Privacy Policy.
What DUELS collects, why, for how long, and who else touches it. It describes processing as it exists today — not processing that is planned.
Who we are
DUELS is a skill-based competition platform operated by DUELS v/Silas Greve Abainza, a personally owned small business (PMV) registered in Denmark under CVR 46451813. We are the data controller for personal data processed through the platform.
- Address: Nyrnberggade 22, st. tv, 2300 København S, Denmark
- Contact for privacy and data protection: info@duels.dk
We have not appointed a Data Protection Officer. We are not required to: we are a one-person business, we carry out no large-scale monitoring, and we process no special-category data.
What data we collect
Everything below is data you give us, or that your use of the platform generates. We collect nothing else.
| Category | What it is | Where it comes from |
|---|---|---|
| Account | Your handle (chosen by you, publicly visible on leaderboards and match screens), your initials (derived from the handle), and an email address | You, at registration |
| Credentials | A password, stored only as a hash by our authentication provider. We never see or store your password | You, at registration |
| Match history | Which game, who you played, the result, the moves you made, the timing of those moves, and when the match started and settled | Generated server-side as you play |
| Match setup | Queue entries and invite links you create or accept — the game, the room, and the invite token | Generated as you look for an opponent |
| Account balance record | A balance figure held against your account | Generated at registration |
| Feedback (no longer collected) | A three-point rating and any free text submitted through the after-match feedback box that the platform used to show. That box was removed on 28 August 2026 and nothing new is recorded. What was already submitted is still held | You, before the box was removed |
| Technical | IP address, browser and device type, and request logs | Automatically, on access |
| Session | A session identifier stored in a cookie so you stay signed in | Automatically, on sign-in |
Two things about that table are worth stating plainly rather than leaving to be inferred.
The email address
On the surface that involves no money, the platform generates the address itself from your handle. It is not a real inbox, it is never sent anything, and it exists only because our authentication provider requires an address-shaped field. You are not asked for a real email and we do not have one. Where the platform does ask for a real email address, it is used for account recovery and service messages, and for nothing else.
The balance record
Every account carries a balance figure. No real money has ever entered or left this platform. There is no deposit path, no withdrawal path and no payment provider. The figure records progress in play only and is not convertible into anything.
What we do not collect
We say this explicitly, because the absence of a thing is easy to assume and easy to get wrong:
- No CPR number, no legal name, no date of birth. There is no MitID or other identity verification in the product.
- No payment card details, no bank details, no payment history. There is no payment path.
- No analytics, tracking or advertising data. The platform contains no analytics package, no tracking pixel, no advertising identifier and no third-party cookie.
- No location data beyond what an IP address inherently reveals.
- No special categories of personal data (Art. 9) and no data from children.
Why we collect it, and the legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Creating and running your account | Account data, credentials, session | Contract performance — Art. 6(1)(b) |
| Running matches, showing results and leaderboards | Handle, match history | Contract performance — Art. 6(1)(b) |
| Finding you an opponent | Match setup data | Contract performance — Art. 6(1)(b) |
| Detecting cheating and resolving disputes | Match history, move timing, IP | Legitimate interest — Art. 6(1)(f) |
| Keeping the platform secure and available | Technical data, request logs | Legitimate interest — Art. 6(1)(f) |
| Holding feedback already submitted, until it is deleted | Feedback | Legitimate interest — Art. 6(1)(f) |
| Keeping records the law requires us to keep | Account and match records | Legal obligation — Art. 6(1)(c), Bogføringsloven |
Legitimate interest assessments
Where we rely on legitimate interest, we have considered whether our interest is overridden by your rights, and concluded it is not:
- Anti-cheat and dispute resolution. A 1v1 competition only works if both players can rely on the result. The processing is limited to data the match itself generates, involves no special categories, and you are told about it here before you play.
- Security and availability. Standard server logging, minimal in scope, retained briefly, and necessary to run any service on the internet at all.
- Feedback. It is no longer collected. What was submitted while the box existed was volunteered, was never readable by the opponent it concerned, and is retained only until it is deleted.
You can object to any of these at any time — see section 07.
How long we keep it
| Data | Retention | Basis |
|---|---|---|
| Account data (handle, email, credentials) | For as long as the account is open | Contract |
| Match history and results | 2 years from the match date | Dispute resolution and anti-cheat |
| Records that count as bookkeeping records | 5 years from the end of the financial year they concern | Bogføringsloven §10 |
| Feedback already submitted | Until deleted, or anonymised with the account if that comes first | Legitimate interest |
| Technical and session logs | Short-lived — cleared on our hosting providers’ own log rotation | Legitimate interest |
What “close my account” actually does
This is deliberate, and it is not us keeping your data because we want it. Bogføringsloven §10 requires bookkeeping records to be retained for 5 years, and GDPR Art. 17(3)(b) expressly exempts data a controller must keep to comply with a legal obligation. Erasing those records would not be privacy compliance; it would be a bookkeeping offence.
An account cannot be closed while a match is still in progress.
Who else processes it
Two processors, both under a data processing agreement, both in the EU:
| Processor | Role | What they hold | Location |
|---|---|---|---|
| Supabase | Database and authentication hosting | All structured platform data — accounts, credentials, matches, feedback | EU region |
| Vercel | Application hosting and content delivery | IP address and request logs | EU region where available |
That is the complete list. There is no payment institution, no identity verification provider, no analytics vendor, no advertising network and no email marketing platform, because the platform uses none of those things.
We do not sell your data. We do not share personal data with anyone for marketing purposes. We will disclose data to a public authority only where we are legally required to, and we will tell you if that happens unless we are prohibited from telling you.
International transfers
Both processors operate within the EU/EEA. Data is not transferred outside the EU/EEA without an appropriate safeguard under GDPR Chapter V. Vercel’s content delivery network may serve static assets from outside the EU; data that identifies you is held in the EU region.
Your rights
Under GDPR you have the following rights, and you exercise all of them by writing to info@duels.dk:
| Right | What it means |
|---|---|
| Access | Get a copy of the personal data we hold about you |
| Rectification | Have inaccurate data corrected |
| Erasure | Have your data deleted, subject to the retention obligations in section 04 |
| Portability | Receive your data in a structured, machine-readable format |
| Restriction | Have us limit processing while a dispute is resolved |
| Objection | Object to processing we base on legitimate interest |
| Withdraw consent | Where we rely on consent, withdraw it at any time — this does not affect processing already carried out |
We respond within one month. If a request is complex we may extend that by two further months, and we will tell you within the first month if we do.
Where we cannot fully comply — because a record is one the law requires us to keep — we will say so plainly, tell you which record and which obligation, and delete what we can.
Security
- All traffic is encrypted in transit (TLS).
- Passwords are hashed by our authentication provider. We never see them and cannot recover them.
- Database access is governed by row-level security: your data is readable by your own session, not by other players. Handles are public by design, because leaderboards and match screens show them.
- Game state is rendered server-side, so a client cannot read or alter another player’s position.
- Production credentials are not accessible outside the application.
If a breach occurs that poses a risk to individuals, we will notify Datatilsynet within 72 hours and tell affected users without undue delay.
Cookies
The platform sets one kind of cookie: a session cookie that keeps you signed in. It is set by our authentication provider, it is strictly necessary to provide a service you have asked for, and under the Danish cookie rules a strictly necessary cookie requires no consent banner. That is why you do not see one.
We set no analytics cookies, no advertising cookies and no third-party cookies of any kind. If that ever changes, this policy changes with it and a consent mechanism goes up before the cookie does.
Children
DUELS is for adults aged 18 and over. We do not knowingly collect data from anyone under 18. As stated in section 08, the age restriction is self-declared. If you believe a minor has an account, write to info@duels.dk and we will close and anonymise it.
Changes to this policy
We may update this policy when the law changes or when what we do changes. Where a change is material — a new processor, a new purpose, a new category of data — we will tell you on the platform before it takes effect. The version and date at the top of this page say when it last changed.
Complaints
You can complain to us at info@duels.dk, and you have the right to complain to the Danish supervisory authority:
- Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark
- www.datatilsynet.dk
Governing law
This policy is governed by Danish law and the General Data Protection Regulation (EU 2016/679). Disputes arising from it are subject to Danish jurisdiction.
Contact
DUELS v/Silas Greve Abainza
- CVR 46451813
- Nyrnberggade 22, st. tv, 2300 København S, Denmark
- info@duels.dk