- We collect what we need to sell you a license and run the loader — account, license, device identifier (HWID), payment metadata, session logs.
- When our anti-tamper subsystem detects analysis tools on your device, we collect a one-shot forensic snapshot (system, network, running-process names) and issue an HWID ban you can appeal.
- Session logs and tripwire raw events are kept 30-90 days. Payment records are kept 7 years (tax law). Active HWID bans persist until overturned.
- We use Stripe, NOWPayments, Cloudflare, our EU hosting provider, Discord, and a transactional email provider. We do not sell or share your data for advertising.
- You have access, deletion, correction, portability, and objection rights — request them at /dsar or [email protected]. Response window: 30 days (EU/UK) or 45 days (US) from receipt.
This policy applies to all users of KyTech loader software and account services. If you are located in a jurisdiction with additional statutory rights, the region-specific section below supplements this policy — where they conflict, the region-specific text controls.
01Who we are
KyTech, Ltd. ("KyTech", "we", "us"), a Florida limited-liability company, operates this website, the associated loader software, the customer account panel, and the paid game-enhancement services described therein. We are the data controller for the personal data described in this policy (a "business" under the CCPA/CPRA).
- Privacy contact: [email protected]
- Postal: the operating-entity address is provided on request with any data-subject request.
- Supervisory authority (EU): the lead authority in the member state of your habitual residence. You may also lodge complaints with the UK Information Commissioner's Office (ICO), the French CNIL, or the Bavarian BayLDA depending on where you sit.
- Article 27 representative (EU) / UK representative: designated on request in writing.
02What we collect — data categories
The table below is the authoritative enumeration of every category we collect. Anything not listed here is out of scope; anything we begin to collect will be added here before the practice starts.
| Category | Fields | Source | Purpose |
|---|---|---|---|
| Account identifiers | Email, Discord ID, username, hashed password (Argon2id) | Signup | Contract, authentication |
| License data | License key, activation status, plan, expiry | Purchase | Contract |
| Device identifier (HWID) | SHA-256 hash of BIOS-UUID · MAC · COMPUTERNAME | Loader handshake | Contract, anti-fraud |
| Payment metadata | Stripe payment token, card BIN + last-4, crypto invoice ID | Stripe / NOWPayments (pass-through) | Contract, tax law |
| Session logs | UUID, cheat ID, timestamps, status transitions | Injector runtime | Service delivery, abuse detection |
| Anti-tamper telemetry | See explicit breakout below | Loader preflight, only on tripwire | Anti-tamper (legitimate interest) |
| Support tickets | Subject, body, attachments, chat transcripts | User submission | Contract |
| Admin audit log | Actions taken by our staff on your account | Staff actions | Legal obligation, security |
Fields collected at the moment a tripwire fires
Our loader includes a client-side anti-tamper subsystem that watches for the presence of debuggers, disassemblers, kernel-debug hardware, memory editors, packet-analysis tools, and a specific set of VPN clients while it is preparing to inject. This scan runs on your device and transmits nothing during a clean launch. If — and only if — a signature match occurs, the loader assembles and sends an evidence record to our servers.
Collected on your device (client-side)
hostname— your Windows machine namewindowsUser— the current Windows account name (may contain your personal name)osEdition,osVersion,osBuild— Windows edition and buildpsEdition,psVersion— PowerShell edition and versionuptimeSec— seconds since last boot
domain,partOfDomain— Active Directory membershiptimezone— your IANA/Windows timezone idlocale— e.g.en-USlocalIpsV4/localIpsV6— private-range IP addresses of active adaptersmacAddressesand fulladaptersAlltable (name, description, status, MAC)processesAll— names only of every running process (no command lines, no file paths)- The specific
reason,tier, andtimestampof the detection
Stamped by our server (server-side, cannot be spoofed by the client)
remoteIp— the public IP address of the connectionuserAgent— the browser/HTTP User-Agent header (capped at 512 characters)cfIpCountry,cfIpCity,cfIpColo,cfIpAsn— coarse geographic + ASN metadata derived by Cloudflare from your IPreceivedAt— server-side epoch millisecond timestamp
Purpose: to identify actors who are attempting to reverse-engineer, deobfuscate, or repackage the loader — activity which threatens the integrity of the service and every paying customer's investment.
Legal basis: GDPR Article 6(1)(f) — legitimate interest. Our Legitimate Interest Assessment (LIA) balancing test is documented and available on request; see §12 DSAR.
Retention: raw tripwire evidence rows are held for 30 days, then hard-deleted by an automated nightly sweeper. If a ban is minted from an incident, a denormalised subset (hostname, IP, country, city, User-Agent) is carried forward on the ban row for as long as the ban is active. See §5 for the full retention schedule.
03What we do NOT collect
- Contents of any file on your disk — no paths, no filenames, no file bodies
- Command-line arguments of any process (only the process name is captured)
- Browser history, saved passwords, cookies, or credentials from other applications
- Contents of network traffic; captured packets; DNS queries
- Data from other games or applications not affiliated with KyTech
- Biometric data — HWID and MAC are device identifiers, not biometric identifiers within the meaning of GDPR Article 4(14)
- Anything at all from a person who does not launch our loader
04Why we collect — legal bases (GDPR Article 6)
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide the loader / injector service | Account, License, HWID, Session logs | Art 6(1)(b) Contract |
| Process payments, issue receipts | Payment metadata | Art 6(1)(b) Contract |
| Retain tax records | Invoices, payment metadata | Art 6(1)(c) Legal obligation (national tax law) |
| Anti-tamper monitoring, HWID bans, incident forensics | Anti-tamper telemetry, HWID, Session logs | Art 6(1)(f) Legitimate interest — protecting service integrity and paying customers from cheat-tool proliferation. LIA on file. |
| Admin audit log | Staff-action records | Art 6(1)(f) Legitimate interest + Art 6(1)(c) where a regulator requires it |
| Marketing emails, optional analytics | Email, aggregate telemetry | Art 6(1)(a) Consent — opt-in only, withdrawable |
| Breach notification if required | Contact email | Art 6(1)(c) Legal obligation (Art 33-34) |
A summary of the Legitimate Interest Assessment (LIA) — the balancing test performed to justify Art 6(1)(f) processing — is available on request via any DSAR channel below.
05Retention windows
Retention starts from the most recent activity on the record, not from first collection. Automated sweepers run nightly at 03:00 UTC.
| Category | Retention | Then |
|---|---|---|
| Account data | Account lifetime + 90 days | Hard-delete email and username; the hash-only HWID is retained for anti-fraud |
| Payment metadata | 7 years | Hard-delete (tax-law compliance) |
Session logs (injector_events) | 90 days | Nightly sweeper deletes |
Tripwire raw events (tripwire_events) | 30 days | Nightly sweeper deletes |
| HWID bans — active | Indefinite | Legitimate-interest retention; overturnable at any time via Support |
| HWID bans — expired or overturned | 2 years from state change | Purged; the HWID hash is no longer personal data once dissociated from identifiers |
| Admin audit log | 2 years | Purged (regulator retention floor) |
| Support tickets | Account lifetime + 90 days | Purged with account |
| Telemetry | 30 days raw / 90 days aggregated | Aggregates retained; raws purged |
| Web-server access logs | 30 days | Purged |
06Sharing — sub-processors and recipients
We do not sell personal information, share it for cross-context behavioural advertising, or process it for profiling with legal effects. The following sub-processors handle data on our behalf under written data-processing agreements.
| Recipient | Purpose | Data | Location | Legal instrument |
|---|---|---|---|---|
| Stripe, Inc. | Card processing | Payment metadata | US + EU | DPA + SCCs |
| NOWPayments OÜ | Crypto invoicing | Invoice ID, amount | Estonia | DPA |
| Cloudflare, Inc. | CDN, DDoS, TLS termination, edge analytics | IP, User-Agent, request headers | Global anycast | DPA + SCCs; EU-US Data Privacy Framework certified |
| Hosting provider (Hetzner Online GmbH — primary; DigitalOcean — failover) | Application + database hosting | All service data | Frankfurt (DE) primary; US failover | DPA + SCCs where cross-border |
| Discord, Inc. | OAuth sign-up, role sync | Discord ID, email, username | US | DPA + SCCs |
| Transactional email (SendGrid, Postmark — whichever is live) | Sending order receipts, password-reset mail, DSAR acknowledgements | Email address, message body | US | DPA + SCCs; EU-US DPF certified |
07Cross-border transfers
- Primary hosting region: Frankfurt, Germany (Hetzner FSN1 datacenter).
- EU → US transfers: where the sub-processor is EU-US Data Privacy Framework certified (Cloudflare, SendGrid) we rely on the adequacy decision under the DPF. Otherwise we rely on Standard Contractual Clauses (Module 2, 2021 European Commission Implementing Decision 2021/914, unmodified).
- UK: the UK IDTA addendum is layered on top of the SCCs.
- Swiss FADP: we use FDPIC-approved SCCs.
- Transfer Impact Assessment (TIA): maintained per Schrems II and available to regulators on request.
08Cookies, SDKs, and tracking
- Strictly necessary — session cookie (
connect.sid): HttpOnly, SameSite=Lax, Secure. Required to keep you signed in. - Strictly necessary — CSRF token cookie (
x-csrf-token): protects form submissions. - Strictly necessary — referral capture (
ky_ref, 14-day, HttpOnly): if you arrived via?ref=CODE, we drop this cookie to attribute a signup to the referring user. - Analytics — Cloudflare Web Analytics beacon: server-side aggregate only, no cross-site tracking, sets no cookies.
- No third-party advertising SDKs. No Facebook Pixel, no Google Analytics, no ad-tech pixels.
Because we set no non-essential cookies, no cookie-consent banner is legally required under the EU ePrivacy Directive as implemented in the UK PECR or the Bavarian TDDDG. If we ever add one, the banner appears first and processing waits for consent.
09Security
- Transport: TLS 1.2+ enforced end-to-end. HSTS enabled.
- At rest: host-level disk encryption (LUKS) plus SQLite file-system encryption on the database volume.
- Device identifiers: the HWID is stored as a SHA-256 hash. A raw device identifier is never persisted.
- Passwords: Argon2id with per-user salt.
- Admin access: WebAuthn / hardware-key 2FA required. The admin panel is loopback-only from the public internet — access requires an SSH-forwarded tunnel from an authorised operator.
- Anti-tamper evidence: stored on the same encrypted volume as production data. Every read of an incident record by staff is written to the admin audit log.
- Breach response — EU/UK (GDPR Art 33/34): notification to the competent supervisory authority within 72 hours of becoming aware of a personal-data breach where the risk threshold is met. Affected data subjects are notified per Article 34.
- Breach response — Florida (FIPA, F.S. § 501.171): as a Florida-based operator, we notify each affected Florida resident of a covered breach within 30 days of discovery. If a breach affects more than 500 Florida residents, we also notify the Florida Attorney General within 30 days.
- Breach response — other U.S. states: we comply with the notification timelines and content requirements of each state whose residents are affected (all 50 U.S. states plus D.C. have breach-notification statutes with timelines ranging from "without unreasonable delay" to 30-90 days).
10Special categories
- We do not process special-category data as defined by GDPR Article 9 (health, race, sexual orientation, religion, political opinion, trade-union membership, genetic, or biometric data).
- The HWID (SHA-256 of BIOS UUID · MAC · hostname) is a device identifier, not a biometric identifier for the purposes of Article 4(14) — which requires processing of physical, physiological, or behavioural characteristics of a natural person. It is nonetheless treated as personal data because it can identify a device that identifies a natural person.
- MAC addresses are personal data (indirectly identifying) but do not fall within a special category.
- The Windows username field (
[Environment]::UserName) may contain a personal name; this is disclosed explicitly in §2 above and is retained under the same rules as the rest of the anti-tamper record.
11Age gate
- The service is 18+. Account creation requires attestation of age.
- COPPA (United States): we do not knowingly collect data from children under 13. If we learn a child under 13 has provided data we delete it on discovery.
- GDPR Article 8: the age of digital consent varies by member state (13-16). This is not in scope here because the service is 18+.
- UK Age Appropriate Design Code: not in scope for the same reason.
12Your rights & the DSAR workflow
You can exercise the following rights over the data we hold about you. Region-specific extensions are in §13 below.
All users
- Access — receive a JSON export of every record tied to your license, HWID, or email.
- Rectification — self-service in the account panel for editable fields; email us for anything else.
- Erasure — the account and every personally attributable record are deleted. See the carve-out below.
- Portability — the same JSON export as Access, structured for import into another service.
- Objection / restriction — your account is frozen; hard-tier HWID bans remain in force under the legitimate-interest balancing test.
- Complaint — you may lodge a complaint with your local supervisory authority (see §1).
Response windows
- EU / UK (GDPR): 30 days, extendable by 60 days for complex requests (Art 12(3)).
- California (CCPA / CPRA): 45 days, extendable by 45 days (§1798.130(a)(2)).
- Virginia (VCDPA): 45 days, extendable by 45 days (§59.1-577(B)).
- Colorado (CPA), Connecticut (CTDPA), Utah (UCPA): 45 days.
- Canada (PIPEDA): 30 days.
- Australia (Privacy Act, APP 12): reasonable time — interpreted as 30 days.
Identity verification
For account-linked requests we send a verification link to the mailbox on your account. For account-less requests (a person who owns a license but never registered), verification is a license key plus the last four digits of the payment instrument used at purchase.
Erasure carve-out (HWID hash retention)
After account deletion we retain the SHA-256 HWID hash and the reason code for any active hard-tier ban, without any personal identifiers (no email, no name, no license key). Legal basis: GDPR Article 17(1)(e) and 17(3)(b) — legitimate interest in preventing evasion of anti-cheat / anti-tamper bans, balanced against the minimal residual data (a hash and a category label). This retention is time-limited under §5 (2 years post-expiry or overturn) and this disclosure satisfies the transparency requirement of Article 17(3)(b).
Data-subject request form
Submit an access, deletion, correction, portability, or objection request. We acknowledge within one business day and respond within the statutory window for your jurisdiction.
13Region-specific supplements
California CCPA / CPRA
- Categories collected in the last 12 months: Identifiers, Commercial Information, Internet Activity, coarse Geolocation (country/city from IP), no Inferences drawn for advertising.
- We do NOT sell or share personal information as defined by CPRA §1798.140(ah).
- Consumer rights: Know, Delete, Correct, Opt-out of Sale/Share (n/a), Limit Sensitive Use (n/a — no sensitive PI processed), Non-discrimination.
- Authorized-agent submissions accepted with written attestation.
- No financial incentives are offered in exchange for personal data.
Virginia VCDPA
- Consumer rights: Access, Correct, Delete, Portability, Opt-out of Sale (n/a), Opt-out of Targeted Advertising (n/a), Opt-out of Profiling with legal effects (n/a).
- Appeal process: response to an appeal within 60 days; unresolved appeals escalate to the Virginia Attorney General.
Colorado CPA
- Rights substantively equivalent to VCDPA (Access, Correction, Deletion, Portability, Opt-out of Sale, Targeted Advertising, and Profiling with legal effects).
- Universal Opt-Out Mechanism (UOOM) signals honoured for opt-outs that apply to us (currently none, because we do not sell, target, or profile).
Connecticut CTDPA
- Rights substantively equivalent to VCDPA. Appeals under §11(c) of the Act.
Utah UCPA
- Consumer rights: Access, Delete, Portability, Opt-out of Sale/Targeted Advertising.
- Utah does not provide a right of correction — for correction requests from Utah residents, we will process them under our general rectification policy as a courtesy.
Canada PIPEDA
- The 10 fair-information principles are satisfied by this policy read together with our accountability posture (§1 privacy contact).
- Right to withdraw consent at any time, except where a contract or law requires continued retention.
- Complaint escalation: Office of the Privacy Commissioner of Canada.
Australia Privacy Act 1988 (APPs 1-13)
- APP 5 notification is satisfied by this policy.
- APP 12 access, APP 13 correction — routed through the same DSAR workflow.
- APP 8 overseas disclosure — the sub-processors in §6 are the disclosed recipients.
- Complaint escalation: Office of the Australian Information Commissioner (OAIC).
Switzerland revFADP
- Rights of access, rectification, deletion, and objection are honoured on the same timeline as GDPR.
- FDPIC-approved SCCs are used for cross-border transfers.
Brazil LGPD
- Data-subject rights under Article 18 mirrored to the GDPR workflow.
- The ANPD is the escalation authority.
14Changes to this policy
- Material changes (expansion of collection, new sub-processor category, weakening of retention) — at least 30 days' advance notice by email to the address on file plus an in-panel banner.
- Immaterial changes (typos, clarifications, updated URLs) — a version bump plus a line in the changelog below.
- Historical versions of this policy are archived at
/privacy/versionsso a returning customer can diff.
15Contact
- Privacy questions: [email protected]
- DSAR self-service: /dsar
- Support (including ban appeals): [email protected]
- Postal address: available on request with any data-subject request.
16Changelog
- v1.0.0 — 2026-07-20 — Wave 5 addendum: expanded anti-tamper telemetry disclosure (system, network, and process-name blocks), added the explicit §2 spotlight, updated the retention table to cover the new denormalised ban columns, and published this document under a formal version number for the first time.