Privacy Policy
This draft must be reviewed by qualified counsel and completed with Pijon’s final legal entity, address, company number, vendors, retention periods, and transfer mechanisms before production use.
1. Who we are
Pijon is operated by [Pijon legal entity], registered under company number [company number], with its registered office at [registered address, Belgium] (“Pijon”, “we”, “us”, or “our”). Questions may be sent to privacy@pijon.example. Our data protection contact is [name or role].
2. Scope and our role
This Policy covers Pijon’s public website, studio accounts, subscription and support interactions, and the Pijon anti-cheat service. For studio account, billing, website, and direct support data, Pijon generally acts as data controller.
When a game studio sends player or match data to Pijon, the studio generally determines the purposes and means of that processing and Pijon acts as processor on its documented instructions. The applicable Data Processing Agreement controls that processing. Players should also review the privacy notice of the relevant game studio.
3. Personal data we process
- Account data: name, work email, authentication data, role, studio membership, and account preferences.
- Commercial data: plan, billing contact, invoices, VAT details, payment status, and transaction references. Card data should be handled by the payment provider, not Pijon.
- Support data: messages, attachments, call notes, diagnostic information, and feedback.
- Technical data: IP address, browser, operating system, device and application identifiers, timestamps, logs, and security events.
- Anti-cheat data: pseudonymous player identifiers, session and match identifiers, build information, device-integrity signals, server-authoritative actions, approved gameplay telemetry, evidence, and review outcomes.
- Website choices: theme preference stored locally and, where introduced, cookie-consent choices.
Studios must not send special-category data, government identifiers, payment card details, private communications, or unrelated personal data unless expressly agreed in writing and lawfully supported.
4. Why we process data
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, subscriptions, documentation, support, and the service | Contract performance or steps requested before contract |
| Protect accounts, prevent fraud, investigate abuse, and maintain security | Legitimate interests and legal obligations |
| Process invoices, tax records, and mandatory business records | Legal obligations and contract performance |
| Improve reliability, usability, and product performance | Legitimate interests, using minimised or aggregated data where practical |
| Send requested product communications and service notices | Contract performance or legitimate interests |
| Send optional marketing or use non-essential analytics | Consent where required |
| Process studio-provided player data | The studio’s documented instructions under the Data Processing Agreement |
5. Anti-cheat analysis and human review
Pijon may generate risk indicators, confidence assessments, and recommended actions from integrity, server, and behavioral signals. Pijon is designed to support reviewable studio decisions. Studios configure enforcement policy and remain responsible for player notices, sanctions, appeals, and any legally required human involvement.
Pijon should not be configured to make solely automated decisions producing legal or similarly significant effects unless the studio has confirmed a lawful basis, safeguards, transparency, and any required right to human intervention.
6. Sharing and processors
We may share data with carefully selected providers for:
- cloud hosting, databases, content delivery, security, and monitoring;
- authentication, email delivery, customer support, and documentation;
- payment processing, invoicing, accounting, and fraud prevention;
- professional advisers, auditors, insurers, and authorities where legally required; and
- a corporate transaction, subject to appropriate confidentiality and notice.
The final production Policy must identify or link to the current subprocessors. We do not sell personal data or use anti-cheat data for third-party advertising.
7. International transfers
Where personal data is transferred outside the European Economic Area, the United Kingdom, or Switzerland, we use an applicable adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where required.
8. Retention
We keep data only as long as needed for the stated purpose, contract, security, legal obligations, and dispute resolution. Final periods must be recorded in Pijon’s retention schedule. Expected categories include:
- account data for the subscription term plus [period];
- billing and tax records for the statutory retention period;
- support records for [period] after closure;
- security and audit logs for [period];
- player evidence according to each studio’s configured retention instructions; and
- backups until overwritten under the documented backup lifecycle.
9. Security
We use technical and organisational measures proportionate to risk, including encryption in transit and at rest, access controls, multifactor authentication for privileged access, scoped credentials, audit logging, monitoring, backup controls, vulnerability management, and incident-response procedures. No system is completely secure; studios must also secure their own integrations and credentials.
10. Your rights
Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, or objection; withdraw consent; and lodge a complaint with a supervisory authority. In Belgium, the authority is the Data Protection Authority.
Requests relating to a player’s game data should normally be sent to the relevant studio. If Pijon receives such a request as processor, we may refer it to that studio. We may verify identity and retain a record of the request where legally permitted.
11. Children
Studio accounts are intended for authorised business users. Player-data processing may involve games used by minors; the studio is responsible for age-appropriate notices, parental consent where required, and configuring proportionate collection and retention. Pijon does not knowingly create direct consumer accounts for children.
12. Cookies and local storage
The public site currently stores the selected light or dark theme in local storage. Authenticated services may require strictly necessary session and security technologies. Non-essential analytics or marketing technologies must not be used without the legally required consent. See our Cookie Policy.
13. Changes and contact
We may update this Policy as the service, vendors, or law changes. Material changes will be communicated through the service or by email where appropriate. Contact privacy@pijon.example or write to [postal address].