← Back to HellasPrivacy Policy
Last updated: 2026-06-29
1. Introduction
This Privacy Policy describes how Hellas Online (the "Game") collects, uses, stores, and protects your personal data. It supplements the Terms of Service.
Controller during closed beta. Hellas Online is currently operated as a personal project by an individual operator residing in Finland, who acts as the data controller for the personal data described below. The legal-entity details required for public registration (full controller name, registered address, registration number where applicable) will be published in this Policy before public registration opens. For privacy or data-protection inquiries during closed beta, contact privacy@hellasonline.xyz.
The Game's servers and infrastructure are located in Finland.
2. Data We Collect
We collect the following categories of data:
- Account information: email address, hashed password (we never store plaintext passwords), display name
- Game-state data: towns, units, resources, research, kingdom membership, alliance history, in-game messages, forum posts, kingdom communications, in-game actions
- Technical data: IP address, browser/user-agent string, session identifiers, timestamps of game actions
- Communication content: chat messages, in-game messages, forum posts, kingdom communications, bug reports
- Moderation data: warnings, suspensions, bans, and the reasons recorded for them
We do not knowingly collect special categories of personal data (race, religion, health, sexual orientation, etc.) and ask that you do not submit such data through the Game.
3. How We Use Your Data
We process your data for the following purposes:
- To operate, maintain, and improve the Game
- To authenticate you and secure your account
- To enforce the Terms of Service, detect cheating, and respond to abuse reports
- To communicate with you about your account, gameplay, or Game updates
- To debug technical issues and analyze gameplay patterns for game balancing
- To comply with legal obligations
4. Legal Basis (GDPR)
For users in the European Economic Area, our legal bases for processing under the EU General Data Protection Regulation (GDPR) are:
- Performance of contract (Article 6(1)(b)): processing necessary to provide the Game you signed up for
- Legitimate interests (Article 6(1)(f)): protecting the Game from abuse and cheating, debugging, improving gameplay balance, and preventing ban evasion
- Legal obligation (Article 6(1)(c)): responding to lawful requests from authorities and meeting record-keeping requirements
- Consent (Article 6(1)(a)): where you have given clear consent for a specific purpose, you may withdraw that consent at any time
5. What Other Players Can See
Some of the data you submit is visible to other players as part of normal gameplay. This is the visibility model:
- Public to all players: your display name, your kingdom name and membership, the locations of your towns on the world map (subject to fog-of-war and your kingdom's territory), and your public statistics on the leaderboard
- Public within a channel: chat messages are visible to participants of the channel they are posted in - Global to all players, Kingdom to your kingdom members, Island to players present on the same island
- Public on the forum: forum posts and threads are visible according to that forum's membership rules (administrative-only categories are limited to operators)
- Visible to your kingdom only: kingdom-internal messages, kingdom treasury contributions, kingdom voting records
- Private to you: your resource counts, garrison composition, research progress, account email, and password hash
Beyond what is shown in-game and on the forum, we do not sell, rent, or share account data with third parties for advertising or marketing purposes.
6. Operational Data Sharing
We may share data with:
- Hosting and infrastructure providers (located in Finland, within the EEA) strictly to operate the Game
- Law enforcement or government authorities when compelled by valid legal process or to prevent serious harm
7. Data Retention
- Account credentials (email, password hash, recovery data): retained while your account is active and removed within 30 days of an account-deletion request
- Game-state data and pseudonymized chat / forum content authored by the account: retained for the active lifetime of the game world the content was created in. After a game world is decommissioned, retained data is anonymized or deleted within 12 months
- Server and access logs: typically retained for up to 12 months for debugging and abuse investigation, then deleted
- Moderation records (bans, warnings, the reasons for them): retained as long as needed to enforce future bans, on the basis of legitimate interests (Article 6(1)(f) GDPR)
- Ban-evasion identifiers: hashed identifiers (such as hashed IP addresses and hashed email addresses) of permanently banned accounts may be retained beyond account deletion to prevent ban evasion. These are stored in hashed (one-way) form and used only to detect repeat ban-evasion attempts
- Backups: full database backups are retained for short rolling windows (typically up to 30 days) and overwritten on rotation
8. Your Rights
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: ask us to correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): request deletion of your account, subject to the retention exceptions described in section 7
- Right to restriction of processing
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object to processing based on legitimate interests
- Right to withdraw consent (where processing is based on consent), without affecting prior lawful processing
- Right to lodge a complaint with a supervisory authority - in Finland this is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto, tietosuoja.fi)
To exercise any of these rights, email privacy@hellasonline.xyz or submit a request through the in-game Bug Report form. We aim to respond within 30 days.
9. Security
We use industry-standard technical and organizational measures to protect your data, including hashed password storage (bcrypt / argon2), HTTPS for all client / server communication, server-side input validation, restricted operational access to the database, and rate limiting on sensitive endpoints. No system is perfectly secure.
Breach notification. In the event of a personal-data breach, we will notify the relevant supervisory authority (in Finland, Tietosuojavaltuutetun toimisto) without undue delay and where feasible within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to the rights and freedoms of affected users, we will also notify those users directly without undue delay (Article 34 GDPR).
10. Children
The Game is intended for users aged 16 and older. Users between 16 and the age of majority in their country (typically 18) must have parental or guardian consent to register, as described in the Terms of Service. We do not knowingly collect personal data from anyone under 16. If we become aware that we have collected such data, we will delete it. If you are a parent or guardian and believe a child under 16 has provided us with personal data, please contact us via the channels listed in section 14.
11. International Transfers
Game data is stored on servers located in Finland. If you access the Game from outside the European Economic Area, your data is transferred to and processed in Finland. As a member of the EEA, Finland is subject to the GDPR and provides a level of data protection equivalent to that of other EEA countries.
12. Cookies, Local Storage, and Analytics
Local storage. The Game uses browser local storage to keep you signed in (refresh tokens) and to remember user-interface preferences (theme, layout, last-selected town). We do not use third-party advertising cookies, tracking pixels, or cross-site tracking technologies.
First-party analytics. The Game records anonymous-or-pseudonymous event-level analytics on its own servers in Finland: events such as login, registration, battle outcomes, building / research / tutorial completion, kingdom and forum activity. This data is used solely for game balancing, debugging, and operational improvement. It is not shared with any third-party analytics, advertising, or marketing services.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through an in-game notification or a notice on the login page. The "Last updated" date at the top of this page reflects the most recent revision; a brief revision history is available at the bottom of this page.
14. Contact
For privacy questions, data-subject access requests, or to report a privacy concern, email privacy@hellasonline.xyz or use the Bug Report option in the in-game Help section. We respond to GDPR-related requests within the timelines required by law (typically 30 days).
By using Hellas Online you acknowledge that you have read and understood this Privacy Policy.
Revision History
2026-06-29 (revision 3): Operator contact addresses consolidated under the hellasonline.xyz domain.
2026-04-28 (revision 2): Controller identity clarified for closed-beta phase; per-data-type retention windows tied to game-world activity (no longer "indefinite"); ban-evasion identifier retention disclosed; first-party analytics disclosed (Section 12); 72-hour breach notification commitment stated explicitly (Article 33 GDPR); visibility of in-game data clarified (Section 5); 16-17-with-consent acknowledged (Section 10); contact email published.
2026-04-28 (revision 1): Initial publication.