This English version is provided for convenience. The German version is legally binding.
1. Controller
The controller for data processing on the website raijin2.de, in the launcher and on the Raijin2 game server is:
pendientependiente
pendiente
Germany
E-mail: [email protected]
We have not appointed a data protection officer because we are not required to. For all data protection questions you can reach us at the e-mail address above.
2. Summary
- We only process the data we need for the website, your account and the game.
- There is no tracking, no analytics, no advertising and no social media plugins. Fonts, images and scripts of the website are served from our own server.
- We store password and PIN only as hashes, never in plain text.
- Our servers are located in Germany (Hetzner, Nuremberg). The website is delivered and protected via Cloudflare.
- We do not sell data and only share it where necessary for operation or where we are legally obliged to.
3. Hosting and Cloudflare
Hetzner
Website, game server, databases, patch files and backups are stored on a dedicated server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in the Nuremberg data centre. Hetzner processes the data only on our behalf (data processing under Art. 28 GDPR). The legal basis is our legitimate interest in secure and economical operation (Art. 6(1)(f) GDPR) and, as far as your account is concerned, the performance of the user agreement (Art. 6(1)(b) GDPR).
Cloudflare
The website, the launcher’s patch files and the launcher news are delivered via the network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare forwards requests to our server, encrypts the connection, speeds up delivery and fends off attacks. In doing so, Cloudflare processes your IP address, date and time, the requested address, browser and operating system details and security-relevant characteristics of the request. The connection to the game server itself does not go through Cloudflare but directly to our server at Hetzner.
The legal basis is our legitimate interest in a secure, fast website protected against attacks (Art. 6(1)(f) GDPR). Cloudflare is our processor. Data may be transferred to the USA. Cloudflare is certified under the EU-US Data Privacy Framework; to that extent an adequacy decision of the EU Commission applies to the USA (Art. 45 GDPR). In addition, the EU Commission’s standard contractual clauses apply. More information: Cloudflare privacy policy.
4. Visiting the website
With every request, our server and Cloudflare process technically necessary data: IP address, date and time, requested address, status code, amount of data transferred, the previously visited page (if your browser sends it) and browser and operating system. We need this data to deliver the website, find errors and detect attacks. One-time codes in links (for example for resetting your password) are masked before storage.
Legal basis: Art. 6(1)(f) GDPR (secure operation). The logs of our web server and of the website application are deleted after 14 days.
5. Cookies
We only set cookies that are technically necessary for the website. That is why we do not ask for consent (§ 25(2) no. 2 TDDDG).
| Name | Purpose | Duration |
|---|---|---|
r2sid | Session: keeps you logged in and protects forms against forgery. Only set when you log in or use a form. | 7 days after the last request |
lang | Remembers the chosen language (German/English). | 1 year |
To fend off bots, Cloudflare may in individual cases set its own, likewise technically necessary security cookie (for example __cf_bm, 30 minutes). There are no advertising, analytics or tracking cookies.
6. Registration and account
When you register, we process account name, e-mail address, password, PIN, the chosen language and the time and IP address of registration. We store password and PIN only as hashes, the PIN additionally with a random salt. Before the account is created we send a confirmation link to the e-mail address you entered; unconfirmed registrations are deleted after 24 hours. There is only one account per e-mail address – to ensure this, we compare new addresses with existing ones.
The account also includes the delete code for characters, the time of the last login on the website and in game and the IP address of the last game login. Under “My account” you can view and change your data yourself.
The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR); we process the registration IP address to prevent abuse (Art. 6(1)(f) GDPR) and delete it after 90 days.
7. Login and abuse protection
- Throttling failed attempts: To make guessing passwords harder, we count failed logins and requests per account and per IP address. After too many failed attempts, login is blocked for a while (website: 15 minutes; in game: ten minutes after five failed attempts). We delete these counters after one day at the latest.
- Security log: We store security-relevant events – such as registration, changes of password, PIN, e-mail address or delete code, wrong entries under “My account” and actions of the team – with time and IP address. This lets us detect attacks and help you if your account is stolen. We remove the IP address after 90 days and keep the entry itself as long as the account exists.
- Links by e-mail: Links for resetting your password or PIN and for changing your e-mail address are valid for one hour and only once. We only store a hash, the time and the IP address and delete the entries seven days after expiry.
Legal basis: Art. 6(1)(b) GDPR (a secure account) and Art. 6(1)(f) GDPR (protection against attacks and fraud).
8. Running the game
When you play, we process your account’s game data: characters (name, class, level, empire, guild, position, play time), inventory, storage, yang, Raijincoin balance, friend and guild lists and settings. The game cannot work without this data (Art. 6(1)(b) GDPR).
In addition, the game server writes logs that allow us to fix errors, trace lost items, uncover fraud and cheating and investigate complaints (Art. 6(1)(f) GDPR): logins and logouts with IP address, channel and play time; movements of valuable items and yang (trading, buying, upgrading, drops); level-ups; reports of the cheat protection; commands of team members; and messages in the public shout chat (without character name). We do not store private messages, group or guild chat. We delete these logs after six months unless we need them longer in an individual case to clarify a specific incident.
Publicly visible in game and in the ranking on the website are: character name, level, class, empire, guild and game progress. Account name, e-mail address and IP address are never public.
9. Anti-cheat captcha
To detect bots, the game server shows a number check after about 30 minutes of active play. If it is not solved within two minutes or after three failed attempts, the server disconnects you automatically; you can log in again immediately. We log this disconnect with character, account, IP address, reason (time out or failed attempts), number of disconnects, level, map and position. If disconnects pile up on one day, a note is created for the team.
The automatic disconnect is an automated decision. However, it has no legal effect and does not significantly affect you: you can continue playing immediately and no ban is imposed automatically. A human team member always decides on bans; you can comment and appeal. The legal basis is our legitimate interest in a fair, bot-free game (Art. 6(1)(f) GDPR). We delete these logs after six months.
10. Raijincoins and item shop
We store every credit and debit of Raijincoins with account, amount, reason, time and new balance. We store every item shop purchase – in game or on the website – with account, character, item, quantity, price, time and IP address. We use this to show you your purchase history, deliver items to the item shop storage and answer queries (Art. 6(1)(b) GDPR). We keep this data as long as the account exists; entries belonging to a purchase with real money are kept as long as tax and commercial law require (Art. 6(1)(c) GDPR).
11. Payments via Stripe
Payments with real money are not enabled yet. This section applies once they are.
When you buy Raijincoins, we store order number, account, package, amount, currency, status, timestamps and the IP address of the order. For payment we redirect you to the checkout page of Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. There you enter your payment and contact details directly with Stripe; we do not receive payment data. We ourselves only send Stripe the order number, package and amount. Stripe tells us whether the payment succeeded, was refunded or charged back.
Stripe is itself responsible for processing the payment and also processes the data to meet legal obligations (for example anti-money-laundering rules) and to prevent fraud. Data may be transferred to Stripe, Inc. in the USA; Stripe is certified under the EU-US Data Privacy Framework. Details: Stripe privacy policy.
The legal basis is the performance of the purchase contract (Art. 6(1)(b) GDPR), retention under tax and commercial law (Art. 6(1)(c) GDPR) and our legitimate interest in preventing fraud (Art. 6(1)(f) GDPR). We delete the IP address of an order after 180 days.
12. Vote4Bonus
When you vote for Raijin2 via the website, we store account, toplist, time, IP address and a random identifier. We pass the identifier to the toplist so that it can confirm your vote to us; the toplist does not learn your account name this way. We use the IP address to limit how many accounts from one connection receive a bonus. Legal basis: Art. 6(1)(b) and (f) GDPR. We remove the IP address after 30 days. On the toplist itself, its operator is responsible for data processing.
13. E-mail and support
We only send e-mails that you trigger or that are necessary for your account: confirming your registration and a new e-mail address, resetting your password or PIN and – once payments are active – purchase confirmations and notices about changes to these texts. We do not send newsletters or advertising.
Our mailbox [email protected] and e-mail delivery are provided by checkdomain GmbH, Große Burgstraße 27/28, 23552 Lübeck, Germany, as our processor. If you write to us, we process your e-mail address, the content and – if you provide them – account name and other details to handle your request (Art. 6(1)(b) or (f) GDPR). We delete support e-mails no later than twelve months after the matter is closed, unless we have to keep them longer due to legal obligations or an ongoing dispute.
14. Launcher and game client
At every start, the launcher downloads the current list of game files and the news from raijin2.de (via Cloudflare) and updates the client. As with every website request, IP address, time, the files requested and the launcher version are processed (section 4). The launcher does not send any further data about your computer.
If you save credentials in the game client for quick login, account name, password and PIN are stored only on your computer in the file accounts.dat in the game folder. They are encrypted with the Windows Data Protection API (DPAPI) and can only be read by your Windows user account on that computer. We never receive this file. You can remove saved logins on the login screen at any time.
15. Discord and other links
We refer to our Discord server and to toplists only with plain links. No content of these services is embedded in our pages and no data flows to them unless you click the links. If you follow a link, the respective provider (for example Discord Inc., USA) is responsible for further processing.
16. Recipients and third countries
Your data is only received, as far as necessary for the respective purpose, by: our team (with access according to their tasks), our processors Hetzner (hosting), Cloudflare (delivery and protection of the website) and checkdomain (e-mail) and – once payments are active – Stripe as an independently responsible payment provider. Authorities only receive data if we are legally obliged to provide it. Transfers to the USA only take place via Cloudflare and Stripe and are based on the EU-US Data Privacy Framework (Art. 45 GDPR) and additionally on standard contractual clauses (Art. 46 GDPR).
17. Retention periods at a glance
| Data | Retention |
|---|---|
| Account and game data | until the account is deleted |
| Web server and website logs | 14 days |
| Unconfirmed registrations | 24 hours |
| Failed-attempt counters | 1 day at most |
| Reset links | 7 days after expiry |
Sessions (cookie r2sid) | 7 days after the last request |
| IP address for Vote4Bonus | 30 days |
| IP address of registration and in the security log | 90 days |
| IP address of an order | 180 days |
| Game logs and anti-cheat log | 6 months |
| Support e-mails | 12 months after the matter is closed |
| Orders and bookings with real money | statutory retention period (currently up to 8 or 10 years) |
| Backups | 14 days, then deleted automatically |
If your account is deleted, we delete or anonymise the associated data unless we have to keep it due to legal obligations. It disappears from backups after 14 days at the latest.
18. Your rights
You have the right to
- access the data we process about you (Art. 15 GDPR),
- rectification of incorrect data (Art. 16 GDPR),
- erasure (Art. 17 GDPR) – for example of your entire account,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on our legitimate interest on grounds relating to your particular situation (Art. 21 GDPR).
To do so, write to [email protected], preferably from the address stored for your account – this lets us verify that the request really comes from you.
You can also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority at your place of residence or the authority responsible for us in the German federal state where we are based.
19. Obligation to provide data
Account name, e-mail address, password and PIN are required for registration; without them we cannot create an account. The IP address is transmitted technically with every connection. Beyond that you do not have to give us any data.
20. Children and young people
Raijin2 is intended for people aged 16 and over; minors need the consent of their parents or guardians (see Terms of Service). We do not collect age data. If we learn that an account was created by a younger child, we delete it. Parents or guardians can contact us about this at any time.
21. Changes
We update this privacy policy when our services or the law change. The version published on this page applies; we announce significant changes on the website.