GDPR · ARTICLE 30

Record of
processing activities

The register describes the processing of personal data by the association's site and Discord bot, heading by heading following the CNIL's model (the French data protection authority). It is public: anyone can consult or download it, without an account and without asking.

It also describes the support portal (Spiceworks), match streaming and the web server's technical logs. Managing memberships of the association is not part of the site: the association keeps it outside the site, and this register does not describe it — for any question about it, use the contact details of the privacy policy.

Translation provided for convenience

This page is an English translation of the French original, provided for convenience. In case of any discrepancy between the two, the French version prevails. Read the French version.

CONTROLLER

Parties

UPDATED OCTOBER 6, 2026
Data controllerBluegenji Esport — French nonprofit (law of 1901), 4 impasse des Cyprès, 51210 Janvilliers, France
ContactRequests regarding data: Keryan Houssin, technical host of the site, appointed by the association to receive them — email and phone (privacy policy and legal notice of the site) —, or the site's “Report a problem” form (footer), “GDPR” category (« RGPD »); the association: email and phone (legal notice of the site)
Person to contact for requests regarding dataKeryan Houssin, technical host of the site, appointed by the association to receive requests regarding data (contact details given with those of the data controller). He is not a data protection officer within the meaning of Article 37 of the GDPR; the association remains the data controller
Host (processor)Keryan Houssin (private individual, volunteer of the association), 13 rue du Chemin Fourchue, 14000 Caen, France — processor (processing agreement (GDPR, art. 28) drafted, awaiting signature by the association and the host), data hosted in France (site and Discord bot on a Raspberry Pi in Caen, France)
17 PROCESSING ACTIVITIES

Processing activities

T01 Player accounts and profiles

Main purposeAllowing players to have an account on the tournament platform
Sub-purposes
  • Displaying a public profile (username, avatar, in-game usernames according to visibility settings)
  • Putting players in touch (adding each other in game, team recruitment)
  • Exporting one's data and deleting one's account from “My profile”
Legal basisPerformance of the service requested by the player (contract) for the account; consent for the optional data the player fills in and chooses to make visible
Data subjectsPlayers registered on the site
Data
  • Site username (since September 30, 2026, never taken from the name of the Google account: neutral username at creation; an earlier Google account may have received that name), avatar (copied to our servers; since the same date, hidden by default when it comes from the login provider)
  • Overwatch (BattleTag), Marvel Rivals and Discord usernames; certification of the Discord username
  • Declared adulthood (yes / no / not specified)
  • Visibility settings, availability for recruitment, roles on the platform
  • No real name, no email address, no phone number, no postal address
Sensitive dataNone
Retention
  • Lifetime of the account
  • On deletion: complete erasure if the account has left no trace (no match played, no registration in a solo tournament, no team owned, no tournament organized), immediate anonymization otherwise — the username is replaced by a borrowed username, and only the anonymized account remains, with its tournament and team history; in both cases, the connection data log (T14) is kept until its legal deadline; the information provided when the account was created (username, provider identifiers) is not kept after deletion, apart from the encrypted backup copies (T09, 30 days at most) and the record of the deletion in the log that replays it after a restoration (account identifier and creation date, 60 days); the reports sent by the account are detached from it and follow their own period (T11), and a staff member's refereeing actions remain named in the server logs, according to their rotation (T05)
  • Login sessions: 30 days after login
Recipients
  • The site's public (only the data the player makes visible)
  • Players of the same match, until the tournament is over (BattleTag even when hidden, to add each other in game)
  • Logged-in players of the site: certified Discord username, if the player makes it visible
  • The association's staff according to their role (administration, refereeing)
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Session tokens stored as a hash (SHA-256), httpOnly cookie
  • No password: login delegated to Google, Discord or Blizzard, or one-time code

T02 Authentication

Main purposeLogging a player into their account without a password
Sub-purposes
  • Login through Google, Discord or Blizzard (OAuth)
  • Login with a six-digit code sent by the bot by Discord direct message
  • Linking several means of logging in to the same account
Legal basisPerformance of the service requested by the player (contract)
Data subjectsPlayers registered on the site
Data
  • Opaque Google, Discord and Blizzard technical identifiers
  • Discord identifier and Discord username (login by code or by button), recorded without being certified — certification, which exposes it, is a separate action (T04)
  • Way the Discord account was linked (OAuth button or code by direct message)
  • Login code (kept only as a hash), number of attempts
  • IP address, in memory to limit attempts; that of a successful login is written to the connection data log (T14), for the host's legal obligation only
Sensitive dataNone
Retention
  • Login identifiers: lifetime of the account, or until the provider is unlinked; erased when the account is deleted (only the connection data log, T14, outlives it, apart from the encrypted backup copies, T09, 30 days at most)
  • Login codes: valid 10 minutes, purged one day after expiry, erased when the account is deleted
Recipients
  • Google, Discord and Blizzard, which authenticate the player (controllers of their own processing)
  • Discord, which delivers the direct message containing the code
Transfers outside the EUPossible to the United States, depending on the provider the player chooses to log in with — Google and Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework); Blizzard: standard contractual clauses of the European Commission (art. 46 GDPR), included in its terms of use
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Anti-CSRF token and state sealed on the way out for each OAuth login
  • Five attempts per code, five codes per quarter of an hour and per account, rate limits per IP address
  • Only the minimum permissions are requested from providers (neither email address nor server list)

T03 Tournaments, teams and achievements

Main purposeOrganizing amateur tournaments and keeping their results
Sub-purposes
  • Forming teams (members, roles, invitations)
  • Notifying the owner and managers of a team of a request to join by Discord direct message (without naming the requester, at most one message per player and per team every 24 h)
  • Registering teams or players, generating brackets, entering and refereeing scores
  • Publishing results, rankings, statistics and achievements
Legal basisLegitimate interest (organizing competitions, sporting memory of the scene)
Data subjects
  • Registered players
  • Team members
  • Refereeing staff
Data
  • Team membership and team roles
  • Registrations, scores, forfeits, penalties (with reason and referee who imposed it), rankings
  • Map-by-map detail of a match: score and replay code of each map (the replay shows the players' identifiers in game, hidden BattleTag included), account that entered it
Sensitive dataNone
Retention
  • Results and achievements: no defined retention period, kept as long as the site exists; anonymized when the account is deleted (borrowed username)
  • Replay codes: kept with the result they document (a detail that no longer explains it is erased); the link to the account that entered them is erased when the account is deleted, the codes remain (the game is kept by the game's publisher)
  • Right to object available on request
Recipients
  • The site's public
  • Refereeing and administration staff
  • Discord, which delivers the direct message of a request to join
Transfers outside the EUUnited States: Discord (delivery of direct messages) — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Changing a score locked as soon as the next round has started

T04 Contacting players during a tournament

Main purposeAllowing the organizers to reach a player taking part (rescheduling, settling a dispute, confirming a forfeit)
Sub-purposes
  • Exposing the certified Discord username to administrators, at any time, and to referees while the player is registered for a tournament that is not over (from the registration phase)
  • Opening a player's hidden BattleTag to administrators and referees, while they are registered for a tournament that is not over
  • When a match is launched, presenting to the players of both teams and to the registered caster the certified Discord username and the BattleTag of one or two players per team, and those of the caster, until the end of the match
  • Collecting the “Ready” of each party to a match (teams, caster) before it is launched
  • Sending match reminders by Discord direct message (one week, 24 h and 1 h before)
  • Alerting the referee role (score conflict, expired postponement, report on a player)
Legal basisConsent for exposing the certified Discord username to the organizers (certification, a separate action taken by the player from their profile — never acquired by logging in alone — and withdrawable by removing their tag); performance of the service requested by the player (contract — terms of use) for presenting the contacts to the parties to a match at its launch and collecting the “Ready”; legitimate interest (smooth running of tournaments) for match reminders and refereeing alerts
Data subjects
  • Players taking part in a tournament
  • Referees
  • Casters registered on a match
Data
  • Discord username and identifier
  • BattleTag
  • Date and opponent of the match
  • Time at which each party declared itself ready, registered caster
  • Reason for a report
Sensitive dataNone
Retention
  • Certified username: until it is changed or the account is deleted
  • Records of reminders and alerts sent (match and step, without content): kept with the match, so with no time limit
  • “Ready” and caster of a match: kept with the match; the caster of a deleted account is removed from matches not yet played
Recipients
  • The association's administrators and referees
  • Players and caster of the same match, from its launch to its end
  • Discord, which delivers the messages
Transfers outside the EUUnited States: Discord (delivery of direct messages) — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Uncertified username invisible to everyone, administrators included; certified username never shown to a visitor without an account
  • Match contacts served only to the parties to the match, never in the tournament's public snapshot

T05 Staff activity log on Discord

Main purposeKeeping the staff informed of notable events on the platform
Sub-purposes
  • New players, tournament registrations and withdrawals, match results, closings
  • Traceability of refereeing actions (penalties, removal of participants, rollbacks), for moderation
Legal basisLegitimate interest (administration and oversight of refereeing)
Data subjectsStaff
Data
  • On Discord: team names, scores, tournament names — no player username (“a player”, including in solo tournaments) and no staff member named (“the staff”)
  • In the server logs: username and identifier of the staff member who carried out a refereeing action
Sensitive dataNone
Retention
  • Discord messages: kept in a staff-only channel, purged manually by the association and by the bot after 365 days (one year), in batches — several nights for a large backlog (processing activity T08)
  • Server logs: according to their automatic rotation
Recipients
  • The association's staff with access to the channel
  • Discord (hosting of the channel)
  • Technical manager (server logs)
Transfers outside the EUUnited States: Discord — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Private channel, access restricted by Discord role

T06 Site audience measurement

Main purposeKnowing how much the site is visited
Sub-purposesCounting visits (24 h, 7 days, 30 days, total) and unique visitors (24 h, 7 days, 30 days, 25 months)
Legal basisLegitimate interest (art. 6.1.f GDPR: knowing how much the site is visited), without a measurement cookie or third-party tracker; right to object (art. 21) applied by the site itself — the browser's Global Privacy Control and Do Not Track signals, or the objection button of the privacy policy (“Audience measurement” section; bg_audience_optout cookie, without identifier): a refused visit is not recorded, as the server reads these signals itself, and is not even sent when the browser exposes them to the page. For visits already recorded, the right is exercised like the other rights: with the person to contact for requests regarding data, through the report form, “GDPR” category (« RGPD »), or with the association
Data subjectsVisitors of the site
Data
  • Hash salted with a server secret (SHA-256), derived from the account or from the IP address and the browser: pseudonymized data — without the secret, it cannot be linked to anyone, but the association, which holds it, can recompute the hash of an account or of an IP address and browser pair
  • Page viewed (without URL parameters), date
  • “Logged-in visitor” indicator (yes / no), without the account concerned
  • Several loads by the same visitor within 30 minutes count as a single visit
Sensitive dataNone
Retention
  • Visit details (hash, page, date) erased after 31 days, after being added to a daily counter that only keeps the number of visits
  • One hash per visitor, without page but with the “logged-in visitor” indicator and the date of the last visit, erased 25 months after that last visit (including after the account is deleted, which does not erase it sooner); hashes prior to this rule are dated from when it was introduced
  • IP address, browser and account identifier never recorded as such
Recipients
  • The association's staff
  • Any member of a Discord server where the bot is installed, for the totals only (visits and visitors), through the public /stats-site command
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • No measurement cookie — a single session storage value (bg:last-visit-ping), never sent, avoids reporting the same load twice; the salting secret is neither in the database nor in the backups, and without it no visit is counted
  • Objection read again on the server side (Sec-GPC and DNT headers, objection cookie): a refused visit is neither hashed, nor counted against the rate limit, nor written

T07 Presenting the association and recruiting volunteers

Main purposePresenting the board and the volunteers, and recruiting
Sub-purposes
  • “Association” page: board members and volunteers
  • Recruitment announcements with a Discord contact or a link
Legal basisConsent of the volunteers and board members concerned
Data subjects
  • Board members
  • Volunteers
  • Authors of recruitment announcements
Data
  • Last name, first name and username, category or position, date of joining, photo
  • Discord username and identifier or contact link of an announcement
Sensitive dataNone
RetentionDuration of involvement in the association, or of publication of the announcement
RecipientsThe site's public
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires

T08 BlueGenji Discord bot

Main purposeProviding the bot's services on partner Discord servers
Sub-purposes
  • Relaying announcements between the channels of partner servers, passing on edits and deletions, cooldowns, /stats message counter, dashboard statistics, removal of the copies of an excluded user
  • Exclusion of a user from the relay by moderation — valid for the whole network of partner servers (community moderation), hence the list of exclusions open to the administrators of each server
  • Activity statistics (/stats command, which shows each person only their own activity; the bot's dashboard)
  • Confirming memberships of the association and scheduled reminders on its servers
  • Delivering messages written by the site: codes, reminders, moderation notices (report naming the person, logo hidden, removed or deleted), requests to join a team and information about data by direct message, without being kept by the bot; refereeing alerts, reports and the site's activity log (without player usernames) posted in the staff's private log channel, refereeing alerts also sent to the members of the refereeing role of each server that has set one
Legal basisLegitimate interest (operating, moderating and measuring the relay between partner servers); the site's messages fall under the basis of their original processing
Data subjects
  • Discord users of the servers where the bot is installed
  • Administrators and moderators of these servers
  • Members of the association whose membership is confirmed by the bot
Data
  • Relayed announcements: identifiers of the original message and its author, date, identifiers of the copies and their channels (content copied into partner channels, never recorded in the database)
  • Scrims and recruitment: author's identifier, game, level or role (chosen from a closed list; free text for announcements prior to this rule, also kept in the daily counts), server, date; beyond 30 days, only counts per day, server and level or role
  • Public activity feed on the bot's page: time, type of event (relay, scrim, recruitment, login), server name, level or role — without Discord identifier
  • Exclusions: identifiers of the excluded user and the moderator, date; identifiers and reason posted in the staff's private log channel, reason copied by direct message to the bot's owner, usernames and reason displayed by /ban-list
  • Configuration: identifiers of servers, channels and roles, invitation, identifier of the administrator who set it
  • Memberships and scheduled reminders: identifier of the member or role targeted and of the author, message, date of the next sending (for a membership: its expiry date, hence membership status), frequency; membership certificate delivered by direct message without being kept
  • Technical log (staff's private channel, server logs): name of the servers that add or remove the bot, errors that may quote an identifier; the bot no longer writes a username there of its own accord, messages prior to this rule excepted (the free-text reason for an exclusion or an error delivering a direct message may quote one)
Sensitive dataNone
Retention
  • Tracking of relayed announcements: 7 days, erased at the first relay after that deadline and at the latest during the night or when the bot restarts; the copies posted in partner channels remain on Discord until they are deleted (by the author within that period, afterwards by the administrators of each server)
  • Scrims and recruitment: 30 days; then, during the following night (or at a restart), author's identifier erased and rows collapsed into counts per day, server and level or role, kept with no time limit as a history of the bot's activity
  • Exclusions: record until the exclusion is lifted; its notice and reason (staff's private log channel, and reason copied by direct message to the bot's owner) are deleted when it is lifted — for an exclusion prior to this rule, only the reason posted in the channel, the rest following the log channel's period
  • Configuration (relayed channels and their rank filters, invitation and refereeing role with the identifier of who set them, bot administration role, modules): until removed by the administrators, at the latest until the bot leaves the server, which erases it (a departure that occurred while the bot was down, which Discord does not report to it, is caught up at its restart)
  • Memberships and scheduled reminders: until the reminder's last sending (for a membership, its expiry date) or its deletion, at the latest until the bot leaves the server where they were recorded, which erases them (departure while the bot was down included, caught up at restart)
  • Activity feed: 30 days, deleted during the following night
  • Staff's private log channel, and the bot's direct messages to its owner: 365 days (one year), then deleted by the nightly cleanup, in batches (several nights for a large backlog), except the reason posted in the channel for an ongoing exclusion — and, for an exclusion imposed from this rule onward, its notice and the copy of its reason by direct message —, deleted when it is lifted
  • Server logs: according to their automatic rotation
  • Backups: 30 days at most (processing activity T09)
Recipients
  • The association's staff (moderation, administration)
  • The bot's owner (its technical host), for the reasons for exclusion received by direct message
  • Excluded user, who receives the reason for their exclusion by direct message when they post an announcement in a relayed channel
  • Members of the channel where /scrim or /recrute is used (public reply of the command)
  • Members of the refereeing role of each server that has set one (/set-referee-role), for the site's refereeing alerts
  • Members of partner servers, who read the relayed announcements
  • Administrators of any server where the bot is installed (including a server created to invite it there) and holders of the bot administration role (/set-bot-admin), for the network's list of exclusions (/ban-list, reply visible only to the requester) — the exclusion applies to the whole network, each server must know who can no longer post there
  • Discord (execution platform)
Transfers outside the EUUnited States: Discord — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires

T09 Backups

Main purposeResuming activity after an outage, corruption or a handling error
Sub-purposes
  • Weekly archive of the site's and the bot's databases
  • Hourly copy of uploaded images (avatars, logos, photos)
  • Log of account deletions, replayed after any restoration
Legal basisLegitimate interest (continuity of the service)
Data subjectsAll the persons of the register's other processing activities
Data
  • Copy of all the data above
  • Deletion log: account identifier and creation date, date of deletion
Sensitive dataNone
Retention
  • Archives: 30 days at most, then permanent deletion
  • Images: for as long as they are on the site (removed within the hour following their deletion)
  • Deletion log: 60 days per entry
  • Copy of the bot's database written next to it before a restoration (unencrypted, on the bot's machine): deleted at the next successful restoration, at the latest during the night after it turns 30 days old
Recipients
  • Keryan Houssin, the association's technical manager and the site's host (processor — processing agreement (GDPR, art. 28) drafted, awaiting signature by the association and the host), sole holder of the decryption keys
  • Hetzner Online GmbH (Germany), Storage Share service, sub-processor of the association through the site's host, who accepted its data processing agreement (Data Processing Agreement, version 1.2) on October 1, 2026; processing exclusively in the European Union or the European Economic Area, which stores the encrypted copies without being able to read them
Transfers outside the EUNone
Security
  • Encryption on the site's server before any upload (the “age” encryption tool for the archives, an rclone crypt remote for the images, the hidden logos and the log — checked in production on September 30, 2026, maintained for storage with Hetzner): keys held only by the site's host, Keryan Houssin, and never sent to Hetzner
  • Upload encrypted in transit (HTTPS/TLS)
  • Permanent deletion, without trash or version history at the storage provider
  • Private key of the archives kept off the server; key of the images and the log on the server only, with a backup copy off the server
  • Account deletions replayed before any return to service after a restoration

T10 Informing players of policy changes

Main purposeInforming each account of a change in the processing of its data
Sub-purposes
  • Presenting at the next visit the published changes the account has not yet acknowledged (“I have read this” — no agreement is requested)
  • Announcing each change once by Discord direct message to reachable accounts that have not acknowledged it on the site, one week after its publication and at most one message per month
Legal basisLegal obligation to inform (GDPR, articles 12 to 14)
Data subjectsPlayers registered on the site
Data
  • Changes acknowledged by the account, with the date
  • Discord announcements already sent to the account, with their date
  • Discord identifier or certified Discord username, to address the announcement
Sensitive dataNone
RetentionLifetime of the account (erased with it)
Recipients
  • The player themselves
  • Discord, which delivers the direct message
Transfers outside the EUUnited States: Discord (delivery of direct messages) — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • An announcement reserved before sending, so that no account receives it twice

T11 Reports, appeals and moderation of content and accounts

Main purposeReceiving and handling the reports sent to the association, including notices of illegal content
Sub-purposes
  • Receiving a report from anyone, with or without an account (copyright, moderation, bug, GDPR, host, other)
  • Notifying the players and team members targeted, and allowing them to contest; allowing the author of a report to contest the decision taken
  • Hiding a reported team logo or player avatar, then restoring it or permanently deleting it; removing an image outside any report, on a reason entered by moderation
  • Suspending an account contrary to the terms of use (sessions closed, login refused during the suspension), giving its holder the reasons, then lifting it or letting it expire
  • Acknowledging receipt of a notice of illegal content, then notifying its author of the decision and the means of redress
  • Answering requests to exercise rights and requests sent to the hosting provider, including those from authorities
  • Receiving by email or by phone, through the person to contact for requests regarding data, requests to exercise rights and questions about data processing, and answering them
  • Receiving the requests sent to the association's own email or phone (published, protected, in the legal notice), and answering them
  • Alerting administrators on Discord, without naming anyone
Legal basisLegitimate interest (GDPR, art. 6.1.f) of the association in enforcing its terms of use for the moderation of content and accounts contrary to them — review, hiding, removal of an image, suspension of an account, and keeping the decision while it can be contested; legal obligation (GDPR, art. 6.1.c) for requests to exercise rights (GDPR, art. 12), notices of illegal content, in copyright as in moderation (Regulation (EU) 2022/2065, art. 16), requests sent to the hosting provider (art. 11 and 16) and appeals (art. 20), without an agreement box; consent of the reporter (box when sending) for bug and other reports; by email or by phone as through the form (“GDPR” category, « RGPD »), a request to exercise rights or a question about the processing of one's data — which falls under the right of access (GDPR, art. 15) — is based on the same legal obligation
Data subjects
  • Reporters, users or not (rights holders, representatives, visitors)
  • Players and team members targeted by a report
  • Persons, members or not, who send a request regarding their data by email or by phone
  • Persons who write to or phone the association
Data
  • Category, description, items designated and page the report came from
  • Reporter's account if logged in; email address they provide; for copyright, the name or corporate name of its author, their email address, their capacity (rights holder, representative or third party), the content concerned and where to see it on the site, the reason for the request and a statement of good faith
  • Appeals: text, account of their author and optional address
  • Hidden team logos and player avatars (file kept offline), date of hiding and of the deadline; reason for a removal decided outside a report (sent to the team or the player, not kept by the site)
  • Account suspensions: account targeted, facts relied on, clause invoked, dates of start, expiry and lifting, moderation member who imposed or lifted it
  • Requests regarding data received by email or by phone: content of the request and of the reply, sender's email address or number, and often their name
  • Requests received at the association's email or phone: same data
Sensitive dataNone
Retention
  • Report and appeals: duration of handling, then 30 days after archiving (6 calendar months for a copyright or moderation report sent from an account, its author's period for contesting) — extended as long as a logo or avatar hidden or deleted on the basis of the report can still be contested (6 months at most after the decision)
  • Request received by email or by phone: same rule as a GDPR request made through the form — duration of handling, then 30 days after the request is closed (the equivalent of archiving a report), before deletion from the mailbox of the person to contact (email) or from their phone (texts received and sent, voicemail, call log)
  • Request received at the association's email or phone: same rule — duration of handling, then 30 days after it is closed, before deletion from the association's mailbox or phone
  • Hidden logo or avatar: 6 months at most without a challenge (period for contesting of art. 20.1 of Regulation (EU) 2022/2065, which the association applies), then permanent deletion; if contested, until the decision
  • Account suspension: while it runs, then 6 months after it is lifted or expires (same period for contesting), erased at the first login to the site after that period; erased with the account, or when it is anonymized
Recipients
  • The association's administrators
  • Players and team members targeted: reason and description of the report, never the reporter's identity
  • Holder of a suspended account: the decision, the facts relied on and the clause invoked, never the name of the moderation member who imposed it
  • Discord, which delivers the alerts and direct messages (without name, address or description)
  • Keryan Houssin, technical host of the site, the person appointed by the association for requests regarding data: requests received by email or by phone
  • That person's telephone operator: requests made by phone (call, text, voicemail)
  • Microsoft, which hosts that person's mailbox (personal Microsoft account (Outlook.com), governed by the Microsoft Services Agreement and the Microsoft privacy statement, without a processing agreement; storage location not guaranteed by Microsoft; messages not encrypted by the association, readable by Microsoft): requests received and replies sent by email
  • Members of the association's board who check its email and phone
  • Google (the association's Gmail mailbox, hosted by Google; messages not encrypted by the association, readable by Google): requests received and replies sent by the association's email
  • Telephone operator of the association's line: requests made to its phone
Transfers outside the EU
  • United States: Discord (delivery of alerts and direct messages) — Discord, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
  • Possible to the United States: Microsoft (Outlook.com mailbox of the person to contact, requests received and replies sent by email) — Microsoft, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
  • Possible to the United States: Google (the association's Gmail mailbox) — Google, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Handling panel restricted to administrators; a report's page open only to the persons targeted
  • Sending limits per person and per hour
  • Hidden logo or avatar moved out of the folder served by the site; preview restricted to administrators
  • Suspension restricted to the moderation permission, impossible on one's own account or on an administrator's; the staff's Discord log carries neither the player's username nor the reason
  • Requests received by email or by phone: no measure specific to the association beyond deletion after the retention period; they are protected only by the measures of Microsoft or Google (mailboxes), the telephone operators and the devices that receive them

T12 Push notifications

Main purposeNotifying a player on their devices, at their request, of what concerns them on the site
Sub-purposes
  • Start of their matches, score to confirm, tournament kick-off, match reminders
  • Requests to join a team they manage, reports and moderation decisions concerning them, changes to the data policy
  • Refereeing and moderation alerts for the staff holding these roles
Legal basisConsent (activation on each device, withdrawable at any time, topic by topic)
Data subjectsRegistered players who turn on notifications on a device
Data
  • The device's subscription address, provided by the browser, and its encryption keys
  • Date of subscription and of the last notification delivered
  • Notification topics turned off by the account
Sensitive dataNone
Retention
  • Subscription: until it is turned off, revoked by the browser, or the account is deleted
  • Subscription with no notification delivered: 180 days at most
  • Topics turned off: lifetime of the account
Recipients
  • The player themselves
  • Their browser's push service (Google, Mozilla, Apple or Microsoft), which delivers an encrypted message it cannot read
Transfers outside the EUUnited States: push service of the browser chosen by the player, which only receives end-to-end encrypted messages (RFC 8291) — Google, Mozilla, Apple and Microsoft, certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework)
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Content encrypted for the subscribed device only; sendings signed by the site's key (VAPID)
  • No player username in a notification
  • Accepted push services limited to those of the browsers on the market

T13 Acceptance of the terms of use

Main purposeKeeping proof that the site's terms of use have been accepted, and which version of them
Sub-purposes
  • Collecting acceptance when the account is created, when a team is created and when the management of a team is received
  • Asking for acceptance again when the terms change version
Legal basisPerformance of the service requested by the player (contract)
Data subjectsPlayers registered on the site
DataVersion accepted, context of the acceptance (account creation, login, team creation or management), date
Sensitive dataNone
Retention
  • Lifetime of the account
  • On deletion: complete erasure, whether the account is erased or anonymized — the details of the acceptances as well as the last version accepted and its date
Recipients
  • The player themselves, through the export of their data
  • The association's technical manager, who administers the database
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires

T14 Connection data log

Main purposeKeeping the data that makes it possible to identify the author of content published by a member (logo, avatar, team name), which the association hosts
Sub-purposes
  • Recording each login (IP address, date and time, means of logging in)
  • Disclosing this data to a judicial authority that requests it, and to it alone
Legal basisLegal obligation (GDPR, art. 6.1.c) of the hosting provider of content: French Act on Confidence in the Digital Economy (« loi pour la confiance dans l'économie numérique », LCEN), art. 6; Decree No. 2021-1362
Data subjectsPlayers registered on the site
Data
  • Internal identifier of the account
  • IP address of the login, as retained by the site's proxy server
  • Date and time of the login, means of logging in (Google, Discord, Blizzard or code by direct message)
  • Neither the source port of the connection, nor a log of the creation or modification of content (only logins are recorded), nor the information provided when the account was created: that leaves with the account (apart from the encrypted backup copies and the deletion log, T09)
Sensitive dataNone
Retention
  • 365 days (one year) after each login, then automatic erasure
  • Kept until that deadline even after the account is deleted (GDPR, art. 17.3.b)
Recipients
  • Judicial authorities, upon requisition
  • The player themselves, through the export of their data, as long as their account exists
  • The association's technical manager, who administers the database and answers judicial requisitions
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • No screen or route of the site consults this log; it serves no other purpose

T15 Support portal (Spiceworks)

Main purposeReceiving and handling support and moderation requests that do not concern content on the site (in-match behavior, insults, cheating, dispute on Discord)
Sub-purposes
  • Receiving a ticket on the association's support portal, which the site only links to (no data is sent there by the site)
  • Exchanging with the requester, examining the request and closing it
Legal basisLegitimate interest (GDPR, art. 6.1.f) of the association in enforcing the rules of its tournaments and its community, and in answering the requests sent to it
Data subjects
  • Requesters (players or not)
  • Persons named in a ticket
Data
  • Content of the ticket and of the exchanges, any attachments
  • Contact details the requester provides to receive the reply, usernames mentioned
Sensitive dataNone
RetentionTicket: duration of its handling, then 1 month after it is closed, then deletion by the association
Recipients
  • Members of the association's staff in charge of support and moderation
  • Spiceworks, which hosts the portal (a processor of the association, under Spiceworks' data processing agreement (Data Processing Agreement))
Transfers outside the EUPossible to the United States: Spiceworks — Spiceworks (Ziff Davis, Inc.), certified under the EU-U.S. Data Privacy Framework: European Commission adequacy decision (EU) 2023/1795 of 10 July 2023 (EU-U.S. Data Privacy Framework); as a fallback, standard contractual clauses of the European Commission (art. 46 GDPR) contained in Spiceworks' data processing agreement
Security
  • Access to the portal restricted to the staff members in charge of support
  • Deletion of closed tickets at the end of the retention period

T16 Match streaming

Main purposeStreaming tournament matches live and keeping the replay
Sub-purposes
  • Streaming a match live on the association's channel or a caster's (YouTube, Twitch or Kick)
  • Publishing the link to its YouTube replay on the match page
Legal basisLegitimate interest (GDPR, art. 6.1.f) of the association in promoting its competitions, the purpose set out in its bylaws; right to object (art. 21) open to each player
Data subjects
  • Players of the streamed matches
  • Casters
Data
  • In-game and site usernames, team names, images of the game, in-game results and performance, as they appear on screen — neither webcam nor voice chat of the players
  • Voice and username of the casters
  • Link to the stream and replay of a match
Sensitive dataNone
Retention
  • Live: nothing kept by the site, which only keeps the link to the channel
  • Replay link: kept with the match, like its results (T03); the video stays on the platform until it is deleted by the channel that published it
  • Right to object: on request (“Report a problem” form, “GDPR” category (« RGPD »)), the player appears under a neutral name in subsequent streams, the replay link is removed from the site, and a video published by the association's channel is hidden or deleted
Recipients
  • Public of the streaming platforms and of the site
  • Streaming platforms (YouTube, Twitch, Kick), controllers of their own processing, including of their viewers' data; the site only links to the channels and embeds no player, it sends them no data
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Stream links limited to a list of platforms, no embedded player; no contact data displayed on screen by the site
  • No webcam or voice chat of the players on screen

T17 Web server access logs

Main purposeEnsuring the server's security and diagnosing outages
Sub-purposes
  • Recording each request received by the site's proxy server (nginx)
  • Detecting attacks and abuse, understanding an outage
Legal basisLegitimate interest (GDPR, art. 6.1.f): security of the service (art. 32)
Data subjectsVisitors of the site
DataIP address, date and time, page requested, response code, response size, referring page and browser (nginx's default log format)
Sensitive dataNone
Retention14 days at most, by automatic rotation, then deletion
RecipientsThe association's technical manager, who is also the site's host
Transfers outside the EUNone
Security
  • Server access restricted to the technical manager (SSH key authentication, automatic banning of failed attempts)
  • Encrypted communications (HTTPS)
  • Role-based administration rights, limited to what each task requires
  • Logs readable only by the server's administrator, never exposed by the site
Record of processing activities · BlueGenji Esport