Last Chaos Aurum
A sorceress with a staff
A knight with a sword
Download game Windows client Sign up start playing for free
Download game Windows client Sign up start playing for free
Download game Sign up

Privacy Policy

Version of Oct 3

This Privacy Policy (the "Policy") sets out the procedure for the collection, recording, storage, use, transfer, protection and destruction of the personal data of Users of the Last Chaos Aurum website and game server and forms an integral part of the Terms of Service. The Policy has been prepared having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, the "GDPR"), Directive 2002/58/EC ("ePrivacy") and the California Online Privacy Protection Act ("CalOPPA"). Registration of an account and any other use of the Service signify that the User has read this Policy.

1Terms and Definitions

1.1. "Administration": the administration of the non-commercial Last Chaos Aurum project, which determines the purposes and means of the Processing of Personal Data.

1.2. "Service": the website, game server, game client and other services of the Last Chaos Aurum project taken together.

1.3. "User": a natural person who uses the Service, including a person who has registered an account.

1.4. "Personal Data": any information relating to an identified or identifiable natural person, whether directly or indirectly (Art. 4(1) GDPR).

1.5. "Processing": any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, pseudonymisation, restriction, erasure and destruction (Art. 4(2) GDPR).

1.6. "Processor": a person who processes Personal Data on behalf of the Administration (Art. 4(8) GDPR).

1.7. "Cookies": pieces of data stored on the User's terminal equipment and transmitted to the Service on subsequent requests.

Terms not defined in this section shall be construed in accordance with the GDPR.

2Controller

2.1. The controller of Personal Data within the meaning of Art. 4(7) GDPR is the Administration. The project is non-commercial and is not affiliated with the right holders of the Last Chaos game.

2.2. Requests concerning the Processing of Personal Data shall be sent to the email address [email protected] or submitted via the Support section.

3Categories of Data Processed

3.1. The Administration processes the following categories of Personal Data:

  • (a) account identification data: login, email address and a record of its confirmation, and a cryptographic hash of the password (bcrypt algorithm) which precludes recovery of the password in its original form;
  • (b) technical data: IP addresses, date and time of registration and authorisation; data on visits to the pages of the website: IP address, country, page address, address of the referring website, date and time of the visit, information about the browser and device (User-Agent header);
  • (c) game data: information on characters, in-game property, the balance of the in-game currency Cash, marketplace transactions, rewards received, breaches of the Rules and sanctions imposed;
  • (d) referral data: the code of the User who invited the registering User, where provided;
  • (e) information provided by the User when contacting the Administration.

3.2. The Administration does not deliberately collect special categories of Personal Data (Art. 9 GDPR), payment card details or identity document data, and does not use advertising identifiers or third-party tracking tools. The only web analytics tool used is Cloudflare Web Analytics, as set out in clause 8.3.

4Purposes and Legal Bases of Processing

4.1. Personal Data is processed for the following purposes and on the following legal bases:

  • (a) the conclusion and performance of the Terms of Service, including the creation and maintenance of the account, provision of access to the Service, operation of the marketplace and of the rewards programme (Art. 6(1)(b) GDPR);
  • (b) ensuring the information security of the Service and preventing unauthorised access, password guessing, the use of automated means (bots), fraud and other breaches of the Rules (legitimate interest of the Administration, Art. 6(1)(f) GDPR);
  • (c) sending service notifications and restoring access to the account (Art. 6(1)(b) GDPR);
  • (d) compliance with obligations imposed on the Administration by applicable law (Art. 6(1)(c) GDPR);
  • (e) analysis of website traffic: number of visitors, referral sources and pages viewed, for the purpose of developing the Service (legitimate interest of the Administration, Art. 6(1)(f) GDPR).

4.2. The Administration does not sell Personal Data, does not disclose it for targeted advertising, does not send marketing communications and does not engage in automated decision-making, including profiling, which produces legal effects concerning the User or similarly significantly affects the User (Art. 22 GDPR).

5Disclosure of Personal Data

5.1. The Administration may disclose Personal Data to the following categories of recipients solely to the extent necessary to achieve the purposes of Processing:

  • (a) the hosting provider that hosts the Service (OVHcloud, location: Germany), acting as a Processor;
  • (b) Cloudflare, Inc. (USA), which provides protection against network attacks, content delivery and verification of requests for automated activity (Cloudflare Turnstile upon registration, password recovery and after repeated entry of a wrong password), collection of website visit statistics without the use of Cookies (Cloudflare Web Analytics) and forwards e-mails sent to [email protected], acting as a Processor; the User's network traffic, including the IP address and technical characteristics of the browser, passes through its infrastructure;
  • (c) the e-mail provider that delivers service e-mails, including account recovery e-mails (Brevo, Sendinblue SAS, France), acting as a Processor;
  • (d) the provider of the Administration's mailbox that receives requests sent to [email protected] (Google LLC, USA), acting as a Processor;
  • (e) the operator of the XtremeTop100 top list, solely at the User's initiative when using the server voting feature: a numeric account identifier is transmitted without the login or email address; the operator of the top list processes the User's IP address independently in accordance with its own rules;
  • (f) public authorities in cases expressly provided for by applicable law.

5.2. Personal Data is transferred outside the European Economic Area on the basis of the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 or other appropriate safeguards provided for in Chapter V GDPR.

5.3. Following links to third-party resources, including Discord, does not entail any disclosure of Personal Data by the Administration. The processing of Personal Data by such resources is governed by their own policies, for which the Administration bears no responsibility.

5.4. Information on payment services shall be added to this Policy before payments are accepted.

6Retention Periods

6.1. Personal Data is retained for the lifetime of the account unless otherwise provided in this section.

6.2. Authorisation logs and website page visit logs containing IP addresses are retained for 12 (twelve) months from the date of their creation and are deleted thereafter.

6.3. Upon deletion of the account, Personal Data shall be destroyed or anonymised within a period not exceeding 30 (thirty) calendar days, except for records of breaches of the Rules and sanctions imposed, which are retained for 2 (two) years in order to prevent repeated breaches (Art. 6(1)(f) GDPR).

6.4. Retention periods may be extended where necessary for the establishment, exercise or defence of legal claims (Art. 17(3)(e) GDPR).

7Rights of the Data Subject

7.1. In accordance with Arts. 15-21 GDPR, the User has the right:

  • (a) to obtain confirmation as to whether Personal Data is being processed and access to such Personal Data;
  • (b) to obtain the rectification of inaccurate Personal Data;
  • (c) to obtain the erasure of Personal Data ("right to be forgotten");
  • (d) to obtain the restriction of Processing;
  • (e) to receive the Personal Data in a structured, commonly used and machine-readable format (right to data portability);
  • (f) to object to Processing based on the legitimate interest of the Administration.

7.2. A request shall be submitted in the manner set out in clause 2.2 from the email address specified upon registration of the account or by other means allowing the requester to be reliably identified. The Administration shall respond to the request within 1 (one) month of its receipt; this period may be extended by 2 (two) further months taking into account the complexity and number of requests (Art. 12(3) GDPR).

7.3. The User has the right to lodge a complaint with a data protection supervisory authority of the Member State of the European Union of the User's habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR).

7.4. Users who are residents of the State of California may obtain information on the categories of Personal Data collected and the categories of persons to whom it is disclosed in the manner set out in clause 7.2.

9Security Measures

9.1. The Administration implements appropriate technical and organisational measures to protect Personal Data (Art. 32 GDPR), including storing passwords solely as a cryptographic hash, transmitting data over the secure HTTPS protocol, segregating and minimising access rights to databases and restricting access to the server infrastructure.

9.2. In the event of a personal data breach likely to result in a high risk to the rights and freedoms of Users, the Administration shall notify Users without undue delay by publication on the website and in the project's official Discord community (Art. 34 GDPR).

10Minors

10.1. The Service is intended for adults. The Administration does not knowingly process the Personal Data of persons under the age of 16 (sixteen) (Art. 8 GDPR).

10.2. Where it is established that an account has been registered by a person under that age, the relevant Personal Data shall be deleted.

11Amendments to the Policy

11.1. The Administration may amend this Policy unilaterally. A new version shall enter into force upon its publication unless otherwise provided in the new version.

11.2. The current version of the Policy is permanently available at /privacy.