Privacy Policy
Product schedules
01 Scope of This Notice
This notice, in effect from 30 August 2026, explains how CEDRA Interactive handles personal data. It applies to the cedrainteractive.com website and to every product the studio publishes, whether a game, a platform, an engine or a tool. It also covers ordinary business contact: email you send us, job applications, and commercial correspondence.
The notice is layered. Sections 1 to 20 state the rules that hold across everything we operate. The annexes add what a particular jurisdiction or a particular role requires: Annex A for Türkiye, Annex B for the EEA, the United Kingdom and Switzerland, Annex C for the United States, Annex D for Asia-Pacific, and Annex E for the commitments we take on when we process data on a customer's behalf rather than our own. Where an annex is more specific than the body, the annex governs for the people it covers.
Each product also carries a schedule, published with the terms of service, which states the data its own use involves. Alongside a schedule a product may carry a further supplement: an in-game privacy screen, a store-page disclosure, or a data-processing agreement signed by a customer. A schedule and a supplement add detail for one product and do not replace this notice; they are read together with it.
This notice does not cover the platforms we publish through. Steam, the Epic Games Store, Google Play and the Apple App Store each act as an independent controller for the account, payment and device data they collect from you, under their own policies. We receive only what those platforms pass to us, as described in section 7.
Terms used here carry the meaning given in the applicable law: "personal data" and "processing" as in the GDPR and Law no. 6698, "personal information" as in the US state statutes, and the local equivalents named in Annex D.
02 Who Is Responsible for Your Data
CEDRA Interactive operates through two established entities, one in Türkiye and one in Estonia. For most of the processing described here they act as joint controllers within the meaning of article 26 of the GDPR, because they decide together what data the studio's products collect and why.
| Entity | Primary role | Supervisory authority |
|---|---|---|
| CEDRA Interactive, Türkiye | Data controller (veri sorumlusu) under Law no. 6698. Leads processing for users in Türkiye, the KVKK compliance programme, and the VERBİS registration. | Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), Ankara. kvkk.gov.tr |
| CEDRA Interactive, Estonia | Controller under the GDPR. Leads processing for users in the EEA, the United Kingdom and Switzerland, and represents the studio before EU authorities. | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tallinn. aki.ee |
The Essence of the Joint Arrangement
Article 26(2) of the GDPR requires us to make the substance of our arrangement available to you. Product and engineering decisions that determine what data is collected are taken jointly by the studio. Responsibility for informing you, answering your requests and dealing with the authorities is allocated by where you are: the Estonian entity for the EEA, the UK and Switzerland; the Türkiye entity for Türkiye. Security measures, retention schedules and vendor assessments are set once and applied by both. Each entity keeps its own record of processing activities.
Under article 26(3) you do not have to determine which entity to approach. Write to [email protected] and your request will be handled whichever entity is the addressee, and answered within the shortest period either applicable law allows.
Because the Estonian entity is established in the European Union, the studio does not require a representative under article 27 of the GDPR. A representative for the United Kingdom is addressed in Annex B.
Where we run a product for a customer organisation, that customer is the controller and we are the processor. That relationship is set out in section 8 and Annex E, and it is the only processing in this notice whose purpose we do not determine. Which products it applies to is stated in their schedules.
Registered company names, registration numbers and registered addresses for both entities are available on request from the address above, and are published here as each registration completes.
03 What Data We Process
We collect what a given product needs in order to work, and we do not retain data for which we have no purpose. What this amounts to depends on how you reach us.
If You Visit the Website
- Connection data: IP address, user-agent string, the page requested, the referring page, and the date and time of the request. Our hosting provider records these in order to serve the page and to defend against attack.
- Approximate location derived from the IP address: country and, in coarse terms, region. We do not attempt to locate you more precisely.
- Analytics identifiers and behaviour: a cookie identifier, pages viewed, session duration, and interaction counts. Section 6 lists the cookies by name.
- Your interface language, kept in your own browser under the key cedra-locale, and a flag under cedra-preloader-seen that prevents the opening animation replaying in the same tab. Neither is transmitted to us.
If You Write to Us
- Your name and email address, the content of your message and anything you attach, together with the technical headers your mail carries.
- For job applications: your CV and the career history, education, references and portfolio links you choose to include.
If You Play One of Our Games
- The account or player identifier your platform issues, such as a Steam ID, an Epic account ID, or a Google Play or Apple identifier, and the display name attached to it.
- Game state: progress, saves, settings, scores and the run history a title needs in order to resume.
- Gameplay telemetry: which levels are attempted, how long a session lasts, where a run ends, and which options are used. We use this to balance difficulty and to identify defects in design.
- Device and diagnostic data: device model, operating system version, language, graphics and memory characteristics, crash reports and stack traces.
- Purchase records passed to us by the store: that a transaction occurred, what it was for, and the amount. Card numbers do not reach us; the platform handles payment.
- Support and moderation records: tickets you open, reports you file or that name you, and enforcement decisions.
If You Are a Customer Organisation
- Account and billing data for your organisation: contact names, work email addresses, the plan you are on, invoices, and tax identifiers where a tax authority requires them.
- Console usage: authentication events, API keys, query volume and audit logs, which we hold as controller for security and billing.
- Event data your integration sends about your own end users. We hold that as your processor, under your instructions, and not for our own purposes. See Annex E.
Where the Data Comes From
- Directly from you: what you type, send or upload, including email, support tickets and job applications.
- Automatically from your device when you use the site or a game: connection data, device and diagnostic data, and gameplay telemetry.
- From the store platforms, which pass us an account identifier, a display name, entitlement information and confirmation of a purchase, as described in section 7.
- From our hosting and infrastructure providers, in the form of server and security logs.
- From a customer organisation, in the form of the event data it instructs us to process on its behalf. See Annex E.
- From publicly available sources only where you made something public yourself, such as a post in a community space we operate or on our GitHub organisation.
Special Categories
We do not set out to process special categories of personal data (health, biometrics, racial or ethnic origin, political opinions, religious or philosophical belief, trade-union membership, sex life or sexual orientation, genetic data), and none of our products request any of it. We do not process criminal-conviction data. If such data reaches us unsolicited, in a support ticket or a job application, we delete it unless we are required to retain it.
We do not purchase personal data from data brokers, we do not enrich what you give us from third-party datasets, and we do not operate advertising networks or cross-site tracking in our games or on this site.
04 Why We Process It, and on What Legal Basis
Every processing operation requires a purpose and a lawful basis. The table gives both, mapped to the GDPR and to Law no. 6698 side by side, because most of our processing falls under both at once. Article references are to the GDPR and to Law no. 6698 respectively.
| Purpose | Data used | GDPR basis | Law 6698 basis |
|---|---|---|---|
| Serving the website and keeping it available | Connection data, server logs | Art. 6(1)(f), legitimate interest in operating our own site | Art. 5(2)(f), legitimate interest |
| Defending against attack, abuse and fraud | Connection data, session and device data, enforcement records | Art. 6(1)(f), legitimate interest in security | Art. 5(2)(f), legitimate interest |
| Measuring how the site is used | Analytics cookie identifiers, page and session data | Art. 6(1)(a), consent | Art. 5(1), explicit consent |
| Answering your email and pre-contract enquiries | Name, email, message content | Art. 6(1)(b), steps before a contract; otherwise 6(1)(f) | Art. 5(2)(c), contract; otherwise 5(2)(f) |
| Running a game and saving your progress | Platform identifier, game state, settings | Art. 6(1)(b), performance of the contract accepted on play | Art. 5(2)(c), directly related to performance of a contract |
| Diagnosing crashes and fixing defects | Device data, crash reports, stack traces | Art. 6(1)(f), legitimate interest in a functioning product | Art. 5(2)(f), legitimate interest |
| Balancing difficulty and improving design | Gameplay telemetry | Art. 6(1)(a) where consent is requested in-product; otherwise 6(1)(f) | Art. 5(1) explicit consent; otherwise 5(2)(f) |
| Processing purchases and issuing invoices | Store transaction records, billing data | Art. 6(1)(b) and 6(1)(c) | Art. 5(2)(c) and 5(2)(ç) |
| Providing support and moderating community spaces | Contact details, ticket content, reports, diagnostic data | Art. 6(1)(b) and 6(1)(f) | Art. 5(2)(c) and 5(2)(f) |
| Sending commercial messages you requested | Name, email, record of your permission | Art. 6(1)(a), consent | Art. 5(1) explicit consent, with Law no. 6563 and the IYS regime |
| Operating a product for a customer organisation | Event data the customer's integration sends | Art. 28, processor acting on the controller's instructions | Art. 12 and the data-processing agreement |
| Billing and administering customer accounts | Organisation contacts, plan, usage volume, invoices | Art. 6(1)(b) and 6(1)(c) | Art. 5(2)(c) and 5(2)(ç) |
| Assessing job applications | CV, career history, references | Art. 6(1)(b) and 6(1)(f) | Art. 5(2)(c) and 5(2)(f) |
| Meeting accounting, tax and company-law duties | Invoices, contracts, correspondence | Art. 6(1)(c), legal obligation | Art. 5(2)(a) and 5(2)(ç) |
| Establishing, exercising or defending legal claims | Whatever the specific dispute requires | Art. 6(1)(f), and art. 9(2)(f) if special categories arise | Art. 5(2)(e), establishing or protecting a right |
Reliance on Legitimate Interest
Before relying on legitimate interest we carry out and record a balancing assessment, weighing the interest pursued against its effect on you, and we consider whether a less intrusive means would achieve the same purpose. You may request the outcome of any such assessment, and you may object to the processing under section 13. Where a purpose does not survive that balance, we seek consent instead or we do not pursue the purpose.
We carry out a data protection impact assessment under article 35 of the GDPR before introducing processing likely to present a high risk, and we do not release such a feature while the assessment remains open.
Using Data for a New Purpose
Before using data we already hold for a purpose not listed above, we assess whether the new purpose is compatible with the original one. If it is not, we inform you first and, where the law requires it, request your consent.
05 Consent, and Its Withdrawal
Where consent is the basis, we request it at the point the processing would begin, in the product and before the data moves, and separately for each purpose rather than bundled into a single acceptance. Consent obtained is recorded: what was asked, in which wording, and when.
Consent must be freely given, so refusal is available without consequence. Declining analytics or optional telemetry does not degrade a game or restrict access to the site. Where a feature cannot operate without the data, we state this at the point of the request.
You may withdraw consent at any time and as easily as it was given: from the privacy or settings screen in the product concerned, from the unsubscribe link in any commercial message, or by writing to [email protected]. Withdrawal takes effect prospectively; it stops the processing but does not render lawful past processing unlawful. On withdrawal we cease processing and delete or anonymise the data that consent covered, unless another basis in section 4 independently requires its retention.
Under Law no. 6698 consent must be explicit, specific and informed, and it cannot be made a condition of a service. Continued use of a product is not treated as consent, and silence is not treated as agreement.
Some jurisdictions in Annex D require consent to be collected separately for particular operations: a distinct authorisation per purpose under Korean law, and a separate consent for cross-border transfer under Chinese law. Where you are covered by those rules, the product requests consent accordingly.
07 Games and Store Platforms
Our games are distributed through Steam, the Epic Games Store, Google Play and the Apple App Store. Each of those is a separate company and a separate controller. When you buy or install a title, that platform collects your account, payment and device data under its own privacy policy, over which we have no access and no control.
What reaches us from a platform is limited to an account or player identifier, the display name attached to it, entitlement information (whether you own the game or a particular item) and aggregate purchase records. Card numbers, bank details and billing addresses do not reach us.
Within a game we process what section 3 describes: game state so that a save functions, telemetry so that difficulty can be tuned, and crash data so that defects can be fixed. Where a title requests optional telemetry, the privacy screen in that title is where the permission is granted or withdrawn, and the choice persists across sessions.
Anti-Cheat, Fraud and Enforcement
For titles with competitive elements we process session, device and behavioural signals to detect cheating, exploitation and fraudulent purchases, on the legitimate-interest basis in section 4. Detection may be automated, but a suspension or ban affecting your access is reviewed by a person before it takes effect, and you may contest it under section 16.
Community Spaces and User Content
Content you post in a community space we operate, or on our GitHub organisation, is visible to others by design and should be treated as public. We retain moderation records, including reports filed and decisions taken, for the period given in section 11. Third-party community platforms we may use are independent controllers for the accounts they hold.
Device Permissions, In-Game SDKs and the Advertising ID
A game asks for a device permission only when a feature needs it, at the point that feature is used, and the operating system holds the switch rather than us: you can refuse at the prompt and withdraw it later in your device settings. Declining a permission disables the feature that needed it and nothing else. We do not request access to your contacts, your microphone, your precise location or your photo library in order to run a game.
The SDKs inside our games are our own: our analytics SDK, for the telemetry described above, and the crash reporting built into our engine. We embed no advertising, attribution or social SDKs, so no third-party library in our games is collecting on its own account.
Our games do not collect or use the Android Advertising ID or Apple's Identifier for Advertisers. We build no advertising profiles, and there is no advertising identifier held by us to link to anything else. Identifiers a store platform assigns you are covered above.
Store-Page and In-Game Disclosures
A title's schedule, its store page and its in-game privacy screen state what that specific game collects. These are the schedules and supplements described in section 1: they add product detail and are read alongside this notice.
08 Two Roles, Kept Separate
Some of what the studio publishes is licensed to other organisations and run for them, rather than offered to a person directly. Where a product works that way, and its schedule says so, we stand in two distinct positions at once. The distinction is material, because different obligations attach to each.
As Controller, for Our Customer's Own Data
The account, billing and console-usage data of the customer organisation is data whose purpose we determine. We process it to provide the service, to invoice, to secure the platform and to meet our accounting duties, on the bases given in section 4.
As Processor, for the Event Data a Customer Sends
The telemetry a customer's game sends about that customer's players belongs to the customer. The customer determines what is collected and why; we hold and process it only on their documented instructions, under a data-processing agreement meeting article 28(3) of the GDPR and article 12 of Law no. 6698. We do not use it to improve our own products, we do not combine it with data from other customers, and we do not profile the end users it concerns.
The consequence for a player is this: if you played a game made by one of our customers, and that game sends telemetry to a product we run for them, the studio that made the game is the controller and your request for access or deletion goes to them. If you send it to us we will forward it to them promptly and confirm to you that we have done so, but we cannot determine it ourselves, because acting without the controller's instruction is what a processor may not do.
Annex E sets out the full list of commitments attaching to that role, including our handling of sub-processors, security, breach notification to the controller, assistance with data-subject requests, and return or deletion of data on termination.
Where the integration is done through an SDK we publish as open source, reading or compiling that source code involves no processing of personal data by us: a game that integrates it sends event data to the customer's own instance, under that customer's configuration.
09 Who Else Sees Your Data
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not rent or trade contact lists. Data leaves our control only in the categories below.
| Recipient category | Named recipients | Purpose |
|---|---|---|
| Hosting, CDN and network protection | Cloudflare, Inc. | Serving this site and absorbing attack traffic. Connection data and logs. |
| Website analytics | Google LLC / Google Ireland Limited | Google Analytics 4, on the consent basis in section 6. |
| Store and distribution platforms | Valve Corporation, Epic Games, Inc., Google LLC, Apple Inc. | Distribution, payment and entitlement. Each is an independent controller, not our processor. |
| Code hosting and public community | GitHub, Inc. (Microsoft Corporation) | Our public repositories and the SDKs we publish as open source. |
| Email and business tooling | Our mail and productivity providers | Receiving and answering correspondence, and internal administration. |
| Professional advisers | Lawyers, accountants, auditors | Legal advice, statutory accounts, audit. Bound by professional confidentiality. |
| Authorities and courts | Regulators, tax authorities, courts, law enforcement | Only where a valid legal obligation or a lawful order applies. See below. |
| A future corporate transaction | An acquirer or successor entity | If the studio is reorganised, merged or acquired. You would be informed, and the recipient would be bound by this notice until it lawfully replaced it. |
Every party acting as our processor is engaged under a written contract limiting them to our instructions and requiring confidentiality, appropriate security, restrictions on onward transfer, and deletion or return on termination. We assess a provider's security and privacy posture before engagement, and we do not give a processor more data than its task requires.
Government and Law-Enforcement Requests
We disclose data to an authority only where legally obliged. We verify that a request has a proper legal basis and originates from a body with jurisdiction, we require it in writing, we narrow it to what is actually sought, and we challenge it where it is overbroad or unlawful. Where we are permitted to inform you of a request concerning you, we do so.
10 Transfers Across Borders
A studio established in Türkiye and Estonia, using global infrastructure and distributing through American storefronts, transfers data across borders in the ordinary course. Each of the regimes below sets its own rules for that, and we satisfy them separately.
From the EEA, the UK and Switzerland
Transfers out of the EEA rely on Chapter V of the GDPR. Where the recipient country benefits from an adequacy decision under article 45, that is the basis. For recipients in the United States we rely either on the EU-US Data Privacy Framework, following the Commission's adequacy decision of 10 July 2023 where the recipient is certified under it, or on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. For other third countries we use those same clauses. Following the Court of Justice's judgment in Case C-311/18 (Schrems II) we also carry out a transfer impact assessment for each such route, and add supplementary measures where the assessment requires them, including encryption in transit and at rest, minimisation before transfer, and a commitment to challenge unlawful access requests.
UK transfers use the UK International Data Transfer Agreement or the UK Addendum to the EU clauses. Swiss transfers use the clauses as recognised by the Federal Data Protection and Information Commissioner, and the Swiss-US Data Privacy Framework where applicable.
From Türkiye
Article 9 of Law no. 6698 was rewritten by Law no. 7499, and the current regime has applied since 1 June 2024. Under it a transfer abroad may rest on an adequacy decision by the Personal Data Protection Board or, in the absence of one, on standard contracts, binding corporate rules, a written undertaking approved by the Board, or one of the exceptional grounds in article 9(6). The Board has not to date issued an adequacy decision for any country. Our transfers from Türkiye therefore rest on the standard contract, which we notify to the Board within five business days of signature as article 9 requires, or on an approved undertaking, or on an article 9(6) ground where one genuinely applies. We do not treat consent as a routine transfer mechanism.
Between Our Own Two Entities
Data moving between the Türkiye and Estonia entities is covered by an intra-group arrangement carrying the standard contract for the Türkiye leg and the Standard Contractual Clauses for the EEA leg, with a single set of security and retention rules applying at both ends.
From Asia-Pacific
Annex D sets out the transfer requirements applying under Chinese, Korean, Japanese, Singaporean and Indian law, including the separate consent and the security-assessment or standard-contract route that the PIPL requires for outbound transfers.
You may ask which mechanism covers a specific transfer, and request a copy of the relevant clauses with commercial terms redacted, at [email protected].
11 How Long We Keep It
We retain personal data for as long as the purpose it was collected for requires, and thereafter for any period a statute obliges us to. When both are exhausted we delete it or anonymise it so that it can no longer be linked to you. Where a legal-hold period is the sole reason data survives, we restrict access to it and cease using it for any other purpose.
| Data | Period | Basis for that period |
|---|---|---|
| Server and access logs | 12 months | The window in which a security incident can still usefully be investigated. |
| Website analytics data | 14 months | The maximum retention Google Analytics 4 permits; deleted by Google at expiry. |
| Email correspondence | 3 years from the last message | Continuity of the relationship, and the period in which a dispute over it may arise. |
| Game account, saves and progress | While the account is active, then 30 days | The grace period after a deletion request, so that an accidental deletion can be reversed. |
| Gameplay telemetry | 24 months, or until consent is withdrawn | Sufficient to compare across releases; aggregated and de-identified thereafter. |
| Crash reports and diagnostics | 12 months | The support life of the release the crash originated from. |
| Anti-cheat and enforcement records | 3 years | Detecting repeat behaviour, and allowing an appeal to be examined. |
| Purchase, invoice and accounting records | 10 years (Türkiye), 7 years (Estonia) | Turkish Commercial Code art. 82 and, for tax, Tax Procedure Law art. 253 (5 years); Estonian Accounting Act § 12. |
| Commercial-message permission records | The evidentiary period the applicable regulation prescribes after the permission lapses | Proving that a message was sent with permission, under Law no. 6563 and the IYS regime. |
| Customer event data held as processor | As the customer instructs; deleted or returned within 30 days of the contract ending | The customer is the controller and sets the period. |
| Job applications | 1 year, or 2 years if you agree to remain in the pool | The next hiring round for a comparable role. |
| Files relating to a claim or dispute | Until the claim is time-barred, generally 10 years | Turkish Code of Obligations art. 146, and the equivalent limitation period elsewhere. |
Backups follow their own cycle. Data deleted from a live system may persist in an encrypted backup until that backup rotates out, which takes no longer than 90 days. We do not restore a backup in order to recover data you asked us to delete.
12 Security and Data Breaches
We take technical and organisational measures proportionate to the risk, as article 32 of the GDPR and article 12 of Law no. 6698 both require:
- Traffic to this site and to our services is encrypted in transit with TLS. Data at rest is encrypted on the systems that hold it.
- Access is granted on least privilege and reviewed periodically. Administrative access requires multi-factor authentication.
- Secrets and signing keys are held outside version control, and our repositories are scanned to keep them so.
- Actions on production systems are logged, and the logs are retained per section 11.
- Changes pass code review before release, and dependencies are monitored for known vulnerabilities.
- Backups are encrypted and their restoration is tested.
- Providers are assessed before engagement and bound by written processing terms.
- Personnel are bound by confidentiality obligations outlasting their engagement, and are trained on handling personal data.
- Environments are separated, and live personal data is not used in development or testing.
No set of measures makes a system immune. Our commitment is that a failure is detected, contained and disclosed.
If a Breach Occurs
We investigate, contain and record every incident. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it, under article 33 of the GDPR. Where the risk is high, we also notify you under article 34, stating what happened, which data was involved, what we have done, and what you can do.
In Türkiye the same 72-hour deadline applies to notifying the Personal Data Protection Board, under article 12(5) of Law no. 6698 as set out in the Board's decision no. 2019/271 of 24 January 2019, and affected data subjects must be informed within the shortest reasonable time. Breach-notification duties under the other regimes in this notice, including the mandatory notification obligations in Singapore and the state breach statutes in the United States, are met on their own timelines. Where we act as a processor, we notify the controller without undue delay and leave notification of authorities and individuals to them, as Annex E provides.
13 Your Rights
The rights you hold depend on which law covers you, and the annexes give the specifics. In substance, wherever you are, the following apply.
- Confirmation of whether we process data about you, and a copy of it, together with the purposes, the recipients, the retention period and the source.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure where the data is no longer needed, where consent is withdrawn and no other basis supports the processing, or where the processing was unlawful.
- Restriction of processing while an accuracy dispute or an objection is examined.
- Portability: receipt of the data you provided in a structured, commonly used, machine-readable format, and its transmission to another controller where technically feasible.
- Objection to processing based on legitimate interest, and an absolute objection to direct marketing, which admits no balancing.
- Withdrawal of consent at any time, without having to give reasons.
- Freedom from a decision made solely by automated means having a legal or similarly significant effect. See section 16.
- Notification, where we correct or delete data and it is possible to do so, that we have passed that on to the recipients we shared it with.
- Complaint to us, to your supervisory authority, and to a court. Approaching us first is not a precondition for either.
- No detriment for exercising any of these rights. Exercising a right has no effect on service, price or quality.
Rights are not unlimited. A request may be refused in part where granting it would disclose another person's personal data, breach a legal obligation to retain, or prejudice the establishment or defence of a legal claim. Where we refuse or limit a request, we identify the exception relied on and the reason, so that our decision can be challenged.
14 How to Make a Request
Write to [email protected], stating what you seek and, if you can, which product or account it concerns, which shortens the search. Marking the subject line as a privacy request helps it reach the right desk. There is no form to complete and no particular wording is required.
We may need to confirm your identity before disclosing or deleting personal data, because doing either for the wrong person is itself a breach. We ask for the minimum that establishes it, usually a reply from the email address already on the record or the account identifier used in the product, and we do not require identity documents unless no other means will suffice.
Deadlines
| Regime | Deadline | Note |
|---|---|---|
| GDPR / UK GDPR | 1 month | Extendable by 2 further months for complex or numerous requests. We inform you within the first month if we extend, and of the reason. |
| Law no. 6698 (Türkiye) | 30 days | Under art. 13 and the Communiqué on Application Procedures. See Annex A for the fee schedule and the complaint route. |
| US state privacy laws | 45 days | Extendable once by a further 45 days with notice. Appeal rights are in Annex C. |
| Asia-Pacific | As each statute prescribes | Annex D. Where two regimes both apply, we answer within the shorter of them. |
Requests are free of charge. We charge only where a law expressly allows it: the per-page schedule under Turkish law described in Annex A, or the cost of the medium where you request a copy on physical media. We do not charge for a repeat request unless it is manifestly excessive, and where we conclude that it is, we say so and give reasons rather than simply refusing.
You may use an authorised agent where the applicable law allows it. We will require proof of the authorisation, and we may still verify your identity directly.
15 Children
None of our products is directed at young children, and we do not knowingly collect personal data from a child below the age at which they can consent for themselves. That age differs by jurisdiction, so we apply the local threshold:
| Jurisdiction | Threshold | Basis |
|---|---|---|
| United States | 13 | COPPA. Verifiable parental consent below 13. |
| EEA | 16, or the lower age a member state sets (13 in Estonia) | GDPR art. 8; Estonian Personal Data Protection Act § 8. |
| United Kingdom | 13 | UK GDPR and the Data Protection Act 2018. |
| Türkiye | Capacity under the Turkish Civil Code | Law no. 6698 sets no separate age; a minor without capacity requires their legal representative to consent. |
| South Korea | 14 | PIPA. Consent of the legal guardian below 14. |
| China | 14 | PIPL. Data of a minor under 14 is sensitive personal information; guardian consent required. |
| India | 18 | DPDP Act 2023. Verifiable consent of a parent or lawful guardian. |
Where a store platform applies its own age gate, such as a Steam, Google Play or App Store account with a child flag or a family-linked account, we honour the signal it passes us and restrict processing accordingly.
We do not profile children, we do not target advertising at them, and we do not sell or share the personal data of anyone we know to be a minor.
If you are a parent or guardian and believe a child has given us personal data, write to [email protected]. We will investigate, delete what we should not be holding, and inform you of the outcome.
16 Automated Decisions and Profiling
We do not make decisions about you by automated means alone where the decision has a legal effect or is similarly significant. We do not use automated processing to set prices individually, and we do not score or rank players for any purpose outside a game's own mechanics.
Automation is used in two places, and in both a person stands behind the outcome. Anti-cheat and fraud detection flags patterns automatically, but a suspension or ban is reviewed by a person before it takes effect. Abuse filtering in community spaces may hide content automatically, and a person reviews it on appeal.
Where an automated decision does affect you, you may request the reasoning behind it, express your point of view, contest the outcome and obtain review by a person. Under article 11 of Law no. 6698 you may object to an adverse result produced by an analysis carried out exclusively through automated systems, and request that the resulting harm be remedied.
Gameplay telemetry is used in aggregate to tune difficulty for all players. It is not used to build a persistent behavioural profile of an individual player for purposes outside the game.
17 Commercial Messages
We send commercial email only to people who requested it. There is no pre-ticked box, and purchasing a game does not enrol you in anything. Every message carries a working unsubscribe link, and unsubscribing takes effect immediately and without our asking for a reason.
Recipients in Türkiye are covered by Law no. 6563 on the Regulation of Electronic Commerce and the Regulation on Commercial Communication and Commercial Electronic Messages. Permissions and opt-outs are registered in the Message Management System (IYS) as that regime requires, and you may check or withdraw your permission there as well as with us.
In the EEA and the UK, marketing email rests on your consent under article 13 of Directive 2002/58/EC, or on the narrow soft opt-in for our own similar products where you gave us your address in the course of a purchase. In the United States our messages comply with the CAN-SPAM Act, and we do not send marketing calls or texts without the consent the TCPA requires. Canadian recipients are covered by CASL. The requirements in Annex D apply where you are covered by them.
Objection to direct marketing is absolute and admits no balancing. After you unsubscribe we retain a suppression record of your address for the sole purpose of not contacting you again in error.
Service messages are distinct from marketing, and cannot be unsubscribed from while you hold an account or an order with us: a security notice, a change to these terms, a breach notification or a receipt. We keep them to their purpose and do not use the channel to advertise.
18 Links and Third-Party Services
This site links out to our GitHub organisation, our Steam curator page, teliqos.io, and our profiles on LinkedIn, X and Instagram. Following a link takes you to a service we do not operate. Those services determine for themselves what they collect, under their own policies, and we are not responsible for that processing. Our links carry no tracking parameters.
We embed no social-media widgets, no comment systems and no third-party video players on this site, so reading a page does not put you in contact with any of those companies.
Where you interact with us on a third-party platform, such as a reply on X, a message on LinkedIn or an issue on GitHub, that platform is an independent controller for your account, and we are a controller only for what we then do with the content of the exchange.
19 Changes to This Notice
This notice will change as the studio's products change and as the law does. The effective date stated in section 1 identifies the text you are reading.
For a change that materially affects you, such as a new purpose, a new category of recipient, a new transfer route or a narrowing of your rights, we give notice before it takes effect: on this page and, where we hold your contact details and the change warrants it, directly. Where a change requires your consent, we request it rather than assume it, and the processing does not begin until you agree.
Continuing to use a product after a minor, non-material change is not treated as consent to anything. Consent is requested expressly or not relied on.
Superseded texts are archived and may be requested at [email protected].
20 Account and Data Deletion
You can ask us to delete your account and the data attached to it at any time, and you do not have to install anything to do it. Write to [email protected] with "deletion" in the subject line, naming the platform identifier or the account you want removed. Where a game offers deletion from its own settings screen, that route reaches the same place. This section is the deletion path we publish to the app stores.
What Is Deleted
- The account or player identifier we hold, the display name attached to it, and your game state: progress, saves, settings and scores.
- Gameplay telemetry linked to that identifier, and the crash reports attributable to it.
- Support tickets and correspondence, unless one of them is evidence in a dispute that is still open.
- Any consent record whose only purpose was to permit processing that is now stopping.
What Is Retained, and Why
- Purchase, invoice and accounting records, for the statutory periods in section 11. These we cannot delete: the Turkish Commercial Code and the Estonian Accounting Act require them to be kept, and a tax authority may call for them.
- Enforcement records where an account was suspended or banned for cheating or fraud, for the period in section 11, so that the same behaviour cannot simply be re-registered.
- A minimal suppression record of your email address if you unsubscribed from commercial messages, held for the sole purpose of not contacting you again by mistake.
- Anything a law requires us to hold, or that is needed to establish, exercise or defend a legal claim. Where this applies we tell you which ground it is, and we restrict the data for as long as we hold it.
How Long It Takes
We confirm receipt and act within 30 days at the latest, and sooner where we can. Game accounts pass through the 30-day grace period in section 11 first, so that an accidental request can be reversed; ask us to skip it and we will. Data deleted from live systems may persist in an encrypted backup until that backup rotates out, which takes no longer than 90 days, and we do not restore a backup in order to recover data you asked us to delete.
Deleting Part of It
You do not have to close the account to remove something from it. You can ask us to delete telemetry and keep your progress, or to withdraw a consent without closing anything. Section 13 sets out the rights this rests on and section 14 the procedure.
If the data concerns a game made by a customer of ours rather than by us, the decision to delete is theirs and not ours. Send the request to us in any case: we forward it to them promptly and confirm to you that we have. See section 8 and Annex E.
21 Contact and Complaints
Questions, rights requests and complaints under this notice go to [email protected]. We prefer to hear from you first, because most matters are resolved faster directly, but nothing here requires you to approach us before an authority or a court.
The studio has not appointed a statutory data protection officer, because neither entity meets the criteria in article 37 of the GDPR that would make one mandatory. Responsibility for data protection sits with the studio's management, reachable at the address above, and the contact person for the Turkish register is recorded in VERBİS.
Supervisory Authorities
| Where you are | Authority |
|---|---|
| Türkiye | Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), Ankara. kvkk.gov.tr. See Annex A for the sequence and the deadlines. |
| Estonia | Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tallinn. aki.ee |
| Elsewhere in the EEA | The authority of your country of residence or workplace, or of the place the alleged infringement occurred, under GDPR art. 77. A list is published by the European Data Protection Board at edpb.europa.eu. |
| United Kingdom | Information Commissioner's Office. ico.org.uk |
| Switzerland | Federal Data Protection and Information Commissioner. edoeb.admin.ch |
| United States | Your state Attorney General, and the California Privacy Protection Agency for California residents. See Annex C. |
| Asia-Pacific | The authority named for your jurisdiction in Annex D. |
You may also bring proceedings before a court. Nothing in this notice limits a right you hold under mandatory law, and nothing in it waives a remedy.
Annex A: Türkiye (Law No. 6698)
This annex applies if you are in Türkiye or your data is processed by our Türkiye entity. It supplements the body of the notice and, for the people it covers, prevails over it where the two differ.
The controller is CEDRA Interactive's Türkiye entity, identified in section 2. The disclosure obligation under article 10 is met by this notice, in the manner prescribed by the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation. Where processing rests on explicit consent, that consent is obtained separately from this disclosure, as the Authority requires.
Your Rights Under Article 11
- Learn whether your personal data is being processed.
- Request information about it if it has been processed.
- Learn the purpose of the processing and whether the data is being used consistently with that purpose.
- Learn the third parties, in Türkiye or abroad, to whom it has been transferred.
- Request that incomplete or inaccurate data be corrected.
- Request that it be erased or destroyed, in the circumstances set out in article 7.
- Request that a correction, erasure or destruction be notified to the third parties to whom the data was transferred.
- Object to an adverse result reached about you through an analysis carried out exclusively by automated systems.
- Claim compensation for damage suffered as a result of unlawful processing.
Making an Application, and the Fee
Applications are made under article 13 and the Communiqué on the Procedures and Principles of Application to the Data Controller. You may apply in writing or by the other means the Communiqué recognises, including registered electronic mail, a secure electronic signature, a mobile signature, or the email address you have previously notified to us and which is registered in our systems. In practice, [email protected] is the address to use. Your application should state your name, your Turkish identity number if you are a citizen, your address or email for notification, and the subject of your request.
We answer within 30 days at the latest. The answer is free of charge for up to ten pages. Beyond ten pages a fee of 1 Turkish lira per page may be charged, and if the answer is provided on a recording medium such as a CD or flash drive, the cost of that medium may be charged. Where the cause of the request is a fault of ours, any fee charged is refunded.
Complaint to the Board
If your application is refused, if the answer you receive is inadequate, or if we do not answer in time, you may complain to the Personal Data Protection Board under article 14, within 30 days of learning our answer and in any event within 60 days of the date of your application. The right to bring proceedings before a court is unaffected.
Registration, Transfers and Breach
Our Türkiye entity's registration in the Data Controllers' Registry (VERBİS) is maintained under article 16 where the registration criteria apply to it. Transfers abroad follow article 9 as amended by Law no. 7499, described in section 10. A personal-data breach is notified to the Board within 72 hours of our becoming aware of it, under article 12(5) and Board decision no. 2019/271, and to affected data subjects within the shortest reasonable time.
Cookies that are not strictly necessary are used only with explicit consent under article 5(1), consistent with the Authority's Guidelines on Cookie Practices. Commercial electronic messages follow Law no. 6563 and the IYS regime described in section 17.
Annex B: EEA, United Kingdom and Switzerland
This annex applies if you are in the European Economic Area, the United Kingdom or Switzerland. The controller for you is CEDRA Interactive's Estonia entity, identified in section 2, jointly with the Türkiye entity on the terms described there.
Rights Under the GDPR
You hold the rights in articles 15 to 22: access, rectification, erasure, restriction of processing, data portability, objection, and the right not to be subject to a decision based solely on automated processing. You may withdraw consent at any time under article 7(3), and lodge a complaint with a supervisory authority under article 77. You are also entitled to an effective judicial remedy under article 79 and to compensation under article 82.
Where processing is based on legitimate interest, article 21(1) permits you to object, and we then cease processing unless we can demonstrate compelling grounds that override your interests. Where the processing is direct marketing, article 21(2) applies and there is nothing to demonstrate: we cease.
Joint Controllers and the Point of Contact
The essence of the article 26 arrangement is set out in section 2. Under article 26(3) you may exercise your rights against either entity, and [email protected] reaches both.
Transfers, Assessments and Records
Transfers out of the EEA follow Chapter V as described in section 10. We maintain records of processing under article 30, carry out data protection impact assessments under article 35 where required, and apply data protection by design and by default under article 25.
United Kingdom
If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply, and the Information Commissioner's Office is your supervisory authority. Because the studio has no UK establishment, a representative under article 27 of the UK GDPR is appointed where the conditions for that obligation are met. You may request the current representative's details, and any request sent to our main address is handled in either case.
Switzerland
If you are in Switzerland, the revised Federal Act on Data Protection, in force since 1 September 2023, applies alongside this notice, and the Federal Data Protection and Information Commissioner is your supervisory authority. Swiss law extends data protection to the data of legal entities as well as individuals, and we apply the same standards to both.
Estonia
Estonian law completes the GDPR where the Regulation permits a member state to do so. Most relevantly, section 8 of the Personal Data Protection Act sets the age at which a child can consent for themselves at 13, rather than the default of 16 in article 8(1). The Estonian Data Protection Inspectorate is the lead supervisory authority for the studio's EEA processing.
Annex C: United States
This annex applies if you are a resident of a US state with a comprehensive privacy statute. It serves as the notice at collection those statutes require, and it uses their vocabulary: "personal information" rather than "personal data".
Sale, Sharing and Sensitive Information
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes beyond those permitted without an option to limit. We have never sold or shared the personal information of anyone we knew to be under 16.
California: CCPA as Amended by the CPRA
The categories of personal information we collect, the purposes, the sources and the categories of recipient are those set out in sections 3, 4 and 9 of this notice, which together constitute our notice at collection under Civil Code § 1798.100. Retention periods are in section 11, and we do not keep personal information longer than stated there.
As a California resident you have the right to know what we collect and to receive a copy, to have inaccurate information corrected, to have information deleted, to opt out of sale or sharing, to limit the use and disclosure of sensitive personal information, and not to be discriminated or retaliated against for exercising any of these. Because we neither sell nor share, and do not use sensitive personal information beyond the permitted purposes, the opt-out and limitation rights have no subject matter to operate on; requests are nonetheless honoured as confirmations and we say so in our response.
We honour Global Privacy Control signals as opt-out preference signals. You may use an authorised agent, with proof of authorisation. Under California's "Shine the Light" law (Civil Code § 1798.83) you may also enquire about disclosures of personal information to third parties for their direct-marketing purposes; we make none. Complaints may be directed to the California Privacy Protection Agency or the Attorney General.
Other States
Comparable rights, to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling, apply under the statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota and Maryland, and under the other state laws that come into force from time to time. Where a state requires opt-in consent for sensitive personal information, we obtain it.
We answer within 45 days, extendable once by a further 45 days with notice to you. If we decline a request, you may appeal by replying to our decision. We will respond to the appeal within the period your state prescribes and, if we still decline, inform you how to complain to your Attorney General.
Children, Messages and Breach
COPPA applies to children under 13, and section 15 describes how we handle age. Commercial email complies with the CAN-SPAM Act; marketing calls and texts are sent only with the consent the TCPA requires. Where a state data-breach statute applies, we notify affected residents and the state authorities on that statute's timeline, alongside the obligations in section 12.
Annex D: Asia-Pacific
This annex applies if you are in one of the jurisdictions below. Each adds requirements of its own, and where they are stricter than the body of this notice, the stricter rule governs for you.
| Jurisdiction | Statute and authority | What it adds |
|---|---|---|
| Japan | Act on the Protection of Personal Information (APPI); Personal Information Protection Commission | You may request disclosure, correction, addition, deletion, and cessation of use or of third-party provision. We record the purpose of use, and we obtain your consent before providing your data to a third party abroad, with information about the recipient country's regime. |
| South Korea | Personal Information Protection Act (PIPA); Personal Information Protection Commission | Consent is sought separately for each purpose, and separately again for transfer abroad and for optional items. You may demand access, correction, deletion and suspension of processing. Guardian consent is required below 14. Sensitive information and unique identifiers require distinct consent. |
| Singapore | Personal Data Protection Act (PDPA); Personal Data Protection Commission | You may request access and correction, and withdraw consent at any time. Marketing to Singapore numbers respects the Do Not Call Registry. Notifiable data breaches are reported to the Commission and to affected individuals within the statutory timelines. |
| India | Digital Personal Data Protection Act, 2023; Data Protection Board of India | We act as Data Fiduciary and give an itemised consent notice, available in English and the scheduled languages on request. You may access, correct, complete, update and erase your data, nominate another person to exercise your rights, and use our grievance mechanism before approaching the Board. Verifiable parental consent applies below 18, and we do not track or target advertising at children. |
| China | Personal Information Protection Law (PIPL); Cyberspace Administration of China | Separate consent is obtained for sensitive personal information, for provision to third parties and for transfer outside China. Outbound transfer additionally requires a CAC security assessment, the CAC standard contract, or certification, as applicable. Data of a minor under 14 is sensitive personal information and requires guardian consent. You may access, copy, correct, delete and port your data, withdraw consent, and request an explanation of our processing rules. |
| Australia | Privacy Act 1988 and the Australian Privacy Principles; Office of the Australian Information Commissioner | You may seek access and correction, and complain to us and then to the Commissioner. We take reasonable steps to ensure an overseas recipient handles your data consistently with the APPs, and eligible data breaches are notified under the NDB scheme. |
Where one of these regimes requires a local representative, agent or grievance officer and the conditions for that requirement are met, we appoint one, and their contact details are available at [email protected].
If you are in a jurisdiction not named here, the body of this notice applies to you in full, as does any mandatory local law. Write to us if you wish to know which rules we are applying to your data.
Annex E: When We Act as Processor
This annex sets out our commitments where a customer organisation is the controller and we process personal data on its behalf, in practice the event data its integration of one of our products sends about that customer's own end users. Which products can put us in that position is stated in their schedules. It reflects article 28(3) of the GDPR, article 12 of Law no. 6698, and the equivalent obligations in the other regimes in this notice. The signed data-processing agreement governs; this annex is its published summary.
- We process only on the controller's documented instructions, including as to transfers, and not for our own purposes. If an instruction appears to breach applicable law, we say so before acting.
- Everyone we authorise to process the data is bound by confidentiality surviving the end of their engagement, and access is limited to those who require it for the service.
- We apply the security measures in section 12, and we agree them with the controller as appropriate to the risk of their particular processing.
- We engage a sub-processor only with the controller's authorisation, we keep the list of sub-processors current and available, we give advance notice of an intended change so that an objection can be raised, and we impose the same data-protection obligations on any sub-processor we engage. We remain answerable for their performance.
- We assist the controller in responding to data-subject requests. We do not answer such a request ourselves. Where an end user contacts us directly, we forward the request to the controller promptly and inform the person that we have done so.
- We notify the controller of a personal-data breach affecting their data without undue delay, with the information they require in order to make their own notifications, and we leave notification of authorities and individuals to them.
- We assist with data protection impact assessments, prior consultations and demonstrating compliance, and we make the necessary information available.
- We permit audits and inspections by the controller or an auditor they mandate, on reasonable notice and without disrupting the service, and we co-operate with the supervisory authorities having jurisdiction over the controller.
- On termination we delete or return the data at the controller's election, and delete existing copies unless a law requires their retention, in which case we identify the law and keep the data restricted for as long as we hold it.
- We transfer the data across borders only on the controller's instruction and with a valid mechanism from section 10 in place.
The event data a customer sends us is not available for our own use. It does not train our models, it does not inform our own games, and it is not pooled across customers. This follows from the processor role itself: departing from it would make us a controller of that data and place us in breach.
Our own use of one of our platforms on our own games is a separate matter. There we are the controller, and sections 4, 7 and 11 apply to it in the ordinary way.