Privacy
ZentWorld is designed around data minimisation. There is no registration, no freely chosen public profile, no advertising and no marketing trackers. Only privacy-minded daily operational metrics are collected for internal statistics.
Anonymous device ID
For the core service ZentWorld uses a random internal visitor/device ID and technically necessary local browser data. Only after you confirm your first participation is a public builder identity with an automatically generated alias activated. The internal UUID is never shown publicly.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in reliably providing the shared world and recognising your daily participation). Where technically necessary information is stored on or read from the terminal device, this is done under section 25(2) no. 2 TDDDG insofar as it is strictly necessary to provide the digital service expressly requested by you.
IP address and abuse protection
The application does not store the raw IP address in the database. For abuse protection, the server creates an HMAC-SHA-256 value from the IP address, the current UTC day and a secret server key. A plain hash is deliberately not used because IPv4 addresses have a small search space. The stored HMAC rotates daily and is removed automatically after a configurable short retention period.
Pseudonymised identifiers can still qualify as personal data under data-protection law. This page therefore describes the processing rather than claiming that the values are legally “anonymous”.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is protecting ZentWorld against abuse, repeated use, manipulation and attacks and ensuring stable operation.
Stored game data
PostgreSQL stores, in particular, the internal visitor UUID, creation/usage timestamps, builder ID and alias after participation, daily build actions, builder-triggered plots, construction/completion data, badges, world and settlement data and internal events. For internal visitor statistics, a rotating HMAC is used once per UTC day to deduplicate visits; only the aggregated visitor total for that day is retained long-term. Archived worlds contain frozen world, plot, ranking and builder statistics. Only specifically intended pseudonymous information such as builder alias, plots and game statistics is public.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is the durable and traceable operation of the persistent game world, attribution of pseudonymous contributions, awarding badges and rankings and providing world archives.
Internal world captures and timelapses
ZentWorld may automatically create internal screenshots and timelapses of the virtual world. These media contain only the virtual world with roads, plots, places and buildings plus general world statistics such as world code, world type, day, date, time and aggregate counts. They do not contain IP addresses, visitor or builder IDs, owner markers, presence data or admin information.
Legal basis: Where generated world captures and timelapses contain only non-personal virtual-world content and general world statistics, no GDPR legal basis is required for the media themselves. Where pseudonymous game data is processed temporarily during technical generation, this is based on Article 6(1)(f) GDPR for the legitimate interest in documenting, administering and presenting world development.
Cookies
The device cookie is required for the core function. A separate admin-session cookie is only set after a successful admin login. A technically necessary first-party cookie stores the selected language. No marketing cookies are set.
Legal basis: Section 25(2) no. 2 TDDDG applies to technically strictly necessary cookies and local browser information. Where identifiers used in this context are personal or pseudonymous, subsequent processing is based on Article 6(1)(f) GDPR for the legitimate interest in core functionality, language selection, security and administration of the service.
Server logs
The application itself does not write raw IP addresses to its PostgreSQL database. Infrastructure and access logs may nevertheless be created during technical operation. These can contain technically necessary connection data such as IP address, time, requested resource and browser/protocol information.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is error analysis, system security, abuse detection and ensuring stable technical operation.
Retention
The daily IP HMAC is removed after the short server-configured retention period. The daily HMAC used only to deduplicate visitor counts is deleted after a few days; only the anonymous daily total is retained. Game and world data generally remain available for as long as they are needed for the persistent world, archives, rankings and abuse protection. Technical infrastructure logs may be subject to separate retention periods set by the relevant providers.
Legal basis: Retention does not have a separate additional legal basis; it follows the legal basis stated for the respective processing and the storage-limitation principle in Article 5(1)(e) GDPR.
Your rights
Depending on applicable data-protection law, you may have rights including access, rectification, erasure, restriction, data portability and objection. You may also lodge a complaint with a data-protection supervisory authority. Because ZentWorld deliberately operates without accounts or real names, a suitable way of showing that a request relates to your local builder identity may be necessary for some requests.
Legal basis: Where personal data is processed to handle a data-protection request, this is carried out in particular to comply with legal obligations under Article 6(1)(c) GDPR in conjunction with the GDPR data-subject rights.
Hosting and technical infrastructure
ZAP-Hosting
The virtual server running ZentWorld is hosted by ZAP-Hosting GmbH. Technically necessary connection and server data may be processed to provide, stabilise and secure the server.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is secure, available and performant hosting infrastructure. Where the provider acts as a processor, the requirements of Article 28 GDPR also apply.
Provider privacy policy · Further provider information
Cloudflare
Cloudflare is placed in front of ZentWorld as a reverse proxy/CDN. It is used in particular for DDoS protection, secure delivery and caching. Part of the connection therefore passes through Cloudflare, which may process technically necessary connection data including the IP address.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is in particular DDoS protection, secure delivery, availability and efficient provision of ZentWorld. Where Cloudflare acts as a processor, the requirements of Article 28 GDPR also apply.
Provider privacy policy · Further provider information
Controller and contact
The controller contact details are listed in the legal notice. For privacy questions or requests regarding your data, use the contact address listed there.
Legal basis: Providing controller information itself fulfils a statutory transparency obligation. Where you contact the controller about data-protection matters, the necessary processing is carried out in particular under Article 6(1)(c) GDPR; Article 6(1)(f) GDPR may apply to other enquiries.