|
|
Privacy Policy of BitMeUp UG (haftungsbeschränkt)
Version: Hamburg, 13 August 2026 Latest change: Cloudflare Turnstile (bot and abuse protection) added You can request an overview of the personal data stored for your account every 30 days using the following link: https://bitmeup.com/bitmeup/privacy/request.php 1. Controller The controller responsible for the processing of personal data on bitmeup.com, the associated game sites and within the games and services is:
BitMeUp UG (haftungsbeschränkt)
c/o Carsten Heeder Fritz-Flinte-Ring 86 22309 Hamburg, Germany Email: [email protected] A data protection officer has not been appointed, as the legal requirements for a mandatory appointment are not met. For any questions regarding data protection you can reach us at the email address above or via our support form. 2. Why we process data (purposes and legal bases) BitMeUp UG operates various games and services in which data must be processed in order to run the games and to ensure game fairness and security. We only process personal data where one of the following legal bases of the GDPR permits it: • Art. 6 (1) (b) GDPR (contract): for everything required to provide your account, the games, the services and to process purchases (e.g. registration, login, game progress, payment processing, support). • Art. 6 (1) (f) GDPR (legitimate interest): for the security of our systems, the prevention of abuse and fraud, multi-account and fairness checks as well as technical logs. Our legitimate interest is the stable, fair and secure operation of the games for all users. • Art. 6 (1) (a) GDPR (consent): for everything that is not strictly required, in particular newsletters, personalised advertising, analytics cookies (see “Cookies & Consent”) and access to the messaging system (see “Private Messages”). You may revoke any consent given at any time with effect for the future. • Art. 6 (1) (c) GDPR (legal obligation): e.g. for statutory retention obligations relating to payment transactions. For individual features we specify below which data is stored and for how long. We cannot publish an exact description of all detection methods (e.g. for multi-account checks), as they could otherwise be circumvented — we ask our community for their understanding. 3. Recipients and transfers to third countries Your data is only passed on to third parties where this is required for operation (described per service below), where we are legally obliged to do so, or where you have consented. Data processing agreements pursuant to Art. 28 GDPR are in place with service providers processing data on our behalf. Some service providers (e.g. Cloudflare, Twilio SendGrid, Xsolla, Google, Atlassian) also process data in the USA. We base such transfers on the standard contractual clauses of the EU Commission (Art. 46 (2) (c) GDPR) and — where the respective provider is certified there — on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). 4. Changes to this privacy policy We update this policy whenever our processing changes. In the event of material changes we will inform you by means of a clear notice on our sites and/or in the games and ask you to take note of the updated version. Your RightsYou have the following rights under the GDPR vis-à-vis BitMeUp UG: • Access to the data stored about you (Art. 15 GDPR) — most easily via our data request tool; • Rectification of inaccurate data (Art. 16 GDPR); • Erasure (Art. 17 GDPR) — please note: for game-technical reasons it is not always possible to delete a game account immediately; in that case all personal data is removed from the game account unless it is legally required for billing or prosecution purposes; • Restriction of processing (Art. 18 GDPR); • Data portability (Art. 20 GDPR);
Right to object (Art. 21 GDPR): You have the right to
object at any time, on grounds relating to your particular situation, to
the processing of personal data concerning you which is based on
Art. 6 (1) (f) GDPR (legitimate interest). If we process your data for
direct marketing, you may object to such processing at any time without
giving reasons.
• Withdrawal of consent (Art. 7 (3) GDPR) — at any time with effect for the future, e.g. via the “privacy settings” in the portal or the settings of the respective game; • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, datenschutz-hamburg.de. To exercise your rights, an informal message to [email protected] or via the support form is sufficient. Hosting, Server Logs, Cloudflare & Bot ProtectionOur games and services run on servers operated in Germany. Server logs: When you visit our sites and services, the web servers automatically record log files. This data includes e.g. browser type and version, operating system used, referrer URL (the previously visited page), IP address, date and time of access and the requested file/URL. The logs serve to ensure operation, analyse errors and defend against attacks (Art. 6 (1) (f) GDPR) and are not merged with other data sources for advertising purposes. Cloudflare: All access to our public sites and games is routed through the content delivery network of Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, or Cloudflare Germany GmbH). Cloudflare thereby processes your IP address and connection data as technically required in order to deliver content quickly and to defend against attacks (e.g. DDoS) (Art. 6 (1) (f) GDPR). For transfers to the USA see section 3 of the basics. More information: cloudflare.com/privacypolicy. Cloudflare Turnstile (bot and abuse protection): In certain areas of our sites, games and services we use “Cloudflare Turnstile” to check whether a request comes from a human or from a bot. The check is not displayed permanently but only when there is a reason for it — in particular for actions that lend themselves to automation, or in the case of unusually high action rates (see e.g. SpaceInvasion). For this purpose a script provided by Cloudflare (challenges.cloudflare.com) is loaded into the page. Cloudflare thereby processes your IP address, browser and device information (e.g. browser type and version, operating system, language setting, screen and time zone data) as well as technical signals about the behaviour in the browser, and stores or reads information on your device for this purpose. According to Cloudflare, Turnstile does not set any cookies for advertising or tracking purposes, and the data is not used for advertising or for cross-site profiling. We send the verification token generated by Turnstile back to Cloudflare together with your IP address for validation; we log the result (passed / not passed) together with your user ID and the time. The legal basis is our legitimate interest in defending against bots, automation and abuse, and in fairness within our games (Art. 6 (1) (f) GDPR). Storing and reading the information required for this on your device is exempt from consent under Section 25 (2) of the German TDDDG, as it is strictly necessary for the use you have requested. For transfers to the USA see section 3 of the basics. More information: cloudflare.com/privacypolicy. If Turnstile cannot be loaded (e.g. because scripts or Cloudflare are blocked in your browser), we generally show our own image captcha instead. It runs entirely on our servers; no data is generated at Cloudflare in that case. Cookies & ConsentTechnically required cookies: We use cookies that are required for operation — in particular session and login cookies (so that you stay logged in and can switch between the portal and the games) as well as preference cookies (e.g. language, app detection). These are exempt from consent under Section 25 (2) of the German TDDDG; the associated data processing is based on Art. 6 (1) (b) and (f) GDPR. The login does not work without these cookies. Storing and reading the information required by our bot and abuse protection is likewise exempt from consent under Section 25 (2) TDDDG (Cloudflare Turnstile, see Hosting, Cloudflare & Bot Protection). Cookies requiring consent, and advertising: We only use cookies and comparable technologies for personalised advertising and analytics if you have consented via our consent banner (consent banner according to the IAB TCF standard, managed via Google’s consent platform) (Section 25 (1) TDDDG, Art. 6 (1) (a) GDPR). The banner shows you the list of advertising partners and lets you make a granular choice. Withdrawal: You can change or withdraw your consent at any time via the “privacy settings” item (linked at the bottom of the portal and within the games). Google Services & AdvertisingWe use — in each case only with your consent given via the consent banner (Art. 6 (1) (a) GDPR) — services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”): • Google Analytics for statistical analysis of the use of our sites. The information generated (including a truncated IP address) may be transferred to Google servers, including in the USA. • Advertising services provided by Google and partners to finance the free-to-play operation of our games. Without consent, no personalised advertising is displayed. For transfers to the USA see section 3 of the basics. Further information on how Google processes data: policies.google.com/technologies/partner-sites and policies.google.com/privacy. You can change your choice at any time via the “privacy settings”. Third-Party LoginsYou can optionally link your BitMeUp account with external providers and log in through them: Google, Facebook, Steam, Twitch and — where offered — Discord. Their use is voluntary; logging in with email address and password is equally possible. When you log in via a provider we receive from it — depending on the provider — your user ID there, your display name, possibly your profile picture and possibly your email address. For the link we store the external user ID, the date of linking and the date of later changes (Art. 6 (1) (b) GDPR). After unlinking, the external ID is retained for another 90 days for traceability and then deleted. For the data processed by the respective provider itself, please refer to its privacy policy (Google, Meta/Facebook, Valve/Steam, Twitch, Discord). BitMeUp Team Structure
What is a chat moderator:
A chat moderator is a voluntary member of our community focusing on looking after the chat. These players still participate fully in the game.
What is a board moderator:
Board moderators have access to data and administrative functions of the forum software used. Board moderators may hold other BitMeUp team ranks in parallel. If only the board moderator rank is held, participation in our games remains possible. Board moderators have signed a non-disclosure agreement issued by BitMeUp UG and are aware that BitMeUp UG and they themselves work with confidential customer data.
What is a team member:
Private Messages
Team members have access to scripts and programs developed by BitMeUp UG which allow them to view logs and evaluations of game content or actions. This applies exclusively to the administration of the games and the monitoring of the services and fairness. All team members have signed a non-disclosure agreement issued by BitMeUp UG and are aware that BitMeUp UG and they themselves work with confidential customer data. You can write private messages to other players in the chat, the forum or in the games. All games can also be used without access to an existing in-game messaging or chat system. Use of these functions requires the user's consent that, in the event of a suspected violation of the game rules, the Terms and Conditions or applicable law, the team and the operator are entitled to access private and other messages or other data entered into the respective tool (Art. 6 (1) (a) and (f) GDPR). The team and the operator thus have access to the information and data entered by the user into the respective system — even if consent is withdrawn at a later time (for messages created while consent was given). You can grant access in the settings of the respective game; withdrawal is possible at any time. We expressly point out that private messages are only viewed if there is a suspicion of a violation of the law, the Terms and Conditions or the game rules. No team member reads private messages without cause. If access is required, no private messages whatsoever are published or made available to third parties (except to competent authorities, e.g. the police, in the event of a criminal offence). We take the privacy of every user very seriously and — like all participating players — only want to preserve fairness and to investigate criminal offences, misconduct in the game or rule violations. BitMeUp Email Delivery For sending emails (e.g. registration, password and notification emails and — only with consent — newsletters) we use the SendGrid service of Twilio Inc., 101 Spear Street, San Francisco, CA 94105, USA, as a processor. For this purpose we transmit the email address as well as the subject and content of the respective email to the SendGrid servers via an encrypted connection. Using a specialised delivery provider ensures that our emails are delivered reliably and are not lost in spam filters (Art. 6 (1) (b) and (f) GDPR; newsletters only under Art. 6 (1) (a) GDPR — you can unsubscribe via the link in every mail or the portal settings). For transfers to the USA see section 3 of the basics. More information: twilio.com/legal/privacy. BitMeUp Forum SoftwareBitMeUp UG uses the forum software of WoltLab GmbH (woltlab.com), which maintains and further develops the software. We adopt the default settings of the WoltLab software for data collection and deletion and make no changes to them. When a BitMeUp account is created, a forum account is created automatically (Art. 6 (1) (b) GDPR). These accounts are set up in such a way that all data can continue to be lawfully used, changed or deleted by the automatic tasks and processes of the WoltLab software. Please note the privacy policy of the forum software: forum software privacy policy BitMeUp Chat SoftwareThe games use a chat system developed by BitMeUp UG. It is based on the same rules in all games: All chat messages are temporarily available on our chat servers for a maximum of 3 minutes. During this time the messages are written to our database. • Alliance and global chat messages are deleted after 14 days. • All whisper/private chat messages are deleted after 7 days. If messages are reported by a player, the message is stored permanently for a ticket. Once the ticket has been processed, the ticket and the chat message are deleted after 90 days. Chat moderators in the game: All chat moderators can only view global chat messages. This also applies to reported chat messages. Team members: Team members can view all global, alliance and private messages. We expressly point out that private chat messages are only viewed if they are reported by the author or the recipients or if there is a reasonable suspicion of a criminal offence or a violation of the Terms and Conditions or the game rules. BitMeUp Payment BitMeUp UG engages Xsolla (USA) Inc., 15260 Ventura Blvd, Sherman Oaks, CA 91403, USA, to carry out and manage the payment transactions in all games. Xsolla acts as the provider of the purchase processing. For these purposes we transmit the following data to Xsolla via encrypted connections (Art. 6 (1) (b) GDPR): • user IDs to verify the user• the user's universe, world or realm • the user's email address • the user's language • the currency specified by the user or derived from the language • game-related data (e.g. account age in days, points, chosen starter monster in Mebula) Important: We ourselves do not store any payment information (no credit card or bank details) — the actual payment takes place directly with Xsolla or the chosen payment provider. Questions and concerns before, during and after a purchase are handled by the Xsolla support, which you can reach at any time via the “Pay Station”. For transfers to the USA see section 3 of the basics. More information: xsolla.com/privacypolicy. BitMeUp SupportBitMeUp UG uses various support systems. The BitMeUp portal, Damoria and Mebula use email for requests: • BitMeUp portal: [email protected] • Damoria: [email protected] • Mebula: [email protected] An email written by the user or a request created via bitmeup.com/support/ is subsequently processed by the “Jira Service Desk” software of Atlassian Pty Ltd or Atlassian, Inc. This software categorises and manages requests so that the team can find the best possible way to solve a problem (Art. 6 (1) (b) GDPR). We use the retention and deletion settings recommended by Atlassian. All data entered here is treated strictly confidentially and is not passed on to third parties by either BitMeUp or Atlassian. For possible transfers to the USA see section 3 of the basics. More information on Atlassian's privacy practices: atlassian.com/legal/privacy-policy SpaceInvasion Classic uses an in-game ticket system. An in-game message is created which a team member can then assign to themselves. The problem is resolved exclusively via the in-game messaging system. This function is also available if the user has not consented to the in-game messaging function. In that case the user only sees in-game messages written by or to team members. SpaceInvasion 2 uses an in-game ticket system. This is a ticket system separate from the in-game messages in which the player can open tickets (problems, requests or bug reports). The player can reply to these tickets without consenting to access to the in-game messaging or chat system. In Damoria, requests may occasionally be resolved further in the game via the in-game messaging
system. There may be cases in which the team contacts the player, e.g. when a special castle has been won/acquired.
BitMeUp UG expressly points out that no support is offered via TS3, forum, IRC, telephone or other channels. We reserve the right to use one or more of these platforms if it supports finding a solution. BITMEUP Desktop AppOur desktop app is a shell around the BitMeUp portal; the same sections as for the website apply. In addition: • Persistent login: If you stay logged in within the app, a device token is stored on your device — where possible in the keychain/password store of your operating system. On our servers, only a verification value (hash) of the token is stored together with the device name and the time of last use (Art. 6 (1) (b) and (f) GDPR). The token is rotated on every use; it is deleted when you log out. • Browser hand-off: If you launch a game in the browser from within the app, a one-time, short-lived and IP-bound hand-off code is used which expires after one minute. Geolocation (Country Detection)To offer you suitable defaults (e.g. language and currency) and for fairness checks, we determine the approximate country of origin from your IP address (Art. 6 (1) (b) and (f) GDPR). For this purpose your IP address may be transmitted to one of the following services, which return the corresponding country to us: • FreeIPAPI (freeipapi.com)
Only the IP address is transmitted; no reference to your account is passed to these services. The determined country is stored with your account. Alternatively, we evaluate the language settings of your browser. BitMeUp PortalUser data upon registration: All data provided during the registration process is treated confidentially. It is stored for up to 90 days after termination of the contract (Art. 6 (1) (b) GDPR). This data comprises: • email address • user name for the portal and the forum respectively • the hashed password (if a password has been set) • affiliate ID (which partner linked to us) • referring user • language • registration date • date of acceptance of the Terms and Conditions and the accepted version • whether consent to the newsletter was given BitMeUp Portal: Data The following data is collected during usage actions in the portal and the services:
The player logs in:
• IP address • time of login • service (app, game or portal) of the login This data is retained for 90 days.
The player links or unlinks a game account, creates a new game account or
deletes a game account:
The following is logged: • the action • the game account • the date This data is deleted after 360 days or upon deletion of the account.
The player wins in the BitMeUp lottery:
A winning entry with the winning number and the user name is created.
It is deleted after 90 days.
The user wants to link, unlink or delete a BitMeUp account or log in to one of
the BitMeUp games or services. For this purpose a temporary session is opened
which stores the user's IP address to ensure that this access can still be
attributed to the user.
These sessions are valid for 1 minute and are deleted immediately after expiry.
Login via external providers (Google, Facebook, Steam, Twitch, Discord where offered)
To maintain the link between the BitMeUp account and the external account, the following data is stored: • the user ID of your external account • the date of linking • the update date in the event of a change or deletion of the link After deletion of the link, the external ID is retained for another 90 days for traceability.
Acceptance of the Terms and Conditions and the Privacy Policy:
SpaceInvasion
When you accept a new version of our Terms and Conditions/Privacy Policy, we store the accepted version, the time, the IP address and the channel of acceptance (portal, app or game) in order to be able to prove the acceptance (Art. 6 (1) (b) and (c) GDPR). SpaceInvasion 1 (SpaceInvasion Classic) and SpaceInvasion 2 are used via a global SpaceInvasion portal account. To participate in SpaceInvasion, the user needs a BitMeUp account. Creation, administration and deletion take place via the BitMeUp portal (see above). All payment transactions are processed by Xsolla (see BitMeUp Payment). Use of the chat is subject to the chat usage rules (see BitMeUp Chat). The following game actions are logged with a timestamp:
The purchase or use of Urplasma (global as well as per universe) to acquire premium goods,
features or other game functions. The purchase of assistants, interdimensional transmitters,
energy reserves, free games at the interdimensional transmitter, gifts or other premium features.
The following data is recorded: • the user ID • the amount or the feature • the transaction number • the action • the timestamp Additional data received from Xsolla Inc.: • the user's IP address • the user's country code • the exact conversion rate of the transaction Please note: we do not store any payment information! This data is stored permanently until the SpaceInvasion portal account is deleted. This is necessary to be able to trace packages with longer runtimes and to record problems. We reserve the right to delete data that is no longer relevant at irregular intervals.
Game actions are logged.
Please assume that we log all game actions, including construction and demolition of buildings, research, fleet and defence construction, alliances and all fleet activities. This data is stored for 30–180 days depending on necessity.
In SpaceInvasion, various data (IP address, browser and system information) is collected and
subsequently evaluated for multi-account checks.
Furthermore, header and port queries are performed to detect the use of proxy providers. Please note that the use of anonymisation software is not tolerated under our Terms and Conditions! This data is stored for 60 days.
For actions that lend themselves to automation, or in the case of unusually
high action rates, a security check (“captcha”) may be required. It is
handled via Cloudflare Turnstile (see
Hosting, Cloudflare & Bot Protection);
alternatively we show our own image captcha without Cloudflare.
Damoria
The following data is recorded: • the user ID • what triggered the check (type of action) • the result (requested / solved / not solved) • the timestamp The check serves solely to detect bots and automation (Art. 6 (1) (f) GDPR). These logs are deleted as soon as they are no longer needed for evaluation. A BitMeUp account is required to use Damoria. The administration of the BitMeUp account is subject to the privacy rules of the BitMeUp portal. In Damoria itself, the following data may be provided voluntarily: • gender • birthday • place of residence • country This data can be deleted or changed at any time. Upon deletion of the Damoria account, this data is deleted as well. Payment processing is handled via Xsolla (see BitMeUp Payment). Use of the chat is subject to the chat usage rules (see BitMeUp Chat). The following game actions are logged with a timestamp:
The purchase of gold, the use of gold or premium features.
Payment actions are stored permanently until the account is deleted. This is necessary to be able to trace whether packages with long runtimes have been used. We reserve the right to delete log entries that are no longer relevant at irregular intervals.
All actions upgrading or downgrading a castle are logged.
Please assume that we log every game-relevant action concerning castles, treasury, market, premium and all troop actions. These action logs are deleted after 360 days.
In Damoria, various data (IP address, browser and system information) is collected and
subsequently evaluated for multi-account checks.
Mebula
This data is stored for 90 days. Players registered with Mebula use a BitMeUp account and/or Facebook account to participate in the game. For use via the BitMeUp portal: • registration, administration, login and deletion are handled via the BitMeUp portal. • all payment processing is carried out by Xsolla (see BitMeUp Payment). For use via Facebook, the Facebook API is used, which provides BitMeUp UG with the following data: • Facebook ID of the account • email address • your name This data is automatically deleted 90 days after deletion of the account. Facebook reserves the right to retain access and transactions of the Facebook payment interfaces for legal purposes and, in the event of chargebacks, to pass them on to BitMeUp or external agencies for prosecution. Use of the chat is subject to the chat usage rules (see BitMeUp Chat). The following game actions are logged with a timestamp. All these game logs are retained for 90 days.
The acquisition and use of in-game items, glyphs, runes, attacks, monsters
and premium features requiring silver, gold or items is logged.
Editing, releasing (deleting) or changing Mebulies (monsters) is logged.
A monster (Mebuly) is only completely deleted after 90 days.
As soon as a player is listed in a ranking, the name and the monster team
are stored for the duration of the placement in the ranking or as long as
the account has not been deleted.
Player characters are not deleted automatically by the system.
Nexus & Mebula Legends
Should a deletion by the operator be planned due to inactivity, the player will be informed by email well in advance of the deletion. A BitMeUp account is also required to participate in Nexus and Mebula Legends. Registration, administration, login and deletion are handled via the BitMeUp portal (see above); the sections BitMeUp Portal, BitMeUp Payment and BitMeUp Chat apply accordingly. In these games too, game-relevant actions (e.g. purchases and the use of premium features, combat and progression actions) are logged with a timestamp in order to be able to trace purchases and for abuse and fairness checks (Art. 6 (1) (b) and (f) GDPR). For multi-account checks, the IP address as well as browser and system information may be collected and evaluated. |