DUELSFREEPRIZE DUELS
What we hold

Privacy Policy.

What DUELS collects, why, for how long, and who else touches it. It describes processing as it exists today — not processing that is planned.

Version 2.0In effect 2026-08-28Datatilsynet supervises
01

Who we are

DUELS is a skill-based competition platform operated by DUELS v/Silas Greve Abainza, a personally owned small business (PMV) registered in Denmark under CVR 46451813. We are the data controller for personal data processed through the platform.

  • Address: Nyrnberggade 22, st. tv, 2300 København S, Denmark
  • Contact for privacy and data protection: info@duels.dk

We have not appointed a Data Protection Officer. We are not required to: we are a one-person business, we carry out no large-scale monitoring, and we process no special-category data.

02

What data we collect

Everything below is data you give us, or that your use of the platform generates. We collect nothing else.

CategoryWhat it isWhere it comes from
AccountYour handle (chosen by you, publicly visible on leaderboards and match screens), your initials (derived from the handle), and an email addressYou, at registration
CredentialsA password, stored only as a hash by our authentication provider. We never see or store your passwordYou, at registration
Match historyWhich game, who you played, the result, the moves you made, the timing of those moves, and when the match started and settledGenerated server-side as you play
Match setupQueue entries and invite links you create or accept — the game, the room, and the invite tokenGenerated as you look for an opponent
Account balance recordA balance figure held against your accountGenerated at registration
Feedback (no longer collected)A three-point rating and any free text submitted through the after-match feedback box that the platform used to show. That box was removed on 28 August 2026 and nothing new is recorded. What was already submitted is still heldYou, before the box was removed
TechnicalIP address, browser and device type, and request logsAutomatically, on access
SessionA session identifier stored in a cookie so you stay signed inAutomatically, on sign-in

Two things about that table are worth stating plainly rather than leaving to be inferred.

The email address

On the surface that involves no money, the platform generates the address itself from your handle. It is not a real inbox, it is never sent anything, and it exists only because our authentication provider requires an address-shaped field. You are not asked for a real email and we do not have one. Where the platform does ask for a real email address, it is used for account recovery and service messages, and for nothing else.

The balance record

Every account carries a balance figure. No real money has ever entered or left this platform. There is no deposit path, no withdrawal path and no payment provider. The figure records progress in play only and is not convertible into anything.

What we do not collect

We say this explicitly, because the absence of a thing is easy to assume and easy to get wrong:

  • No CPR number, no legal name, no date of birth. There is no MitID or other identity verification in the product.
  • No payment card details, no bank details, no payment history. There is no payment path.
  • No analytics, tracking or advertising data. The platform contains no analytics package, no tracking pixel, no advertising identifier and no third-party cookie.
  • No location data beyond what an IP address inherently reveals.
  • No special categories of personal data (Art. 9) and no data from children.
03

Why we collect it, and the legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Creating and running your accountAccount data, credentials, sessionContract performance — Art. 6(1)(b)
Running matches, showing results and leaderboardsHandle, match historyContract performance — Art. 6(1)(b)
Finding you an opponentMatch setup dataContract performance — Art. 6(1)(b)
Detecting cheating and resolving disputesMatch history, move timing, IPLegitimate interest — Art. 6(1)(f)
Keeping the platform secure and availableTechnical data, request logsLegitimate interest — Art. 6(1)(f)
Holding feedback already submitted, until it is deletedFeedbackLegitimate interest — Art. 6(1)(f)
Keeping records the law requires us to keepAccount and match recordsLegal obligation — Art. 6(1)(c), Bogføringsloven

Legitimate interest assessments

Where we rely on legitimate interest, we have considered whether our interest is overridden by your rights, and concluded it is not:

  • Anti-cheat and dispute resolution. A 1v1 competition only works if both players can rely on the result. The processing is limited to data the match itself generates, involves no special categories, and you are told about it here before you play.
  • Security and availability. Standard server logging, minimal in scope, retained briefly, and necessary to run any service on the internet at all.
  • Feedback. It is no longer collected. What was submitted while the box existed was volunteered, was never readable by the opponent it concerned, and is retained only until it is deleted.

You can object to any of these at any time — see section 07.

04

How long we keep it

DataRetentionBasis
Account data (handle, email, credentials)For as long as the account is openContract
Match history and results2 years from the match dateDispute resolution and anti-cheat
Records that count as bookkeeping records5 years from the end of the financial year they concernBogføringsloven §10
Feedback already submittedUntil deleted, or anonymised with the account if that comes firstLegitimate interest
Technical and session logsShort-lived — cleared on our hosting providers’ own log rotationLegitimate interest

What “close my account” actually does

This is deliberate, and it is not us keeping your data because we want it. Bogføringsloven §10 requires bookkeeping records to be retained for 5 years, and GDPR Art. 17(3)(b) expressly exempts data a controller must keep to comply with a legal obligation. Erasing those records would not be privacy compliance; it would be a bookkeeping offence.

An account cannot be closed while a match is still in progress.

05

Who else processes it

Two processors, both under a data processing agreement, both in the EU:

ProcessorRoleWhat they holdLocation
SupabaseDatabase and authentication hostingAll structured platform data — accounts, credentials, matches, feedbackEU region
VercelApplication hosting and content deliveryIP address and request logsEU region where available

That is the complete list. There is no payment institution, no identity verification provider, no analytics vendor, no advertising network and no email marketing platform, because the platform uses none of those things.

We do not sell your data. We do not share personal data with anyone for marketing purposes. We will disclose data to a public authority only where we are legally required to, and we will tell you if that happens unless we are prohibited from telling you.

06

International transfers

Both processors operate within the EU/EEA. Data is not transferred outside the EU/EEA without an appropriate safeguard under GDPR Chapter V. Vercel’s content delivery network may serve static assets from outside the EU; data that identifies you is held in the EU region.

07

Your rights

Under GDPR you have the following rights, and you exercise all of them by writing to info@duels.dk:

RightWhat it means
AccessGet a copy of the personal data we hold about you
RectificationHave inaccurate data corrected
ErasureHave your data deleted, subject to the retention obligations in section 04
PortabilityReceive your data in a structured, machine-readable format
RestrictionHave us limit processing while a dispute is resolved
ObjectionObject to processing we base on legitimate interest
Withdraw consentWhere we rely on consent, withdraw it at any time — this does not affect processing already carried out

We respond within one month. If a request is complex we may extend that by two further months, and we will tell you within the first month if we do.

Where we cannot fully comply — because a record is one the law requires us to keep — we will say so plainly, tell you which record and which obligation, and delete what we can.

08

Security

  • All traffic is encrypted in transit (TLS).
  • Passwords are hashed by our authentication provider. We never see them and cannot recover them.
  • Database access is governed by row-level security: your data is readable by your own session, not by other players. Handles are public by design, because leaderboards and match screens show them.
  • Game state is rendered server-side, so a client cannot read or alter another player’s position.
  • Production credentials are not accessible outside the application.

If a breach occurs that poses a risk to individuals, we will notify Datatilsynet within 72 hours and tell affected users without undue delay.

09

Cookies

The platform sets one kind of cookie: a session cookie that keeps you signed in. It is set by our authentication provider, it is strictly necessary to provide a service you have asked for, and under the Danish cookie rules a strictly necessary cookie requires no consent banner. That is why you do not see one.

We set no analytics cookies, no advertising cookies and no third-party cookies of any kind. If that ever changes, this policy changes with it and a consent mechanism goes up before the cookie does.

10

Children

DUELS is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. As stated in section 08, the age restriction is self-declared. If you believe a minor has an account, write to info@duels.dk and we will close and anonymise it.

11

Changes to this policy

We may update this policy when the law changes or when what we do changes. Where a change is material — a new processor, a new purpose, a new category of data — we will tell you on the platform before it takes effect. The version and date at the top of this page say when it last changed.

12

Complaints

You can complain to us at info@duels.dk, and you have the right to complain to the Danish supervisory authority:

13

Governing law

This policy is governed by Danish law and the General Data Protection Regulation (EU 2016/679). Disputes arising from it are subject to Danish jurisdiction.

14

Contact

DUELS v/Silas Greve Abainza

  • CVR 46451813
  • Nyrnberggade 22, st. tv, 2300 København S, Denmark
  • info@duels.dk