Privacy, Consent and Data Use
These notes explain how ADK records data use, respects player and server choices, limits identifying information, and supports access or deletion requests without weakening local authority.
Data Rules Registry
This service stores Human-approved rules for how each data class must be handled, including its purpose, access, retention, review, and deletion behavior. Runtime systems consume compact, versioned decisions instead of inventing privacy rules for themselves.
The registry enforces the policy it was given; it does not decide whether that policy is lawful. Qualified Humans remain responsible for the legal decision and its jurisdictional scope.
Player Data Mode Policy
This policy decides what kind of data processing is allowed for a player. It checks local settings and rules. The policy makes sure local gameplay data is not shared with central services without permission. It helps keep local server use separate from central ADC services. This policy supports local data handling before any ADC features use the data.
Checking Privacy Before a Feature Launches
This service determines whether a feature needs additional privacy review before release. Automated checks may stop a launch when required steps are missing, but only authorized people can complete the final review. The service records the requirement; it does not make legal decisions or overrule a legal reviewer.
For example, approval for Denmark and the EU does not automatically approve the same feature in a country or state with different privacy rules.
Choosing How Much Player Data a Report May Use
This service decides whether reporting data stays on the local server, uses a name that does not directly identify the player, or may be shared with ADC through account-linked permission. It chooses the least identifying option that can provide the approved function.
Sharing less data may disable some central features, but it does not change gameplay or security and never provides a gameplay advantage. The same privacy rules apply to every player; the service cannot quietly make individual exceptions.
Data Flow Registry Service
This service records approved ways personal data may move between servers, plugins, Kestrel, ADC, storage, and external recipients. Each registered flow identifies its purpose, responsible parties, data categories, destinations, and lifecycle rules.
The framework does not infer legal permission from the fact that data happens to be available. A Human-approved flow is required before governed sharing activates.
Handling Requests About Personal Data
This service checks and coordinates requests to delete, unlink, restrict, anonymize, or correct personal data. It acts only on data ADK controls, respects retention and legal-hold rules, and sends requests to the responsible local controllers.
It records a small compliance receipt without pretending that ADK controls an independent server owner.
Example: ADK can send an erasure request to a local controller and record its answer, but that record does not falsely claim the controller completed the request.
Secure Identity Vault Service
This service keeps the link between a player’s identity and a case pseudonym behind a separate protected boundary. Ordinary reviewers receive the case evidence they are authorized to judge without receiving the identity mapping.
Exceptional access requires a narrowly scoped authorization, produces an auditable receipt, and does not turn the case system into a general player-identity lookup.