Privacy Notice
Controller contact, purposes, legal bases, transfers, retention, and rights for Contact's website, key, licensing, and support data.
Short version
Contact may process access keys, IP addresses, browser/device data, local acceptance records, support messages, and Luarmor licensing or anti-abuse signals, including device-related identifiers. Contact does not sell personal data and does not run its own targeted advertising profiles. Third-party key providers and runtime websites have their own privacy practices.
1. Controller and Contact Details
The controller for Contact's own website, key-flow, licensing, anti-abuse, and support processing is the Contact Project Operator, the operator of Contact and contactinghere.lol. Privacy requests should be sent to privacy@contactinghere.lol. Legal and rights-holder notices should be sent to legal@contactinghere.lol. Discord and Telegram may be used for ordinary support, but email is the preferred channel for formal requests.
No Data Protection Officer is appointed. No EU or UK representative is appointed for the current operation. If a representative or additional public trader details become legally required because Contact's processing, establishment, targeting, or commercial model changes, this notice should be updated before the relevant processing continues.
2. Data We May Process
| Category | Examples |
|---|---|
| Website and security logs | IP address, user agent, requested URLs, timestamps, referrer, error logs, Cloudflare/Hostinger security events. |
| Key and licensing data | Access key, key status, issue/expiry timestamps, validation results, runtime requests, rate-limit and abuse signals. |
| Device-related identifiers | Hardware-derived identifiers, device fingerprints, or equivalent license-binding identifiers processed through providers such as Luarmor. |
| Support and review data | Discord or Telegram usernames, email address if provided, support messages, files you send, appeal/review details, moderation history. |
| Local browser acceptance record | Terms version, Privacy Notice version, acceptance timestamp, and local browser state stored on your device. |
3. Purposes and Legal Bases
Where GDPR or similar law applies, the following legal bases are used for Contact's own processing. If a law outside the GDPR uses different labels, the closest equivalent basis is used.
| Processing | Purpose | Legal basis | Legitimate interest, where used |
|---|---|---|---|
| Key validation and loader access | Provide temporary access and generate configured loaders. | Contract or steps requested before a contract. | Not primary basis. |
| Device-related licensing and anti-abuse | Prevent key sharing, unauthorized redistribution, tampering, fraud, and abuse. | Legitimate interests; contract where necessary to provide the service. | Protecting Contact, users, licensing systems, and infrastructure from abuse. |
| Website, CDN, and security logs | Deliver the website, diagnose failures, block attacks, and maintain availability. | Legitimate interests; legal obligation where security retention is required. | Network security, fraud prevention, debugging, and service reliability. |
| Support and false-positive review | Answer requests, investigate issues, and review enforcement decisions. | Contract, legitimate interests, or consent where the request includes optional data. | Resolving user issues, preventing abuse, and keeping accurate support records. |
| Legal notices and rights-holder requests | Handle claims, preserve evidence, and comply with legal duties. | Legal obligation; legitimate interests. | Defending legal claims and responding to lawful notices. |
| Local acceptance record | Remember accepted Terms and Privacy versions on the same browser. | Contract and legitimate interests. | Evidence of acceptance and avoiding repeated prompts until versions change. |
4. Cookies and Local Storage
Contact's key page may store a local acceptance record on your device. This record is used to remember whether this browser accepted the current Terms and Privacy Notice versions. If you clear browser storage, use another browser, or the legal versions change, you may need to accept again. Third-party providers may use their own cookies, analytics, advertising, or tracking technologies under their own policies.
5. Sharing, Processors, and Independent Providers
Data may be shared with infrastructure, hosting, CDN, security, key delivery, licensing, anti-abuse, and support providers as needed to operate Contact. This may include Cloudflare for DNS/CDN/security, Hostinger for hosting, Luarmor for licensing and anti-abuse controls, Discord or Telegram for support messages you send there, and third-party key providers such as Work.ink, ShrtFly, and LootLabs when you visit them. External providers may act as processors, independent controllers, or separate services depending on the context and their own terms.
6. International Transfers
Contact is available globally, and providers may process data in countries other than yours. For EEA, UK, or Swiss data, transfers may rely on adequacy decisions where available, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum or IDTA, Swiss equivalents where applicable, provider Data Privacy Framework certification where valid for the provider and transfer, or another lawful transfer mechanism. For occasional user-initiated support or legal requests, derogations may apply where permitted by law. You may request information about the transfer mechanism relevant to your data through the privacy contact.
7. Automated Access Controls and Review
Licensing and anti-abuse systems may automatically allow, deny, rate-limit, suspend, or flag access based on key status, integrity checks, device-related identifiers, and abuse signals. These systems protect the project from unauthorized redistribution and tampering. If you believe an access block is a false positive, contact support or the privacy contact and include enough information to verify the request. Human review may be available where required by law or where reasonably possible, although access may remain suspended during review.
8. Retention
| Data | Typical retention | Reason |
|---|---|---|
| Website and CDN/security logs | 30 to 90 days where available. | Security, debugging, abuse prevention. |
| Temporary key records | For the key lifetime plus up to 90 days. | Validation, troubleshooting, abuse prevention. |
| Device-related anti-abuse records | Up to 24 months after the relevant event. | Prevent repeat abuse, redistribution, and tampering. |
| Support and review messages | Up to 24 months after last interaction. | Continuity, evidence, dispute handling. |
| Legal notices and disputes | As long as needed for the claim or legal duty. | Compliance, defense, preservation. |
| Local acceptance record | Until cleared by you or replaced by a new version. | Versioned acceptance on your browser. |
Longer retention may apply where required for security, legal obligations, fraud prevention, disputes, backups, or abuse prevention. Data that is no longer needed should be deleted or de-identified where reasonably possible.
9. Your Rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, objection, withdrawal of consent, information about automated processing, or review of certain decisions. You may also have the right to complain to a data protection authority. Some requests may be limited where data is needed for security, legal obligations, abuse prevention, dispute defense, or where we cannot reasonably verify the requester.
Residents of jurisdictions with consumer privacy laws may also have rights to know, access, delete, correct, appeal, or opt out of certain uses. Contact does not sell personal data and does not use Contact-controlled data for cross-context targeted advertising.
10. Children
Contact is not directed to children under 13 or to children below the minimum age required by local law for the relevant service. If you believe a child provided personal data without required permission, contact us so we can review and delete it where appropriate.
11. Security
We use reasonable technical and organizational measures to protect Contact and reduce abuse. No online service is perfectly secure. Do not send sensitive personal data, government IDs, payment card numbers, passwords, private account credentials, or unrelated personal data through support channels.
12. Changes
We may update this Privacy Notice by posting a revised version with a new "Last updated" date and version number. Material changes apply prospectively unless a different effective date is required by law. The key page may require renewed acceptance when this notice changes materially.