Overview
This Policy describes the categories of data that may be processed, for what purposes, and which rights you have under GDPR and related laws.
Data Controller
Key Definitions
- Personal data: Information relating to an identifiable person.
- Processing: Any action performed on personal data.
- Controller: Decides the purposes of processing.
- Processor: Acts on behalf of a controller.
What We Collect
- Account identifiers (e.g., username, email)
- Billing metadata if applicable
- Payment tokens (no raw card data)
- Server IPs/ports
- Session & access logs
- Telemetry required for service operation
- HTTP logs
- Firewall / DDoS events
- Fraud prevention indicators
- Support requests
- Error logs/screenshots voluntarily provided
Where Data Comes From
- Direct input by users
- Automatically collected technical data
- Third-party services (e.g., payment providers)
Purposes & Legal Bases
| Purpose | Examples | Legal Basis |
|---|
Processors / Recipients
| Processor Type | Purpose | Region | Safeguards |
|---|
International Transfers
Transfers outside the EEA/UK/CH may rely on Standard Contractual Clauses or equivalent safeguards.
Retention
| Category | Typical Retention |
|---|
Marketing Communications
Marketing communications are sent only with explicit consent and may be withdrawn at any time.
Automated Decisions
No automated decision-making is used that produces legal or significant effects on individuals.
Security Measures
- Encryption in transit
- Access controls
- DDoS protection
- Regular audits and vendor agreements
Your GDPR Rights
- Request your personal data
- Receive data in portable format
- Correct inaccurate data
- Request deletion
- Limit how data is processed
- Object to processing
- Withdraw consent
- Complain to a supervisory authority
How to Exercise Rights
You may exercise your rights through our internal contact system.
Complaints
You may lodge a complaint with any competent supervisory authority in the EEA/UK/CH.
Changes
This Policy may be updated to reflect legal or technical changes.