Legal
Datenschutzerklärung - GDPR / DSGVO Art. 13 and TDDDG Section 25
Public contact is available through XYVRA Discord.
The web server and hosting environment may process connection data such as IP address, request time, requested URL, referrer, browser information and technical error data. The purpose is secure, reliable operation and abuse prevention. The typical legal basis is Art. 6(1)(f) GDPR, based on the legitimate interest in operating and protecting the service.
Hosting provider: Hustensaft. Retention: confirm the actual retention period with the hosting provider.
The site uses cookies required for authentication and security. Access to information stored on a device is governed by Section 25 TDDDG in addition to the GDPR.
xyvra_admin_sid: admin session cookie, HttpOnly, session based.xyvra_portal_sid: customer portal session cookie, HttpOnly, session based.xyvra_did: random pseudonymous device identifier used for login-abuse protection, HttpOnly, stored for up to one year.No analytics or advertising cookies are intentionally set by this codebase. The operator should verify the deployed hosting stack and any reverse proxy before making this statement publicly.
If you choose to sign in with Discord, you are redirected to Discord's OAuth service. After successful login, this site receives and stores in the session your Discord user ID, display name, discriminator and avatar identifier. The OAuth access token is used to request the profile and is not saved by this site after the callback.
The data is processed to provide the requested account and portal functions. Depending on the exact contractual setup, the relevant legal basis is generally Art. 6(1)(b) GDPR for account or service performance and Art. 6(1)(f) GDPR for security and abuse prevention. Discord processes data under its own privacy terms and may process data outside the EEA.
When you use the portal, the site may process your Discord user ID and display name together with license/account associations, reviews, suggestions, support tickets, uploaded base-find screenshots and related timestamps. Support tickets also store the email address and message you submit. This data is used to provide the requested portal functions, moderate submissions, provide support and protect the service against abuse.
Retention must follow the purpose and any statutory obligations. Reviews, suggestions, support tickets, license associations and moderation records currently remain stored until they are deleted by an administrator or the underlying data file is otherwise cleaned up. The operator should define and publish concrete deletion periods before launch.
Recipients can include the hosting provider and Discord where the corresponding function is used. If a provider processes data outside the EEA, the operator must ensure that the requirements of GDPR Chapter V are met and describe the transfer mechanism actually used by that provider.
Subject to the legal requirements, you may have rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Where processing relies on consent, consent can be withdrawn for the future. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
Confirm the real controller details, the hosting provider's legal identity and location, actual server-log retention, any processor agreements, the Discord transfer mechanism, deletion periods, and whether additional services are loaded in production. This policy reflects the supplied code, not unknown server-side services outside the archive.
Last reviewed: September 2026