Piltover Archive Privacy Policy

Last Updated: June 19, 2025

1. Introduction and Data Controller Information

Welcome to Piltover Archive!

This Privacy Policy explains how Piltover Archive ("we," "us," or "our") collects, uses, processes, and protects your personal data when you use our website, located at https://piltoverarchive.com (the "Service"). We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and German data protection laws.

Data Controller:

Data Protection Officer (DPO):

We are not legally required to appoint a Data Protection Officer at this time.

2. Data Collection and Processing

We only collect and process personal data that is necessary for providing our services and for purposes explicitly stated in this policy, based on a valid legal basis.

a) Account Registration and Login (Authentication Cookies)

Data Collected: Username, email address, password (hashed), IP address upon registration/login, session data, user preferences.

Purpose: To create and manage user accounts, enable secure login, provide access to deck building tools, remember user sessions, and personalize your experience.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR). This data is essential for us to provide you with the core functionalities of our service. Without this data, we cannot provide you with a user account or access to the deck building features.

b) Deck Building and Content Creation

Data Collected: Deck data (e.g., card lists, names, descriptions), user-generated content, associated metadata (e.g., creation date, last modified date).

Purpose: To enable you to create, store, manage, and optionally share your decks on our platform.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR). This data is integral to the service you sign up for.

c) Communication with Us (Contact Form/Email)

Data Collected: Your name, email address, and the content of your message.

Purpose: To respond to your inquiries, support requests, and feedback.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR) in effectively communicating with our users and providing support. If your inquiry relates to an existing contractual relationship, the legal basis may also be performance of a contract (Art. 6(1) lit. b GDPR).

d) Website Analytics (Umami Analytics)

Data Collected: Usage data, such as pages visited, time spent on pages, referral sources, device information (e.g., browser type, operating system). We use Umami Analytics, a privacy-focused web analytics solution. We self-host Umami Analytics, meaning no data is shared with external third parties for analytics purposes. IP addresses are anonymized before processing.

Purpose: To understand how our website is used, identify popular content, and improve our website's performance and user experience.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR). We only collect analytics data if you have given your consent via our cookie banner.

e) Server Log Files

Data Collected: IP address, browser type and version, operating system, referrer URL, hostname of the accessing computer, time of the server request.

Purpose: For technical security purposes, such as identifying and mitigating cyber-attacks, ensuring the stability and operational integrity of our systems, and diagnosing errors.

Legal Basis: Legitimate interest (Art. 6(1) lit. f GDPR) in maintaining the security and functionality of our website.

3. Cookies and Other Technologies

Our website uses cookies and similar technologies. Cookies are small text files that are stored on your device (computer, tablet, smartphone) when you visit our website. They help us to provide you with a functional and user-friendly experience.

a) Strictly Necessary Cookies

Examples: Authentication cookies used by our authentication provider to keep you logged in, session cookies that remember your choices as you navigate the site.

Purpose: These cookies are essential for the basic functionality of our website. Without them, core features like logging in, creating decks, or maintaining a user session would not work.

Legal Basis: Performance of a contract (Art. 6(1) lit. b GDPR) and our legitimate interest (Art. 6(1) lit. f GDPR) in providing a functional and secure website. These cookies are necessary for the service to operate and do not require your explicit consent prior to being set.

b) Analytics Cookies (Umami)

Examples: Cookies set by Umami Analytics to track website usage.

Purpose: As described in Section 2d, to understand website usage patterns and improve our services.

Legal Basis: Your explicit consent (Art. 6(1) lit. a GDPR). These cookies are only placed if you opt-in via our cookie banner.

Managing Cookies:

You can manage your cookie preferences at any time by clicking on the "Cookie Settings" link usually found in the footer of our website. You can also configure your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

4. Data Sharing and Recipients

We do not sell your personal data to third parties. We only share data with trusted service providers and partners who assist us in operating our website and providing our services, based on appropriate legal bases and data processing agreements.

Categories of Recipients:

  • Hosting Provider: Hetzner Online GmbH. We use them to host our website and store data.
  • Authentication Provider: Stack-Auth. They provide the infrastructure for user authentication and account management.
  • Analytics Provider: Umami Analytics. As Umami is self-hosted, no direct data sharing occurs with a third-party analytics provider.

We have entered into Data Processing Agreements (DPAs) with all relevant service providers to ensure they comply with GDPR standards and process your data only according to our instructions and applicable data protection laws.

5. Data Transfer to Third Countries

Personal data may be transferred to countries outside the European Union (EU) or European Economic Area (EEA) if one of our service providers is located there.

For example, our authentication provider, Stack-Auth, is based in the United States. When data is transferred to such third countries, we ensure appropriate safeguards are in place to guarantee a level of data protection equivalent to that in the EU. This is typically achieved through the implementation of Standard Contractual Clauses (SCCs) issued by the European Commission, or by relying on an adequacy decision from the European Commission for the respective country.

As our Umami Analytics solution is self-hosted within the EU, no data is transferred to third countries for analytics purposes.

You can request a copy of the specific safeguards by contacting us using the details provided above.

6. Data Retention

We store your personal data only as long as necessary for the purposes for which it was collected or as required by law.

  • Account Data: Your account data and associated deck data will be retained for as long as your account is active. If you delete your account, your personal data will be erased, unless legal obligations require longer retention (e.g., for tax or commercial law purposes).
  • Analytics Data: Data collected via Umami Analytics is stored for 14 months before being automatically deleted.
  • Communication Data: Correspondence (e.g., emails from contact forms) is retained for the duration of the communication and a reasonable period thereafter for reference or legal defense purposes.
  • Server Log Files: Typically retained for 7-14 days for security and technical purposes.

7. Your Data Protection Rights (GDPR Rights)

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access (Art. 15 GDPR): You have the right to request confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data and further information.
  • Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate personal data concerning you and to have incomplete personal data completed.
  • Right to Erasure ("Right to be Forgotten") (Art. 17 GDPR): You have the right to request the deletion of your personal data under certain conditions.
  • Right to Restriction of Processing (Art. 18 GDPR): You have the right to request the restriction of processing your personal data under certain conditions.
  • Right to Data Portability (Art. 20 GDPR): You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance.
  • Right to Object (Art. 21 GDPR): You have the right to object to the processing of your personal data where the legal basis is our legitimate interest.
  • Right to Withdraw Consent (Art. 7(3) GDPR): Where the processing of your personal data is based on your consent, you have the right to withdraw this consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. You can manage your consent for analytics cookies via our cookie banner.
  • Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR):You have the right to lodge a complaint with a supervisory authority, particularly in the Member State of your habitual residence, place of work, or place of the alleged infringement if you believe that the processing of personal data relating to you infringes the GDPR.

To exercise any of these rights, please contact us using the details provided in Section 1 of this Privacy Policy.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, but are not limited to:

  • Using SSL/TLS encryption for all data transmission.
  • Implementing access controls to limit who can access personal data.
  • Regular data backups and disaster recovery plans.
  • Pseudonymization or anonymization where appropriate.
  • Regular security audits and updates.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. We encourage you to review this Privacy Policy periodically for any changes.

logo

Your Riftbound Companion Tool!

© 2025 PiltoverArchive.com. Piltover Archive was created under Riot Games' "Legal Jibber Jabber" policy using assets owned by Riot Games. Riot Games does not endorse or sponsor this project.