Privacy policy Escape Leipzig

Version: 5 October 2026

We're glad you're visiting www.escapeleipzig.de. Protecting your personal data matters to us. Here we explain in plain terms which data we process, why, on what legal basis, and what rights you have.

1. Controller

The controller for data processing on this website and in our booking system is:

Artur Hammerschmidt (sole proprietorship)
Burgstraße 2, 04109 Leipzig

Phone: +49 341 21829494
Email: info@escapeleipzig.de

Competent supervisory authority: Die Sächsische Datenschutz- und Transparenzbeauftragte, Maternistraße 17, 01067 Dresden (postal address: Postfach 11 01 32, 01330 Dresden)

If you have any questions about data protection, you can reach us at any time at info@escapeleipzig.de.

2. General information on data processing

Personal data is any information relating to you, for example your name, email address or booking details. We only process such data if there is a legal basis for it: either because you have given your consent (Art. 6(1)(a) GDPR), because we are performing a contract with you (point b), because we are fulfilling a legal obligation (point c), or because we have a legitimate interest (point f).

Your rights. You have the right at any time to:

  • access to the data we store about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on a legitimate interest, and at any time to the use of your data for advertising, for example for our request for a review (Art. 21 GDPR).

Where we process data on the basis of your consent, you can withdraw that consent at any time with effect for the future. This does not affect the lawfulness of the processing carried out up to the point of withdrawal.

You also have the right to lodge a complaint with a data protection supervisory authority, for example with the competent authority named above.

Providing your data is generally voluntary. For a booking, however, we do need certain details (for example your name and contact details), without which we cannot handle the contract.

3. Server, hosting and server log files

Our website and our own booking system run on a server that we rent from Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The server is located in a Hetzner data centre in Helsinki (Finland), so within the EU. Hetzner processes the data on our behalf; we have concluded a data processing agreement with them under Art. 28 GDPR. The legal basis is our legitimate interest in running things securely and reliably (Art. 6(1)(f) GDPR) and, for bookings, also the performance of the contract (Art. 6(1)(b) GDPR).

Every time the site is accessed, the server automatically records what are known as server log files. These include the IP address, the date and time of access, the page requested, the browser used and the operating system. This data is technically necessary in order to deliver the website, find faults and fend off attacks (Art. 6(1)(f) GDPR). You'll find how long we store it in section 21.

4. Cookies, local storage and consent

Only a few things are technically necessary on our site: a session identifier that protects our forms against misuse, a setting for your language and the record of your choice in the consent banner. Without them the site does not work as intended, and no consent is needed for them (Section 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR). Exactly which entries these are and how long they stay is set out in our cookie policy.

For statistics (Google Analytics) and marketing (Meta pixel) we ask for your consent first. For this we use our own consent banner, which appears on your first visit. Before you agree, our site does not load anything from Google or Meta (Section 25(1) TDDDG, Art. 6(1)(a) GDPR). We store your choice in your browser's local storage, not in a cookie. You can change or withdraw it at any time via the “Analytics & cookies” link at the bottom of the page.

5. Google Analytics 4

If you agree to statistics, we use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to understand how our website is used: which pages are visited, for how long, roughly where visits come from and at which point a booking is abandoned. Google Analytics works with a pseudonymous identifier (client ID) stored in a cookie on your device, not with your name. Google only uses your IP address to work out your approximate location and, according to Google, does not store it. Google processes this data on our behalf.

Counting bookings and voucher purchases. Once a booking is confirmed or a voucher has been paid for, our server reports this directly to Google Analytics: the experience, the number of people, the amount and a booking or order number, but no names and no contact details. If you have agreed to statistics, our booking page passes on the Google identifier from your browser, so that Google can link the booking to your visit. Without your consent our server sends a random identifier instead, which is not linked to your device. Our server also counts, without an identifier for your device and without your IP address, how often an experience is viewed and how often a booking is started.

Google Ads. Our Google Analytics account is linked to our Google Ads account. This lets us see whether an advert led to a booking. Google may only use the data for advertising purposes, for example to show you relevant adverts, if you have also agreed to marketing; we control this through Google's consent mode.

If you only agree to marketing, our site also loads the Google script, because we measure how well our adverts work through Google Analytics. Google Analytics then sets no cookie of its own and only receives reports of page views; Google Ads may set the _gcl_au cookie to match a booking to the right advert.

Google Signals. If you have agreed to marketing, are signed in to Google and have personalised ads switched on there, Google can link your visits across devices (Google Signals). We only see aggregated reports from this, for example by age group, never individual people.

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via “Analytics & cookies”. We base the counting without an identifier on our legitimate interest in measuring how well our website works (Art. 6(1)(f) GDPR). For data transfers to the USA, see section 20.

6. Meta pixel (Facebook pixel)

If you agree to marketing, we use the Meta pixel (provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland) on our pages, including the room, combo and voucher pages with the booking or voucher form. It lets us measure how effective our advertising on Facebook and Instagram is, for example whether someone books with us after clicking on an advert. It also lets us show you relevant adverts there and build audiences for our advertising, for example from visitors who have looked at a particular experience. Before you agree, the pixel does not load anywhere.

What is sent to Meta. The pixel tells Meta which of our pages you visit and, on room, combo and voucher pages, which experience you are looking at. If you complete a booking in the booking form, it reports the experience booked, the number of people and the total price; for a request, only the experience and the number of people. When you buy a voucher, it reports the amount as soon as you are passed on to the payment page. In addition, there is the information your browser sends with every request (for example IP address, browser type, the address visited and the previously visited address) and the pseudonymous identifiers from the _fbp and _fbc cookies (see cookie policy). Meta can link this data to your Facebook or Instagram account, if you have one, and so match your visit and your booking to an advert. Apart from the experience, the number of people and the amount, the pixel passes nothing from our forms to Meta, in particular not your name, email address, phone number or postal address. We have switched off the pixel's automatic collection of clicks and page content and the automatic matching of contact details (advanced matching).

The legal basis is your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time via “Analytics & cookies”. For data transfers to the USA, see section 20.

For the collection of data through the pixel and its transfer to Meta, we and Meta are joint controllers (Art. 26 GDPR). You can read the essential content of the agreement concluded for this purpose (Meta's Controller Addendum) at https://www.facebook.com/legal/controller_addendum. You can exercise your rights both against us and directly against Meta.

7. Fonts (embedded locally)

Our fonts are stored locally on our server and are loaded directly from there. No connection is made to Google's servers or those of any other font provider, and no data is transferred to third parties in this context.

8. Bookings and requests through our booking system

For bookings and requests we use our own booking system on our server (section 3). We process the details you enter, for example your name, email address, phone number, address, where applicable your company, the chosen experience, time slot, number of people, the age of the group, extras, voucher or discount code, your answer to “How did you hear about us?”, your language and your comment. We use them to handle your booking, to send you the confirmation, a reminder and any changes by email, to settle the bill on site and to deal with cancellations and rebookings. The legal basis is the performance of the contract with you, and for a request the steps prior to entering into a contract (Art. 6(1)(b) GDPR).

To protect against large numbers of fake bookings, we store a check value (hash) of your IP address, formed with a secret key, with every booking and every voucher purchase, not the IP address in plain text (Art. 6(1)(f) GDPR).

If you email us about your booking, or we email you, our system matches the message to your booking using your email address and stores it in the booking history, so that our team knows where things stand. We group your bookings and voucher purchases under your email address, so that we can help you quickly if you have questions (Art. 6(1)(b) and (f) GDPR).

Our previous booking system. Until 5 October 2026, bookings and voucher purchases ran through Regiondo (Regiondo GmbH, Westendstr. 28, 60325 Frankfurt am Main, Germany). We have transferred open bookings and valid vouchers from that period to our own system. The original data remains with Regiondo, which stores it as our processor until the statutory retention periods expire.

9. Buying vouchers and payments through Mollie

If you buy a voucher, we process your name, your email address and the value, as well as the details you add to the voucher itself (for example names for “from” and “to” and a personal message) and, if you would like the printed voucher by post, the delivery address. We store the voucher code and every redemption so that your balance is correct (Art. 6(1)(b) GDPR).

You pay for vouchers and cancellation fees through the payment service provider Mollie (Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands). For this we take you to Mollie's payment page and pass on the amount, a description (for a voucher with the voucher code and its value, for a cancellation fee with the name of the experience) and, as a technical extra detail, our internal voucher or booking number. If you have agreed to statistics, we also pass the Google identifier from your browser to Mollie as a technical extra detail when you buy a voucher, so that the purchase report (section 5) can be linked to your visit after payment. You enter your payment details directly with Mollie. Mollie tells us whether the payment has arrived. Mollie is a regulated payment institution and is itself responsible for processing the payment, in line with its own privacy policy. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

10. Paying on site and receipts (ready2order, PayPal)

When you pay on site, we create the receipt with our till system ready2order (ready2order GmbH, Hintere Zollamtsstraße 17, 1030 Wien, Austria), which contains the technical security device required by law. For this we pass on the service, the price and the booking number as well as your name, your email address and, if given, your company and address, so that the receipt or invoice is linked to the right booking. ready2order processes the data on our behalf. The legal basis is our statutory record-keeping and receipt obligations (Art. 6(1)(c) GDPR in conjunction with Section 146a AO) and the performance of the contract (Art. 6(1)(b) GDPR).

PayPal on site. If you pay with PayPal at the counter, you send the amount from your PayPal account to our PayPal address. PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, 2449 Luxembourg) processes the data of your PayPal account and of the payment. In our PayPal account we see the details of the payment, for example your name, the amount and the time. PayPal is independently responsible for processing the payment and processes your data in line with its own privacy statement. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

11. Email

Our emails run through the servers of Strato AG (Otto-Ostrowski-Straße 7, 10249 Berlin, Germany). We send booking confirmations and other messages through them, and emails to info@escapeleipzig.de arrive there in our mailbox. Strato processes the data on our behalf; there is a data processing agreement under Art. 28 GDPR. Our booking system matches the messages in this mailbox to your booking (section 8).

12. Team calendar and shift planning

So that our team knows which group is coming when, we mirror confirmed bookings into a Google calendar used by our team (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The entry contains the experience, time slot, number of people, your name, your phone number, your email address and your comment, so that the team can reach you with any questions on the day. Our shift planning tool, which also runs on Google, reads the time slot, experience, number of people, name and comment for this. Only our team has access; if someone leaves, we remove their access. The legal basis is carrying out your booking (Art. 6(1)(b) GDPR) and our legitimate interest in reliable shift planning (Art. 6(1)(f) GDPR). For data transfers to the USA, see section 20.

13. Internal team messages (Slack)

For short internal messages to our team we use Slack (provider: Slack Technologies Limited, Salesforce Tower, 60 R801, North Dock, Dublin, Ireland). For requests, cancellations, rebookings and when a group has not turned up, the team gets a message there with the experience, time slot, team size and your name, and for requests also your phone number and email address, so that someone can respond quickly. If you order a printed voucher by post, the team gets the code, the value, the name of the person receiving it and the delivery address there, so that it can send the voucher. If there is an unusually high number of bookings or voucher orders in a short time, the team gets a warning with a shortened email address so that it can spot misuse. The records of calls with our AI phone assistant (section 18) also go there. Slack processes the data on our behalf. The legal basis is carrying out your booking (Art. 6(1)(b) GDPR) and our legitimate interest in quick coordination within the team (Art. 6(1)(f) GDPR). For data transfers to the USA, see section 20.

14. Newsletter

In the booking form you can tick a box to say you would like news from us, at most four times a year. The box is not ticked in advance. We then send you an email with a confirmation link. Only once you click it do we add you to the mailing list (double opt-in). So that we can prove your consent, we store the time you signed up, a check value of your IP address formed with a secret key, and the time you confirmed.

You can unsubscribe at any time via the link in every newsletter email or with a short message to info@escapeleipzig.de. We then put your address on a block list so that you do not receive any more newsletters.

We send the newsletter with newsletter software on our own server (section 3). For delivery we use the email service Amazon Simple Email Service (Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg), with its data centre in Frankfurt am Main, as our processor.

The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future. We store the proof of your consent on the basis of our legitimate interest (Art. 6(1)(f) GDPR).

15. Request for a review

If you booked with us online, we send you one single email after your visit asking for a review, usually a few hours after your time slot. We use the email address from your booking for this and point this out to you in the booking form. The legal basis is our legitimate interest in feedback and reviews (Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG).

You can object to this use of your email address at any time, without incurring any costs other than the transmission costs at the basic rates: by clicking the unsubscribe link in the email or with a short message to info@escapeleipzig.de. We make a note of your objection so that you do not receive any more emails of this kind.

The link in the email takes you to our page www.escapeleipzig.de/bewerten/. If you write to us directly through the form there, section 16 applies. The links to Google, TripAdvisor and Facebook take you to those providers' own pages, where their privacy terms apply.

16. Contact form

If you write to us through the contact form or the form on our review page, we process the details you provide (for example your name, email address and your message) in order to deal with your enquiry and reply to you. The message goes by email through our server to our mailbox (section 11); our booking system also stores it in its message log, and for a booking in the booking history (section 8). The legal basis is our legitimate interest in answering your enquiry (Art. 6(1)(f) GDPR), and for enquiries about a booking additionally the steps prior to entering into a contract or the performance of that contract (Art. 6(1)(b) GDPR).

We delete your enquiry and the associated data as soon as it is no longer needed, at the latest once the matter has been finally settled and no retention obligations stand in the way.

17. Online withdrawal through the website

Through the “Withdraw from a contract” button (German: “Vertrag widerrufen”), in the footer of our pages or at www.escapeleipzig.de/widerruf/, you can withdraw electronically from a contract concluded online. In doing so we process the details you enter in the form (name, email address, details identifying the contract such as a voucher code or order number, and your message) in order to receive, check and handle your withdrawal. After you click “Confirm withdrawal”, you will receive an acknowledgement of receipt by email without delay, with information about the content of your declaration of withdrawal and the date and time it arrived (Section 356a BGB).

The legal basis is the performance or the unwinding of the contract with you (Art. 6(1)(b) GDPR). You'll find how long we store this data in section 21.

18. Contact by phone and AI phone assistant

If you call us, your call may be taken wholly or partly by an AI-supported phone assistant. For the phone infrastructure we use the provider Placetel (provider: Gamma Placetel GmbH, Lothringer Straße 56, 50677 Köln). The AI assistant takes down your request, answers common questions and passes you on to the right place if needed.

The AI itself (speech recognition, language model and voice) is provided by Miyon AG (Im Duxer 42, 9494 Schaan, Liechtenstein, so within the European Economic Area); we use it through Placetel. Miyon processes the data on our behalf; there is a data processing agreement under Art. 28 GDPR. Miyon uses further service providers for this, for example for hosting and for the voice. The conversation with the assistant is not recorded as audio; it is kept as text. A voice message is different: if you speak to our answering machine, your message goes to our mailbox by email as an audio file (section 11) and is kept there like other emails (section 21).

We want to be transparent about this: at the start you're talking to an AI system, not to a person. We process the details mentioned in the conversation in order to take down and deal with your request. For some information the assistant checks free time slots through a technical interface. If you ask about your booking, it uses your phone number or the email address you give to check whether a booking exists, and then only tells you the date, time, room and number of people. If you ask whether your email has reached us, it uses your phone number or email address to search the messages of the last 30 days in our mailbox (section 11), and only learns whether, when and at which location a matching email arrived, not what it says. If you say at the start, for example, that you have called before, it uses your phone number to read the record of your last call to us, so that you do not have to repeat everything. These interfaces run on our own server at Hetzner in Helsinki, so within the EU (section 3).

The record of the call, with your phone number, the course of the conversation as text and a summary, goes to our team in Slack (section 13) and by email to our mailbox (section 11), so that they can call you back or write to you.

The legal basis is handling your request in the course of entering into a contract or within an existing business relationship (Art. 6(1)(b) GDPR) as well as our legitimate interest in being reachable efficiently (Art. 6(1)(f) GDPR). We base the search in our mailbox and the check against your last call on our legitimate interest in clearing up your request quickly and without repetition (Art. 6(1)(f) GDPR); you can object to this (Art. 21 GDPR). We delete the call logs (in Slack and in our mailbox) after three months.

There is no decision based solely on automated processing which produces legal effects concerning you (Art. 22 GDPR). The assistant takes down your request and passes it on to people.

19. Observation in the game room

During the game the game master watches the room live by video camera and listens in live, in order to accompany you, give you clues and step in in an emergency. The cameras in the rooms do not record anything: picture and sound from the observation are neither stored nor passed on. The legal basis for the video observation is our legitimate interest in safely accompanying the game (Art. 6(1)(f) GDPR). Listening in live is part of the service you have booked and therefore performance of the contract (Art. 6(1)(b) GDPR). We point out the observation to you before you enter the room.

20. Data transfers to the USA

Some of the providers we use (Google, Meta, Slack, some of Miyon's service providers and, where applicable, Amazon) also process data on servers in the USA or belong to companies based in the USA. Where a transfer to the USA takes place, we rely primarily on the respective provider's certification under the EU-US Data Privacy Framework, for which an adequacy decision of the EU Commission exists. Where this certification does not apply, we use the EU Commission's standard contractual clauses. A transfer only takes place where you have consented or another legal basis exists.

21. Storage period

We store personal data only for as long as is necessary for the respective purpose:

  • Server log files: the logs are overwritten automatically as soon as they reach a fixed size, usually after a few days.
  • Your choice in the consent banner: until you change it or delete the website data in your browser. For cookies, see our cookie policy.
  • Analytics data (Google Analytics): no more than 14 months.
  • Booking, voucher and payment data as well as receipts: for the duration of handling the contract and then until the statutory retention periods expire, as a rule 8 years for accounting vouchers and invoices and 6 years for business letters, in each case from the end of the calendar year (Section 147 AO, Section 257 HGB).
  • Details we are not required to keep (for example your phone number, your comment and the check value of your IP address), including the entries in the team calendar and the team messages: until the end of the third year after your last time slot (standard limitation period).
  • Newsletter: until you unsubscribe. We keep the proof of your consent for three more years after that, and the block list permanently.
  • Objection to the request for a review: permanently, so that we do not write to you again.
  • Contact enquiries (form, email, phone): until your request has been finally settled; if it concerns a contract, until the retention period for business letters expires.
  • Phone assistant call logs (Slack and mailbox): three months.
  • Declarations of withdrawal (online withdrawal): for the duration of handling your withdrawal and then until the statutory retention and limitation periods expire.

As soon as a statutory retention period expires or the purpose no longer applies, the data is deleted or blocked.