Privacy requests are accepted through @dkpanel.
1. Operator and scope
The DKPanel project operates the website, dashboard, DKPanel and SteamVault. This Policy explains the data processed when a person visits the site, creates an account, starts checkout, activates the software or contacts support.
2. Data we process
- Email, protected password hash, account status and roles.
- Session-token hash, session expiry, IP address, User-Agent and technical sign-in timestamps.
- Selected product and plan, price, currency, duration, checkout and subscription status, provider identifiers and minimised payment events.
- Machine-fingerprint hash, device public key, installation ID, device proof, label, client version, activation and heartbeat information.
- Security and audit records: action, time, safe identifier, request ID and IP.
- Information voluntarily sent to support through Telegram.
3. Data that is not uploaded
Game usernames and passwords, Steam Guard secrets, .maFile data, device private keys, local DKPanel or SteamVault databases and inventory contents are not uploaded to the web dashboard. Do not send this information to support.
4. Purposes
- Create and secure accounts, sign users in and manage sessions.
- Display plans, run checkout, record subscriptions and deliver digital access.
- Bind a licence to one machine and prevent replay or unauthorised use.
- Provide support, diagnose faults, prevent fraud and investigate incidents.
- Apply the Terms, process refunds and meet binding legal requirements.
5. Legal bases
Data is processed to perform the customer agreement, take requested pre-purchase steps, meet binding requirements, pursue legitimate security interests and, where required, on the basis of consent.
6. Cookies
The website uses only the essential HttpOnly dk_session cookie for authentication and dashboard protection. Ordinary JavaScript cannot read it and it remains valid for no more than 30 days. Advertising, behavioural and third-party analytics cookies are not currently used.
7. Recipients and third parties
- Hosting, database and infrastructure providers, only as necessary to operate the service.
- Heleket or another checkout provider for a real payment; it separately processes wallet, network, transaction and related AML/KYC data under its own policy.
- Telegram when a user contacts @dkpanel; the conversation is also governed by Telegram’s terms.
- Competent authorities only where disclosure is legally required.
8. Retention
The session cookie is valid for up to 30 days and then stops granting access. Account and product data is retained while the account is used or until a deletion request is processed. Payment, subscription, licensing and audit records may remain after account deletion while objectively necessary for security, refunds, disputes, accounting or binding requirements.
9. User rights
A user may request information, email correction, processing restriction or account deletion through @dkpanel. Support may verify account ownership before acting. Records required for security, a dispute or law may be restricted and de-identified instead of immediately erased.
10. Security and international processing
DKPanel uses password hashing, HttpOnly sessions, request limits, access controls and action auditing. Data may be processed in countries where infrastructure or a provider operates; transfers are limited to the service purpose.
11. Changes
The current edition and date are published here. Material changes apply to new actions after publication unless mandatory law requires otherwise.