RSX-PRV-01

Privacy
policy.

What personal data the ID Portal, API, Webhooks, and AI Portal collect, the lawful basis for each use, who it is shared with, how long it is kept, and the rights you hold over it.

Effective
10 August 2026
Version
1.0
Applies to
All RSX users, developers, and visitors

01Who we are

1.1
RSX is a development brand operated from Silesia, Poland by a group of individuals working under the wider Whitehill Group banner, some of whom are based in the United Kingdom. Neither RSX nor Whitehill Group is an incorporated company.
1.2
Because there is no company to name, the controller of the personal data described in this policy is a natural person: paige@rsx.group, contactable at privacy@rsx.group. The other individuals who operate RSX process data under their direction.
1.3
Our main establishment is in Poland, so the EU GDPR applies to our processing. Where you are in the United Kingdom the UK GDPR also applies. Where the two differ, we apply whichever gives you more protection.
1.4
We have not appointed a Data Protection Officer, as we are not required to. Data protection matters are handled directly by privacy@rsx.group.

02What this policy covers

2.1
This policy covers personal data we process through the ID Portal, the API, Webhooks, the AI Portal, our websites, our documentation, our support channels, and the systems we operate on Roblox.
2.2
It does not cover:
  • applications built by other developers on the RSX Platform — they are separate controllers with their own notices, and section 6 explains the split;
  • Roblox itself, Discord, or any other third-party platform you use alongside ours — their own policies apply;
  • sites we link to.
2.3
Terms used here have the meanings given in the Terms of Service.

03What we collect

3.1
Account data — ID Portal. Collected when you register and while you hold an account: email address, username and display name, a hashed and salted password or an external authentication identifier, account status and roles, security settings including two-factor enrolment, and your preferences.
3.2
Linked account data. If you link a Roblox or Discord account, we store the platform’s user ID, the username and avatar reference at the time of linking, and the scopes you granted. We do not receive or store your password on those platforms.
3.3
Authentication and session data. Session and refresh token identifiers, issue and expiry times, sign-in and sign-out events, the IP address and user agent used, approximate location derived from IP at country level, and failed authentication attempts.
3.4
Developer and API data. Registered application details, hashed API keys and key metadata, and for each request: timestamp, endpoint, method, response status, latency, approximate payload size, rate-limit counters, IP address, and user agent. We do not retain full request or response bodies except where sampled for a specific investigation.
3.5
Webhook data. The endpoint URLs you register, signing secret metadata, and for each delivery: event type and ID, timestamp, response status, latency, and retry history. We log delivery outcomes rather than the full payload content, except where needed to diagnose a reported failure.
3.6
AI Portal data. The prompts and files you submit, the outputs generated, the model and settings used, token counts, timestamps, and the account or key that made the request. Abuse-detection signals derived from that traffic.
3.7
Technical and security data. Server and edge logs, request metadata processed by our infrastructure provider, bot and abuse detection signals, and records of enforcement action taken on an account.
3.8
Support and correspondence. Anything you send to our contact addresses, together with the address you sent it from and our replies.
3.9
We do not collect payment card details, government identity documents, biometrics, precise location, or special category data as defined by Article 9 GDPR. Do not send them to us — including through the AI Portal.

04Why we use it, and our lawful basis

4.1
We process personal data only for the purposes below, on the lawful bases stated.
PurposeData usedLawful basis
Creating and running your account, authenticating you, and providing the Services you ask forAccount, linked account, authenticationContract — Art. 6(1)(b)
Issuing and validating API keys, applying rate limits, and delivering webhooksDeveloper, API, webhookContract — Art. 6(1)(b)
Running AI Portal requests and returning output to youAI PortalContract — Art. 6(1)(b)
Keeping the platform secure: detecting abuse, credential stuffing, key leakage, fraud, and attacksAuthentication, API, technical, AI Portal signalsLegitimate interests — Art. 6(1)(f), in securing our systems and protecting users
Enforcing our terms, investigating reports, and preventing evasion of enforcementAccount, technical, enforcement recordsLegitimate interests — Art. 6(1)(f), in operating a safe platform
Diagnosing faults, monitoring capacity, and improving reliabilityAPI, webhook, technicalLegitimate interests — Art. 6(1)(f), in a working service
Answering your support requests and data rights requestsSupport, accountContract, and legal obligation — Art. 6(1)(b) and 6(1)(c)
Service notices: security alerts, breaking changes, terms updatesAccount contactContract, and legitimate interests — Art. 6(1)(b) and 6(1)(f)
Optional product updates or announcements by emailAccount contactConsent — Art. 6(1)(a), withdrawable at any time
Meeting legal obligations and responding to lawful requestsAs requiredLegal obligation — Art. 6(1)(c)
4.2
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask for that assessment, and you can object under section 11.
4.3
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
4.4
If we ever want to use your data for a new purpose that is not compatible with the above, we will tell you first and, where required, ask for consent.

05AI Portal

5.1
Inference runs on infrastructure we control. AI Portal requests are executed on RSX-operated systems and on our infrastructure provider’s managed inference platform. Prompt and output content is not sent to external model vendors such as commercial chatbot APIs.
5.2
We do not train on your content. Prompts, files, and outputs are not used to train, fine-tune, or evaluate any model, ours or anybody else’s.
5.3
Content is processed to produce your output, and separately to generate abuse-detection signals such as rate and content-policy flags. Staff access to prompt content is restricted to named personnel, permitted only to investigate a specific reported fault or abuse case, and logged.
5.4
Retention is set out in section 10. You can delete an AI Portal conversation from the portal at any time, which removes it from your history and schedules it for deletion from our systems.
5.5
Do not submit credentials, payment details, health or other special category data, or somebody else’s personal data that you have no lawful basis to process.
5.6
Output is generated automatically and can be wrong. Section 10 of the Terms of Service and section 7 of the Developer Terms set out your responsibilities before relying on it.

06Webhooks and developer applications

6.1
When you connect a third-party application to your RSX account, we send that developer the data covered by the scopes you approved. From that point they are an independent controller for what they hold, and their own privacy notice governs it.
6.2
The Developer Terms require developers to publish a privacy notice, request minimum scopes, secure what they receive, delete it when you disconnect, and notify us of incidents within 48 hours. We enforce those obligations, but we cannot control what a developer does with data once delivered.
6.3
To see or remove your connections, open the ID Portal and revoke the application. Revoking stops further delivery immediately and obliges the developer to delete what they hold. To confirm deletion, contact the developer directly; tell us at privacy@rsx.group if they do not comply.
6.4
Webhook deliveries go only to endpoints registered by the developer. We log the outcome of each delivery as described in clause 3.5.
6.5
Players who interact with an RSX system inside a Roblox experience do not hold RSX accounts. Where we process a Roblox user ID in that context, we do so on behalf of the experience operator and keep it only as long as the feature requires.

07Cookies and similar technologies

7.1
We use strictly necessary cookies and local storage only: your session token, cross-site request forgery protection, load balancing and bot-protection identifiers set by our infrastructure provider, and your interface preferences. These do not require consent because the Services cannot work without them.
7.2
We do not use advertising cookies, third-party trackers, social plug-ins, or cross-site analytics.
7.3
Where we measure traffic, we use aggregate, cookieless analytics that does not build a profile of you or track you across sites.
7.4
Blocking strictly necessary cookies in your browser will prevent sign-in from working.

08Who we share data with

8.1
We share personal data only with the categories of recipient below. We do not sell it.
RecipientRoleWhat they receive
CloudflareHosting, edge network, storage, managed inference, DDoS and bot protection, transactional email deliveryEffectively all traffic-borne data: request metadata, IP addresses, stored account and platform data, AI Portal content processed for inference, email address and message content for account, security, and service notices
Roblox, DiscordAccount linking, at your instructionOnly what the authorisation flow requires; we receive their identifiers, they receive no RSX data beyond the request itself
Other Whitehill Group membersThe wider group RSX operates within — shared administration, security, and support, including individuals in the United KingdomAccess on a need-to-know basis, under confidentiality obligations and the direction of the controller
Professional advisersLegal, accounting, insuranceOnly where necessary for a specific matter
Law enforcement, regulators, courtsLegal obligationOnly what a valid, specific, lawful request requires — see clause 8.3
8.2
Processors act only on our documented instructions under a contract meeting Article 28 GDPR, with confidentiality, security, sub-processor, and deletion obligations. We review them before engagement.
8.3
We respond to lawful requests from authorities, but we check that each request is valid, specific, and proportionate, disclose only what is required, and tell you unless legally prohibited from doing so.
8.4
If the operation of RSX passes to a different operator, or to an entity later formed to run it, data may transfer with it. We will notify you before that happens and before any change of purpose, and this policy continues to apply until you are told otherwise.
8.5
We will publish material changes to our processors on this page at least 30 days before they take effect, so you can object.

09International transfers

9.1
Our infrastructure is configured to process and store data in the European Economic Area and the United Kingdom wherever the service allows it.
9.2
Some of the individuals who operate RSX are based in the United Kingdom and access data from there. That transfer relies on the European Commission’s adequacy decision for the United Kingdom and, in the other direction, on the UK’s adequacy regulations for the EEA.
9.3
Where a processor operates a global network and data may be handled outside the EEA or UK, the transfer is covered by the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, plus encryption in transit and at rest and a transfer risk assessment.
9.4
You can request a copy of the transfer safeguards for a specific processor from privacy@rsx.group.

10How long we keep it

10.1
We keep personal data only as long as we need it for the purpose it was collected for.
DataRetentionThen
Account and profile dataFor the life of the accountDeleted within 30 days of account closure
Linked account recordsUntil you unlink, or the account closesDeleted within 30 days
Session and authentication recordsSession lifetimeDeleted on expiry or sign-out
Sign-in and security event history12 monthsDeleted
API request logs30 daysDeleted; aggregate, non-identifying counters may be kept
Webhook delivery logs14 daysDeleted
AI Portal prompts and outputs30 days, or until you delete the conversationDeleted
Abuse and content-policy flags12 monthsDeleted unless part of an open case
Support correspondence24 months from last contactDeleted
Enforcement records (suspensions, terminations)Retained while needed to prevent evasion, reviewed every 3 yearsReduced to the minimum identifier set
Records needed for a legal claim, obligation, or investigationAs long as the obligation or claim period lastsDeleted
10.2
Deletion means removal from live systems immediately and from encrypted backups within 90 days, as backups rotate. Data in a backup is not used for any purpose while it waits to be overwritten.
10.3
We keep a minimal record of terminated accounts — an identifier, the date, and the ground — because we cannot enforce clause 8.3 of the Terms of Service without it. This is a legitimate interest and you may object under section 11.

11Your rights

11.1
Under the EU and UK GDPR you have the right to:
  • Access — get a copy of the personal data we hold about you, and information about how we use it.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — have data deleted where we no longer have grounds to keep it.
  • Restriction — have processing paused while a dispute about accuracy or grounds is resolved.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Object — object to processing based on legitimate interests, including profiling, on grounds relating to your situation.
  • Withdraw consent — at any time, where we rely on consent. This does not affect processing already carried out.
  • Complain — to a supervisory authority, as set out in clause 16.3.
11.2
Exercise any of these by writing to privacy@rsx.group from the email address on your account, or through the ID Portal where the tool exists. Say which right you are exercising and which data it concerns.
11.3
We respond within one month. We may extend by up to two further months for complex requests, and will tell you within the first month if we do.
11.4
Requests are free. We may charge a reasonable administrative fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain why.
11.5
We may ask for information to confirm your identity, but only what is necessary and only where we genuinely cannot otherwise verify you. We will not create a new identity record from it, and we delete what you send once verification is complete.
11.6
Some rights are limited. We may keep data needed for a legal obligation, for the establishment or defence of a legal claim, or for the enforcement records in clause 10.3. Where we refuse a request, we will tell you the reason and how to challenge it.

12How we protect data

12.1
Technical measures: TLS for all traffic; encryption at rest for stored data; passwords stored using a modern memory-hard hashing algorithm with per-user salts; API keys stored only as hashes; signed and expiring session tokens; signed webhook payloads; network-level DDoS and bot protection.
12.2
Organisational measures: access on a least-privilege basis, granted per role and reviewed periodically; multi-factor authentication required for administrative access; audit logging of administrative actions; separation of production from development data; supplier review before engaging a processor.
12.3
No system is completely secure. You play a part too — use a unique password, enable two-factor authentication, and keep API keys off client devices.
12.4
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify our supervisory authority within 72 hours of becoming aware, and we will notify you without undue delay where the risk is high. Our notice will say what happened, what data was affected, what we have done, and what you should do.
12.5
Report a suspected vulnerability or breach to security@rsx.group. Section 12 of the Developer Terms sets out our disclosure terms.

13Age and minors

13.1
RSX accounts are for people aged 16 or over. The platform is a developer tool and is not directed at children.
13.2
We do not knowingly collect personal data from anyone under 16 in connection with an RSX account. If we learn that an account holder is under 16, we will terminate the account and delete the data, other than the minimal record needed to prevent re-registration.
13.3
If you believe someone under 16 holds an account, tell us at privacy@rsx.group and we will investigate promptly.
13.4
Players in a Roblox experience may be under 16. We do not collect account data from them. Where an RSX system inside an experience processes a Roblox user ID, we do so on behalf of the experience operator, for the shortest period the feature requires, and we do not use it to build a profile.

14Automated decisions

14.1
We use automated systems to detect abuse: rate-limit breaches, credential stuffing, leaked keys, spam patterns, and AI Portal content-policy violations. These systems can automatically throttle traffic, revoke a key, or restrict an account.
14.2
Automated action is limited to what is needed to stop immediate harm. A permanent termination is reviewed by a person before it is final, except where clause 8.3 of the Terms of Service applies and the evidence is unambiguous.
14.3
Where a decision that significantly affects you is made by automated means, you have the right to be told, to obtain human review, to express your view, and to contest it. Use appeals@rsx.group.
14.4
We do not use automated decision-making for profiling unrelated to security and enforcement, and we do not use it for marketing.

15Changes to this policy

15.1
We update this policy when our practices, our processors, or the law change.
15.2
For changes that materially affect how we use your data, we will give at least 30 days’ notice by email or in the ID Portal before they take effect. Where a change requires consent, we will ask for it rather than assume it.
15.3
Corrections and clarifications take effect when published. The version and effective date at the top of this page always reflect the current text.
15.4
Previous versions are available on request from privacy@rsx.group.

16Contact

16.1
RSX is an unincorporated group operating from Silesia, Poland, under the Whitehill Group banner. Controller: paige@rsx.group.
16.2
Privacy and data rights requests: privacy@rsx.group. Security: security@rsx.group. Everything else: legal@rsx.group.