Privacy Policy
Effective Date: July 7, 2026
Summary: ETERNEL collects the data needed to operate accounts, enforce geo-compliance, process payments and withdrawals, run fair-play systems, and improve the product. We do not sell your personal data. We use service providers such as Clerk, PostHog, hosted checkout providers, push notification providers, KYC providers, and AppsFlyer attribution where configured. This policy explains what we collect, why, and your rights.
1. Data Controller
Data Controller: Eternel Games Ltd, a company registered in England and Wales (Company No. 17139657), with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom.
Contact: [email protected]
Eternel Games Ltd is the operational entity responsible for processing your personal data. Platform intellectual property is owned by Eternel Games LLC (Wyoming, USA).
Note: No Data Protection Officer (DPO) is currently appointed. This may need to be reassessed if processing reaches a scale requiring one under UK GDPR Article 37.
2. Data We Collect
2.1 Account Data
Collected at registration:
- Email address
- Display name and optional public handle
- Authentication credentials and session data handled by our authentication provider (passwords are never stored by us in plain text)
- Signup security signals (for example IP address and device fingerprint hash)
2.2 KYC Data
Collected before first Cash-Out, or when triggered by risk-based assessment:
- Full legal name
- Government-issued ID (document type and number, or scan)
- Proof of address (utility bill or bank statement)
KYC documents may be processed by a third-party provider acting as a data processor under a Data Processing Agreement (DPA).
2.3 Financial Data
- Deposit and withdrawal history
- Transaction history (entry fees, cash-outs, bonuses)
- Current account balance
- Deposit/withdrawal destination details needed to process payments
Payment method details for fiat transactions are handled by third-party payment processors. We do not store full card numbers.
2.4 Gameplay Data
- Game session history (date, duration, tier, outcome)
- In-game statistics (kills, deaths, placements, survival time)
- Ranking and seasonal scores
2.5 Technical Data
Collected automatically for security, compliance, anti-fraud, and product operation:
- IP address
- Approximate location from IP address and precise device location when you request access to wallet or paid tournament features
- Device type and browser
- Device identifiers used for security, attribution, push notifications, and session management
- Session timestamps
We use security/session cookies, PostHog for product analytics, and AppsFlyer for install attribution and campaign measurement when configured. We do not sell personal data or use third-party advertising cookies on the web client.
2.6 Communication Data
- Support tickets and correspondence
- Email communications
3. Data We Do Not Collect
We believe in transparency. Here is an explicit list of what we do not do with your data:
- We do not sell or rent personal data to advertisers
- We do not use third-party advertising cookies on the web client
- We do not use IDFA-based tracking unless we first obtain any consent required by Apple and applicable law
- We do not build behavioral profiles for sale to advertisers or data brokers
- We do not collect biometric data
- We do not perform automated decision-making or profiling beyond anti-fraud and anti-collusion
- We do not store payment card numbers (handled entirely by payment processors)
4. Why We Process Your Data (UK GDPR Art. 6)
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Account Data | Create and manage your account | Contract performance |
| KYC Data | Identity verification, anti-money laundering | Legal obligation |
| Financial Data | Process payments, maintain records | Contract + Legal obligation |
| Gameplay Data | Provide game services, rankings | Contract performance |
| Technical Data | Security, anti-fraud, geo-restriction | Legitimate interest |
| Analytics Data | Measure product usage and improve performance | Consent where required / Legitimate interest where permitted |
| Attribution Data | Measure install source and campaign performance | Consent where required / Legitimate interest where permitted |
| Communication | Respond to support requests | Contract performance |
| Anti-teaming data | Detect and prevent collusion | Legitimate interest |
We do not rely on “consent” as a legal basis for core data processing. Consent is only used where specifically required (e.g., analytics cookies, marketing emails if introduced in the future).
5. Data Storage & Security
- All data is stored on servers hosted by Hetzner in the European Union
- Security measures include: encryption at rest, encryption in transit (TLS), cryptographically hashed passwords, access controls, and regular security audits
- KYC documents are stored encrypted with access restricted to authorized personnel only, and deleted as required by AML regulations
6. International Data Transfers
Eternel Games Ltd is established in the United Kingdom. Your data is primarily stored on servers in the European Union (Hetzner, Germany). Some data is processed by service providers located in the United States.
- UK to EU: Transfers from the UK to the EU/EEA are covered by the UK adequacy regulations, which recognize the EU as providing an adequate level of data protection.
- UK to US: Transfers to US-based processors (such as Clerk, PostHog, AppsFlyer, and other configured service providers) are governed by the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), as applicable. Each US processor is bound by a Data Processing Agreement (DPA) that includes these transfer mechanisms.
- EU users: Where EU GDPR applies to the processing of your data (by virtue of Article 3(2) — offering services to individuals in the EU), the same transfer safeguards apply under EU Standard Contractual Clauses.
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of account + 3 years after closure |
| KYC Data | As required by AML law (typically 5 years after account closure) |
| Financial Data | 7 years (tax and accounting obligations) |
| Gameplay Data | Duration of account + 1 year after closure |
| Technical Data | 6 months (rolling deletion) |
| Communication Data | 2 years after last interaction |
| Anti-teaming logs | 6 months (rolling deletion) |
After the retention period expires, data is permanently deleted or irreversibly anonymized.
8. Your Rights (UK GDPR Articles 15–22)
As a data subject, you have the following rights:
- Access — Request a copy of all personal data we hold about you (response within 30 days)
- Rectification — Correct inaccurate or incomplete data
- Erasure — Request deletion of your data (subject to legal retention requirements — e.g., AML-required KYC data cannot be deleted before the mandatory retention period)
- Restriction — Request that we stop processing your data in certain circumstances
- Portability — Receive your data in a structured, machine-readable format
- Object — Object to processing based on legitimate interest
- Withdraw consent — Where consent is the legal basis (currently limited to analytics cookies and marketing, if applicable)
- Complaint — Lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk. If you are located in the EU, you may also contact your local EU supervisory authority.
To exercise your rights: Email [email protected] with subject “Data Rights Request.” We will respond within 30 days (extendable by 60 days for complex requests, with notification).
Account deletion: You can initiate account deletion from the app’s profile/settings area or by contacting support. Deleting an account removes the account and associated personal data from our active systems, except for limited records we are legally required to retain for tax, accounting, AML, fraud prevention, dispute handling, or regulatory compliance.
9. Third-Party Processors
The following third parties process data on behalf of Eternel Games Ltd:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Hetzner | Server hosting | All data (encrypted) | EU |
| PostHog | Product analytics | Usage and event analytics data | US/EU |
| AppsFlyer | Install attribution and campaign measurement | Device attribution identifiers, install/conversion events, app version | US/EU |
| Hosted checkout provider | Deposit checkout and payment processing | Checkout amount, currency, email, payment status, checkout token metadata | Provider-dependent |
| KYC provider | Identity verification & AML | KYC documents and verification results | Provider-dependent |
| Expo | Native push notifications | Push token and device notification metadata | US/EU |
| Clerk | Authentication & transactional emails | Email address, account data | US |
All processors are bound by Data Processing Agreements (DPAs) compliant with UK GDPR where required. Transfers to US-based processors are covered by UK IDTAs or the UK Addendum to EU SCCs. We do not sell data to advertisers or data brokers. If we configure attribution postbacks, limited conversion events may be sent through AppsFlyer to advertising measurement partners to measure campaign performance, subject to applicable consent and platform rules.
11. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information.
- We do not sell your personal information to third parties.
- We do not use data brokers. If limited attribution or conversion events are treated as “sharing” under California law, you may opt out by emailing [email protected] with subject “Do Not Share.”
- You have the right to know what personal information we collect, request deletion, and opt out of any future sale or covered sharing.
- We will not discriminate against you for exercising your CCPA/CPRA rights.
The categories of personal information we collect are described in Section 2 above. To exercise your California privacy rights, email [email protected] with subject “California Privacy Request.”
12. Children’s Privacy
The Platform is not intended for users under 18 (or the age of majority in their jurisdiction, if higher). Users under the required age may not create accounts or use the Platform.
If we discover a minor using the Platform, we may close the account, delete or restrict personal data as required by law, and apply account restrictions required for compliance.
If you are a parent or guardian and believe your child has created an account, please contact us immediately at [email protected].
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or in-platform notification at least 14 days in advance. The “Last Updated” date at the top of this policy always reflects the current version.
Continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions: [email protected]
For general support: [email protected]
Eternel Games Ltd, 128 City Road, London, EC1V 2NX, United Kingdom
Eternel Games LLC · 30 N Gould St, Ste 61798, Sheridan, WY 82801, USA — Intellectual Property & Legal
Eternel Games Ltd · Company No. 17139657 · Registered in England and Wales
128 City Road, London, EC1V 2NX, United Kingdom
Contact: [email protected]
