Privacy Policy
Velkaris – The Chronicle of Blades
Effective date: May 2026
1. Introduction
The following information provides an overview of how we process your personal data and outlines your rights
under data protection law. This privacy policy applies to:
- the website velkaris.net (information pages, news, roadmap, lore, encyclopedia);
- the game application app.velkaris.net (browser client and Capacitor-based mobile apps for iOS and
Android); - all features offered through these services, including registration, playing multiple characters across multiple
worlds, clan and community functions, in-game purchases, and push notifications.
All processing of personal data takes place in accordance with the EU General Data Protection Regulation
(GDPR) and applicable German data protection laws (BDSG, TTDSG).
2. Controller
The data controller within the meaning of the GDPR is:
Digitalagentur Seidl GmbH Holzhofstraße 19 82362 Weilheim i.OB Germany
Represented by: Ludwig Seidl Email: contact@velkaris.net
3. Data Protection Officer
We are not legally required to appoint a Data Protection Officer. The contact for all data protection matters is:
Ludwig Seidl Email: l.seidl@seidl-it.info
4. Definitions
This policy uses the terminology defined in the GDPR (Art. 4 GDPR), in particular:
- Personal data – any information relating to an identified or identifiable natural person (e.g. name, email, IP
address, account ID, character name). - Processing – any operation performed on personal data (e.g. collection, storage, modification, transfer,
deletion). - Processor – a service provider that processes personal data on our behalf (e.g. our hosting provider).
- Consent – any freely given, informed and unambiguous indication of the data subject’s wishes.
5. Legal Bases for Processing
We process your personal data on the following legal bases:
- Art. 6(1)(a) GDPR – Consent (e.g. newsletter, optional cookies, push notifications).
- Art. 6(1)(b) GDPR – Performance of a contract (game access, payment processing, provision of the app).
- Art. 6(1)(c) GDPR – Compliance with legal obligations (e.g. tax and commercial retention periods).
- Art. 6(1)(f) GDPR – Legitimate interest (e.g. IT security, fraud and cheat prevention).
6. Hosting
Our entire technical infrastructure (web servers, game servers, database) is operated by:
Hetzner Online GmbH Industriestraße 25 91710 Gunzenhausen Germany
All servers are located exclusively in data centres within the Federal Republic of Germany. A data processing
agreement (DPA) pursuant to Art. 28 GDPR is in place with Hetzner Online.
When you access our services, the following technical data is transmitted to our servers and stored in so-called
server log files:
- IP address
- Date and time of access
- URL / endpoint requested
- Browser type and version, or app version
- Operating system
- Referrer (previous page)
This data is processed to ensure functionality, troubleshoot errors, and defend against attacks (Art. 6(1)(f) GDPR).
Logs are automatically deleted after a maximum of 30 days, unless security-relevant incidents require longer re‐
tention.
7. SSL/TLS Encryption
All connections to velkaris.net and app.velkaris.net are made exclusively over an encrypted HTTPS connection
(TLS 1.2 or higher). This applies in particular to login credentials, payment data, and all game content.
8. Cookies and Similar Technologies
8.1 Strictly Necessary Cookies
We use strictly necessary cookies and comparable technologies (such as local storage and refresh token cookies)
to operate the website and the game app. These include:
- Authentication cookies (refresh token) to keep you logged in
- Session cookies for active sessions
- Language and preference cookies
- Consent cookie for the cookie banner
Legal basis: § 25(2)(2) TTDSG, Art. 6(1)(f) GDPR.
8.2 Consent-based Cookies
We currently do not use any marketing, tracking or analytics cookies. Should we introduce such technologies in
the future, we will obtain your consent via our cookie banner (§ 25(1) TTDSG, Art. 6(1)(a) GDPR).
9. Account Registration and Sign-In
9.1 Standard Registration
A user account is required to use the game app. During registration, we collect:
- Email address
- Password (stored only as a secure hash; never accessible in plain text)
- IP address and timestamp of registration (for abuse prevention)
Authentication is handled via JSON Web Tokens (JWT). Upon login, a short-lived access token and a longer-lived
refresh token (stored as an HttpOnly cookie) are issued. With every login, we record the IP address and timestamp
so that suspicious activity can be detected.
Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (security).
9.2 Sign-In via Third-Party Providers (OAuth)
You may alternatively sign in via the following external providers:
Google Sign-In – Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. On sign-in,
Google transmits your email address, a unique Google account ID and, where applicable, your public name to us.
We use this data solely to create your account and authenticate you. Privacy policy: https://policies.google.com/
privacy
Discord OAuth – Provider: Discord Netherlands BV, Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands.
On sign-in, your Discord user ID, username, avatar and email address are transmitted to us. We use this data
solely to create your account and authenticate you. Privacy policy: https://discord.com/privacy
Legal basis: Art. 6(1)(a) GDPR (consent given by clicking the respective button) and Art. 6(1)(b) GDPR (contract
performance). You may withdraw your consent at any time by disconnecting the provider in your account settings
or by deleting your account.
We do not establish any link beyond the authentication purpose. No activity is published in your Discord or
Google account.
10. Game Account, Characters and Gameplay Data
In the course of operating the game, we process the following data:
10.1 Character Data
Each account may create multiple characters across multiple game worlds. For each character we store:
- Character name (pseudonym)
- Race, class, gender, appearance
- Level, experience points, attributes, skills
- Inventory, equipment, upgrades, set bonuses
- World position and current world assignment
- Game progress, completed quests, achievements
- Statistics (kills, deaths, PvP rating, playtime)
10.2 Combat and Activity Data
- Combat logs (PvE and PvP)
- Trading activity, auction house transactions
- Clan membership, rank within the clan, join date
- Chat messages (world, clan, group, private)
10.3 Purposes of Processing
- Providing the game (Art. 6(1)(b) GDPR)
- Fair play, anti-cheat, abuse prevention (Art. 6(1)(f) GDPR)
- Handling support requests and reports (Art. 6(1)(b) and (f) GDPR)
10.4 Retention Period
Gameplay data is stored as long as your account exists. Upon account deletion, character and game data are
anonymised or deleted (see section 15). Chat messages are automatically deleted after 90 days unless required for
an ongoing abuse investigation or support case.
11. Public Profiles (PublicSpieler & PublicClan)
Important notice: Character names, clan names and clan tags are publicly visible within the game platform and
are displayed on publicly accessible profile pages:
- PublicSpieler page – shows the character name, race, class, level, clan affiliation, statistics (PvP ranking,
achievements) and, where applicable, the equipment set. - PublicClan page – shows the clan name, clan tag, member list (with links to the corresponding PublicSpieler
pages), clan statistics and an optional clan description.
These profiles are accessible without logging in and may be indexed by search engines. We therefore strongly
recommend that you do not use your real name as a character or clan name, but choose a pseudonym instead.
Legal basis: Art. 6(1)(b) GDPR (contract performance – a public game world is a core feature of a multiplayer
RPG) and Art. 6(1)(f) GDPR (legitimate interest in maintaining a vibrant, publicly visible game community).
You cannot opt out of search engine indexing for an individual character; full removal occurs only after deletion
of the character or account.
12. Payment Processing via Stripe
In-game purchases (premium content, virtual currency, cosmetic items) are processed via the payment service
provider Stripe.
EU provider: Stripe Payments Europe, Limited 1 Grand Canal Street Lower, Grand Canal Dock Dublin, D02
H210, Ireland
Parent company (USA): Stripe, Inc. 510 Townsend Street San Francisco, CA 94103, USA
12.1 Data Processed
When a purchase is made, the following data is transmitted to Stripe and/or collected directly by Stripe:
- First name and last name
- Billing address, country
- Email address
- Payment method (e.g. credit card number, IBAN, PayPal account, Apple Pay / Google Pay token)
- Transaction amount, currency, date and time
- IP address, browser/device information (for fraud prevention via Stripe Radar)
- A unique transaction ID
Payment instrument data (card number, CVC etc.) is processed and stored exclusively by Stripe in a PCI-DSScertified environment. We do not receive or store this data. We only receive confirmation of a successful payment
together with the transaction ID.
12.2 Legal Basis
Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (fraud prevention).
12.3 Transfer to Third Countries (USA)
Stripe may transfer personal data to Stripe, Inc. in the USA. Stripe is certified under the EU–US Data Privacy
Framework (https://www.dataprivacyframework.gov/), ensuring an adequate level of data protection within the
meaning of Art. 45 GDPR. In addition, Stripe has implemented EU Standard Contractual Clauses (Art. 46 GDPR).
12.4 Retention Period
Payment-related data is subject to statutory retention periods under German tax and commercial law (§ 147 AO, §
257 HGB). Invoices and accounting records are retained for 10 years; other business correspondence for 6 years.
After expiry, the data is deleted.
12.5 Further Information
Stripe’s privacy policy: https://stripe.com/privacy
13. Push Notifications (Mobile App)
The mobile app (iOS and Android) can send push notifications, for example for:
- incoming private or clan messages
- PvP attacks on your character
- completed actions (crafting, upgrades, travel)
- important clan events
- event reminders
Push notifications are sent only if you have enabled them in your operating system and in the app settings.
13.1 Services Used
Android: Firebase Cloud Messaging (FCM) Provider: Google Ireland Limited, Gordon House, Barrow Street,
Dublin 4, Ireland. A pseudonymous FCM device registration ID and the message content are transmitted. Privacy:
https://firebase.google.com/support/privacy
iOS: Apple Push Notification Service (APNs) Provider: Apple Distribution International Ltd., Hollyhill
Industrial Estate, Hollyhill, Cork, Ireland. A pseudonymous APNs device token and the message content are
transmitted. Privacy: https://www.apple.com/legal/privacy/
We store the device token per character and world so that notifications can be delivered to the correct device. If
you disable push notifications in the app, the corresponding token is deleted.
13.2 Legal Basis
Art. 6(1)(a) GDPR (consent given by enabling push notifications in the app settings). You may withdraw your
consent at any time via the app settings or your operating system settings.
13.3 Third Country Transfers
Both Google and Apple may transfer data to the United States. Both companies are certified under the EU–US
Data Privacy Framework.
14. Contacting Us
If you contact us by email, the contact form, or via support functions in the app, we process your details (name,
email address, account ID, message content) in order to handle your enquiry.
Legal basis: Art. 6(1)(b) GDPR (if related to a contract) or Art. 6(1)(f) GDPR (legitimate interest in answering en‐
quiries).
Retention period: until your enquiry has been fully resolved, and no longer than required by statutory retention
periods.
15. Account Deletion
You can delete your account at any time, either
- via the account settings in the app, or
- by email to l.seidl@seidl-it.info.
Upon deletion:
- all characters, gameplay progress, inventories and personal settings are irreversibly deleted;
- email address, OAuth links and push tokens are deleted;
- chat messages and forum posts in which you appear as sender or recipient are anonymised (shown as
“Deleted Player”) where full deletion would disproportionately impair readability for other players; - clan memberships are terminated; clan data of other members is retained;
- payment-related data (invoices, Stripe transaction records) is retained for the statutory retention periods (§
147 AO, § 257 HGB), but excluded from any further use within the game.
A deleted account cannot be restored.
16. Minors
Use of Velkaris is permitted to persons aged 16 years or older (USK 16 rating). By registering you confirm that
you are at least 16 years of age.
For consent to data processing that is not necessary for the performance of the contract (e.g. push notifications),
Art. 8 GDPR applies: persons under 16 require the consent of a parent or legal guardian. If we become aware that
a user has not reached the minimum age, the account is suspended and, once the matter has been clarified, deleted.
17. Newsletter
You can subscribe to our newsletter on velkaris.net. Newsletters are sent via:
Brevo GmbH Köpenicker Straße 126 10179 Berlin, Germany
Subscription uses a double opt-in process: after sign-up, you receive a confirmation email with an activation link.
We store the email address, IP address and timestamp of sign-up and confirmation.
Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time via the unsubscribe link in
every newsletter or by email.
Brevo privacy policy: https://www.brevo.com/legal/privacypolicy/
18. Security Measures
To safeguard our services we use, among others:
- TLS encryption (HTTPS) for all data transmissions
- Password hashing using modern algorithms (bcrypt / argon2)
- JWT-based authentication with refresh token rotation
- Rate limiting and brute force protection
- Server-side validation of all gameplay actions (anti-cheat)
- Backups in Germany (Hetzner) with encrypted transfer
- Logging and monitoring to detect anomalies
19. Your Rights as a Data Subject
You have the following rights regarding the personal data we process about you:
19.1 Right of Access (Art. 15 GDPR)
You may request information about the data we process about you.
19.2 Right to Rectification (Art. 16 GDPR)
You may request correction of inaccurate or incomplete data.
19.3 Right to Erasure (Art. 17 GDPR)
You may request deletion of your data, provided no statutory retention obligations apply.
19.4 Right to Restriction of Processing (Art. 18 GDPR)
You may request restriction of processing.
19.5 Right to Data Portability (Art. 20 GDPR)
You may request that your data be provided in a structured, commonly used, machine-readable format.
19.6 Right to Object (Art. 21 GDPR)
You may object at any time to processing based on legitimate interests.
19.7 Right to Withdraw Consent (Art. 7(3) GDPR)
You may withdraw any consent at any time, with effect for the future.
19.8 Right to Lodge a Complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18 91522 Ansbach, Germany https://
www.lda.bayern.de
19.9 Exercising Your Rights
To exercise your rights, please contact: l.seidl@seidl-it.info
20. Automated Decision-Making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
In-game automated mechanisms (e.g. matchmaking, Stripe Radar for fraud prevention) do not produce legal
effects concerning you within the meaning of Art. 22 GDPR.
21. Disclosure of Data to Third Parties
We disclose your personal data only:
- to the processors named in this policy (Hetzner, Brevo, Stripe, Google, Apple, Discord) for the purposes
described; - to law enforcement and supervisory authorities where we are legally obliged to do so;
- with your explicit consent.
We do not sell or otherwise commercially share your data beyond the cases described above.
22. Retention Overview
| Data category | Retention period |
|---|---|
| Server log files | Max. 30 days |
| Account master data | Until account deletion |
| Character and gameplay data | Until account deletion |
| Chat messages | 90 days |
| Invoices / payment records | 10 years (§ 147 AO) |
| Business correspondence | 6 years (§ 257 HGB) |
| Newsletter data | Until withdrawal |
| Push tokens | Until push notifications are disabled |
| Login IP addresses | 90 days |
23. Updates to this Privacy Policy
This privacy policy is effective as of May 2026.
We may need to update this policy as our services evolve or when legal requirements change. The current version
is always available at https://velkaris.net/en/privacy-policy/. For material changes, registered users will be
notified by email or by an in-app notice.
24. Objection to Promotional Emails
We hereby object to the use of the contact data published in the legal notice and in this policy for the purpose of
sending unsolicited advertising. The operators reserve the right to take legal action in the event of unsolicited
promotional emails.