EVILGARD Interactive
Privacy Policy
Last updated: 22 September 2026
This is the English counterpart of the German privacy policy. If the versions differ, the German text is authoritative.
1. Data controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Kai Rainer Hochreiter
EVILGARD Interactive
Katherweg 6
54294 Trier
Germany
General contact and privacy enquiries: contact@evilgard.com
Business enquiries: business@evilgard.com
2. General information about data processing
This website provides information about the PC game EVILGARD and the independent project behind it, EVILGARD Interactive.
Personal data are processed only where this is necessary for the technical provision and security of the website, for handling enquiries or to meet legal obligations.
This website does not use analytics, advertising or tracking services. Text is displayed using system fonts available on your device; no external font files or other third-party resources are embedded.
3. Hosting by STRATO
This website is hosted by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
When you access the website, the web server processes data that are technically necessary. This may include:
- the IP address of the device requesting the page,
- the date and time of access,
- the page or file requested,
- the volume of data transferred,
- browser type and browser version,
- operating system,
- referrer URL,
- request status.
This processing is carried out to provide the website technically, ensure the stability and security of the service, and detect and defend against attacks or misuse.
The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure, stable and functional provision of this website.
STRATO states that it stores visitors’ IP addresses for a maximum of seven days to detect and defend against attacks. According to STRATO, host names and IP addresses are anonymised in web-server log files made available to hosting customers; these log files may be available in the customer area for a limited period.
Where STRATO processes personal data on behalf of the website operator, this takes place under a data processing agreement pursuant to Article 28 GDPR.
5. Contact by email or form
When you get in touch, your email address, message and any further information you choose to provide are processed to handle and respond to your enquiry. Send general questions about EVILGARD, feedback, press, community and other general enquiries to contact@evilgard.com. Platform operators such as Steam, Epic or GOG, as well as enquiries about partnerships, contracts, invoices, purchases and other business matters, should use business@evilgard.com.
Contacting the operator is voluntary. There is no statutory or contractual obligation to provide personal data for a general enquiry. However, an email address and a message are needed to process an enquiry through this form. Without these details, the form enquiry cannot be processed or answered. Your name and subject are optional. Separately, accessing the website involves the technical connection data described in section 3.
Where your enquiry concerns entering into or performing a contract with you, Article 6(1)(b) GDPR is the legal basis. General enquiries are processed under Article 6(1)(f) GDPR. The legitimate interest is handling and answering enquiries about EVILGARD and EVILGARD Interactive.
The form validates entries on the server and passes them through the WordPress mail function to the STRATO hosting mail transport. The recipient is contact@evilgard.com. The email address you enter is used as the reply address. The form code does not store an additional copy of the message in the WordPress database or send an automatic reply to the entered address. The general contact form sends exclusively to contact@evilgard.com, not to business@evilgard.com.
STRATO provides the active email mailboxes and the audit-proof STRATO email archiving service. Enquiries are handled in STRATO Webmail and are not forwarded to other mailboxes. contact@evilgard.com is excluded from STRATO email archiving. business@evilgard.com is archived through STRATO email archiving. Successful handoff to the mail system does not establish confirmed delivery.
Active mailbox: Ordinary enquiries sent to contact@evilgard.com with no further business or legal relevance are generally deleted from the active mailbox promptly after they have been fully handled and their purpose has been fulfilled, in accordance with the established deletion procedure. Further retention may be necessary while a message is still needed for a specific business matter or to establish, exercise or defend legal claims.
STRATO email archive: Audit-proof archiving of business@evilgard.com serves the traceable retention of relevant correspondence and, where applicable, compliance with statutory retention obligations. Deleting a message from the active mailbox does not simultaneously delete an archived copy. Separate retention and deletion procedures apply to the archive. No promise is therefore made that a message will be completely and permanently deleted from all systems after a fixed number of days. Personal data in the archive may likewise be retained only while a necessary processing purpose or statutory obligation exists; once neither applies, deletion from the archive must be arranged separately.
Statutory retention: Where a message is subject to a statutory retention obligation, it is retained for the applicable statutory period. The legal basis for this is Article 6(1)(c) GDPR. The type of message and the obligation that actually applies determine retention, rather than the mere fact that the message is archived. Any further retention necessary to establish, exercise or defend legal claims is based on Article 6(1)(f) GDPR. Not every contact enquiry is subject to statutory retention simply because it arrives by email.
6. Language selection
This website is available in German and English. Polylang assigns content to the respective language URLs. Automatic browser-language detection and the language-preference cookie are disabled. Language switching uses neither cookies nor LocalStorage or SessionStorage entries.
7. External links to Discord and Steam
The website may contain links to external services, in particular Discord and the Steam platform.
Until you follow an external link, displaying an ordinary link does not embed the respective third-party service in this website.
When you click an external link, you leave this website. From that point on, the external provider may process personal data under its own privacy policy. The website operator generally has no control over the nature, scope or purpose of that processing.
No Discord or Steam widgets are embedded at present.
8. No web analytics or profiling
This website uses no web analytics, advertising or tracking services. The operator does not create usage profiles for advertising purposes. Processing required for technical security is described in sections 3 and 15.
9. Recipients of personal data
Personal data are shared only where necessary for the relevant purpose and permitted by a legal basis.
STRATO GmbH processes data as the provider of web hosting, the email mailbox and STRATO email archiving. Processing on behalf of the operator is governed by an agreement under Article 28 GDPR. The website operator identified above also receives contact enquiries.
10. Retention period
Retention depends on the relevant purpose and any applicable statutory obligations. Section 5 distinguishes the criteria for the active mailbox, the separate STRATO email archive and correspondence subject to statutory retention. The hosting and security log information in section 3 does not set deletion periods for emails or the email archive. The technical validity and cleanup rules in section 15 apply to form checks and abuse counters.
Website and database backups: STRATO creates automatic backups of the website and its database for recovery following technical faults or data loss. These backups may contain personal data stored in the website at the time of the backup. They are separate from STRATO email archiving for business@evilgard.com, which is described in section 5.
Separate private website snapshots also exist for maintenance checks and recovery. Backup retention must be limited to the period required for these purposes unless statutory obligations require otherwise. Deleting data from the live website does not simultaneously remove those data from all existing backup copies. Similarly, a form token reaching its validity limit does not mean it is immediately removed from backups.
11. Your rights
Subject to the applicable legal conditions, you have the following rights in particular:
- right of access under Article 15 GDPR,
- right to rectification under Article 16 GDPR,
- right to erasure under Article 17 GDPR,
- right to restriction of processing under Article 18 GDPR,
- right to data portability under Article 20 GDPR,
- right to object to certain processing under Article 21 GDPR.
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. This does not affect the lawfulness of processing carried out before withdrawal.
To exercise your rights, contact contact@evilgard.com.
12. Right to lodge a complaint with a data protection authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority.
For the controller’s location, the relevant authority is in particular:
The Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
Germany
13. Automated decision-making
No decision based solely on automated processing, including profiling within the meaning of Article 22 GDPR, takes place in connection with this website.
14. Changes to this Privacy Policy
This Privacy Policy is updated when the website, actual data processing or legal requirements change. The privacy implications of additional functions are assessed before they are introduced.
15. WordPress, form security and editorial access
WordPress and Polylang run on this website’s STRATO hosting. Public registration and commenting are not available. No external CAPTCHAs, Gravatar or embedded social-media services are used.
Form cookie: EVILGARD_CONTACT contains a random identifier, not names, email addresses or messages. It binds security checks to the respective browser session. The cookie applies to this website and is protected with Secure, HttpOnly and SameSite=Lax. It has no fixed browser expiry date and is treated as a session cookie. Closing a single tab does not delete it; browser session restoration may preserve it even across a restart.
Server-side security data: Each displayed form creates a single-use form token associated with a derived identifier of the cookie. It is valid for 30 minutes and deleted after a successful mail handoff. A sending confirmation, also bound to the session, is valid for 5 minutes and consumed when displayed. These entries contain no message text or email addresses. They are stored in the WordPress database separately from the browser cookie.
Expiry and deletion: Expired form tokens and confirmations can no longer be used. WordPress removes expired entries on access or through its daily scheduled transient cleanup. Automatic execution uses WP-Cron and depends on website requests; without requests, physical deletion may occur later. Deletion at the exact moment of expiry is not promised.
Abuse counters: The server derives a pseudonymous identifier from the IP address using a secret server key. The form code stores neither the plain IP address nor a name, email address or message in these counters. The identifier is not considered anonymous. At most 5 checked submission attempts are allowed per fixed 10-minute window and 30 per fixed hourly window. Invalid entries following a successful session check also count. An exceeded limit prevents sending; the respective counter starts afresh in a new time window.
Old counters become eligible for deletion only after the end of their window plus one hour and are deleted when the next hourly scheduled cleanup runs. A short-lived processing lock prevents concurrent use of the same form token and is removed after processing. Leftover locks older than one hour are removed by this cleanup. Here too, WP-Cron may delay physical deletion when there are no website requests. The hosting logs described in section 3 are separate.
Editors: Only editors use the WordPress cookies wordpress_sec_… and wordpress_logged_in_… for protected administration access. Without “Remember Me”, these are session cookies and server-side login validity is normally two days. With “Remember Me”, validity is 14 days and the browser lifetime includes an additional twelve-hour technical grace period. Logging out removes the login cookies and ends the respective server session. WordPress stores a token verifier, expiry and login times and, where provided, the IP address and browser identifier in the user’s session data. Expired sessions no longer establish a login; stored expired entries are cleaned when session data are updated, not necessarily at the moment of expiry. The cookies wp-settings-… and wp-settings-time-… may store interface preferences and their modification time for up to one year. These administration functions are not offered to ordinary unauthenticated visitors.
Right to object to processing based on legitimate interests
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where it is based on Article 6(1)(f) GDPR. The data concerned will then no longer be processed unless the controller demonstrates compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. You may send your objection to contact@evilgard.com.