Privacy Policy
Contract: 90
Last updated: July 12, 2026
1. General information
This Privacy Policy sets out how personal data of users of the contract90.com website, operated under the Contract: 90 brand, is processed.
The data controller is:
Mbsoft
NIP (Polish tax ID): PL8652586384
Contact for data protection matters:
help@contract90.com
2. Data Protection Officer
The controller has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR.
3. Scope of data processed
The controller processes only ordinary personal data (it does not process special categories of data under Article 9 GDPR, such as health, racial or ethnic origin, or religious belief).
Data processed includes:
-
Waitlist sign-up form:
- email address,
- the language version of the site the form was submitted from, so we can send you updates in the right language.
Providing this data is voluntary but necessary to join the waitlist.
Without it, we can’t send you updates on the game’s progress or contract launches.Submissions from the form are stored in the controller’s own CMS (Payload CMS), maintained directly by the controller - the data is not passed to any external CMS provider.
-
Technical data:
- the user’s IP address,
- date and time of the request,
- the URL requested,
- the HTTP response code (e.g. 200, 404),
- browser information (user agent),
- the referring page address (referer),
- the country the request originated from (based on IP geolocation),
- data saved in the browser’s localStorage (only light/dark theme and language preferences - stored locally on the user’s device and never sent to our servers).
Processing: automatic while using the site. Users can block localStorage via browser settings, though this may limit functionality (preferences won’t be remembered).
The above technical data is processed automatically by Cloudflare’s infrastructure to keep the site running, protect against DDoS attacks, and optimize performance. The IP address is also used briefly (a few minutes at most, in server memory) to rate-limit sign-up submissions from a single IP address - it is not stored alongside the waitlist submission itself.
-
Analytics data:
- the URL and title of the page visited, and the referring page address,
- browser type, operating system, device type, screen resolution, browser language,
- country, region, and city of origin (derived from IP address; the IP address itself is not stored),
- an anonymous session identifier (a pseudonymized hash generated from technical data, rotated monthly),
- interaction events: submitting or failing to submit the waitlist sign-up form.
Analytics data is collected using a tool maintained directly by the controller (no external analytics provider is involved), without the use of cookies. Analytics data does not allow direct identification of a user. IP addresses are not stored.
4. Source of personal data
Personal data is collected directly from the individuals it concerns, through:
- the waitlist sign-up form on contract90.com,
- email correspondence sent to: help@contract90.com
The controller does not obtain data from any other sources.
5. Purposes of processing
Personal data is processed for the following purposes:
- joining the waitlist and sending emails about the game’s development progress, contract launches, access opening, and - after launch - new content and features for Contract: 90,
- handling correspondence related to inquiries sent to our contact address,
- remembering user preferences (language, light/dark theme),
- keeping the website secure and functioning correctly,
- analyzing site traffic and usage patterns to improve and optimize the service.
6. Legal basis for processing
Personal data is processed on the basis of:
-
Article 6(1)(a) GDPR - the consent of the data subject, given when joining the waitlist (which also covers receiving emails about development progress and new game content) and for data saved in localStorage,
-
Article 6(1)(f) GDPR - the controller’s legitimate interest, namely:
-
Site security:
Interest: Protection against cyberattacks (DDoS, intrusion attempts, form abuse), ensuring the site is available and stable for all users.
Balancing test: Processing minimal technical data (IP, connection logs) is proportionate to this purpose and does not unreasonably infringe on users’ rights. -
Handling correspondence:
Interest: Being able to respond to messages sent directly to our contact address.
Balancing test: People who write to our contact address can reasonably expect their data to be used to provide a response. -
Site traffic analysis:
Interest: Understanding how the site is used, identifying functional issues, and improving service quality.
Balancing test: Processing is limited to anonymized technical data, with no way to identify a user. IP addresses are not stored. The session identifier is pseudonymized and reset monthly.
-
Anyone on the waitlist can withdraw at any time and stop receiving further messages by withdrawing consent as described in section 10.
7. Recipients of data
Personal data may be shared with the following processors:
-
Cloudflare Inc. (101 Townsend St, San Francisco, CA 94107, USA) - a processor acting under a data processing agreement. Cloudflare provides:
- site hosting,
- DNS proxying,
- DDoS protection,
- performance optimization.
Cloudflare may process data outside the European Economic Area.
Legal safeguards: standard contractual clauses approved by the European Commission, and participation in the EU-US Data Privacy Framework. -
Purelymail - a processor handling our email hosting, acting under a data processing agreement.
-
Parties authorized under applicable law (e.g. law enforcement, upon a valid request).
The CMS and analytics tooling are maintained directly by the controller and are not separate recipients of data.
Data is not sold or shared with other parties for marketing purposes.
8. Data transfers outside the EU/EEA
Because we use Cloudflare, technical data may be processed outside the European Economic Area. Cloudflare applies appropriate legal safeguards, including standard contractual clauses, and participates in the EU-US Data Privacy Framework, ensuring processing complies with the GDPR.
9. Data retention periods
Personal data is retained for the following periods:
- waitlist email address - until consent is withdrawn or the user opts out of further messages,
- email correspondence - for the duration of the correspondence and up to 12 months afterward, to allow us to respond to any follow-up questions and to protect against potential claims,
- technical data:
- localStorage - until manually cleared by the user or the browser’s site data is cleared,
- server logs (Cloudflare) - up to 30 days, per Cloudflare’s policy (https://www.cloudflare.com/privacypolicy/),
- the IP address used for rate-limiting - held temporarily in server memory, for a few minutes at most,
- analytics data - up to 12 months from collection, then automatically deleted.
Once the relevant period has passed, data is permanently deleted, unless the law requires it to be kept longer.
10. Your rights
Data subjects have the right to:
- access their personal data,
- have it corrected,
- have it deleted,
- restrict its processing,
- data portability,
- object to processing,
- withdraw consent at any time, including opting out of further emails about Contract: 90.
To exercise these rights, contact the controller.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) or your local data protection authority.
11. Profiling and automated decision-making
Personal data is not used for profiling or automated decision-making within the meaning of Article 22 GDPR. Analytics data is grouped into anonymous sessions solely for statistical purposes, with no effect on any individual’s legal or factual situation.
12. Cookies and localStorage
This site does not use cookies.
We use only the browser’s localStorage to remember your language and display mode (light/dark) preferences. This data:
- is stored only locally on your device,
- is never sent to our servers,
- stays in your browser until you manually remove it.
You can remove data stored in localStorage at any time via:
- your browser settings (clearing site data),
- your browser’s developer tools (F12 → Application/Storage → Local Storage).
The data saved in localStorage is listed in section 3.
13. Data security
The controller applies appropriate technical and organizational measures to protect personal data against loss, unauthorized access, alteration, or disclosure. This includes:
- Encrypted connections: All data transmitted between the user and our server is protected via SSL/TLS (HTTPS).
- Validation and rate-limiting: The waitlist sign-up form validates submitted data server-side and limits the number of submissions from a single IP address to prevent abuse.
- Access restrictions: Only authorized individuals have access to collected data, and systems are protected with passwords and authentication mechanisms.
- Software updates: Systems and applications are regularly updated to address known security vulnerabilities.
14. Changes to this policy
The controller reserves the right to update this Privacy Policy. The current version is always available on this website.