Effective 10 August 2026

Privacy notice

This notice explains how PokerDesk handles personal data. You can browse tournament information and use the Barcelona planner without creating an account or accepting non-essential analytics.

1. Who is responsible

MN River Invest GmbH is the operator of PokerDesk and the controller responsible for personal data processed through pokerdesk.io where applicable.

MN River Invest GmbH
Meidlinger Hauptstraße 7–9/EG 8
1120 Wien, Austria
Company register: FN 614415 b
Register court: Handelsgericht Wien
Managing director: Martin Nielsen

Privacy questions and requests: privacy@pokerdesk.io.

2. What data PokerDesk processes

Browsing and planning on your device

PokerDesk can store tournament selections, entry counts, travel preferences, draft planning details, and a language you choose in your browser. This lets the site restore your choices on that device. Browser-local information is not an account record and is not uploaded merely because you use the planner.

Accounts and saved plans

If you use an account, PokerDesk processes the account identifier, email address, display name, an optional profile-image URL where present, password hash where password login is used, verification status, an optional marketing-email preference and its timestamp, session records, and account timestamps. Information you deliberately save to the account may include plan names and notes, festival or stop details, selected events and entries, origin airport, broad hotel-budget and cabin preferences, and travel notes. Passwords are stored as one-way hashes rather than readable passwords.

An account and external sign-in are optional; public planning remains usable without them. If you choose an account, the required email or provider identifier and authentication fields are necessary to create, identify, and secure it. PokerDesk cannot provide that account function without those required fields.

Facebook and other external sign-in

When an external sign-in option is available and you choose it, the provider first processes the sign-in under its own privacy terms. For Facebook sign-in, PokerDesk may receive a stable Facebook user identifier, name, and email address if Facebook supplies it. PokerDesk uses that information to create or identify the account you requested. It does not silently attach a provider identity to an existing PokerDesk account merely because the email address matches, and it does not retain the provider access token after sign-in. Facebook processes the sign-in under the Meta Privacy Policy.

Messages and privacy requests

If you email PokerDesk, it processes your address, message, delivery information, and related correspondence so it can answer, route, and document the request. Do not send passwords, social-login access tokens, payment-card details, passports, or other unnecessary sensitive information.

Security and reliable operation

Limited request, error, health, authentication, and security records may be generated to deliver the service, diagnose failures, prevent abuse, and protect accounts. These records are operational logs, not advertising profiles, and are kept bounded and purpose-limited.

3. Why PokerDesk processes data

  • To provide accounts, authentication, saved plans, and requested service-related support (GDPR Article 6(1)(b), where processing is needed for the requested service).
  • To secure, maintain, troubleshoot, and improve the reliability of PokerDesk, prevent abuse, and establish or defend legal claims (Article 6(1)(f), legitimate interests).
  • To comply with legal duties, respond to applicable privacy-rights requests, and answer valid authority requests (Article 6(1)(c)).
  • To process optional analytics or marketing only after valid consent where consent is required (Article 6(1)(a)).

Where PokerDesk relies on legitimate interests, it limits the data and balances those interests against users' rights. You may object as described below.

4. Cookies and browser storage

StoragePurposeDuration
Account session cookieKeeps an account securely signed in.Up to 30 days, or until logout.
External sign-in attempt cookieProtects a sign-in attempt against forgery and returns you safely.Up to 10 minutes.
Language cookie and local storageRemembers an interface language you explicitly choose.Up to 365 days from the choice; local value until cleared.
Planner local storageRestores selections and preferences on the same browser.Until you clear it or the saved schedule version is replaced.

You can remove local information through your browser's site-data controls. Doing so may remove a plan that has not been saved to an account, but the public schedule remains usable.

5. Analytics

PokerDesk currently does not run non-essential product or marketing analytics on the public service. It does not currently issue analytics visitor identifiers, build advertising profiles, fingerprint devices, track people across unrelated sites, or collect precise location for analytics.

Before any non-essential analytics is enabled, PokerDesk will update this notice to describe the actual implementation, provide any legally required choice with rejection as practical as acceptance, prevent collection before consent, support withdrawal, and apply a maximum 90-day retention period to raw event-level analytics. Irreversibly anonymized aggregate statistics may be retained longer.

6. Service providers, external sites, and transfers

Personal data is available only to MN River Invest GmbH and service providers that need it to host, secure, authenticate, maintain, or communicate for PokerDesk, and to public authorities where disclosure is legally required. Providers are required to protect the data where applicable.

PokerDesk uses Hostinger Email Services for company email. Hostinger processes sender and recipient details, message and delivery metadata, and message content to deliver and store correspondence. If you choose Facebook or another external sign-in, that provider also processes the sign-in under its own notice before sending the approved account details to PokerDesk.

Some tournament-source, travel, activity, training, calendar, and other links take you to independent third-party sites. A travel link may include the destination, origin airport, and travel dates shown or selected so the third party can open a relevant search. The site also receives the information a browser normally sends when you open it and applies its own privacy notice. PokerDesk does not send your full personal tournament plan merely because you open an external link.

If a provider processes personal data outside the European Economic Area, PokerDesk uses an applicable lawful transfer mechanism where required, such as an adequacy decision or contractual safeguards. You may contact PokerDesk for information about the safeguard relevant to your data.

7. How long data is kept

  • Browser-local plans and preferences remain until you clear them or their saved version is replaced.
  • Account and saved-plan data is kept while needed to provide the account, then deleted or anonymized after a valid deletion request, subject to necessary legal exceptions.
  • Account sessions expire after no more than 30 days; external sign-in attempt cookies expire after no more than 10 minutes.
  • Correspondence is kept only as long as needed to handle the request, meet a legal duty, or establish, exercise, or defend a legal claim.
  • Operational and security records are minimized and retained only as long as needed for their security or reliability purpose.

Restricted continuity backups are not used for ordinary product activity. If data that was validly deleted is present in a backup that cannot immediately be altered, the deletion must be re-applied before restored data is returned to ordinary use, subject to any overriding legal retention duty.

8. Your choices and rights

Subject to applicable conditions, you may request access, correction, deletion, restriction, or portability of your personal data, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing that was lawful before withdrawal. PokerDesk may ask for proportionate information to verify that a requester is entitled to act for the account.

Send requests to privacy@pokerdesk.io. See the data deletion instructions for the shortest deletion route. You may also complain to the Austrian Data Protection Authority or another competent supervisory authority.

9. Automated decisions and data minimization

PokerDesk does not make decisions with legal or similarly significant effects about users through automated processing. The current service does not ask for payment-card or bank details, passport data, or precise location. Sharing a plan is an explicit user action; plans are private by default.

10. Changes to this notice

PokerDesk will revise the effective date and the relevant explanation before materially changing how it processes personal data. A fresh choice will be requested where the change legally requires one.