Privacy • GDPR • Transparency
We take the protection of your personal data seriously and comply with applicable data protection laws, in particular the General Data Protection Regulation (GDPR).
Last updated: 14 September 2026
Cloud Spheres UG (haftungsbeschränkt)
Represented by: Silas Noel Timmermann and Alan Khudhur (Managing Directors)
Biberweg 24, 33102 Paderborn, Germany · HRB 18602, District Court Paderborn
Email: [email protected]
Data Protection Officer:
The obligation to appoint a Data Protection Officer pursuant to Art. 37 GDPR / § 38 BDSG is being kept under review. Until a formal appointment, data-protection inquiries are handled directly at [email protected]. Once a DPO is appointed, their contact details will be published here.
This Privacy Policy explains how we collect, process, and use your personal data when you visit our website or use our services (e.g., game servers).
We process personal data for the following purposes:
We process the following data:
Processing is based on Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligation), Art. 6(1)(f) GDPR (legitimate interests in a secure and reliable operation of our services) and, to the extent we obtain consent (e.g. for optional cookies or a newsletter), Art. 6(1)(a) GDPR.
Customer content is processed on certified infrastructure in European data centres. Infrastructure providers in use:
We engage the following processors with whom data-processing agreements pursuant to Art. 28 GDPR are in place. The complete, continuously maintained list is available at cloud-spheres.com/subprocessors:
Further processors
For business communication, support tickets and CRM we use Microsoft 365 (Microsoft Ireland Operations Limited) with the EU Data Boundary enabled. Application-error telemetry optionally uses Sentry (Functional Software, Inc.) with PII scrubber and IP anonymisation. Tax advisors and authorities receive data only within the legally required scope (Art. 6(1)(c) GDPR). The full list with respective safeguards is available at cloud-spheres.com/subprocessors.
Third-Country Transfers
Data is processed primarily within the EU/EEA. Third-country transfers may arise from the use of Cloudflare, Inc., Stripe, Inc., ActiveCampaign, LLC (Postmark), Microsoft Corporation and Functional Software, Inc. (Sentry). Google LLC (USA) is added by the use of Google Analytics 4; unlike the five recipients named above, that transfer takes place only if you have consented to the “Analytics” category in the cookie banner, and it ends when you withdraw that consent. Such transfers are safeguarded by EU Standard Contractual Clauses (SCC, Module 2/3, Art. 46(2)(c) GDPR) and, where available, by the EU-US Data Privacy Framework adequacy decision. Supplementary measures: client-side AES-256 encryption of backups before off-site transfer, encryption keys held exclusively in the EU, Microsoft EU Data Boundary active, AWS processing exclusively in EU regions.
In the event of security incidents, abuse, or unlawful use, we may share relevant usage data with our infrastructure partners and, where applicable, competent law enforcement authorities. This is done in accordance with Art. 6(1)(f) GDPR (legitimate interest in preventing misuse) or Art. 6(1)(c) GDPR where there is a legal obligation.
We retain your data only as long as necessary for the respective purposes or where statutory retention obligations apply. For example, tax-relevant records may be retained for up to 10 years under § 147 AO (German Fiscal Code). In particular, your billing name and address are stored immutably in issued invoices and retained for 10 years under § 147 AO even after you request account deletion; only your live billing profile fields are anonymised within 30 days.
As a data subject, you have comprehensive rights with respect to your personal data.
| Right | Description | Legal basis |
|---|---|---|
| Access | Right to access your stored personal data | Art. 15 GDPR |
| Rectification | Right to correct inaccurate data | Art. 16 GDPR |
| Erasure | Right to have your data deleted | Art. 17 GDPR |
| Restriction | Right to restrict processing | Art. 18 GDPR |
| Data Portability | Right to receive and transfer your data | Art. 20 GDPR |
| Object | Right to object to processing | Art. 21 GDPR |
| Withdraw Consent | Consent you have given may be withdrawn at any time with effect for the future | Art. 7(3) GDPR |
You can exercise all GDPR rights listed above directly through your account dashboard or by contacting us at [email protected]. We respond to all requests within one month as required by Art. 12 GDPR. For complex requests, this period may be extended by up to two further months with prior notification.
If you believe your rights have been violated, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). See the "Contact & Supervisory Authority" section below.
We implement appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR to protect your data against loss, destruction, and unauthorized access, alteration, or disclosure:
Please note that, despite these measures, the transmission of data over the internet (e.g. when communicating by email) can have security vulnerabilities; complete protection against access by third parties is not technically possible.
Our services are intended for persons aged 18 and over. Minors may only use our services with the consent of their legal guardians; details are governed by our Terms of Service. Where, in individual cases, we base processing on consent and the offer is made directly to a child, processing in relation to children under the age of 16 is lawful only to the extent that consent is given, or authorised, by the holder of parental responsibility (Art. 8 GDPR). If we become aware that a child's data has been transmitted to us without the required consent, we will delete that data.
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects or similarly significantly affects you. Decisions regarding contract acceptance or termination are made by our team manually.
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data processing practices.
If you have any questions or concerns about privacy, feel free to reach out to us at any time.
Contact us directly with general or privacy-related questions.
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
You also have the right to contact any other data protection supervisory authority (Art. 77 GDPR).