Information Security PolicyLast updated 17.07.2026
This is an informational translation. The authoritative version is in Russian and is governed by the laws of the Russian Federation.
Policy
- 1.1. This Policy describes the means by which the Operator protects information in the operation of the website legacy.sx, its subdomains and the game servers of the LEGACY project.
- 1.2. The document is informational in nature and is addressed to Users. It discloses the protective measures applied, but it is not technical documentation and does not describe the configuration of the systems to an extent that could in itself facilitate an attack on them.
- 1.3. The Operator is the same person who acts as the Contractor under the public offer of the project. The User is any person accessing the Website or the game servers, including the Customer under the offer.
- 1.4. The Policy covers the source code of the Project, its databases, server infrastructure and the communication channels between them.
Legal basis
- 2.1. The Policy has been prepared with regard to:
— Federal Law No. 152-FZ of 27.07.2006 "On Personal Data", in particular Article 19, which defines the measures for ensuring the security of personal data during their processing;
— Federal Law No. 149-FZ of 27.07.2006 "On Information, Information Technologies and Information Protection";
— Decree of the Government of the Russian Federation No. 1119 of 01.11.2012, establishing the requirements for the protection of personal data in information systems. - 2.2. The procedure for processing personal data, the purposes, the retention periods and the rights of the User are disclosed in the personal data section of the public offer. The present document is devoted to the technical and organisational side of protection.
The Operator's objectives
- 3.1. The objectives are:
— to prevent access by outsiders to Users’ data;
— to keep the data undistorted and to ensure their availability;
— to detect an abnormal event in good time and to respond to it;
— to comply with the requirements of the legislation of the Russian Federation. - 3.2. The Operator proceeds from the premise that protection must be proportionate to the actual threats and to the nature of the data processed: the Project does not collect identity documents, does not store payment details and does not maintain correspondence of Users.
Access rights
- 4.1. Access to the server infrastructure and the databases of the Project is held exclusively by the Operator personally. No other persons — including game server administrators, moderators and assistants engaged by the Operator — are granted access to the databases or the server infrastructure.
- 4.2. The rights granted to persons assisting in the operation of the Project are limited to in-game and moderation functions and do not allow access to Users’ data beyond what is visible within the gameplay.
- 4.3. The granting and revocation of any elevated rights is performed by the Operator and is recorded in the event log (section 6).
Connection security
- 5.1. Data exchange between the User and the Website is carried out over the HTTPS protocol with TLS encryption. The certificate is issued by a trusted certification authority and is renewed as it approaches expiry.
- 5.2. The Project does not create a separate password for the User and does not request the User’s Steam credentials. Sign-in is performed by means of Steam OpenID: identity verification takes place on the side of Valve Corporation, and the Project receives only the result of the check.
- 5.3. A consequence of this design is that Users’ passwords do not exist within the Project, and therefore they can neither be stolen from the Operator nor disclosed in the event of a compromise of the Operator’s infrastructure.
- 5.4. Steam credentials are not transmitted to the Operator, are not stored by the Operator and are not processed in any form.
Event logging
- 6.1. The Operator maintains an event log in which actions significant for security and for settlements are recorded: balance transactions, activation of paid features, changes of access rights, and administrative actions.
- 6.2. Log entries are used to examine disputes, to reconstruct what occurred and to detect abnormal activity.
- 6.3. Access to the log is held by the Operator.
Request rate
- 7.1. Requests to sensitive sections of the Website are subject to rate limits. This measure is directed against automated brute-force attempts and against attempts to create a load for which the Project is not intended.
- 7.2. If the established limits are exceeded, requests are temporarily rejected.
Backups
- 8.1. Backup copies of the Project databases are made once every twenty-four hours.
- 8.2. Backup copies are intended for restoring the operability of the Project after a failure, data corruption or an erroneous change.
- 8.3. The Operator does not guarantee the recovery of data changed or lost in the interval between backups.
Payment data
- 9.1. Payments are accepted by third-party certified payment services. The card number, its expiry date and the CVC2/CVV2 code are entered on their pages.
- 9.2. The Operator does not receive, store or process payment details. They are not and cannot be present on the servers of the Project, since they never reach them.
- 9.3. Compliance with the requirements of the PCI DSS standard is ensured by the payment services that process card data. The Operator does not process such data, and the said standard does not apply to the Operator’s infrastructure.
- 9.4. If the User’s card is enrolled in 3-D Secure, the issuing bank additionally requests confirmation of the transaction on its own page.
Personal data
- 10.1. The databases of the Project containing personal data are hosted on servers located within the territory of the Russian Federation, in accordance with part 5 of Article 18 of Federal Law No. 152-FZ.
- 10.2. The volume of information processed is reduced to what is necessary: the Steam identifier, the display name and profile image obtained upon authorisation, the e-mail address if the User has provided it, the balance state and the transaction log, as well as technical data arising in the course of using the Website.
- 10.3. The information is not transferred to outsiders. The exceptions are: transfer to payment services to the extent necessary to carry out the settlement, and cases where disclosure is required by law.
- 10.4. The retention period is determined by the purposes of processing. The data are deleted together with the Account on the grounds provided for by the offer, or upon the User’s application to withdraw consent.
Incidents
- 11.1. An incident is any event that has led or could have led to unlawful access to data, their distortion or destruction, or to a disruption of the operation of the Project.
- 11.2. A report of an incident is to be sent to support@legacy.sx with the note "Security" in the subject line.
- 11.3. The Operator reviews the report within no more than 3 (three) business days from the moment of receipt and takes measures to eliminate the consequences.
- 11.4. If unlawful access to personal data is confirmed, the Operator will notify the affected Users and the authorised body for the protection of the rights of personal data subjects in the manner and within the time limits established by the legislation of the Russian Federation.
Vulnerability reports
- 12.1. The Operator has an interest in being informed of vulnerabilities and does not pursue researchers acting in good faith.
- 12.2. A researcher who discovers a vulnerability shall:
— report it to support@legacy.sx without delay;
— not use the finding to access other persons’ data and not modify such data;
— not extract Users’ data, limiting themselves to the minimum confirmation that the vulnerability exists;
— not disclose information about the vulnerability until it has been remedied. - 12.3. Actions performed in accordance with clause 12.2 that have caused no harm are not regarded by the Operator as a breach of the terms of use of the Project and are not treated as grounds for restricting access.
- 12.4. This section does not permit attacks on the availability of the Project, interference with the gameplay, or access to the data of other Users.
What the Policy does not guarantee
- 13.1. Absolute protection of information systems does not exist. The Operator applies the measures described herein but does not guarantee that the Project will not be subjected to a successful attack.
- 13.2. The Operator is not responsible for the security of the User’s device, the User’s Steam account or the User’s communication channel. Compromise of a Steam account is beyond the Operator’s control.
- 13.3. Measures not named in this Policy are not claimed by the Operator. The absence of a mention of any technology or practice shall not be construed as an assertion that it is applied.
Revision of the Policy
- 14.1. The Policy is revised as legislation, the design of the Project and the nature of threats change.
- 14.2. The current version is published at https://legacy.sx/security and applies from the moment of publication.
- 14.3. Questions regarding the content of this Policy are to be sent to support@legacy.sx.