privacy at a glance
Your IP address and Steam identifiers are received when you connect so traffic can reach the server and your account can be authenticated.
We link logs and identifiers for whitelists, moderation, anti-cheat, ban enforcement, troubleshooting and security—not advertising profiles.
AUREK does not sell personal information or run behavioural advertising in this build.
You can ask about, correct or in some cases delete or restrict personal data, subject to legal and security exceptions.
before connecting
joining the game server creates technical and gameplay logs.
Garry’s Mod and the underlying network connection necessarily expose connection information to the server. You cannot use the game server without the basic processing needed to route your connection, authenticate your Steam account, maintain security and distinguish you from other players.
1. who we are and what this notice covers
AUREK RP (“AUREK”, “we”, “us” or “our”) is an independent fan community operated jointly by its two owners, Lucifer in the United Kingdom and William in the United States. For the purposes of this notice, they determine why and how AUREK processes personal data and act as the operators/controllers of the community.
This notice covers personal data processed through the AUREK website, Discord administration, Garry’s Mod servers, applications, whitelists, support, moderation, anti-cheat, logs, events and connected community systems. Third-party platforms process information under their own privacy notices.
Privacy requests can be made by opening a ticket in the official AUREK Discord and labelling it “privacy request”.
2. personal data we may collect
| category | examples |
|---|---|
| Steam and game identity | SteamID, SteamID64, account/profile name, authentication result, Garry’s Mod identifiers, linked in-game name and account status. |
| network and technical data | IP address, source port, connection and disconnection times, ping, server/client version, request time, user agent, error data, rate-limit events and hosting or proxy logs. |
| Discord identity | Discord user ID, username, display name, avatar, relevant server roles, ticket messages and basic OAuth profile data used to sign you into staff applications, event feedback and approved administration tools. |
| gameplay and character data | Character names, jobs, ranks, regiments, permissions, progression, inventory, currency, vehicles, actions, commands, events, deaths, arrests and other server state. |
| communications | Text chat, commands, applications, forms, support tickets, appeals, reports, feedback and messages sent to staff. Voice is normally transmitted live by the platform; AUREK may receive clips or recordings submitted as evidence. |
| moderation and security | Warnings, mutes, bans, reasons, evidence, staff notes, screenshots, clips, linked identifiers, suspected alternate accounts, ban-evasion indicators, anti-cheat alerts and investigation outcomes. |
| staff application data | Selected staff area, age in completed years (not date of birth), timezone, Steam profile or SteamID, in-game name, availability, Garry's Mod and Star Wars RP experience, previous staff experience, moderation history, scenario answers, application status and authorised review notes. |
| event feedback data | Overall rating, event date and description, event host, regiment or job played, what you liked or disliked, suggested improvements, additional comments, review status and authorised internal notes. |
| whitelist and access data | Other application answers, test results, approvals, denials, role assignments, training records and access-control history. |
| website and admin data | Session ID, login and logout times, Discord OAuth identity, form submission references, administrator actions, saved site links, notices and private project notes. |
| transaction data, if introduced | Order reference, product, amount, currency, status and processor account reference. AUREK should not receive full card details from a compliant payment processor. |
We do not intentionally ask for special-category information such as health, ethnicity, religion, political beliefs or sexual orientation. Do not post sensitive real-world information in game or community channels. If such information appears in a report or incident, we may process the minimum necessary to protect users, moderate content or meet legal obligations.
3. how information is collected
- Directly from you: when you connect, complete a staff application, send event feedback, open a ticket, send a message, appeal, report a user, use Discord OAuth or otherwise communicate with AUREK.
- Automatically: through game-server, web-server, anti-abuse, authentication, security and administration logs generated when systems are used.
- From platforms: from Steam/Valve, Garry’s Mod/Facepunch, Discord and other providers where their service passes identifiers or profile information needed for the feature you use.
- From other people: through player reports, staff observations, submitted clips, screenshots or witness information.
- From public sources: where reasonably necessary to verify an impersonation, public threat, rights claim, ban evasion or security issue.
4. why we use data and our lawful bases
| purpose | typical lawful basis |
|---|---|
| provide access, authenticate accounts, maintain characters and deliver requested community functions | Performance of a contract or steps you ask us to take before joining; legitimate interests where the arrangement is informal or free. |
| receive, assess and administer staff applications, including contacting applicants and recording decisions | Steps you ask us to take by applying and legitimate interests in selecting, organising and safeguarding the volunteer staff team. |
| receive and review event feedback, identify patterns and improve future events | Legitimate interests in understanding player experience, supporting event staff and improving the community; your submission is voluntary. |
| operate whitelists, permissions, staff tools, support and events | Performance of our arrangement with you and legitimate interests in administering the community. |
| moderate conduct, investigate reports, enforce rules, link sanctions and prevent ban evasion | Legitimate interests in protecting users, maintaining fair roleplay, enforcing rules and defending claims. |
| anti-cheat, fraud prevention, account security, network protection, rate limiting and incident response | Legitimate interests in network and information security; legal obligation where applicable. |
| preserve and disclose evidence of suspected illegal activity or child-safety concerns | Legal obligation, legitimate interests, and where applicable substantial public interest or protection of vital interests. |
| Discord OAuth for applications, feedback and administrator access | Legitimate interests in connecting submissions to the correct community account, preventing abuse and restricting administrative systems. |
| respond to legal requests, rights claims, tax/accounting requirements or disputes | Legal obligation and legitimate interests in establishing, exercising or defending legal claims. |
| optional analytics, marketing or non-essential cookies, if later introduced | Consent where required. They are not included in the current public website build. |
Where we rely on legitimate interests, we must identify a genuine purpose, assess whether the processing is necessary and balance it against your rights. We document and review that assessment where required.
5. Steam IDs, IP addresses and server logs
When you connect, the server receives your IP address as part of ordinary internet communication and receives or derives Steam identifiers to authenticate and distinguish your account. We may record these identifiers with timestamps, connection outcomes and gameplay events.
These records are used for:
- routing the connection and authenticating the player;
- maintaining characters, whitelists, ranks and permissions;
- connection history, debugging, performance monitoring and incident response;
- moderation, report investigation, anti-cheat and exploit detection;
- linking known alternate accounts, preventing ban evasion and enforcing network-level blocks;
- protecting staff, players, infrastructure and the integrity of the game economy; and
- establishing, exercising or defending legal claims.
“Tracking” in this context means internal operational correlation of account, connection, gameplay and moderation records. It does not mean selling behaviour profiles or using game activity for third-party targeted advertising.
VPN or proxy use may be restricted where it materially prevents security, authentication or sanction enforcement. An IP address can be shared or reassigned, so it should not normally be treated as conclusive proof on its own.
6. moderation, reports and anti-cheat
Staff and security tools may create reports, flags and evidence about suspected misconduct. Automated systems may immediately block or flag obvious threats, cheats, rate abuse or invalid authentication. Significant sanctions should generally be reviewed by an authorised person, although temporary automatic protection may apply while a matter is investigated.
We may combine Steam IDs, Discord IDs, IP data, device or client indicators, gameplay patterns, prior sanctions and report evidence where reasonably necessary to identify abuse or ban evasion. We do not promise to reveal detection rules or reporter identities where doing so would compromise safety, privacy or security.
False positives can occur. Use the published appeal process if you believe information is inaccurate. A moderation appeal is separate from a legal data-protection request.
7. website, Discord OAuth, forms and sessions
The public homepage and policy pages can be viewed without signing in. Staff applications, event feedback and the administrator panel require Discord OAuth so submissions and administrative actions can be connected to a verified Discord account.
AUREK requests only Discord's identify scope in this build. Discord provides the website with your Discord user ID, username, display name and avatar. We do not request your email address, server list or permission to act as you. The OAuth access token is used to request that basic profile and is not intentionally written to the persistent application or feedback store.
After login, the website sets an aurek.sid cookie linked to a server-side session containing basic Discord profile data and a security token. The session normally expires after eight hours and can end earlier when you sign out or expired sessions are cleaned up. The website may process an IP address in memory for rate limiting, while the hosting provider or reverse proxy may also create ordinary access and security logs.
Staff applications and event feedback are not anonymous. Each submission stores a copy of the basic Discord identity shown before the form is sent, together with a unique reference and the answers supplied. Only the owners and authorised reviewers with a genuine need to know should access complete submissions. Internal review notes and decisions are also restricted to authorised administrators.
The form presents a short, just-in-time explanation and direct links to these policies before submission. The acknowledgement checkbox records that the notice was presented and accepted; it does not remove legal rights or turn every use of data into consent-based processing.
9. international access and transfers
AUREK is operated from the United Kingdom and the United States, and service providers may process data in other countries. This means information may be accessed outside the country where you live.
AUREK will not make a restricted international transfer unless an approved mechanism applies, such as an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another lawful safeguard, together with appropriate security measures.
10. how long we keep data
We keep personal data only for as long as reasonably necessary for the stated purposes, legal obligations, safety and dispute handling. Our current retention schedule is set out below. A specific record may be kept for a shorter or longer period where the purpose, legal obligation, safety risk or dispute reasonably requires it:
| record | intended retention |
|---|---|
| short-lived rate-limit and security state | Minutes to days, unless promoted into an incident record. |
| authenticated website sessions | Up to eight hours for staff applicants, feedback users and administrators, then expired session files are removed during scheduled cleanup. |
| routine connection, web, gameplay, command and chat logs | Normally up to 12 months, with shorter rotation where practical; longer only where linked to a live investigation, sanction, security incident or legal claim. |
| staff applications and review notes | Normally up to 24 months after the application is closed or the staff relationship ends, unless a shorter period is sufficient or the record is needed for an ongoing role, dispute, safeguarding issue, repeated-abuse pattern or legal claim. |
| event feedback and review notes | Normally up to 12 months after submission so trends and event-team improvements can be reviewed; longer where the response becomes part of a complaint, moderation matter, safety issue or legal claim. |
| support tickets and ordinary reports | Normally up to 24 months after closure, unless needed for a dispute, safeguarding issue or repeated-abuse pattern. |
| warnings, bans, linked identifiers and sanction evidence | For the life of the sanction and as reasonably necessary afterwards to prevent evasion, handle appeals and defend decisions. Permanent-ban records may remain while AUREK operates, subject to periodic review and minimisation. |
| whitelist, role and progression records | While active and for a reasonable period after inactivity, removal or closure to administer returns, disputes and security. |
| security incidents and legal claims | For the investigation and any relevant legal limitation or regulatory period. |
| backups | Typically overwritten within 90 days, unless isolated for security recovery or a legal hold. |
| financial and tax records, if applicable | For the period required by tax, accounting and consumer law, commonly six years in the UK. |
We may delete or anonymise information earlier where it is no longer needed. A request for deletion is not absolute: we may retain limited information where necessary to enforce a continuing ban, protect others, comply with law or establish, exercise or defend legal claims.
11. security and data incidents
We use measures appropriate to the size and risk of the community, which may include access controls, least-privilege permissions, signed and HTTP-only sessions, encryption in transit, protected environment secrets, rate limits, backups, logging and restricted staff access. No internet service can promise absolute security.
Do not send passwords, authentication tokens, full payment-card details or unnecessary real-world identification through AUREK. If you believe personal data or an account has been compromised, contact us promptly through the official Discord.
AUREK should maintain an incident-response process, assess reportable breaches and notify affected people or regulators where the law requires it.
12. children and younger players
AUREK is not intended for children under 13. Users must also meet any higher local or platform minimum age. Staff applicants must be at least 16 years old. The application asks for age in completed years only; it does not require a full date of birth or government identification for the ordinary application process.
Because an online game community may be accessed by people under 18, AUREK should apply high-privacy defaults, collect only what is needed, avoid unnecessary profiling and place younger users' interests first when designing new features. Event feedback does not require an age field and should not be used to request unnecessary real-world details.
Do not submit real names, home addresses, schools, private images, health details or other unnecessary sensitive information in an application or feedback form. Reports involving grooming, sexual exploitation or immediate risk are handled under the Safety & Reporting Policy and may be reported to platforms or authorities.
13. your data-protection rights
Depending on the law that applies, you may have rights to:
- be informed about processing and obtain a copy of personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction in certain circumstances;
- object to processing based on legitimate interests;
- receive certain data in a portable format;
- withdraw consent where consent is the lawful basis; and
- challenge certain solely automated decisions.
Rights are not absolute. We may need to verify identity and may redact information about other people or refuse a request where an exemption applies, the request is manifestly unfounded or excessive, or retention remains necessary for security, sanctions, legal obligations or claims. We will explain the lawful reason where required.
14. requests, complaints and changes
Open a ticket in the official AUREK Discord, label it “privacy request”, state the right you want to exercise and provide enough information to locate the relevant account or records. Do not post sensitive details in a public channel.
If you are dissatisfied, first ask AUREK to review the matter. UK users may also complain to the Information Commissioner’s Office. People elsewhere may contact their local data-protection authority.
We may update this notice as systems or law change. Material changes will be highlighted on the website or Discord, and the version and effective date at the top will be updated.