Effective date · September 20, 2026
Privacy Policy
This Policy governs the processing of personal data carried out in the course of providing the Fiveops service.
1. Data Controller
The data controller is Fiveops.
Enquiries: support@fiveops.app. Business details are set out on the Legal notice page.
2. Data Processed on the Marketing Site
Where the visitor gives explicit consent, Google Analytics measurement runs on the fiveops.app domain. In that context the pages viewed, the referring address, an approximate location (country/city level) and browser information are processed.
Until consent is given, no analytics cookie is placed and no identifier is created.
No marketing cookies, advertising cookies or profiling are used. Further information is set out in the Cookie Policy.
3. Categories of Personal Data Processed
3.1 Data Provided Directly
Where sign-in is performed through Discord, the user id, username, avatar and electronic mail address transmitted by Discord are processed.
Correspondence and files submitted within support tickets are processed.
Payment and invoicing data is collected by the Merchant of Record; payment card details are not transmitted to the Company.
3.2 Data Collected Automatically
Session data and sign-in records (date, time and IP address) are retained for the purpose of information security.
Audit records of staff actions carried out in the panel are retained.
Technical data transmitted by the server is addressed separately in the following article.
4. Data Transmitted by the Server
The following data is transmitted to the Company by the resource: server name, IP address, version information, player count and status signal; records of actions carried out by Staff Members; bans; support tickets and the files attached to them.
Players' character, vehicle, inventory and balance data is not transmitted to the Company. Such data is held in the Subscriber's own database; where it is displayed in the panel it is read live by the resource and is not retained by the Company.
5. Purposes and Legal Grounds of Processing
Personal data is processed for the following purposes and on the following legal grounds:
| Purpose | Legal ground |
|---|---|
| Creating the account and providing the Service | Conclusion and performance of a contract |
| Authorisation and access control | Performance of a contract |
| Delivering invoice and service notices | Performance of a contract |
| Ensuring information security and preventing misuse | Legitimate interest |
| Handling support requests | Performance of a contract |
| Meeting financial and legal obligations | Legal obligation |
6. Data Security Measures
The Company applies the following technical and organisational measures to protect personal data:
- TLS encryption in transit.
- Role-based access control and the principle of least privilege.
- Regular backups held under access control.
- Regular updating of dependencies and server software.
- Recording of staff actions in an audit log.
Notwithstanding those measures, it is acknowledged that no method of transmission over the internet or of electronic storage provides absolute security.
7. Retention Periods
Log records are retained for thirty (30) days and are deleted at the end of that period.
Bans and support tickets are retained until deleted by the Subscriber or until the account is closed.
Where the account is closed, data is deleted within ninety (90) days at the latest.
Support correspondence is retained for three (3) years from the last interaction.
Records subject to retention obligations under financial legislation are retained for the period prescribed by that legislation.
8. Recipients of Transferred Data
Personal data is not sold. It is shared with the following service providers for the purpose of providing the Service:
- Polar Software Inc. — payment, invoicing and sales tax operations. Payment card details are not transmitted to the Company.
- Cloudflare, Inc. — delivery of the marketing site and storage of files attached to support tickets.
- Discord, Inc. — authentication, bot messages and log channels.
- Google Ireland Limited — measurement of the marketing site (Google Analytics), only where explicit consent has been given.
Where a court order or a legal obligation applies, disclosure is made only to the extent requested.
9. Transfers Abroad
Certain of the service providers listed above are established outside Türkiye, in the United States and the European Union, and data may be processed on servers in those countries.
Transfers are carried out only to the extent necessary for the provision of the Service.
10. Rights of the Data Subject
The data subject has the right to access their data, to request its rectification, erasure or the restriction of its processing, and to request its portability.
Requests are to be directed to support@fiveops.app and are concluded within thirty (30) days at the latest.
11. Disclosure under KVKK and the Right to Complain
Under Turkish Personal Data Protection Law no. 6698, the data controller is Fiveops.
Applications concerning the rights listed in article 11 of that Law may be directed to support@fiveops.app.
Where an application is refused, the response is considered insufficient or no response is given within the prescribed period, the data subject has the right to lodge a complaint with the Turkish Personal Data Protection Board (kvkk.gov.tr).
Users established in the European Union have the right to lodge a complaint with the supervisory authority of their country under the General Data Protection Regulation (GDPR).
12. Automated Decision-Making and Profiling
Personal data is not analysed solely by automated means in a manner producing legal effects or significantly affecting the data subject.
Automated checks aimed at preventing misuse are applied together with human review.
13. Third-Party Links
The Service may contain links to third-party websites. The Company is not responsible for the content or privacy practices of those sites.
Reviewing the privacy notices of those sites is recommended.
14. Business Customers and the Data Processing Agreement
A Data Processing Agreement (DPA) and an up-to-date sub-processor list are available on request from support@fiveops.app.
15. Amendments to the Policy
Where this Policy is amended, the date shown at the head of this page is updated. Material amendments are additionally notified by electronic mail or through the panel.
Questions regarding these documents may be directed to support@fiveops.app.
Other legal documents