EnigmaTeams ← Home Pricing
FR EN DE IT

Legal Notice, Terms & Privacy Policy

EnigmaTeams · Last updated: August 2026 · Version 2.1 · Français · Deutsch · Italiano

In short: EnigmaTeams only collects the data strictly necessary to operate the service (first name, questionnaire answers, optional email). No data is sold or shared for commercial purposes. You can request deletion of your data at any time at hello@enigmateams.com.

Table of Contents

  1. Legal Notice (Impressum)
  2. Terms of Use (ToU)
  3. Terms of Sale (ToS)
  4. Personal Data Collected
  5. Your Rights (GDPR & Swiss nDPA)
  6. Cookies & Local Storage
  7. Security
  8. Third-Party Services
  9. International Data Transfers
  10. Representative in the EU
  11. Governing Law & Disputes

1. Legal Notice (Impressum)

Service Operator

EnigmaTeams is a brand operated by:
Fiducium Sàrl
Rue des Beaux-Arts 14, c/o Gaël Ghislain Monney
2000 Neuchâtel, Switzerland
Company ID (UID): CHE-488.904.546
Contact: hello@enigmateams.com
Website: https://enigmateams.com

Hosting

Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, United States
Cloudflare Privacy Policy
Infrastructure certified ISO 27001, SOC 2 Type II.

Editorial Responsibility

Loïc Monney — hello@enigmateams.com

2. Terms of Use

2.1 Acceptance

Using the EnigmaTeams service (hereinafter "the Service") implies full and unreserved acceptance of these Terms of Use. If you do not accept these terms, please do not use the Service.

2.2 Service Description

EnigmaTeams is a web platform enabling the creation and management of social game events (city-hunt, team-building, social evenings). The Service is accessible without installation, directly from any connected device's web browser.

2.3 Permitted Use

The Service is intended for lawful and benevolent use: professional, associative, and private events. Strictly prohibited:

  • Any illegal, fraudulent, or malicious use
  • Collecting personal data from participants without their knowledge
  • Distributing offensive, discriminatory, or illegal content via the questionnaire
  • Attempting to circumvent security measures (rate limiting, tokens)
  • Automated use (bots, scraping) without written authorisation

2.4 Organiser Responsibility

The organiser is solely responsible for the content of questions entered, the proper conduct of the event, and obtaining participant consent for data collection. EnigmaTeams is not liable for user-generated content.

2.5 Availability and Modifications

EnigmaTeams aims for maximum availability but does not guarantee uninterrupted service. EnigmaTeams reserves the right to modify, suspend, or discontinue the Service at any time, with prior notice where possible. Material changes to these Terms will be communicated by email to organisers with active accounts.

2.6 Intellectual Property

All elements of the Service (code, design, texts, logo) are the exclusive property of EnigmaTeams and are protected by Swiss intellectual property law. Any reproduction or use without written authorisation is prohibited. Content created by users (questions, answers) remains their property.

2.7 Limitation of Liability

The Service is provided "as is" without warranty of results. EnigmaTeams shall not be liable for direct or indirect damages arising from use or inability to use the Service. EnigmaTeams' liability is limited to amounts paid for the Service over the preceding 12 months.

3. Terms of Sale

3.1 Offers and Prices

  • Free Plan: free, no credit card required, limited to 6 participants and 3 stages per event.
  • Pro Plan: one-time payment per event, from CHF 29 / EUR 29 depending on participant count (up to 25: from 29; up to 60: from 59; up to 120: from 109). Beyond 120 participants, contact us for an Enterprise quote. Price displayed on the Pricing page and in your dashboard according to your country and local currency. Prices are inclusive of applicable taxes for consumers; exclusive of VAT for registered businesses.
  • Enterprise: custom pricing, separate contract.

3.2 Order Process

Purchasing a Pro licence is done directly from your organiser dashboard. Clicking "Upgrade to Pro" redirects you to a secure Stripe payment page. The order is confirmed by email upon receipt of payment.

3.3 Payment

Payments are processed by Stripe (PCI-DSS certified). EnigmaTeams never has access to your full payment details. Accepted payment methods are those offered by Stripe at the time of purchase.

3.4 Right of Withdrawal (EU Consumers)

Under EU Directive 2011/83/EU on consumer rights, you have 14 days from the date of purchase to exercise your right of withdrawal without giving any reason or paying any penalty.

The Pro plan consists of access to organizing an event: payment immediately activates the Pro features (unlimited participants, customization, etc.), but these only serve to prepare your event — the actual execution of the service only begins when the game is launched. As long as the game hasn't been launched, your right of withdrawal remains fully available. When you launch the game, if your statutory 14-day period hasn't elapsed yet, you'll be asked to confirm: you then request immediate execution of the service and waive your right of withdrawal for this event, in accordance with Article 16(m) of the Directive. This confirmation is timestamped and kept as evidence.

To exercise your right of withdrawal before launching the game, contact us at hello@enigmateams.com.

3.5 Policy for non-EU customers (including Switzerland)

Swiss law does not provide a general right of withdrawal for this type of online purchase. EnigmaTeams nonetheless applies, as a voluntary contractual commitment, the same rule to all customers regardless of their country of residence: as long as the game hasn't been launched, a cancellation request is accepted unconditionally.

3.6 Invoicing and VAT

An invoice is automatically issued after each payment via Stripe. Applicable VAT depends on your country of residence and is calculated at checkout (Swiss VAT 8.1% where applicable, or local EU VAT via the OSS mechanism). Business customers registered for VAT may provide their VAT number to receive invoices excluding tax.

3.7 Defects and Warranty

If the Service does not function as described, contact hello@enigmateams.com. We commit to addressing all complaints within 5 business days and offering a refund or credit if a defect is confirmed and unresolved.

4. Personal Data Collected

4.1 Participants

  • First name (required): identification in the game and leaderboard
  • Email (optional): sending registration confirmation and reminders if provided and consented
  • Questionnaire answers: used to generate quiz questions — displayed anonymously during the game
  • Team assignment (if team mode is enabled)
  • Progress: question answers, jokers used, unlocked fragments, score

4.2 Organisers

  • Organisation name / first name: displayed in participant communications
  • Contact email (optional): Pro communications, magic login link, post-event summary
  • Event configuration: branding, geo-located stages, questions, fragments
  • Payment data: processed exclusively by Stripe (EnigmaTeams stores no banking data)

4.3 Technical Data

  • IP addresses: used for anti-abuse rate limiting, not retained beyond the limitation window (1 hour max)
  • Session tokens: cryptographically secure random strings, stored in Cloudflare KV, expire with the event
  • Access logs: managed by Cloudflare as processor, per their own retention policy (see Cloudflare's privacy policy)

4.4 Legal Basis for Processing

  • Organiser — Contract performance (Art. 6.1.b GDPR): the organiser is our contractual customer; processing their data is necessary to provide the Service.
  • Participant — Legitimate interest of the organiser, carried out by EnigmaTeams on their behalf (Art. 6.1.f GDPR): the participant is not a party to the contract with EnigmaTeams (the organiser is); their data (first name, questionnaire answers) is collected on the organiser's behalf, in the organiser's legitimate interest in running their event. EnigmaTeams acts here as a processor under Art. 28 GDPR (see §4.6).
  • EnigmaTeams' legitimate interest (Art. 6.1.f GDPR): security, anti-fraud, service improvement (for all users).
  • Consent (Art. 6.1.a GDPR): marketing communications, only if explicitly accepted — a dedicated checkbox for the organiser at event creation, a one-click sign-up link in the end-of-event email for the participant. Never added automatically to a marketing list.

4.5 Retention Periods

  • Free events: data automatically deleted after 90 days from creation
  • Pro events: retained until explicit deletion request (max 2 years after creation)
  • Verified reviews: retained until deletion request
  • Payment data: retained by Stripe per their legal obligations (10 years in Switzerland)

4.6 Processing on Behalf of the Organiser (B2B relationship)

When an organiser uses EnigmaTeams to collect data about their own participants (colleagues, clients, members), they act as the data controller under GDPR for that data, and EnigmaTeams acts as a processor (Art. 28 GDPR) on their behalf. A standard Data Processing Agreement (DPA), covering the Art. 28 GDPR guarantees, is available on request for Pro and Enterprise organisers at hello@enigmateams.com.

5. Your Rights (GDPR & Swiss nDPA)

Under the General Data Protection Regulation (GDPR, EU 2016/679) and the Swiss Federal Act on Data Protection (nDPA, in force since 1 September 2023), you have the following rights:

  • Right of access (Art. 15 GDPR / Art. 25 nDPA): obtain a copy of your personal data
  • Right of rectification (Art. 16 GDPR): have inaccurate data corrected
  • Right to erasure (Art. 17 GDPR / Art. 32 nDPA): request deletion of your data ("right to be forgotten")
  • Right to object (Art. 21 GDPR): object to certain processing activities
  • Right to data portability (Art. 20 GDPR / Art. 28 nDPA): receive your data in a structured, machine-readable format
  • Right to restriction (Art. 18 GDPR): request restriction of processing in certain cases
  • Right not to be subject to automated individual decision-making (Art. 22 GDPR / Art. 21 nDPA)

To exercise your rights: hello@enigmateams.com. We respond within 30 days (GDPR legal deadline). Supervisory authorities:

  • 🇨🇭 Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — www.edoeb.admin.ch
  • 🇪🇺 EU: EDPB member authorities list

Self-service erasure: an organiser can delete an individual participant at any time from their dashboard (outside of a live game), or delete their entire event — and thus all associated data — via the dedicated button under "Settings → Danger zone". These actions are immediate and don't require contacting our support.

6. Cookies & Local Storage

EnigmaTeams uses no tracking, advertising, or third-party analytics cookies by default. When audience-measurement tools (Google Analytics) or advertising tools (Google Ads, Meta) are enabled, they only activate after your explicit consent via the banner shown at the bottom of the page — you can reopen it at any time via the 🍪 button, accept all, reject all, or separately customize audience measurement and advertising. Your choice is remembered for a maximum of 13 months, after which you'll be asked again.

The other storage mechanisms used are strictly functional and require no consent, as they do not enable cross-session or cross-site tracking:

  • sessionStorage: current game session (cleared when the tab is closed)
  • localStorage: your event list on the "My Events" page, your cookie consent choice, and the UTM parameters of the campaign that brought your visit (source, campaign...) until an event is created — never shared with a third party, stored locally on your device

7. Security

  • All communications encrypted in transit (HTTPS/TLS 1.3)
  • Cloudflare infrastructure: ISO 27001, SOC 2 Type II, FedRAMP Moderate certified
  • Session tokens: crypto.randomUUID() strings (256 bits of entropy)
  • Organiser PINs: hashed (SHA-256) before storage
  • Rate limiting on all sensitive routes
  • Security headers: CSP, HSTS, X-Frame-Options DENY, Permissions-Policy
  • No user passwords stored: authentication via event PIN only

8. Third-Party Services

🔵 Cloudflare (hosting, KV, CDN)

Primary host. All data stored on Cloudflare infrastructure. Privacy Policy · GDPR

📧 Resend (transactional emails)

Used for transactional emails related to your event (confirmation, invitation, summary, reminders) whenever an email address is provided. Marketing use is separate and always based on explicit consent: an organiser is only added to our newsletter list if they tick the dedicated checkbox (unchecked by default) when creating their event; a participant is only added if they themselves click the sign-up link offered in the end-of-event email — never automatically. You can unsubscribe at any time via the link in every email or at enigmateams.com/unsubscribe. Resend Privacy Policy

🤖 OpenAI (AI assistant, Pro plan only)

Used to generate quiz questions and puzzle fragments. Data sent is limited to the location context entered by the organiser — no participant personal data is transmitted. OpenAI Privacy Policy

💳 Stripe (Pro payments)

PCI-DSS certified payment provider. Banking data never transits through EnigmaTeams servers. Stripe Privacy Policy

🗺️ OpenStreetMap / Leaflet (mapping)

Used to display the stage mini-map in the player app. Map tiles loaded from OpenStreetMap Foundation servers. OSM Privacy Policy

🔤 Google Fonts

Typefaces loaded from Google CDN — implies a connection to Google servers on page load. Google Privacy Policy

9. International Data Transfers

EnigmaTeams is based in Switzerland. Some service providers are established in the United States (Cloudflare, OpenAI, Stripe, Resend). These transfers are governed by:

  • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914/EU)
  • The EU-Swiss adequacy decision for EU → Switzerland transfers
  • Provider-specific certifications (ISO 27001, SOC 2, EU-US Data Privacy Framework for Cloudflare)

For any questions about data transfers: hello@enigmateams.com

10. Representative in the European Union

Fiducium Sàrl (publisher of EnigmaTeams) is established in Switzerland and does not currently have an establishment in the European Union. Under Art. 27 GDPR, a representative established in the EU, tasked with handling requests from supervisory authorities and data subjects residing in the EU, is being appointed. Their contact details will be published here once appointed. In the meantime, any request regarding your GDPR rights can be sent directly to hello@enigmateams.com, which remains the priority point of contact.

11. Governing Law & Disputes

Governing Law

These Terms are governed by Swiss law, in particular the Swiss Code of Obligations (CO) and the Federal Act on Data Protection (nDPA). For consumers residing in the European Union, mandatory consumer protection provisions of their member state continue to apply.

Amicable Resolution

In case of dispute, please contact us first at hello@enigmateams.com. We commit to responding within 5 business days and doing our best to resolve the dispute amicably.

EU Online Dispute Resolution

EU consumers may use the European Commission's ODR platform: ec.europa.eu/consumers/odr

Jurisdiction

Failing amicable resolution, disputes will be submitted to the exclusive jurisdiction of the competent Swiss courts. Mandatory EU jurisdiction rules (Brussels I bis Regulation) apply for EU consumers.

Questions?

Our team responds in French, English, German, and Italian.

✉ hello@enigmateams.com
© 2026 EnigmaTeams · Switzerland 🇨🇭 Home Pricing Dashboard Contact · Français English Deutsch Italiano

With your consent only, we use audience-measurement cookies (Google Analytics) and advertising cookies (Google Ads, Meta) to understand site usage and measure our campaigns. Learn more