Skip to content
FRONT-RISK
Last updated: [INSERT DATE]

Privacy Policy

This privacy policy explains the nature, scope, and purpose of processing personal data within this website.

This privacy policy informs you, in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and the Austrian Data Protection Act (DSG), about the nature, scope and purpose of the processing of personal data within our online service Front-Risk.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:
[COMPANY NAME / FULL NAME]
[STREET AND NUMBER]
[POSTAL CODE] [CITY], Austria
Email: front-risk@gmx.net
[optional: phone, VAT ID, commercial register number]

2. General Information

We process personal data exclusively in accordance with the provisions of the GDPR and all other applicable laws. Personal data means any information relating to an identified or identifiable natural person.

3. Legal Bases for Processing

  • Art. 6(1)(a) GDPR – consent (e.g. optional cookies, newsletter)
  • Art. 6(1)(b) GDPR – performance of a contract and pre-contractual steps (e.g. account, gameplay)
  • Art. 6(1)(c) GDPR – legal obligation (e.g. tax retention)
  • Art. 6(1)(f) GDPR – legitimate interests (e.g. IT security, fraud prevention, anonymous statistics)

4. Categories of Data and Purposes

4.1 Account / Login

On registration we collect: email address, password (hashed, never stored in plaintext), nickname, registration timestamp, and login timestamps / IP addresses for abuse prevention. Purpose: providing access to the game and managing the account. Legal basis: Art. 6(1)(b) GDPR. Retention: until the account is deleted by the user; IP logs for a maximum of 30 days.

4.2 Forum Posts

When you create threads or replies, the content, timestamp and author (nickname / account ID) are stored and made visible to other registered users. Legal basis: Art. 6(1)(b) GDPR (performance of the forum service). Retention: until deletion by the user or moderation action. Anonymisation of deleted posts is technically possible.

4.3 In-Game Chat

Messages inside a game room are processed ephemerally — they exist only in server memory for the duration of the session and are discarded once the match ends. They are not persisted. If abuse is reported, a short-term log (max. 24 h) may be created. Legal basis: Art. 6(1)(b) and (f) GDPR.

4.4 Server Log Files

When you access the website, our hosting provider automatically processes technical data: IP address, date and time, requested URL, user agent, referrer. Retention: maximum 30 days. Legal basis: Art. 6(1)(f) GDPR (IT security).

4.5 Cookies and Analytics

We use strictly necessary cookies (session, language, theme) on the basis of Art. 6(1)(f) GDPR and § 165(3) Austrian TKG 2021. Optional analytics / marketing cookies are only set after your explicit consent via our cookie banner (Art. 6(1)(a) GDPR). Consent can be withdrawn at any time.

Analytics services in use: [e.g. Plausible Analytics – cookieless / Google Analytics 4 / none]. Details and opt-out: [LINK TO PROVIDER POLICY].

5. Processors and Recipients

The following services process data on our behalf pursuant to Art. 28 GDPR:

  • Web / frontend hosting: [e.g. Vercel Inc., USA – Standard Contractual Clauses]
  • Game server hosting: [e.g. Railway / Hetzner / provider]
  • Database: [e.g. Supabase / Postgres provider]
  • Email delivery: [e.g. Resend / Postmark / none]
  • Analytics: [provider — see 4.5]

6. Transfers to Third Countries

Where data is transferred to providers outside the EEA (e.g. USA), such transfers rely on the EU-US Data Privacy Framework or the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. An adequate level of protection is ensured contractually.

7. Retention Periods

We store personal data only for as long as necessary to achieve the respective purpose or as required by statutory retention obligations. Once the purpose ceases to apply, the data is deleted or anonymised.

8. Your Rights as a Data Subject

You have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure / “right to be forgotten” (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise these rights, please contact us using the address listed above.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority. In Austria:
Austrian Data Protection Authority
Barichgasse 40–42, 1030 Vienna
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at
Web: www.dsb.gv.at

10. Data Security

We employ technical and organisational measures (TOMs) in accordance with Art. 32 GDPR, in particular TLS encryption of data transfers, password hashing, access restrictions and regular security reviews.

11. Minors

Our service is not directed at children under the age of 14 (§ 4(4) DSG in conjunction with Art. 8 GDPR). If we become aware that a minor has created an account without parental consent, we will delete the account.

12. Changes to this Policy

We reserve the right to update this privacy policy whenever new features or changes in the legal landscape make this necessary. The current version is always available on this page.