This counsel-review draft maps the personal-data processing visible in the Scrimlog frontend. Hosting, database, email, backup and backend-retention facts still require operator confirmation.
Controller: [COUNSEL/OPERATOR: full legal name and legal form], [registered street address], [postal code and city], Austria.
Privacy contact: [OPERATOR: working privacy email]. Telephone or other rapid contact: [OPERATOR: insert]. Data protection officer: [insert contact if appointed; otherwise state that no DPO has been appointed after counsel confirms this is correct].
This notice covers the public website, accounts, authentication, teams, replay upload and analytics, draft tools, billing, support and security logging.
Scrimlog acts as controller for account administration, authentication, billing, platform security, legal compliance and its own service operations. [COUNSEL: determine whether Scrimlog acts as a processor for replay, roster, notes and team analytics where a team customer determines the purpose of processing. If so, offer an Article 28 GDPR data-processing agreement and a subprocessor list.]
Account and profile data can include username, email address, password verifier, internal user identifier, role, account status, selected language and linked Steam or Dota account identifier.
Team data can include team name and slug, Dota team identifier, logo URL, team membership, roles, invitations, joining dates, linked player identifiers, team ownership, opponent names and match notes.
Uploaded and submitted data can include replay files, match identifiers, match URLs, tags and information entered into team-scoped tools. Replay-derived analytics can include player names or identifiers, hero and item selections, performance, positions, events, inventories, wards, couriers and other gameplay statistics.
Billing data can include plan, entitlement, Stripe customer and subscription identifiers, status, trial and renewal dates, invoices and transaction or tax information. Payment-card details are entered into Stripe’s hosted or embedded checkout and should not be received by Scrimlog directly.
Communications data can include support, privacy, security and legal requests and related correspondence. [OPERATOR: add every production support/email channel.]
Google or Steam may provide account identifiers and profile information during OAuth sign-in according to the permissions shown in their flow. [OPERATOR: list the exact scopes and returned fields for each provider.]
Replay and match data is provided by uploaders or obtained through supported public match identifiers and can concern players who do not have a Scrimlog account. Team managers or coaches can provide identifiers, roles, opponent names and notes concerning other people.
Stripe provides subscription, checkout, invoice, payment-status and fraud-prevention information. Infrastructure and security providers can provide IP address, request, device and diagnostic information.
[COUNSEL: complete the GDPR Article 14 assessment for non-user players and other indirectly obtained data, including the source, notice timing and any applicable exemption and safeguards.]
Contract and requested steps — create and authenticate accounts, manage teams, process replays, provide analytics, apply entitlements, provide support and fulfil paid subscriptions. Proposed basis: Article 6(1)(b) GDPR. [COUNSEL: separate user contracts from processing performed for a team customer.]
Billing, tax and accounting — create checkout sessions, administer subscriptions, collect payments, issue or retain transaction records and meet accounting obligations. Proposed bases: Article 6(1)(b) and 6(1)(c) GDPR. [OPERATOR: identify the exact Austrian retention duties.]
Security and reliable operation — prevent abuse, protect accounts, rotate sessions, diagnose errors, rate-limit requests, preserve evidence and maintain service integrity. Proposed basis: Article 6(1)(f) GDPR; legitimate interests are network, information and service security and the establishment or defence of legal claims. [COUNSEL: document the balancing test and retention limits.]
Consent-based activity — use consent where required for optional device storage, non-essential third-party components or communications. Proposed basis: Article 6(1)(a) GDPR and §165(3) TKG 2021 where applicable. Consent may be withdrawn without affecting earlier lawful processing.
[COUNSEL/OPERATOR: add or remove product analytics, marketing, newsletter, feedback, aggregated research or model-training purposes. The current policy must not authorise purposes the production service does not actually perform.]
Frontend hosting and delivery: Cloudflare [OPERATOR: insert contracting entity, product, processing location and role]. Backend/API, database, object storage, backups and Kubernetes hosting: [OPERATOR: identify every provider, entity, region and function].
Payments and subscription management: Stripe [OPERATOR: insert contracting entity and products]. Authentication: Google and Valve/Steam when the corresponding provider is selected. Dota media delivery: Valve/Steam content delivery hosts.
Fonts are currently requested from Google Fonts by visitors’ browsers. [OPERATOR: preferably self-host the fonts; otherwise identify the Google entity, data transferred, legal basis and transfer safeguard.]
Email, support, observability and log collection: [OPERATOR: identify production providers or state which functions are operated internally]. Professional advisers, auditors, insurers, courts, regulators and authorities may receive data where necessary or legally required.
Scrimlog does not sell personal data. [COUNSEL/OPERATOR: verify this statement against every vendor contract and future advertising or analytics plan.]
Some recipients may process data outside the EEA, including in the United States. For each transfer, Scrimlog must identify the recipient and rely on an applicable adequacy decision, including the EU–US Data Privacy Framework only where the recipient is currently certified, or another valid safeguard such as Standard Contractual Clauses with any required supplementary measures.
[OPERATOR: complete and maintain a transfer register for Cloudflare, Stripe, Google, Valve/Steam and all backend, support and logging providers. State how a copy of the relevant safeguard can be requested.]
Raw replay files: the public product currently promises encryption at rest and automatic deletion thirty days after parsing. [OPERATOR: verify this in production, including failed parses, replicas and backups, or correct both the product and this notice.]
Derived match and team analytics: [OPERATOR/COUNSEL: define the retention period, deletion triggers and treatment after subscription expiry, account deletion, team deletion or a member leaving.] Account and profile data: [define active-account period and post-closure period]. Security and application logs: [define period by log category]. Billing and tax records: [define statutory period]. Support and legal correspondence: [define period or criteria]. Backups: [define rotation and deletion period].
The local pending-invite entry expires after one hour. The local language preference remains until the user changes it or clears browser storage. Retention may be extended where necessary for a legal obligation, dispute or security investigation, with access restricted accordingly.
Scrimlog uses an HttpOnly refresh-token cookie to restore and protect an authenticated session. [OPERATOR: disclose its host, path, lifetime, Secure and SameSite attributes and the corresponding server-side token retention.]
The browser stores the selected language under "scrimlog.lang" and can temporarily store an invitation token and role under "shelgon_pending_invite" for up to one hour so an invite survives sign-in or registration.
Stripe’s embedded checkout and the Google or Steam authentication flows may use their own cookies or similar technologies for payment, authentication, security and fraud prevention. [OPERATOR/COUNSEL: perform a production network and storage audit, classify each item as strictly necessary or consent-requiring, and implement a consent mechanism before any non-essential access occurs.]
Authorised team members can access team-scoped roster, replay and analytics information according to their roles and entitlements. Team managers and coaches may be able to edit roles, link identifiers, enter notes and manage other members.
Where Scrimlog processes team data on a customer’s behalf, access, export, correction and deletion requests may need to be handled under that customer’s instructions. Scrimlog will assist the controller as required by the applicable data-processing agreement.
Scrimlog automatically parses replay data and generates statistics, draft scores and pick or ban suggestions. These outputs support gameplay analysis and are not used to make decisions that produce legal or similarly significant effects about a person.
[OPERATOR: verify that there is no automated account enforcement, behavioural advertising, personalised price, eligibility decision or model training. Update this section before introducing any such processing.]
Scrimlog uses technical and organisational measures intended to protect data, including access controls, short-lived access tokens, rotated refresh tokens and encryption where implemented. No online service can guarantee absolute security.
[OPERATOR/COUNSEL: verify and document encryption in transit and at rest, key management, access review, backup security, incident response, vulnerability reporting, processor controls and personal-data-breach procedures before making more specific public claims.]
Subject to the GDPR’s conditions and exceptions, a person may request access, rectification, erasure, restriction, data portability and information about processing; object to processing based on legitimate interests; and withdraw consent at any time where consent is the basis.
Requests can be sent to [OPERATOR: privacy email]. Scrimlog may need to verify identity and should respond within the applicable statutory period. [OPERATOR: implement an internal request workflow covering team-controlled data, exports, backups and recipients.]
A person may lodge a complaint with the Austrian Data Protection Authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, Austria; email dsb@dsb.gv.at; telephone +43 1 52 152-0; https://www.dsb.gv.at/. A person may also contact another competent supervisory authority, particularly in the EU Member State of habitual residence or work.
[COUNSEL/OPERATOR: define whether accounts are restricted to adults, how age is addressed in email and OAuth registration, and how parental authority is verified where required. The replay data can also concern players who are minors even when the uploader is an adult.]
Scrimlog will date material changes to this notice and provide additional notice where the change significantly affects users or requires renewed consent.
Privacy questions and requests: [OPERATOR: privacy email and postal contact]. Security reports: [OPERATOR: security contact]. General support: [OPERATOR: support contact].