Privacy PolicyL3 SimGuard & LAND3 Simulations Developer Portal  ·  Last updated: 2026-05-25  ·  Effective: 2026-05-25

This Privacy Policy explains what personal data we process when you use the L3 SimGuard desktop application or the LAND3 Simulations developer portal, why we process it, on what legal basis, with whom we share it, how long we keep it, and which rights you have. A German version is available at /datenschutz.

1. Controller

Simulatortechnik Reinemuth
George-Washington-Str. 221
68309 Mannheim
Germany

E-Mail: contact@land3simulations.com

Data subject requests (access, deletion, objection, etc.) should be sent to the same address.

2. Data We Process

We process the following categories of personal data:

  • Account data (developer portal): email address, hashed password, role and permission assignments, session tokens.
  • License and activation data (L3 SimGuard): device identifier, activation key, license validation timestamps.
  • Software metadata (L3 SimGuard): installed version, operating system version, installation and uninstallation events, update events.
  • Integrity and tamper events (L3 SimGuard): anti-tamper event codes, timestamps, and the device identifier they relate to. We do not transmit the contents of your Protected Add-ons or any of your personal files.
  • Crash and error reports (L3 SimGuard): stack traces, application version, operating system, locale, and breadcrumbs from the application's own logging, collected via Sentry. You can disable this at any time in Settings → General → Disable crash reporting.
  • Server logs: IP address, timestamp, requested URL, HTTP status, user agent — logged by our hosting and CDN providers for security and abuse prevention.

3. Purposes and Legal Basis

  • License validation, activation, software delivery and updates — performance of contract (GDPR Art. 6(1)(b)).
  • Anti-tamper integrity checks and abuse prevention — legitimate interest in protecting our software and licensed content from circumvention (GDPR Art. 6(1)(f)).
  • Crash and error reporting — legitimate interest in maintaining software stability and security (GDPR Art. 6(1)(f)). You may object via the in-app opt-out (see Section 2).
  • Account authentication for the developer portal — performance of contract (GDPR Art. 6(1)(b)).
  • Server logs — legitimate interest in operating and securing our infrastructure (GDPR Art. 6(1)(f)).

4. Recipients and Processors

We use the following processors. Data processing agreements under GDPR Art. 28 are in place with each.

  • Google LLC (USA; Firebase Hosting) — hosting of the developer portal website. Transfers to the USA are protected by the EU Standard Contractual Clauses.
  • Supabase Inc. (USA, processing in EU region) — backend database, authentication, and edge functions for the developer portal and license backend. Transfers to the USA are protected by the EU Standard Contractual Clauses.
  • BunnyWay d.o.o. (Slovenia, EU; trading as BunnyCDN) — delivery of the L3 SimGuard installer and update packages.
  • Functional Software, Inc. d/b/a Sentry (USA) — crash and error reporting. Transfers to the United States are protected by the EU Standard Contractual Clauses.
  • Cloudflare, Inc. (USA) — bot protection (Turnstile) on the developer portal login. Transfers to the USA are protected by the EU Standard Contractual Clauses.

5. International Transfers

Where data is transferred outside the European Economic Area (in particular to the United States), the transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures.

6. Retention

  • Account data: for the lifetime of the account; deleted within 90 days of account closure.
  • License and activation data: for the duration of the license and up to 24 months thereafter for fraud and abuse investigation.
  • Tamper and integrity events: up to 12 months.
  • Crash reports: up to 90 days (Sentry default retention).
  • Server logs: up to 30 days for security, longer if needed to investigate a specific incident.

7. Your Rights (GDPR, EU / EEA / UK)

You have the right to:

  • access your personal data (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erase your data (Art. 17), subject to legal retention duties;
  • restrict processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21), including a right to object to crash reporting at any time via the in-app toggle;
  • lodge a complaint with a supervisory authority. The competent authority for our location is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg. UK users may complain to the Information Commissioner's Office (ICO).

To exercise any of these rights, contact us at the contact address in Section 1.

8. California Residents (CalOPPA and CCPA / CPRA)

California residents may contact us at the contact address in Section 1 to exercise any rights granted by California law, including the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt out of any sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.

Our processing is limited to the purposes described in Section 3. We do not sell personal information, and we do not engage in cross-context behavioral advertising.

9. Other Jurisdictions

Residents of Brazil (LGPD), Canada (PIPEDA), Australia, Quebec (Law 25), or other jurisdictions with comparable laws may have additional rights regarding their personal data. Contact us at the contact address in Section 1 to exercise them.

10. Cookies and Local Storage

The developer portal uses only strictly necessary local storage and cookies: the Supabase authentication session token, and the Cloudflare Turnstile bot-protection token. These are required for the site to function and do not require consent. We do not use analytics, advertising, or tracking cookies.

11. Security

Communication with our servers is encrypted in transit (HTTPS / TLS). Passwords are stored hashed. Access to backend systems is restricted to authorized personnel.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified to you by an in-application message, by email (where applicable), or by publication on this page with an updated "Last updated" date.