NextWorld2 Discord 10K+ members on Discord
International server The NextWorld2 international server launches at the end of this year! Don’t miss out: follow NextWorld2 and join our Discord server. Join our Discord

Privacy Policy

Information about handling personal data

Language note. This document is the official English translation of the original Hungarian version. In case of any discrepancies, the Hungarian version prevails. Hungarian version

The www.nextworld2.com website (hereinafter: Website) and the NextWorld2 online game (hereinafter: Game) are operated by the service provider and data controller, who hereby informs visitors to the Website and users of services through the Website (i.e. users) about its data management practices.

1. The Data Controller

Data Controller details:
company name: Donut Interactive Kft.
company registration number: 01-09-324747
court of registration: Metropolitan Court of Registration
registered office: 1068 Budapest, Király utca 80.
tax number: 26335577-2-42
statistical number: 26335577-5821-113-01
e-mail: [email protected]
hereinafter: Data Controller.

2. Purpose, scope, and duration of data processing

The Data Controller processes the personal data of Website visitors and users (as data subjects) that are necessary for contacting and communicating, for providing the service (that is, participation in the Game and information about the Game's terms), and for fulfilling the legal relationship established between the Data Controller and the data subjects regarding this service.

To use the Website and participate in the Game, you need to register by providing certain personal data.

The personal data processed by the Data Controller can only come from natural persons who visit the Website, contact the Data Controller, or register on the Website.

By registering, you consent to the Service Provider recording and processing the data you provide during registration.

By registering, you consent to the Service Provider recording your login data, the time you spend in the Game, and transaction data related to Items obtained in the Game, for the purpose of monitoring the operation of the Website and Game and preventing abuse.

By registering, you consent to the Service Provider recording messages you send to other users or to the Data Controller during your visit to the Website, as well as any additional personal data you may provide in those messages, for quality assurance purposes.

The data processed by the Service Provider fall into the following categories:

  • registration data (name, email address, password);
  • transaction data (Karzium purchases and top-ups);
  • login and log data (IP address, in-game activity);
  • customer Support tickets (Discord ticket system and email);
  • hardware and system information (device ID, operating system, performance parameters, error reports) for development, debugging, and system stability analysis.

Personal data are processed by the Data Controller or by persons/organizations providing services to the Data Controller for purposes and content defined by the Data Controller, but only as long as necessary to fulfill contractual or legal obligations, enforce contractual claims, or achieve other data processing purposes. Personal data will be deleted from the Data Controller's records or properly anonymized when no longer needed.

You have the right to request that the Data Controller delete your personal data without undue delay if it is no longer needed, or if any other reason for deletion specified in Article 17(1) b)-f) of the GDPR applies (GDPR Article 17). If you have used paid services in the Game, participated in user-to-user trading, or if it is necessary for investigating any user issue, and also considering accounting and tax regulations, the Data Controller will retain the data within the statutory limitation period.

You can request the deletion or modification of your personal data primarily through the ticket system operating on the official Discord server of the Game, or by emailing [email protected].

If unlawful or misleading personal data is used and/or if the data subject commits a crime or attacks the Data Controller's IT system, the Data Controller is entitled to immediately delete the provided personal data. However, if required by an official or court procedure, the Data Controller will retain the personal data for the period ordered by the authority or court, or for the duration of the procedure. If a court or authority legally requires it, the Data Controller will delete the personal data as specified in the order.

This Privacy Policy does not cover services and/or data processing related to other websites referenced on the Website, including services, promotions, or other content provided by third parties not named as data controllers in this Policy. Data processing related to these is governed by the privacy policies of the third-party service providers, and the Data Controller is not responsible for such data processing.

3. Use of cookies

While operating the Website, the Data Controller uses so-called cookies to improve user experience, ensure proper functioning of the Website, and for statistical analysis. A cookie is a small data file saved by the website to your device, containing certain information about your visit.

The use of cookies is based on your prior, explicit consent, which you can give and withdraw at any time via the Website's cookie banner.

Types of cookies used on the Website:

  • Session cookies: these are stored temporarily and are automatically deleted when you close your browser.
  • Persistent cookies: these are stored on your device for a longer period and allow the Website to recognize returning visitors.
  • Third-party cookies: these include, for example, cookies used by Google Analytics, which collect anonymous data for statistical purposes about how the Website is used.

Most browsers automatically accept cookies, but you can manage them (including deleting and blocking them) in your browser settings.

4. Automated decision-making and profiling

The Data Controller does not use automated decision-making processes based solely on machine processing (including profiling) that would have legal effects on you or similarly significantly affect you.

The Data Controller may analyze user behavior (e.g. time spent in the Game, acquired Items, messaging habits) exclusively for statistical purposes or to improve service quality, but these data processing activities do not result in decisions that affect you individually.

If the Data Controller uses automated decision-making or profiling in the future, you will be informed in advance and your rights under Article 22 of the GDPR will be ensured.

Data processing for protecting Game integrity and preventing cheating: The Data Controller, to ensure fair and smooth operation of the Game, detect and prevent cheating, abuse, and prohibited automated solutions (especially bots, macros, scripts, external programs), creates, logs, stores, and regularly or occasionally checks and analyzes security snapshots of your in-game activities, gameplay, and technical data related to your user account using both automated and manual methods. The main and ongoing goal of this activity is to maintain a clean, fair, and equal gaming environment for everyone.

The types of data processed for this purpose typically include: user account and character IDs, gameplay-related events and statistics, characteristics and timing patterns of actions performed in the Game, aggregated input activity data, and technical and device data related to running the Game (such as IP address, client version, technical details of the runtime environment).

The legal basis for this data processing is the legitimate interest of the Data Controller and other Game users (GDPR Article 6(1)(f)): preserving the integrity of the Game, preventing cheating and abuse, and maintaining a fair and equal gaming environment for everyone. The prevention of fraud as a legitimate interest is specifically confirmed by Recital 47 of the GDPR. The Data Controller established this legitimate interest by carrying out a balancing test, the result of which is available upon request.

The Data Controller processes this data exclusively for the above security purposes, only to the extent and for the duration necessary, and does not share it with third parties except as required by law. You also have the right to object to this processing as described in this Notice (GDPR Article 21); however, the Data Controller may continue processing if there are compelling legitimate grounds that override your interests, rights, and freedoms-especially to protect the integrity of the Game and the rights and interests of other users. Based on the results of such checks, you may be subject to actions (such as account restriction, suspension, or deletion), against which you can initiate the complaint and review procedure set out in the Rules, which includes human (not solely automated) review.

5. Legal basis for data processing

In this section, the Data Controller defines the legal bases for processing your data.

  • Contract: processing of personal data is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract (GDPR Article 6(1)(b)).
  • Legal obligation: processing of certain personal data (mainly for tax and accounting purposes) is mandatory due to legal obligations, and any official or court requests received by the Data Controller may also require data processing (GDPR Article 6(1)(c)).
  • Consent: The Data Controller will always ask for your explicit consent for processing data that is only needed for marketing communications (e.g. newsletters, ads, promotions) (GDPR Article 6(1)(a)).
  • Legitimate interest: processing of certain data may be necessary for the legitimate interests of the Data Controller or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms that require protection of personal data (GDPR Article 6(1)(f)).

6. Principles of data processing

The Data Controller processes data in accordance with the principles of lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.

The Data Controller draws your attention to the fact that providing personal data is voluntary, but if certain required data are missing or inaccurate, the Data Controller may not be able to maintain proper contact and/or create or fulfill a contract. Therefore, it's important that you provide the requested data accurately and completely. The Data Controller will always specify which data are essential for contacting you or providing the service and for participating in the Game.

The Data Controller does not verify the personal data you provide. You are solely responsible for the accuracy of your personal data, but the Data Controller will take all reasonable measures to promptly delete or correct any unnecessary, incorrect, or inaccurate personal data for the purposes of data processing.

7. Data processing by third parties

7.1 Data processors

The Data Controller uses third-party services (e.g. accounting, financial) for its business activities. Based on contracts with these service providers as data processors, certain personal data (name, email address, billing data) may be transferred to or accessed by these providers for the purpose of providing the service. The data processor may only process this data according to the Data Controller's instructions, unless required otherwise by EU or member state law.

7.2 Data processing related to payment transactions

Financial service providers involved in payment transactions have their own data protection policies for the data needed to process payments. The personal data you provide on the payment interface is processed only by the payment service provider; the Data Controller named in this policy does not have access to this data. Therefore, you must always read and accept the privacy policy of the payment provider before completing your transaction.

SimplePay card payment service:
SimplePay Zrt.
Registered office: Budapest, Váci út 135-139-B. building, 5th floor, 1138.
Company registration number: 01-09-174466
Tax number: 24386106-2-42

Data Transfer Statement for SimplePay Payment:
I acknowledge that the following personal data stored in the user database of nextworld2.com by Donut Interactive Kft. (1068 Budapest, Király utca 80.) as data controller will be transferred to SimplePay Zrt. as data processor. The scope of data transferred by the data controller includes: last name, first name, email address, billing name, billing address, tax number (if provided). The nature and purpose of the data processing carried out by the data processor can be found in the SimplePay Privacy Policy at the following link: https://simplepay.hu/adatkezelesi-tajekoztatok/

VoxPay invoicing service:
Voxinfo Kft.
Registered office: 1037 Budapest, Királylaki út 132.
Company registration number: 01-09-562739
Tax number: 12180439-2-41
Privacy policy: https://fizetes.voxpay.hu/adatvedelem

7.3 Data processing related to Game support and customer service requests - Discord

The Data Controller handles Game-related Support and customer service requests through the official Discord server's ticket system. This ticket system is operated by the Data Controller itself, within its own IT system (Support module).

The Discord system (see more in Section 13 of the Rules) has its own data protection policy for data required to register for the Discord system. For data provided during Discord registration, the Discord Terms of Service (https://discord.com/terms) and Privacy Policy (https://discord.com/privacy) apply.

Support requests can be submitted through the ticket system operating on the official Discord server of the Game. The content of requests submitted via tickets and any related personal data are processed and stored by the Data Controller in its own IT system, as described in section 8 of this Policy. The Data Controller does not use any external, third-party ticket system provider for this purpose, and ticket content is not stored on third-party servers.

The Discord platform (Discord Inc.) as a communication channel may store and, if necessary, forward message data exchanged via Discord on its own servers, including data centers outside the EU/EEA, according to its own data protection policy. However, the Data Controller stores the content of tickets and related personal data within the European Union or EEA, and does not transfer personal data to countries outside the EU or EEA.

8. How personal data is stored and data security

The Data Controller's IT system, and thus the actual location of data processing, is on servers operated by OVH Groupe SAS (headquarters: 2 rue Kellermann, 59100 Roubaix, France, www.ovhcloud.com) as part of a cloud service. Despite using cloud services, the Data Controller is fully responsible for hosting and data processing.

The Data Controller protects data with appropriate measures, especially against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction, damage, or inaccessibility due to changes in technology.

Taking into account the current state of technology, the Data Controller ensures the security of data processing with technical, organizational, and structural measures that provide a level of protection appropriate to the risks involved. The Data Controller's IT system and network are protected against computer-aided fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, hacking, and denial-of-service attacks. The Data Controller ensures security with both server-level and application-level protection procedures.

To prevent unauthorized use of personal data and related abuses, the Data Controller applies extensive technical and operational security measures. The Data Controller selects and operates IT tools for processing personal data so that the processed data:

  • accessible to authorized persons (availability)
  • authenticity is ensured (data processing authenticity)
  • integrity is verifiable (data integrity)
  • protected against unauthorized access (data confidentiality).

The Data Controller informs you that electronic messages transmitted over the internet, regardless of protocol (email, web, ftp, etc.), are vulnerable to network threats aimed at unfair activities or disclosure or modification of information. To protect against such threats, the Data Controller takes all reasonable precautions, monitors systems to record any security deviations, and provides evidence in the event of any security incident. System monitoring also allows checking the effectiveness of the security measures in place.

9. Rights of data subjects regarding data processing

Every natural person whose personal data is processed by the Data Controller, as a data subject, has the following rights regarding data processing:

Right to prior information: you have the right to be informed about facts and information related to data processing before it begins (GDPR Article 13).

Right of access: you have the right to receive feedback from the Data Controller on whether your personal data is being processed, and if so, to access your personal data and certain related information (GDPR Article 15).

Right to rectification: you have the right to request that the Data Controller correct inaccurate personal data about you without undue delay. Considering the purpose of processing, you also have the right to request the completion of incomplete personal data, including by means of a supplementary statement (GDPR Article 16).

Right to erasure (“right to be forgotten”): you have the right to request that the Data Controller delete your personal data without undue delay, and the Data Controller is obliged to do so if the data is no longer needed or if any other reason for deletion specified in Article 17(1) b)-f) of the GDPR applies (GDPR Article 17).

Right to restriction of processing: you have the right to request that the Data Controller restrict processing, especially if the Data Controller no longer needs the data, or if processing is unlawful, or if any other condition specified in Article 18(1) a)-d) of the GDPR applies (GDPR Article 18).

Notification obligation regarding rectification or erasure of personal data or restriction of processing: The Data Controller will inform all recipients to whom personal data has been disclosed about any rectification, erasure, or restriction of processing, unless this proves impossible or requires disproportionate effort. Upon request, the Data Controller will inform you about these recipients as well (GDPR Article 19).

Right to data portability: under the conditions set out in GDPR Article 20, you have the right to receive your personal data provided to a Data Controller in a structured, commonly used, machine-readable format, and to transmit those data to another Data Controller without hindrance from the original Data Controller (GDPR Article 20).

Right to object: you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(f) of the GDPR (processing necessary for the legitimate interests of the Data Controller or a third party) (GDPR Article 21).

Automated decision-making in individual cases, including profiling: you have the right not to be subject to a decision based solely on automated processing-including profiling-that produces legal effects concerning you or similarly significantly affects you (GDPR Article 22).

Notification of a data protection incident: if a data protection incident is likely to result in a high risk to your rights and freedoms, the Data Controller will inform you of the incident without undue delay (GDPR Article 34).

Right to lodge a complaint with a supervisory authority (right to legal remedy): you have the right to lodge a complaint with a supervisory authority-especially in the member state of your habitual residence, place of work, or place of the alleged infringement-if you believe that the processing of your personal data violates the GDPR (GDPR Article 77).

Right to effective judicial remedy against the supervisory authority: Every natural and legal person has the right to effective judicial remedy against a legally binding decision of the supervisory authority concerning them, or if the supervisory authority does not handle a complaint or does not inform the data subject within three months about the procedural developments or the outcome of the complaint (GDPR Article 78).

Right to effective judicial remedy against the data controller or processor: Every data subject has the right to effective judicial remedy if they believe their rights under the GDPR have been violated due to improper handling of their personal data (GDPR Article 79).

10. Legislation

The Data Controller refers to the General Data Protection Regulation of the European Union in this Privacy Notice - Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) - by its English abbreviation (GDPR).

The Data Controller refers to Act CXII of 2011 on the right to informational self-determination and freedom of information in this Privacy Policy as 'Infotv.'

11. Legal remedies, supervisory authority

According to Section 52 (1) of the Info Act, anyone can initiate an investigation at the National Authority for Data Protection and Freedom of Information (NAIH) by reporting that a violation of rights has occurred or is at direct risk in connection with the processing of personal data.

Supervisory authority contact details:
National Authority for Data Protection and Freedom of Information
address: 1055 Budapest, Falk Miksa utca 9-11.
phone: +36 (30) 683-5969
+36 (30) 549-6838
+36 (1) 391 1400
fax: +36 (1) 391-1410
e-mail: [email protected]
mailing address: 1363 Budapest, Pf.: 9.

You can find detailed information on the authority's website: https://naih.hu.

You can also take legal action against any data controller or data processor if you believe your personal data has been processed in violation of the rules set out by law or by a binding legal act of the European Union.

12. Questions, comments, or requests related to the Data Controller's data processing

No data protection officer has been appointed at the Data Controller. If you have any questions, comments, or requests about data processing, you can send them directly to [email protected].

13. Scope of the Privacy Policy

This Privacy Policy was finalized on 2026.07.13. The Data Controller reserves the right to modify this Privacy Policy, supplement or clarify it as required by changes in legislation, and will always inform affected data subjects of any changes through the Website.

Donut Interactive Kft.
Data Controller