Legal

Privacy policy (website)

This website uses no cookies and no tracking services. This policy describes which data is processed when you visit the website.

Last updated: 8 October 2026

This English version is provided for convenience. The German version is legally binding; mandatory consumer rights under the law of your country of residence remain unaffected.

Table of contents
  1. Controller
  2. Your rights
  3. Right to lodge a complaint
  4. This website
  5. Hosting and technical access
  6. No cookies, no tracking, no third parties
  7. Contact by e-mail
  8. Contact form
  9. External links

Controller

The controller for data processing on this website and for SHARDFALL is:

Peppox Entertainment, owner Michael Burgemeister
Am Becherweg 6, 55270 Ober-Olm, Germany
E-mail: kontakt@peppox.de

We have not appointed a data protection officer, as this is not legally required. For questions about data protection, you can reach us at the e-mail address above.

Your rights

You have the following rights against us: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21) to processing based on a legitimate interest. You can withdraw any consent you have given at any time with effect for the future. Please contact kontakt@peppox.de for this.

Right to object: Where we process data on the basis of legitimate interests (Art. 6(1)(f) GDPR), for example with the contact form, you may object at any time on grounds relating to your particular situation.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz), Hintere Bleiche 34, 55116 Mainz, Germany, datenschutz.rlp.de.

This website

This policy concerns visits to peppox.de. The separate SHARDFALL privacy policy applies to the game SHARDFALL and its online services.

Hosting and technical access

This website is hosted on a virtual server operated by us at netcup GmbH, Emmy-Noether-Str. 10, 76131 Karlsruhe, Germany; the server is located in a data centre in Nuremberg (Germany). A data processing agreement under Art. 28 GDPR exists with netcup.

When you visit the website, your browser transmits technically necessary data: IP address, date and time, the requested page or file, and information about the browser and operating system. The server processes this data solely to deliver the pages and to secure the connection (Art. 6(1)(f) GDPR; legitimate interest in secure and functional operation). The web server does not keep an access log. Error messages of the server (for example failed connection attempts) may contain an IP address; these logs are limited in size to 100 MB at most; the oldest entries are overwritten automatically. The hosting provider may additionally process connection data for technical reasons.

No cookies, no tracking, no third parties

This website sets no cookies and stores no data in the browser (no local storage). No analytics or advertising services, no social media plugins, no embedded videos or maps and no third-party JavaScript are used. Fonts are loaded from our own server. A consent prompt (cookie banner) is therefore not required.

Contact by e-mail

If you write to us, we process your details (e-mail address, content of the message, where applicable account ID) to handle your request (Art. 6(1)(b) or (f) GDPR). The messages are deleted once the request has been dealt with. Where statutory retention obligations apply (for example for business letters under Section 257 HGB and Section 147 AO), deletion takes place only after they expire. The e-mails are stored with the e-mail service provider we use, with whom a data processing agreement exists.

Contact form

If you use the contact form, we process your name, e-mail address, the subject you selected and your message in order to handle and answer your enquiry (Art. 6(1)(b) GDPR where it concerns steps prior to entering into a contract, otherwise Art. 6(1)(f) GDPR). For requests concerning data subject rights and reports of illegal content we process the data to comply with legal obligations (Art. 6(1)(c) GDPR). We also store the time, the language and a technical identifier. Required fields are marked; without them we cannot reply.

The message is stored on our server and forwarded to our mailbox. We usually send an acknowledgement of receipt (without repeating your message; it may be omitted if abuse is suspected or limits are exceeded) automatically to the address you give. Stored form messages are deleted after 180 days at the latest; messages in our mailbox are kept only for as long as necessary for handling the enquiry and for legal reasons (Section 257 HGB, Section 147 AO). To protect against abuse (spam) we use a hidden field and a limit on requests per IP address; for this the IP address (for IPv6 the network prefix) is held in memory only, for at most one hour, and is neither stored nor logged; to detect duplicate submissions and to limit confirmation e-mails, hash values of the address and text are kept in memory for up to 24 hours. We use an e-mail service provider as a processor for sending e-mail. No cookies are set and no third-party scripts are loaded.

This website links, for example, to the app stores. Merely visiting our pages does not transmit any data to these providers; their privacy terms apply only once you click a link.

↑ Back to top