This document is a draft pending legal review. It describes what this service actually stores and shares; the controller’s identity and contact details are to be completed.
1. Who is responsible
The controller of the personal data described here is the entity operating IronGames, to be completed before launch, together with its contact address and, where one is required, its data protection representative.
2. What we collect, and why
Account data
Your username, email address and password hash, so you can have an account and recover it. Where you enable two-factor authentication we also store the secret and your recovery codes.
Order and billing data
Your orders, invoices and subscription state, so we can provide and bill for the service and meet our accounting obligations. Card details are handled by our payment provider and never reach our servers; we keep only the provider’s reference, the card brand and last four digits where the provider supplies them.
Technical and security data
IP addresses, timestamps and an activity log of significant actions on your account and servers — logins, password changes, subuser changes, server operations. We need these to secure accounts, investigate abuse and answer “who did this?” when you ask.
Support data
The tickets you open and the messages in them, so we can help you and refer back to previous conversations.
3. What we do not do
We do not sell personal data. We do not use your world files, server content or support messages to build advertising profiles.
4. Who we share it with
Only the processors needed to run the service: our payment provider, our email delivery provider, and the infrastructure providers hosting the nodes your server runs on. Each processes data on our instructions. We also disclose data where we are legally required to.
5. Where your data is held
You choose your server’s region at checkout, and its files stay in that region. Account, billing and support data is held in our primary region. Where data moves outside your own jurisdiction we rely on the safeguards our providers have in place.
6. How long we keep it
Account data lasts as long as your account. Server files are deleted after an account is closed, once the closure is complete. Invoices and billing records are kept for the period tax and accounting law requires. Security and activity logs are kept for a limited retention window, to be completed.
7. Your rights
Subject to the law that applies to you, you can ask for a copy of your data, ask us to correct or delete it, object to or restrict certain processing, and ask for it in a portable form. You can also complain to your data protection authority. Open a ticket from your panel to make a request, and we will verify it is really you before acting on it.
8. Security
Passwords are stored hashed, never in plain text. Sessions are cookie-based over HTTPS. Two-factor authentication is available on every account. Changing your password revokes existing daemon access to your servers, so an old session cannot keep using replaced credentials.
9. Children
This service is not directed at children below the age at which they can consent to online services in their own country. The applicable minimum age is to be completed.
10. Changes
If we change how we use your data we will update this page and, where the change is material, notify you directly.