations or respond to lawful requests.

5. Sharing Your Personal Data

We may share your personal data with:

  • Service Providers: Third-party providers who assist us in operating our Services (e.g., hosting, analytics, or marketing platforms), acting as data processors under our instructions and in compliance with GDPR.
  • Advertising Partners: With your consent, we may share data with third-party advertising networks to deliver targeted ads.
  • Twitch: When using Twitch OAuth, certain data is shared with Twitch in accordance with their privacy policy.
  • Legal Authorities: If required by law or to protect our rights, property, or safety, or that of our users.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred, with appropriate safeguards in place.

All third parties with whom we share data are required to comply with GDPR and maintain adequate data protection measures.

6. International Data Transfers

If you are located in the European Economic Area (EEA), your personal data may be transferred to and processed in countries outside the EEA (e.g., for Twitch OAuth or third-party services). We ensure such transfers comply with GDPR by using Standard Contractual Clauses (SCCs) or other approved mechanisms to safeguard your data.

7. Your Data Protection Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of Access (Article 15): To request access to the personal data we hold about you.
  • Right to Rectification (Article 16): To request correction of inaccurate or incomplete data.
  • Right to Erasure (Article 17): To request deletion of your data under certain conditions (e.g., when no longer necessary or if consent is withdrawn).
  • Right to Restrict Processing (Article 18): To limit how we process your data in certain circumstances.
  • Right to Data Portability (Article 20): To receive your data in a structured, commonly used, and machine-readable format and transmit it to another controller.
  • Right to Object (Article 21): To object to processing based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: You may lodge a complaint with a supervisory authority in your country of residence (e.g., Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)).

To exercise these rights, contact us at luca@magicspot.de. We will respond within one month, though this may be extended for complex requests. We may require identity verification before processing your request.

8. Your Choices

  • Email Communications: You can opt out of promotional emails by clicking the unsubscribe link in those emails. Service-related communications (e.g., account updates) are not optional.
  • Twitch OAuth: You can revoke our access to your Twitch account via your Twitch account settings.
  • Cookies: You can manage cookie preferences through our Cookie Consent Tool or your browser settings. Disabling cookies may affect Service functionality.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse, in accordance with GDPR requirements. However, no system is completely secure, and we cannot guarantee absolute security.

10. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. For example:

  • Account data is retained while your account is active and for 1 year after account deletion, unless otherwise required.
  • Marketing data is retained until you withdraw consent or opt out.
  • Usage data is retained for 1 year for analytics purposes.

Data no longer needed is securely deleted or anonymized.

Our Services may contain links to third-party websites, such as Twitch. We are not responsible for their privacy practices. Please review their privacy policies before sharing data.

12. Children’s Privacy

Our Services are not directed to individuals under 16. We do not knowingly collect personal data from children under 16. If we learn such data has been collected, we will delete it promptly.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes by posting the updated policy on our website or by email (where required by law). The updated policy will take effect upon posting or as specified.

14. Contact Us

If you have questions, concerns, or wish to exercise your rights, please contact our Data Protection Officer at:

MagicSpot GmbH i.G.
An der Peterstirn 4
97421 Schweinfurt

You may also contact your local data protection authority if you have concerns about our data practices.