We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our web portal (the "Service").
SUMMARY OF KEY POINTS
This summary provides key points from our Privacy Policy, but you can find out more details about any of these topics by using our table of contents below.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we collect any information from third parties? We do not collect any information from third parties.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties (hosting providers, payment processors, analytics providers).
How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet can be guaranteed to be 100% secure.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by visiting subtails.com/data-export (future feature), or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
ceyxstudios
Stollestr. 25 01159 Dresden
info@ceyxstudios.com
2. Data We Collect
When you use our Service, we may collect the following types of data:
- Personal Information: such as your name, email address, and account login details when you register or contact us.
- Usage Data: including your IP address, browser type, device information, and pages visited (collected automatically via cookies and analytics tools).
- Linked Gaming Accounts (future feature): Steam, Xbox, PlayStation IDs for personalized recommendations (Epic 3).
- Payment Information (future feature): processed securely by third-party payment providers (e.g., PayPal, Stripe). We do not store or have direct access to your full payment details.
- Communications: information you provide when subscribing to newsletters or contacting our support.
3. How We Use Your Data
We process your data for the following purposes:
- To provide, operate, and maintain our Service.
- To create and manage user accounts.
- To process transactions via trusted payment service providers (future feature).
- To send administrative and marketing communications (only if you have consented).
- To analyze and improve the Service, including via Google Analytics.
- To comply with legal obligations.
5. Legal Basis for Processing (GDPR)
We process personal data under the following legal bases:
- Consent (Art. 6(1)(a) GDPR) – e.g., when you sign up for a newsletter.
- Contractual necessity (Art. 6(1)(b) GDPR) – e.g., when creating an account or making payments.
- Legitimate interests (Art. 6(1)(f) GDPR) – e.g., analytics, service improvement.
- Legal obligation (Art. 6(1)(c) GDPR).
6. Data Sharing
We may share your data only with trusted third parties:
- Hosting provider: Vercel (servers may be located in the EU or the US).
- Database provider: Neon (PostgreSQL database hosting, servers in the EU/US).
- Email service: SendGrid (for transactional emails and notifications).
- Gaming platform APIs: Steam, Epic Games Store, GOG (for library sync and game data, when you link your accounts).
- Messaging services: Discord (for optional notifications via Discord bot, when you opt in).
- Payment providers: such as PayPal or Stripe, for secure payment processing (future feature).
- Analytics providers: Google Analytics.
- Legal authorities if required by law.
We do not sell or rent your personal data.
7. Third-Party Websites
In Short: We are not responsible for the safety of any information that you share with third parties that we may link to or who advertise on our Services, but are not affiliated with, our Services.
The Services may link to third-party websites, online services, or mobile applications and/or contain advertisements from third parties that are not affiliated with us and which may link to other websites, services, or applications. Accordingly, we do not make any guarantee regarding any such third parties, and we will not be liable for any loss or damage caused by the use of such third-party websites, services, or applications. The inclusion of a link towards a third-party website, service, or application does not imply an endorsement by us. We cannot guarantee the safety and privacy of data you provide to any third parties. Any data collected by third parties is not covered by this Privacy Policy. We are not responsible for the content or privacy and security practices and policies of any third parties, including other websites, services, or applications that may be linked to or from the Services. You should review the policies of such third parties and contact them directly to respond to your questions.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA. We ensure that such transfers comply with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) where required.
10. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this Privacy Policy, unless a longer retention period is required by law.
- Active accounts: Data retained while your account is active
- Inactive accounts: Accounts inactive for 2 years will be archived and data anonymized
- Deleted accounts: When you request account deletion, we will delete your data within 30 days, except where retention is required by law
- Usage data: Analytics data may be retained for up to 2 years for service improvement and legal compliance
After the retention period, personal data is either deleted or anonymized so it can no longer be associated with you.
11. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (HTTPS)
- Encrypted database storage
- Regular security audits
- Access controls and authentication
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11a. Data Breach Notification
In the event of a data breach that may risk your rights and freedoms, we will notify affected users within 72 hours as required by GDPR Article 33.
12. Your Rights (GDPR & CCPA)
You have the right to:
- Access: Request a copy of your personal data.
- Correction: Update inaccurate data.
- Deletion: Request deletion of your account and all associated data (Epic 3 feature).
- Restriction: Restrict or object to processing.
- Portability: Request data export in JSON format (Epic 3 feature).
- Withdraw consent: Opt-out of marketing communications at any time.
- Lodge a complaint: Contact your local data protection authority.
To exercise your rights, visit subtails.com/data-export (future feature) or contact us at info@ceyxstudios.com
13. Children's Privacy
Our Service is intended for users aged 16 and older. Users between 13-15 require parental consent. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13 without verification of parental consent, we will take steps to delete that information.
14. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected.
At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Privacy Policy.
15. Do United States Residents Have Specific Privacy Rights?
In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law.
Categories of Personal Information We Collect
We have collected the following categories of personal information in the past twelve (12) months:
- Identifiers: Name, email address, account credentials
- Internet Activity: IP address, browser type, pages visited, usage data
- Geolocation Data: General location based on IP address
- Inferences: Preferences derived from usage patterns
Personal Information We Do NOT Sell
We do not sell personal information. We have not sold personal information in the past 12 months and do not intend to sell personal information in the future.
Your Rights Under US Privacy Laws
Depending on your state of residence, you may have the following rights:
- Right to know what personal information we collect, use, and disclose
- Right to request deletion of your personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale of personal information (not applicable - we don't sell data)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at info@ceyxstudios.com or visit subtails.com/data-export (future feature).
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. We will notify users of material changes via email (if you have provided your email address).
Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
17. Contact
If you have questions about this Privacy Policy, please contact us at:
ceyxstudios
info@ceyxstudios.com
Stollestr. 25 01159 Dresden
Germany
Response time: We will respond to your inquiry within 30 days as required by GDPR.
8. Social Logins (Future Feature - Epic 3)
In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.
Our Services offer you the ability to register and log in using your third-party social media account details (like your Steam, Xbox, or PlayStation logins). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, friends list, and profile picture, as well as other information you choose to make public on such a social media platform.
We will use the information we receive only for the purposes that are described in this Privacy Policy or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their privacy policy to understand how they collect, use, and share your personal information, and how you can set your privacy preferences on their sites and apps.