1. Data Controller
The data controller responsible for the processing of your personal data on this platform is the
Blightveil Organization Administration.
If you have questions regarding this privacy disclosure, data processing activities, or wish to exercise your
statutory data protection rights, please contact our administration team via Discord or through our designated
support channels.
2. Personal Data We Collect and Legal Bases
We process personal data strictly necessary to provide authentication, role synchronization, access management,
and platform security.
| Data Category |
Description & Source |
Legal Basis (GDPR) |
| Account Credentials & Profile |
Username, Argon2 password hash (for direct sign-ins), 2FA/TOTP verification keys, display preferences,
and rank hierarchy. |
Art. 6(1)(b) Contract / Service Performance |
| Discord Identity |
Discord Snowflake ID, Discord username, avatar hash, and OAuth access tokens (obtained via Discord
OAuth2 flow). |
Art. 6(1)(b) Account Linking & Role Sync |
| TeamSpeak 3 Identifiers |
TeamSpeak Client Unique Identifier (cluid), client database ID (cldbid), and connection synchronization
status. |
Art. 6(1)(b) Voice Server Access & Permissions |
| Session Telemetry & Logs |
IP address, approximate location, device user-agent, session creation timestamps, and last active
records (via qsessions). |
Art. 6(1)(f) Legitimate Interest (Security & Rate Limiting) |
| Audit & Moderation Logs |
Administrative record changes, moderation actions, and ban enforcement records (including Discord
Snowflake IDs and TeamSpeak UIDs) maintained to enforce community rules and prevent ban evasion. |
Art. 6(1)(f) Legitimate Interest (Integrity, Security & Community Safety)
|
3. Cookies and Storage Disclosure
Our platform operates without third-party tracking, advertising pixels, or commercial analytics.
We exclusively utilize strictly necessary technical cookies:
- Session Cookie (
sessionid): Facilitates secure user authentication and maintains
login state across the portal. Retention: active session duration (up to 1 year or until logged out).
- CSRF Security Cookie (
csrftoken): Protects against Cross-Site Request Forgery
attacks when submitting forms.
- 2FA Verification State: Validates multi-factor authentication sessions.
Under Article 5(3) of the EU ePrivacy Directive, strictly necessary technical cookies do not require prior
opt-in consent because they are essential to provide the service requested by the user.
4. Third-Party Services & Infrastructure
In operating the portal and synchronizing organization services, personal data is processed in conjunction with
the following external providers:
- Discord Inc.: Used for OAuth2 authentication, identity verification, and role synchronization
bots.
- TeamSpeak Systems GmbH: Used for linking identities and synchronizing voice server
permissions.
- Content Delivery Networks (CDNs): Static assets, styling libraries (Bootstrap, Select2,
FontAwesome, Google Fonts), and JavaScript packages may be retrieved via public CDNs (cdnjs, jsDelivr, jQuery
CDN) to optimize performance. When your browser requests these assets, your IP address is transmitted to the
hosting infrastructure.
5. Your Rights Under GDPR
As a data subject located in the European Union / European Economic Area (or applicable jurisdictions), you hold
the following rights:
- Right of Access (Art. 15 GDPR): You can inspect your active sessions, account profiles, and
linked identifiers directly in the user dashboard at any time.
- Right to Rectification (Art. 16 GDPR): You may update your profile preferences, display
names, and credentials through self-service settings.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You have the right to request
deletion of your account and associated personal data upon ceasing usage of the platform. Please note that
pursuant to Article 17(3) GDPR, this right is subject to statutory exemptions: minimal
identifiers and moderation logs strictly required to enforce active administrative bans, prevent ban evasion,
and protect community safety will be retained.
- Right to Restrict or Object to Processing (Arts. 18 & 21 GDPR): You may object to data
processing based on legitimate interests.
- Right to Terminate Sessions: You can terminate active sessions on any remote device
immediately via the Active
Sessions Manager.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to file a complaint with a
competent Data Protection Authority in your EU Member State.
6. Data Retention and Deletion
Personal data is retained only for as long as necessary to fulfill organizational operations:
- Active Accounts: Retained for the duration of your membership or active usage of our
services.
- Session Telemetry: Stored dynamically in Redis/PostgreSQL and automatically cleared upon
session expiration or manual termination.
- Moderation & Ban Records: Minimal identifiers (such as Discord Snowflake IDs, TeamSpeak
client UIDs, and moderation logs) may be retained indefinitely to enforce administrative bans, prevent ban
evasion, and maintain community safety under our legitimate interests.
- Account Deletion: Upon legitimate request, user records are deleted or anonymized in
compliance with our data protection policies.
7. Age Requirements & Children's Privacy
Our services are not intended for or directed at children. In accordance with Discord's Terms of Service, the US
Children's Online Privacy Protection Act (COPPA), and Article 8 of the GDPR:
- Users must be at least 13 years of age (or the minimum legal age required in their country of
residence, up to 16 in certain EU Member States) to create an account or link Discord/TeamSpeak profiles.
- We do not knowingly collect or process personal data from individuals under the applicable minimum legal age.
If we become aware that personal data of a minor has been collected without parental consent, we will take
prompt steps to delete that account and associated records.