sofasports

Legal

Privacy Policy

Hosted in the EU and aligned with GDPR. Here is what we collect, why, and how to control it.

Last updated: 14 September 2026

Servers in the EU · GDPR aligned

Your account and community data are stored on servers in the European Union. We process personal data under the UK GDPR and EU GDPR, rely on clear lawful bases, keep retention short, and honour access, erasure and portability requests at privacy@sofasports.co.uk.

1. Overview

sofasports (www.sofasports.co.uk) is an independent esports community site. This policy explains what personal data we collect, why, how long we keep it, and the rights you have under the UK General Data Protection Regulation and the EU General Data Protection Regulation (together, “GDPR”).

Data controller: sofasports. Privacy contact: privacy@sofasports.co.uk. If you are in the UK or EEA you also have the right to complain to your supervisory authority (in the UK, the Information Commissioner's Office; in the EEA, your national authority).

2. Where your data lives

Our application and database servers are hosted in the European Union. Your account data, forum posts, team pages and session records are stored and processed in the EU.

We choose EU-region hosting so your data benefits from GDPR protections by default. Some support processors (for example email delivery or OAuth sign-in) may process limited data outside the EU/EEA — where that happens we rely on an adequacy decision or Standard Contractual Clauses, as described below.

3. Data we collect

Account data: username, email address, password hash (for email sign-up), profile details you add, and linked OAuth account identifiers if you sign in with Discord, Google or Microsoft.

Community content: forum posts, team pages, roster applications and moderation records tied to your account.

Technical and security data: session tokens, device and browser basics, IP address, login and password-reset events, and error logs used to keep the service safe and working.

Preferences and notifications: notification settings and in-app notification history.

We do not intentionally collect special-category data. Please do not post sensitive personal details about yourself or others in public areas.

4. Why we use it (lawful bases)

Contract — to provide the service you asked for: creating and running your account, showing your posts and teams, and sending service emails such as password resets.

Legitimate interests — to keep the community safe and the site working: moderation, abuse prevention, security logging, and improving rankings, fixtures and performance.

Consent — for optional things such as marketing emails (we only send them if you opt in) and certain cookies or analytics where consent is required. You can withdraw consent at any time.

Legal obligation — where we must retain or disclose records to comply with law.

Team activity emails (applications, decisions, withdrawals and removals) are transactional, sent under contract/legitimate interests rather than consent, and every one links your profile where you can switch them off. In-app notifications always send regardless.

5. Who we share it with

Hosting and database: our EU-hosted infrastructure providers, acting as processors on our instructions.

Email delivery: Resend, used to send transactional emails such as password resets. Only the minimum needed (address, message content) is shared.

OAuth sign-in (only if you use it): Discord, Google or Microsoft, to verify your identity. They receive the standard OAuth request; we receive a verified identifier and basic profile details you approve.

Esports data: PandaScore, for fixtures and results. This is generally non-personal match data, not your account data.

We do not sell your personal data. We disclose data to authorities only where required by law.

6. International transfers

Our core servers are in the EU. Where a processor operates outside the UK/EEA (for example a US-based email or OAuth provider), transfers are protected by an adequacy decision where one exists, or by Standard Contractual Clauses plus appropriate safeguards.

You can ask us for details of the transfer mechanism used for a specific provider.

7. How long we keep data

Accounts: kept while your account is active. If you delete your account we remove or anonymise your profile and credentials; public forum posts may be retained in anonymised form to preserve discussion context unless you ask us to remove them.

Security logs and backups: typically kept for up to 12 months, then deleted or anonymised, unless needed longer for an ongoing abuse or legal matter.

Marketing preferences: kept until you unsubscribe or withdraw consent.

8. Your rights

Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, plus rights around automated decision-making (we do not make solely automated decisions with legal effect).

To exercise any right, email privacy@sofasports.co.uk from your account address. We will respond within one month (extendable by two months for complex requests).

You can also update your username and profile in-app, unsubscribe from marketing via the link in any message, and manage OAuth links in your provider settings.

9. Cookies and sessions

We use strictly necessary cookies and storage for sign-in sessions, security (such as CSRF protection), and remembering preferences. These do not require consent.

If we add optional analytics or embedded media that set non-essential cookies, we will ask for consent first and let you change your choice at any time.

10. Children

sofasports is not directed at children under 13 (or the higher minimum age in your country). If you believe a child has created an account, contact us and we will review and remove it where appropriate.

11. Security

We use hashed passwords, encrypted connections (HTTPS), scoped server credentials, and least-privilege access to production data. No system is perfectly secure, so please use a unique password and keep your OAuth accounts protected.

If we become aware of a personal-data breach that risks your rights, we will notify the relevant authority within 72 hours where required and inform affected users without undue delay.

12. Changes and contact

We may update this policy as the site evolves. Material changes will be flagged on the site; the “last updated” date below always shows the current version.

Last updated: 14 September 2026.

Privacy queries or rights requests: privacy@sofasports.co.uk. General support: support@sofasports.co.uk.

Related: Terms of Service