This English version is a translation provided for convenience. The German version at https://avaleryon.com/datenschutz/ is the authoritative text.
1. Who is responsible
Avaleryon Media
Jonas Erlinghagen
Leopoldstr. 2-8, Gebäude P-F-407
32051 Herford
Germany
Email: contact@avaleryon.com
Legal notice: https://avaleryon.com/legal-notice/
We are the controller for the processing described below, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR).
We are not required to appoint a data protection officer. The thresholds in Article 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) are not met.
2. What this policy covers
This policy describes what happens to personal data when you visit this website or contact us by email. It does not cover our games. Where a game processes player data, that processing is described separately and the relevant policy is linked from the game’s store page.
3. The short version
This website collects very little. It sets no cookies, loads nothing from third-party servers, and runs no tracking or advertising tools. The only personal data that arises automatically is contained in server log files, and the IP addresses in those logs are anonymised before they are stored.
The sections below set this out in full.
4. Visiting this website
What is processed
When your browser requests a page from our server, our hosting provider records the request in a log file. A log entry can contain:
- your IP address, anonymised before storage
- the date and time of the request
- which page or file was requested
- the referring page, if your browser sent one
- your browser type and version
- your operating system
- the amount of data transferred and whether the request succeeded
Why
We need this to deliver the website to you, to keep the server running reliably, and to recognise and defend against attacks such as denial-of-service attempts.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is in operating a functioning and secure website. We consider this interest not to be outweighed by your interests, particularly because the IP addresses are anonymised and the retention period is short.
How long
Seven days, then the log files are deleted. If a specific security incident requires it, affected entries may be kept longer until the incident is resolved.
Anonymisation
Our hosting provider anonymises IP addresses before writing them to the log. We cannot trace a log entry back to an individual person.
5. Visitor statistics
We look at basic visitor numbers using the statistics function built into our hosting package. These figures are calculated from the anonymised log files described above.
No cookies are involved. Nothing is read from or written to your device. Individual visitors cannot be identified, and no profiles are created.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is in understanding how the site is used.
6. Cookies and similar technologies
This website does not use cookies.
We store no information on your device and access none that is already there, beyond what is unavoidably necessary to transmit the page you requested.
Because of this, no consent under § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) is required, and we do not operate a cookie banner or consent management tool.
7. External content
Everything on this site — text, images, video, fonts, stylesheets, scripts — is served from our own server.
In particular:
- We do not load fonts from Google Fonts or any other external font service.
- We do not embed videos from YouTube, Vimeo or comparable platforms.
- We do not embed Steam widgets, store frames or other Valve-hosted content.
- We do not embed social media feeds, share buttons or comparable widgets.
- We do not use content delivery networks operated by third parties.
Opening a page on this website therefore transmits no data to any third party.
8. Links to other sites
We link to our store pages on Steam and, where applicable, to profiles on other platforms. These are ordinary links.
Nothing is loaded from those providers while you are on our site, and no data reaches them until you click a link and leave. From that point the operator of the destination site is responsible for what happens to your data, under their own privacy policy.
Steam is operated by Valve Corporation, P.O. Box 1688, Bellevue, WA 98009, USA. Valve’s privacy policy: https://store.steampowered.com/privacy_agreement/
9. Contacting us by email
There is no contact form on this website. We publish an email address, and clicking it opens your own email program. No data is collected on our site when you get in touch.
What is processed
Whatever your message contains — typically your email address, your name if you give it, and the content of your message — together with the technical details that accompany any email, such as timestamps and the servers involved.
Why
To read your message and reply to it, and to handle any follow-up correspondence.
Legal basis
Article 6(1)(b) GDPR where your message concerns a contract or steps leading to one. Otherwise Article 6(1)(f) GDPR, our legitimate interest being in responding to people who write to us.
How long
Until your enquiry is dealt with and there is no further reason to keep the correspondence. Business correspondence may be subject to statutory retention periods under German commercial and tax law — see section 10. You can ask us to delete your message at any time.
A note on email security
Email is not encrypted end-to-end by default. Transport between servers is normally encrypted, but messages sitting on a mail server usually are not. We cannot guarantee the security of a message in transit before it reaches us. Please do not send sensitive information by unencrypted email.
10. Email hosting
Our web hosting package includes email. Our hosting provider therefore processes sender and recipient addresses, message contents and associated technical data on our behalf, including for spam filtering.
Legal basis: Article 6(1)(f) GDPR, our legitimate interest being in operating a working email address.
11. How long we keep things
We delete personal data once the purpose it was collected for no longer applies, unless we are required to keep it.
German commercial and tax law imposes retention periods that can apply to business correspondence and records — for example ten years for accounting records and annual financial statements (§ 147 AO, § 257 HGB), and six years for other business letters of tax relevance. Data that may be needed to assert or defend legal claims can be kept for the duration of the applicable limitation period, generally three years (§§ 195, 199 BGB).
Where more than one period could apply to the same data, the longest one governs. Data retained solely because of a legal obligation is used only for that purpose and nothing else.
Nothing in this section affects the seven-day deletion of server log files described in section 4.
12. Who receives your data
We do not sell personal data, and we do not pass it to third parties for their own purposes.
The only party that processes personal data on our behalf is our hosting provider:
ALL-INKL.COM – Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68
02742 Friedersdorf, Germany
https://all-inkl.com
Privacy information: https://all-inkl.com/datenschutzinformationen/
They act as a processor under Article 28 GDPR, bound by a data processing agreement we have concluded with them. Their servers are in Germany.
No data is transferred outside the European Economic Area in connection with this website.
Beyond this, we would disclose data only where we are legally required to — for instance in response to a valid order from a court or public authority.
13. Automated decision-making
We do not use automated decision-making or profiling as described in Article 22 GDPR.
14. Security
We use TLS encryption for all connections to this website. You can tell it is active from the “https://” at the start of the address and the padlock your browser displays. This protects data in transit between your browser and our server against interception.
We also take appropriate technical and organisational measures under Article 32 GDPR to protect data against loss, misuse and unauthorised access, taking into account the state of the art, the cost of implementation, and the risk involved. Given how little data this website processes, that risk is low.
15. Your rights
Under the GDPR you have the following rights regarding your personal data.
Access (Article 15). You can ask whether we process data about you and, if so, receive a copy along with information about the purposes, the categories of data, who receives it, how long we keep it, and where it came from.
Rectification (Article 16). You can have inaccurate data corrected and incomplete data completed.
Erasure (Article 17). You can ask us to delete data about you, subject to the exceptions in the GDPR — for instance where we are legally obliged to retain it.
Restriction (Article 18). You can ask us to limit what we do with your data instead of deleting it, for example while a dispute about its accuracy is resolved.
Portability (Article 20). Where processing is based on consent or a contract and carried out by automated means, you can receive the data you gave us in a structured, commonly used, machine-readable format, or ask us to transmit it to someone else.
Withdrawal of consent (Article 7(3)). Where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of what was done beforehand. We currently do not rely on consent for anything on this website.
Complaint (Article 77). You can complain to a data protection supervisory authority — in the member state where you live, where you work, or where you believe an infringement occurred.
To exercise any of these, just email contact@avaleryon.com. No particular form is needed.
16. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that we base on Article 6(1)(f) GDPR (legitimate interests). This includes any profiling based on that provision.
If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing serves to establish, exercise or defend legal claims.
Where we process your personal data for direct marketing, you can object at any time without giving any reason, and we will stop.
To object, email contact@avaleryon.com.
17. Supervisory authority
The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
https://www.ldi.nrw.de
You are free to complain to the authority where you live or work instead.
18. Changes to this policy
We update this policy when what we do with data changes, or when the law requires it. The version published here applies to your visit. If a change requires something from you, such as consent, we will ask you separately rather than relying on you noticing an update.
