Skip to main content
Game status:: In development

Privacy Policy

Which personal data does HeusMt2 process, why and how? Our privacy policy on account data, cookies, retention periods and your rights under KVKK.

This English version is provided for information. If the two versions differ, the Turkish text prevails.

At HeusMt2 we care about your privacy. This policy explains in everyday language which personal data we process, for what purpose and how, when you sign up for HeusMt2 (heusmt2.com) or use the site. For the same information mapped to the articles of the law, see the KVKK Privacy Notice page: both texts are based on the same inventory.

1. What data do we collect?

  • Account information: username, email address, password (stored in the database only as an irreversible hash; plain text is never kept), the character deletion code and the time the account was created (used for the coupon age requirement).
  • Mobile phone, optional: you can leave the phone field empty on the sign-up form and your account will still be opened. If you provide it, it is used only for account recovery and security.
  • Technical data: the session ID; a hash of the IP address and request times, to limit misuse.
  • Server access and error logs: the web server logs every request, and these logs contain your raw (unhashed) IP address. The "hash" guarantee above applies to the rate-limiting records, not to the server logs. Details: KVKK Privacy Notice article 2.
  • Game login records: the game login records store the login and logout time, the raw IP address, the channel and the play time. It is used for account security and for investigating misuse.
  • In-game security records: item and character events, cheat detection, staff commands, character name changes and the last connection IP address. Details are in the KVKK notice.
  • Yang transaction ledger and guild storage movements: the character, amount, balance, transaction type and (for Yang movements) counterparty character are recorded; no IP address is included. Kept for the consistency of the game economy and for fraud investigation; separate from the event and security records above.
  • In-game chat logs: general, group (party), guild and shout messages are recorded together with the sending character and the time, as written (raw), before the profanity filter. Whispers (private messages) are never recorded. They are used to investigate fraud, harassment and complaints and as evidence for sanctions; only the authorised management team can access them, and they are kept for at most 90 days.
  • Shop transactions: if a purchase is made in the Item Shop (Nesne Market), on the web or in-game, the character name, the product and the time; for the in-game shop, also the IP address.
  • Coupon use: the coupon used, the time of use and the raw IP address. The use record protects single use; the IP field is emptied after 12 months.
  • Referral programme: the referral code, the link between the referring and the referred account, eligibility and reward status. The referrer is shown only total numbers.
  • Support correspondence: if you write to us, your email address and the content of your message.
  • Consent proof record: the moment the consents you ticked when signing up were given and the version of the texts you agreed to. The IP address is deliberately not written to this record.
  • Bot protection: a Cloudflare Turnstile check runs at sign-up and login; during this check your IP and browser information are passed to the provider doing the check.
  • Game data: character name, level, kingdom, guild and progress. So that guild membership can be tracked correctly, guild join/leave records are kept with the character as game data; the IP address in these records is deleted after 90 days. The level progression record is also kept with the character/account.
  • Browser storage: two keys are kept in your browser; one remembers that you closed the cookie notice, the other that you closed the language suggestion bar. They contain no personal data and are not sent to the server. In addition, two small preference cookies are used that remember your choice for the animated scene and the intro curtain on the home page; they contain no personal data and are not read on the server side (details in the Cookie Policy).

We do not collect data for advertising, profiling or behavioural tracking.

2. What is public?

When the server opens, your character name, level, kingdom, guild name, experience and in-game ranking statistics (boss, Metin, monster, dungeon, fish, chest, PvP and Guild Battle counters) are published publicly in the ranking and guild tables. Your account name, email, phone and IP information are never published under any circumstances. The game is not yet open to players; rankings are not published. If you do not want your character name to be visible, you can write to us or delete your account.

3. For what purposes do we process data?

  • To create and manage your free game account,
  • To keep your account and the server secure (preventing brute force, bots, cheating and fraud),
  • To run the game and enforce the balance and fair-play rules,
  • To investigate fraud, harassment and complaints in in-game chat and use chat logs as evidence for sanctions,
  • To verify referral and coupon conditions, process rewards and prevent reuse,
  • To answer support requests and contact you when necessary,
  • To fulfil our legal obligations.

Your personal data is processed on the legal grounds of the establishment/performance of a contract (the account agreement), legitimate interests (server and account security, in-game chat logs and cookieless visit statistics), legal obligation and, regarding the optional phone number and transfer abroad, your explicit consent. You can withdraw your consent at any time.

5. Who do we share data with?

Your personal data is not sold to third parties and not shared for marketing purposes. Sharing happens only in these three cases:

  • Cloudflare: attack and bot protection; traffic to the site passes through this provider's network. Without this protection we cannot provide the service securely.
  • Hosting provider: the infrastructure our servers run on.
  • Authorised public authorities: in case of a legal obligation, limited to the scope of the request.

These providers' infrastructure is abroad, and the transfer is not a possibility but an ongoing situation: every request to the site passes through the protection layer's network. The basis, the risk and the legal route we are aiming for are written in detail in KVKK Privacy Notice article 5.

6. Cookies and visit measurement

Our site uses strictly necessary cookies (session and security) and two small preference cookies that remember your motion and intro choices on the home page; there are no advertising or tracking cookies. We measure visit statistics in aggregate with cookieless Cloudflare Web Analytics; this method does not write cookies to your browser and does not identify you individually. For details, see our Cookie Policy page.

7. How long data is kept

  • Account and game data: as long as the account is open. A deletion request is processed within 30 days at the latest; the data is deleted or anonymised. Records that must be kept by law may be retained for the relevant period. Guild join/leave records are kept with the character; the IP address in these records is deleted after 90 days. Application steps.
  • Referral and coupon use records: until the account is deleted; the raw IP field in the coupon use record is emptied after 12 months at the latest, and the record remains.
  • Game login IP address: cleared after 12 months at the latest. For the retention period of the other fields in the login record, see the table in the KVKK notice.
  • In-game event and security records: 90 days; after that the record is deleted together with the IP it contains. The Yang transaction ledger, guild storage movements and guild join/leave records are not covered by this period (see their own items).
  • Yang transaction ledger (no IP): kept live for 12 months, then moved to a monthly archive; deleted, archive included, 2 years after the transaction date (within 1 month at the latest, because it is archived monthly).
  • Guild storage movements (no IP): deleted 2 years after the transaction date (not archived).
  • IP in character and shop records: cleared after 12 months at the latest.
  • In-game chat logs: at most 90 days.
  • Rate-limiting records: at most 1 hour.
  • Password reset records: the link is valid for 60 minutes; the record is kept for at most 7 days.
  • Server access/error logs (including raw IP): at most 90 days; the actual setting today is much shorter: 14 days.
  • Shop purchase records: 10 years from the transaction date, as proof of purchase; the IP is cleared after 12 months at the latest.
  • Consent proof record: as long as the account is open and, because of the burden of proof, for 3 years after the account is deleted.
  • Support requests and correspondence: deleted 1 year after the request is closed; if a legal dispute is ongoing, they may be kept until the dispute is resolved.
  • Sanction (ban) records: for as long as the sanction lasts and for 2 years after it ends.

Backups: records that are deleted or anonymised may remain in backup copies for some time. Backup copies are rotated regularly over roughly 14 days; if a backup run fails, the most recent sound copy may be kept longer for recovery.

For the full table, see KVKK Privacy Notice article 6.

8. Data security

Passwords are stored only as irreversible hashes, all site traffic is encrypted with HTTPS, the session cookie is protected with the HttpOnly and SameSite flags, forms have CSRF protection and rate limiting, the server is protected by firewall rules and database access rights are kept to a minimum.

9. In case of a data breach

If we learn that your personal data has been obtained unlawfully, we notify the Personal Data Protection Board of the incident within 72 hours at the latest. If we cannot notify within this period, we explain the reason for the delay to the Board together with the notification. We contact the affected users as soon as reasonably possible, as soon as we determine who is affected.

The notification we send to users always includes:

  • When the breach happened (and when we learned of it),
  • The affected categories of personal data (for example email address, login record),
  • The possible consequences of the breach, that is, what could be done against you with this data,
  • The measures we have taken and recommend taking,
  • Our contact details for more information (iletisim@heusmt2.com, §13 below).

We do not hide it.

10. Minors

The service is intended for people over 18, or those who join with the permission of a parent or legal guardian. If a parent/guardian who believes their child signed up without permission writes to us, the account and data concerned are deleted without delay.

11. Your rights (KVKK art. 11)

The account deletion steps are on the Account Deletion page.

Regarding your personal data, you have the right to learn whether it is processed, to request information, to know the third parties it is transferred to, to request its correction or deletion and to object to the processing. You can send your requests to the address below; they are answered free of charge within 30 days at the latest.

12. Changes

This policy may be updated from time to time. The current version is always published on this page and the date at the top is updated; substantial changes are announced.

13. Contact

For any question or request about privacy and personal data:
Email: iletisim@heusmt2.com
Support: our Support page

This English version is provided for information. If the two versions differ, the Turkish text prevails.