Privacy & data protection
The operating entity, jurisdiction and legal contact details have not yet been confirmed. This document is a draft for review, not a finalized legal notice. Identity verification remains unavailable. Email sending also remains disabled until sender and legal configuration is complete.
Draft updated 19 September 2026. Account verification, recovery and optional email sign-in codes use Brevo. Marketing campaigns remain disabled. The contact address and remaining legal details still require completion and review.
1. Who is responsible for your data?
- Controller / legal name
- Marco Silva
- Country and contact address
- Spain. Postal contact address pending.
- Privacy contact
- [email protected]
- Company registration, where applicable
- [REGISTRATION DETAILS]
The domain is decider.gg. A domain name or the DECIDER brand does not, by itself, identify the legal controller. These placeholders must be completed before this notice is treated as final.
2. What information is used?
- Account: email address, player name, profile details, password hash, verification status and account settings. Passwords are not stored as readable text.
- Steam: linked Steam identifier, public profile name and avatar. Steam sign-in does not give DECIDER your Steam password or email address; the contact email you provide separately must be verified.
- Competition and community: matches, ratings, results, parties, organizations, tournament participation, reports, messages, support requests and moderation decisions.
- Purchases: membership, coins, inventory, payment references and fulfillment records. Payment-provider details and contractual roles must be confirmed in the final provider list.
- Security and operation: sessions, access and error records, rate-limit identifiers, authentication events, MFA configuration and recovery-code hashes.
- Email: address, verification and recovery requests, subscription choice, consent-event history, message category, delivery status, bounces and complaints.
- Desktop: app version, random installation identifier, foreground/background status, connection times and recorded signed-in usage. This does not record your screen, files or use of other applications.
3. Purposes and proposed legal bases
The controller must confirm and document the applicable legal basis before the final notice is published. The intended separation is:
- Providing an account and requested features: performance of the service agreement, where necessary for that purpose.
- Email verification, password recovery and account protection: providing and securing the requested account; the specific contractual or legitimate-interest basis must be documented.
- Abuse prevention, moderation and operational security: the controller’s legitimate interests, subject to a documented necessity and balancing assessment and applicable safeguards.
- Optional newsletters, offers and promotional updates: your separate, voluntary consent. Refusing marketing does not prevent account registration or use.
- Billing, legal claims and mandatory records: the applicable legal obligation or other appropriate basis, once identified.
We do not treat acceptance of the Terms or acknowledgement of this notice as consent to marketing.
4. Verification and account recovery
When email delivery is activated, new accounts must verify their contact email. Verification links expire after 24 hours and password-reset links after 30 minutes. They can be used once; requesting a replacement invalidates the previous link. Password recovery does not disable an existing authenticator or email sign-in verification. Optional email sign-in codes expire after five minutes, are single-use, and allow five attempts. Codes are stored as keyed hashes; queued messages are encrypted. Existing sessions are rejected after a password reset.
Recovery messages and player-name reminders are sent only to eligible account addresses. Public recovery responses do not confirm whether an address is registered. Existing accounts are not automatically marked as email-verified.
5. Newsletters and service emails
Marketing subscriptions are optional and unchecked by default. We record the choice, time, source and notice version. You can withdraw through Account settings or the unsubscribe link in a marketing email, without signing in. Withdrawal prevents future queued marketing sends; it cannot recall a message already in transit.
Necessary security and service messages are separate. Administrators must record an operational reason for a service-wide email and must not use that audience for advertising. Bounced or complained-about addresses are suppressed from further sending. The email feature adds no application tracking pixel. Account emails are sent with pixel tracking consent set to false; provider settings do not track contacts with unknown consent.
6. Who can receive the data?
Authorized administrators and support staff access information according to their duties. Public profile and competition information is visible according to the relevant feature. Email recipients are addressed individually; the community mailing list is not exposed to other recipients.
Brevo provides account email delivery. It receives the recipient address, message content and delivery metadata. Its data-processing agreement, subprocessors, processing locations, retention settings and any international-transfer safeguards must be reviewed before activation. Hosting, payment, Steam and other providers must also be listed accurately in the final notice: [PROVIDER REGISTER AND LOCATIONS].
7. Retention
Ranked match integrity evidence includes server-recorded gameplay demos, Steam identifiers, round events and technical timestamps for all participants, regardless of Premium. Demos are private to authorized support and administrators; access is logged. Archived demos are kept for 30 days, extended to at most 180 days when linked to an open investigation or appeal. Server-side analysis prioritizes human review; statistical signals do not automatically impose cheating sanctions. This feature does not inspect files or processes on your computer, and records gameplay without relaying voice into the demo.
The email implementation applies these limits: verification/reset tokens are removed within seven days after expiry; encrypted queued content is cleared when processing ends; delivery records are removed after 90 days; daily sending-budget counters are removed after 100 days. Pending campaign messages expire after seven days. Cleanup runs periodically, so deletion may follow the stated threshold by up to one cleanup interval.
Subscription choices and consent history remain linked to the account and are removed with account deletion. A withdrawal is recorded so the previous choice is not silently restored. A finalized retention schedule is still required for inactive accounts, consent evidence after closure where necessary, financial records, matches, moderation evidence, admin campaign content, technical logs and backups: [RETENTION PERIODS AND JUSTIFICATION]. We do not claim that all platform data already has a finalized retention schedule.
8. Your rights and how to ask
Subject to the applicable conditions, you can request access, correction, erasure, restriction or portability of your data, object to processing based on legitimate interests, and withdraw consent without affecting processing before withdrawal. Rights requests can be sent to [email protected]. While this contact is being configured, signed-in players can open a support request marked “Privacy / data request”. Do not send identity documents unless a necessary, proportionate and secure verification process has been explained.
Requests should normally be answered within one month. Where the law permits an extension, the controller must explain it within the initial period. Erasure can be limited by legal obligations or the need to establish, exercise or defend legal claims; the controller must explain any applicable exception. You can complain to the competent supervisory authority, including the authority where you live, work or consider an infringement occurred. The controller is based in Spain; the Spanish supervisory authority is the AEPD.
9. Security and account protection
Access controls, HTTPS, password hashing, optional MFA, expiring single-use email links and encrypted pending email content help protect account information. They do not constitute a guarantee that incidents cannot occur. The controller must maintain an incident-response process, assess notification duties and document processor arrangements.
10. Cookies, age limits and identity checks
See the cookie and local-storage notice for session and preference storage. Non-essential tracking requires assessment and an appropriate choice mechanism before activation where applicable. Eligible ages, parental-authorization requirements and served territories must be completed: [AGE / TERRITORY POLICY]. KYC remains inactive; no identity documents or biometric information are collected through the verification page.
11. Changes and review
Material changes should be communicated through the service or appropriate account notices. New marketing purposes must not be silently added to a previous consent. This draft follows the transparency and rights topics in the General Data Protection Regulation; it does not certify the platform’s legal compliance.
Questions
Existing players can use DECIDER support for service questions. Do not submit identity documents there. A dedicated legal and privacy contact will be published before the verification service launches.