RSX-PRV-01
Privacy
policy.
What personal data the ID Portal, API, Webhooks, and AI Portal collect, the lawful basis for each use, who it is shared with, how long it is kept, and the rights you hold over it.
- Effective
- 10 August 2026
- Version
- 1.0
- Applies to
- All RSX users, developers, and visitors
01Who we are
1.1
RSX is a development brand operated from Silesia, Poland by a group of individuals working under the wider Whitehill Group banner, some of whom are based in the United Kingdom. Neither RSX nor Whitehill Group is an incorporated company.
1.2
Because there is no company to name, the controller of the personal data described in this policy is a natural person: paige@rsx.group, contactable at privacy@rsx.group. The other individuals who operate RSX process data under their direction.
1.3
Our main establishment is in Poland, so the EU GDPR applies to our processing. Where you are in the United Kingdom the UK GDPR also applies. Where the two differ, we apply whichever gives you more protection.
1.4
We have not appointed a Data Protection Officer, as we are not required to. Data protection matters are handled directly by privacy@rsx.group.
02What this policy covers
2.1
This policy covers personal data we process through the ID Portal, the API, Webhooks, the AI Portal, our websites, our documentation, our support channels, and the systems we operate on Roblox.
2.2
It does not cover:
- —applications built by other developers on the RSX Platform — they are separate controllers with their own notices, and section 6 explains the split;
- —Roblox itself, Discord, or any other third-party platform you use alongside ours — their own policies apply;
- —sites we link to.
2.3
Terms used here have the meanings given in the Terms of Service.
03What we collect
3.1
Account data — ID Portal. Collected when you register and while you hold an account: email address, username and display name, a hashed and salted password or an external authentication identifier, account status and roles, security settings including two-factor enrolment, and your preferences.
3.2
Linked account data. If you link a Roblox or Discord account, we store the platform’s user ID, the username and avatar reference at the time of linking, and the scopes you granted. We do not receive or store your password on those platforms.
3.3
Authentication and session data. Session and refresh token identifiers, issue and expiry times, sign-in and sign-out events, the IP address and user agent used, approximate location derived from IP at country level, and failed authentication attempts.
3.4
Developer and API data. Registered application details, hashed API keys and key metadata, and for each request: timestamp, endpoint, method, response status, latency, approximate payload size, rate-limit counters, IP address, and user agent. We do not retain full request or response bodies except where sampled for a specific investigation.
3.5
Webhook data. The endpoint URLs you register, signing secret metadata, and for each delivery: event type and ID, timestamp, response status, latency, and retry history. We log delivery outcomes rather than the full payload content, except where needed to diagnose a reported failure.
3.6
AI Portal data. The prompts and files you submit, the outputs generated, the model and settings used, token counts, timestamps, and the account or key that made the request. Abuse-detection signals derived from that traffic.
3.7
Technical and security data. Server and edge logs, request metadata processed by our infrastructure provider, bot and abuse detection signals, and records of enforcement action taken on an account.
3.8
Support and correspondence. Anything you send to our contact addresses, together with the address you sent it from and our replies.
3.9
We do not collect payment card details, government identity documents, biometrics, precise location, or special category data as defined by Article 9 GDPR. Do not send them to us — including through the AI Portal.
04Why we use it, and our lawful basis
4.1
We process personal data only for the purposes below, on the lawful bases stated.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account, authenticating you, and providing the Services you ask for | Account, linked account, authentication | Contract — Art. 6(1)(b) |
| Issuing and validating API keys, applying rate limits, and delivering webhooks | Developer, API, webhook | Contract — Art. 6(1)(b) |
| Running AI Portal requests and returning output to you | AI Portal | Contract — Art. 6(1)(b) |
| Keeping the platform secure: detecting abuse, credential stuffing, key leakage, fraud, and attacks | Authentication, API, technical, AI Portal signals | Legitimate interests — Art. 6(1)(f), in securing our systems and protecting users |
| Enforcing our terms, investigating reports, and preventing evasion of enforcement | Account, technical, enforcement records | Legitimate interests — Art. 6(1)(f), in operating a safe platform |
| Diagnosing faults, monitoring capacity, and improving reliability | API, webhook, technical | Legitimate interests — Art. 6(1)(f), in a working service |
| Answering your support requests and data rights requests | Support, account | Contract, and legal obligation — Art. 6(1)(b) and 6(1)(c) |
| Service notices: security alerts, breaking changes, terms updates | Account contact | Contract, and legitimate interests — Art. 6(1)(b) and 6(1)(f) |
| Optional product updates or announcements by email | Account contact | Consent — Art. 6(1)(a), withdrawable at any time |
| Meeting legal obligations and responding to lawful requests | As required | Legal obligation — Art. 6(1)(c) |
4.2
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask for that assessment, and you can object under section 11.
4.3
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
4.4
If we ever want to use your data for a new purpose that is not compatible with the above, we will tell you first and, where required, ask for consent.
05AI Portal
5.1
Inference runs on infrastructure we control. AI Portal requests are executed on RSX-operated systems and on our infrastructure provider’s managed inference platform. Prompt and output content is not sent to external model vendors such as commercial chatbot APIs.
5.2
We do not train on your content. Prompts, files, and outputs are not used to train, fine-tune, or evaluate any model, ours or anybody else’s.
5.3
Content is processed to produce your output, and separately to generate abuse-detection signals such as rate and content-policy flags. Staff access to prompt content is restricted to named personnel, permitted only to investigate a specific reported fault or abuse case, and logged.
5.4
Retention is set out in section 10. You can delete an AI Portal conversation from the portal at any time, which removes it from your history and schedules it for deletion from our systems.
5.5
Do not submit credentials, payment details, health or other special category data, or somebody else’s personal data that you have no lawful basis to process.
5.6
Output is generated automatically and can be wrong. Section 10 of the Terms of Service and section 7 of the Developer Terms set out your responsibilities before relying on it.
06Webhooks and developer applications
6.1
When you connect a third-party application to your RSX account, we send that developer the data covered by the scopes you approved. From that point they are an independent controller for what they hold, and their own privacy notice governs it.
6.2
The Developer Terms require developers to publish a privacy notice, request minimum scopes, secure what they receive, delete it when you disconnect, and notify us of incidents within 48 hours. We enforce those obligations, but we cannot control what a developer does with data once delivered.
6.3
To see or remove your connections, open the ID Portal and revoke the application. Revoking stops further delivery immediately and obliges the developer to delete what they hold. To confirm deletion, contact the developer directly; tell us at privacy@rsx.group if they do not comply.
6.4
Webhook deliveries go only to endpoints registered by the developer. We log the outcome of each delivery as described in clause 3.5.
6.5
Players who interact with an RSX system inside a Roblox experience do not hold RSX accounts. Where we process a Roblox user ID in that context, we do so on behalf of the experience operator and keep it only as long as the feature requires.
09International transfers
9.1
Our infrastructure is configured to process and store data in the European Economic Area and the United Kingdom wherever the service allows it.
9.2
Some of the individuals who operate RSX are based in the United Kingdom and access data from there. That transfer relies on the European Commission’s adequacy decision for the United Kingdom and, in the other direction, on the UK’s adequacy regulations for the EEA.
9.3
Where a processor operates a global network and data may be handled outside the EEA or UK, the transfer is covered by the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, plus encryption in transit and at rest and a transfer risk assessment.
9.4
You can request a copy of the transfer safeguards for a specific processor from privacy@rsx.group.
10How long we keep it
10.1
We keep personal data only as long as we need it for the purpose it was collected for.
| Data | Retention | Then |
|---|---|---|
| Account and profile data | For the life of the account | Deleted within 30 days of account closure |
| Linked account records | Until you unlink, or the account closes | Deleted within 30 days |
| Session and authentication records | Session lifetime | Deleted on expiry or sign-out |
| Sign-in and security event history | 12 months | Deleted |
| API request logs | 30 days | Deleted; aggregate, non-identifying counters may be kept |
| Webhook delivery logs | 14 days | Deleted |
| AI Portal prompts and outputs | 30 days, or until you delete the conversation | Deleted |
| Abuse and content-policy flags | 12 months | Deleted unless part of an open case |
| Support correspondence | 24 months from last contact | Deleted |
| Enforcement records (suspensions, terminations) | Retained while needed to prevent evasion, reviewed every 3 years | Reduced to the minimum identifier set |
| Records needed for a legal claim, obligation, or investigation | As long as the obligation or claim period lasts | Deleted |
10.2
Deletion means removal from live systems immediately and from encrypted backups within 90 days, as backups rotate. Data in a backup is not used for any purpose while it waits to be overwritten.
10.3
We keep a minimal record of terminated accounts — an identifier, the date, and the ground — because we cannot enforce clause 8.3 of the Terms of Service without it. This is a legitimate interest and you may object under section 11.
11Your rights
11.1
Under the EU and UK GDPR you have the right to:
- —Access — get a copy of the personal data we hold about you, and information about how we use it.
- —Rectification — have inaccurate data corrected and incomplete data completed.
- —Erasure — have data deleted where we no longer have grounds to keep it.
- —Restriction — have processing paused while a dispute about accuracy or grounds is resolved.
- —Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- —Object — object to processing based on legitimate interests, including profiling, on grounds relating to your situation.
- —Withdraw consent — at any time, where we rely on consent. This does not affect processing already carried out.
- —Complain — to a supervisory authority, as set out in clause 16.3.
11.2
Exercise any of these by writing to privacy@rsx.group from the email address on your account, or through the ID Portal where the tool exists. Say which right you are exercising and which data it concerns.
11.3
We respond within one month. We may extend by up to two further months for complex requests, and will tell you within the first month if we do.
11.4
Requests are free. We may charge a reasonable administrative fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain why.
11.5
We may ask for information to confirm your identity, but only what is necessary and only where we genuinely cannot otherwise verify you. We will not create a new identity record from it, and we delete what you send once verification is complete.
11.6
Some rights are limited. We may keep data needed for a legal obligation, for the establishment or defence of a legal claim, or for the enforcement records in clause 10.3. Where we refuse a request, we will tell you the reason and how to challenge it.
12How we protect data
12.1
Technical measures: TLS for all traffic; encryption at rest for stored data; passwords stored using a modern memory-hard hashing algorithm with per-user salts; API keys stored only as hashes; signed and expiring session tokens; signed webhook payloads; network-level DDoS and bot protection.
12.2
Organisational measures: access on a least-privilege basis, granted per role and reviewed periodically; multi-factor authentication required for administrative access; audit logging of administrative actions; separation of production from development data; supplier review before engaging a processor.
12.3
No system is completely secure. You play a part too — use a unique password, enable two-factor authentication, and keep API keys off client devices.
12.4
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify our supervisory authority within 72 hours of becoming aware, and we will notify you without undue delay where the risk is high. Our notice will say what happened, what data was affected, what we have done, and what you should do.
12.5
Report a suspected vulnerability or breach to security@rsx.group. Section 12 of the Developer Terms sets out our disclosure terms.
13Age and minors
13.1
RSX accounts are for people aged 16 or over. The platform is a developer tool and is not directed at children.
13.2
We do not knowingly collect personal data from anyone under 16 in connection with an RSX account. If we learn that an account holder is under 16, we will terminate the account and delete the data, other than the minimal record needed to prevent re-registration.
13.3
If you believe someone under 16 holds an account, tell us at privacy@rsx.group and we will investigate promptly.
13.4
Players in a Roblox experience may be under 16. We do not collect account data from them. Where an RSX system inside an experience processes a Roblox user ID, we do so on behalf of the experience operator, for the shortest period the feature requires, and we do not use it to build a profile.
14Automated decisions
14.1
We use automated systems to detect abuse: rate-limit breaches, credential stuffing, leaked keys, spam patterns, and AI Portal content-policy violations. These systems can automatically throttle traffic, revoke a key, or restrict an account.
14.2
Automated action is limited to what is needed to stop immediate harm. A permanent termination is reviewed by a person before it is final, except where clause 8.3 of the Terms of Service applies and the evidence is unambiguous.
14.3
Where a decision that significantly affects you is made by automated means, you have the right to be told, to obtain human review, to express your view, and to contest it. Use appeals@rsx.group.
14.4
We do not use automated decision-making for profiling unrelated to security and enforcement, and we do not use it for marketing.
15Changes to this policy
15.1
We update this policy when our practices, our processors, or the law change.
15.2
For changes that materially affect how we use your data, we will give at least 30 days’ notice by email or in the ID Portal before they take effect. Where a change requires consent, we will ask for it rather than assume it.
15.3
Corrections and clarifications take effect when published. The version and effective date at the top of this page always reflect the current text.
15.4
Previous versions are available on request from privacy@rsx.group.
16Contact
16.1
RSX is an unincorporated group operating from Silesia, Poland, under the Whitehill Group banner. Controller: paige@rsx.group.
16.2
Privacy and data rights requests: privacy@rsx.group. Security: security@rsx.group. Everything else: legal@rsx.group.