Privacy policy

Sample, details to follow This page is a sample. Some details about the provider are still missing and are marked [[…]]. It is not complete yet.

This page states which personal data World of Vikings processes, why, on what legal basis and for how long. It describes what the site and the game server actually do.

As of: 23 September 2026

The German version is authoritative. The English version is a translation.

Controller

The controller within the meaning of the GDPR is the provider named in the legal notice:

[[NAME]] [[STRASSE HAUSNUMMER]] [[PLZ ORT]] [[E-MAIL]]

The short version

  • We do not set cookies.
  • There is no analytics, no advertising and no ad network.
  • Fonts, images and scripts come from our own server. No third-party services are loaded when you open the site.
  • We do not pass data on to third parties, except to the hosting provider that runs the server.

Visiting the website and server logs

When you open a page, the server processes technically necessary data: your IP address, date and time, the address requested, the response status, the amount of data transferred and your browser identification. They appear in the web servers’ logs.

The purpose is safe and stable operation, detecting attacks and troubleshooting. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).

Retention: the reverse proxy in front, which sees your IP address, rotates its access logs weekly and keeps four rotations (about five weeks). Its error logs, which can also contain IP addresses, are rotated weekly with ten rotations kept (about eleven weeks). The web server behind it only sees the proxy’s internal address and deletes its logs after 14 days.

Account

When you create an account we store your username, your email address, your password and the time of creation. If you pick an avatar in your account, we also store which of your heroes represents you in the Thing.

We never store the password in plain text, only as a salted hash (scrypt). The email address is stored but not verified; we currently send no emails to it. It is the contact detail for your account.

The purpose is providing the account and the game. The legal basis is Art. 6(1)(b) GDPR (contract for use). The data is kept until the account is deleted (see “Your rights”).

Obligation to provide data

An account exists only with a username, email address and password; without them we cannot create it and you cannot play. They are necessary for the terms of use, not required by law. You can read the website without an account.

Heroes (characters) and game state

For each hero we store the name, appearance, class, equipment, the time of creation and of the last play, and your character’s game state in the server’s world file. A hero’s name is visible to other players.

The purpose is the game itself; the legal basis is Art. 6(1)(b) GDPR. You can delete heroes in your account at any time. Otherwise they are kept as long as the account.

Signing in and abuse protection

After you sign in, your browser receives a signed sign-in token that is valid for 30 days. It lives in your browser’s storage, not in a cookie (see “Browser storage”).

To stop password guessing and mass account creation, the server counts failed sign-ins and registrations per IP address: after five failed attempts in 15 minutes sign-in pauses, after five registrations in an hour registration pauses. These counters exist only in memory, are never written to disk and disappear at the latest when the window ends or on restart. The legal basis is Art. 6(1)(f) GDPR.

Game connection, chat and bans

The game connects to the game server over a WebSocket. Your IP address is technically necessary for that. The game server’s operating log records, among other things, the connection with the IP address, the sign-in with the hero name and chat messages with the sender’s name. This log is rotated by size; there is currently no fixed deletion period.

For rule violations we may ban an account, a player identifier or an IP address. A banned IP address is stored, together with the reason and time, until the ban expires or is lifted. The legal basis is Art. 6(1)(f) GDPR (protecting the player community).

The Thing (forum)

What you write in the Thing is publicly visible: title, text, your hero or account name as author and the time. We also store reactions, thread subscriptions and notifications, each with your account identifier, and reports by other users (reporter and reason).

A post you delete is no longer shown. For traceability its content is initially kept internally. The legal basis is Art. 6(1)(b) GDPR (using the forum) and (f) (moderation).

Browser storage (no cookies)

The site and the game keep data in your browser’s local storage. It stays on your device and is not sent to us with every request. Required for the service you asked for to work are:

  • sign-in token and account name (valid 30 days) and the chosen shore
  • the ticket for entering the game
  • short technical notes of the game, such as a destination you asked for in the game or the switching off of a graphics feature that makes your device too slow

These are strictly necessary under § 25(2) no. 2 TDDDG for us to provide the service you asked for (signing in, playing); no consent is needed for this (Art. 6(1)(b) GDPR).

Only after an action of your own does your browser also store:

  • the draft of the character creation (figure, appearance, class, hero name)
  • your language choice in the game, graphics settings and the contrast switch

These entries only serve to find your own choice again at the next visit; they do not leave your device. We likewise treat them as expressly requested by the user (§ 25(2) no. 2 TDDDG, Art. 6(1)(f) GDPR) and therefore use no cookie banner. You can delete the data in your browser settings at any time; you will then have to sign in again.

Backups

The server makes regular backups: of the world file with the game states, of the accounts database and of the forum database. They are kept on the server itself, not off-site, and are readable only by the administrator (root).

The purpose is recovery after a failure or error (Art. 6(1)(f) GDPR). Backups are kept for 30 days and then deleted. When we delete data at your request, it therefore disappears from backups only once those expire, after 30 days at the latest.

External links

The site links to Discord and to the source code on GitHub. Only when you click one of these links do you leave our site and data flows to that provider. Its privacy policy applies.

Recipients and hosting

The server runs at a hosting provider that works for us as a processor under Art. 28 GDPR. There are no other recipients. We do not sell data and do not pass it on for advertising.

Hosting:[[HOSTING-ANBIETER UND STANDORT]]

Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). To use them, write to the email address in the legal notice.

Erasure (Art. 17 GDPR): you can delete your account yourself, under “Account” on this website (password and your username as confirmation). This deletes your account and all your heroes, plus game state, inventory and your chests; your buildings stay behind without an owner. Your Thing posts stay in place so conversations remain readable; the author then shows as “Deleted hero”, detached from your account and hero. Reactions, subscriptions, notifications and your reports are deleted. Individual names may remain in the text of posts, for example in quotes; write to the e-mail address in the legal notice about those. The data disappears from backups after 30 days at the latest (see “Backups”).

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is:

[[ZUSTÄNDIGE DATENSCHUTZ-AUFSICHTSBEHÖRDE]]

Minors

[[MINDESTALTER UND REGEL FÜR MINDERJÄHRIGE]]

Changes

If the game or the processing changes, we adapt this policy. The version published here applies.

Legal notice