Legal
Privacy Policy
Last updated 5 October 2026
This policy explains what personal data Synergy Co. (“we”) processes when you visit this website or play HEXFRONT on Roblox, why, and what rights you have under the GDPR.
1. Controller
[Full name / company], [address]. Contact: hexfrontco@gmail.com. Full details in the Imprint.
2. Hosting and server logs
This website runs on a server of netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, under a data processing agreement (Art. 28 GDPR). When you open a page, the web server briefly processes technical data (IP address, time, requested URL, browser user agent) to deliver the page and protect it against attacks. Legal basis: Art. 6(1)(f) GDPR (secure operation). Logs are deleted after [14] days at the latest.
3. Cookies
- hf_consent: stores your cookie choice for 180 days. Strictly necessary.
- hf_session, hf_pending, hf_oauth: only set for staff who log in to the admin area. Strictly necessary for security.
Strictly necessary cookies don’t need consent (§ 25(2) TDDDG). You can change your choice at any time via “Cookie settings” in the footer.
4. Website analytics (only with consent)
If you click “Accept analytics”, we load a privacy-friendly, self-hosted analytics tool ([e.g. Umami, hosted on our netcup server]) that counts page views without building cross-site profiles. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw consent at any time in the cookie settings.
5. Contact form
When you send a message we store your name, email address, topic, message and a one-way hash of your IP address (used only for spam protection, the raw IP is not saved). We use it only to answer you. Legal basis: Art. 6(1)(b) and (f) GDPR. Messages are deleted [12 months] after the request is closed.
6. In-game analytics in HEXFRONT
To find bugs, balance the game and understand which features players use, the game servers send gameplay data to our own server: your Roblox user ID and display name, session start and end, device type (PC/mobile/console), country (as provided by Roblox), in-game actions (e.g. act started or completed), purchases of in-game items in Robux, and technical error reports. We don’t receive your real name, email address, payment details or chat messages. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in running and improving the game). Raw event data is deleted after [13 months]; aggregated statistics without user IDs may be kept longer. Purchases are processed by Roblox; see the Roblox Privacy Policy.
7. Staff login
Staff log in to the admin dashboard with “Sign in with Roblox” (OAuth 2.0). We receive the Roblox user ID, username and avatar URL to check access. Legal basis: Art. 6(1)(f) GDPR.
8. Recipients
Data is processed on our server in Germany. We don’t sell personal data or share it for advertising.
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). To use them, email us with your Roblox user ID. You can also complain to a data protection supervisory authority, e.g. the one in your federal state.
10. Children
Many Roblox players are under 16. We collect only the minimum gameplay data described above, never ask players for contact details in-game, and the contact form is meant for players 16+ or a parent or guardian.