Privacy Policy · version 2026-08-12

This policy explains the information handled by the Devil-Guard website, Devil-Guard Server and Devil-Guard PC. It is designed to support transparent handling under applicable Australian privacy law and, where the GDPR applies, European data-protection requirements. Nothing in this policy removes rights you have under applicable law.

Who controls the service

Devilish Services operates the Devil-Guard website and determines the purposes of the central platform. Participating game-server operators may also have separate responsibilities for their own server logs, HawkSync records and moderation decisions.

Privacy contact

Privacy questions, access/correction requests and applicable GDPR requests can be sent to appeals@devilishservices.com. We may need to verify identity before releasing or changing account-linked information.

Australian and GDPR scope

Australian privacy obligations are applied where they legally apply. GDPR rights are supported where GDPR applies to the relevant processing, including circumstances covered by its territorial-scope rules. Merely visiting this Australian website from Europe does not by itself determine the legal result.

Information we handle

Account information

Username, email address, display name, primary DFBHD name and approved aliases, account status, roles, password hash, login/security history and personal client-token records.

Device and protection information

Machine identifier, Windows GDID and MachineGuid where provided by Devil-Guard PC, client/session identifiers, approved executable hashes, signed attestation status, protection signals and client version.

Game-server information

HawkSync-observed player name, game-server IP address, active game port, server identity, join/session information, VPN/proxy/Tor/relay classification and enforcement results.

External server-name lookup

When a Devil-Guard PC client is playing on a DFBHD server that does not run Devil-Guard Server, the PC may report the game's current server name, IP address and port. If those local server fields are unavailable, Devil-Guard Web may use the public IP:port or compare the PC-reported in-game player name with public NovaHQ BHD server/player information to identify the advertised server name. These lookups are made by the website backend: Devil-Guard does not send the player's client token, machine ID, GDID or account identity to NovaHQ, and lookup failure cannot deny play.

Detection and optional evidence

Core detections can include DLL/module, hook, executable-memory integrity, unbacked executable-region, file-integrity and selected environment signals. Normal runtime memory monitoring reports detection results and region/code-integrity metadata rather than arbitrary process-memory contents. Separately enabled enhanced evidence may include a DFBHD screenshot, minidump, executable copy, selected Windows-event material or relevant process information.

Appeals and administration

Ban/appeal reasons, council votes and outcomes, correspondence while an appeal is open, server-host assignments and administration/audit actions.

Technical records

Security logs, request timestamps, source IPs where required for security or server correlation, email-delivery records and essential session/security data.

Protected-server joins without an account

A participating server can collect the player name and game IP it directly observes even where the player has no Devil-Guard account or PC client. The separate Protected Server & Join Data notice explains that collection and its consequences.

Why information is used

Provide the service

Authenticate users, issue personal tokens, connect PC and server reports, display account activity, process appeals and keep protected services operating.

Security and fair-play protection

Validate signed reports, identify integrity/runtime detections, correlate protected-server joins, prevent ban evasion, classify network-anonymiser use where enabled and enforce server rules.

Legal bases where GDPR applies

Depending on the processing, the basis may include performance of the service/contract, legitimate interests in platform and game-server security, compliance with legal obligations, and consent where a genuinely optional function requires it. Optional enhanced evidence and optional third-party media are kept separate from essential processing.

Automated processing

Software can automatically evaluate protection status and produce or assist server-access decisions. The logic, categories of information and appeal/human-review safeguards are described on the Automated Decisions & Enforcement page.

Retention, disclosure and rights

Detailed case evidence is minimised after a final council decision while a compact ban history remains. An upheld active restriction retains only identifiers still required to enforce it. Information is disclosed only to roles/services needed for the stated purpose, to infrastructure providers where required to operate the service, or where law requires/permits it. Cross-border processing, if used, is assessed under applicable requirements. Access, correction, erasure, restriction, objection and portability rights are explained on the Data Rights page; these rights can have legal exceptions.

Privacy complaints

Raise a privacy concern with the privacy contact first so it can be recorded, investigated and answered. Where Australian privacy law applies, this does not remove any right to complain to the OAIC. Where GDPR applies, it does not remove a right to complain to the competent supervisory authority.