top of page

Privacy Policy

Last Edited (Effective immediately):

2 Ekim 2026

Privacy Policy

Updated: October 2nd 2026, 23.00 (Türkiye Time, UTC+3) (Effective immediately)


Scope and responsibility


This Privacy Policy explains how Pokenix collects, uses, stores, discloses, and otherwise processes personal data in connection with Pokenix Services. Personal data means information relating to an identified or identifiable individual. An account identifier, online identifier, or record associated with a player can be personal data even when it does not contain a real name.


Pokenix Services means websites, applications, games, game servers, community spaces, forums, software, tools, APIs, authentication systems, online services, and other digital products or services operated, provided, published, or controlled by Pokenix that reference or are governed by this Privacy Policy. Pokenix is currently operated by an individual under the Pokenix brand. In this Policy, Pokenix, we, us, and our refer to that individual in their capacity as the operator of Pokenix Services.


Pokenix is responsible for processing for which it determines the purposes and means, including the administration of its own accounts, software, servers, and community spaces. A platform or infrastructure provider can separately be responsible for processing that it determines for its own purposes. The distinction is explained below.


This Policy describes processing across different types of functionality. It does not mean that every Service collects every category described, that every feature is available, or that every user has a single account shared across all Services. Processing depends on the Service you use, its configuration, the features you choose, and your interactions. A Service-specific or supplemental privacy notice may provide additional details and govern the particular processing it expressly addresses. Applicable law takes precedence over any notice.


Questions about this Policy and requests concerning your personal data, including access, correction, and deletion requests, can be sent to info@pokenix.com.


How information reaches us


We receive information when you register, sign in, complete a profile, change settings, play a game, participate in a community, publish content, send a message, submit a report, or contact us. We also receive information generated by the operation of our software and servers, including account events, gameplay state, technical requests, and security records.


Information may come from an authentication system when you sign in, a platform on which you participate in a Pokenix community, an integration you use to link accounts or relay messages, or a provider delivering a communication or notification. Other users may identify you in a message, quote your content, include you in a group, or submit a report involving you. Public search and indexing services provide search performance and indexing information as described below.


Required information depends on the requested functionality. Without an account identifier and the information needed to authenticate you, we cannot provide account-dependent features. Without a delivery address or notification identifier, we cannot send a communication through that channel. Optional profile fields, optional participation, and notification permissions are separate choices. Refusing an optional use does not by itself prevent unrelated functionality.


This Policy does not authorize collection of unrelated information merely because a Service could technically obtain it. New processing that materially differs from the practices described here requires appropriate information and a lawful basis before it begins, including consent where required.


Accounts, profiles, and preferences


Account and profile information can include your email address, username, display name, name if provided, internal account identifiers, profile biography, avatar or profile picture, and country information you choose to provide. Account records can include creation and update times, verification status, applicable groups or roles, and the history of relevant account changes. Different Services may use different subsets of this information.


For applicable Services, registration processing also includes your confirmation that you meet the minimum-age and legal-majority requirements described below. This confirmation is information you provide about your eligibility, rather than an independently verified age or identity.


Preferences can include language, appearance, theme, reduced-motion settings, notification choices, saved or favorite items, and other settings for functionality you use. Community accounts can also have group membership, permissions, trust levels, badges, profile fields, and activity information associated with participation. The visibility of a profile field or activity record depends on the relevant area and its settings; an email address used for account administration is not automatically a public profile field.


Where a profile is synchronized with a shared account system, selected changes such as a name, biography, avatar, or country can be transmitted to that system and made available to connected Services according to their configured permissions. A connected Service may maintain its own account record and does not necessarily accept every profile change locally. A matching email address does not necessarily establish that two separate accounts belong to the same person.


Authentication and account security


Our authentication processing includes credentials where an account is created directly, password hashes rather than readable passwords in systems that use password hashing, verification and password-reset information, account identifiers, authentication events, and session records. A password submitted for verification is processed by the account system handling that login. Password-reset and verification flows can involve a token, its validity period, delivery information, and completion status.


Connected Services can use a shared authentication system using standardized sign-in and authorization protocols. In those flows, a Service receives the account identifier and the profile, email, group, or role information allowed by its configured scope, together with the tokens or assertions needed to authenticate the session. The connected Service does not receive your account-system password merely because you sign in through that system. Depending on the implementation, session information and tokens are held on a server, in a session cookie, or in protected application storage, including the operating system's credential store.


Where offered and configured, additional authentication methods can involve passkey public keys and credential identifiers, authenticator configuration, recovery information, and records of setup or use. A passkey or local biometric check does not mean that Pokenix receives your fingerprint or facial scan; the authenticator or operating system handles the local verification and returns the authentication result. Authentication factors are not automatically made available to every connected Service.


Security records can include successful and failed login events, relevant network and browser information, session creation and revocation, last activity, permission changes, and administrative actions. Signing out or revoking a session is different from deleting an account. Signing out of one Service does not necessarily end every session in a shared account system or another Service.


Technical information and location distinctions


When your device communicates with a Service, its infrastructure can process an IP address, request time, requested page or API endpoint, response status, connection information, browser user agent, browser and operating system information, and relevant application version. Logs can include errors, authentication failures, rate-limit events, and identifiers needed to investigate a technical problem or security incident. Host, platform, and content delivery providers can process network information even when the application itself stores only a subset of it.


The form of an IP record differs between systems. Some application records use a hash; some security or hosting records can retain an IP address in readable or encrypted form accessible to authorized operators. Hashing or encrypting an address does not necessarily make the associated record anonymous. Network information can help investigate repeated abuse or associated accounts, but a shared address can represent several people and does not by itself prove that accounts have the same owner.


Where supplied by hosting or platform reporting, technical information can include an approximate country, region, or city inferred from an IP address. Such estimates are imprecise and can reflect a network endpoint, proxy, or VPN. An application may receive a country indication without independently determining a city or retaining the underlying address. A country entered in your profile is a separate source of information.


These practices do not involve collecting precise GPS location. A player's position, teleport destination, region, or spawn point in a virtual world is an in-game coordinate, not the player's physical location. We do not describe either an IP-based estimate or a virtual-world coordinate as precise real-world location.


Activity, search, and operational information


Depending on the functionality used, activity information includes visits and requests, sign-in and last-activity times, content you view or interact with, reading progress, notification read status, favorites, recent launches, and participation in groups, parties, rooms, or discussions. Community software can maintain topic subscriptions, bookmarks, saved drafts, replies, likes or other reactions, and revisions. Where a poll or other optional interaction is offered, its response and visibility follow that feature's settings and notice.


Search functionality processes the query and filters needed to return results. A query sent to a website, forum, or search endpoint can also appear in the associated request or operational records. A filter applied solely within an application to information already on your device does not necessarily transmit or store a search history. We do not treat every use of a search box as a permanently saved account history.


Presence functionality can use account identifiers, temporary browser or connection identifiers, heartbeat times, and online or offline state to show whether participants are available and manage active sessions. A presence indicator is not a guarantee that a particular person is continuously using a device.


Operational information can include error details, delivery failures, administrative audit records, and performance measurements generated by our infrastructure. Where server diagnostic tools are used, reports can include technical state and identifiers present in the sampled activity or logs. Generating or sharing a diagnostic report is a separate operation; the availability of a profiling tool does not mean that it continuously collects or publishes user activity.


Games, multiplayer sessions, and virtual worlds


Game functionality can process account or player identifiers, usernames, nicknames, character appearance, room or session identifiers, party membership, invitations, joining requests and their status, host information, participant lists, capacity, and connection or presence state. In games with differentiated roles, it can also process roles, permitted observations, choices, votes, actions, results, and messages visible only to the relevant participants or spectators.


Persistent server and virtual-world functionality can store player identifiers, connection and join or leave records, inventories, stored items, experience, health, hunger, game mode, statistics, achievements or advancements, playtime, spawn information, and in-game position. World records can include changes to blocks or regions, structures, signs, books, and other player-created text or objects. An object remaining in a shared world can continue to contain information associated with its creator.


Where the corresponding game features are offered, records can include virtual currency balances, shop purchases and sales, player trading, listing activity, ownership or membership of protected regions, land claims, trusted users, and teleport-related state or cooldowns. These are records of virtual activity; they do not by themselves mean that Pokenix collects a payment card or processes a real-money purchase. Permissions, display names, group formatting, and character or disguise appearance can be associated with player identifiers by the software implementing those features.


Game and server moderation can involve warnings, restrictions, bans, whitelist entries, relevant IP-based restrictions, reasons, durations, reports, appeals, and staff actions. Commands and chat can appear in server logs or plugin-managed records where the relevant logging is enabled. The records created depend on the enabled game features, integrations, and logging settings.


Some session state and limited interaction history are held only in working memory and end when a session closes, a stage changes, or the server restarts. Other data, including persistent world, player, account, and moderation records, are stored in files or databases and can be included in backups. There is no uniform promise that gameplay is either entirely temporary or permanently recorded.


User content and visibility


User content can include topics, posts, replies, comments, messages, links, profile text, avatars, images, attachments, files, reactions, reports, and other material submitted through an available feature. Records can include the author or sender, audience or recipient, submission time, edits, revision history, and related activity. Uploads can contain personal data within the file itself or its metadata.


Public content and public profile information can be visible to other users, people who are not signed in, search engines, web crawlers, and other third parties. Public topic listings, search results, feeds, or APIs can expose the content and associated information that the relevant area makes public. An area restricted to signed-in users or selected participants has a different audience from a public page. Game rooms and party listings can also disclose a host's display name, session description, or participant information to the audience able to view them. A room code or invite mechanism does not make information public unless the feature actually exposes it.


Access to restricted content depends on permissions and participation, not merely on whether you describe the content as private. Reactions, poll responses, participant lists, and profile activity may have their own visibility settings. Please check the audience before sharing information and avoid posting credentials, sensitive identifiers, or someone else's private information unnecessarily.


People who can see content can copy, quote, download, capture, archive, or redistribute it. Search engines and other services can index or cache public material. Deleting an original item or an account does not necessarily remove another user's quote, an external archive, a search-engine copy, a notification already delivered, or a copy outside our control. Content in a retained discussion or revision can still identify you after an account name is removed.


These practical limits do not remove our obligations concerning records we control. Where applicable law requires erasure, correction, notification to recipients, or reasonable steps concerning public copies, we must address those requirements. Preservation of a discussion is not an automatic legal justification for retaining all personal data within it.


Non-public messages, support, and live voice


Where a Service supports private messages, restricted chat, participant-only conversation, or support correspondence, we process the message, sender and recipient or group identifiers, time, delivery or read information where used, and attachments submitted through that feature. Restricted game channels can limit messages to a role, party, or other defined audience. Non-public messages are not automatically published to the general public.


Access differs between systems. For example, forum administrators can have access to private messages, while ordinary moderators may have access only when they participate or when a message is reported. Operators with authorized database or server access can have technical access to stored messages or session state in software they operate. Access for administration, troubleshooting, support, moderation of reported abuse, or compliance with a legally binding request must have an appropriate purpose and lawful basis. Calling a feature private does not mean that it is end-to-end encrypted or inaccessible to operators.


Support and privacy correspondence can include your contact address, account information, the question or request, relevant screenshots or attachments, troubleshooting details, and our response. Provide only information reasonably needed for the matter. Information about another person or sensitive information included in a report may require additional protections or a different legal basis; sending it to us does not create unrestricted permission to use it.


When you use an optional live voice feature, microphone audio is transmitted through the voice infrastructure to the intended listeners, and the system processes the player or connection identifier, voice session and group information, and network information needed for delivery. Proximity-based delivery can depend on your position in the virtual world. You can control participation using the client and microphone controls available for that feature. Live transmission does not by itself mean that Pokenix creates or retains an audio recording.


Other participants or separately installed recording tools may capture communications. Those copies are distinct from Pokenix's own processing. If you submit an audio file as content or as part of a report, it is processed as a submitted file, rather than as an automatic recording of all live conversations.


Notifications and email


Service communications can include verification or password-reset messages, security notices, account-related messages, support and administrative replies, privacy-request correspondence, announcements, and notifications associated with content or participation. The channels available vary; storing a notification preference does not mean that delivery through every listed channel is implemented.


In-app notification records can include the recipient, message and routing information, creation time, and read or dismissal state. Where notification history is made available, an earlier announcement can remain accessible or become visible to a later participant according to that feature's settings.


Where you permit mobile push notifications, we process the app-specific device token, its association with the relevant account and application environment, preference information, and delivery or retry status. The push notification provider receives the token and notification payload necessary to deliver the alert. Payloads can contain a title, short alert, and routing identifiers; this does not necessarily send the complete underlying message. Notifications can be displayed on a lock screen or another device surface according to your operating-system settings. Disabling notifications affects subsequent delivery and does not necessarily retract alerts already delivered.


Email processing includes the recipient address, name or username where included, message content, subject line, attachments, timestamps, message identifiers, and information about delivery, failures, bounces, complaints, or unsubscribe choices where handled by the provider. We use email delivery providers, email hosting providers, and platform communication or automation services for these functions. The provider handling a particular communication receives the information needed for that function; using several communication services does not mean that each receives every message.


If you subscribe to a newsletter or other optional promotional communication that is offered, your subscription and consent information and the information needed to send it are processed for that purpose. Marketing communications require the permissions applicable to that channel and jurisdiction. You can withdraw the relevant consent or unsubscribe using the option supplied with the communication or by contacting info@pokenix.com. Necessary account, security, legal, and request-related communications can continue under their separate lawful basis.


Where email engagement measurement is used, Pokenix uses limited aggregate open and click counts or rates to evaluate overall communication effectiveness. This applies to promotional and transactional email where measurement is available. Engagement reporting used for Pokenix analytics does not identify individual recipients or provide recipient-level open or click histories. Recipient identifiers, including email and IP addresses, are excluded or anonymized in that reporting.


Email providers can calculate overall open and click counts or rates. Aggregate engagement information can retain event types, dates, or counts without identifying the recipient to Pokenix. We do not use these metrics to determine which particular recipient opened an email or clicked a link.


Aggregate engagement reporting is separate from ordinary email delivery and administration. Email providers process the recipient address, message content, delivery status, bounces, complaints, consent or unsubscribe information, and relevant message metadata needed for those functions. Their infrastructure also handles the technical requests and events needed to deliver email and generate engagement statistics. This does not mean that Pokenix receives identifiable recipient-level engagement metrics or that all personal data involved in email delivery is anonymized. Aggregate reporting does not by itself establish that previously created records have been deleted; any retained records remain subject to the retention and deletion requirements in this Policy.


Aggregate email engagement metrics can include opens generated by email-client privacy features and automated bot activity. An open or click count can therefore reflect automated image loading, a proxy, or a security scanner rather than human reading or deliberate interaction. These effects can inflate apparent engagement, and the aggregate metrics do not establish that a particular recipient read a message or intentionally clicked a link.


Permission to receive a communication and permission for optional engagement measurement are separate where applicable law requires them to be separate. Anonymous reporting does not by itself remove any applicable notice, consent, or device-access requirements. We do not treat an unknown tracking-consent preference as permission for engagement measurement. Managing tracking consent does not change the restriction of Pokenix email engagement analytics to aggregate reporting. You can contact info@pokenix.com about measurement choices or to withdraw a relevant consent. Unsubscribing from promotional communications and managing consent for measurement are distinct choices. Necessary delivery, bounce, complaint, and security records can continue under their separate lawful basis.


Software on your device and extensions


Some software functionality operates on your device, including local notes, task lists, selected files, preferences, and recent-item information. Local processing does not mean that the content is automatically uploaded to Pokenix. Information can remain in local application storage or logs until you remove it using the available controls or your operating system. Removing a server account does not necessarily erase files, backups, or preferences on your device.


An application can make network requests for sign-in, requested online functionality, update checks, or downloads. Update and download infrastructure receives the network information needed to handle those requests. If you send a local file, screenshot, or diagnostic log to support, the submitted material becomes part of that support processing.


Optional extensions, plugins, integrations, or scripts can operate with the capabilities you enable and may send information to their own endpoints. A third-party extension's independent processing is governed by its own applicable privacy information. Review its source, permissions, and notices before providing access. A locally executed script or extension does not automatically become a Pokenix-hosted data collection system.


Purposes and limits of use


We process account, credential, session, and profile information to register and authenticate users, maintain accounts, synchronize authorized profile information, and provide requested account-dependent functionality. We process participation, gameplay, world, content, and communication information to deliver the particular game, community, publishing, group, or communication features you use and to preserve their necessary state.


We use preferences and relevant activity records to apply your settings, restore requested state, present your saved items, deliver chosen notifications, and make interface or catalog suggestions based on those preferences or activity. These uses do not authorize unrelated behavioral advertising.


We use technical, security, report, and moderation information to maintain availability, diagnose problems, manage permissions, investigate abuse, handle appeals, and protect users and systems. Identifiers and relevant evidence can be associated with an account to investigate a specific incident or prevent repeated misuse. A restriction or record in one Service does not necessarily apply automatically throughout the ecosystem.


We process correspondence to respond to questions, support users, administer communications, and handle privacy requests. We use delivery information to send messages reliably and respect communication choices. Website activity and appropriately limited usage, performance, search, and aggregate email engagement reporting help us understand availability, discoverability, visitor activity, and overall communication effectiveness and improve the relevant functionality. These reporting purposes remain subject to the consent and lawful-basis requirements described in this Policy.


We also process information where necessary to meet legal obligations, respond to valid legal process, and establish, exercise, or defend legal claims. A purpose described here does not make every data category necessary for that purpose. Processing must remain relevant and proportionate to the particular need.


Lawful bases


The lawful basis depends on the purpose, data, and applicable law. This Policy is an information notice. Reading it, registering an account, accepting service rules, or continuing to use a Service is not blanket consent to every processing activity or international transfer.


Under Türkiye's Personal Data Protection Law No. 6698, where applicable, processing without explicit consent can be based on necessity directly related to entering into or performing a contract with the data subject, express provision in law, compliance with a legal obligation, establishment, exercise, or protection of a right, or a necessary legitimate interest that does not harm the data subject's fundamental rights and freedoms. Otherwise, an appropriate explicit consent or another specifically applicable statutory condition is required.


For account creation, authentication, and requested communication, community, or gameplay processing, contractual necessity applies only to the extent genuinely necessary to provide the agreed functionality. For mandatory legal retention and legally required disclosures, the basis is the relevant legal obligation or statutory requirement. For handling a concrete dispute or preserving necessary evidence, the basis is the establishment, exercise, or protection of rights where that condition is met. For proportionate security logging, abuse prevention, service maintenance, and limited operational analysis, the basis is a necessary legitimate interest, subject to assessment of necessity and the impact on users. Optional uses requiring consent, including non-essential tracking where required and consent-dependent promotional communications, are handled separately.


If the EU General Data Protection Regulation or UK GDPR applies to particular processing, the corresponding bases are performance of a contract or steps requested before entering into one, compliance with a legal obligation, legitimate interests balanced against your rights and interests, or consent, as appropriate to the purposes above. Our relevant legitimate interests are secure and reliable operation, prevention and investigation of misuse, administration of communities and communications, proportionate improvement of functionality, and protection of legal rights. These interests do not override consent requirements or permit disproportionate processing.


Making information public does not permit unlimited reuse. Any reliance on a statutory condition for information made public must respect that condition and the purpose for which it was made public. Information revealing health, beliefs, biometrics used for identification, or other specially protected matters is subject to additional legal conditions where applicable. We do not request such information as a general condition of ordinary participation.


When we rely on consent, you can withdraw it for future processing without affecting the lawfulness of processing carried out before withdrawal. Withdrawal does not prevent processing under a different valid basis, and we must explain any such continuing basis rather than treating the original consent as irrevocable.


Cookies, browser storage, and similar technologies


Web Services use cookies and similar storage to maintain sessions, carry out authentication, protect requests, and support functionality. Some session cookies contain an opaque identifier rather than the underlying account information. Short-lived authentication-flow storage can associate a request with the returning sign-in response. A cookie's expiration or a session's validity period is not necessarily the retention period of account or security records.


Preference storage can remember a theme or other interface choice. Local storage can hold preferences or reconnection information, such as a room identifier and nickname, and session storage can hold information limited to a tab or browser session. Some information can remain after an unexpected disconnect. We and the website or consent-management providers used for the relevant site maintain cookie consent records, including the choice and time and associated technical information such as the visitor's IP address and device details where included in the consent log. These records support administration of choices and demonstration of consent or refusal. Different Services can have their own consent records and controls.


Hosted websites can use provider-controlled cookies needed for hosting, security, and reliable delivery. Websites with visitor measurement enabled also use analytics technologies in connection with the website analytics processing described below. Certain visitor activity tracking depends on cookie consent. Other analytics, embeds, or integrations can introduce additional storage or access technologies when enabled. Cookie information is specific to each site's configuration; the relevant site's cookie information and consent interface, where provided, identify the technologies used there.


Technologies strictly necessary for a requested service are treated separately from optional preferences, measurement, or marketing. Where applicable law requires prior consent for non-essential storage or access, that processing requires the relevant choice before it starts. A legitimate interest in improving a Service is not a substitute for a legally required cookie consent.


You can use available cookie controls and your browser settings to manage or remove storage. Browser controls do not necessarily change a consent record or delete server-held information, and blocking necessary session storage can prevent sign-in or requested functionality. Clearing browser storage does not necessarily delete an account, unsubscribe from email, or remove previously submitted content.


Measurement, search visibility, and externally loaded resources


Hosting providers and website platforms process requests and operational information to deliver and secure hosted pages. We use website analytics on Pokenix websites where visitor measurement is enabled. Depending on the website and measurement used, the information available to us includes page views, traffic sources, device categories, recent or live visitor information, and approximate location such as country or city supplied by the provider. Reports can contain visitor or session-level activity as well as aggregate statistics; the absence of a real name does not necessarily make a visitor record anonymous. Location estimates derive from network information and do not establish precise GPS location.


Pokenix's access is to the reports and records made available for its site, not automatically every underlying record that a provider processes for its own platform. Certain visitor activity tracking is subject to cookie consent, and the associated consent records are maintained as described above. The applicable cookie choices and notice govern consent-dependent tracking. Essential hosting and security processing are distinct from optional visitor measurement. A provider's additional capabilities do not establish that Pokenix uses those capabilities.


Search performance services provide information about how Pokenix websites appear in search results and are crawled or indexed. Reports can include search queries, impressions, clicks, click-through rates, search positions, landing pages, countries, device categories, search appearance, and crawling or indexing information. Reports can be aggregated or omit some query information for privacy. These reports do not give Pokenix access to an individual user's search-provider account or complete search history. Verifying website ownership for search performance reporting does not by itself install behavioral tracking or cookies on a Pokenix site. This reporting is distinct from website visitor analytics.


Where a page loads a resource directly from a third-party host, that host receives the request information needed to deliver it, which can include the IP address, user agent, and referrer subject to browser settings. For example, pages using externally hosted fonts cause font requests to the font host. Such a resource request is separate from an analytics cookie or an advertising profile. Embedded content and interactive external resources can involve additional provider processing according to their own notices and the relevant configuration.


Recipients and integrations


Personal data is made available to Pokenix personnel and authorized administrators or moderators as needed for their responsibilities. Access depends on the system, role, and purpose; community moderation privileges do not automatically grant access to every account, credential, private communication, or infrastructure record.


Infrastructure recipients include hosting and server providers, website platforms, database and storage infrastructure, network and content delivery services, and providers used to operate or support authentication, security, and diagnostics. They process the data needed for the function they provide. A software project's publisher is not automatically a recipient of data merely because we run its software on our own infrastructure.


Measurement recipients include website analytics providers and search performance services for the reporting described above. The use of a provider for one function does not mean that it receives every category of data described in this Policy.


Communication recipients include email delivery and hosting providers, push notification providers, platform communication or automation services, and services used for authorized account linking or message delivery. App distribution and update hosts handle requests for the downloads or updates they provide. Other users receive information according to the visibility and participation rules of the relevant content, conversation, game, or community feature.


Where an account-linking or community-to-game bridge is enabled and you use it, the integration can associate platform user identifiers with game or account identifiers, synchronize configured roles, or relay selected messages and related sender information between environments. Relayed material becomes visible to the audience of the destination area as well as any audience at its source. An integration's ability to perform additional functions does not mean that those functions are enabled. A link or bridge does not automatically give Pokenix access to your unrelated platform conversations or platform credentials.


If you contact us about a contribution made through an external hosting platform, correspondence can include a contributor identifier and relevant credit or contribution details. The external platform handles its own billing and payment processing. A contribution record or a virtual economy record does not establish that Pokenix receives your full payment credentials.


Information can also be provided to a professional adviser where necessary for a particular legal, privacy, or security matter, subject to the applicable confidentiality and legal requirements. Any processing by a provider on our behalf requires the applicable instructions, contractual arrangements, and protections. A provider acting for its own purposes has separate responsibilities, and a provider's general privacy policy does not establish that Pokenix has implemented a particular contractual safeguard.


You can contact info@pokenix.com for information about the particular providers and recipients relevant to your processing. Where applicable law requires a provider to be specifically identified or additional information to be provided, we must supply that information through the appropriate privacy notice or other required disclosure. Describing recipient categories here does not replace those obligations.


Third-party platforms and unrelated external links


A Pokenix-operated space on a third-party platform involves both our administration of that space and the platform's own processing. This Policy applies to the information Pokenix receives or controls for its own purposes. The platform's privacy policy, terms, account controls, and age requirements also apply to its platform processing.


In a community hosted on an independent communication platform, Pokenix administrators can receive or view member user identifiers, usernames, display names, avatars, roles, membership and participation information, messages visible under channel permissions, and moderation information, according to the platform's permissions. A bot or integration can receive additional information only within its permissions and configured functions. The platform's own processing of account credentials, IP addresses, device information, or payment information does not mean that ordinary Pokenix community administrators receive those records. Communicating with Pokenix through a separate website or an external integration can create a separate data flow.


Website hosting and platform providers can process site-visitor data on the site operator's behalf, while also processing information independently for their own platform purposes. Game-server hosting providers can store server files and logs and process player or connection information needed for hosting and operation. That does not mean that Pokenix players must provide Pokenix with a hosting-provider account, or that the host's own customer billing records become Pokenix player records.


Software distribution and account platform providers can separately process information when you obtain software, use a platform account, or use their infrastructure. Pokenix receives only the information made available through the relevant integration or developer reporting; use of a platform does not automatically give us its complete customer or account records.


Pokenix Services may contain links to websites, applications, platforms, services, or resources not operated or controlled by Pokenix. When you follow an external link, the third party's privacy policy, terms, cookie policy, and other rules may apply. Pokenix does not control unrelated third-party privacy practices, data processing, security, content, or policies. Review the relevant privacy information before providing data or using an external service. A link does not by itself imply Pokenix ownership, operation, control, or endorsement. This external-link principle does not remove our responsibility for our own processing or our operation of a presence hosted on a third-party platform.


Legal requests and protection of rights


We may be required to disclose information to courts, law enforcement, regulators, government agencies, or other legally authorized parties under applicable law, valid legal process, a court order, subpoena, regulatory request, or another legally binding requirement. Disclosure must be limited to information reasonably necessary or legally required under the applicable request, with consideration of its validity, scope, and the protections available under applicable law.


A non-binding request does not by itself create an entitlement to unrestricted access. A separate disclosure to address a concrete threat, investigate unlawful misuse, or protect a legal right requires its own lawful basis and a necessary, proportionate scope. This Policy does not grant governments general access to our systems or all user records.


International processing and transfers


Personal data can be processed or stored in countries other than your country of residence through the infrastructure, platforms, and service providers used for Pokenix Services. These locations depend on the particular Service, provider, product, resource configuration, and operation involved. Laws and available protections can differ between countries.


For applications, account systems, databases, and other infrastructure operated by Pokenix using hosting providers, the physical hosting location depends on the configuration of the relevant resource. The application database, backups, logs, and provider support or security processing can have different locations. A provider's list of available regions does not identify the region selected for a Pokenix resource, and this Policy does not assign a single country to all Pokenix-controlled infrastructure.


Third-party platforms and service providers determine the locations for the processing they carry out within their services, subject to the applicable arrangements. Storage in a stated region does not necessarily mean that all support access, delivery, content distribution, or subprocessor activity occurs only there. An optional data-residency feature applies only to the products and data it covers and when it is actually selected; its availability does not establish that it applies to our account. Provider headquarters, a domain name, and the location of a user do not establish where every copy of their data is stored or accessed.


An international transfer must satisfy the requirements applicable to Pokenix's processing. Under the current transfer provisions of Türkiye's Personal Data Protection Law, this can require an applicable adequacy decision and processing condition, or an available statutory safeguard meeting the required conditions, such as an appropriate standard contract or other authorized safeguard. The statutory exceptions for occasional transfers are limited and are not a general solution for routine international hosting or communications.


Where EU or UK data protection law applies, restricted transfers require the applicable adequacy arrangement, appropriate safeguards, or a narrowly applicable derogation. EU and UK transfer requirements are not interchangeable with Türkiye's requirements. A provider's own use of standard clauses, or a provider's public assurance of compliance, does not by itself establish that every Pokenix transfer meets the relevant law.


Cross-border processing is subject to applicable law and appropriate safeguards where required. The required mechanism and its associated obligations must be satisfied for the particular transfer; this Policy is not itself a transfer safeguard. Publication of a provider's DPA, standard clauses, certification, or list of subprocessors does not by itself verify that a particular mechanism covers Pokenix's processing or satisfies Türkiye's transfer requirements. You can contact info@pokenix.com for information about the destinations, recipients, and safeguards applicable to your processing and, where required by law, a copy or meaningful description of the relevant safeguards with appropriate protection for confidential information. Use of a Service is not blanket consent to transfer data to any country.


Retention, deletion, and anonymization


Retention depends on the purpose and system. Account and profile information is retained for the operation of the account and associated functionality, subject to a valid deletion request and any lawful continuing need. Content and shared-world records can remain relevant while a discussion, community record, or world continues. Security, moderation, support, delivery, and administrative records have different purposes and must not be retained indefinitely merely because they might someday be useful.


Relevant criteria include whether the account or feature remains in use, whether information is needed to maintain requested functionality, the age and relevance of a security incident or moderation record, an unresolved complaint or dispute, a required legal retention period, applicable limitation periods, and the practical backup cycle. Any continued retention must have a valid basis and a proportionate scope. Where the purpose and other lawful grounds end, personal data must be erased, destroyed, or genuinely anonymized as required by applicable law.


Following verification of a valid deletion request, public-facing account information and profile content can generally be removed or disabled within 1 to 3 business days. This timeframe concerns the account and profile presentation on Pokenix-controlled interfaces; it is not a promise that every post, quote, search-engine copy, or previously delivered communication disappears within that period.


Deletion of personal data from active internal systems may take up to 30 days, depending on the nature and scope of the request and applicable legal requirements. Information that has a necessary, lawful continuing retention basis is handled as described below. These operational timeframes do not extend statutory deadlines or change when a legally valid request starts an applicable response period. Where the law requires an earlier response or action, that requirement takes precedence. Any legally permitted extension requires the applicable conditions and notice.


Ending a session, clearing a local preference, unsubscribing from a message category, deleting a post, deleting a Service account, and deleting a shared authentication account are different actions. Data can be distributed across connected Services and platforms, and the scope of a request matters. You can ask us to address information across Pokenix-controlled systems without needing to identify every internal database.


Deletion from active records does not necessarily remove every backup immediately. A backup can temporarily retain information until it is overwritten, expires, or is otherwise lawfully removed. Any retention or restoration of backup data remains subject to applicable deletion, restriction, security, and lawful-processing requirements. Backups do not provide an exemption from those requirements or permit deleted data to be returned to unrestricted ordinary use.


Removing a community account may involve deleting it or replacing account identifiers so that existing discussions can remain. Replacing a username, removing an email address, or disconnecting an avatar does not necessarily anonymize identifiable post text, attachments, quotes, revision history, IP records, or administrative logs. Those remaining records must be assessed separately. We do not describe pseudonymous data as irreversibly anonymous merely because a visible profile name has changed.


Some information can be retained after account deletion where necessary for legal obligations, security, fraud or abuse prevention, a specific dispute, proportionate moderation records, backups subject to the requirements above, or another applicable lawful purpose. Each retained category needs its own valid basis and proportionate retention period; these purposes do not justify retaining an entire account indefinitely. A necessary restriction record can be distinct from the deleted profile. Where a request cannot be fulfilled in full, the applicable reason and scope of retained information must be explained as required by law. External platform records, copies held by other users, and files on your own device may require separate action through their respective controls or operators.


Controls and privacy requests


Depending on the Service, available controls allow you to edit certain profile fields, manage preferences and notifications, remove your own content, manage sessions, change authentication methods, or obtain an export. Availability and scope vary. An export supplied by a particular interface need not contain every record controlled by Pokenix, and a missing interface control does not remove a statutory right.


For privacy inquiries, access, correction, deletion, or another applicable right, contact info@pokenix.com. Identify the relevant account or Service where possible and describe the request. Tell us whether it concerns a particular item or account or your information across Pokenix Services. We may need additional information to locate the relevant records and reasonably verify that you are the data subject or an authorized representative, in accordance with applicable law.


Verification must be proportionate to the request and its risks. Do not send a password, authentication secret, recovery code, or an unnecessary complete identity-document copy by email. If further verification or a legally prescribed submission method is needed, we will explain the information or procedure required. A request must not expose another person's private information or undermine the security of an account.


Rights, exceptions, response periods, and permitted fees depend on the law governing the processing. We must respond within the applicable period, explain a lawful refusal or limitation where required, and provide information about any available review or complaint route. We do not promise immediate erasure of all records, and a technical limitation alone does not cancel a legal obligation.


Rights under Türkiye's Personal Data Protection Law


Where Law No. 6698 applies, you can learn whether your personal data is processed, request information about that processing, learn its purpose and whether data is used consistently with that purpose, and learn the third parties to whom it is transferred domestically or abroad. You can request correction of incomplete or inaccurate data, request erasure or destruction under the statutory conditions, and request notification of the relevant correction, erasure, or destruction to recipients.


You can also object to a result against you arising from analysis of your data exclusively through automated systems and seek compensation for damage caused by unlawful processing.


You must first apply to the data controller in accordance with the applicable procedure. Formal applications under the relevant request rules are submitted in Turkish and must contain the legally required information and use an accepted submission method. An email sent from an address previously provided to the controller and recorded in its system can be an accepted method under those rules. info@pokenix.com is available for privacy contact and assistance with the applicable procedure, including where another formal method is needed.


Requests must be resolved as soon as possible and within 30 days, subject to the applicable rules. Processing the request is free unless the legally permitted cost tariff applies. If the response is rejected or inadequate, or no timely response is given, the applicable procedure permits a complaint to the Personal Data Protection Board. The statutory complaint periods include 30 days from learning of the response and, in any event, 60 days from the application date; the appropriate period must be assessed under the circumstances and applicable rules.


EU, EEA, UK, and other applicable rights


The EU General Data Protection Regulation and UK GDPR apply according to their territorial and other legal conditions, including relevant establishment, offering of services, or monitoring of behavior. A website's mere accessibility from a country does not by itself settle applicability. We do not assume that every privacy framework applies to every Pokenix user.


Where the GDPR or UK GDPR applies, you can request access to your personal data and processing information, correction, erasure where its conditions are met, and restriction of processing in the circumstances provided by law. Where processing is automated and based on consent or contract, the right to data portability can entitle you to receive qualifying data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.


You can object, on grounds relating to your particular situation, to processing based on legitimate interests, subject to the legally permitted grounds for continuing it. You can object to direct marketing and related profiling without that balancing requirement. Consent can be withdrawn at any time for future processing.


Requests normally require a response within one month under those laws. An extension of up to two additional months is available only where justified by complexity or the number of requests, with the required explanation within the initial month. The laws also specify when a proportionate fee or refusal is permitted for manifestly unfounded or excessive requests.


You can complain to the competent supervisory authority, including the authority in the EU or EEA member state of your habitual residence, workplace, or the alleged infringement, or the UK Information Commissioner's Office where applicable. Contacting us first can help resolve a concern but is not a mandatory prerequisite to those complaint rights.


Other laws can provide additional rights, including information, correction, deletion, objection, or review rights, when their territorial scope and statutory conditions are met. The availability of a Service does not establish that Pokenix meets every business threshold in another jurisdiction. Contact info@pokenix.com to request an applicable right or ask which processing is covered.


Age eligibility and children's privacy


You must be at least 18 years old and have reached the age of legal majority in your country or jurisdiction of residence to create an account or use interactive Pokenix Services. Both requirements apply. Account creation and interactive functionality, including games, communities, publishing, and messaging, are intended for eligible adults. Parental permission or a third-party platform's lower minimum age does not override this Pokenix requirement. An app-store content rating is not proof of legal eligibility or age verification.


In the registration flows for applicable Pokenix Services, users are required to confirm that they are at least 18 years old and have reached the age of legal majority in their country or jurisdiction of residence before completing registration. We process this required confirmation to apply the registration eligibility requirements.


The registration confirmation is a user attestation. It is not formal identity verification or independent verification of the user's actual age. Requiring the confirmation does not establish that every user's age has been independently verified. Eligibility requirements for account creation and interactive use are distinct from the processing of ordinary technical information when someone visits a publicly accessible page. An age restriction also does not establish that no younger person has visited a page or supplied information.


The processing of any child's data remains subject to applicable child-protection and data protection requirements, including additional protections or parental authorization where legally required. Such authorization does not make a person who fails the eligibility requirements eligible to create an account or use interactive Services.


If you believe that someone below the applicable eligibility age has created an account or that we have processed a child's information contrary to applicable law, contact info@pokenix.com. We will assess the relevant processing and take the steps required by law, including restriction or deletion where appropriate. We must retain only information that has a necessary, lawful continuing basis, such as limited evidence needed to handle the concern. A platform's family or privacy controls do not necessarily govern all processing by a separately operated Service.


Security and incidents


Our architecture includes HTTPS and TLS for supported web and API connections, authenticated sessions, scoped permissions, role-based access in administrative systems, and rate limits or related login protections where implemented. Connected authentication flows use measures such as PKCE and validation of authentication responses. Certain credentials or tokens are hashed or encrypted, and supported native applications use protected operating-system storage. These measures apply to the particular systems and data fields implementing them, rather than establishing that every database, backup, or communication is encrypted in the same way.


Administrative access, server operation, and security records support protection against unauthorized access, misuse, and disruption. Security measures must be appropriate to the processing and risks. No system or transmission method can guarantee absolute security, and this Policy does not claim end-to-end encryption, independent security certification, or complete prevention of incidents.


If a personal data breach occurs, applicable law determines our obligations to investigate, contain and address the incident and to notify the relevant authority and affected people when required. Required notifications must be made within the applicable legal periods; this Policy does not substitute a discretionary timetable for a statutory requirement.


Changes and contact


We review this Policy when functionality, data practices, providers, technology, or legal requirements change. A routine provider or technical change within a described category does not by itself expand the data, purposes, or uses permitted by this Policy. Where a change materially affects the processing described here, including data categories, purposes, recipient roles, privacy protections, or international transfers, we must update the applicable privacy information and provide any notice or obtain any consent required by law. Specific provider disclosures and cookie information must also be kept current where required. The Updated date at the beginning identifies the current version and its stated effective time. For material changes, we will provide the additional notice required by applicable law, using an appropriate Service notice, account communication, or other suitable method.


An updated Policy does not retroactively authorize unlawful processing, remove existing rights, or replace consent where consent is required. If a new purpose or feature requires additional information or consent, that requirement must be addressed before the relevant processing begins. A separate or supplemental notice can explain a specific feature without requiring a fixed list of product names in this Policy.


For questions about this Policy, processing information, or requests for access, correction, deletion, or other applicable privacy rights, contact info@pokenix.com.

bottom of page