
KVKK Privacy Notice
The HeusMt2 privacy notice under KVKK (Law No. 6698): data categories processed, purposes, legal grounds, transfers and the rights of the data subject.
This English version is provided for information. If the two versions differ, the Turkish text prevails.
Last updated: October 4, 2026 · Under Law No. 6698 on the Protection of Personal Data
This privacy notice has been prepared under Law No. 6698 on the Protection of Personal Data (KVKK) to inform you about how your personal data is processed by HeusMt2 (heusmt2.com) in its capacity as data controller. For more detailed explanations of the practice, you can see our Privacy Policy page.
1. Data controller
Data controller: HeusMt2. HeusMt2 is a community-based Metin2 game server project run by an independent team. Contact and notification address: iletisim@heusmt2.com.
2. Categories of personal data processed
The list below has been prepared according to the fields the system actually records.
- Identity/account: username (nickname), interface language preference and the
account creation time (
create_time; used for the coupon age requirement). - Contact: email address. The mobile phone number is optional: you can leave it empty on the sign-up form and your account will still be opened.
- Authentication: the password (stored in the database only as an irreversible hash; plain text is not kept anywhere) and the character deletion code.
- Transaction security: the session identifier (
PHPSESSIDsession cookie; deleted when you close your browser, details in the Cookie Policy); a hash of the IP address and request timestamps, to limit misuse. - Server access and error logs: the web server logs every request; these logs contain the request time, the requested address, the browser identifier and your raw (unhashed) IP address. We state this openly because the "hash" guarantee above applies to the rate-limiting records, not to the server logs: investigating an attack or a fault is not possible without the IP. The retention period is in §6.
- Game login records: the game login/logout time, play time, channel and raw IP address are recorded in the game database's login records. They are used for account security and for investigating misuse; this is different from the rate-limiting IP hash above.
- In-game security records: item and character actions, cheat detection, character name changes, the last connection IP address and staff commands; the relevant records may contain character/account information and the raw IP.
- In-game chat logs: general chat, group (party) chat, guild chat and shout messages are recorded: the text of the message, the sending character, the time it was sent, the chat type, the kingdom, group or guild the message went to, the channel and the map. The text is stored as written (raw), before the profanity filter is applied; even if the filter hides a word with asterisks, the record keeps it as written. Whispers (private messages) are never recorded. These records are used to investigate fraud, harassment and complaints and as evidence for sanctions; only the authorised management team can access them. The retention period is in §6.
- Bot check: during sign-up/login, a Cloudflare Turnstile check runs to confirm
that you are human; during this check your IP address and browser information are passed to the
provider doing the check. The check frame keeps a localStorage key named
cf.turnstile.uin Cloudflare's own domain; heusmt2.com's code does not write this key and cannot read it. - Visit statistics: page visits are measured in aggregate with Cloudflare Web Analytics, which does not use cookies; this method does not write cookies to your browser and does not identify you individually (details in the Cookie Policy).
- Game data: character name, level, kingdom, guild and in-game progress information. So that guild membership can be tracked correctly, guild join/leave records are kept with the character as game data; the IP address in these records is deleted after 90 days. The level progression record is also kept with the character/account as in-game progress data.
- Yang transaction ledger and guild storage movements: the character, amount, balance, transaction type and (for Yang movements) counterparty character are recorded; no IP address is included. It is used for the consistency of the game economy and for fraud investigation; it is kept separate from the event and security records above and has its own periods (§6).
- Shop transactions: if a purchase is made in the Item Shop (Nesne Market), on the website or in the game, the character name, the product bought and the transaction time are recorded; for the in-game shop, the IP address is also recorded. This record serves as proof of purchase and for investigating misuse.
- Coupon use: the record of the coupon used, the time of use and the raw IP address. It is kept to prevent reuse of the same coupon and misuse.
- Referral programme: the referral code, the identity of the account that referred you, eligibility and reward status. The referrer is not shown your account identity; only total numbers are shown.
- Consent proof record: the moment the consents you ticked when signing up were given and the version of the texts you agreed to are stored. The IP address is deliberately not written to this record.
- Data published publicly: when the server opens, the character name, level, kingdom, guild name, experience and in-game ranking statistics (boss, Metin, monster, dungeon, fish, chest, PvP and Guild Battle counters) are published publicly in the ranking tables (your account name, email and phone are never published). While the game is closed to players, rankings are not published. If you do not want them published, we recommend that you delete your account or write to us.
- Support correspondence: if you write to us by email, the content of the correspondence and your email address.
- Browser storage: a key (
hm_cookie_ack, localStorage) that remembers that you closed the cookie notice is kept in your browser. It contains no personal data and is not sent to the server. A second key (h2_dil_oneri_kapali, localStorage) that remembers that you closed the language suggestion bar is also kept; it too contains no personal data and is not sent to the server. In addition, two preference cookies are used:h2_hareket, which remembers that you stopped the animated scene on the home page or chose to turn it on while data saving is on, andh2_intro, which remembers that you have seen the intro curtain once. Both are written by the script on the page and are deleted after 365 days; they contain no personal data and are not read on the server side (details in the Cookie Policy).
We do not collect data for advertising, profiling or behavioural tracking; in-game chat logs are not used for marketing purposes.
3. Purposes of processing personal data
- Creating, verifying and managing the game account,
- Ensuring server and account security, preventing and detecting misuse (bots, brute force, fraud, cheating),
- Running the game and enforcing the balance and fair-play rules,
- Investigating fraud, harassment and complaints in in-game chat and using chat logs as evidence for sanctions,
- Running the referral programme, checking reward conditions and preventing misuse in coupon use,
- Publishing the ranking and guild tables when the server opens,
- Measuring site visit statistics without cookies and in aggregate,
- Handling support and contact requests,
- Fulfilling legal obligations and defending against legal claims.
4. Legal grounds for processing (KVKK art. 5)
- art. 5/2-c, establishment or performance of a contract: username, password hash, email, character deletion code, game data, the referral relationship, reward status and coupon use.
- art. 5/2-f, legitimate interests: security records, the IP hash, rate limiting, the bot check, game login and coupon use IP records, in-game security records, cheat detection, cookieless visit statistics (Cloudflare Web Analytics) and in-game chat logs.
- art. 5/2-ç, legal obligation: meeting the requests of competent authorities.
- art. 5/1, explicit consent: the mobile phone number you provide optionally. You can withdraw your consent at any time.
- Transfer abroad (§5): the basis we are aiming for is the art. 9 appropriate safeguards route; until that process is complete, your explicit consent is also taken into account on a temporary basis. Details, and the reason for this distinction, are in §5.
5. Transfer of personal data and transfer abroad (KVKK art. 8-9)
Your personal data is not transferred to third parties for marketing purposes and is not sold. Transfers take place only in the cases below and to the minimum extent necessary:
- Cloudflare (a cloud infrastructure and security provider based abroad): traffic to the site passes through this provider's network for attack and bot protection; cookieless visit statistics (Cloudflare Web Analytics) are also measured by this provider; during this, your IP address and browser information are processed. Without this protection it is not possible for us to provide the service securely.
- Hosting infrastructure provider: the site and game servers run in the data centres of the provider we buy hosting from.
- Competent public institutions and organisations: in case of a legal obligation, limited to the basis and scope of the request.
Transfer abroad, stated openly: the infrastructure of the providers above is abroad. This is not a possibility but an ongoing situation: every request to the site passes through the protection layer's network. So we are not saying "it may happen now and then"; it happens all the time.
KVKK art. 9, as amended by Law No. 7499, sets up a three-tier system for transfer abroad: (1) countries for which the Board has issued an adequacy decision, (2) failing that, appropriate safeguards (standard contract, written undertaking, binding corporate rules), (3) failing those, exceptions such as explicit consent, only in incidental cases.
Our situation is as follows, and we report it as it is: as of today, the standard contract/written undertaking process on route (2) that we are aiming for with the providers we use has not yet been completed. This means that a solid basis as envisaged by art. 9 is currently missing; we do not hide this. Until the process is complete, the explicit consent you separately ticked during sign-up is also recorded as an indicator, but we state openly that this does not fully meet the ongoing nature of the transfer within the meaning of art. 9: the article treats explicit consent as an exception only for incidental transfers. The goal is (2); once the standard contract/written undertaking is signed and notified to the Authority, this text will be updated and the basis moved there.
⚠️ For accounts opened before 5 September 2026, this separate consent HAS NOT YET BEEN OBTAINED. Until that date, the transfer consent on the sign-up form was inside the same box as the other declarations; since it was not obtained as a separate consent, we do not count it as one. Separate consent from these accounts will be requested in the login flow before the server opens to everyone. The game is not yet open to players; all of these accounts belong to our team and our test users.
The risk you should know before consenting (KVKK art. 9): the country where the data is processed may not offer the same level of protection as Turkey; in case of a problem, the ways of seeking your rights may work differently and may be more cumbersome. The data transferred is limited to what is needed to provide the service technically (IP address, browser information, account and game data) and is not transferred for marketing purposes and is not sold.
You can withdraw your consent. You do this by writing to iletisim@heusmt2.com. But let us be honest: without this protection and hosting layer we cannot technically provide the service: withdrawing consent means closing the account. This is a situation that does not make the consent "truly free", and that is exactly why we are aiming for route (2) above.
6. Retention periods
| Data | Period |
|---|---|
| Account information (username, email, phone, password hash, deletion code, creation time) | As long as the account is open. A deletion request is processed within 30 days at the latest; account information is deleted or anonymised. Records that must be kept by law may be retained for the relevant period. |
| Game data (character, level, guild, progress) | Together with the account. Guild join/leave records are kept with the character; the IP address in these records is deleted after 90 days. The level progression record is included. In case of a reset (wipe), it may be deleted earlier. |
| Referral code, referral relationship and reward status | Until the account is deleted. A deletion request also requires the referral record to be removed; the implementation in the current account deletion flow has not yet been verified. |
| Coupon use (coupon, time, raw IP) | The use row that prevents reuse remains until the account is deleted; the raw IP field is set to NULL after 12 months at the latest. |
| Game login records (login/logout time, play time, channel, raw IP) | The raw IP kept for account security is cleared by the jail maintenance task after 12 months at the latest. The other fields are subject to the account deletion procedure. |
| In-game event and security records (item and character actions, cheat detection, staff commands, character name changes) | 90 days; after that the record is deleted together with the raw IP it contains. The Yang transaction ledger, guild storage movements and guild join/leave records are not covered by this row; see their own rows. |
| Yang transaction ledger (character, amount, balance, transaction type, counterparty character; no IP) | Kept live for 12 months, then moved to a monthly archive; deleted, archive included, 2 years after the transaction date (within 1 month at the latest, because it is archived monthly). |
| Guild storage movements (guild, character, amount, storage balance, transaction type; no IP) | Deleted 2 years after the transaction date (not archived). |
| Raw IP in character and shop records | The IP field is cleared after 12 months at the latest. |
| In-game chat logs (general, group, guild and shout; whispers are not recorded) | At most 90 days; then deleted. |
| Rate-limiting records (IP hash + timestamp) | As long as the counter window: at most 1 hour; after that it becomes meaningless and is cleared. |
| Password reset records (username, link hash, IP hash, timestamps) | The link is valid for 60 minutes; the record is kept for at most 7 days for investigating misuse, then deleted. The link itself is not stored; only its irreversible hash is kept. |
| Server access and error logs (including raw IP) | At most 90 days; if a security incident investigation is ongoing, until the investigation ends. The actual setting today is much shorter: web server logs rotate after 14 days. |
| Game server logs | The game engine keeps logs in local directories for a short time; the syslog and syserr logs are additionally archived on the host for 30 days. The raw IP fields of database records containing IPs are cleared after 12 months at the latest. This period is separate from the web server access log. |
| Shop purchase records (character name, product, time; for the in-game shop, also the IP) | Kept as proof of purchase for 10 years from the transaction date, then deleted; the IP in the in-game shop record is cleared after 12 months at the latest. |
| Consent proof record (username, consent time, text version) | As long as the account is open and, because of the burden of proof under KVKK, for 3 years after the account is deleted; then deleted. |
| Support requests and correspondence | Deleted 1 year after the request is closed. If there is a legal dispute, they are kept until the dispute is resolved. |
| Sanction (ban) records | Kept for as long as the sanction lasts and for 2 years after it ends; then deleted. |
If there is a legal retention obligation, the period set by that legislation applies.
Backups: records that are deleted or anonymised may remain in backup copies for some time. Backup copies are rotated regularly over roughly 14 days; if a backup run fails, the most recent sound copy may be kept longer for recovery.
7. How personal data is collected
Personal data is collected entirely electronically, through information provided by you via the sign-up form and support correspondence, and through automatic technical records arising from use of the site and the game (session, IP hash, security records).
8. Automated decisions and profiling
No decision with legal effect is taken about you by fully automated systems. Automated signals may be used in bot and cheat detection; however, sanctions such as closing an account are applied after human review, and you can appeal (see the Terms of Use, article 8).
Eligibility for the referral reward is checked automatically using account age, character level and total play time. This check is not a decision with legal effect such as closing an account.
9. Minors
The service is intended for users over 18, or users who join with the permission of a parent or legal guardian. We do not knowingly collect data from minors without guardian permission. If a parent/guardian who believes their child signed up without permission writes to us, the account and data concerned are deleted without delay.
10. Data security measures
- Passwords are stored only as irreversible hashes.
- All site traffic is encrypted with HTTPS; the session cookie is protected with the
HttpOnlyandSameSiteflags. - Forms have CSRF protection; login and sign-up have rate limiting and a bot check.
- Database access rights are kept to a minimum; management interfaces are restricted.
11. Your rights as the data subject (KVKK art. 11)
Under article 11 of KVKK, you have the right to learn whether your personal data is processed; if it has been processed, to request information about it; to learn the purpose of processing and whether it is used in line with that purpose; to know the third parties in Turkey or abroad to whom it is transferred; to request its correction if it was processed incompletely or incorrectly, and its deletion/destruction when the conditions are met; to request that these actions be notified to the third parties to whom the data was transferred; to object to a result against you arising from the analysis of the processed data exclusively by automated systems; and to request compensation if you suffer damage because of unlawful processing.
12. How to apply
For the steps of an account deletion request, see the Account Deletion page.
You can send your requests regarding the rights above to the email address below, together with information that allows us to identify you. Your request is concluded free of charge as soon as possible depending on its nature, and within 30 days at the latest. If we reject your request, if you find our answer insufficient or if no answer is given in time, you retain the right to file a complaint with the Personal Data Protection Board.
Email: iletisim@heusmt2.com
13. Changes
This text may be updated; the current version is always published on this page and the date at the top is updated. Substantial changes are announced on the site and in the community channels.
This English version is provided for information. If the two versions differ, the Turkish text prevails.