Skip to content
RECLAIMWARD
The gameFeaturesWorldField notesForumMediaFAQSupport
Account
Sign inCreate account

RECLAIMWARD / Legal information

Privacy policy

Updated: 09.09.2026 · 2026-09-09.6

How we process personal data for our website, free account portal and optional newsletter. This policy covers reclaimward.com and reclaimward.de where it points to our service.

Contents
  1. Controller and privacy contact
  2. Purposes and legal bases
  3. Website access and hosting
  4. Registration and account administration
  5. Character profiles and APIs
  6. Sessions, login records and security
  7. Newsletter and consent
  8. Contact and support
  9. Recipients and international transfers
  10. Retention and deletion
  11. Your rights
  12. External links
  13. Adults only
  14. Changes
  15. Public forum, reports and moderation
  16. Steam connection and license verification
  17. Two-factor authentication
  18. Notifications and private support tickets
  19. CMS extensions: drafts, bug reports and game servers

1. Controller and privacy contact

Controller under the GDPR: Kevin Rasch, Nateweg 9a 45896 Gelsenkirchen, Deutschland. Email: support@reclaimward.com.

Privacy contact and appointment status: Eine datenschutzbeauftragte Person ist derzeit nicht bestellt. Nach aktueller Einschätzung besteht keine Benennungspflicht nach Art. 37 DSGVO und § 38 BDSG; Datenschutzanfragen bearbeitet der Verantwortliche.

You do not need an account to exercise privacy rights and may contact us after suspension or termination.

2. Purposes and legal bases

We process data to provide requested functions, communicate with you, secure the service and meet legal obligations. Account data is not sold. The newsletter is optional and is not required for an account.

Necessary contract and pre-contract processing relies on GDPR Article 6(1)(b); consent on Article 6(1)(a); specific legal obligations on Article 6(1)(c); necessary security and abuse prevention on Article 6(1)(f). Our legitimate interests are protecting accounts, availability and users’ rights, balanced against your interests. Accepting the Account Terms is not blanket consent to advertising or data processing.

3. Website access and hosting

Requests involve the IP address, time, requested resource, response status and browser/operating-system details. Depending on server configuration, transfer volume and referrer may also be recorded. Delivering and protecting the website relies on Article 6(1)(f).

The production host is ALL-INKL.COM – Neue Medien Münnich, proprietor René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. An Article 28 GDPR processing agreement covers production hosting. According to the provider, hosting is delivered on its own servers in Germany. Hosting/server log retention: Im ALL-INKL-KAS ist für die für den Betreiber abrufbaren Webserver-Logdateien eine Aufbewahrung von 7 Tagen eingestellt. Technisch erforderliche Sicherheitsprotokolle des Hostinganbieters können nach dessen Vertrags- und Datenschutzbedingungen abweichend verarbeitet werden; bei Änderung der Einstellung wird diese Angabe aktualisiert. These logs are separate from application security records.

Simply reading public information pages does not create an application session cookie. Sessions begin for requested form and account functions; see Cookies and local storage.

4. Registration and account administration

We need an email address, password and display name. Records include a random account ID, language, status, role, timestamps, verification status and security/login information. Passwords are stored as hashes, not plaintext. A pseudonym is allowed.

You separately confirm that you are at least 18. We retain the time of that statement, accepted version and language of the Account Terms, their text including incorporated Community Rules, and an integrity hash. The ordinary registration process does not collect a date of birth or identity document. These records evidence the agreement under Article 6(1)(b), and, where necessary for a specific dispute, Article 6(1)(f).

Email verification, recovery and email changes use expiring security links. Related messages and password/email-change alerts are service messages, not newsletter advertising. Without necessary account details an account cannot be provided; some functions require email verification. The newsletter, public pages and accounts are separate services.

Your display name is chosen during registration and initially remains internal. Posting with your account publishes it as that post’s author name. You cannot change it yourself after registration; only an administrator can change it after reviewing a support request. You may instead select one of your own characters as the public identity for a post. See the forum section for details. While the Steam feature is disabled, the website starts neither new Steam links nor ownership checks. Existing links can still be removed.

5. Character profiles and APIs

We retain linked character IDs, names, professions, status and timestamps, and available profile/progression fields such as level, XP and skills. The site holds central profiles. Live game transfer begins only after the operator enables a game server in the admin area and assigns a character; section 19 gives details. Requested profile management relies on Article 6(1)(b) GDPR.

Character profiles start private. In your account you may publish an individual active character with its name, profession, selected emblem and biography. Level and XP require a separate choice. Publication is based on your consent under Article 6(1)(a) GDPR, which you may withdraw at any time in character settings with effect for the future. Names and professions in existing forum posts remain visible under the forum rules. This does not publish your email, account ID, other characters or undisclosed game statistics.

6. Sessions, login records and security

Authenticated-session records contain account association, a protected session reference, IP address, shortened browser identifier and timestamps. Login records include outcome, time, account association where available, and pseudonymised email/IP identifiers. Pseudonymised information is not necessarily anonymous.

Rate limits help prevent password attacks and abuse. Administrative audit records identify actor, event, target and time. These measures rely on Article 6(1)(f); necessary session administration also relies on Article 6(1)(b). Requests may be temporarily blocked on reaching limits. Solely automated decisions with legal or similarly significant effects under Article 22 are not intended. Lasting administrative suspensions involve authorised people and can be challenged.

7. Newsletter and consent

Only a separate subscription followed by confirmation of the verification link adds you to the confirmed recipient list. We retain email, language, subscription/confirmation times, consent version and wording, and confirmation/unsubscription security references.

Consent covers the operator’s RECLAIMWARD emails about development, devlogs, tests, releases and community news. The bases are GDPR Article 6(1)(a) and section 7(2) no. 2 of the German Unfair Competition Act. Subscription is not tied to account access and is not shared with unrelated advertisers.

Withdraw at any time using the unsubscribe link or support@reclaimward.com, with no costs beyond ordinary transmission costs. Earlier lawful processing is unaffected. Unsubscription removes the subscription record from the active list. There are no open-tracking pixels or personalised click profiles. Advertising campaign delivery is not yet configured; additional future mailing providers will be identified before use.

8. Contact and support

We process your contact details, message and information needed to handle the request under Article 6(1)(b) for contract/account matters, or Article 6(1)(f) for other legitimate enquiries and security reports. Mail/support provider: ALL-INKL.COM – Neue Medien Münnich, Inhaber René Münnich, Hauptstraße 68, 02742 Friedersdorf, Deutschland; Versand und Postfächer über Server in Deutschland. Support/service mail retention: E-Mails werden gelöscht, sobald die jeweilige Anfrage abschließend bearbeitet ist und keine gesetzliche Aufbewahrungspflicht oder erforderliche Rechtsverteidigung entgegensteht. Für das allgemeine Supportpostfach besteht derzeit keine starre Regellöschfrist; maßgeblich sind diese Kriterien und eine regelmäßige Erforderlichkeitsprüfung..

Provide only necessary information. We do not request passwords or recovery tokens in ordinary support. If there are reasonable doubts about the identity of someone exercising privacy rights, we may request additional information necessary to verify identity.

9. Recipients and international transfers

Access is limited to people needing it for operation, support or administration, and relevant hosting/mail or other service providers. Article 28 agreements are required where they act as processors. Necessary disclosures to courts, authorities or professional advisers require a specific legal obligation or a legitimate need to establish, exercise or defend claims.

Transfers outside the EEA: Hosting sowie Support- und Transaktionsmail werden bei ALL-INKL.COM in Deutschland verarbeitet. Es sind keine Analyse- oder Werbedienste eingebunden. Beim bloßen Anklicken externer Links gilt die Datenschutzerklärung des jeweiligen Anbieters. Solange die Steam-Verknüpfung deaktiviert ist, erfolgt durch diese Website keine automatisierte Übermittlung an Valve.. Where applicable, the recipients, countries and Article 44 et seq. basis must be identified, such as an applicable adequacy decision or appropriate safeguards. We do not obtain blanket consent to worldwide transfers. International visitors alone do not establish that we transfer data to an overseas processor.

10. Retention and deletion

Data is retained for its purpose or a specific legal basis requiring continued retention. Technical cleanup periods below depend on the operator maintaining the scheduled cleanup job.

  • Accounts and character profiles: while providing the account, followed by deletion of unnecessary data after termination or a valid erasure request. Deactivation is not deletion. “Request account deletion” suspends access and creates a request for handling, not immediate complete erasure.
  • Age statement and accepted terms: stored in the account to evidence the agreement during the relationship; removed on ordinary full account deletion. Evidence needed for a specific dispute is separately restricted to that purpose.
  • Verification/email-change links: 24 hours. Password reset: 30 minutes. Used or expired token records are removed.
  • Browser login: 30 minutes idle, 12 hours absolute. Expired session references are cleaned up; native private session files are removed by cleanup after more than 24 hours without modification.
  • API access token: 15 minutes. Refresh family: at most 30 days from initial issue, not extended by rotation; cleaned after expiry.
  • Login events and last login IP: 90 days. General audit events: 180 days. Necessity is reviewed during operation; incident evidence is retained separately only where required in a specific case.
  • Rate-limit records: the applicable window, currently one minute, 15 minutes or one hour, then cleanup.
  • Unconfirmed newsletters: 24-hour confirmation period followed by cleanup. Confirmed subscriptions: until withdrawal or ending the newsletter.
  • Application error logs contain reduced diagnostic details, not form data or access tokens. Rotation is size-based; rotated files are removed after 90 days. Hosting logs follow their separate stated period.
  • Backups: Eigene verschlüsselte CMS-Sicherungen werden manuell oder nach dem im Admin-Menü gewählten Intervall erstellt. Das System bewahrt die dort festgelegte Anzahl von 2 bis 30 Sicherungen auf und entfernt beim Überschreiten die ältesten. ALL-INKL.COM gibt für seine Systeme tägliche Vollsicherungen an; deren Rotation richtet sich nach dem Hostingvertrag und liegt außerhalb der normalen Nutzung durch den Betreiber.. Pending scheduled expiry, deleted data in backups is restricted from normal use. Restores must reapply prior deletions; backups do not permit indefinite operational reuse.

11. Your rights

Subject to statutory conditions you may request access, rectification, erasure, restriction and portability under Articles 15–20. Consent can be withdrawn for the future. You may object to Article 6(1)(f) processing for reasons relating to your particular situation; objection to direct marketing needs no reason and ends that processing.

Contact support@reclaimward.com. We respond without undue delay, normally within one month. If complexity or number of requests justifies an Article 12(3) extension, we explain the extension and reasons within the first month. Any applicable exceptions are explained individually. Account editing/export tools assist but do not replace or restrict these rights, and a blocked account does not prevent a request.

You may complain to a supervisory authority, particularly where you habitually reside or work, or where an alleged infringement occurred, under Article 77. The operator’s competent authority: Landesbeauftragte für den Datenschutz Sachsen-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, https://datenschutz.sachsen-anhalt.de/. You need not contact us first.

12. External links

Discord, YouTube, X, TikTok and Steam store pages are linked where configured. External players or tracking pixels are not automatically loaded when visiting this site. The separately initiated Steam account connection is described below.

13. Adults only

Accounts are exclusively for adults aged 18 or over. This does not certify that all publicly accessible game images, trailers or future content meet every applicable youth-protection requirement; those are assessed separately. If we learn of a minor’s account, we review and take proportionate action, including suspension and necessary erasure. We do not routinely request identity copies from everyone.

14. Changes

We update this policy when functions, processing or legal requirements change. The version identifies its date. New purposes are explained before further processing and any necessary new consent is requested separately; updating a policy cannot substitute for consent.

15. Public forum, reports and moderation

Activation records an optional selected character association, acceptance time, language, version, wording and hash. Posts record content, topic, category, language, the selected account display name or character name/profession at posting, times, revision number and genuine staff label where applicable. Visible content and these author details are public; internal account associations and email addresses remain private. Requested publication and agreement records rely on Article 6(1)(b).

Likes internally record post, user and time; only counts are public. Bookmarks are private to their owner. There are no direct messages, user file attachments or behavioural recommendation profiles. Search uses titles and text; lists sort by pinned state and activity.

Reports retain post reference, category, grounds, name/email where provided or required, any reporter account association, times, status and decision. Random private tracking keys are stored as hashes. Reporter details are limited to authorised reviewers. This supports investigating unlawful content and protecting people under Article 6(1)(c) where a legal duty applies, otherwise (f). Sensitive data voluntarily included is handled only where necessary and lawful; please avoid unnecessary sensitive details.

Moderation notices and necessary emails explain decisions. The delivery queue retains recipient, language, text and times, deletes successfully delivered messages and retries failures. Undelivered queue entries are removed after 30 days. The operator monitors failures and considers required alternative follow-up. Mailbox retention follows the actual period stated above.

Public posts remain for the requested discussion until removed or continued storage is no longer justified. Self-removal clears active text and public author details for that post, leaving a neutral marker. Account erasure requests require the operator to review and implement necessary removal or anonymisation in context. Hidden posts become empty markers after 180 days unless earlier erasure or separately justified evidence retention is required. Closed reports and moderation notices are cleaned after six months; open reports remain for necessary handling with ongoing necessity review. Bookmarks, likes and membership evidence are removed with complete account deletion. Backup periods apply as stated above.

16. Steam connection and license verification

When you choose to link Steam, you are redirected to Steam to sign in. Steam is operated by Valve Corporation in the United States, which is independently responsible for data processed there. We receive a Steam-confirmed Steam ID. Your Steam credentials are entered only at Steam and are not stored by us. Valve privacy information: https://store.steampowered.com/privacy_agreement/.

For the requested character feature, our server sends the Steam ID and game identifier to the Steamworks interface. We store the Steam ID, derived profile link, identity verification time, game identifier, license result and check time. Verification associates your account and establishes eligibility for the character feature under Article 6(1)(b) GDPR. We do not request your full game library, friends list, payment details or Steam password.

A confirmed result is reused for new characters for no more than five minutes, after which it is checked again. Signing in, reading public pages and using support do not require Steam linking. New characters cannot be created without a confirmed own permanent license. Contact support if verification fails; license verification is not proof of a personal payment.

You can unlink Steam after confirming your password. This removes the Steam association and verification result from your active account. Existing characters are not deleted. Technical one-time values prevent callback replay and expire after ten minutes; expired values are removed at the next maintenance run. Security events without Steam credentials follow the stated audit retention period.

Connections to Valve can involve transfers to the United States. The recipient is Valve Corporation, P.O. Box 1688, Bellevue, WA 98009, USA. Valve states in its privacy policy that it participates in the EU-U.S. Data Privacy Framework. The operator checks the current certification status before enabling this feature and periodically thereafter. Current operating status and safeguards: Noch nicht aktiv. Valve details: https://store.steampowered.com/privacy_agreement/. A link to Valve’s policy does not replace our own assessment.

17. Two-factor authentication

If enabled, we store an encrypted authenticator secret, activation time and the last used time step. Recovery codes are displayed in plain text only once and then stored only as hashes. Each code works once. Security events record setup, removal and recovery without code contents. Processing protects accounts and administrative powers under Article 6(1)(f) GDPR. A second factor is required for moderation and administration.

Unfinished setup and sign-in verification expire after ten and five minutes respectively. The configured secret is removed when the second factor is disabled or the account is permanently deleted; used recovery codes are deleted immediately. New codes replace old ones. Your chosen authenticator app is a separate service; no external QR-code provider is embedded.

18. Notifications and private support tickets

For replies, mentions and subscribed topics we store the account and post association, notification type and time, and read state. Topic subscriptions and the last read post position are account-specific. Topics you create or reply to are initially subscribed. You may unsubscribe on the topic. These functions provide requested community features under Article 6(1)(b) GDPR. They are not used for advertising, audience analytics or cross-profile tracking. Notifications are deleted after 90 days and inactive read positions after 180 days at the next maintenance run. Subscription preferences remain until changed or the account is deleted.

Private support tickets contain the account association, an optional own character, subject, category, messages, processing status, timestamps and reply history. Only the owner and authorized administrators have access; the moderator role does not grant access. Processing is based on Article 6(1)(b) GDPR for contractual requests, otherwise Article 6(1)(f) to address the request; legally required processing relies on Article 6(1)(c). Closed tickets and their history are removed at the next maintenance run 180 days after the last update. Open requests remain pending resolution and are regularly reviewed for continued need.

Support replies create account notifications. The new reply and mention notifications do not send additional marketing or support emails. Data export includes your tickets, history, subscriptions, read positions and notifications. It excludes authenticator secrets and recovery codes.

19. CMS extensions: drafts, bug reports and game servers

When you choose Save draft in the forum, we store the text, title, selected character and category privately in your account. Drafts are not public. Unchanged drafts are removed by maintenance after 30 days; publishing removes a matching draft. Your account export includes saved drafts.

Bug reports can contain the game version, server name, reproduction steps, expected behavior and actual behavior. Authorized administrators assign a priority and may internally link duplicate reports. This does not disclose other reporters’ information to you. Support ticket access rules and retention periods apply.

If the operator connects a game server, it may report status and player counts. When progression mode is also enabled, it sends level, experience, total play time and update time for explicitly assigned characters. The website also stores server assignment and a technical sequence number to reject stale messages. This supports the requested character service under Article 6(1)(b) GDPR. Public profiles still require the existing visibility choice. Assignments and play time records are removed when a character is fully deleted and are included in the account export.

Encrypted CMS backups contain the database, uploaded images and private configuration. Administrators set backup frequency and how many backups to keep. Actual retention must be documented under Eigene verschlüsselte CMS-Sicherungen werden manuell oder nach dem im Admin-Menü gewählten Intervall erstellt. Das System bewahrt die dort festgelegte Anzahl von 2 bis 30 Sicherungen auf und entfernt beim Überschreiten die ältesten. ALL-INKL.COM gibt für seine Systeme tägliche Vollsicherungen an; deren Rotation richtet sich nach dem Hostingvertrag und liegt außerhalb der normalen Nutzung durch den Betreiber.. Restore tests use temporary staging tables that are removed after testing. Restoring a backup revokes active sessions and API access; previous erasures must be applied again. No additional analytics or advertising services are embedded.

Legal notice ↗Cookie settings ↗Terms of use ↗Account terms ↗Forum Terms ↗Community guidelines ↗
RECLAIMWARD

A world in development. A future built together.

Development newsletter ↗
Server statusDevelopment status
© 2026 RECLAIMWARD
Legal noticePrivacy noticeCookie settingsTerms of useAccount termsForum TermsCommunity guidelines