Welcome Back

New here? Create an account

Cancel current build?

This will stop the current build and refund 75% of its cost. Are you sure?

VoidVerse

Privacy Policy

Last Updated: September 2026

1. Controller and Contact Information

The controller responsible for data processing on this website and in the game pursuant to Article 4(7) of the EU General Data Protection Regulation (GDPR / DSGVO) is:


admin@voidverse.net


(hereinafter referred to as the "Operator", "we", or "us").

2. Core Principle: Zero Tracking and Data Minimization

We design and operate this browser game strictly under the principles of data minimization and privacy by design (Art. 5(1)(c) and Art. 25 GDPR).

  • No Analytics or Web Trackers: We do not use Google Analytics, Matomo, Plausible, or any other tracking tools.

  • No Advertising or Profiling: We do not embed ad banners, affiliate networks, tracking pixels (such as Meta Pixel), or behavior-tracking SDKs.

  • No External CDNs / Fingerprinting: Font files, CSS frameworks, scripts, and graphical assets are delivered directly from our own infrastructure or secure hosting provider—not loaded via third-party tracking CDNs.

  • No Third-Party Cookies: We set no marketing, targeting, or statistical cookies.

3. Data Processing During Website Visit (Server Log Files)

When you access our game website, your web browser automatically transmits connection data that is technically necessary to establish the connection and deliver pages securely.

Collected Data:

  • IP address of the requesting device

  • Date and time of the server request

  • Uniform Resource Identifier (URI / page path requested)

  • HTTP status code (success, not found, server error)

  • Transferred data volume in bytes

  • Browser type, browser version, and operating system (User-Agent string)

  • Referrer URL (previously visited website, if sent by your browser)

Legal Basis & Purpose:

  • Legal Basis: Art. 6(1)(f) GDPR (Legitimate Interests).

  • Legitimate Interests: Ensuring technical stability, network security, rapid fault diagnosis, and mitigation of distributed denial-of-service (DDoS) attacks.

  • Storage Period: Server log files are stored for a maximum of 7 to 14 days and subsequently deleted or fully anonymized, unless temporary preservation is required for evidence in a security incident.

4. Account Registration and Gameplay Data

To save game progress, prevent multiple account abuse, and enable player interaction, we store necessary account information.

Collected Data:

  • Registration Credentials: Username, email address, password (stored strictly as a salted cryptographic hash; passwords are never readable in plain text).

  • Game Telemetry & State: In-game currency, inventory, building/research levels, timestamps of game actions, and battle/quest outcomes.

  • Security & Moderation: Registration IP address and the timestamp/IP of the latest login (used exclusively for multi-account detection, bot prevention, and anti-abuse verification under Art. 6(1)(f) GDPR).

  • In-Game Communication: In-game direct messages, forum/chat contributions (if applicable) to maintain community moderation and enforce the Game Rules.

Legal Basis & Purpose:

  • Legal Basis: Art. 6(1)(b) GDPR (Fulfillment of contract / Terms of Service) to provide the gameplay functionality requested by the user.

  • Storage Period: Account and gameplay data remain stored as long as your account is active. If you delete your account, personal data is erased, except where retention is legally mandated.

5. Cookies and Local Storage (TDDDG Notice)

Under Section 25(2) No. 2 of the German Telecommunications-Telemedia Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz – TDDDG), consent is not required if technical storage or access is strictly necessary to deliver a digital service explicitly requested by the user.

  • Session Cookie: A temporary session identifier cookie is placed on your device to keep you authenticated while navigating the game. It is automatically deleted once you log out or close your browser.

  • Security (CSRF Token): A small security token is stored to prevent Cross-Site Request Forgery attacks.

  • Local Storage: Used exclusively to store local client preferences (e.g., UI layout preferences, audio volume, dark/light mode toggle). No personal identifiers or profiling tokens are written to local storage.

Because we do not store non-essential or third-party cookies, no intrusive cookie consent banner is legally required.

6. Email Communication and Password Resets

If you request a password reset or system notification:

  • We process your email address to transmit an automated, signed reset link.

  • Legal Basis: Art. 6(1)(b) GDPR (Contractual execution) and Art. 6(1)(f) GDPR (Secure account recovery).

  • We do not send marketing newsletters, promotional blasts, or promotional product emails without prior explicit double opt-in consent (Art. 6(1)(a) GDPR).

7. Hosting and Data Processors

Our web application and database are hosted on servers located within the European Union (EU) / European Economic Area (EEA):

  • Hosting Provider: [Insert Name of Hoster, e.g., Hetzner Online GmbH, Netcup GmbH, etc.]

  • Location: [e.g., Falkenstein / Nuremberg, Germany or EU Data Center]

  • Data Processing Agreement: We have concluded a Data Processing Agreement (Auftragsverarbeitungsvertrag – AVV) pursuant to Art. 28 GDPR with our hosting provider to ensure data is processed strictly according to our instructions and under European data security standards.

8. Data Security (Encryption)

For security reasons and to safeguard the transmission of sensitive content (e.g., passwords and form submissions), this game utilizes end-to-end TLS/HTTPS encryption. You can identify an encrypted connection by the https:// prefix and the lock icon in your browser's address bar.

9. Your Rights Under the GDPR

As a data subject located in the EU, you possess the following statutory rights regarding your personal data:

  1. Right of Access (Art. 15 GDPR): You can request confirmation as to whether personal data concerning you is being processed and obtain a copy of that data.

  2. Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or incomplete personal data.

  3. Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You can request the deletion of your account and personal data, provided no statutory retention duties prevent erasure.

  4. Right to Restriction of Processing (Art. 18 GDPR): You may demand the restriction of processing under certain statutory circumstances.

  5. Right to Data Portability (Art. 20 GDPR): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.

  6. Right to Object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to data processing based on Art. 6(1)(f) GDPR (Legitimate Interests).

  7. Right to Withdraw Consent (Art. 7(3) GDPR): Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

To exercise any of these rights, contact us at: [Your Contact Email].

10. Right to Lodge a Complaint with a Supervisory Authority

Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority (Datenschutzaufsichtsbehörde), in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement.

For Germany, you may contact the State Commissioner for Data Protection (Landesbeauftragte/r für den Datenschutz) of the federal state in which the Operator is domiciled.