Privacy Policy
Last updated: August 16, 2026
We take the protection of your personal data seriously. Use the tabs below to view the privacy information that applies to our website or to the Gloom Hunters game.
This part of our Privacy Policy applies to the Gloom Hunters website. It explains what data we process when you simply visit our site.
1. Controller
The controller responsible for data processing on this website is:
Michael Becker
c/o Postflex #8538
Emsdettener Str. 10
48268 Greven, Germany
Email: contact@gloomhunters.com
Phone: +49 178 6817429
2. Hosting & Server Log Files
Our website is hosted on Cloudflare Pages, a service provided by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). When you access the website, Cloudflare automatically processes technical information that your browser transmits and stores it in so-called server log files, in particular:
- your IP address (shortened/anonymized where possible);
- browser type and version;
- the operating system you use;
- date and time of access;
- the referrer URL (the page you visited before);
- the volume of data transferred.
This data is processed to deliver the website reliably, to ensure its stability and security, and to defend against attacks (e.g. DDoS protection). The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in a secure and functioning website). Cloudflare processes this data on our behalf as a processor under Art. 28 GDPR.
As Cloudflare is a US provider, data may be transferred to the United States. Such transfers are safeguarded by the EU Standard Contractual Clauses. For details, please see the Cloudflare Privacy Policy.
3. Cookies & Tracking
This website does not use any analytics, advertising, or tracking cookies, and it does not profile its visitors. Cloudflare may set strictly necessary cookies (e.g. to tell humans and bots apart and to protect the site). These are technically required to provide the service you requested; the legal basis is § 25(2) TDDDG together with Art. 6(1)(f) GDPR. We do not carry out any automated decision-making or profiling (Art. 22 GDPR).
4. Contacting Us by Email
If you contact us by email (for example via the address above or our contact page), we process your email address and the content of your message solely in order to handle and respond to your request. The legal basis is Art. 6(1)(b) GDPR where it relates to a contract, otherwise Art. 6(1)(f) GDPR (our legitimate interest in answering enquiries). Where we process your message in order to comply with a legal obligation, for example when you exercise a data protection right, the legal basis is Art. 6(1)(c) GDPR. We delete this data once it is no longer required and no statutory retention periods prevent deletion.
5. External Links & Social Media
Our website contains simple links to external platforms such as YouTube, TikTok, Discord, Instagram, X, Reddit, and Overpalmed. These are plain hyperlinks. No data is transmitted to these providers until you actively click a link and leave our site. Once there, the respective provider's own privacy policy applies.
The Discord link leads to our official Gloom Hunters community server. That server contains a public raid feed showing player usernames from the game. If you want to know what is published there and why, please see section 7 of the Game tab.
6. Retention
Server log data is stored only for as long as necessary for security and operational purposes and is then deleted or anonymized. Email correspondence is retained only for as long as needed to process your request and to document how we handled it.
7. Your Rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)). To exercise any of these rights, contact us using the details above. Before we act on a request, we may need to ask you for information that allows us to check that the request really comes from you.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or workplace. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW).
9. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes to our website or to legal requirements. The current version is always available on this page.
This part of our Privacy Policy applies to the Gloom Hunters game (mobile and PC). It explains what personal data we process when you create an account and play, and what is published in our official Discord community server.
1. Controller
The controller responsible for data processing in the game is:
Michael Becker
c/o Postflex #8538
Emsdettener Str. 10
48268 Greven, Germany
Email: contact@gloomhunters.com
Phone: +49 178 6817429
2. What Personal Data We Process
Depending on how you play and sign in, we process the following categories of personal data:
- Account identifiers: your Unity player ID and your username (display name).
- Sign-in data: your password in hashed form, or a unique identifier (token) from Google, Apple, or Facebook if you sign in with one of those providers, and any limited profile information those providers share with us.
- Game data: your progress, statistics, base and defense configurations, and settings.
- Multiplayer and raid data: which player raided which base, the result of the raid, how long it took, and the in-game rewards involved.
- Raid history: a short record of your most recent raids, showing the other player's username and level, when the raid happened, how it ended, and the in-game rewards.
- Leaderboard data: your username together with your scores for raid wins, Gloom Berries collected, and guards defeated.
- Push notification data: your Unity player ID, which serves as the address label for your device, a push subscription identifier held by our notification provider, basic device information such as device model, operating system, app version, language, and time zone, and the content of the raid notifications we send you.
- Diagnostic data: error and warning category, the affected game component or provider, a sanitized technical message, your username, your pseudonymous Unity player ID, and a timestamp where applicable.
- Analytics data: event and usage data, session information, device data (such as device model, operating system, language, and an approximate region derived from your IP address), and a unique identifier / player ID.
- Contact data: your email address and the content of your message if you write to us.
3. Accounts & Sign-In
To play online and save your progress, Gloom Hunters uses Unity Authentication (part of Unity Gaming Services). You can choose how to sign in:
- Guest / temporary account: you can play as a guest without providing any name or email. A randomly generated player ID is created so that your progress can be stored. Guest accounts are temporary and may be removed automatically after a prolonged period of inactivity.
- Username & password: you choose a username (display name) and a password. Your username is public; please see section 6. Your password is never stored in plain text; it is kept only in hashed form by Unity Authentication.
- Social sign-in (Google, Apple, Facebook): you can sign in through one of these providers. We receive a unique identifier (token) confirming your login. We never receive your password. Depending on the provider and your settings, limited profile information (such as an email address or name) may be shared with us. Please also review the privacy policy of the provider you use.
Purpose: to create, secure, and manage your player account and let you access your progress across devices. Legal basis: Art. 6(1)(b) GDPR (performance of the contract to provide the game).
4. Game Progress & Cloud Save
We store your in-game data (such as game progress, statistics, your base and defense configurations, and settings) linked to your player ID using Unity Cloud Save. This lets you keep your progress and continue across sessions and devices. Legal basis: Art. 6(1)(b) GDPR.
5. Online & Multiplayer Features
Gloom Hunters is a game in which you raid bases built by other players, and your own base can be raided, even while you are offline. To make this possible, your player ID, display name, and your base/defense setup are shared with other players as part of normal gameplay and matchmaking, and the outcome of a raid is shown to the players involved. This is a core part of the game you signed up for. Legal basis: Art. 6(1)(b) GDPR.
The game keeps a short history of recent raids so that both sides can see what happened. Your raid inbox lists the last ten raids against your base, with the attacking player's username and level, when it happened, how it ended, and the Gloom Berries involved. Your own attack history lists the last ten bases you raided in the same way. When a new raid is recorded, the oldest entry drops off automatically.
Gloom Hunters also has leaderboards for raid wins, Gloom Berries collected, and guards defeated. If you appear on one, your username and your score are visible to other players. Legal basis: Art. 6(1)(b) GDPR, as these are part of the game we provide.
6. Your Public Username
Your username (display name) is a public game identifier. When you choose or change it, the game shows you this warning:
"Don't use your real name or personal information. Your username is public and may appear in community features."
Your username can be seen:
- by other Gloom Hunters players;
- during raids and other multiplayer functionality;
- in community features of Gloom Hunters, such as the leaderboards and the raid history the other player sees;
- in the push notification another player receives when you raid their base (see section 8);
- in the public raid feed in our official Gloom Hunters Discord server (see section 7).
Please follow that warning: do not use your real name, email address, phone number, or other personal details as your username. Choosing an invented name limits how much you reveal about yourself, but it does not make your username anonymous and it does not take it outside the scope of data protection law. A username stays personal data under the GDPR, because it can be linked to you as a player, and everything in this Privacy Policy continues to apply to it.
If you would like your username changed, please contact us using the details above.
7. The Public Raid Feed in our Discord Server
We run an official Gloom Hunters community server on Discord. It contains a public channel called #raids. When raids happen in the game, our server-side game logic (Unity Gaming Services Cloud Code) may automatically publish short messages about them in that channel. The messages are delivered through BotGhost, a third-party Discord bot platform we use as a technical intermediary (see section 12).
These messages show only:
- the public username of the attacking player;
- the public username of the defending player;
- the raid activity itself;
- the result of the raid, such as a victory or a defeat.
Examples of what such a message looks like:
"UsernameA started a raid against UsernameB"
"UsernameA defeated UsernameB"
The raid feed never contains internal Unity player IDs, email addresses, IP addresses, device identifiers, authentication information, passwords, or authentication tokens.
Who can see it: the channel can be viewed by the members of our Discord server. Anyone with an invite link can join that server, so in practice the raid feed is visible to anyone who chooses to join, including people who do not play Gloom Hunters. Once a message has been posted, other people can read, copy, quote, or screenshot it, and we cannot undo that.
Purpose: to provide multiplayer activity, community interaction, and a history of activity within the Gloom Hunters community, so that players can follow what is happening in the game and talk about it.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest is operating and maintaining a living community around a multiplayer game. In weighing this against your interests, rights, and freedoms, we have taken into account that only the public username you chose yourself is published, that this username is already shown to other players during raids, that no private identifiers of any kind are included, that we warn you when you choose your username, and that you can object at any time under Art. 21 GDPR (see section 18). We do not ask you for consent for the raid feed, so consent is not the legal basis for it.
Please note that raid messages are a historical record. They are not rewritten if you later change your username, and they are not removed automatically just because a Gloom Hunters account is deleted. You can ask us to deal with them separately; see sections 14, 15, and 18.
8. Push Notifications
Gloom Hunters sends you a push notification when another player raids your base. That is the only kind of notification we send. To deliver it we use OneSignal, a push notification service (see section 12).
When a raid happens, our server-side game logic (Unity Gaming Services Cloud Code) passes the message to OneSignal, and OneSignal delivers it to your device. The following data is involved:
- your Unity player ID, which we send to OneSignal as the address label for your device. We do not store or send device tokens ourselves;
- a push subscription identifier that OneSignal and your device's operating system use to deliver the message to the right device;
- the content of the notification, which includes the public username of the player who raided your base;
- basic technical information that the OneSignal software built into the game collects from your device so that notifications can be delivered correctly, such as device model, operating system, app version, language, and time zone.
OneSignal states that it does not collect IP addresses from users in the EU and the UK.
We do not send advertising, marketing, or promotional push notifications, and we do not send notifications to encourage you to come back and play.
You decide whether you receive notifications at all. Push notifications require permission on your device. You can refuse that permission, and you can withdraw it at any time in your device settings. If notifications are switched off, no further notifications are sent to your device.
Purpose: to tell you that your base has been raided, so that you can react to it.
Legal basis: Art. 6(1)(b) GDPR. Being told when your base is raided is part of the multiplayer game we provide to you, in which your base can be attacked while you are offline. Where German law applies, storing and reading the information on your device that is needed for this is covered by § 25(2) TDDDG, because it is strictly necessary to provide the notification service you have switched on.
9. Private Developer Diagnostic Channels
Our Discord server also contains private channels called #errors and #warnings. Ordinary members of the Discord server cannot see or access them. Access is restricted to authorized Gloom Hunters developers.
When something goes wrong in the game, Gloom Hunters may send a sanitized diagnostic report to those channels, along the same path as the raid feed (Unity Gaming Services Cloud Code, then BotGhost, then Discord). Such a report may contain:
- your public username;
- your pseudonymous Unity player ID;
- the error or warning category;
- the affected game system, component, or provider;
- a sanitized technical error or warning message;
- a timestamp, where applicable.
An example report looks like this:
Gloom Hunters Error
Guest#0152 | [Unity Player ID] reports: [AccountLinker] GooglePlayGames operation failed: Google Play Games sign-in was cancelled.
Purpose: debugging, troubleshooting, security, stability, investigating problems, and maintaining Gloom Hunters.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest is keeping the game working, secure, and stable, and being able to find and fix faults that affect players. In weighing this against your interests, we have taken into account that the reports are limited to what we need in order to understand a fault, that they are sanitized before they are sent, that the channels are not public, and that you can object at any time under Art. 21 GDPR (see section 18).
Our systems are designed not to transmit passwords, authentication tokens, session tokens, Apple identity tokens, Google identity tokens, authorization headers, API secrets, bot tokens, payment information, or personal information that is not needed to understand the fault.
10. Analytics
We use Unity Analytics to understand how the game is used and to improve its balance, performance, and stability. This may process event and usage data, session information, device data (such as device model, operating system, language, and an approximate region derived from your IP address) and a unique identifier / player ID. We do not use this data for advertising and we do not build marketing profiles about you. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in analyzing and improving our game). You may object to this processing at any time (see section 18). We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not use your data for profiling (Art. 22 GDPR).
11. Legal Bases at a Glance
- Account, sign-in, cloud save, in-game multiplayer and raids: Art. 6(1)(b) GDPR, performance of the contract to provide the game.
- Public raid feed on Discord: Art. 6(1)(f) GDPR, our legitimate interest in community interaction and a record of community activity.
- Push notifications telling you that your base was raided: Art. 6(1)(b) GDPR, performance of the contract, together with § 25(2) TDDDG for the information stored on your device.
- Diagnostic error and warning reports: Art. 6(1)(f) GDPR, our legitimate interest in troubleshooting, security, and game stability.
- Analytics: Art. 6(1)(f) GDPR, our legitimate interest in analyzing and improving the game.
- Protecting the game against abuse, cheating, and attacks: Art. 6(1)(f) GDPR, our legitimate interest in security.
- Answering your messages: Art. 6(1)(b) GDPR where it concerns the game contract, otherwise Art. 6(1)(f) GDPR.
- Handling data protection requests and meeting legal duties: Art. 6(1)(c) GDPR, compliance with a legal obligation.
Wherever we rely on Art. 6(1)(f) GDPR, you have the right to object under Art. 21 GDPR. Section 18 explains how.
12. Recipients & Third-Party Services
We do not sell your personal data. It is shared only with the following recipients:
- Unity Technologies (Unity Gaming Services: Authentication, Cloud Save, multiplayer and matchmaking, Cloud Code, and Analytics), acting as our processor under Art. 28 GDPR. Data received: account identifiers, sign-in data, game data, multiplayer data, and analytics data. See the Unity Gaming Services Privacy Policy.
- Sign-in providers (Google, Apple, or Facebook), but only if you choose to sign in with them. Data received: the sign-in request and confirmation handled by that provider.
- BotGhost, the third-party Discord bot platform available at botghost.com. We use it purely as a technical intermediary that passes our messages on to Discord. Data received: the content of the messages described in sections 7 and 9, meaning public usernames and raid information, and the sanitized diagnostic data including the pseudonymous Unity player ID. BotGhost does not publish the identity of its operating company or the location of its processing, and its role and obligations are governed by its own terms; please see the BotGhost Privacy Policy and Terms of Service. We do not transmit any credentials, tokens, or account secrets through BotGhost.
- OneSignal, Inc., 201 S. B Street, San Mateo, CA 94401, USA, which delivers the push notifications described in section 8 to your device on our behalf. Data received: your Unity player ID as the address label for your device, the content of those notifications, including the username of the player who raided your base, and the push subscription and basic device information listed in section 8. OneSignal states that it acts primarily as a data processor in relation to the services it provides to its clients, and it makes a data processing addendum available at onesignal.com/dpa. See the OneSignal Privacy Policy.
- Discord. The messages described in sections 7 and 9 are stored and displayed on the Discord platform. For users in the EEA, Discord states that Discord Netherlands BV, Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, is the controller for personal data processed through its services, and that Discord, Inc. (San Francisco, USA) is the controller for everyone else. Discord's data protection officer can be reached at dpo@discord.com. Data received: the content of the messages described in sections 7 and 9. We are the controller for our decision to publish these messages and for their content; Discord processes the data on its own platform under its own privacy policy rather than as our processor. See the Discord Privacy Policy.
The game contains no advertising and no in-app purchases.
13. International Data Transfers
Some of our service providers process data outside the EU/EEA, including in the United States. Transfers to a third country require a legal basis under Chapter V of the GDPR (Art. 44 to 49).
- Unity and the sign-in providers may process data outside the EU/EEA. These transfers are covered by the safeguards those providers set out in their own privacy documentation, such as an adequacy decision of the European Commission or the EU Standard Contractual Clauses.
- Discord states that it processes and stores information on servers in the United States. Discord, Inc. is certified under the EU-U.S. Data Privacy Framework, which is covered by an adequacy decision of the European Commission, and Discord additionally states that it relies on the EU Standard Contractual Clauses for transfers out of the EEA.
- OneSignal states that it hosts and stores data in Europe and accesses it from the United States and other countries in which it or its service providers operate. OneSignal, Inc. is certified under the EU-U.S. Data Privacy Framework and states that it also relies on the EU Standard Contractual Clauses for such transfers.
- BotGhost does not publicly state where it processes data. Where a transfer outside the EU/EEA takes place, the terms and privacy policy of that provider apply. Only the limited data described in sections 7 and 9 is passed through this route.
14. Retention
Account and game data. We keep your account and game data for as long as your account exists. Temporary guest accounts may be deleted automatically after a long period of inactivity.
Analytics data. Retained only in line with Unity's retention periods, in aggregated or limited form.
Raid messages in the public feed. These messages stay in the #raids channel as a record of community activity, because the history of that activity is the point of the channel. There is no automatic deletion after a fixed number of days. Instead, we apply the following criteria under Art. 5(1)(e) GDPR:
- we review the channel at regular intervals, at least once a year, and check whether keeping older messages is still necessary for the community purpose;
- messages that are no longer needed for that purpose are deleted;
- individual messages are deleted or edited when we have to do so, for example following a valid erasure request or a successful objection (see section 18);
- if we discontinue the raid feed or close the channel, its content is deleted.
Diagnostic reports. Reports in #errors and #warnings are kept only for as long as we need them to investigate and fix the fault they describe and to recognise whether the same fault occurs again. We do not set a fixed calendar period, because how long a report remains useful depends on the fault; instead we review these channels regularly and delete reports that are no longer needed for that purpose.
Raid history and leaderboards. Your raid inbox and your attack history each keep only your last ten raids; when a new raid is recorded, the oldest entry drops off automatically, so this data does not build up over time. Leaderboard scores are kept for as long as your account exists.
Push notification data. Your push subscription is kept for as long as you have notifications switched on and the game installed on that device. We delete your OneSignal record when your Gloom Hunters account is deleted. OneSignal states that notifications sent through its interface are deleted approximately 30 days after delivery.
Email correspondence. Kept only for as long as needed to process your request and to document how we handled it, subject to any statutory retention periods.
15. Account Deletion and How It Differs from Your Data Protection Rights
These are two separate things, and it is worth understanding the difference.
Deleting your Gloom Hunters account. You can permanently delete your account and its associated data at any time directly in the game. See our Account Deletion page for step-by-step instructions. This removes your account and the game data linked to it, and we also delete your push notification record at OneSignal so that no further notifications are sent. It does not automatically rewrite historical raid messages that have already been published in our Discord server, and it does not automatically remove every historical raid message, because those messages are a separate record held on the Discord platform.
Exercising your data protection rights. Separately from deleting your account, you can exercise your rights under the GDPR, including asking us to erase personal data that appears in the raid feed or in our diagnostic channels. Send that request to contact@gloomhunters.com. Having already deleted your account does not stop you from making such a request and is not a reason for us to refuse one. Section 18 explains how we handle requests.
16. Children & Minimum Age
Gloom Hunters is intended for players aged 12 and over and carries a 12+ age rating. We are aware that some of our players are minors, and we give the personal data of children and young people particular protection.
Children under 12: The game is not intended for children under the age of 12, and we do not knowingly collect personal data from them. If you are a parent or guardian and believe a child under 12 has provided us with personal data, please contact us using the details above and we will delete it.
Players under the age of digital consent (under 16 in Germany; between 13 and 16 in other EU/EEA member states): if you are below this age, you may only create an account, use the online features, and provide personal data with the involvement and permission of a parent or legal guardian. Because creating an account and using our online services forms a contract, your parent or guardian must agree to it on your behalf; and where any processing relies on consent, that consent must likewise be given or authorised by them. By signing in or playing online, you confirm that you have this permission.
Keeping younger players safe: please do not use your real name, email address, or other personal details as your public username. Your username is visible to other players during raids and matchmaking, and it also appears in the public raid feed in our Discord server, where people outside the game can see it and where messages remain as a record of community activity (see sections 6, 7, and 14). We keep the data we process to a minimum, we never use children's data for advertising, marketing profiles, or automated decision-making, and the game contains no ads and no in-app purchases.
Parents and guardians can exercise all of the rights described below on behalf of their child, including access, rectification, erasure, and objection to the raid feed, and can delete the account and its data at any time directly in the game (see our Account Deletion page) or by contacting us using the details above.
17. Data Minimization & Security
We follow the principle of data minimization in Art. 5(1)(c) GDPR: we transmit only the data that is actually needed for the purpose concerned. In particular:
- the public raid feed contains only public usernames and the raid information needed for the community feature, and never internal Unity player IDs, email addresses, IP addresses, device identifiers, authentication information, passwords, or authentication tokens;
- diagnostic reports are sanitized before they are sent, are limited to what we need in order to understand a fault, and are posted only to channels whose access is restricted to authorized Gloom Hunters developers;
- push notifications carry only the short message you need to see, such as who raided your base, and never account details, contact details, or anything from your saved game;
- credentials and secrets, including passwords, authentication and session tokens, Apple and Google identity tokens, authorization headers, API secrets, and bot tokens, are never sent to BotGhost, Discord, or OneSignal.
We and our processors use appropriate technical and organizational measures, such as encrypted transmission, hashed passwords, and access restrictions on the private developer channels, to protect your data against loss, misuse, and unauthorized access. No online service can be made completely secure, and we do not claim otherwise; we work to keep the risk as low as we reasonably can.
18. Your Rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)).
How to make a request. Contact us at contact@gloomhunters.com. Please tell us which right you want to exercise and give us your username, so that we can find the right data. We answer without undue delay and in any event within one month, and we will tell you if we need to extend that period as permitted by Art. 12(3) GDPR.
Checking who you are. Before we act on a request, we may need to verify that you are the account holder the request concerns. Publishing or deleting data on the say-so of the wrong person would itself be a data protection problem. We ask only for what we need for that check and use it only for that purpose. If we genuinely cannot link a request to an identifiable account, we will tell you and explain what would help.
Right to object (Art. 21 GDPR). Where we rely on our legitimate interests under Art. 6(1)(f) GDPR, which covers the public raid feed (section 7), the diagnostic channels (section 9), analytics (section 10), and security, you can object at any time on grounds relating to your particular situation. If you object, we stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defence of legal claims. In practice:
- for the raid feed, we exclude your username from future raid messages and, on request, remove or edit existing messages that name you;
- for diagnostic reports, we stop including your username and player ID;
- for analytics, we stop the analytics processing that relates to you.
Push notifications (section 8) are based on Art. 6(1)(b) GDPR rather than legitimate interests, so Art. 21 does not apply to them. You control them directly: switch notifications off for Gloom Hunters in your device settings and nothing further is sent.
Erasure and its limits. When you ask us to erase your personal data, we delete what we hold, including messages in the raid feed and the diagnostic channels that identify you, as far as those messages are still present and we can locate them. We cannot promise that every trace disappears everywhere. Some limits are practical and some are legal:
- messages that other people have already copied, quoted, forwarded, or screenshotted are outside our control and cannot be recalled by us;
- a raid message names two players, so where only one of them asks for erasure we remove or edit the message in a way that no longer identifies that person;
- Art. 17(3) GDPR allows us to keep data where it is still needed, for example to comply with a legal obligation or for the establishment, exercise, or defence of legal claims. If we rely on such an exception, we tell you which one and why.
You can also delete your account directly in the game at any time; please see section 15 for what that does and does not cover.
19. Right to Lodge a Complaint
You may lodge a complaint with a data protection supervisory authority, in particular in your country of residence. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW).
20. Changes to this Policy
We may update this Privacy Policy to reflect changes to the game or to legal requirements. The current version is always available on this page.