CARBON STEALTH ANTICHEAT ← BACK TO SITE
CARBON STEALTH VCC · GDPR / REG. 2016/679

Privacy Policy

How Carbon Stealth VCC collects, uses, stores, and protects personal data under the EU General Data Protection Regulation. Plain-language, no dark patterns.

LAST UPDATED April 2026EFFECTIVE immediatelyVERSION 1.0JURISDICTION BG + IT

Who we are

Carbon Stealth VCC (hereinafter "Carbon Stealth", "we", "us") is a limited company registered in Bulgaria (EIK BG208725180), with registered office at ul. Samuil 3, Bobov Dol 2670, Bulgaria, and operational staff based in Milan, Italy.

For the purposes of the EU General Data Protection Regulation (GDPR, Regulation 2016/679), the Bulgarian Personal Data Protection Act, and the Italian Personal Data Protection Code (d.lgs. 196/2003 as amended by d.lgs. 101/2018), Carbon Stealth VCC is the Data Controller for personal data processed through the Carbon Stealth Anticheat product, the carbonstealth.eu website, and any managed-tier panel we operate on your behalf.

Data Controller

ENTITY
Carbon Stealth VCC
EIK / VAT
BG208725180
REGISTERED
ul. Samuil 3, Bobov Dol 2670, Bulgaria
OPERATIONS
Milan, Italy
DPO / PRIVACY
dpo@carbonstealth.eu
GENERAL
support@carbonstealth.eu

What data we collect

2.1 Data collected via the Carbon Stealth scanner (end-user machine)

When a player runs the Carbon Stealth scanner on their machine (with explicit consent — see §4), the scanner inspects local system state to detect cheat software. The inspection is scoped to the following categories of data, each of which is read only to the extent necessary to produce a cheat-detection verdict. Only findings that match a detection rule — plus the minimal context needed for the operator to evaluate them — are submitted; everything else is discarded locally.

What we do NOT collect: personal documents, chat messages, email contents, stored passwords, credit-card numbers, cryptocurrency wallets, keystrokes, clipboard contents, screenshots, audio, or video. No browsing activity or network traffic is inspected other than the specific matches described above. No kernel driver is installed. The scanner does not run persistently in the background — it executes a single scan and exits.

For a detailed, version-specific technical inventory of inspection rules (provided under mutual NDA to operators and enterprise customers for procurement review), contact dpo@carbonstealth.eu.

2.2 Data collected via the Carbon Stealth Panel (operator)

When you create an operator account on a Carbon Stealth panel (self-hosted or managed), we collect:

2.3 Data from payment processors

If you subscribe to a paid tier, Stripe Payments Europe Ltd. processes your payment and shares with us: cardholder name, billing country, last four digits of the card, transaction amount, subscription status. Your full card number, CVC, and authentication credentials are handled exclusively by Stripe under their privacy policy (stripe.com/privacy).

Why we collect it

DATA CATEGORYPURPOSELEGAL BASIS (GDPR ART. 6)
Scanner findingsDetect cheating software for the server operator that requested the scanArt. 6(1)(a) — explicit consent, obtained at each scan via in-scanner EULA
Operator account (email, password)Provide access to the management panelArt. 6(1)(b) — performance of a contract
Session IP & user agentSession integrity, CSRF protection, rate-limitingArt. 6(1)(f) — legitimate interest in security
Payment detailsProcess subscriptionsArt. 6(1)(b) — contract execution
Analytics (aggregated, anonymised)Product improvementArt. 6(1)(a) — consent via cookie banner

Legal basis & consent

The Carbon Stealth scanner never executes a scan without the end user's explicit, informed consent. On every launch, the scanner presents a plain-language EULA dialog (see Scanner EULA) describing what will be inspected, the purpose, and the retention period. The user must click "I accept" to proceed. Consent is freely given, specific, informed, and unambiguous as required by GDPR Art. 4(11) and Art. 7.

You may withdraw consent at any time by declining a scan or by contacting the data controller that requested the scan. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal.

How long we keep data

DATA CATEGORYRETENTIONAFTER RETENTION
Scan reports (self-hosted)Controlled by server operatorOperator's responsibility
Scan reports (managed Operator tier)365 days, or account lifePermanent deletion within 30 days
Session IP / CSRF token24 hoursAutomatic deletion
Login audit log30 daysAutomatic deletion
Operator accountAccount life + 30 daysPermanent deletion
Payment records10 yearsRequired by BG/IT accounting law
Analytics (no PII)Rolling 26 monthsAutomatic deletion

Who we share with

We do not sell personal data. We do not share personal data except for the following service providers bound by data-processing agreements (DPAs):

No advertising networks. No retargeting pixels. No cross-site tracking.

International data transfers

Primary storage is in the European Union (Hetzner Germany, managed tier). Stripe operates from Ireland. Google Fonts is served from a global CDN; where a transfer outside the EEA is necessary, Google relies on the European Commission's Standard Contractual Clauses (SCCs, Decision 2021/914). No transfer to a country without an adequacy decision occurs without appropriate safeguards.

Your rights under GDPR

Under Articles 12–22 GDPR you have the following rights:

To exercise any of these rights email dpo@carbonstealth.eu. We respond within 30 days (extendable by 60 days — Art. 12(3)). No fee is charged unless requests are manifestly unfounded or excessive (Art. 12(5)).

Security measures

We apply appropriate technical and organisational measures under Art. 32 GDPR:

Children under 16

Carbon Stealth is intended for use by adults and by teenagers aged 16 or older with parental consent. We do not knowingly process personal data of children under 16 without verified parental consent, consistent with Art. 8 GDPR. If you believe we have collected data of a minor in error, contact dpo@carbonstealth.eu and we will delete it within 72 hours.

Changes to this policy

We may update this Privacy Policy to reflect product or legal changes. Material changes will be announced on carbonstealth.eu and via email to operator accounts at least 30 days before taking effect.

Contact

Privacy & GDPR requests

DPO EMAIL
dpo@carbonstealth.eu
POSTAL
Carbon Stealth VCC · Attn: Data Protection
ul. Samuil 3, Bobov Dol 2670, Bulgaria
RESPONSE SLA
30 days (extendable 60 days for complex requests)
BG AUTHORITY
Commission for Personal Data Protection — cpdp.bg
IT AUTHORITY
Garante per la Protezione dei Dati Personali — garanteprivacy.it