ServerQuay

Privacy

# Privacy Notice **Seller and responsible party:** ServerQuay, the trading name of ServerHarbor. Before launch, ServerQuay must publish the full legal identity and address of the responsible business and a working privacy/support contact. This notice describes the intended handling of personal information for the website and game-server hosting service. It must be checked against the actual storefront, payment provider, and hosting supplier before collection begins. ## Information we handle Depending on how you use the service, we may handle account details such as name, email address, login identifiers, subscription and cancellation status; transaction references, amounts, currency, and billing status from a payment provider (we do not intend to store full card numbers); support messages and information you choose to provide; and technical or service information such as IP address, device/browser data, access and security logs, server configuration, usage, and provisioning events. Game-server files or player information may be processed by the hosting supplier when needed to provide the server. Do not put unnecessary personal or sensitive information in a server, ticket, or public community. We receive information from you, your device, the payment processor, and hosting or infrastructure suppliers. We do not knowingly ask children for personal information or target them with marketing. The service account holder must meet the age requirement in the Terms. ## Purposes and legal bases We use information to create and secure accounts, take and reconcile subscription payments, provision and operate the requested server, provide support, handle cancellations and refunds, prevent fraud and abuse, meet legal obligations, resolve disputes, and improve reliability. Where GDPR applies, the relevant basis is generally contract performance, legal obligation, legitimate interests in security and service operation (balanced against your rights), or consent where required, such as for non-essential cookies or certain marketing. Under POPIA, processing is for a lawful, specific purpose and on an applicable justification. For US state privacy laws, this notice describes the relevant categories and purposes; applicable rights are explained below. ## Sharing and international processing We share only information needed with the payment processor, hosting/provisioning supplier, infrastructure or security providers, and professional advisers or authorities where necessary and lawful. These providers may process data in countries other than yours. Before launch, the seller must identify the actual providers, locations, and appropriate contractual safeguards, including GDPR transfer safeguards where required. We do not sell personal information or share it for cross-context behavioral advertising as a business practice. We do not use personal information for targeted advertising. We will update this notice if actual practices differ. ## Retention and security We keep information only as long as reasonably needed for the purposes above, including account operation, support, security, legal recordkeeping, and dispute resolution, then delete or de-identify it where practicable. Different records may have different legally required periods. The seller must define and implement a retention schedule before launch. Access is limited to people and providers who need it. Reasonable technical and organizational safeguards are used, but no system can be guaranteed completely secure. If a qualifying breach occurs, we will notify affected people and regulators when required by law. ## Your choices and privacy rights Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; appeal a decision; or complain to a regulator. South African data subjects may exercise rights under POPIA and complain to the Information Regulator. People in the EEA or UK may contact their data protection authority. Residents of US states with applicable privacy laws may request access, correction, deletion, portability, and opt out of sale, targeted advertising, or certain profiling; we do not sell or use targeted advertising as described above. We will not discriminate against you for exercising a right where prohibited by law. Send a request through the privacy/support contact published on the service. We may ask for reasonable information to verify the request and may retain information required by law or needed for security and disputes. If we cannot comply, we will explain why and provide any applicable appeal route. You may also complain to your regulator. A Data Protection Officer or representative will be identified if legally required. ## Cookies and similar technology Essential technologies may be used for account sessions, security, and service operation. Non-essential analytics or advertising cookies must not be enabled until the site gives any consent required by law. See the Cookie Notice if one is published. Browser controls can manage some cookies, but blocking essential cookies may affect functionality. ## Children The service is not directed to children and account holders must be adults as described in the Terms. We do not knowingly collect children’s personal information for marketing. If you believe a child has provided information, contact us through the published privacy route so we can assess and delete it where appropriate and legally required. ## Changes and contact We may update this notice to reflect changes in the service or law and will post the current version with its revision date. Questions and rights requests can be sent using the privacy contact published on the service. The complete business identity, contact route, provider list, retention schedule, and actual international-transfer arrangements must be completed before taking customer data.