1. Controller
Art. 13 (1) (a) GDPR
Christoph Barton, Vienna, Austria. Full postal address: see Impressum.
Contact for data protection requests: privacy@ggez.gg
A dedicated Data Protection Officer (DPO) has not been appointed — the criteria of Art. 37 GDPR are not met (small operator, no large-scale processing of special categories).
2. Data we collect & legal basis
Art. 13 (1) (c) GDPR
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account (email/password) | Email, password hash, verification token | Art. 6 (1) (b) — contract | Until deletion |
| Google / Discord OAuth login | Provider sub-ID, email, display name | Art. 6 (1) (b) — contract | Until deletion |
| Riot RSO link | PUUID, game name, tag line. The OAuth token is used during sign-in to read your account and is not stored. | Art. 6 (1) (b) | Until unlink/deletion |
| Login session | Session ID (httpOnly cookie), user ID | Art. 6 (1) (f) — security; § 25 (2) TDDDG | 30 days rolling |
| League of Legends match data (you & opponents) | Match results, items, KDA, timeline events (Riot API) | Art. 6 (1) (f) — legitimate interest in providing stats tracker | Cache 14 days, aggregates indefinitely |
| Teamfight Tactics match data | Ranked match results of high-elo players (PUUID, placement, units, items) — used only in aggregate for the team-comp tier list | Art. 6 (1) (f) — legitimate interest | Aggregated snapshot only; raw responses not stored |
| VALORANT match data (your own matches) | Match results, scoreboard, and the round positions Riot records at each kill, spike plant and defuse (PUUID, Riot ID, agent, map). Loaded only after you sign in with Riot, and only for matches you played in. | Art. 6 (1) (a)/(b) — your Riot Sign-On consent | Cache 24 h (matches), 5 min (match list) |
| Drawings on the round map | Your pen, arrow and circle marks, and any markers you move | § 25 (2) TDDDG — strictly necessary for the feature you requested | Stored only in your browser (localStorage); never transmitted to us |
| AI Coach chat | Your messages, tool-call results, AI responses | Art. 6 (1) (b) — service delivery; (a) for memory | 90 days (conversation), 12 months (memory) |
| AI Coach usage analytics | Per message: the message text, which surface it came from, interface language, country (derived by Cloudflare from the connection, not stored as an IP address), Riot region, PUUID if your account is linked, which data tools ran, whether the answer succeeded, and how long it took. A random browser ID is added only if you consented to analytics; without it the entry cannot be linked to your other visits. | Art. 6 (1) (f) — legitimate interest in measuring and fixing the feature | 90 days |
| Visit counter | Each page load adds 1 to a daily counter for the kind of page you landed on. Nothing about you is stored with it. Only if you consented to analytics, your browser keeps a small record (first and last visit day, number of visit days, in localStorage) so the counter can tell new from returning visitors; that record never leaves your browser, only the resulting "new" or "returning" is counted. | Art. 6 (1) (f) — legitimate interest in knowing how the site is used; § 25 (1) TDDDG consent for the browser record | Daily totals indefinitely; browser record until you clear it |
| Rate-limiting / security | IP address (hashed/short-lived), user agent | Art. 6 (1) (f) — security | Max 7 days |
| Cookie consent | Choice + timestamp (localStorage) | § 25 (2) TDDDG | 12 months |
3. Third-party processors
Art. 13 (1) (e), Art. 28 GDPR
We have data processing agreements (DPA / AVV gem. Art. 28 GDPR) with all processors below:
- Cloudflare, Inc. (USA + global edge) — Hosting (Pages, Workers), CDN, D1 database, KV cache, DDoS protection, Turnstile bot check on login, sign-up and the contact form, Email Routing for our @ggez.gg addresses. Standard Contractual Clauses + EU-US Data Privacy Framework.
- Resend (Plus Five Five, Inc.) (USA) — sends our emails: account verification, password reset and contact-form messages. SCCs + DPF.
- Turso (ChiselStrike, Inc.) (EU region) — libSQL user database.
- OpenAI, L.L.C. (USA) — AI Coach chat completion (model gpt-4o-mini). Your chat messages, match data and selected profile data are transmitted to OpenAI in the USA. Transfer mechanism: SCCs + DPF. OpenAI does not use API data to train models per their data usage policy.
- Anthropic, PBC (USA) — fallback / experimental AI features. SCCs + DPF.
- Riot Games, Inc. (USA) — Riot Sign-On (RSO) and the game APIs we use: Account-V1, Match-V5 and Spectator-V5 (League of Legends), TFT-Match-V1 and TFT-League-V1 (Teamfight Tactics), VAL-Match-V1 and VAL-Content-V1 (VALORANT). When you link your Riot account, your PUUID and OAuth tokens are exchanged with Riot. VALORANT match data is requested only for the account you signed in with.
- valorant-api.com (community project, not a processor) — agent and map artwork plus static map metadata. Images are loaded by your browser from that domain, so it receives your IP address; no account data of yours is sent.
- Google LLC (USA) — Google OAuth login (if used). SCCs + DPF.
- Discord, Inc. (USA) — Discord OAuth login (if used). SCCs.
4. International transfers
Art. 13 (1) (f), Art. 44-49 GDPR
Transfers to the USA (Cloudflare, OpenAI, Anthropic, Riot, Google, Discord) take place on the basis of Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and, where available, the EU-US Data Privacy Framework (Art. 45 adequacy decision, 10 July 2023).
5. AI Coach — automated processing
Art. 22, Art. 13 (2) (f) GDPR
The AI Coach analyses your match data and generates recommendations using a large language model (OpenAI gpt-4o-mini). This is not an automated decision with legal effect within the meaning of Art. 22 GDPR — recommendations are advisory and do not affect any contract, ranking or legal status. Inputs to the AI are processed in the USA; do not enter sensitive personal data into the chat.
6. Match data of other players
Art. 6 (1) (f), Art. 14 GDPR
To deliver tier lists, opponent stats, OTP (one-trick) detection and matchup analysis, we process publicly available match data from the Riot API which contains other players' game names and PUUIDs. Legal basis: legitimate interest in operating a community stats tracker (Art. 6 (1) (f)). The interest is balanced by: (i) data is provided by Riot via a public API that players consent to under Riot's ToS; (ii) we store no contact data; (iii) any player may request erasure of their data from our caches by emailing privacy@ggez.gg.
6a. Pro players and streamers
Art. 6 (1) (f), Art. 14, Art. 21 GDPR
On leaderboards and profiles we show when a Riot account belongs to a professional player or a streamer: their esports handle, current team and stream channel (Twitch, SOOP, CHZZK). We store only the Riot ID, the handle and the channel name — no real names, no contact data. The link between account and person comes from public community sources: lolpros.gg, Leaguepedia (CC BY-SA 3.0), onetricks.gg, trackingthepros.com, deeplol.gg and the players' own channel pages; teams and lineups come live from the official LoL Esports API. Legal basis: legitimate interest in showing who is who on a public ranked ladder, as other stats sites do (Art. 6 (1) (f)); the data is already public and concerns people in their public role as players or streamers.
Objection: if this is you and you don't want the link shown, press "That's you? Remove" on your profile while signed in with that Riot account — all your known accounts are unlinked at once and stay unlinked on future imports. Without a Riot sign-in, email privacy@ggez.gg and we remove it within 30 days (Art. 21, Art. 12 (3)).
6b. Contact form
Art. 6 (1) (b), (f) GDPR
When you use the contact form, your email address, the optional name and Riot ID and your message are sent to us as an email through our mail provider Resend and are not stored on ggez.gg. We use them only to answer you and delete the mail when the matter is closed. Cloudflare Turnstile checks that the form is sent by a person; it processes technical data such as your IP address and browser characteristics and sets no advertising cookies.
7. Riot account link & VALORANT data
Art. 7, Art. 13 (2) (c) GDPR
Linking your Riot account is optional and everything on ggez.gg works without it. If you link it, we store your PUUID, Riot game name and tag line. The OAuth token issued by Riot is used during sign-in to identify your account and is not kept afterwards. We never see or receive your Riot password.
For VALORANT we request only your own matches. A match is loaded only if your PUUID is one of its participants. Riot's match data includes the position of each player at every kill, spike plant and defuse; we use those positions to draw the round on the map. Match responses are cached for 24 hours and match lists for 5 minutes, after which they expire automatically. We do not build a searchable database of other players' VALORANT matches.
Withdrawing consent: you can unlink your Riot account at any time in your profile settings, or by emailing privacy@ggez.gg. Unlinking clears the PUUID, Riot ID and any token fields on your record; cached match data expires on its own within 24 hours and is not renewed. Withdrawal does not affect the lawfulness of processing before it (Art. 7 (3)).
9. Your rights
Art. 15-22, 77 GDPR
- Access (Art. 15) — request a copy of your stored data
- Rectification (Art. 16) — correct inaccurate data
- Erasure / "right to be forgotten" (Art. 17) — delete your account & data via Profile → Delete Account, or by email
- Restriction (Art. 18) — limit processing
- Data portability (Art. 20) — export your data via Profile → Export My Data (JSON)
- Objection (Art. 21) — object to processing based on legitimate interest
- Withdraw consent (Art. 7 (3)) — without affecting prior lawfulness
- Lodge a complaint with the supervisory authority (Art. 77) — Austrian Datenschutzbehörde (DSB), or in Germany the BfDI / your state authority
To exercise any right, contact privacy@ggez.gg. We respond within 30 days (Art. 12 (3)).
10. Minors
Art. 8 GDPR
Our service is not directed at children under 16. If you are under 16, please use the platform only with verifiable consent of a parent/guardian. We do not knowingly collect data from children under 16 without such consent — contact us if you believe we hold such data.
11. Security
Art. 32 GDPR
TLS encryption in transit, password hashing (Argon2id), database access tokens, principle of least privilege. No system is perfectly secure — please report vulnerabilities responsibly to privacy@ggez.gg.