Privacy

Who is responsible

The controller of your personal data is Mateusz Urbaniak, acting for Mrged Mistakes, an independent game studio from Łódź, Poland. You can reach us about your data at [email protected].

What the contact form collects

When you use the contact form, we receive your name, your email address, the topic you chose, and your message. Giving us these details is voluntary, but without them we cannot answer you.

Why, and on what basis

We use these details only to reply to your enquiry. The legal basis is our legitimate interest in answering messages sent to us (Article 6(1)(f) GDPR). We do not use them for marketing, and we do not sell or share them.

Where it goes and how long we keep it

The site does not store your message in a database. It is delivered by email to the studio's inbox, and the team members who handle enquiries can read it. We keep it only as long as the conversation needs it, and for as long as we may need it to deal with a follow-up or a claim.

Email delivery (Resend)

To deliver your message to our inbox, our server hands it to Resend, an email delivery service of Resend, Inc. Resend receives your name, your email address, the topic and the message, and acts for us only to deliver the email. Resend is based in the United States, so this data can leave the European Economic Area; Resend covers such transfers with standard contractual clauses in its data processing agreement. See Resend's privacy policy for how long it keeps delivery records.

Bot protection (Cloudflare Turnstile)

To keep automated spam out, the contact form uses Cloudflare Turnstile, a service of Cloudflare, Inc. The Turnstile script is loaded from Cloudflare's servers only on the contact page. It runs a check in your browser, and Cloudflare receives technical data to tell people from bots: your IP address, and browser and device signals. When you send the form, our server passes the check result and your IP address to Cloudflare to confirm it.

The legal basis is our legitimate interest in protecting the form and the studio's inbox from abuse (Article 6(1)(f) GDPR). Cloudflare acts for us in running the check. Cloudflare is based in the United States, so this data can leave the European Economic Area; Cloudflare says it protects such transfers with the EU–U.S. Data Privacy Framework and standard contractual clauses. The check is automated, but it only decides whether the form accepts your submission and has no legal or similarly significant effect on you. If it fails, you can try again or write to [email protected].

See Cloudflare's privacy policy and the Turnstile documentation for exactly what Cloudflare processes and for how long. We do not use Turnstile for advertising.

Server logs and abuse limits

Like any website, our web server records standard technical details of each request: your IP address, the time, and the page requested. We use them to run the site securely and to fix faults (legitimate interest, Article 6(1)(f) GDPR), and they are deleted by routine log rotation. To stop a single address from flooding the form, the server also counts form submissions per IP address in memory for an hour. That count is not written to disk and disappears when the service restarts.

Cookies and analytics

This site sets no analytics or advertising cookies and does not track you across pages. We use no analytics service. The only third-party resource it loads is the Cloudflare Turnstile check, and only on the contact page.

Other sites

The site links to services such as Steam, itch.io, Instagram, LinkedIn and GitHub. They have their own privacy policies, and we do not control what they do with your data once you follow a link.

Your rights

Under the GDPR you can ask us for access to the data we hold about you, ask us to correct or delete it, ask us to restrict how we use it, and object to our using it on the basis of legitimate interest, on grounds relating to your situation. Write to [email protected] and we will answer within one month.

You can also lodge a complaint with a data protection authority. In Poland that is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw.