Privacy Policy
Last updated: 13 September 2026
This Privacy Policy (the “Policy”) governs the processing of personal data of visitors and registered users (each, a “User”) of the website dreich.games and its subdomains (the “Site”), which presents DREICH, a tabletop role-playing game in development.
The Policy is issued in accordance with the Law of Ukraine “On Personal Data Protection” and, where applicable, Regulation (EU) 2016/679 (the “GDPR”). By using the Site the User confirms that the User has read this Policy. Where processing is based on consent, such consent is requested separately and may be withdrawn at any time.
Capitalised terms not defined herein have the meaning given to them in the Terms of Service.
1. Controller and contact details
The controller of personal data processed through the Site is the author of the DREICH project, a natural person resident in Ukraine operating the Site (the “Controller”).
Requests concerning this Policy, the exercise of data subject rights, and complaints shall be addressed to dreichgames@gmail.com. The Controller has not appointed a data protection officer, being under no obligation to do so under applicable law.
2. Scope
This Policy applies to personal data processed through the Site. It does not apply to third-party resources accessible by hyperlink from the Site, which operate under their own policies and for which the Controller bears no responsibility.
3. Categories of personal data processed
The Controller processes the following categories of personal data, according to the User’s interaction with the Site:
- Subscription data: the email address, the language version of the Site from which the subscription was submitted (ua or en), and the date of subscription.
- Account data: the email address; a one-time six-digit authentication code, valid for ten (10) minutes and deleted upon successful use, an unused code remaining in the record in an invalid state until superseded; confirmation that the address has been verified; the date of account creation; and the date of the most recent authentication.
- Google account data: where the User elects to authenticate by means of Google, an identity token issued by Google containing basic profile data. The Controller retains only the email address and the Google account identifier; all other data contained in the token is discarded. The Controller does not receive the User’s Google credentials, contacts, files or any other content of the User’s Google account.
- Entitlement data: the list of materials to which the User’s account has been granted access.
- Technical data: the IP address, the user agent, the resource requested and the timestamp of the request, recorded automatically by the web server.
- Analytics data: as described in Clause 5.
The Controller does not process the User’s name, date of birth, sex, telephone number, postal address, payment data or precise location, and does not process special categories of personal data within the meaning of Article 9 of the GDPR. The Site operates without passwords; no password or password hash is stored.
4. Purposes of processing and legal bases
Personal data is processed for the following purposes and on the following legal bases:
- Creation and operation of a User account and provision of access to materials — performance of a contract to which the data subject is party (Article 6(1)(b) of the GDPR), that contract being the Terms of Service.
- Dispatch of the development newsletter — consent (Article 6(1)(a) of the GDPR), given upon subscription and withdrawable at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Audience measurement and improvement of the Site by means of analytics cookies — consent (Article 6(1)(a) of the GDPR), given in accordance with Clause 5.
- Prevention of abuse, unsolicited registration and automated attack, and diagnosis of technical faults — the legitimate interests of the Controller in maintaining the security and availability of the Site (Article 6(1)(f) of the GDPR).
- Compliance with legal obligations to which the Controller is subject — Article 6(1)(c) of the GDPR.
Personal data shall not be processed for purposes incompatible with those set out above without prior information to the data subject and, where required, the data subject’s consent.
5. Cookies, local storage and analytics
The Site employs the following technologies for storing information on, and accessing information from, the User’s terminal equipment:
- Strictly necessary local storage: a single entry under the key auth-token containing a session token valid for seven (7) days, written only upon successful authentication. It is necessary for the provision of a service expressly requested by the User and is accordingly exempt from the consent requirement. It is erased upon logout or upon clearing of site data in the browser.
- Analytics cookies: Google Analytics 4, operated by Google LLC and, in respect of Users in the European Economic Area, the United Kingdom and Switzerland, by Google Ireland Limited, which sets cookies of the _ga family in order to distinguish sessions and returning visitors and to compile aggregated statistical reports. IP addresses are truncated before storage and are not used by the Controller to identify individual Users.
- Third-party cookies set by Google in the course of authentication, where the User elects to sign in by means of Google; such cookies are governed by Google’s own privacy policy.
No analytics cookie is set before the User has given prior consent by means of the cookie consent notice, nor where consent is refused or subsequently withdrawn. Consent may be refused without any restriction of access to the Site and may be withdrawn at any time by means of the same notice or by deleting the cookies in the browser settings. Refusal or withdrawal does not affect the strictly necessary storage described above.
The Site sets no advertising cookies, constructs no advertising profile and participates in no cross-site tracking. All fonts are served from the Site’s own infrastructure; no font, script or stylesheet is requested from a third-party content delivery network.
Browsers permit cookies to be blocked or erased. Blocking the strictly necessary storage described above renders authentication impossible.
6. Recipients of personal data
Personal data is not sold, rented or otherwise made available to third parties for their own purposes. It is disclosed solely to the following recipients, acting as processors or as independent controllers, to the extent necessary for the operation of the Site:
- MongoDB, Inc. (MongoDB Atlas) — cloud database hosting of accounts and subscriptions.
- Contabo GmbH — hosting of the server on which the Site operates.
- Cloudflare, Inc. — domain name resolution, traffic routing and protection against automated attack; all traffic to the Site traverses this network.
- Google LLC and Google Ireland Limited — authentication by means of Google, where elected by the User, and audience measurement by means of Google Analytics 4, subject to consent.
- The provider of the electronic mail service by which authentication codes and newsletters are dispatched.
Personal data may further be disclosed to competent public authorities where disclosure is required by law, and to professional advisers bound by an obligation of confidentiality.
7. International transfers
Certain recipients identified in Clause 6 process personal data outside Ukraine and the European Economic Area. Such transfers are effected on the basis of the Standard Contractual Clauses adopted by the European Commission, an adequacy decision, or another transfer mechanism provided for by applicable law. A copy of the relevant safeguards may be requested at dreichgames@gmail.com.
8. Retention periods
- Authentication codes — ten (10) minutes; a code that has been used is deleted immediately, an unused code remaining in an invalid state until superseded.
- Account data — for the duration of the account. Following a verified erasure request, the data is deleted within thirty (30) days.
- Subscription data — until withdrawal of consent or receipt of a request for erasure.
- Technical server records — until overwritten in the ordinary course of log rotation; such records are not archived, aggregated or used for profiling.
- Analytics data — for the retention period configured in Google Analytics, not exceeding fourteen (14) months from the User’s last activity.
Upon expiry of the applicable period the data is deleted or irreversibly anonymised, save where a longer retention period is required by law.
9. Rights of the data subject
Subject to the conditions laid down by applicable law, the data subject has the right to:
- obtain confirmation as to whether personal data concerning them is processed, and to obtain a copy thereof;
- obtain the rectification of inaccurate or incomplete data;
- obtain the erasure of data;
- obtain the restriction of processing;
- object to processing carried out on the basis of legitimate interests;
- receive their data in a structured, commonly used and machine-readable format and have it transmitted to another controller;
- withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal;
- lodge a complaint with a supervisory authority.
Requests shall be submitted to dreichgames@gmail.com from the email address to which the account or subscription is registered. The Controller shall respond within thirty (30) days of receipt. Where a request is manifestly unfounded or excessive, in particular by reason of its repetitive character, the Controller may decline to act upon it, stating the reasons.
Consent to the newsletter may be withdrawn by written request to dreichgames@gmail.com and, where an unsubscribe facility is provided within a message, by means of that facility.
10. Security measures
The Site is served exclusively over HTTPS. Access to the database is restricted to an allowlist of IP addresses and to a dedicated credentialed account. Session tokens are cryptographically signed and time-limited. Authentication codes are invalidated after five (5) unsuccessful attempts.
No method of transmission or storage is absolutely secure. The Controller implements technical and organisational measures appropriate to the risk but gives no warranty of absolute security.
11. Children
The Site is not directed at persons under the age of sixteen (16), and the Controller does not knowingly process their personal data. Where the Controller becomes aware that such data has been provided, it shall be erased without undue delay. Any person may report such a case to dreichgames@gmail.com.
12. Automated decision-making
The Controller does not carry out automated decision-making producing legal effects concerning the data subject or similarly significantly affecting them within the meaning of Article 22 of the GDPR, and does not engage in profiling for such purposes.
13. Amendments to this Policy
The Controller reserves the right to amend this Policy. The version in force is that published at this address, the date stated at the head of the page indicating the date of its last amendment. Material amendments shall be notified to account holders and subscribers by email not less than ten (10) days before they take effect.
14. Complaints and contact
Questions, requests and complaints: dreichgames@gmail.com.
A data subject who considers that the processing of their personal data infringes applicable law may lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or, within the European Economic Area, with the supervisory authority of their habitual residence.
See also the Terms of Service.