Vue logo

Privacy Policy

Last updated: August 12, 2026

Protecting your personal data is important to us. This Privacy Policy explains what personal data frostberry UG (haftungsbeschränkt) processes when you use our website, our games, and the online services integrated into them, how this data is collected and used, with whom it may be shared, and how long it is retained.

This Privacy Policy applies in particular to:

  • the website frostberry.de,

  • games and applications provided by frostberry UG (haftungsbeschränkt),

  • online and multiplayer features of our games,

  • the integration of Epic Online Services (EOS) and Epic Account Services.

1. Data Controller

The controller responsible for processing personal data within the meaning of the General Data Protection Regulation (GDPR) is:

frostberry UG (haftungsbeschränkt)
Frankenweg 37
97318 Kitzingen
Germany

Phone: 015254086098
Email: [email protected]
Website: frostberry.de

For questions regarding privacy or to exercise your data protection rights, you may contact us using the email address above.

2. What Data We Collect

The personal data we process depends on which of our services you use.

We may receive personal data in the following ways:

  1. directly from you, for example when you contact us,

  2. automatically, for example through server logs or technical connection data,

  3. from third-party providers, particularly Epic Games in connection with Epic Online Services and Epic Account Services.

3. Data Processing When Using Our Games

When you use our games, technical and gameplay-related data may be processed where necessary to provide the game and its online features.

This may include in particular:

  • technical device and connection information,

  • IP address,

  • platform or user identifiers,

  • player identifiers,

  • session and multiplayer data,

  • information about game sessions you create or join,

  • technical error and diagnostic information,

  • data required to prevent abuse or maintain security.

The specific data processed depends on the features you use.

4. Epic Online Services and Epic Account Services

Our games use Epic Online Services ("EOS") and Epic Account Services, services provided by Epic Games, particularly for authentication and online or multiplayer functionality.

This section specifically explains what data is collected in connection with EOS, how it is collected, how it is used, with whom it is shared, and how long it is retained.

4.1 How Data Is Collected Through Epic Online Services

When you sign in to our game using Epic Account Services or use EOS functionality, authentication is carried out through Epic Games systems.

Depending on the EOS features being used and the permissions you have granted, our game may receive or process information including:

  • your Epic Account ID,

  • your Epic Online Services Product User ID (PUID),

  • your publicly visible Epic display name,

  • information about whether authentication was successful,

  • platform identifiers linked to your Epic account where required for the relevant functionality and made available by Epic,

  • session, lobby, or multiplayer information,

  • technical connection information.

If social functionality such as friends lists is introduced in the future, the relevant data will only be processed where the feature is enabled and the necessary access has been granted by Epic and/or the user.

We do not receive your Epic Games password.

The actual sign-in to an Epic account and the processing of authentication information required for that sign-in are handled by Epic Games.

4.2 How We Use EOS Data

Information received through Epic Online Services is used only where necessary to provide and operate the relevant game functionality.

This includes in particular:

  • player sign-in and authentication,

  • uniquely identifying a player within our online services,

  • providing multiplayer functionality,

  • creating, finding, and joining game sessions,

  • managing lobbies and game sessions,

  • connecting players with one another,

  • displaying player names or display names within multiplayer functionality,

  • maintaining the functionality and security of online services,

  • diagnosing and resolving technical problems,

  • preventing abuse, manipulation, fraud, or unauthorized access,

  • complying with legal obligations.

We do not use personal data received through Epic Account Services for purposes that are incompatible with the relevant Epic permission or game functionality.

We do not sell players' personal data.

4.3 Sharing of EOS Data

As part of providing online functionality, data may be processed or transmitted between our game and Epic Games / Epic Online Services.

Epic Games provides the technical infrastructure for the Epic Online Services used by our games.

Certain information may also be visible or technically available to other players where this is necessary for multiplayer functionality.

This may include, for example:

  • player name or display name,

  • participation in a game session,

  • lobby or session information,

  • information required to establish connections between players.

Personal data will otherwise only be disclosed to third parties where:

  • this is necessary to provide the service,

  • you have given your consent,

  • a service provider processes data on our behalf,

  • or we are legally required to disclose the information.

We do not sell personal data received through Epic Online Services to third parties.

Epic Games may additionally process data relating to Epic Online Services in accordance with its own privacy policy and the agreements applicable to Epic Online Services.

5. Storage and Retention of Game and EOS Data

We retain personal data only for as long as necessary for the relevant purpose or for as long as required by applicable law.

5.1 Authentication Data

We do not store Epic Games passwords.

Short-lived authentication tokens or session information are used only where necessary for login and to maintain the relevant game or online session.

Where Epic Games itself processes or stores such data within Epic Online Services, the applicable retention period is additionally governed by Epic Games' privacy and retention practices.

5.2 Player Identifiers

Persistent technical player identifiers such as an Epic Account ID or EOS Product User ID may be retained where necessary to uniquely identify a player and provide online or gameplay functionality.

Such identifiers are retained only for as long as:

  • the associated game or user relationship exists,

  • storage is necessary to provide a requested feature,

  • legitimate security or abuse-prevention interests require retention,

  • or legal obligations require further retention.

When the purpose of the processing no longer applies and there is no legal obligation to continue storing the data, the relevant personal data will be deleted or anonymized.

5.3 Multiplayer and Session Data

Temporary lobby, session, and connection data are generally processed only for as long as necessary to conduct the relevant online or multiplayer session and technically provide the service.

Where certain information is required for technical troubleshooting, security, or abuse prevention, it may be retained for the additional period necessary for those purposes.

6. Legal Bases for Processing in Our Games

Where the GDPR applies, personal data is processed in particular on the following legal bases:

Article 6(1)(b) GDPR – Performance of a Contract

Processing takes place where necessary to provide features of our game requested by you, including:

  • sign-in,

  • authentication,

  • multiplayer,

  • sessions and lobbies,

  • other requested online functionality.

Article 6(1)(f) GDPR – Legitimate Interests

We may process data where necessary for our legitimate interests, particularly for:

  • ensuring IT and game security,

  • technical troubleshooting,

  • preventing fraud and abuse,

  • maintaining the stability of our services.

Article 6(1)(a) GDPR – Consent

Where processing requires your consent, processing will only take place after you have provided the relevant consent.

This may particularly apply to optional features or additional account permissions.

Consent may be withdrawn at any time with effect for the future.

7. Website and Server Log Files

When you access our website, technically necessary data is automatically processed by the web server.

This may include:

  • IP address,

  • date and time of access,

  • requested page or file,

  • referrer URL,

  • browser type and browser version,

  • operating system,

  • internet service provider,

  • additional technical information relating to the request.

This data is required in particular to:

  • technically provide the website,

  • ensure stability and security,

  • identify technical errors,

  • detect and prevent attacks and abusive use.

The legal basis is Article 6(1)(f) GDPR.

Our legitimate interest is the secure and reliable operation of our website.

8. Cookies

Our website may use cookies.

Cookies are small text files that are stored on the user's device.

Technically necessary cookies may be used to provide website functionality and enable use of the website.

Where cookies or similar technologies require consent, they are generally only activated after the user has provided the relevant consent.

Users can delete or block cookies through their browser settings. Doing so may restrict certain website functions.

9. Matomo

We use Matomo to analyze the use of our website.

Matomo may allow us to evaluate, for example:

  • which pages are accessed,

  • how frequently individual pages are visited,

  • how long visitors remain on a page,

  • from which website visitors arrive at our website.

Our Matomo installation is operated on a server used by us.

We use the collected information to analyze and improve our website.

Where consent is required, processing is based on Article 6(1)(a) GDPR.

Where processing may lawfully be based on legitimate interests, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in analyzing and improving our website.

10. Contacting Us

If you contact us by email, contact form, or another method, we process the personal data you provide.

This may include in particular:

  • your name,

  • your email address,

  • the contents of your message,

  • any additional information you voluntarily provide.

The data is used solely to process your request and, where applicable, for subsequent communication.

Depending on the nature of your request, the legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.

The data will be deleted once the request has been fully resolved, unless legal retention obligations or other legitimate reasons require continued storage.

11. Embedded Content and Social Networks

Our website may contain content or functionality from external providers, including:

  • Facebook / Meta,

  • Instagram,

  • LinkedIn,

  • YouTube.

When such content is loaded, a connection to the respective provider's servers may be established. Information such as your IP address, browser information, and the page visited may be transmitted to the provider.

If the user is simultaneously logged in to the respective service, the provider may be able to associate the website visit with the user's account.

Where consent is required before loading such content, it will only be activated after the user has provided the relevant consent.

The respective provider's own privacy policy applies to any further processing carried out by that provider.

12. Recipients and Service Providers

Personal data may be disclosed to service providers where this is necessary to provide our website, games, or online services.

These may include in particular:

  • hosting providers,

  • server and infrastructure providers,

  • Epic Games in connection with Epic Online Services,

  • technical service providers,

  • IT security providers.

Where a provider processes personal data on our behalf, the processing is carried out in accordance with applicable data protection requirements.

Data may also be disclosed where we are legally required to do so or where disclosure is necessary to establish, exercise, or defend legal claims.

13. International Data Transfers

When using international service providers, personal data may be processed outside Germany or the European Economic Area.

This may particularly apply to services provided by internationally operating companies such as Epic Games.

Where the GDPR applies to such a transfer, it will only take place in accordance with the legal requirements governing international data transfers.

The respective provider may additionally have its own responsibilities and obligations under applicable data protection law.

14. Data Security

We implement appropriate technical and organizational measures to protect personal data against:

  • loss,

  • manipulation,

  • unauthorized access,

  • unauthorized disclosure,

  • destruction,

  • or other unlawful processing.

However, internet-based data transmission can generally involve security risks. Absolute protection cannot therefore be guaranteed.

15. Data Retention

Where no more specific retention period is stated in this Privacy Policy, we retain personal data only for as long as necessary for the relevant purpose of processing.

Additional statutory retention periods may apply.

When determining retention periods, we consider in particular:

  • the purpose of processing,

  • the type of data,

  • whether the data is necessary to provide our services,

  • security and abuse-prevention requirements,

  • statutory retention obligations,

  • the establishment or defense of legal claims.

Once the purpose of processing no longer applies, personal data will be deleted or anonymized unless there is a legal or otherwise permissible basis for continued storage.

16. Your Rights

Where the applicable legal requirements are met, you have the following rights in particular:

Right of Access – Article 15 GDPR

You may request information about whether we process personal data concerning you and, if so, what personal data we process.

Right to Rectification – Article 16 GDPR

You may request the correction of inaccurate personal data or completion of incomplete personal data.

Right to Erasure – Article 17 GDPR

You may request the deletion of your personal data where the applicable legal requirements are met.

Right to Restriction of Processing – Article 18 GDPR

You may request restriction of the processing of your personal data where the applicable legal requirements are met.

Right to Data Portability – Article 20 GDPR

Where the applicable legal requirements are met, you may receive your personal data in a structured, commonly used, and machine-readable format.

Right to Object – Article 21 GDPR

You may object to processing based on Article 6(1)(e) or (f) GDPR where the applicable legal requirements are met.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time with effect for the future.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

17. Privacy Requests and Deletion of Game Data

If you would like to request access to, correction of, or deletion of personal data stored by us, you may contact:

[email protected]

For requests relating to one of our games, please provide, where possible, the name of the game and the user account concerned.

For data that is processed exclusively by Epic Games as an independent controller and to which we do not have access, you may also need to contact Epic Games directly.

We will inform you where a particular request can only be processed through Epic Games.

18. Minors

Depending on the relevant game and Epic services being used, our online services may be subject to age restrictions and specific privacy mechanisms provided by Epic Games.

Where Epic Account Services provides age-verification, parental-consent, or similar mechanisms for minors, the relevant functionality is provided through Epic.

We do not knowingly use personal data relating to minors for our own advertising purposes beyond the purposes described in this Privacy Policy.

19. Automated Decision-Making

We do not use personal data for solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the user or similarly significantly affects the user.

20. Changes to This Privacy Policy

We may update this Privacy Policy where:

  • new features are introduced into our games,

  • additional online services are integrated,

  • the type of data being processed changes,

  • legal requirements change.

The current version will be published on our website.

Last updated: August 12, 2026