Privacy Policy

Information according to EU General Data Protection Regulation (GDPR)

1. Controller

The controller within the meaning of the GDPR is:

Justin Schneider
Marktstraße 1
99444 Blankenhain
Germany
Email: kirvxdesign@gmail.com

2. General Information on Data Processing

We only process personal data as far as necessary to provide, operate and secure this website and its community features. Processing is based on:

  • Art. 6(1)(b) GDPR (Contract / User Account)
  • Art. 6(1)(f) GDPR (Legitimate interest in a secure and functional online service)

Our servers (web + database) are hosted by Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany (server location: Germany).

3. Data We Collect

a) Server Log Files

When visiting our website, the following data is automatically processed and temporarily stored:

  • anonymised IP address of the requesting device
  • date and time of access
  • page or file requested (URL)
  • amount of data transferred
  • browser type and version
  • operating system
  • referrer URL (previous page)

This data is processed exclusively for technical availability, security and error analysis. No personal profiling. Legal basis: Art. 6(1)(f) GDPR.

b) Login via Discord (OAuth 2.0)

We use “Login with Discord” (OAuth 2.0) for authentication.

With your consent, Discord transfers the following data:

  • Discord user ID
  • Username + discriminator
  • Avatar image
  • optional language setting

We store this data locally for your KIRVX account. We do not receive passwords, messages, friends lists or server info.

c) Login via Google (OAuth 2.0)

We also offer login via Google.

Depending on consent, Google provides:

  • Google Account ID
  • Name
  • Verified email
  • Profile picture

This data is used exclusively to create and manage your KIRVX account.

Data may be processed in third countries. Google uses Standard Contractual Clauses.

d) User-generated content

When you create or manage content, we process the information you provide.

File uploads are stored on servers in Germany.

e) Cookies

Our website uses only technically essential cookies:

  • Session cookie (session ID)
  • Language preference
  • Cookie consent status

These cookies contain no personal data.

We do not use tracking or marketing cookies.

f) Contact via email

Email data is processed solely to handle your request.

4. Recipients of Data

Personal data may be processed by:

  • Strato AG (hosting / server location Germany)
  • Discord Inc. (OAuth login)
  • Google Ireland / Google LLC (OAuth login)

No further transfer to third parties. No external tracking tools.

5. Storage Duration

We store personal data only as long as necessary for its purpose.

After deletion of the KIRVX account, associated data is removed unless legal obligations require retention.

6. Data Security

We implement appropriate technical and organisational measures, including:

  • strict use of HTTPS (SSL/TLS)
  • server location Germany
  • secure session and cookie handling
  • security headers (CSP, HSTS, etc.)
  • blocking script execution in upload folders
  • regular software updates

7. Your Rights under GDPR

You have the following rights:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)

You may contact us anytime to exercise your rights.

8. Withdrawal of Consent

If processing is based on consent, you may withdraw it at any time.

9. Right to Lodge a Complaint

If you believe your data is unlawfully processed, you may file a complaint.

Supervisory authority:

Thuringian Commissioner for Data Protection and Freedom of Information
Häßlerstraße 8
99096 Erfurt
Germany
Email: poststelle@datenschutz.thueringen.de

10. Changes to this Privacy Policy

We may update this policy due to legal or technical changes.