Privacy Policy
Information according to EU General Data Protection Regulation (GDPR)
1. Controller
The controller within the meaning of the GDPR is:
Justin Schneider
Marktstraße 1
99444 Blankenhain
Germany
Email:
kirvxdesign@gmail.com
2. General Information on Data Processing
We only process personal data as far as necessary to provide, operate and secure this website and its community features. Processing is based on:
- Art. 6(1)(b) GDPR (Contract / User Account)
- Art. 6(1)(f) GDPR (Legitimate interest in a secure and functional online service)
Our servers (web + database) are hosted by Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (server location: Germany).
3. Data We Collect
a) Server Log Files
When visiting our website, the following data is automatically processed and temporarily stored:
- anonymised IP address of the requesting device
- date and time of access
- page or file requested (URL)
- amount of data transferred
- browser type and version
- operating system
- referrer URL (previous page)
This data is processed exclusively for technical availability, security and error analysis. No personal profiling. Legal basis: Art. 6(1)(f) GDPR.
b) Login via Discord (OAuth 2.0)
We use “Login with Discord” (OAuth 2.0) for authentication.
With your consent, Discord transfers the following data:
- Discord user ID
- Username + discriminator
- Avatar image
- optional language setting
We store this data locally for your KIRVX account. We do not receive passwords, messages, friends lists or server info.
c) Login via Google (OAuth 2.0)
We also offer login via Google.
Depending on consent, Google provides:
- Google Account ID
- Name
- Verified email
- Profile picture
This data is used exclusively to create and manage your KIRVX account.
Data may be processed in third countries. Google uses Standard Contractual Clauses.
d) User-generated content
When you create or manage content, we process the information you provide.
File uploads are stored on servers in Germany.
e) Cookies
Our website uses only technically essential cookies:
- Session cookie (session ID)
- Language preference
- Cookie consent status
These cookies contain no personal data.
We do not use tracking or marketing cookies.
f) Contact via email
Email data is processed solely to handle your request.
4. Recipients of Data
Personal data may be processed by:
- Strato AG (hosting / server location Germany)
- Discord Inc. (OAuth login)
- Google Ireland / Google LLC (OAuth login)
No further transfer to third parties. No external tracking tools.
5. Storage Duration
We store personal data only as long as necessary for its purpose.
After deletion of the KIRVX account, associated data is removed unless legal obligations require retention.
6. Data Security
We implement appropriate technical and organisational measures, including:
- strict use of HTTPS (SSL/TLS)
- server location Germany
- secure session and cookie handling
- security headers (CSP, HSTS, etc.)
- blocking script execution in upload folders
- regular software updates
7. Your Rights under GDPR
You have the following rights:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
You may contact us anytime to exercise your rights.
8. Withdrawal of Consent
If processing is based on consent, you may withdraw it at any time.
9. Right to Lodge a Complaint
If you believe your data is unlawfully processed, you may file a complaint.
Supervisory authority:
Thuringian Commissioner for Data Protection and Freedom of Information
Häßlerstraße 8
99096 Erfurt
Germany
Email:
poststelle@datenschutz.thueringen.de
10. Changes to this Privacy Policy
We may update this policy due to legal or technical changes.