Your privacy matters to us. HeadBox is currently an Early Access / Public Demo platform. We collect only the data we need to run a waitlist, provide accounts, keep the game fair, and improve the product. This Policy explains what we collect, why, and what rights you have over it.
Introduction
Verse Digital GmbH ("we," "us," "our") operates HeadBox, a competitive survival shooter currently available as an Early Access / Public Demo. This Policy applies to our website, our waitlist, and the demo build.
Because HeadBox is still in development, the Platform is limited in scope: an account, a waitlist place, and the demo build. Everything we collect is listed in Section 2, and we collect nothing beyond it. If the Platform gains features that need more data, we will update this Policy and tell you before that processing begins.
HeadBox is intended for users aged 18 or over. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us using the details in Section 13 and we will delete the data and close the account.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This Policy should be read alongside our Terms of Use and Cookie Policy.
Information We Collect
We collect the following, and nothing more:
Account Data
- Username;
- Email address;
- Password, stored only as a one-way hash — we never see or store it in plain text;
- Basic account settings, such as your communication preferences.
Device & Usage Data
- IP address, browser type and version, operating system, and device identifiers;
- Log files, error reports, and crash data;
- Pages visited and how you move through the site, collected through analytics.
Support Data
- Messages you send us, including bug reports and feedback, and our replies.
We do not collect identity documents, banking details, or biometric data, and we do not ask for your full legal name, date of birth, or address.
How We Use Information
We use your data only for the following purposes:
- Account Management: Creating your account, reserving your username, authenticating you, and managing your waitlist place;
- Platform Functionality: Delivering the demo build and keeping the site and game working as intended;
- Analytics: Understanding how the site and demo are used so we can see what works;
- Security: Protecting accounts, detecting cheating and abuse, and preventing unauthorised access;
- Customer Support: Answering your questions and investigating problems you report;
- Communication: Sending service messages such as account confirmations and security alerts, and — only if you opt in — development updates about the game;
- Product Improvement: Using feedback and aggregated usage data to improve HeadBox before full release.
We do not sell your personal data. We do not use automated decision-making that produces legal or similarly significant effects on you without offering human review.
Legal Bases for Processing
Under the GDPR we must have a valid legal basis for each processing activity. We rely on:
- Contract Performance (Art. 6(1)(b)): Providing your account and the demo, as described in our Terms of Use;
- Legitimate Interests (Art. 6(1)(f)): Platform security, anti-cheat, abuse prevention, and product improvement. We balance these against your rights before relying on this basis;
- Consent (Art. 6(1)(a)): Optional analytics cookies and development-update emails. You can withdraw consent at any time, without affecting processing carried out beforehand;
- Legal Obligation (Art. 6(1)(c)): Responding to lawful requests from authorities.
We do not process special category data.
Anti-Cheat & Platform Security
A fair game matters even in a demo. To detect cheating and abuse we may collect and analyse:
- Device identifiers, to detect multi-accounting or banned devices;
- IP address and connection data, to spot suspicious access patterns;
- Gameplay telemetry, analysed for patterns consistent with automated assistance;
- Account activity, such as login frequency and device switching.
We rely on legitimate interests for this processing. Where our systems flag a possible violation, a member of our team reviews it before any account restriction is applied, and you may contest the outcome through the process set out in our Terms of Use.
Cookies & Analytics
A cookie is a small text file stored on your device. We use three kinds:
- Strictly Necessary: Required for the site to work — sign-in, session management, and security. These cannot be switched off;
- Analytics: Help us understand page views, session length, and errors. Set only with your consent;
- Functional: Remember preferences such as language. Set only with your consent.
We do not use marketing or advertising cookies. You can change your choices at any time through the Cookie Preference Centre in the site footer; turning off optional cookies will not stop you using HeadBox. Analytics data is aggregated or pseudonymised wherever possible. See our Cookie Policy for the full list.
Sharing of Information
We do not sell your personal data. We share it only where necessary, with:
- Service Providers: Cloud hosting, email delivery, analytics, and customer support tools. Each is contractually bound to process data only on our instructions;
- Legal & Regulatory Authorities: Where required by law, or where disclosure is necessary to protect rights, property, or safety;
- Corporate Transactions: If our business is merged, acquired, or restructured, subject to equivalent data protection commitments;
- With Your Consent: For anything not listed above.
These providers operate their own privacy policies, which we encourage you to review. This Policy does not cover third-party sites you reach by following links from HeadBox.
International Transfers
Some of our service providers operate outside the European Economic Area. Where your data is transferred outside the EEA, we rely on one of the following safeguards:
- A European Commission adequacy decision covering the destination country;
- The European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR;
- Another lawful transfer mechanism recognised under applicable law.
You may request a copy of the safeguards that apply to your data using the contact details in Section 13.
Data Retention
We keep data only as long as we need it:
- Account Data: For as long as your account is open, and up to 12 months after you close it;
- Security & Anti-Cheat Logs: Up to 12 months, to support ongoing investigations and appeals;
- Support Messages: 24 months from the date the matter is resolved;
- Analytics Data: Identifiable session data for no more than 14 months; aggregated statistics may be kept indefinitely.
When data is no longer needed it is securely deleted or irreversibly anonymised.
Your Privacy Rights
Under the GDPR you have the right to:
- Access (Art. 15): Get a copy of the data we hold about you;
- Rectification (Art. 16): Have inaccurate or incomplete data corrected;
- Erasure (Art. 17): Have your data deleted where we no longer need it;
- Restriction (Art. 18): Limit how we process your data in certain circumstances;
- Portability (Art. 20): Receive your data in a structured, machine-readable format;
- Object (Art. 21): Object to processing based on legitimate interests;
- Withdraw Consent: At any time, without affecting processing carried out beforehand;
- Complain: To a supervisory authority — in Germany, the data protection authority of the federal state in which we are registered.
To exercise any of these rights, contact us using the details in Section 13. We respond within one month, as required by the GDPR, and may need to verify your identity first.
Security
We use technical and organisational measures to protect your data, including:
- Encryption in transit using TLS 1.2 or higher;
- Passwords stored using modern one-way hashing — we never store them in plain text;
- Access controls limiting staff access to personal data on a need-to-know basis;
- Monitoring for suspicious activity and unauthorised access.
If a data breach is likely to put your rights at risk, we will notify the supervisory authority within 72 hours of becoming aware of it, and tell you directly where the risk is high. No system is completely secure — please keep your password private and tell us immediately if you suspect someone else has accessed your account.
Changes to This Policy
We will update this Policy as HeadBox develops. The revision date is shown at the top of the page.
For material changes — including any that introduce new categories of data or new purposes — we will give you prominent notice before they take effect, by in-platform notification or email. Continuing to use HeadBox after a revised Policy takes effect means you acknowledge it.
Contact Information
For any question or request about this Policy or your data:
- Data Controller: Verse Digital GmbH
- Privacy Enquiries: Available through our Help Centre
- Website: www.verse-digital.de
We acknowledge requests within 5 business days and respond within one month. If you are not satisfied with our response, you may lodge a complaint with the competent supervisory authority.