Privacy policy
This is a translation for convenience. Only the German version is legally binding.
Last updated: October 2026
We care about protecting your data. This policy explains which personal data is processed when you visit and use this website and the game Rivenward Online, and why. In short: as little as possible.
Rivenward Online is in development. Sections marked “not yet in operation” describe features we are preparing; they apply from the day the feature launches. Until then, the processing described there does not take place.
1. Controller
Strukturaflow IT e.U.
Owner: Natascha Reiner
Flatschacher Straße 10, 8724 Spielberg, Austria
E-mail: office@strukturaflow.com
For privacy questions about Rivenward Online you can also reach us at kontakt@rivenwardonline.com [PLACEHOLDER: Suggestion: address still to be set up]. No data protection officer has been appointed, as there is no legal obligation to do so.
2. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw any consent you have given at any time with effect for the future. Just write to office@strukturaflow.com.
You also have the right to lodge a complaint with the supervisory authority: Österreichische Datenschutzbehörde (Austrian Data Protection Authority), Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at. There is no automated decision-making within the meaning of Art. 22 GDPR; account bans are always decided by a human.
3. Hosting, server logs and delivery
This website and the game servers run on our own server in Austria, not with a hosting provider. The web service of this website keeps no access log: IP addresses, pages requested and browser details are not stored on our server. Only start, stop and technical errors of the service are logged, without reference to individual visitors.
Delivery takes place via the network of Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare performs three tasks for us: the name service (DNS) for the domain rivenwardonline.com, the proxy at the network edge (Cloudflare accepts your connection, encrypts it with TLS and fends off attacks) and a tunnel through which our server collects requests without being reachable from the internet itself. In doing so Cloudflare processes IP addresses, connection and request data (e.g. address requested, browser identifier, time) and, because encryption ends at Cloudflare, also the content of requests, such as an e-mail address entered in a form. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in fast, secure and stable delivery).
Cloudflare is our processor; Cloudflare’s Data Processing Addendum under Art. 28 GDPR applies. Requests are handled in the nearest data centre, for visits from Europe usually in data centres in the EU. Processing exclusively in the EU is therefore not guaranteed; transfers to the USA are based on the EU-US Data Privacy Framework, under which Cloudflare is certified, and additionally on the EU standard contractual clauses. Cloudflare may also ask your browser to send reports about failed connections (Network Error Logging) to Cloudflare; these contain no page content.
4. Contact by e-mail
If you contact us by e-mail, we process your details to handle the request and any follow-up questions (Art. 6(1)(b) or (f) GDPR). The data is deleted as soon as it is no longer needed for these purposes and no statutory retention obligations apply.
5. Waitlist and transactional e-mails
For the waitlist we process your e-mail address, the chosen language and the times of sign-up, confirmation and unsubscription. Sign-up uses double opt-in: you receive a confirmation link, and only clicking it activates the sign-up; the times of sign-up and confirmation are logged as proof. The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with § 174 Austrian Telecommunications Act 2021). You only get mail when a test is coming up or the project ends; the address is not passed on to third parties and not used to advertise other offers.
Mail is sent via our processor Brevo (Sendinblue SAS), 106 boulevard Haussmann, 75008 Paris, France; the data is processed on servers in the EU (data processing agreement under Art. 28 GDPR). Brevo receives your e-mail address and language for this. You can unsubscribe at any time via the link in every e-mail; this counts as withdrawal of your consent. Your data is stored until withdrawal; unconfirmed sign-ups are deleted after [PLACEHOLDER: Suggestion: 30 days].
We also use Brevo to send transactional e-mails required for an account: confirmation of the e-mail address, sign-in links, password resets and notices about security or bans. The legal basis is Art. 6(1)(b) GDPR (terms of use). These e-mails contain no advertising.
The waitlist is not live yet; until then no data is stored via the form.
6. Account for website and game (not yet in operation)
One account covers the website, the forum, the wiki and the game. We process:
- e-mail address and the time it was confirmed,
- display name and optional profile details (avatar, short bio, language),
- the password only as a hash (scrypt with salt); we do not know the password itself,
- sessions: a random session identifier (stored by us only as a hash), expiry time, IP address and browser identifier, so that you can see and sign out your signed-in devices,
- a sign-in log (sign-in, sign-out, failed attempts, password resets, bans) with time, IP address and browser identifier to prevent abuse and to investigate account takeovers,
- ban records with time and reason.
The legal basis is Art. 6(1)(b) GDPR (terms of use) and, for the sign-in log and bans, Art. 6(1)(f) GDPR (legitimate interest in account security and fair play). Short-lived counters limiting sign-in attempts are kept only in memory (Redis) and expire after minutes.
Retention: sessions end after 30 days or on sign-out. Sign-in logs are deleted after [PLACEHOLDER: Suggestion: 90 days]. Ban records are kept for the duration of the ban and at most [PLACEHOLDER: Suggestion: 2 years] afterwards to recognise repeated abuse. You can delete your account in the account settings; after a 14-day period during which you can cancel the deletion, account, profile and characters are deleted.
Cookies: for signed-in use we only set technically necessary cookies: a session cookie, a cookie protecting forms against cross-site requests (CSRF) and a short-lived cookie for status messages, plus, if you choose, a cookie storing your colour scheme. The legal basis is § 165(3) Austrian Telecommunications Act 2021; no consent is required. There are no tracking or advertising cookies. The public pages of this website currently set no cookies at all.
7. Forum and wiki (not yet in operation)
Forum posts and wiki edits are publicly visible together with your display name and the time. We keep earlier versions of edited posts and wiki pages (revisions) so that changes remain traceable and abuse can be reverted. We process reactions, read status and reports of posts to provide the forum.
Moderation: reported posts are reviewed by a human. We store the report, its reason and the outcome (deleted, dismissed, ban). The legal basis is Art. 6(1)(b) GDPR (terms of use) and (f) (legitimate interest in respectful and lawful conduct).
If you delete your account, your public posts and wiki edits remain so that conversations and pages stay understandable, but they are no longer linked to a name (“deleted account”). [PLACEHOLDER: Suggestion: on request we also delete the posts themselves]
8. Game operation (not yet in operation)
For the game we process:
- character data: name, race, class, appearance, level, experience, inventory, position, progress, realm and, on the One Life realm, the death record (time, place, cause);
- connection data: IP address, time of sign-in and sign-out, latency and technical errors, to provide the connection and to prevent fraud and attacks;
- chat logs: we store in-game chat messages with sender, channel and time so that reported insults, fraud or other violations can be reviewed.
The legal basis is Art. 6(1)(b) GDPR (terms of use) and, for connection data and chat logs, Art. 6(1)(f) GDPR (legitimate interest in a secure and fair game). Character names and leaderboards, for example on One Life, may be visible to other players.
Retention: character data for as long as your account exists. Connection data is deleted after [PLACEHOLDER: Suggestion: 30 days], chat logs after [PLACEHOLDER: Suggestion: 30 days]. If a message has been reported, we keep it until the review is complete, and in case of a ban as long as the ban record (section 6).
9. App and mobile use
You can use Rivenward in the browser or add it to your home screen as a web app (PWA). No additional data is transmitted to us. An installed web app may cache program files and graphics on your device so that it starts faster; these files contain no personal data and can be deleted in your browser settings. We only send notifications if you explicitly allow them (not planned at present). For later apps in app stores, the respective store’s privacy policy also applies; this policy will be extended then.
10. Analytics
This website currently uses no analytics or audience measurement, no tracking pixels, no embedded third-party content and no fonts from third-party servers. If we introduce measurement, we will update this policy beforehand.
11. Minors
The waitlist and accounts are open to people aged 16 and over. The basis is Art. 8 GDPR: where processing for a service like this one is based on consent, a child under 16 can only consent validly with parental approval; member states may lower the limit to as low as 13 (Austria: 14 under § 4(4) DSG). We apply the limit of 16 uniformly because the site can be reached throughout the EU. If we learn that a child under 16 has provided data without parental approval, we delete it.
12. Status and changes
Last updated: October 2026. We adapt this policy when features of the website or the game or the legal situation change.