Controller
Laszlo Kardos, sole proprietor (Einzelunternehmer), Zamenhofstraße 9, 01257 Dresden, Germany. Privacy requests can be started through the Mandorka Support Center.
Challenge and WorkProof data
When you start a challenge, Mandorka creates a short-lived session and stores the selected track, assessment version, randomized variant, timestamps, optional referral/campaign information and a pseudonymous client binding. On completion, submitted answer identifiers, score dimensions, WorkProof ID, completion time and integrity metadata are stored. Protected answer keys remain server-side.
Accounts and sessions
If you create an account, Mandorka stores your email address, password verifier data, chosen language, account status and information needed to link paid entitlements. Authentication uses a Secure, HttpOnly, SameSite session cookie. Plain-text passwords are not stored.
Payments, Professional and Pro
Payments use Stripe-hosted Checkout. Stripe processes card/payment credentials and may process billing, device, fraud and transaction information under Stripe's own terms. Mandorka does not store full card details. Mandorka stores relevant Checkout, payment, customer, subscription, invoice and refund identifiers/statuses needed to deliver purchases, subscriptions, Sprint credits, refunds and accounting.
Security and abuse prevention
Protected writes use Cloudflare Turnstile, same-origin checks, bounded payloads, rate limiting and single-use session controls. Mandorka may derive pseudonymous fingerprints from request characteristics such as connecting IP, user agent and language header for abuse prevention. The fingerprint mechanism does not intentionally write the raw IP address into the Mandorka D1 application database.
Affiliate attribution
Affiliate attribution is optional marketing storage. After marketing consent, a valid referral code and optional campaign code can be kept in first-party browser storage for up to 30 days from the latest valid affiliate referral visit. A newer valid affiliate referral replaces the previous one and restarts that window. Mandorka also mirrors the active referral into session storage for same-session link propagation. Withdrawing marketing consent clears stored affiliate attribution. Rejecting marketing storage does not block the core assessment or account service. Affiliate applicants provide a display name, email and program consent; commission events and reversals are recorded server-side.
Employer tools
Public WorkProof verification retrieves the canonical public record for proof identifiers supplied by the user. Employer tools may keep local workspace labels in browser session storage; only identifiers required to fetch canonical records need to be sent to Mandorka.
Purposes and legal bases
Assessment, account and paid-entitlement data is processed to provide the requested service and perform the contract where Article 6(1)(b) GDPR applies. Security and fraud-prevention processing is based on legitimate interests under Article 6(1)(f) GDPR. Optional marketing/affiliate storage is used only with consent. Transaction records may also be retained to satisfy legal obligations.
Processors and infrastructure
Mandorka runs on Cloudflare infrastructure, including Workers and D1, and uses Cloudflare Turnstile for protected actions. Stripe acts as payment infrastructure for Checkout, subscriptions and billing management.
Retention
Short-lived assessment sessions expire quickly. Completed proof, entitlement, transaction, refund and security records may be retained while needed to deliver the service, preserve WorkProof auditability, prevent fraud, reconcile commissions and meet mandatory accounting/legal duties. Account sessions expire and can be revoked.
Public WorkProof
A WorkProof is designed to be shareable. Its public record may contain score, dimension breakdown, assessment version, integrity status, completion timestamp and proof fingerprint. Mandorka does not publish a browsable directory of individual users' proofs by default.
Your rights
Depending on the circumstances, GDPR rights can include access, correction, erasure, restriction, portability, objection and withdrawal of consent. Use the Mandorka Support Center for a protected privacy request. You also have the right to complain to a competent data-protection authority.
Changes
This notice may be updated when products, security controls, processors or legal requirements change. The current version is published on this page.