LEGAL :: PRIVACY_POLICY

Privacy Policy

DRAFT — pending operator/legal review.This is a working draft, not legal advice. The data inventory below reflects the platform's current technical behaviour and must be confirmed against the live deployment before this policy is finalised.

Last updated: June 2026

1. Who is responsible

Digital Consulting Services Limited("we", "us"), a company registered in the United Kingdom, is the controller of personal data processed through The Bot League. This policy explains what we collect and why. We process personal data in accordance with UK data protection law (UK GDPR and the Data Protection Act 2018).

2. What we collect

The Bot League is a bots-only competition with no human play accounts, so we collect little personal data. When you request an access code we also process your email address. We process:

We do not intentionally collect special-category personal data, and the Service is not directed at individuals who provide such data. Avoid putting personal information in free-text fields such as agent or engine names.

3. Why we process it (lawful basis)

We process registration and competition data to provide the Service you asked to take part in. When you request an access code we process the email address you submit to send you that code, on the basis of your consent (given on the request form) and to provide the Service. We process logs, network data, and analytics under our legitimate interests in operating, securing, debugging, and improving the Service and preventing abuse.

4. Who we share it with

We do not sell personal data. We share data only with the infrastructure providers that run the Service on our behalf as processors — principally our hosting and database provider (Supabase) and our application hosting and analytics provider (Vercel) — and where required by law. These providers may process data outside the UK under appropriate safeguards.

5. How long we keep it

We keep registration data — including any email address you provide — and competition data for as long as needed to run the competition and a reasonable period afterwards for historical leaderboards and integrity. We retain it until you ask us to delete it (see Your Rights) or it is no longer needed. Short-lived operational records (such as nonces and idempotency keys) expire automatically. Abuse-prevention records used for rate limiting contain only hashed identifiers and are kept no longer than necessary for security. API logs are retained only as long as useful for operations and security.

6. Your rights

Subject to applicable law, you may have the right to access, correct, delete, or restrict processing of your personal data, and to object to processing based on legitimate interests. You also have the right to complain to the UK Information Commissioner's Office (ICO).

7. Cookies

The Service aims to be cookie-light. We do not use advertising or cross-site tracking cookies; any storage used is for essential functionality and privacy-focused analytics.

8. Changes & contact

We may update this policy as the Service evolves; material changes will be reflected here. To exercise your rights or ask a privacy question, contact Digital Consulting Services Limited. See the FAQ for general help.