Main page
Legal

Data Protection
and Privacy Policy

Grimy KFT  |  Company No. 01-09-457104  |  Last updated: 10 August 2026

Contents

1.Overview

This Data Protection and Privacy Policy (“Policy”) explains how Grimy KFT collects, uses, stores, shares, and protects personal data in connection with the Atlantheos platform available at https://atlantheos.com/ and all related services, accounts, gameplay features, payment flows, market features, payout functions, and support channels operated by us (the “Platform”).

We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), applicable Hungarian data protection law, and other applicable privacy and consumer protection requirements.

We do not sell your personal data.

2.Identity of the Data Controller

The data controller responsible for your personal data is:

Grimy KFT
Company Registration No.: 01-09-457104
Registered Address: 1141 Budapest, Szugló utca 82., Hungary
Website: https://atlantheos.com/
Email: support@atlantheos.com

In this Policy, Grimy KFT is referred to as “we”, “us”, “our”, or the “Company”.

3.Personal Data We Collect

Depending on how you use the Platform, we may collect and process the following categories of personal data:

4.How We Collect Personal Data

We collect personal data directly from you when you create an account, make a purchase, submit a support request, request a payout, complete verification, participate in the Artifact Market, or otherwise interact with the Platform.

We also collect data automatically when you use the Platform, including device data, log data, gameplay data, transaction data, cookies, and similar technologies.

We may receive data from third parties, including payment processors, identity verification providers, fraud prevention providers, hosting providers, analytics providers, email delivery providers, customer support providers, banks, card networks, and competent authorities.

5.Purposes and Legal Bases for Processing

We process personal data only where we have a lawful basis under the GDPR. The main purposes and legal bases are:

6.Required and Optional Data

Some data is necessary to provide the Platform. If you do not provide required account, payment, verification, or transaction information, we may be unable to provide certain features, save your progress, process purchases, operate the Artifact Market, process payouts, handle disputes, or comply with legal obligations.

Optional data, such as certain profile or marketing preferences, may be changed or withdrawn where applicable.

7.Cookies and Similar Technologies

We use cookies and similar technologies as described in our Cookie Policy. Strictly necessary cookies and equivalent browser storage support account access, security, gameplay continuity, payment flows, and basic Platform operation. Optional cookies, such as analytics or advertising cookies, are used only where permitted by law and, where required, after consent.

You may manage cookie choices through the cookie settings available on the Platform or through your browser settings.

8.Disclosure of Personal Data

We may share personal data with the following categories of recipients where necessary:

We require service providers to process personal data only under appropriate contractual and security obligations.

9.International Transfers

Your personal data may be processed in the European Economic Area and, where necessary, outside the European Economic Area.

Where we transfer personal data outside the EEA, we use appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses approved by the European Commission, supplementary measures where needed, or another lawful transfer mechanism under the GDPR.

10.Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide the Platform, comply with legal obligations, resolve disputes, prevent fraud, enforce agreements, and maintain security.

Typical retention periods include:

When personal data is no longer required, we delete it, anonymise it, or securely archive it where continued retention is required by law.

11.Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. Measures may include encryption, access controls, logging, monitoring, secure development practices, fraud detection, role-based permissions, and provider due diligence.

No online service can be guaranteed to be completely secure. You are responsible for keeping your account credentials confidential and for promptly informing us of suspected account compromise.

12.Your GDPR Rights

Subject to applicable conditions and exemptions, you may have the following rights:

To exercise your rights, contact us at support@atlantheos.com. We may need to verify your identity before responding.

Please note that deleting your account data will also delete your game progress, Atlanteans, equipment, Artifacts, and in-game balances, and that this cannot be undone.

13.Automated Processing and Profiling

We may use automated tools to detect fraud, bot activity, market abuse, payment risk, sanctions risk, security threats, and suspicious account behaviour. We may also use automated systems to match opponents in the Arena, balance the Platform, or detect technical issues.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you unless permitted by law and subject to appropriate safeguards. Payout requests are reviewed manually by an administrator.

14.Children

The Platform is not intended for users under 18. We do not knowingly collect personal data from minors. If we become aware that a person under 18 has provided personal data, we will take appropriate steps to delete the data and restrict the account, subject to legal requirements.

15.Marketing Communications

We may send service-related communications, including security notices, purchase confirmations, invoices and receipts, payout updates, account notices, policy updates, and support messages.

We send marketing communications only where permitted by law. You may opt out of marketing communications at any time by using the unsubscribe link or contacting us at support@atlantheos.com.

16.Supervisory Authority

If you are not satisfied with how we handle your personal data, you may lodge a complaint with the Hungarian data protection supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Website: https://www.naih.hu/
Postal address: 1055 Budapest, Falk Miksa utca 9-11, Hungary

You may also have the right to contact the supervisory authority in your EU Member State of residence, place of work, or place of the alleged infringement.

17.Changes to This Policy

We may update this Policy from time to time to reflect changes in our data practices, Platform features, legal requirements, service providers, or security measures. The current version will be available on the Platform. Material changes may be notified through the Platform or by email where appropriate.

18.Contact

For privacy questions, data subject rights requests, or complaints, contact:

Grimy KFT
Company Registration No.: 01-09-457104
Registered Address: 1141 Budapest, Szugló utca 82., Hungary
Website: https://atlantheos.com/
Email: support@atlantheos.com


Company Information

Company name: Grimy KFT
Company number: 01-09-457104
Registered address: 1141 Budapest, Szugló utca 82., Hungary
Email: support@atlantheos.com