Privacy policy
This policy sets out who processes the personal data collected through the owner's four websites, for what purposes and on what legal basis, who it is shared with, how long it is kept and how data subjects may exercise their rights.
- Controller
- Marc Marchal Pastor
- Scope
- 4 sites · 1 controller
- Supervisory authority
- AEPD (Spain)
- Last revised
- 4 September 2026
Data controller
The data controller is a natural person trading under the name «RealCity Developments».
- Controller
- Marc Marchal Pastor
- ID (DNI/NIE)
- 43479769V
- [email protected]
- Scope
- This policy applies to realcity.dev, client.realcity.dev, shop.realcity.dev and getserver.realcity.dev.
No data protection officer has been appointed, as none of the circumstances set out in Article 37(1) GDPR applies.
Processing by site
Each site collects different data for different purposes. They are set out below using the same structure: categories of data, purpose, legal basis and retention period.
2.1. Contact form and quote requests
- Data
- Name, email address, company (optional), Discord username (required only in the FiveM division), service of interest, indicative budget and the content of the message. The date, time and IP address from which consent was given are also recorded, together with the version of this policy accepted.
- Purpose
- To respond to the enquiry received and, where appropriate, to prepare and send a proposal.
- Legal basis
- Pre-contractual steps taken at the data subject's request (Art. 6(1)(b) GDPR) and the data subject's consent given on submitting the form (Art. 6(1)(a) GDPR).
- Retention
- For the duration of the enquiry and, at most, twelve months from the last contact if no engagement follows. Once an engagement is agreed, the data forms part of the contractual relationship described in section 2.2.
2.2. Client panel (client.realcity.dev)
- Data
- Account identification data (depending on the access method used, email and password or a Discord account (OAuth), including where applicable the Discord ID and avatar), the content of requests and proposals, messages and files exchanged, deliveries made, billing data and the account activity log, including dates and IP addresses of access.
- Purpose
- Managing the account, providing the contracted service, communicating with the client during performance, delivering the work, invoicing and providing support.
- Legal basis
- Performance of the contract or of pre-contractual steps (Art. 6(1)(b) GDPR); compliance with legal invoicing and record-keeping obligations (Art. 6(1)(c) GDPR); the controller's legitimate interest in securing the panel and preventing fraudulent access (Art. 6(1)(f) GDPR).
- Retention
- For as long as the account remains active. On closure, account data and conversations are deleted; invoices and the documentation needed to evidence the contractual relationship are blocked for the applicable tax and civil limitation periods, up to a maximum of six years. Access logs are kept for twelve months.
2.3. Script store (shop.realcity.dev)
The store runs on the Tebex platform (Tebex Ltd.), which acts as merchant of record and as an independent controller of payment data, under its privacy policy. The controller never has access to card details or to the purchaser's payment methods.
- Data
- The information Tebex passes to the controller in respect of each order: FiveM (CFX) account ID, email address, username, products purchased, amount, date and order status, together with the Discord ID where the purchaser links their account.
- Purpose
- Delivering and activating the licence through the Cfx.re keymaster, recording the order, providing support, assigning the client role on Discord, managing free trials and preventing fraud and unauthorised use of licences.
- Legal basis
- Performance of the licence contract (Art. 6(1)(b) GDPR); compliance with tax obligations (Art. 6(1)(c) GDPR); the controller's legitimate interest in protecting its licences against unauthorised use (Art. 6(1)(f) GDPR).
- Retention
- The purchase record is kept for as long as the licence remains valid, given its lifetime nature. Data with tax relevance is kept for the statutory periods, up to a maximum of six years.
2.4. Server-base configurator (getserver.realcity.dev)
The configurator does not process personal data. It requires no registration or account, asks for no identifying information, and builds no profile or history associated with whoever uses it.
- What is processed
- Only the configuration parameters chosen by the user themselves — framework, modules, base options — which are technical data and identify no one.
- Purpose
- Generating and delivering the server base according to those options. They are used for no other purpose.
- Retention
- The parameters are used to build the base and discarded once it has been delivered. No record is kept of who generated what.
As no personal data is processed, the rights described in section 5 do not arise here: there is nothing to access, rectify or erase in connection with use of the configurator.
2.5. Usage analytics
Browsing data — pages visited, device, interactions and approximate location derived from the IP address — is processed through Google Analytics 4 and Microsoft Clarity only where the data subject accepts analytics cookies, on the basis of their consent (Art. 6(1)(a) GDPR). That consent may be withdrawn at any time via “Cookie settings”, without affecting the lawfulness of prior processing. Each cookie is detailed in the Cookie policy.
Recipients
Personal data is not sold or disclosed to third parties for commercial purposes. The following providers process data on the controller's behalf as processors, under the corresponding data processing agreement (Art. 28 GDPR), unless expressly stated otherwise:
- Resend, Inc.
- Delivery of the email generated by the contact form. Processor.
- Tebex Ltd.
- Store platform. Independent controller in respect of payment data; processor in respect of the order data it passes to the controller.
- Cfx.re
- FiveM keymaster binding the licence to the purchaser's CFX account. Independent controller under its own policy.
- Discord, Inc.
- Identification in the panel and assignment of the client role. Independent controller under its own policy.
- Google Ireland Ltd.
- Google Analytics 4. Only with the data subject's prior consent.
- Microsoft Ireland Operations Ltd.
- Microsoft Clarity. Only with the data subject's prior consent.
- Hosting
- Own server managed by the owner within the European Union.
Data may be disclosed to courts and public authorities where required by law.
International transfers
Resend, Google, Microsoft, Discord and Cfx.re may process data in the United States; Tebex, in the United Kingdom. Such transfers rely on the adequacy decisions adopted by the European Commission — the EU-US Data Privacy Framework and the adequacy decision for the United Kingdom — and, in the alternative and in respect of providers not certified under them, on the standard contractual clauses approved by the European Commission, supplemented by any additional measures required.
Your rights
Data subjects may exercise the rights granted by Articles 15 to 22 GDPR by writing to [email protected] with the reference “Data protection”, providing proof of identity. Requests are answered within one month of receipt, extendable by a further two months where particularly complex, in which case the data subject will be informed.
- Access
- To know what personal data is being processed.
- Rectification
- To correct inaccurate or incomplete data.
- Erasure
- To request deletion where the data is no longer necessary.
- Objection
- To object to processing based on legitimate interest.
- Restriction
- To request restriction while a complaint is verified.
- Portability
- To receive the data in a structured, commonly used format.
Data subjects may also withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal, and lodge a complaint with the Spanish Data Protection Agency (aepd.es) or with the supervisory authority of their place of residence, in particular where they consider that their request has not been dealt with properly.
Security measures
The controller applies appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR: encryption of communications in transit via HTTPS, access control to the panel and the infrastructure, regular backups and minimisation of the data collected.
In the event of a security breach entailing a high risk to the rights and freedoms of data subjects, they will be notified without undue delay in accordance with Article 34 GDPR, and the supervisory authority will be notified where appropriate.
Minors
The services are not directed at children under fourteen. The controller does not knowingly collect data from children of that age without the consent of those holding parental responsibility or guardianship. Should such processing come to light, the data will be deleted immediately.
Amendments
This policy may be amended to reflect legal or case-law developments or changes to the processing described. Any amendment will be published on this page together with its date. Where an amendment affects processing based on consent, fresh consent will be obtained.
Last revised: 4 September 2026.