Legal

Privacy Policy

Last updated: 2026-09-11. This policy explains how Nordic Daggers eSport processes personal data when you use the player portal. We follow the EU General Data Protection Regulation (GDPR, 2016/679) and the Swedish Data Protection Act (2018:218).

Sammanfattning på svenska

  • Ansvarig: Hugo Caesar, privatperson i Sverige. Kontakta oss via Discord (se avsnitt 1).
  • Uppgifter vi sparar: ditt Discord-ID, användarnamn, visningsnamn och profilbild, ditt Riot-ID (League of Legends-namn), din roll, lag och lane, dina tillgänglighetssvar, när du senast öppnade portalen, samt vilka scrims/matcher du lagt upp via Discord-botten.
  • Varför: för att driva lagets stängda portal och planera träningar och matcher (berättigat intresse, art. 6.1 f).
  • Vem ser det: bara inloggade, whitelistade lagmedlemmar. Inget är publikt. Vi säljer inget, har ingen reklam och ingen spårning.
  • Hur länge: tillgänglighetssvar raderas efter 60 dagar, matcher efter 12 månader, allt annat raderas automatiskt när du tas bort från laget.
  • Dina rättigheter: ladda ner dina uppgifter på /api/me/export, radera dina tillgänglighetssvar själv, eller be oss radera allt. Du kan klaga hos Integritetsskyddsmyndigheten (IMY).

Den fullständiga policyn nedan är på engelska. Fråga oss på Discord om något är oklart.

1. Who is responsible (data controller)

Hugo Caesar, a private individual running the site for the ND eSport team, Sweden. This site is run privately and not by a company or association. You can reach the controller via:

2. What data we process, why, and on what legal basis

DataSourcePurposeLegal basis (GDPR Art. 6)
Discord user IDDiscord, when you log inIdentify you and check whether you are on the team whitelistLegitimate interest (Art. 6(1)(f)) — running a members-only team portal
Discord username and display nameDiscord, when you log inShow who is logged in inside the portalLegitimate interest (Art. 6(1)(f))
Discord avatar URLDiscord, when you log inShow your profile picture inside the portalLegitimate interest (Art. 6(1)(f))
Whitelist entry: your Discord ID, an optional short note written by the admin who added you (e.g. “new jungler”), which admin added you and whenA team admin, before or after your first loginDecide whether you may enter the portal; let admins see who they have invitedLegitimate interest (Art. 6(1)(f))
Availability (which hours you marked as can play / maybe / can’t)You, in the Availability calendarPlan scrims and matches; shown to other whitelisted team membersLegitimate interest (Art. 6(1)(f)) — coordinating the team
Discord ID, username, display name and avatar (stored copy), and the time you last opened the portalDiscord, saved when you open the portalShow your name next to your availability in the team view; show admins who is activeLegitimate interest (Art. 6(1)(f))
Team role (admin / coach / player / substitute), team and laneSet by a team adminOrganise the roster; shown to other whitelisted membersLegitimate interest (Art. 6(1)(f)) — running the team
League of Legends Riot ID (name#tag)You, or a team adminIdentify you in game for scrims and reviews; shown to other whitelisted members with a link to the public op.gg profileLegitimate interest (Art. 6(1)(f)) — running the team
Scrim and match events: title, opponent, time, notes, the opponent’s roster as free text (in-game names), and the Discord name of the member who posted or cancelled the eventOur Discord bot, when a member creates or cancels a match in DiscordShow the schedule in the portal and prepare for gamesLegitimate interest (Art. 6(1)(f)) — scheduling and preparing for games
IP address, browser type, request logsYour device, automaticallySecurity, abuse prevention and keeping the service runningLegitimate interest (Art. 6(1)(f))

We request only the identify scope from Discord. We do not receive your email address, your Discord friends, servers, or messages. You are not required by law or contract to give us any data, but the portal cannot work without a Discord login. We make no automated decisions with legal effect about you — the whitelist is a simple list maintained by hand.

Opponent players: match events may list the in-game names of players on other teams. These come from public match announcements, are visible only to our whitelisted members, and are deleted with the event. If you are an opponent player and want your name removed, contact us.

3. Where your data is stored and for how long

  • Your login session is stored in an encrypted cookie in your own browser. It expires after 7 days or when you sign out. We do not keep a copy of your session on our servers.
  • Your whitelist entry, the stored copy of your Discord name and avatar, your Riot ID, role, team and lane are kept in a database on our server in Sweden for as long as you are a member of the team. When an admin removes you from the whitelist, all of it is deleted automatically, and your name is removed from any match events you posted.
  • Availability answers older than 60 days are deleted automatically. You can also delete all of them yourself at any time.
  • Scrim and match events, including opponent rosters, are deleted 12 months after the event.
  • Server request logs, if enabled by our hosting provider, are kept for at most 30 days for security purposes.
  • Database backups are kept in the EU/EEA for at most 30 days, so deleted data disappears from backups within that time.
  • The service is hosted on Oracle Cloud Infrastructure (Oracle Corporation) in the eu-stockholm-1 region, so the server and database are physically located in Sweden (EU/EEA).

4. Who we share data with

  • Discord Inc. (USA) — provides the login. When you click “Login with Discord” you are sent to Discord, which processes your data under its own privacy policy. In addition, profile pictures inside the portal are loaded directly from Discord’s servers (cdn.discordapp.com), so your IP address is sent to Discord each time you open a portal page. Discord is certified under the EU-US Data Privacy Framework, which the EU Commission has found to provide adequate protection.
  • Other whitelisted team members — can see your name, avatar, Riot ID, role, team, lane and availability answers inside the portal. Nothing is visible to the public.
  • Oracle Corporation (Oracle Cloud Infrastructure) — hosts the server and database in Oracle’s Sweden region as our data processor, under Oracle’s Data Processing Agreement. Oracle is a US company. Data stays in the EU, but if Oracle staff outside the EU need access for support or operations, that transfer is covered by Oracle’s EU-approved Binding Corporate Rules for processors and by the EU-US Data Privacy Framework.
  • op.gg — only if you click a Riot ID link. That opens op.gg’s public site in a new tab under op.gg’s own privacy policy. We send nothing to op.gg ourselves.

We do not sell personal data, use advertising networks, or use third-party analytics.

5. Your rights

Under the GDPR you have the right to:

  • Access the data we hold about you (Art. 15). While logged in you can download it at any time from /api/me/export.
  • Rectification of incorrect data (Art. 16) — your name and avatar come from Discord, so change them there. Your Riot ID you can edit yourself on the portal home page.
  • Erasure (Art. 17) — signing out deletes your session cookie immediately. You can delete all your availability answers yourself from the Availability page. To have everything else deleted, ask any admin to remove you from the whitelist, or contact us.
  • Restriction of processing (Art. 18) and objection to processing based on legitimate interest (Art. 21).
  • Data portability (Art. 20) — the export above is in machine-readable JSON.
  • Lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY): www.imy.se, or the authority in your own EU country.

To exercise any right, contact us through one of the channels listed in section 1. We respond within one month.

6. Cookies

We only use strictly necessary cookies for the login to work. See the cookie information.

7. Age

You must be at least 13 years old to use Discord and this portal (the Swedish Data Protection Act sets 13 as the age limit for children online). We have weighed the interests of younger members when choosing what to store: only game-related data, visible only to the team, with short retention periods.

8. Security

All traffic is encrypted with HTTPS. Session cookies are encrypted, HttpOnly and SameSite-restricted. Access to the whitelist and roster settings is limited to team administrators.

9. Changes

If we change this policy in a meaningful way we will update the date at the top and, where appropriate, notify you inside the portal.