Back to Home

Privacy Policy

1. Controller

The controller responsible for processing personal data within the meaning of the General Data Protection Regulation (GDPR) is:

VidiScope GmbH
Valentin Schierhuber (Geschäftsführer)
Römerstr. 27
89250 Senden
Deutschland
Tel.: +49 731 25089010
E-Mail: office@vidiscope.com
Datenschutzanfragen: datenschutz@vidiscope.com

For any questions regarding data protection, please contact us preferably via the data protection email address given above.

2. General Principles

We process our users' personal data only to the extent necessary to provide a functioning game as well as our content and services. Processing generally takes place only with the consent of the data subject or on the basis of another legal permission. Where consent is obtained for processing personal data, Art. 6(1)(a) GDPR serves as the legal basis.

3. Hosting and Provision of this Service

World of Pharaos is operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The servers are located in Hetzner's data centers in Falkenstein and Nuremberg (Germany). We have entered into a data processing agreement with Hetzner pursuant to Art. 28 GDPR.

Each time a page of the game is accessed, the web server (nginx) automatically collects the following data in so-called log files:

This data is collected to ensure smooth operation as well as to detect and defend against attacks (Art. 6(1)(f) GDPR, legitimate interest in the security and stability of our service). Log files are automatically deleted after 14 days.

To protect against data loss, we create encrypted backups, which are additionally mirrored to a second server also operated in Germany. Backups are retained on a staggered basis and deleted after 120 days at the latest.

4. Cookies and Local Storage

Our game uses only the technically necessary session cookie PHPSESSID. It allows us to recognize you during your visit (e.g. to keep you logged in) and is strictly required for the game to function. The cookie is set with the HttpOnly and SameSite=Lax attributes; on the production system it is additionally transmitted only over an encrypted connection (Secure). It becomes invalid at the end of your session or when you close your browser.

Your selected language (German/English) is stored exclusively in this session, not in a separate cookie.

We do not use any further cookies, tracking or analytics tools, or third-party cookies.

The legal basis for the technically necessary session cookie is Section 25(2) No. 2 TDDDG (German Telecommunications-Digital-Services-Data-Protection Act) in conjunction with Art. 6(1)(f) GDPR. No consent is required for this, as the cookie serves exclusively to provide the service you have explicitly requested.

5. Spam Protection for Forms

To protect registration from automated abuse (bots), we use a simple math captcha, a honeypot field invisible to humans, and a check of how quickly the form was filled in. All three mechanisms run entirely on our own servers; no data is transmitted to external providers (e.g. Cloudflare Turnstile, Google reCAPTCHA, or similar).

The legal basis is our legitimate interest in a functioning game free of abuse (Art. 6(1)(f) GDPR).

6. Registration and Player Account

Participation in the game requires creating a user account. During registration, we collect and store:

This data is required to provide the game and manage your account; the legal basis is Art. 6(1)(b) GDPR (performance of the terms of use).

To protect against brute-force attacks on the login, we log login attempts (email address, IP address, timestamp, success/failure) in a separate table. The legal basis is our legitimate interest in the security of user accounts (Art. 6(1)(f) GDPR). These logs are automatically deleted after 30 days.

If you use the forgot-password function, we generate a time-limited reset token (stored as a hash, including expiry time, usage status, and the requesting IP address). Expired or already-used reset requests are automatically cleaned up. The legal basis is Art. 6(1)(b) GDPR.

If an account violates our terms of use, we store the reason, time, and duration of a suspension in order to track repeat violations and correctly enforce suspensions (Art. 6(1)(f) GDPR).

7. Email Communication

For sending registration and password-reset emails, we use a mail server of Strato AG, Pascalstraße 10, 10587 Berlin. This mail delivery path is technically prepared at this time but not yet live in production. Once active, the following applies: the legal basis for this account-related communication is Art. 6(1)(b) GDPR; we do not send newsletters or other promotional emails.

8. Gameplay and User-Generated Content

As part of using the game, we process your game progress (including your oasis, buildings, resources, troops, and position on the world map), your alliance membership, and battle reports. The legal basis is Art. 6(1)(b) GDPR (performance of the terms of use).

Messages you send to other players via the internal messaging feature (sender, recipient, subject, text) are automatically deleted 7 days after being sent (daily cleanup job). The legal basis is Art. 6(1)(b) GDPR.

In your profile, you may voluntarily provide additional information (e.g. date of birth, gender, origin, occupation, interests, homepage, free text, avatar image). This information is explicitly voluntary, is only stored with your consent (Art. 6(1)(a) GDPR), and can be changed or deleted by you in your profile at any time.

9. Payments (Currently Inactive)

World of Pharaos is currently entirely free to play. A premium/currency system is technically prepared in the code but is not currently active; no payment processing takes place and no payment-related data is processed. Should we activate paid features in the future, we will update this privacy policy in advance accordingly and inform you about the payment service providers used at that time.

10. Disclosure to Third Parties

We disclose your data to third parties only to the extent necessary to provide the game. This concerns in particular our hosting provider Hetzner Online GmbH (processor pursuant to Art. 28 GDPR, see Section 3) and – once activated – the email delivery provider Strato AG mentioned in Section 7. We do not transfer data to any other third parties, do not sell your data, and do not use it for third-party advertising purposes. We do not use Google Analytics, Cloudflare, or comparable third-party services.

11. Transfer of Data to Third Countries

All processing described in this policy takes place exclusively on servers located in Germany. Personal data is not transferred to countries outside the European Union or the European Economic Area (so-called third countries).

12. Your Rights as a Data Subject

Under the GDPR, you have the following rights, which you may assert at any time via the data protection email address given in Section 1:

13. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
www.lda.bayern.de

14. Changes to this Privacy Policy

We reserve the right to amend this privacy policy to ensure it always complies with current legal requirements or to reflect changes to our service (e.g. new features) in the privacy policy. Your next visit will then be governed by the updated privacy policy.

Last updated: August 2026