Back to the start page

Privacy policy

As of: October 2026 · Version 2026-10-11

Convenience translation. The German version is authoritative.

1. Privacy at a glance

General information

The following notes give a simple overview of what happens to your personal data when you use Zephnex, i.e. this online game with its websites, the web app and the apps for desktop and mobile devices. Personal data is any data that can be used to identify you personally. For detailed information on data protection, please see the privacy policy below.

Data collection in Zephnex

Who is responsible for data collection?

Data is processed by the operator. The operator's contact details can be found in the section "Note on the controller" in this privacy policy.

How do we collect your data?

On the one hand, your data is collected when you give it to us, for example when registering, in chat or in the game's feedback form. Other data arises while playing (for example your character's position, progress and inventory) or is collected automatically by our IT systems when you access our servers. This is mainly technical data such as the IP address, the browser or device type and the time of access.

What do we use your data for?

We use your data to provide and operate the game (account, game state, chat, trading, clans), to process purchases, to operate the service securely and without errors and detect abuse, and to answer your enquiries.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request that this data be corrected or deleted. If you have given consent to data processing, you can withdraw it at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. You also have the right to lodge a complaint with the competent supervisory authority. You can delete your game account yourself at any time (see section 6).

You can contact us at any time about this and other questions on data protection.

Analytics tools and advertising

The pages the game server delivers itself (for example this page) do not load scripts, fonts or other content from third parties and contain no web analytics, tracking or advertising services. The one exception is Stripe's payment page, to which you are redirected for purchases and voluntary payments (see section 5).

In the game app (web app, desktop app and mobile apps), which is built with the Unity game engine, we use two Unity services: at every start the app contacts Unity's crash reporting service, and – only with your consent – a usage analytics service (Unity Analytics) measures usage and the app sends error reports to Unity. Details are in section 5 under "Game app (Unity)".

On our website zephnex.com (the landing page) we measure usage with two web analytics services: Plausible Analytics (self-hosted, without cookies) and – only with your consent – Google Analytics 4. Details are in section 5 under "Web analytics on zephnex.com". We use no advertising services and do not pass on data to third parties for advertising purposes.

2. Hosting

We host Zephnex with the following provider:

External hosting

The game is hosted externally. The personal data collected during operation is stored on the hoster's servers. This may include in particular IP addresses, meta and communication data, contract data, contact data, names, game data and other data generated in the course of the game. The servers are located in Germany.

External hosting serves the performance of the contract with our potential and existing users (Art. 6(1)(b) GDPR) and the secure, fast and efficient provision of our online service by a professional provider (Art. 6(1)(f) GDPR).

Our hoster processes your data only to the extent necessary to perform its obligations and follows our instructions regarding this data. A data processing agreement is in place with it.

We use the following hoster:

netcup GmbH
Emmy-Noether-Straße 10
D-76131 Karlsruhe, Germany

3. General information and mandatory notices

Data protection

The operator takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection provisions and this privacy policy.

When you use Zephnex, various personal data is collected. This privacy policy explains which data we collect and what we use it for. It also explains how and for what purpose this happens.

Please note that data transmission over the internet (e.g. communication by email) can have security gaps. Complete protection of data against access by third parties is not possible.

Note on the controller

The controller responsible for data processing is:

Felix Schattenberg
Striesener Straße 4
01307 Dresden, Germany

Phone: +49 351 41717958
Email: privacy@zephnex.com (for data protection requests also reachable at datenschutz@zephnex.com)

The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g. names, email addresses).

Storage period

Unless a more specific storage period is stated in this privacy policy, your personal data remains with us until the purpose for processing no longer applies. If you assert a justified request for deletion or withdraw consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing it (e.g. tax or commercial law retention periods); in the latter case deletion takes place once these reasons cease to apply. An overview of the specific periods is in section 6.

General information on the legal bases of processing

Where you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR. Where your data is required to perform a contract (providing the game and your game account, processing purchases) or to carry out pre-contractual measures, we process it on the basis of Art. 6(1)(b) GDPR. We also process your data where required to comply with a legal obligation (e.g. commercial and tax retention duties) on the basis of Art. 6(1)(c) GDPR. Processing may also be based on our legitimate interest under Art. 6(1)(f) GDPR, for example for operational security, error analysis and detecting abuse. Where information is stored on or retrieved from your device, § 25 of the German TDDDG applies. The legal bases that apply in each case are explained in the following sections.

Recipients of personal data

In the course of our activities we work with external parties (hoster, email service, payment providers, app stores, Unity for crash reports and – only with your consent – for the game app's usage analytics, and – on zephnex.com only with your consent – Google; see sections 2 and 5). We pass personal data on to external parties only if this is necessary to perform a contract, if we are legally obliged to do so (e.g. passing data to tax authorities), if we have a legitimate interest under Art. 6(1)(f) GDPR in doing so, or if another legal basis permits it. When using processors, we pass on personal data only on the basis of a valid data processing agreement.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the processing carried out until the withdrawal remains unaffected. You withdraw your consent in the game app (usage analytics and crash reports) in the game under Options › General › Privacy, and your consent on zephnex.com as described in section 5.

Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)

IF DATA IS PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS IS SET OUT IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES TO ESTABLISH, EXERCISE OR DEFEND LEGAL CLAIMS (OBJECTION UNDER ART. 21(1) GDPR).

We do not carry out direct marketing. Should your personal data nevertheless be processed for direct marketing, you have the right to object at any time to the processing of personal data concerning you for such marketing (objection under Art. 21(2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

The supervisory authority responsible for us is the Sächsische Datenschutz- und Transparenzbeauftragte (Saxon Data Protection and Transparency Commissioner), Maternistraße 17, 01067 Dresden, Germany (https://www.datenschutz.sachsen.de).

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Access, correction and deletion

Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, where applicable, a right to correction or deletion of this data. You can contact us at any time about this and other questions on personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this. The right to restriction of processing exists in the following cases:

If you have restricted the processing of your personal data, this data may – apart from being stored – only be processed with your consent or to establish, exercise or defend legal claims or to protect the rights of another natural or legal person or for reasons of important public interest of the European Union or a Member State.

No automated decision-making

No decision based solely on automated processing that produces legal effects concerning you or significantly affects you (Art. 22 GDPR) takes place. Abuse detection (section 4) only flags anomalies; a human always decides on measures such as a suspension.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, such as your password or your orders, this service uses SSL/TLS encryption. You can recognise an encrypted connection by the browser's address bar changing from "http://" to "https://" and by the lock icon in your browser. When encryption is active, the data you transmit to us cannot be read by third parties.

Objection to advertising emails

We hereby object to the use of contact data published in the legal notice for sending unsolicited advertising and information material. The operator expressly reserves the right to take legal action in the event of unsolicited advertising, for example spam emails.

4. Data collection in Zephnex

Cookies and local storage

Zephnex uses exactly one cookie: the session cookie zephnex_session. It is set after sign-in and contains a random identifier (no username, no data about you). Only a hash of it is stored on our server. The cookie is marked "HttpOnly" (not readable by scripts) and "SameSite=Lax" and is transmitted with the "Secure" attribute over encrypted connections. It is technically necessary to keep you signed in, expires 30 days after your last activity and is deleted when you sign out. The legal basis is § 25(2) no. 2 TDDDG (strictly necessary for the service you expressly requested) and Art. 6(1)(b) GDPR. No consent is required for this. We do not set advertising or tracking cookies. This applies to the game; for the website zephnex.com the following paragraph and section 5 ("Web analytics on zephnex.com") apply in addition.

The web app and the apps may also store settings (for example the language) and caches of game data locally on your device. This data contains no tracking identifiers, is not transmitted to third parties and is necessary for the app to work (§ 25(2) no. 2 TDDDG).

For the Unity services (section 5, "Game app (Unity)") the app additionally stores random identifiers on your device: the installation identifier of the crash reporting service and – only with your consent – the user identifier of the usage analytics. Neither contains any information about you as a person. In the web app they are kept in your browser's storage (local storage or IndexedDB), in the apps in the app's storage. You can delete all of this at any time via your browser or device settings (clear site data or app data, or uninstall the app); after you withdraw consent the analytics user identifier is no longer used.

Server log files and IP addresses

Access data is generated for technical reasons when our servers are accessed. This includes in particular:

This data is recorded in the logs of our web server or reverse proxy and of our application. It serves secure and error-free operation, defence against attacks and abuse, and technical diagnosis. This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the technically error-free and secure provision of the game. The logs are deleted after 14 days. The reverse proxy keeps no access log of its own for the game; requests are recorded only in the application logs.

In addition, at every sign-in we store the IP address and the user agent of your device together with your session. This serves to secure your account and to investigate abuse; the data is not used for access decisions. The session, and with it this data, is deleted as soon as the session expires or you sign out (at the latest 30 days after your last activity). We also use IP addresses briefly in working memory to limit the frequency of sign-ins, registrations and other requests (protection against abuse and overload); they are not stored permanently there.

Registration and game account

For a game account we need a username and a password. We do not store your password in plain text but only as a hash created with the Argon2id method. Providing an email address is voluntary; it is required if you want to reset your password by email or make purchases (we require a confirmed email address for purchases). We also store the time of registration and of your last sign-in as well as any suspension status. For your character we store the display name, your language setting, interface settings, the device class last used (e.g. phone or desktop) and your faction choice. The legal basis is Art. 6(1)(b) GDPR.

Registration is currently only possible with an invitation code. An invitation code is generated by us, can be used once or (for multi-use codes) several times and may include a note by its creator and an identifier of the creator (when generated via our Discord server, the Discord user ID of the authorised person who generated the code). On registration the redemption of the code (code, account, time) is linked to your account (Art. 6(1)(b) and (f) GDPR: controlling access during the alpha phase); once your account is deleted this link no longer exists.

Game data

While you play, we process your character's data to maintain the game state and provide the game: position, ships, modules, inventory, cargo, balances (game money and premium currency), progress (experience, level, quests, achievements, talents), structures and settings. We also log game events (for example sign-in and sign-out, kills, purchases, operator interventions in your account) so that we can trace the course of the game, analyse errors and resolve disputes. The legal basis is Art. 6(1)(b) GDPR, for logging additionally Art. 6(1)(f) GDPR.

Zephnex is a multiplayer game: other players see your display name, your ship, your position in the sector, if applicable your clan including its crest, and your ranking in leaderboards. Please choose a display name that does not allow conclusions about your identity.

Chat, friends, clans and trading

Messages you write in chat (sector, faction, clan or direct messages) are stored with sender, recipient (for direct messages), channel, time and text, so that other players can see them, the history can be shown on connecting and reports can be reviewed. Chat messages are deleted automatically after 14 days. If you or another player report a message, a copy of the message is stored for review by the operator. A word filter may reject messages. No automatic suspension takes place.

We also store your friendships, friend requests and blocked players, your clan membership and your contribution to competition scores, as well as a log of completed trades (players involved, items traded, time) to resolve disputes. The trade log is deleted as soon as one of the accounts involved is deleted. The legal basis is Art. 6(1)(b) GDPR, for logs and reports additionally Art. 6(1)(f) GDPR (protecting the player community, resolving disputes).

Abuse detection

To detect fraud and unauthorised automation (bots), we evaluate technical characteristics of gameplay, for example the rhythm of inputs, rejected actions, and repetition and frequency of chat messages. This evaluation runs in the server's working memory, is not stored permanently and only flags anomalies for review by the operator. The legal basis is Art. 6(1)(f) GDPR (fair play for all players, protection of the service).

Local storage on zephnex.com

On the website zephnex.com we place two entries in your browser's local storage (localStorage), each without an identifier and without transmission to us or to third parties: zx-lang stores the language you chose (without an expiry date, until you delete it); zx-consent stores your answer to the question about web analytics (granted or denied) and the time of the answer. The answer is valid for 12 months, after which we ask again; you can change it at any time via the "Cookie settings" link in the page footer. zx-lang is needed for the display you asked for; zx-consent serves to implement and prove your decision (§ 25(2) no. 2 TDDDG; Art. 6(1)(c) in conjunction with Art. 7(1) GDPR). The cookies of Google Analytics (only after consent) are described in section 5.

Requesting an invitation code

On zephnex.com you can request an invitation code. For this we store what you enter in the form: your email address (mandatory) and, if you wish, your name, the platform you want and a message, plus the language you chose, the time of the request and, later, our decision together with the invitation code created. Your IP address is not stored for this; it is used only briefly in working memory to limit how often requests can be made. The purpose is to handle your request and to send you the code. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give expressly in the form before submitting and can withdraw at any time with effect for the future (informally to privacy@zephnex.com; we then delete the request). A person reviews your request; no automated decision is made. If it is accepted we send you the code by email (via Zoho Mail, see section 5); we send a refusal only if we decide to. You do not receive an acknowledgement of receipt by email. If the email address already belongs to an account, we note this on the request. Storage period: for a decided request the email address, name and message are deleted 30 days after our decision; what remains is a record without personal reference (platform, language, outcome, times). An unanswered request is deleted after 90 days. At your request we delete it immediately.

Error reports and feedback

If a technical error occurs in the app, the app may send an error report to our server: error message, technical trace (stack trace), build identifier and, if you are signed in, the link to your character. The IP address is not written into the report. Error reports are deleted after 90 days. The legal basis is Art. 6(1)(f) GDPR (error correction and stability of the service). These reports stay on our server. Independently of that, the game app uses Unity's crash reporting service (section 5, "Game app (Unity)").

If you send feedback in the game, we store your text together with your character, the build identifier, your position in the game and your balance. The feedback is deleted when you delete your account. The legal basis is Art. 6(1)(f) GDPR (further development of the game) and, where you provide data voluntarily, Art. 6(1)(a) GDPR.

Enquiries by email or telephone

If you contact us by email or telephone, your enquiry including all resulting personal data (name, enquiry) is stored and processed by us for the purpose of handling your request. We do not pass this data on without your consent.

This data is processed on the basis of Art. 6(1)(b) GDPR if your enquiry is related to the performance of a contract or necessary for pre-contractual measures. In all other cases processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6(1)(f) GDPR) or on your consent (Art. 6(1)(a) GDPR) if it was requested.

The data you send us remains with us until you ask us to delete it, withdraw your consent to storage or the purpose for storage no longer applies (e.g. after your request has been dealt with). Mandatory statutory provisions – in particular retention periods – remain unaffected.

Demo access

With a demo link you can try Zephnex without registering. For this we automatically create a throw-away account with a random name and a password that is never issued; you provide no information. In demo access, among other things, chat, clans, friend requests, trading and purchases are not possible. The rules on server logs and sessions above apply. The demo account including its character is deleted automatically, at the latest 60 minutes after creation, after you sign out, or if the connection has been absent for more than five minutes. If you start the demo with a demo code, the duration agreed with the code applies instead of the 60 minutes, but at most 4 hours. The legal basis is Art. 6(1)(b) and (f) GDPR.

5. Service providers and third parties

Email delivery (Zoho Mail)

If you provide an email address, we use it to send messages related to your account: confirmation of the email address, password reset, a notice to your previous address when the email address of your account is changed, the confirmation of your consent when you make a purchase (see below) and – if you request it – a deletion link for your account. We do not send advertising or newsletter emails. These system messages are sent from noreply@zephnex.com; that mailbox is not read, please send replies to support@zephnex.com. For delivery we use the service Zoho Mail (Zoho Corporation B.V., Netherlands). Your email address and the content of the message (including the one-time link) are transmitted to Zoho and processed in data centres in the European Union. Zoho acts as a processor on our behalf; a data processing agreement is in place with Zoho. The legal basis for processing is Art. 6(1)(b) GDPR. More information: https://www.zoho.com/privacy.html.

Payments via Stripe

If you buy premium currency on the web, in the desktop app or in an Android or iOS app distributed directly by us (outside Google Play and the App Store), or voluntarily support the development, payment is processed by the payment provider Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland; for certain processing also Stripe, Inc., USA). We ourselves are the seller (Felix Schattenberg, see legal notice). You are redirected to Stripe's payment page (checkout.stripe.com); Stripe thereby receives your IP address. Stripe processes payment data (for example name, email address, payment method, depending on the payment method an address) for payment processing, fraud prevention and compliance with its own legal obligations under its own data protection responsibility; for issuing the receipt and invoice in our name Stripe acts on our behalf. We neither see nor store payment method or card data.

To Stripe we pass on for a purchase: amount and currency, the name of the package, internal identifiers (character number, purchase number) and the confirmed email address stored with us for pre-filling; for a voluntary payment without logging in we pass on only amount and currency. From Stripe we receive: session and payment ID, payment status, amount, currency, the email address used for payment, for a purchase the indication that you agreed to immediate delivery (with the time), and notices of refunds or payment disputes. We use the email address for our purchase confirmation. The legal basis is Art. 6(1)(b) GDPR (performance of the contract), for retention Art. 6(1)(c) GDPR. Where data is transferred to the USA, this is based on the EU-US Data Privacy Framework or standard contractual clauses. More information: https://stripe.com/privacy.

Voluntary support

For every voluntary payment we store amount, currency, time, the Stripe identifiers, a chosen preset and – only if you were logged in – your character number, so that we can thank you. Without logging in we store no information about you as a person. Retention follows commercial and tax obligations (Art. 6(1)(b), (c) GDPR; § 147 AO, § 257 HGB). If your account is deleted, the link to the character is severed.

Purchases via App Store and Google Play

If you buy in the iOS or Android app, Apple (Apple Distribution International Ltd., Ireland) or Google (Google Ireland Limited, Ireland) processes the payment and your payment data under its own responsibility. The app passes the receipt of your purchase to our server; the server verifies it and only then credits the premium currency. We store only transaction details (transaction or order number, package, amount, status). The legal basis is Art. 6(1)(b) GDPR.

Google Play. When you buy in the Android app from the Play Store, the app passes Google's purchase receipt (the purchase token) and the identifier of the product bought to our server. Our server uses them to ask Google through the Google Play Developer API whether the purchase is valid. Google tells us the order number, the purchase status, the product identifier and the quantity bought; we then acknowledge the purchase to Google (Google automatically refunds an unacknowledged purchase after a few days). We use the purchase token only for this check and acknowledgement and do not store it. What is stored in the purchase ledger (see below) is the order number, the package, the amount credited, the price, the time, the status and the link to your character. We do not learn your Google account or your payment details. The legal basis is Art. 6(1)(b) GDPR, and for retention Art. 6(1)(c) GDPR.

App Store. When you buy in the iOS app, the app passes the transaction signed by Apple; our server verifies the signature and stores the same transaction details. More information for both stores: https://www.apple.com/legal/privacy/ and https://policies.google.com/privacy.

Game app (Unity)

The game app (web app, desktop app, Android and iOS) is built with the Unity game engine. We use two Unity services in it: usage analytics (Unity Analytics) and the crash reporting service (Unity Cloud Diagnostics). Unity Technologies (USA) acts as our processor; Unity's Data Processing Addendum, which is part of Unity's terms of service, applies (Art. 28 GDPR). Where personal data is transferred to the USA or other third countries, the transfer relies on the European Commission's Standard Contractual Clauses that Unity's agreement provides for (Art. 46(2)(c) GDPR). We do not pass account, character or email details on to Unity. More information: https://unity.com/legal/gdpr.

Usage analytics (Unity Analytics) – only with your consent

At the first start the app asks in a privacy dialog whether you consent to usage analytics. The switch is off by default, "Decline" and "Save selection" are equally prominent, and the game is fully usable without consent. As long as you have not consented, the app makes no connection to Unity's analytics service (collect.analytics.unity3d.com). You can change your choice at any time under Options › General › Privacy.

With your consent the app sends standard events (start of the analytics service, game start, running session, game end, first start of this installation, device details) with the following information: a user identifier randomly generated on your device, a session identifier, a device identifier ("idfv": on iOS the Identifier for Vendor, on Android a hash of the ANDROID_ID), device model, processor type and cores, graphics processor, screen size, operating system and platform, app version, bundle identifier, build identifier, language, country (which Unity derives from the IP address) and the device volume. The IP address also reaches Unity as a technical matter. We do not link this data to your account or your character, and we receive no data from Unity with which we could identify you as a person. We use it to understand on which devices and platforms Zephnex is played, how stable and fast it runs there and how many people use it.

The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time with effect for the future: under Options › General › Privacy. The app then sends no more analytics events; the lawfulness of the processing carried out until then remains unaffected.

According to Unity, raw events are stored for 13 months and then deleted automatically; metrics calculated from them (for example user counts and session length) remain until their deletion is requested. According to Unity, the data is stored mainly in the European Union (Belgium, Netherlands); a replicated copy is kept in the USA. If you would like us to have the data deleted earlier, write to privacy@zephnex.com; because the data is linked only to the random user identifier of your device and not to your account, we can find it only with that identifier.

Crash reports (Unity Cloud Diagnostics)

Contact at every start. At every start of the app – on all platforms, including the web app – the app contacts Unity's crash reporting service (cdp.cloud.unity3d.com), regardless of what you chose in the privacy dialog. Unity receives your IP address and technical session and device data determined by the Unity engine, including a random installation identifier. We cannot see the exact content of this data. The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in a stable game and in fixing errors. You can object to this processing under Art. 21 GDPR (privacy@zephnex.com); we will then examine your case individually.

Sending error reports – only with your consent. Whether the app also records errors and sends them to Unity (perf-events.cloud.unity3d.com) is up to you, with the "Crash reports" switch under Options › General › Privacy; it is off by default. If it is on, the app sends on an error or crash: the exception text, the technical trace (stack trace), the last log lines, the device model, the operating system, the app version, the installation identifier and the channel and version of the build. We use this to find and fix errors. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you can withdraw it at any time with effect for the future by turning the switch off. The lawfulness of the processing carried out until then remains unaffected.

According to Unity, data of this service is stored for 7 or 90 days by default, depending on the plan, so at most 90 days. We handle access and deletion requests via privacy@zephnex.com. As with usage analytics, the installation identifier is needed for this, because the reports are not linked to your account.

Purchase ledger

For every purchase we keep an entry in a purchase ledger (package, amount, price, transaction ID, times, provider, status, for purchases via Stripe the consent to immediate delivery with its time and a note of when we sent you the confirmation email about it, link to your character). In addition we keep a premium account log that records every movement of your premium currency (amount, balance afterwards, reason such as purchase, spending, exchange or refund, time, reference to the purchase); it makes refunds and chargebacks traceable. This serves processing, proof towards payment providers and stores, and compliance with commercial and tax retention duties (Art. 6(1)(b), (c) GDPR; § 147 AO, § 257 HGB). The entries of the purchase ledger and of the premium account log remain after your account is deleted, but are separated from your character and are then no longer linked to any person.

Web analytics on zephnex.com

On the website zephnex.com (not in the game itself) we measure usage with two services.

Plausible Analytics. We run Plausible Analytics ourselves on an operator-owned server in Germany; no third-party service is involved. The measuring script and the measurement data pass through zephnex.com itself and are forwarded there to our own Plausible instance. Plausible sets no cookies and stores nothing on your device. No personal profiles are created: a daily-changing hash is formed from the IP address and the browser identifier, which allows the visitors of one day to be counted; the IP address itself is not stored, and you are not recognised across days. What is evaluated is the page viewed, the referring page and rough information on country, browser, operating system and device type. The legal basis is Art. 6(1)(f) GDPR (our interest in data-minimising audience measurement). As nothing is stored on or read from your device, no consent under § 25 TDDDG is needed for this. You can object to the processing under Art. 21 GDPR.

Google Analytics 4 (only with your consent). As long as you have not consented, nothing is loaded from Google and no cookie is set. If you consent in the notice on zephnex.com, your browser loads the measuring script from www.googletagmanager.com and Google Analytics 4 (measurement ID G-SKV93LZ5G1) sets the cookies _ga and _ga_SKV93LZ5G1 (lifetime 13 months, "SameSite=Lax" and "Secure"). They contain a pseudonymous identifier that Google uses to group page views of your browser into visits. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google acts as our processor, its parent company is Google LLC, USA. We use Consent Mode v2: by default everything is denied; with your consent only analytics storage (analytics_storage) is allowed, while ad_storage, ad_user_data and ad_personalization stay denied. Google Signals and ad personalisation are switched off; the data is not used for advertising. The IP address is shortened (IP anonymisation). Data may be transferred to the USA in the process; the European Commission has adopted an adequacy decision for Google under the EU-U.S. Data Privacy Framework (Art. 45 GDPR). The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time with effect for the future: via the "Cookie settings" link in the footer of zephnex.com. On withdrawal analytics storage is denied, measurement is switched off and the _ga cookies are deleted. The lawfulness of the processing carried out until then remains unaffected. More: https://policies.google.com/privacy.

Discord

Authorised persons can have invitation codes generated via the command /invite on our Discord server. The Discord user ID of the generating person is stored with the invitation code as the creator identifier (Art. 6(1)(f) GDPR: traceability of how access is granted). Player data is not transmitted to Discord. Using Discord itself is governed by the privacy policy of Discord Inc.: https://discord.com/privacy.

Links to other sites

If you follow a link to an external site (for example to the privacy policies named above), the terms of the respective operator apply there.

6. Deleting your account and storage periods

How to delete your account

You can delete your game account yourself at any time, permanently:

Alternatively you can request deletion by email to privacy@zephnex.com. Founders of a clan with other members must first hand over leadership or disband the clan.

What is deleted and what remains

On deletion your account, your character and everything attached to it are deleted: game state, ships, modules, balances, friendships, chat messages, clan membership, structures, feedback, trade log, sessions and game events. An existing connection is ended. Only data that is no longer linked to any person, or that we must keep because of legal obligations, remains:

Overview of storage periods

DataStorage period
Account, character, game datauntil the account is deleted
Session (cookie hash, IP address, user agent)until the session expires or you sign out, at the latest 30 days after the last activity
Password reset, confirmation and deletion links (as hash)reset link valid 30 minutes, confirmation and deletion link 24 hours; links are stored only as a hash and deleted with the account at the latest
Server logs (IP address, time, URL)14 days
Chat messages14 days
Game events "sign-in/sign-out"90 days
Other game events (e.g. purchases, operator interventions)until the account is deleted
Error reports90 days
Crash reports at Unity (contact at start; error reports only with consent)according to Unity 7 or 90 days depending on the plan, at most 90 days
Usage analytics at Unity (only with consent)raw events 13 months according to Unity; metrics until deleted
Identifiers of the Unity services on your device (installation identifier; user identifier only with consent)until you delete the app data or uninstall the app
Feedbackuntil the account is deleted
Trade loguntil one of the accounts involved is deleted
Invitation code (link to the account)until the account is deleted
Invitation request (email address, name, message)30 days after our decision; deleted after 90 days if unanswered; only a record without personal reference remains
Entries zx-consent and zx-lang (only in your browser, on zephnex.com)zx-consent 12 months; zx-lang until you delete it
Google Analytics cookies _ga, _ga_SKV93LZ5G1 (only with consent, on zephnex.com)13 months or until you withdraw consent
Plausible measurement data (zephnex.com; no cookie, no IP address)without personal reference, no recognition across days
Purchase ledger, premium account log, support paymentsstatutory retention periods; without personal link once the account is deleted
Log of operator interventions180 days
Backupsat most 30 days
Demo accountat most 60 minutes, or 10 minutes after the connection ends
Demo account with a demo codethe duration agreed with the code, at most 4 hours, or 10 minutes after the connection ends
Emails and telephone enquiries to usuntil the purpose no longer applies; retention periods remain unaffected

7. Age

Zephnex is aimed at persons aged 18 and over. We do not knowingly collect personal data from minors. If you become aware that a minor has sent us data, please send a message to privacy@zephnex.com; we will then delete the account immediately.

Source of the general notes: https://www.e-recht24.de