← Back to home

Privacy Policy

How Brainsoft Games processes your personal data in Ashram and on this site, in accordance with the General Data Protection Regulation (EU) 2016/679.

Last updated · 3 October 2026

1. Who the data controller is

The controller of your personal data is Brainsoft Games ("Brainsoft", "we", "us"), developer and operator of the video game Ashram and of the ashram.live website.

For any matter concerning your personal data, including the exercise of your rights, you can write to llboom@brainsoft.games. We answer requests within one month of receipt at the latest; that period may be extended by two further months for complex requests, and we will tell you why.

2. What data we process

We process only the data needed for you to play, to keep your account and to run the service securely:

  • Account data: email address, username and password (always stored hashed, never in plain text).
  • Game data: characters, level, progress, inventory, lineage, path, session history and gameplay statistics.
  • Content you publish: messages, posts, comments and images you upload to the community section.
  • Technical data: IP address, session identifier, browser type, operating system, and access and error logs.
  • Anti-fraud data: connection records and cheat-detection signals linked to your account.
  • Communications: the email you send us and, if you subscribe voluntarily, your address for the newsletter.

We neither request nor need special categories of data (health, beliefs, ethnic origin, sexual orientation, biometrics). Please do not include such data in your posts or support messages.

3. Purposes and legal bases

Each processing activity has a specific purpose and a legal basis under Article 6 GDPR:

  • Creating and maintaining your account and providing the game service — basis: performance of a contract (Art. 6(1)(b)).
  • Saving your character progress and syncing it across sessions — basis: performance of a contract (Art. 6(1)(b)).
  • Security, fraud prevention, cheat detection and protection against abuse — basis: legitimate interests (Art. 6(1)(f)) in keeping the game fair and the service stable.
  • Moderating content published in the community — basis: legitimate interests (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c)) under the Digital Services Act (EU) 2022/2065.
  • Error diagnosis, load measurement and technical improvement — basis: legitimate interests (Art. 6(1)(f)).
  • Sending the newsletter — basis: your consent (Art. 6(1)(a)), withdrawable at any time from the email itself.
  • Responding to requests from competent authorities — basis: legal obligation (Art. 6(1)(c)).

4. How long we keep your data

  • Account and character data: while the account is active. If you delete it, data is erased or anonymised within 30 days, unless we must keep it to meet a legal obligation or to defend a legal claim.
  • Inactive accounts: after 36 months without access we email you and, absent a reply, proceed to deletion.
  • Technical and security logs: 12 months maximum.
  • Community content: until you delete it or moderation removes it. Moderation records are kept for 12 months.
  • Sanction and ban records: up to 5 years, as a legitimate interest in preventing repeat offences.
  • Newsletter subscription: until you unsubscribe.

5. Who else accesses your data

We do not sell your personal data and we do not share it with third parties for advertising. To run the service we rely on providers acting as processors, under contracts compliant with Article 28 GDPR:

  • Cloudflare, Inc. — website hosting, content delivery network and attack protection.
  • Google Ireland Ltd. / Firebase — storage of community content and image analysis for moderation.
  • Game server and database provider, in data centres in the European Union and the United States.
  • Transactional email provider, for account verification and service notices.

Where a provider processes data outside the European Economic Area, the transfer relies on the Standard Contractual Clauses approved by the European Commission or on an adequacy decision, together with any applicable supplementary measures.

6. Your rights

The GDPR grants you the following rights, which you may exercise free of charge by writing to llboom@brainsoft.games from the address linked to your account:

  • Access: know what data of yours we process and obtain a copy.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data when it is no longer necessary.
  • Restriction: ask us to suspend processing while a dispute is resolved.
  • Portability: receive your data in a structured, commonly used format.
  • Objection: object to processing based on our legitimate interests.
  • Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.

If you believe we have not handled your request properly, you may lodge a complaint with the supervisory authority of your country of residence. In Spain this is the Agencia Española de Protección de Datos (aepd.es).

7. Automated decisions

Anti-cheat and moderation systems may automatically restrict an account or remove content when they detect a clear breach. Because those decisions can affect you, you have the right to request human intervention: write to llboom@brainsoft.games and we will review the case manually.

We do not carry out profiling for advertising purposes, nor do we take automated decisions with legal effects beyond the game service itself.

8. Minors

Ashram is not directed at children under 16. To create an account you must be at least 16, or the minimum age set by your country (which in some Member States is as low as 13), in which case the authorisation of a parent or guardian is required.

If we find that an account belongs to a child below that age without authorisation, we will suspend it and delete their data. If you are a parent or guardian and believe your child has created an account, write to llboom@brainsoft.games and we will act without delay.

9. Cookies and local storage

We use only strictly necessary cookies and local storage: keeping you signed in, remembering your chosen language and protecting forms against automated abuse. We do not use advertising or cross-site tracking cookies, so no prior consent is required under Article 5(3) of Directive 2002/58/EC.

10. Security

We encrypt traffic in transit, store passwords using one-way hash functions, restrict data access to strictly necessary personnel, and apply rate limits and verification at sensitive endpoints.

No system is infallible. Should a security breach occur that poses a high risk to your rights, we will inform you without undue delay and notify the supervisory authority within 72 hours, in accordance with Articles 33 and 34 GDPR.

11. Changes to this policy

We may update this policy to reflect changes in the service or in the law. We will always publish the date of the latest revision and, where the change is substantial, we will notify you on the site or by email before it takes effect.

Other documents