Privacy Policy
1. General information
This privacy policy explains which personal data is processed when using the public Valcoran websites and related public functions.
Personal data means any information relating to an identified or identifiable natural person.
Personal data is processed only to the extent required for operating the websites, providing public functions, processing requests, ensuring the security of the service, fulfilling legal obligations or based on consent.
2. Controller
The controller responsible for data processing is:
Valcoran Projekt in Vorbereitung
Email:
support@valcoran.info
Contact page:
https://valcoran.info/support
3. Privacy contact
Privacy requests may be sent to:
If a separate privacy contact address is maintained, the following also applies:
4. Hosting and technical provision
The Valcoran websites are operated through an external hosting provider.
Hosting provider:
ALL-INKL.COM - Neue Medien Münnich
Hosting address:
Hauptstraße 68, D-02742 Friedersdorf, Deutschland info@all-inkl.com +49 35872 353-10
Hosting location:
Deutschland (Europäische Union)
The hosting provider processes technical data to the extent required for provision, operation, security, error analysis and stability of the websites.
5. Access data and server log files
When the websites are accessed, technical access data may be processed automatically.
This may include in particular:
- IP address
- date and time of access
- requested URL
- referrer URL
- browser type and browser version
- operating system
- device used
- HTTP status code
- transferred data volume
- hostname of the accessing system
- technical error and security information
This data is processed to technically provide the websites, ensure security, analyze errors, detect misuse and maintain stable operation.
The legal basis is the legitimate interest in a secure, stable and functional web offering.
6. Cookies and device information
The websites may use cookies or comparable technical storage mechanisms.
Technically necessary cookies may be used in particular for:
- language settings
- session functions
- security functions
- maintenance mode control
- protection against misuse
- storing necessary technical settings
Where cookies or comparable technologies are technically necessary, they are used to provide the function requested by the user.
Non-essential cookies, in particular for analytics, marketing or external tracking services, are used only if valid consent has been given.
7. Language settings
The websites may store a language selected by the user.
In particular, a language cookie may be processed to provide content in German or English.
This processing serves user-friendly presentation of the website.
8. Maintenance mode and authorized access
During maintenance, technical incidents or full website lockdown, technical information may be processed to control website status and enable authorized internal access.
This may include in particular:
- maintenance status
- language setting
- technical session data
- bypass-related security information
- timestamps of use
- IP address or IP hash
- user agent or user agent hash
This processing serves secure operation, prevention of misuse and controlled technical administration.
9. Contact by email
If users contact us by email, the transmitted data is processed.
This may include in particular:
- name
- email address
- subject
- message content
- time of the request
- technical email data
Processing is carried out to handle the respective request, communicate with the user and maintain traceability.
10. Support form and support tickets
If a support form or support system is used, personal data may be processed.
This may include in particular:
- name
- email address
- language
- category
- subject
- message
- ticket number
- public ticket token
- status
- priority
- first accessed URL
- technical information about the request
- internal processing notes
- public replies
- timestamps of creation, reply and status changes
Support data is used to process requests, enable replies, maintain traceability and prevent misuse.
11. Email delivery and notifications
Email data may be processed for confirmations, support replies or system-related messages.
This may include in particular:
- recipient address
- sender address
- reply-to address
- subject
- message content
- delivery status
- sending time
- technical provider identifiers
- error messages in case of delivery problems
This processing serves delivery, delivery control and error analysis.
12. Reviews and user contributions
If users submit reviews, ratings or other contributions, personal data may be processed.
This may include in particular:
- display name
- email address
- rating scores
- individual ratings
- review text
- language
- time of submission
- moderation status
- technical security information
Reviews and contributions may be displayed publicly after review.
The email address is generally not displayed publicly but may be processed internally for misuse prevention, follow-up questions, moderation and blocking checks.
13. Media, content and public pages
When public pages, media, images or other content are accessed, technical access data may be processed.
This concerns in particular:
- homepage
- game information
- news
- roadmap
- media area
- FAQ
- field guide
- reviews
- support pages
- legal pages
Processing is carried out for technical provision of the content, security and error analysis.
14. Security measures and misuse protection
Technical and organizational protective measures may be used to secure the websites.
These include in particular:
- access restrictions
- protection of sensitive paths
- maintenance mode
- CSRF protection for forms
- session protection
- input validation
- logging of security-relevant events
- protection against automated misuse
- hashing or truncation of technical identifiers where appropriate
These measures serve to protect against unauthorized access, manipulation, loss, misuse and unintended disclosure.
15. Legal bases of processing
Personal data is processed depending on the purpose on the following legal bases:
- consent, where explicit consent is required
- performance of a contract or pre-contractual measures, where a request or service is processed
- legal obligation, where statutory obligations apply
- legitimate interest in operation, security, error analysis, misuse prevention, communication and traceability
Where processing is based on legitimate interest, this interest lies in particular in secure, stable and traceable operation of the websites and offered functions.
16. Recipients of personal data
Personal data is transferred only if this is required for the respective purpose, legally permitted or legally required.
Possible recipients include in particular:
- hosting providers
- email service providers
- technical infrastructure providers
- internally authorized processors
- legal or public authorities where required
No transfer for advertising purposes takes place without a legal basis.
17. Transfers to third countries
A transfer of personal data to countries outside the European Union or the European Economic Area takes place only if this is required for services used and the legal requirements are met.
Where possible, services with processing within Germany or the European Union are preferred.
18. Storage period
Personal data is stored only as long as required for the respective purposes.
Guidance values:
- technical server logs: as long as required for operation, error analysis and security
- contact requests: as long as required for processing and traceability
- support tickets: as long as required for processing, traceability and quality assurance
- reviews: as long as they are published or required for moderation and misuse protection
- security data: as long as required for security review and misuse detection
- legally relevant evidence: according to statutory or legitimate retention interests
If data is no longer required, it is deleted or anonymized unless retention obligations prevent this.
19. Rights of data subjects
Data subjects have the following rights within the framework of legal requirements:
- right of access
- right to rectification
- right to deletion
- right to restriction of processing
- right to data portability
- right to object
- right to withdraw consent
- right to lodge a complaint with a competent supervisory authority
Requests may be addressed to the privacy contact:
20. Withdrawal of consent
If processing is based on consent, this consent may be withdrawn at any time with effect for the future.
The lawfulness of processing before withdrawal remains unaffected.
21. Objection to processing based on legitimate interests
If personal data is processed based on legitimate interests, data subjects may object on grounds relating to their particular situation.
In the event of an objection, it will be reviewed whether compelling legitimate grounds for processing exist or whether processing can be stopped.
22. Requirement to provide data
Providing personal data is generally voluntary.
However, certain functions can only be used if the required data is provided.
This applies in particular to contact requests, support tickets, reviews or security-relevant functions.
23. Automated decisions
According to the current status, no automated decision-making in the sense of a legally significant automated individual decision takes place.
24. Updates to this privacy policy
This privacy policy will be updated if technical functions, data processing activities, service providers used, legal requirements or responsibilities change.
Changes are stored as versioned records so that previous versions remain traceable.