Privacy Policy

Last updated: April 2026

Translation Disclaimer: This document is a translation of the original Portuguese version. In the event of any discrepancies or inconsistencies between this translation and the original Portuguese version, the Portuguese version shall prevail and govern the interpretation of these terms.

🔒 Global Privacy Policy (Master)

Ation Studios | Version 2026.01.16

🌟 Hello! Welcome to our Privacy Policy. Here at Ation Studios, we take your privacy seriously and want you to feel safe. We clearly explain how we collect, use, and protect your data, following the best international practices (LGPD, GDPR, and US privacy legislation, including CCPA/CPRA and other applicable state laws).

Friendly Summary:

  • Your Data: Used only to improve your experience.
  • Control: You have control and can delete your account at any time.
  • Security: We never sell your personal data.
  • Children: We adopt an active posture in protecting minors. Minors' data requires parental verification, and marketing emails are deactivated for sessions of individuals under 18.

1. Overview and Objective

This Global Privacy Policy ("Master Policy") establishes the guidelines for transparency and security regarding how Ation Studios ("We", "Controller") collects, processes, stores, and protects personal data across its ecosystem.

This document applies to:

  1. Digital Games (PC, Consoles, Mobile)
  2. SaaS Platforms (Software as a Service)
  3. B2B Solutions (Business to Business)
  4. Websites, Stores, and Corporate Portals

⚠️ Structure Note: This policy defines the global principles. Specific operational details (what is collected in each product) are found in the Specific Addendums listed at the end.


2. Concepts and Definitions (LGPD/GDPR)

For absolute clarity, we adopt the following legal definitions:

  • Personal Data: Any information relating to an identified or identifiable natural person (e.g., Name, E-mail, IP).
  • Data Subject: You, the natural person to whom the data refers (Gamer or Professional User).
  • Continuity: In case of service discontinuation, Ation will employ reasonable efforts to provide data export tools with at least a 90-day prior notice, upon request, in a reasonably usable format (like CSV or JSON), when technically feasible for the product in question.
  • Controller: Ation Studios, responsible for decisions regarding data processing.
  • Processing: Any operation performed on data (collection, storage, use, sharing, deletion).
  • Anonymization: A process that removes the possibility of linking the data back to its subject (Statistical Data).

We only process your data if there is a legal justification (Legal Basis):

  1. Contract Performance: To deliver the game or service you purchased/subscribed to.
  2. Legitimate Interest: For protection against fraud, security analysis, and product improvement (e.g., aggregated and anonymous Analytics), always respecting your rights and expectations.
    • Enterprise Customers: May request an opt-out of this aggregated analysis via a specific contractual clause.
    • Games and Apps: Whenever technically feasible (e.g., Single-player games), we offer the option to disable sending Analytics in the settings. In services where telemetry is critical for operations (e.g., Multiplayer, Anti-cheat), collection is irrevocable and an inseparable part of providing the service.
  3. Legal Obligation Compliance: To comply with tax laws (invoices) or judicial ones (Brazilian Civil Rights Framework for the Internet).
  4. Consent: When we request your explicit authorization (e.g., Marketing Newsletter).

4. Your Fundamental Rights

Regardless of where you are located, we guarantee the rights provided by the LGPD (Brazil) and the GDPR (Europe):

  1. Confirmation and Access: To know if we process your data and request a simple or complete copy.
  2. Correction: To request the adjustment of incomplete, inaccurate, or outdated data.
  3. Anonymization/Blocking: To request the suspension of the use of unnecessary or excessive data.
  4. Portability: To request the transfer of your data to another supplier (when technically possible).
  5. Deletion: To request the erasure of data processed based on consent (except for retention obligations).
  6. Consent Revocation: To withdraw your permission for marketing communications at any time.
  7. Review of Automated Decisions: To request human review of decisions made solely based on automated processing.

United States Residents (State Privacy Laws): Although our main focus is LGPD/GDPR, we respect the privacy rights of residents of US states with their own legislation, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Texas (TDPSA), and other states with active regulations. This includes the right to opt-out of data sharing for behavioral advertising and non-discrimination in access to services (though we do not sell data for money).

👉 How to Exercise: Requests must be submitted via our Support Portal. Response Time: We answer confirmation and access requests within 15 days. Complex deletion or portability requests will be analyzed and answered within the same timeframe or with a reasonable justification for additional time.


5. Security, Retention, and Mitigated Liability

5.1 Commitment to Security and Diligence

Ation Studios adopts robust technical, organizational, and administrative measures compatible with market standards and the state of the art to protect personal data against unauthorized access, destruction, loss, alteration, or communication. Our defenses include:

  • Encryption: The use of SSL/TLS protocols for data in transit and secure storage.
  • Access Control: The implementation of RBAC (Role-Based Access Control) to ensure only authorized personnel access sensitive data.
  • Monitoring: Active firewalls and periodic audits to identify and correct vulnerabilities.

5.2 Limitation of Liability and External Force Majeure

The Data Subject acknowledges that, despite the employment of cutting-edge tech and rigorous processes, no security system is absolutely invulnerable. Therefore, Ation Studios will not be held liable for damages resulting from security incidents when it demonstrates that:

  1. Proven Diligence: It implemented and maintained all reasonable and expected security measures for its sector, acting without negligence, ineptitude, or recklessness.
  2. Act of Third Party or Force Majeure: The incident resulted from cyberattacks of unpredictable sophistication (that supersede current market defense standards), natural disasters, or massive failures in global third-party infrastructures (e.g., falls in internet backbones or cloud providers).
  3. Exclusive Fault: The damage resulted from the exclusive action or omission of the Data Subject themselves or third parties outside Ation Studios' control.

5.3 Procedure and Notification of Incidents

In compliance with the LGPD and the GDPR, in the event of a security incident:

  1. Detection and Containment: We immediately activate measures to contain the incident and limit impacts.
  2. Analysis: We investigate the origin and scope of the compromise.
  3. Notification: If it poses a relevant risk, and after reasonable confirmation of the incident's nature and scope, we will notify the ANPD (in Brazil) and the affected data subjects within a reasonable timeframe, whenever legally applicable (aiming to observe the 72-hour limit when technically possible after confirmation).
  4. Correction: We fix the vulnerability to prevent future occurrences.

5.4 Retention (Storage Periods)

We keep your data only for the time necessary to fulfill the purposes described or legal obligations:

  • Account Data: For as long as the account remains active.
  • Access Logs: Minimum 6 months, according to Art. 15 of the Brazilian Civil Rights Framework for the Internet.
  • Tax Data: 5 years, to comply with the National Tax Code.
  • Analytics: Up to 2 years, kept pseudonymized for statistical purposes.

6. International Transfer

To guarantee high availability and global performance, our servers operate in the cloud, and may be located in the USA, Europe, or Brazil. We guarantee that these transfers occur to countries with an adequate level of protection or through Standard Contractual Clauses (SCCs) that guarantee compliance with the LGPD and GDPR.

  • Opt-out: Users who, for legal reasons, do not wish their data to be processed outside of Brazil must contact the DPO to verify technical feasibility or request account closure.

Global Availability and Role as Service Provider: Ation Studios' products and services are globally available. When we act as a Processor of data (e.g., SaaS infrastructure for B2B clients), the data inserted by the client into our platform is the client's responsibility (Controller). Ation normally does not access such data for operational and commercial purposes. Internal accesses may occur when strictly necessary for: client-requested technical support; security incident investigation; environment maintenance or recovery; legal obligation compliance; or express request — always recorded internally and limited to the absolute necessary minimum.

Principle of Necessity and Legal Restrictions: Ation Studios does not retain data longer than strictly necessary for the purpose that motivated the collection, or beyond the period required by legal obligation (e.g., access logs for up to 6 months according to Art. 15 of the Internet Civil Framework; tax data for up to 5 years according to tax legislation). After the legal retention periods, the data is permanently deleted.

Jurisdictions with Incompatible Requirements: In jurisdictions requiring compulsory local storage of data incompatibly with our global infrastructure (e.g., China – Data Security Law DSL) or that are under an international embargo, Ation Studios may, at its discretion, restrict or adjust access to its services in those regions, always prioritizing legal compliance and the protection of the data of all subjects.


7. Cookies and Tracking Technologies

On our sites and dashboards, we use cookies to:

  • Essentials: Login, anti-bot security, and load balancing.

  • Performance: Google Analytics or similar (always with an anonymized IP) to understand traffic. Third-party tools may collect data under their own policies.

  • Marketing: Conversion pixels (only with explicit acceptance in the cookies banner). You may revoke this consent at any time via the cookie preferences panel on the site.

    ⚠️ Restriction for Minors: Conversion pixels and third-party marketing cookies are automatically disabled for sessions identified as belonging to users under 18, in compliance with Law 15.211/2025 (ECA Digital) and GDPR principles.

In all these cases you have the option to revoke consent at any time. However, be aware that doing so may partially or completely affect the operation of the offered service.

Third-Party Tools

We use trusted partners to operate our services. Examples include:

  • Analytics: Unity Analytics, Game Analytics, Firebase.
  • Infrastructure: Google Cloud, AWS.
  • Multiplayer: Photon Engine (Exit Games).
  • Marketing: Google Ads (only with consent). In case of doubt, consult their own policies.

🤖 8. Use of Artificial Intelligence

Ation Studios may employ Artificial Intelligence systems to improve your experience and ensure platform security. In compliance with the EU AI Act (fully in force in 2026) and Art. 20 of the LGPD, we assure:

  • Service Optimization: Load balancing, anomaly detection, and continuous improvement of user experience.
  • Security and Moderation: Anti-cheat systems and abusive behavior detection.
  • Support: Automated ticket triage and FAQs.

Guarantees:

  • Preferential Internal Processing: Our AI systems preferentially process data internally. When necessary for support, moderation, fraud detection, or service operation, Ation may utilize third-party AI or automation providers subject to confidentiality and data protection agreements equivalent to this Policy. Identifiable personal data is not sent to external AI models without an adequate legal basis.
  • Human Supervision: No sensitive automated decision that affects civil rights (e.g., permanent ban, account suspension) is applied without the possibility of human supervision and review, guaranteeing your right under Art. 20 of the LGPD.
  • Transparency: When you interact directly with an AI system (e.g., support chatbot), this will be clearly indicated.

📂 9. Specific Product Addendums

For details on liability limitation, consult the Master Terms of Use or access our support portal. For granular details on data collection in your specific use context, consult the mandatory complementary document:


9. Changes to this Policy

We may update this Policy periodically to reflect service improvements, new features, or legal adaptations.

9.1 What Are Relevant Changes?

We consider relevant changes those which:

  • Significantly expand the categories of data collected or processing purposes.
  • Reduce rights or protections previously guaranteed to data subjects.
  • Alter existing legal bases for data processing.
  • Introduce new data sharing with third parties.

Non-relevant changes include: wording corrections, clarifications, reorganization of sections, or link updates.

9.2 How Will You Be Notified?

Relevant changes will be communicated via:

  • Games: In-game notification upon the next game launch.
  • Services: E-mail to the registered account administrator.

9.3 Effective Date of Changes

  • General Rule: New versions of this Policy come into effect 10 calendar days after the publication date, allowing reasonable time for review.
  • Exception - Legal Adaptations: Changes mandated by new laws, regulations, or judicial decisions become effective immediately or according to the required legal deadline, without observing the 10-day period.

The continued use of the services after the new version comes into effect constitutes tacit acceptance of the changes. If you do not agree, you must discontinue use and request the deletion of your data.


10. Governing Law and Jurisdiction

This Policy is governed by the laws of the Federative Republic of Brazil. The courts of the Ation Studios' headquarters district are elected to resolve any doubts arising from this document, with express waiver of any other jurisdiction, however privileged it may be, except for imperative local legislation to the contrary (e.g., GDPR for European residents).


Contact the Data Protection Officer (DPO): Support Portal — Privacy & DPO The official channel for exercising rights, privacy requests, and legal questions.

Addendum

🎮 Addendum A: Privacy in Digital Games

Valid for: Games published on Steam, Epic Games, Consoles, Mobile, and Web.

This document is an integral part of Ation Studios' Global Privacy Policy.


1. What We Collect (Data Minimization)

Unlike many studios, Ation's philosophy is "Privacy by Design". We only collect the data categories necessary for the game's operation, detailed below, and define retention periods for each category.

1.1 Technical Data and Telemetry (Legitimate Interest)

To fix bugs and balance the game, we automatically receive:

  • Hardware: GPU model, CPU, RAM, OS Version, and Resolution.
  • Gameplay and Diagnostics: Error reports (Crash Dumps), session time, level progression, and unlocks. Crash dumps may automatically include technical information of the execution environment, file paths, device identifiers, or limited portions of process memory necessary for diagnostics; this data is used exclusively for debugging and security, with restricted access and limited retention.
  • Platform Identifiers: Your "Steam ID", "Epic ID", or "PSN ID" (a public numerical string) to link your Cloud Saves and Achievements.

1.2 Integrity and Security (Anti-Cheat Mechanisms)

To ensure a fair environment and protect match integrity (especially in competitive modes), the game uses security mechanisms that operate under the logic of self-protection:

  • Process Memory Analysis: The system exclusively monitors the memory space allocated for the game's own process, seeking to identify attempts of code injection or unauthorized modifications to its internal files.
  • Validation of Alterations: Case inappropriate interference in the game's memory is detected, the software may interrupt its execution immediately (preventive crash) or flag the account for validation of fraudulent conduct.
  • Limits of Action (Privacy by Design): Unlike intrusive third-party systems, our technology does not perform scans on external processes, personal files, documents, or operating system folders of the user. The analysis is strictly technical and limited to the execution scope of the Ation Studios' software.
  • False Positives and Contestation: Anti-cheat detection is based on technical heuristics and may, in exceptional cases, generate incorrect flags. Legitimate accessibility tools, overlays, certified drivers, streaming software, antivirus, authorized mods, and compatibility layers (like Proton/Wine) may occasionally be flagged without it automatically implying fraud. No permanent penalty will be applied without the possibility of technical review or contestation by the user via our support channel. Ation reserves the right to group, automate responses, or disregard contestations proven to be abusive, repetitive, or generated in bad faith.
  • Security and Retention: Any logs generated by security incidents are stored in encrypted form and kept for up to 6 months for auditing and ban contestation analysis purposes, being permanently deleted after this period.

2. What We Normally DO NOT Collect

  • Civil Data: Except when strictly required by law, parental verification, technical support, fraud prevention, or regulatory obligation, we normally do not collect your Full Name, CPF/SSN, or Address in our games. Data collected continuously in the Parental Portal (Section 5.2) are used exclusively for guardian identity verification and are not used for commercial purposes.
  • Financial Data: We normally do not have access to your Credit Card. Payment processing occurs directly through the Digital Store (Steam/Sony/Microsoft/Nintendo/Epic Games/etc.). Data processing carried out by distribution, login, cloud, console, or digital store platforms remains subject to the policies and terms of those third parties.

3. Accounts and Login

Most of our titles operate on a "No Prior Registration" model.

  • We use the federated login of the platform you already use (e.g., "Log in with Steam").
  • We do not maintain a database of end-user passwords for games.

4. Purchases and Refunds

The entire purchase relationship is between You and the Digital Store.

  • Ation Studios acts as the developer. We are not the "Merchant of Record".
  • Your refund rights follow the Terms of Service of the Store where the purchase was made.

5. Minors and Child Protection

Ation Studios adopts an active posture to protect children and adolescents, in compliance with the legislation of each region. Below are the rules applied by jurisdiction:

5.1 Passive Access (Institutional Site / Showcase)

Users who only browse the site, watch trailers, or read public content are not subject to age verification. No identified data is collected in this layer.

5.2 Accounts, Interactions, and Products (Linked Access Layer)

When there is account creation, login, interactive features, or any form of identified personal data processing:

  • Brazil (ECA Digital - Law 15.211/2025 / LGPD):

    • Users aged 16 or older: Validation via e-mail or SMS.
    • Users under 16: Registration flow is blocked and redirected to the Parental Authorization Portal. The legal guardian must authorize, link, and configure access limits. Accounts without validation within 30 days will be preventively suspended.
    • Data of minors is limited to the technical minimum (store platform identifier). No data from a minor is used for commercial profiling, targeted advertising, or shared with third parties for marketing purposes.
    • Infallibility Exemption: Ation employs reasonable measures for age verification and parental authorization, without guaranteeing that such mechanisms are infallible or capable of preventing every attempt at fraud, ideological falsehood, or incorrect date of birth provided by the user themselves.
    • Responsibility of the Legal Guardian: The legal guardian who authorizes the account declares possessing legal authority to do so and will be responsible for the information provided and for the activities, access configurations, and any purchases made by the minor under their responsibility.
  • European Union (GDPR - Art. 8):

    • The processing of data of minors under 16 years old (or the minimum age established by the Member State, at least 13 years old) depends on verifiable consent from the legal guardian.
    • Ation Studios applies the most restrictive rule compatible with the user's country within the EU.
  • United States (COPPA - 15 U.S.C. §§ 6501-6506):

    • For users under 13, Ation Studios requires Verifiable Parental Consent (VPC) before any collection of identified personal data.
  • Other Regions:

    • We apply the most restrictive policy compatible with the identifiable local legislation. In the absence of identification, Brazilian requirements are adopted as the standard.

5.3 Marketing Pixels and Minors

Conversion pixels and third-party marketing cookies are automatically disabled for sessions identified as belonging to users under 18, in compliance with Law 15.211/2025 and GDPR principles.

5.4 Unintentional Collection

If Ation Studios becomes aware that it has collected data from a minor without the required parental authorization, this data will be immediately deleted from our servers.

  • For details regarding limitation of liability, consult the Master Terms of Use.
Addendum

💼 Addendum B: SaaS and B2B Privacy

Valid for: Ation Cloud, Dashboards, APIs, and Corporate Contracts.

This document is an integral part of Ation Studios' Global Privacy Policy.


1. Data Collected as CONTROLLER

In these services, Ation Studios acts as the Controller of the data necessary to manage the commercial relationship with your company.

1.1 Registration and Billing (Legal Obligation/Contract)

We collect:

  • Company Data: Corporate Name, CNPJ/VAT ID, Address, and Bank Details.
    • Note: Credit card/bank details are stored in a tokenized manner by the payment gateway (Stripe), with Ation having no access to the full number.
  • Legal Representative/Admin: Full name, corporate e-mail, phone, and job title.
  • Purpose: Issuance of Invoices, license management, and support communication.

1.2 Audit and Security Logs (Legal Obligation)

We automatically record for platform security:

  • Source IP, User-Agent, Timestamp, and Action performed.
  • Retention: 6 months, in accordance with Art. 15 of the Brazilian Civil Rights Framework for the Internet.
  • Offensive Security: We perform periodic vulnerability tests (Pen-tests) to ensure platform integrity.

2. Data Processed as PROCESSOR

When your company uses our tools to manage the data of your own customers (e.g., a user panel for your game), Ation Studios acts as a Processor.

2.1 Shared Responsibility

  • Your Company (Controller): Is responsible for obtaining the consent or legal basis to collect the data of its end users. The Customer declares that it will provide only lawful instructions to Ation Studios. If Ation identifies an instruction as potentially illegal, incompatible with the LGPD/GDPR, or technically unsafe, it may refuse it, suspend it, or request further formalization, without this constituting a breach of contract.
  • Ation Studios (Processor): Is responsible for ensuring the security of the infrastructure where this data is hosted and following the Customer's lawful instructions. Ation may access Customer data when strictly necessary for: requested technical support; incident investigation; environment recovery; fraud prevention; or compliance with a legal obligation — always in a recorded manner and limited to the necessary minimum.

2.2 Sub-processors

To provide the service, we use world-class third-party infrastructure (Sub-processors). We guarantee that all operate under Standard Contractual Clauses (SCCs) or adequacy mechanisms for international transfers. Examples of currently used sub-processors include: AWS and/or Hetzner and/or Google Cloud (infrastructure), Stripe (payments), Cloudflare (security/CDN), and monitoring, analytics, and communication tools. The list may be periodically updated provided that an equivalent level of protection and confidentiality is maintained. For customers subject to the GDPR (Art. 28, item 2) or equivalent legislation requiring prior notification, Ation will notify about the inclusion or replacement of sub-processors with a 30-day notice, guaranteeing the Customer the right to submit a substantiated written objection within this period. In the absence of a timely objection, the alteration will be considered accepted. If the Customer submits a substantiated objection and Ation Studios cannot accommodate it technically or commercially, either party may terminate the contract without incurring penalties, upon a 30-day prior notice, proceeding with data export.

2.3 Data Processing Agreement (DPA)

For Enterprise customers or those processing sensitive data from third parties, we provide a formal Data Processing Addendum (DPA), incorporating EU Standard Clauses when applicable, upon request.

2.4 ECA Digital Compliance by the Controller

When the customer uses Ation Studios' services to serve end users (B2C), the Controller's responsibility clause provided in the Terms of Use Addendum B (Section 5 — ECA Digital Compliance) applies. The customer assumes full responsibility for the age verification of its end users; Ation Studios is exempt as the infrastructure Processor.


3. Business Retention and Deletion

  • Active Account: Data entered into the platform remains available as long as the contract is in effect.
  • Customer's Responsibility for Export: It is the customer's exclusive responsibility to export all of their data before the cancellation is effective, using the export tools available on the platform during the active contract period.
  • Post-Cancellation Retention: After cancellation, data may remain locked for the shortest reasonably necessary period for backup, auditing, operational recovery, legal defense, or legal compliance, observing a maximum limit of 6 months, unless otherwise required by law. In this state, data becomes inaccessible for commercial or operational use and is permanently deleted at the end of the period. Ation Studios has no contractual obligation to provide extraction tools or technical support for exporting data from already canceled accounts; any such requests may be subject to a technical feasibility assessment and the application of operational fees.
  • Early Deletion: Upon express request from the Customer and provided that no legal obligation for retention exists, Ation may preemptively delete data permanently before the operational retention period ends.
  • Incidents due to Customer's Responsibility: Ation shall not be held liable for security incidents, leaks, or unauthorized access resulting from compromised credentials, misconfigurations, third-party integrations, the Customer's failure to apply access controls, or misuse by their end users.
  • Data Subject Requests: Data subject requests related to information controlled by the Customer must primarily be answered by the Customer themselves. Ation will provide reasonable cooperation when technically necessary.

4. Secondary Use (Aggregated Analytics)

We may use anonymized and aggregated metadata (e.g., "total API requests per hour") for system health monitoring and market intelligence. Ation will employ reasonable measures to prevent the identification of customers, users, confidential data, or trade secrets in aggregated and anonymized reports.

  • Enterprise Customers may request an opt-out of this aggregated analysis via a specific contractual clause.