01 / Controller
WHO WE
ARE.
Quarks Factory (“we”, “us”, “our”) is the independent game studio that operates this website and the associated newsletter and contact services. For GDPR purposes we are the controller of the personal data described in this policy: we decide why and how that data is processed.
If you want to exercise your rights, ask a question, or object to processing, write to hello@quarksfactory.com. Press enquiries can also use press@quarksfactory.com.
We do not have a statutory data protection officer. Requests are handled by the studio. You can also lodge a complaint with a supervisory authority (see Your rights).
02 / Categories
WHAT WE
COLLECT.
We do not run advertising trackers or sell personal data. We collect only what is needed to run the site, send news you asked for, and answer messages you send us.
| Source | Personal data | Legal basis |
|---|---|---|
| Newsletter form | Email address; timestamp of subscription; record that you ticked the consent box; list membership in Brevo. Technical data from the request (IP address, user agent, approximate location) may be processed by Cloudflare when the form is submitted. | Consent, Art. 6(1)(a) GDPR, and ePrivacy rules for marketing email |
| Contact form | Name; email address; selected topic; message content; timestamp; consent record. The same technical request data as above may be processed by Cloudflare. | Consent, Art. 6(1)(a), and our legitimate interest in answering you, Art. 6(1)(f) |
| Direct email | Whatever you send to our studio addresses, plus standard email metadata (addresses, timestamps, servers). | Legitimate interest in corresponding with you, Art. 6(1)(f), or steps prior to a contract, Art. 6(1)(b) |
| Website visit | IP address, date and time, requested URL, referrer, browser and device information, country or city derived from IP, security and performance logs. Cloudflare may also set strictly necessary security cookies. | Legitimate interest in hosting, securing and delivering the site, Art. 6(1)(f) |
| Newsletters we send | Delivery status; and, if tracking is enabled in Brevo, whether a message was opened and which links were clicked, often with IP-derived location. | Consent, Art. 6(1)(a), for marketing measurement related to the newsletter you subscribed to |
We do not intentionally collect special-category data (Art. 9 GDPR). Please do not put health, political, religious or similar information in the contact form. We do not use automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR).
We do not target children. This site is for a general adult audience. If you believe a child has sent us personal data, contact us and we will delete it.
03 / Brevo
NEWSLETTER
SIGNALS.
The homepage form lets you subscribe to studio news. You must tick the consent box before we accept the address. We then send the email to our mailing list through Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France).
What happens to your email
- A Cloudflare Pages Function on this site receives the address and forwards it to Brevo’s API.
- Brevo stores you as a contact on our list so we can send development notes, game news and occasional studio transmissions.
- We do not require a name, phone number or other profile fields for this form.
- You can unsubscribe at any time with the link in every newsletter, or by emailing us. After you leave the list we may keep the address on a suppression list so we do not write to you again by mistake.
Brevo is established in the EU. Customer data at rest is generally hosted in the European Union (including infrastructure in France/Germany and Google Cloud in Belgium). Brevo publishes a Data Processing Agreement with its terms and uses subprocessors, some of which may be outside the EEA. Transfers, if any, rely on adequacy decisions, Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework, as described in Brevo’s legal documents.
Read Brevo’s Privacy Policy and Brevo’s Terms (including DPA).
04 / Resend & Gmail
CONTACT
FORM.
The contact page form is for general, press, partnership, feedback and bug-report messages. You provide your name, email, topic and message, and you must tick the privacy consent box before send.
How the message is delivered
- A Cloudflare Pages Function receives the form on this domain.
- Resend (Resend, Inc., United States) sends the email through its API. We use your address only as the reply-to field. The From address is a studio sender we control.
- The email, including name, email, topic and full message, is delivered to our studio inbox, currently operated with Gmail (Google LLC).
Resend: storage in the United States
Resend is our processor for sending that email. According to Resend’s public GDPR documentation:
- Customer data is stored in the United States, including message content, delivery logs, webhook payloads and account records.
- Choosing an EU sending region (if configured) only affects where mail is dispatched from. It does not move stored data to the EU.
- On standard plans, email and log data are retained for about 30 days while the account is active. Backups may persist for a further short period (Resend states 7 days). After account termination, remaining customer data is deleted within 90 days.
- Transfers from the EEA to the US are covered by Standard Contractual Clauses in Resend’s DPA and by Resend’s participation in the EU–U.S. Data Privacy Framework (including the UK Extension).
- Resend encrypts data in transit and at rest and acts as processor for this customer data under an Article 28 DPA.
See Resend GDPR, Resend Privacy Policy and Resend DPA.
Gmail / Google
Once delivered, we read and store the correspondence in our email account so we can reply and keep a record of the conversation. Google processes that mailbox. Google is a US company. Depending on the type of Google account we use, Google may act as a processor under Google’s Cloud Data Processing Addendum (typical for Google Workspace) or, for a consumer Gmail account, under Google’s own terms and privacy policy as an independent service provider.
International transfers to Google rely on the EU–U.S. Data Privacy Framework where Google is certified, and/or Standard Contractual Clauses. Google may store and process data in the United States and other countries where it operates.
05 / Cloudflare
WEBSITE AND
HOSTING.
This site is hosted and delivered through Cloudflare (Cloudflare, Inc., United States), including CDN, DNS, security (such as DDoS and bot protection) and Cloudflare Pages Functions that power /subscribe and /contact.
When you load a page or submit a form, Cloudflare processes End User logs. That typically includes IP address, requested resources, timestamps, user agent, referrer, and similar connection metadata. Form payloads (email, name, message) transit Cloudflare’s network to reach our functions, then go to Brevo or Resend as described above. We do not operate a separate visitor analytics product on this site.
Cloudflare’s network is global: a request may be handled at an edge location near you. Logs and related metadata may be processed in the United States or other countries unless a paid data-localization option is enabled. Cloudflare publishes a Customer DPA, uses Standard Contractual Clauses, and participates in the EU–U.S., Swiss–U.S. and UK Extension Data Privacy Frameworks.
06 / Technical
COOKIES,
FONTS, CDN.
We do not set marketing or analytics cookies ourselves. We do not use Google Analytics, Meta Pixel or similar advertising tags.
Strictly necessary / security
Cloudflare may set cookies that are needed to run and protect the site (for example bot-management or challenge cookies such as __cf_bm or similar). These are used for security and network integrity, not for advertising. Where they are strictly necessary for the service you request, they do not require consent under the ePrivacy rules.
Fonts and front-end libraries
We load Google Fonts from Google’s servers and Bootstrap from jsDelivr. Your browser then contacts those providers, which can see your IP address and standard request headers. That is a transfer of technical data to those providers so the page can render. Legal basis: legitimate interest in presenting a consistent, working site, Art. 6(1)(f). You can block third-party requests in your browser; the layout may degrade.
Provider notices: Google, jsDelivr.
Social networks
Links to Discord, YouTube, X, Instagram and TikTok open those platforms. We do not embed their tracking widgets on this page. If you follow a link, the destination’s own privacy policy applies.
07 / Article 13(1)(f)
PROCESSORS AND
TRANSFERS.
We use the following recipients. “Processor” means they handle data on our instructions for the stated purpose.
| Recipient | Role | Location / transfer |
|---|---|---|
| Brevo (Sendinblue SAS) | Processor: newsletter contacts and sending | EU (France). Some subprocessors may be outside the EEA; safeguards in Brevo’s DPA |
| Resend (Plus Five Five, Inc.) | Processor: sending contact-form email; stores message content and logs | United States. SCCs + EU–U.S. Data Privacy Framework. Content retained ~30 days on standard plans |
| Google LLC (Gmail) | Mailbox where we receive and keep correspondence | United States and other Google regions. DPF and/or SCCs as applicable to the account type |
| Cloudflare, Inc. | Processor: hosting, CDN, security, Pages Functions | Global edge network; US company. Customer DPA, SCCs, DPF |
| Google Fonts / jsDelivr | Independent providers of fonts and JS when your browser requests them | May be outside the EEA |
US transfers are restricted transfers under Chapter V GDPR. We rely on: (1) the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework where the recipient is certified; and (2) the European Commission’s Standard Contractual Clauses, plus the UK Addendum where UK GDPR applies. You can request more detail about the safeguards by emailing us.
Authorities in the United States may, in limited cases, access data held by US companies under US law. We choose vendors that publish SCCs, DPF certification and security measures, but we cannot eliminate that residual risk entirely for Resend, Google or Cloudflare.
We may also disclose data if required by law, to protect our legal rights, or to a successor if the studio is transferred, provided GDPR continues to apply.
08 / Storage
HOW LONG WE
KEEP DATA.
- Newsletter: until you unsubscribe or we delete the list, then on a suppression list as needed to honour that choice.
- Contact messages in our inbox: for as long as the conversation is active and then up to three years, unless a longer period is required for a legal claim, contract or statutory duty. We may delete sooner if you ask and we have no overriding obligation to keep the mail.
- Resend logs and message copies: according to Resend’s retention (about 30 days on standard plans).
- Cloudflare security and access logs: short-lived operational logs as configured by Cloudflare / our plan, typically days rather than years, unless needed to investigate abuse.
- Consent records: for as long as we rely on consent and a reasonable period afterwards to show that we obtained it.
Where processing is based on legitimate interests, you may object. We will stop unless we demonstrate compelling legitimate grounds or need the data for legal claims.
09 / Article 32
SECURITY.
We transmit form data over HTTPS. API keys for Brevo and Resend are stored as server-side environment bindings, not in the public website files. Resend and Cloudflare document encryption in transit and at rest. No method of transmission or storage is perfectly secure. Please do not send passwords, payment card numbers or other highly sensitive secrets through the contact form.
10 / Chapter III
YOUR
RIGHTS.
If GDPR applies to you (for example you are in the EEA, UK or Switzerland), you may:
- Access your personal data and obtain a copy (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erase data in the cases set out in Art. 17 (including when you withdraw consent and we have no other lawful basis).
- Restrict processing (Art. 18).
- Port data you provided to us on the basis of consent, in a structured, commonly used, machine-readable format (Art. 20).
- Object to processing based on legitimate interests (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3)). For the newsletter, unsubscribe or email us. For the contact form, ask us to delete the message where we can.
- Complain to a supervisory authority (Art. 77), in particular in the EU Member State of your habitual residence, place of work, or of the alleged infringement. A list of EEA authorities is published by the European Data Protection Board. In the UK you may contact the ICO. In Switzerland, the FDPIC.
We will respond without undue delay and in any event within one month, extendable by two months for complex requests. We may need to verify your identity. These rights are not absolute; we will explain if an exception applies.
11 / Reach us
QUESTIONS AND
UPDATES.
Privacy requests: hello@quarksfactory.com. Please write “Privacy request” in the subject so we can treat it promptly.
We may update this policy when our tools, purposes or the law change. The “Last updated” date at the top of this page will change. Material changes that affect data we already hold will be announced in a reasonable way (for example a note on this page or, where we have your email and the change is significant, a message).
This notice describes our current website, newsletter (Brevo), contact form (Resend → Gmail) and Cloudflare hosting. It is not a substitute for legal advice. If you need a formal DPA as a business partner, contact us before sending personal data of others.