Privacy Policy
Last updated: March 2026
1. Information We Collect
When you use the DBOGalaxy Support portal, we may collect:
- Email address: Required for account registration, ticket creation, and communication
- Display name: Used to personalize your support experience
- Ticket content: Messages, descriptions, and attachments you provide
- Technical data: IP address (hashed), browser type, language preference
- Cookie consent records: Your cookie preference choices
- Account data: Profile information (bio, language preference), notification settings, and login activity
- Chat messages: Conversations with the AI chatbot and live chat sessions with staff
- Security data: Two-factor authentication status, failed login attempt records, and account lockout information
2. How We Use Your Information
- Providing and improving support services
- Communicating about your support requests via email notifications
- Preventing abuse and maintaining security (brute-force protection, account lockouts)
- Generating anonymized statistics
- Processing AI chatbot queries to provide automated assistance
- Translating content to support our multilingual platform
3. Data Storage
Your data is stored on secure servers. Passwords are securely hashed and never stored in plain text. Two-factor authentication secrets are encrypted. Active ticket data is retained while tickets are open. Closed tickets are archived as HTML transcripts and database records are deleted.
4. Data Sharing
We do not sell or share your personal data with third parties except:
- Email service providers (Zoho Mail) for sending notifications and password reset emails
- Cloudflare for security services (Turnstile verification)
- AI service providers (Groq) for processing chatbot queries-chat messages are sent to generate responses
- Translation services (DeepL) for multilingual content support
- When required by law
5. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
To exercise these rights, submit a ticket through the support portal.
6. Cookies
We use essential cookies for session management and optional cookies for preferences. See our Cookie Policy for details.
7. Security
We implement appropriate technical measures to protect your data, including encrypted connections (HTTPS), secure password hashing, two-factor authentication options, brute-force login protection, and access controls.
8. Contact
For privacy-related inquiries, submit a ticket categorized under "Account" on the support portal.
9. Your Data Rights (GDPR / LGPD / CCPA)
Under applicable data protection regulations (EU GDPR, Brazil LGPD, California CCPA, and others), you have the following rights regarding your personal data:
- Right of Access: You can request a copy of all personal data we hold about you. Use the "Export My Data" feature in your profile settings to receive a JSON file containing all your data.
- Right to Rectification: You can update your personal information at any time through your profile settings, including your display name, bio, and email preferences.
- Right to Erasure (Right to be Forgotten): You can request permanent deletion of your account and all associated personal data. A 30-day grace period is provided to allow you to change your mind. After this period, all personal data will be permanently deleted and forum posts will be anonymized.
- Right to Data Portability: You can export your data in a machine-readable format (JSON) at any time from your profile settings.
- Right to Object: You can opt out of notification emails and announcements through your notification preferences.
To exercise any of these rights, visit your Profile → Settings tab, or submit a support ticket in the "Account" category. We will respond to data requests within 30 days.
Data Retention: We retain your personal data for as long as your account is active. After account deletion, personal data is permanently removed within 30 days. Anonymized forum content (posts) may be retained for community continuity with identifying information removed.