This Privacy Policy explains how Analyse Games handles personal data about the people who visit analyse.net, create an account, work in a team on Analyse Games, pay for a plan or contact us. It is written to meet Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.
Are you a player of a game that uses Analyse Games? The server, network or studio that runs the game decides what player data is collected and why. They are the controller and we process that data for them under our Data Processing Addendum. Please contact the game's operator first. If you can't reach them, write to us and we will pass your request on.
1. Who is responsible
The controller for the processing described here is:
Breukers Willem Albertus E.E., trading as VertCode Development (provider of Analyse Games) Valaoritou 1, 10671 Athens, Greece GEMI 186520701000 · VAT EL802973201 Email: [email protected]
We have not appointed a Data Protection Officer, because the GDPR does not require one for our activities. Questions about this policy or your data go to [email protected].
2. What we collect and where it comes from
| Category | What it includes | Where it comes from |
|---|---|---|
| Account details | Name, email address, profile picture, time zone, password (stored only as a salted Argon2 hash), email notification preferences, an optional separate address for notifications | You |
| Social sign-in | The account identifier, email address and name the provider shares with us when you sign in with Google, Discord or GitHub | The provider you choose |
| Security data | Active sessions with IP address, browser user agent and times; two-factor settings (authenticator secrets encrypted, recovery codes hashed); passkey public keys and names; sign-in attempt counters | Your device and your use of the Service |
| Team and organisation | Organisation, studio and game names; your role; invitations you send or receive, including the invitee's email address | You and your team members |
| Billing details | Company name, VAT number and whether it validated, billing email, billing address, plan, billing interval, subscription status, trial dates, invoices; a Stripe customer reference | You, Stripe, and the European Commission's VIES service for VAT numbers |
| Payment details | Card or other payment details | Entered directly with Stripe. We never receive full card numbers |
| Content you create | Dashboards, segments, campaigns, experiments, goals, alert rules, knowledge base pages, Ask Analyse questions and conversations | You and your team members |
| Connected apps | MCP tokens and approved AI apps: app name, which games and tools they can use, when they were last used. Integration settings for stores and Discord (secrets encrypted) | You |
| Usage records | Counts of Ask Analyse questions and MCP calls per period, needed to apply plan limits | Your use of the Service |
| Communications | Emails and messages you send us, and our replies | You |
| Technical logs | IP address, time, requested URL, response status and error details in server logs | Your device |
We don't use advertising trackers, and we don't buy personal data from anyone. See the Cookie Policy for the small number of cookies and browser storage entries we use.
Do you have to give us this data? Your name, email address and a password or social sign-in are needed to create an account. Billing details are needed to buy a paid plan and to issue invoices required by tax law. Everything else is optional.
3. Why we use it, and our legal bases
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and running your account, providing the Service, team access, alerts and digests you set up | Account, team, content, connected apps | Article 6(1)(b): performance of our contract with you. For team members invited by a customer: Article 6(1)(f), our and the customer's legitimate interest in giving their team access |
| Keeping accounts and the Service secure: sign-in, two-factor, session management, rate limiting, preventing abuse and fraud | Security data, technical logs | Article 6(1)(f): legitimate interest in protecting accounts and our systems. Also Article 32 GDPR |
| Billing, invoicing, VAT checks and collecting payments | Billing details, account details | Article 6(1)(b): contract. Article 6(1)(c): Greek tax and accounting obligations, including issuing invoices through myDATA |
| Applying plan limits and fair use | Usage records, peak players online per account | Article 6(1)(b): contract |
| Ask Analyse and knowledge base features, when you use them | Your questions, conversations, the data the assistant reads to answer | Article 6(1)(b): contract. See AI and Your Data |
| Answering your questions and support requests | Communications, account details | Article 6(1)(b) where it concerns your account, otherwise Article 6(1)(f): legitimate interest in answering you |
| Service emails: security alerts, billing notices, changes to our terms | Account details | Article 6(1)(b) and 6(1)(c) |
| Product news emails to customers | Email address, name | Article 6(1)(f) and Article 11(3) of Greek Law 3471/2006 for similar services you already use. You can turn these off in Account settings, Notifications, or with the link in every email |
| Handling legal claims, requests from authorities, and complaints about content | Any relevant data | Article 6(1)(c) and 6(1)(f): legal obligations, and our legitimate interest in establishing or defending legal claims |
Where we rely on legitimate interests, we have balanced them against your rights. You can ask us for details of that balancing and object at any time (see section 7).
We don't make decisions about you based solely on automated processing that produce legal or similarly significant effects.
4. Who we share it with
- Our subprocessors: hosting, storage, email, rate limiting and AI providers that process data for us under contract. They are listed, with what they do and where, on our Subprocessors page.
- Stripe: processes payments and subscriptions for us. For some purposes, such as fraud prevention and meeting its own financial regulations, Stripe acts as an independent controller under the Stripe Privacy Policy.
- Sign-in providers: if you choose to sign in with Google, Discord or GitHub, that provider knows you signed in to Analyse Games.
- Services you connect: when you connect a store (Tebex, PayNow), a Discord webhook or an AI app through MCP, we exchange data with it at your request.
- Your team: other members of your organisation can see your name, email address, role and activity in the organisation.
- Public authorities: the Greek tax authority (AADE) receives invoice data. We disclose data to courts, police or regulators only where the law requires it.
- Professional advisers: our accountant, lawyers and auditors, who are bound by confidentiality.
- A buyer of our business: if the business is sold or reorganised, under confidentiality and with notice to you.
We never sell personal data.
5. Transfers outside the EU
Our servers and databases are located in the European Union. Some subprocessors, such as Google, Stripe, Resend and Upstash, are companies based in the United States, or may access data from there. When personal data leaves the European Economic Area, we protect it with:
- the EU-US Data Privacy Framework, for US recipients certified under it (an adequacy decision of the European Commission of 10 July 2023, upheld by the EU General Court on 3 September 2025 in case T-553/23, and under appeal at the time of writing), and
- the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), with additional safeguards where needed, for other recipients or as a fallback.
The Subprocessors page shows which mechanism applies to each one. You can ask us for a copy of the relevant safeguards at [email protected].
6. How long we keep it
| Data | How long |
|---|---|
| Account details, team and content | While your account exists. When you delete your account, we delete these straight away from our live databases, and from backups within 90 days |
| Sessions | Until you sign out or the session expires (7 days), and removed from our database within 30 days after that |
| Two-factor challenge and trusted device tokens | 10 minutes and 30 days respectively |
| Ask Analyse conversations | While your account exists |
| Invitations and email confirmation links | Until used or expired |
| Invoices and billing records | As long as Greek tax and accounting law requires, five years from the end of the financial year they belong to under Greek accounting law (Law 4308/2014), and longer if a tax audit is pending. Stripe keeps its own copies of payment records under the Stripe Privacy Policy |
| Support emails | 24 months after the conversation ends |
| Server logs | 30 days |
| Data needed for a legal claim | Until the claim is resolved and limitation periods have passed |
Player data that your games send us is kept according to the Data Processing Addendum.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy (Article 15);
- correct inaccurate data (Article 16). Most details can be changed in Account settings;
- erase your data (Article 17). You can delete your account yourself in Account settings;
- restrict how we use your data (Article 18);
- data portability: receive data you gave us in a machine-readable format or have it sent to another provider (Article 20);
- object to processing based on legitimate interests, including profiling, and at any time to direct marketing (Article 21);
- withdraw consent at any time, where we rely on consent, without affecting processing before you withdrew it.
To use these rights, write to [email protected] from the email address on your account, or tell us how we can verify it's you. We reply within one month. For complex requests we may extend that by two more months, and we will tell you why. It's free, unless a request is clearly unfounded or excessive.
8. Complaints
If you think we have handled your data unlawfully, please tell us first so we can put it right. You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live, work or where the issue happened. In Greece that is:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) Kifisias Avenue 1-3, 11523 Athens, Greece Phone: +30 210 6475600 · Email: [email protected] Website: www.dpa.gr
9. Children
Analyse Games is a tool for people who run games, and accounts are for people aged 18 or over, or with a parent's or guardian's consent. We don't knowingly collect personal data from children through our website or dashboard. If you believe a child has created an account, contact us and we will delete it.
10. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords and tokens, encryption of secrets at rest, two-factor authentication and strict access control. More detail is on our Security page. If a personal data breach is likely to result in a high risk to you, we will tell you without undue delay.
11. Changes to this policy
We update this policy when our processing changes. The date at the top shows when it last changed. If a change is significant, we tell account holders by email before it takes effect.