This policy describes how we process personal data under Regulation (EU) 2016/679 (GDPR) and applicable Romanian law. It complements the Privacy Policy, which describes what data we collect.
1. Data controller
The controller is the entity identified in the Contact details section of this site. Any request concerning your data should be sent to the e-mail address given there.
2. Legal basis for processing
| Purpose | Legal basis |
|---|---|
| Creating and running the game account | performance of a contract (art. 6(1)(b)) |
| Processing payments and issuing fiscal documents | legal obligation (art. 6(1)(c)) |
| Sending the newsletter | consent (art. 6(1)(a)) |
| Fraud prevention and service security | legitimate interest (art. 6(1)(f)) |
| Showing your map position to other players | consent, revocable at any time in settings |
3. Your rights
You have the right to request:
- access to the data we hold about you;
- rectification of inaccurate data;
- erasure ("the right to be forgotten");
- restriction of processing;
- portability, in a structured format;
- objection to processing based on legitimate interest;
- withdrawal of consent at any time, without affecting the lawfulness of
processing carried out beforehand.
Account deletion can be requested directly from the Account deletion page.
4. How long we keep data
- Account data: for as long as the account exists, plus 30 days after deletion
(so an accidental deletion can be reversed).
- Billing records: 10 years, as required by Romanian tax law.
- Newsletter e-mail address: until you unsubscribe.
- Technical logs: 90 days maximum.
5. Who we share data with
We do not sell or rent personal data. We pass on strictly what is necessary to:
- payment processors (NETOPIA Payments, PayPal) — to take payment;
- the transactional e-mail provider — for confirmation messages;
- the hosting provider — to operate the service.
All processors are located in the European Union or provide adequate safeguards for international transfers.
6. Security
Data is transmitted only over encrypted connections (HTTPS). Passwords are stored as hashes and cannot be read by us. Database access is restricted and authenticated.
7. Exercising these rights
Send your request to the e-mail address in the Contact details section. We respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP — dataprotection.ro.