Data Protection · GDPR / DSGVO

Privacy Policy

How we handle personal data on infectus.io. Compliant with the EU General Data Protection Regulation (GDPR/DSGVO) and the Austrian Data Protection Act (DSG). Last updated: 23 September 2026.

1. Controller

The controller responsible for personal data processed on this website within the meaning of Art. 4 No. 7 GDPR is:

ODY Technologies e.U.

Oliver Greil, sole proprietor

6070 Ampass

Austria, European Union

contact@odytechnologies.com

Full legal disclosure: Imprint.

2. Scope

This policy applies to infectus.io. The website is a pre-launch teaser for the game Infectus. There are no user accounts, forms, comments, or analytics on this site. The only personal data processed is the technical request data that is automatically generated by visiting any website on the public internet.

The game itself is not yet available. Before it opens, we will extend this policy to cover it.

3. Hosting & Server Logs

This website is hosted on Cloudflare Pages (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). When you load any page, Cloudflare's edge servers automatically receive standard web request data:

  • your IP address (used to route the response and detect abuse);
  • the URL you requested and the HTTP referrer (if any);
  • your browser's User-Agent string;
  • the date and time of the request.

Purpose. To deliver the website, protect against DDoS and abuse, and maintain technical operations.

Legal basis. Legitimate interest in operating a secure and reliable website (Art. 6 (1) (f) GDPR).

Retention. Cloudflare typically retains edge access logs for a short rolling window (days, not months) for security and operational purposes. See Cloudflare's privacy policy for the current schedule.

International transfer. Cloudflare is a US-based provider with servers worldwide, including in the EU. Transfers to the United States are covered by the EU-U.S. Data Privacy Framework (Cloudflare is certified) and supplementary Standard Contractual Clauses where applicable.

4. No Third-Party Content

All fonts, images, and scripts on this website are served from our own host. We do not embed Google Fonts, content delivery networks, social media plugins, videos, or maps from other providers, so visiting this website does not make your browser contact any third party.

5. Cookies & Tracking

This website does not set any cookies and uses no tracking, analytics, or advertising pixels. If you switch the language manually, we store your choice in your browser's localStorage under infectus.lang, so the language persists across pages. This value never leaves your browser, and you can delete it at any time in your browser settings. It is strictly necessary to provide the language setting you requested (§ 165 (3) TKG 2021).

6. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15): confirmation of whether we process your data and a copy of it.
  • Right to rectification (Art. 16): correction of inaccurate data.
  • Right to erasure (Art. 17): deletion of your data, also known as the "right to be forgotten".
  • Right to restriction (Art. 18): pause processing in disputed cases.
  • Right to data portability (Art. 20): receive your data in a machine-readable format.
  • Right to object (Art. 21): object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7 (3)): without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, email contact@odytechnologies.com. We will respond within one month.

7. Right to Lodge a Complaint

If you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Austrian Data Protection Authority (Datenschutzbehörde):

Österreichische Datenschutzbehörde

Barichgasse 40-42

1030 Wien, Österreich

www.dsb.gv.at

8. Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

9. Children

The upcoming game is intended for users aged 16 and over. This website does not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will delete it.

10. Changes to This Policy

We will update this policy as the game evolves and new processing comes online (game client, accounts, game data, payments). Material changes will be announced on this website before they take effect.