1. Controller
Virexon Labs, represented by Raphael G., Daxlanderstrasse 21, 76185 Karlsruhe, Germany. Contact: support@virexonlabs.com. Full provider information is available in the imprint.
Virexon LabsSoftware + game studioThis policy covers the Virexon Labs website, Virexon Guardian, its Discord bot, associated web panels and internal marketing integrations.
Last updated: September 13, 2026Virexon Labs, represented by Raphael G., Daxlanderstrasse 21, 76185 Karlsruhe, Germany. Contact: support@virexonlabs.com. Full provider information is available in the imprint.
The public Virexon Labs and Guardian websites offer optional first-party analytics. It remains disabled until you actively consent. If enabled, we measure page visits and selected calls to action with random visitor and session identifiers. We do not record names, email addresses, Discord IDs, form contents, URL query parameters, referrers or browser fingerprints for analytics, and we do not load third-party advertising trackers. Hosting may still create technically necessary security logs such as IP address, timestamp, requested URL, response status and user agent.
If you contact us, we process the information you provide to answer your request and perform necessary follow-up. Email is operated through our own Mailcow installation; delivery still involves the mail servers used by the sender and recipient.
When you sign in to the Guardian panel through Discord, we process the Discord account and authorization data needed for authentication and access control. This can include user ID, username, avatar, visible servers, ownership and permission flags, a server-side session, a necessary session cookie and CSRF protection values.
To provide enabled bot and panel functions, we process server IDs and names, channels, roles, members, configuration, moderation records, warnings, verification data, ticket content and transcripts, logs, reminders, level and Orchard economy progress, Zoo state, applications, backups and administrator-provided assets. The exact data depends on the modules selected by the server administrator.
For optional Daily Meme and Cute Pics features, Guardian stores configuration and limited delivery status to prevent duplicate posts. Search terms answer the current request and are not stored in application history. Provider requests are sent by Guardian's server without adding a Discord user ID, username or server ID. Retrieved images are re-encoded and uploaded to Discord.
The private Virexon Hub can connect the Virexon Labs TikTok account through TikTok Login Kit. With the account holder's authorization, we process the TikTok account identifier, display name, avatar, granted scopes, encrypted access and refresh tokens, and public video information such as video ID, title or description, publication time, duration, cover image, views, likes, comments and shares. The data is used only for Virexon Labs' internal campaign reporting. The integration does not publish, edit or delete TikTok content. Access and refresh tokens are encrypted at rest and are never exposed to the browser after authorization. Disconnecting the account in the Hub revokes TikTok access and removes the stored connection. Public YouTube video metadata and statistics may be retrieved through the YouTube Data API for the same internal reporting purpose; no YouTube user account is connected.
For paid services we process information required to activate and manage access, including the linked server, plan, billing cycle, Stripe customer references, payment or subscription status, invoice references, webhook events and limited billing contact details. Payment card data is handled by Stripe and is not stored by Virexon Labs.
The websites store your language and privacy choice as necessary preferences. Optional analytics storage is created only after consent: a random visitor identifier for up to 180 days, a session identifier for the current page session, and Guardian campaign attribution for up to 7 days where present. Analytics events contain the site, page path without query parameters, time, consent version and, for selected buttons, a fixed action name. Withdrawing consent through Privacy settings removes the browser analytics identifier and stops future analytics. The Guardian panel and private Virexon Hub use necessary session and security storage for login, authenticated requests and protected OAuth state.
Optional website analytics is based on your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can refuse it without disadvantage and withdraw it at any time. Other processing supports contract performance and requested services under Art. 6(1)(b) GDPR, legitimate interests in reliable operation, security and abuse prevention under Art. 6(1)(f) GDPR, and legal duties such as accounting under Art. 6(1)(c) GDPR. TikTok account access is additionally based on the authorization actively granted through Login Kit and can be revoked at any time.
Relevant providers include Discord for bot interactions and OAuth, Stripe for payments, Pexels (Canva Germany GmbH) for optional licensed images, TikTok for Login Kit and authorized Display API requests, and Google for public YouTube Data API requests. Infrastructure data is processed on systems used by Virexon Labs. Data is disclosed only where needed to provide the service, comply with law or protect the service. TikTok Privacy Policy: https://www.tiktok.com/legal/page/eea/privacy-policy/en. Google Privacy Policy: https://policies.google.com/privacy.
Individual public website analytics events and their random identifiers are deleted after 90 days. The browser keeps the consent choice and, after approval, its random visitor identifier for up to 180 days. Aggregated totals without visitor identifiers may be retained for business reporting. Website security logs are retained only as long as operationally necessary. Sessions expire automatically. Guardian data is retained while needed for configured features, security history, backups, support or abuse handling. Billing records may be retained longer for accounting, fraud prevention and legal compliance.
You can change or withdraw analytics consent at any time through Privacy settings in the footer of every public website page. Withdrawal stops future analytics and removes the browser analytics identifier; it does not affect processing already carried out with valid consent. Depending on applicable law, you may also request access, rectification, erasure, restriction, objection or data portability and lodge a complaint with a supervisory authority. Requests must contain enough information for safe verification. Contact support@virexonlabs.com.
We may update this policy when products, providers, security practices or legal requirements change. The current version is always published on this page.