1. Data We Collect

We collect the minimum data required to operate the Service:

Email address
Account management and service communications.
Relayed messages
Service delivery โ€” forwarding in-game radio transmissions to the WebSocket service.
IP addresses
Security and rate-limiting purposes.
๐Ÿ”’

Player identifiers are hashed client-side using SHA-256 before transmission. This prevents Codex Dev from ever receiving raw identity data. Pseudonymized data is still considered personal data, and we treat it accordingly.

2. Legal Basis for Processing

Email address
Processed on the basis of contract performance โ€” necessary to provide and manage your account.
Message relay
Processed on the basis of legitimate interests โ€” required to deliver the core functionality of the Service.

3. Retention Periods

Data type Retention
Email address Duration of active account, plus 30 days after deletion
Relayed messages Transient processing only โ€” not stored
IP logs Maximum 30 days
Financial records 7 years (Dutch tax law requirements)

4. Your Rights under GDPR

If you are located in the EU or EEA, you have the following rights regarding your personal data:

  • Access โ€” request a copy of the data we hold about you
  • Correction โ€” request rectification of inaccurate data
  • Deletion โ€” request erasure of your personal data
  • Restriction โ€” request that we limit processing of your data
  • Portability โ€” receive your data in a structured, machine-readable format
  • Objection โ€” object to processing based on legitimate interests

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

5. Sub-processors and International Transfers

We share data with the following sub-processors:

Stripe
Payment processing. Codex Dev accesses only invoices and subscription status.
AI provider
Content generation for NPC survivor responses.
Cloudflare
Infrastructure, DDoS protection, and content delivery.

International transfers outside the EEA are carried out using Standard Contractual Clauses (SCCs) or sub-processors certified under the EUโ€“US Data Privacy Framework.

6. Contact

Questions or requests regarding this Privacy Policy should be sent to [email protected].

You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).