Privacy policy
What is collected, why, for how long, and what you can require us to do about it. Written to be read rather than skipped.
Draft — must be checked by a lawyer before launch. One point in particular needs professional confirmation: on what basis personal data may be transferred to Ukraine, which does not hold an EU adequacy decision. It is marked in the text.
1. Who is responsible
The controller of your personal data is:
Фізична особа-підприємець Лореш Ольга Юріївна (individual entrepreneur Olha Yuriivna Loresh), проспект Лесі Українки, 71, кв. 41, м. Кременчук, Полтавська обл., 39600, Ukraine. Registration № 2 585 000 0000 028268 of 20 April 2018. Telephone +380 98 282 60 66. Email: olga@loreshgames.com.
The same person is also registered as a sole trader (Gewerbe) in Germany, and that is the business that sells to customers in the European Union. Because there is an establishment inside the Union, no separate EU representative under Article 27 GDPR is appointed: that article applies to controllers who have no establishment in the Union at all. Details of both registrations are in the imprint.
2. What we collect, and why
When you send an enquiry
The form asks for your name, email address, country or city, the subject of your enquiry and your message. We use them for one purpose: to answer you and, if it goes further, to agree the terms of a purchase.
- One extra line: if you reached the page through a tagged link — one that
carries
utm_parameters, as links we publish on social networks do — the enquiry also tells us which link it was, so we know which posts are worth making. If there are no tags, it says which site sent you, when the browser reveals that. Nothing is stored on your device and nothing is remembered between pages: the label is read from the address of the page you are on and travels only with the message you chose to send. - Legal basis: your consent, which you give by ticking the box on the form (Article 6(1)(a) GDPR), and — once we are discussing an actual order — the steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
- How it travels: the form posts to a small script on our own web server, which emails the enquiry to Olga's mailbox. There is no third-party form service in between. A copy is also written to a log file on the server so that nothing is lost if the mail fails.
- Retention: enquiries that do not lead to a purchase are deleted within 24 months, and the server log copy is cleared on the same schedule. Where a purchase follows, the correspondence is kept for as long as tax and accounting law requires.
- Consequence of not providing it: we cannot reply. Nothing else depends on it.
When you buy a set
To fulfil an order we process your name, delivery address, contact details, the language your set is printed in, and payment reference data.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR) and compliance with legal obligations such as tax record-keeping (Article 6(1)(c) GDPR).
- Retention: for the statutory retention period applicable to commercial and tax records.
When you simply visit the site
The hosting provider records the usual server log data — IP address, date and time, the page requested, the referring page, browser and operating system — for the security and technical operation of the site.
- Legal basis: our legitimate interest in operating the site securely (Article 6(1)(f) GDPR).
- Retention: web server logs are written to our own disk space at the hosting provider and rotate automatically, so older entries are overwritten in the ordinary course — in practice within about a month. No fixed period is set by the hosting contract, and the provider's documentation does not state one either. The provider keeps its own backups for 7 days. At Cloudflare, which sits in front of the site, connection data is kept for short periods that depend on the type of record — of the order of 72 hours for firewall records and up to 30 days for traffic statistics. Beyond that we keep nothing from the logs, except that visits are counted in our own analytics if you agreed to it, and those records are deleted after 18 months (see section 3).
3. Cookies and measurement
This site sets one cookie of its own: it records whether you accepted or declined optional measurement, so you are not asked again on every page. It contains no identifier and expires after six months. It is strictly necessary in the sense of the ePrivacy rules and cannot be switched off.
No analytics or advertising cookies are set unless you accept them in the banner. If you decline, nothing is loaded and no measurement takes place. You can change your mind at any time by clearing the site's cookies in your browser, which brings the banner back.
If you do accept, the site loads Matomo, an analytics tool we run on our own
server at olgaloresh.com. It is not Google Analytics and no measurement data goes
to an advertising company. Matomo here is configured to set no cookies at all,
so accepting buys us a count of visits rather than a way to follow you: it records the page
you opened, the page that sent you, your approximate location, and your browser and device
type. Your IP address is shortened before it is stored — the last part is replaced with zeroes,
so it no longer identifies your connection. The individual records are deleted automatically
after 18 months; what remains after that is anonymous totals, such as how many people opened a
page in a given month, which cannot be traced back to a visit.
4. Who else sees your data
Your data is not sold, rented or passed to anyone for their own purposes. It is handled by:
- hostpro.ua, the hosting provider that runs this website and stores its files and server logs on servers in Ukraine. [Its public contract offers no data processing terms in the GDPR sense: it does not mention the Regulation, does not distinguish controller from processor, sets no retention period and does not state where the servers are. Clause 7.1 goes further and reserves the provider a right to process personal data at any time without separate consent and to publish it in open sources — most likely aimed at the account holder's own details rather than site visitors', but it needs reading. A lawyer should assess whether this is workable as a processor arrangement, and whether separate terms can be obtained. This ties into the transfer question marked in section 5.]
- Cloudflare, which sits in front of the site to serve it quickly and filter malicious traffic, and therefore processes connection data. Records are kept only briefly — see the retention note in section 2. [Cloudflare publishes standard data processing terms that apply to all plans, including the free one, as part of its subscription agreement. Confirm the current version and reference it here.]
- Google, because enquiries are read in a Gmail account. There is also a mailbox on the loreshgames.com domain, but it forwards to the same Gmail account, so either way your message ends up on Google's servers, which are partly outside the EU, and Google's own terms apply to it. The form deliberately delivers straight to Gmail rather than through the domain mailbox: forwarding adds a hop that breaks sender authentication, and enquiries were being filed as spam.
- The postal or courier service that carries your parcel, which needs your name and delivery address to deliver it.
Production and dispatch are handled by the seller's own German business, so your order details are not passed to any printing or fulfilment company along the way.
The two typefaces on this site are served from our own server, not from Google Fonts. No font request leaves for a third party, and no IP address reaches Google when a page loads.
5. Transfers outside the EU
The controller is established in Ukraine, which the European Commission has not recognised as offering an adequate level of data protection. When you write to us, your message is read and answered from Ukraine.
[This transfer needs a stated legal basis: either appropriate safeguards under Article 46 GDPR, or a derogation under Article 49 — most plausibly Article 49(1)(b), transfer necessary for the performance of a contract concluded at the data subject's request, since enquiries are sent to us voluntarily. A lawyer should confirm which applies and this paragraph should then say so plainly.]
6. Your rights
Under the GDPR you may ask us to:
- confirm what data about you we hold, and give you a copy of it (Article 15);
- correct anything inaccurate (Article 16);
- delete it (Article 17), unless we are legally required to keep it;
- restrict how we use it (Article 18);
- hand it over in a portable format (Article 20);
- stop processing carried out on the basis of legitimate interest (Article 21).
Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect what was lawfully done before it. Write to the contact above and you will receive an answer within one month.
You also have the right to complain to a supervisory authority — in the EU, the data protection authority of the country where you live or work.
7. What we deliberately do not do
- No newsletter is sent unless you separately ask for one.
- No advertising or profiling cookies, and no automated decision-making.
- No sessions are recorded or photographed, and no participant is named in anything we publish. Stories from games are published only when the participant has given written permission, and details are changed.
- Nothing you write in an enquiry is used as marketing material.
8. Changes
If this policy changes, the new version appears on this page with a new date below.
Last updated: 29 July 2026