Skip to content
Legal

Privacy policy

This policy sets out who processes the personal data collected through the owner's four websites, for what purposes and on what legal basis, who it is shared with, how long it is kept and how data subjects may exercise their rights.

Controller
Marc Marchal Pastor
Scope
4 sites · 1 controller
Supervisory authority
AEPD (Spain)
Last revised
4 September 2026
01

Data controller

The data controller is a natural person trading under the name «RealCity Developments».

Controller
Marc Marchal Pastor
ID (DNI/NIE)
43479769V
Scope
This policy applies to realcity.dev, client.realcity.dev, shop.realcity.dev and getserver.realcity.dev.

No data protection officer has been appointed, as none of the circumstances set out in Article 37(1) GDPR applies.

02

Processing by site

Each site collects different data for different purposes. They are set out below using the same structure: categories of data, purpose, legal basis and retention period.

2.1. Contact form and quote requests

Data
Name, email address, company (optional), Discord username (required only in the FiveM division), service of interest, indicative budget and the content of the message. The date, time and IP address from which consent was given are also recorded, together with the version of this policy accepted.
Purpose
To respond to the enquiry received and, where appropriate, to prepare and send a proposal.
Legal basis
Pre-contractual steps taken at the data subject's request (Art. 6(1)(b) GDPR) and the data subject's consent given on submitting the form (Art. 6(1)(a) GDPR).
Retention
For the duration of the enquiry and, at most, twelve months from the last contact if no engagement follows. Once an engagement is agreed, the data forms part of the contractual relationship described in section 2.2.

2.2. Client panel (client.realcity.dev)

Data
Account identification data (depending on the access method used, email and password or a Discord account (OAuth), including where applicable the Discord ID and avatar), the content of requests and proposals, messages and files exchanged, deliveries made, billing data and the account activity log, including dates and IP addresses of access.
Purpose
Managing the account, providing the contracted service, communicating with the client during performance, delivering the work, invoicing and providing support.
Legal basis
Performance of the contract or of pre-contractual steps (Art. 6(1)(b) GDPR); compliance with legal invoicing and record-keeping obligations (Art. 6(1)(c) GDPR); the controller's legitimate interest in securing the panel and preventing fraudulent access (Art. 6(1)(f) GDPR).
Retention
For as long as the account remains active. On closure, account data and conversations are deleted; invoices and the documentation needed to evidence the contractual relationship are blocked for the applicable tax and civil limitation periods, up to a maximum of six years. Access logs are kept for twelve months.

2.3. Script store (shop.realcity.dev)

The store runs on the Tebex platform (Tebex Ltd.), which acts as merchant of record and as an independent controller of payment data, under its privacy policy. The controller never has access to card details or to the purchaser's payment methods.

Data
The information Tebex passes to the controller in respect of each order: FiveM (CFX) account ID, email address, username, products purchased, amount, date and order status, together with the Discord ID where the purchaser links their account.
Purpose
Delivering and activating the licence through the Cfx.re keymaster, recording the order, providing support, assigning the client role on Discord, managing free trials and preventing fraud and unauthorised use of licences.
Legal basis
Performance of the licence contract (Art. 6(1)(b) GDPR); compliance with tax obligations (Art. 6(1)(c) GDPR); the controller's legitimate interest in protecting its licences against unauthorised use (Art. 6(1)(f) GDPR).
Retention
The purchase record is kept for as long as the licence remains valid, given its lifetime nature. Data with tax relevance is kept for the statutory periods, up to a maximum of six years.

2.4. Server-base configurator (getserver.realcity.dev)

The configurator does not process personal data. It requires no registration or account, asks for no identifying information, and builds no profile or history associated with whoever uses it.

What is processed
Only the configuration parameters chosen by the user themselves — framework, modules, base options — which are technical data and identify no one.
Purpose
Generating and delivering the server base according to those options. They are used for no other purpose.
Retention
The parameters are used to build the base and discarded once it has been delivered. No record is kept of who generated what.

As no personal data is processed, the rights described in section 5 do not arise here: there is nothing to access, rectify or erase in connection with use of the configurator.

2.5. Usage analytics

Browsing data — pages visited, device, interactions and approximate location derived from the IP address — is processed through Google Analytics 4 and Microsoft Clarity only where the data subject accepts analytics cookies, on the basis of their consent (Art. 6(1)(a) GDPR). That consent may be withdrawn at any time via “Cookie settings”, without affecting the lawfulness of prior processing. Each cookie is detailed in the Cookie policy.

03

Recipients

Personal data is not sold or disclosed to third parties for commercial purposes. The following providers process data on the controller's behalf as processors, under the corresponding data processing agreement (Art. 28 GDPR), unless expressly stated otherwise:

Resend, Inc.
Delivery of the email generated by the contact form. Processor.
Tebex Ltd.
Store platform. Independent controller in respect of payment data; processor in respect of the order data it passes to the controller.
Cfx.re
FiveM keymaster binding the licence to the purchaser's CFX account. Independent controller under its own policy.
Discord, Inc.
Identification in the panel and assignment of the client role. Independent controller under its own policy.
Google Ireland Ltd.
Google Analytics 4. Only with the data subject's prior consent.
Microsoft Ireland Operations Ltd.
Microsoft Clarity. Only with the data subject's prior consent.
Hosting
Own server managed by the owner within the European Union.

Data may be disclosed to courts and public authorities where required by law.

04

International transfers

Resend, Google, Microsoft, Discord and Cfx.re may process data in the United States; Tebex, in the United Kingdom. Such transfers rely on the adequacy decisions adopted by the European Commission — the EU-US Data Privacy Framework and the adequacy decision for the United Kingdom — and, in the alternative and in respect of providers not certified under them, on the standard contractual clauses approved by the European Commission, supplemented by any additional measures required.

05

Your rights

Data subjects may exercise the rights granted by Articles 15 to 22 GDPR by writing to [email protected] with the reference “Data protection”, providing proof of identity. Requests are answered within one month of receipt, extendable by a further two months where particularly complex, in which case the data subject will be informed.

Access
To know what personal data is being processed.
Rectification
To correct inaccurate or incomplete data.
Erasure
To request deletion where the data is no longer necessary.
Objection
To object to processing based on legitimate interest.
Restriction
To request restriction while a complaint is verified.
Portability
To receive the data in a structured, commonly used format.

Data subjects may also withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal, and lodge a complaint with the Spanish Data Protection Agency (aepd.es) or with the supervisory authority of their place of residence, in particular where they consider that their request has not been dealt with properly.

06

Security measures

The controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR: encryption of communications in transit via HTTPS, access control to the panel and the infrastructure, regular backups and minimisation of the data collected.

In the event of a security breach entailing a high risk to the rights and freedoms of data subjects, they will be notified without undue delay in accordance with Article 34 GDPR, and the supervisory authority will be notified where appropriate.

07

Minors

The services are not directed at children under fourteen. The controller does not knowingly collect data from children of that age without the consent of those holding parental responsibility or guardianship. Should such processing come to light, the data will be deleted immediately.

08

Amendments

This policy may be amended to reflect legal or case-law developments or changes to the processing described. Any amendment will be published on this page together with its date. Where an amendment affects processing based on consent, fresh consent will be obtained.

Last revised: 4 September 2026.