Privacy policy
How personal data is processed, disclosed, retained, and protected, and your rights.
- 01Controller and scope
- 02Personal data processed
- 03How data is collected
- 04Purposes and legal bases
- 05Public profiles and rankings
- 06Recipients and service providers
- 07International transfers
- 08Cookies and similar technologies
- 09Retention and deletion
- 10Security
- 11Your rights and requests
- 12Children and representatives
- 13Policy changes
01Controller and scope
The operator that provides the Hamleon-branded site to end users is the data controller for player accounts and service operations on that site. Where Hamleon software or hosting is supplied for a licensed operator, controller and processor roles follow the parties’ contract and actual decisions about processing.
This policy covers data processed when you use the website, game client, store, tournaments, chat, and account areas as a visitor, guest, registered player, or support requester.
02Personal data processed
- Account and contact: username, email, verification status, language, account type, and role;
- Authentication and security: irreversible password digest, sessions, device-token digest, IP address or security-derived IP digest, browser details, login and audit logs;
- Profile and community: display name, profile image, cosmetic frame, level, friendships, blocks, chats, direct messages, gifts, notifications, and reports;
- Games and tournaments: room or table participation, moves and results, rating, league, missions or achievements, tournament entries, standings, and prizes;
- Economy and purchases: jeton balance and ledger, inventory, VIP, product or order code, amount, currency, provider reference, payment and refund status;
- Support and moderation: request content, attachments, replies, sanctions, appeals, and staff action records;
- Technical use: timestamps, request data, device class, errors, performance, service health, and security events.
Full payment-card numbers and security codes are not stored in the platform database; card data is handled in the payment provider’s secure environment.
03How data is collected
Data comes electronically from registration and account forms, game, chat and store actions, technical records produced by the device and browser, verified payment-provider notifications, and support or moderation workflows.
Public-profile data enters public-site collections only when you enable the relevant visibility setting.
04Purposes and legal bases
- Contract formation and performance: registration, authentication, running games, calculating results, jetons and prizes, delivering purchases, and support;
- Legal obligation: accounting, consumer transactions, lawful authority requests, recordkeeping, and notifications;
- Legal claims: payment disputes, fraud, sanctions, content complaints, and litigation records;
- Legitimate interests: service security, abuse prevention, debugging, capacity planning, and proportionate service analytics, balanced against your rights;
- Consent: non-essential cookies or measurement, optional public-profile visibility, and activities for which law requires separate consent. Consent may be withdrawn at any time.
05Public profiles and rankings
Display name, profile image, cosmetic frame, game activity, ranking, and tournament results are published only when the relevant public-profile permissions are enabled. Email, account or session IDs, wallet and payment references, table IDs, and private messages are excluded from public CMS collections.
Disabling visibility stops new public display; transaction records that must lawfully be retained are unaffected.
06Recipients and service providers
Data may be disclosed only as necessary to role-authorised platform staff; hosting, database and file-storage providers; email and notification services; the payment provider; security and error-monitoring services; professional advisers; and legally authorised public bodies.
Providers are bound by confidentiality, security, and instruction limits. Personal data is not sold for advertising.
07International transfers
If infrastructure or a technical provider is abroad, transfer occurs only where Article 9 of Turkey’s Law No. 6698 permits it, including an adequacy decision, an appropriate safeguard such as standard contractual clauses or binding corporate rules, or an applicable occasional-transfer condition. Data categories, country, recipient, and safeguards are assessed before transfer.
08Cookies and similar technologies
- hamleon_session: secure authentication cookie with HttpOnly, Secure in production, and SameSite=Lax; for the browser session or up to 7 days depending on “remember me”;
- hamleon_device: signed device token used for abuse and access-restriction controls; 1 year;
- HAMLEON_LOCALE_[site]: site-scoped language preference; 1 year.
Non-essential analytics, advertising, or targeting technology does not run without consent. You can delete cookies in browser settings; blocking essential cookies may break sign-in and security features.
09Retention and deletion
Data is retained only while needed for the account and service contract, security, statutory records, and limitation periods. Payment, order, refund, and accounting records are kept for the period required by commercial and tax law (generally up to 10 years depending on record type); guest identity is retained for 7 days, guest chat for 30 days, and anonymous room-activity measurements for 90 days.
Other data whose processing grounds end is deleted, destroyed, or anonymised under the retention and deletion policy. Backup data is put beyond use through normal backup rotation; records needed for an active dispute, security review, or lawful request may be preserved under restricted access until resolution.
10Security
The platform applies risk-based measures including role-based access, tenant isolation, modern one-way password hashing, storage of session-token digests rather than raw tokens, HTTPS, audit logging, rate limits, security monitoring, backups, and oversight of authorised personnel.
No system can promise absolute security. If personal data is unlawfully obtained, notices required by law are made to affected people and the Turkish Personal Data Protection Board.
11Your rights and requests
Under Article 11 of Law No. 6698, you may ask the controller to:
- confirm whether your data is processed and provide information;
- explain purposes, purpose-compatible use, and domestic or overseas recipients;
- correct incomplete or inaccurate data and, where conditions apply, delete or destroy it;
- notify recipients of correction or deletion;
- allow you to object to an adverse result based solely on automated analysis;
- compensate damage caused by unlawful processing.
Submit a request through the support centre linked to your account. After identity verification, requests are handled free of charge as soon as possible and no later than 30 days; the Board’s tariff may apply if the request creates an additional cost.
12Children and representatives
Users who cannot legally act independently should use account and purchase features under legal-representative supervision. Representatives may apply through support with evidence of authority. The platform may verify both the user and representative before responding.
13Policy changes
If purposes, recipients, technologies, or legal bases materially change, this policy is updated and announced before the effective date. Where a new activity requires consent, consent is requested separately from acceptance of this policy.
