Data Controller
For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the European Union General Data Protection Regulation (EU GDPR), the data controller is:
Company Registration Number: 14606666
Incorporated in England and Wales
Contact Email:
[email protected]Support Portal: store.scooperdive.com
Scooperdive Ltd is responsible for determining the purposes and means of processing personal data collected from visitors, account holders, and game server administrators.
What Data We Collect
We only collect personal information that is strictly necessary to deliver our game server hosting services, process billing, safeguard infrastructure, and comply with UK legal obligations:
| Category | Specific Data Points | Origin / Source |
|---|---|---|
| Account Information | Full name, email address, physical billing address, country of residence, telephone number (optional), cryptographic password hash (Argon2/bcrypt). | Provided directly by Customer during account creation or checkout. |
| Billing & Payment Data | Billing name, billing address, VAT/tax identifier, payment method token, transaction reference, last 4 digits of card (Stripe/PayPal), IP address of transaction. (Raw card numbers are never received or stored). | Captured securely via payment gateway (Stripe or PayPal). |
| Server & Network Telemetry | IP addresses used to access client billing, control panel (scooperdive.net), SFTP, SSH, and server console; timestamps; bandwidth usage and server resource utilization metrics. |
Generated automatically when interacting with our network infrastructure. |
| Customer Support & Communications | Support ticket messages, attachments, Discord usernames/IDs (if linked or communicating in our community), feedback responses. | Provided voluntarily when requesting support. |
| Cookies & Device Information | Browser user agent, screen resolution, language choice (sd_lang), consent preferences (sd_consent), and anonymized analytics data (only if consented). |
Managed via browser storage and our custom cookie consent script. |
Lawful Bases for Processing
Under Article 6 of the UK GDPR, we process your personal data under the following lawful bases:
- Performance of a Contract (Art. 6(1)(b)): Processing is necessary to provision your game server, maintain panel access, generate recurring invoices, and provide technical support as outlined in our Terms & Conditions.
- Legitimate Interests (Art. 6(1)(f)): Processing is necessary for our legitimate interests in safeguarding our server network, detecting and preventing fraud or DDoS attacks, troubleshooting bugs, and improving infrastructure performance.
- Compliance with Legal Obligations (Art. 6(1)(c)): We are legally mandated by UK HMRC (HM Revenue & Customs) and statutory accounting legislation to maintain transactional records, invoices, and tax data for a minimum statutory period.
- Consent (Art. 6(1)(a)): We rely on your explicit, affirmative consent for non-essential cookies (such as analytics or marketing embeds). You have the right to withdraw this consent at any time via our Cookie Preferences modal.
How We Use Your Data
We process your personal information strictly for the following operational purposes:
- To deploy, configure, run, and maintain your game server instances and daemon services.
- To authenticate your identity on our billing portal and game management panel.
- To process recurring renewal payments and issue VAT invoices and receipts.
- To detect, mitigate, and investigate malicious activity, port abuse, DDoS attacks, or violations of our Acceptable Use Policy.
- To send essential transactional notifications (service deployment details, invoice reminders, password resets, and critical maintenance notices).
- To provide technical and billing support via our ticketing system and official Discord channels.
Sub-processors & Third-Party Sharing
We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers (“Sub-processors”) who assist us in operating our services under strict data processing agreements:
| Sub-processor | Role & Service | Location |
|---|---|---|
| Stripe Payments UK, Ltd / Stripe, Inc. | Credit/Debit Card payment gateway and fraud detection (Radar). | UK / EU / USA (Adequacy / SCCs) |
| PayPal (Europe) S.à r.l. et Cie, SCA | PayPal transaction processing and dispute resolution. | Luxembourg (EU) |
| Hetzner Online GmbH | European datacenter co-location and bare-metal server infrastructure. | Germany / Finland (EU) |
| Equinix / Core Facilities | North American datacenter infrastructure (Manassas, VA, USA). | United States (SCCs) |
| Cloudflare, Inc. | DNS routing, DDoS mitigation, and SSL/TLS edge caching. | Global Edge (Adequacy / SCCs) |
| Transactional Email Provider (SMTP) | Delivery of invoice notices, automated deployment emails, and password resets. | UK / EU |
International Data Transfers
Because Scooperdive operates game server hardware in both the United Kingdom/European Union and the United States (Manassas, VA), your personal data (such as server credentials and operational telemetry) may be transferred across international borders.
Whenever data is transferred outside the UK or European Economic Area (EEA), we ensure adequate legal protections are in place, including UK International Data Transfer Addendums (IDTA), standard contractual clauses approved by the European Commission, or verified adequacy regulations.
Data Retention & Erasure Schedules
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:
- Active Customer Data: Preserved for the active lifecycle of your account.
- Server Files & Game Worlds: When a server is cancelled or terminated, all game worlds, configuration files, and automated backups are permanently purged within seven (7) to fourteen (14) days.
- Accounting & Invoices: Retained for six (6) full financial years plus current year following the date of transaction to satisfy UK HMRC tax and corporate audit mandates.
- Server Access Logs: Rotated and automatically purged every 30 to 90 days, unless required for an ongoing cybersecurity investigation.
Your Statutory Rights
Under the UK GDPR and EU GDPR, you have extensive statutory rights regarding your personal data:
To exercise any of these rights, please email [email protected] or submit a ticket through our client desk. We will respond within one (1) calendar month in accordance with UK statutory guidelines.
Security Measures
We implement enterprise-grade technical and organizational security measures to protect your personal information against unauthorized access, destruction, loss, or alteration:
- End-to-end TLS 1.3 encryption across all web interfaces, control panels, and APIs.
- Cryptographic password hashing utilizing modern memory-hard key derivation algorithms.
- Optional Two-Factor Authentication (2FA / TOTP) available for all client and panel accounts.
- Isolated server containerization preventing cross-tenant access to game files.
- Automated DDoS filtering and perimeter firewalls actively mitigating volumetric network attacks.
Children's Privacy
Our services are not directed to children under the age of 13. We do not knowingly collect personal information from individuals under 13. If we become aware that personal data of a child under 13 has been collected without verifiable parental consent, we will take immediate steps to delete such data and terminate the associated account.
Contact & Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our privacy team:
Email:
[email protected]Online Desk: store.scooperdive.com
If you are dissatisfied with our response or believe your data rights have been infringed under UK data protection legislation, you have the statutory right to lodge a complaint with the UK supervisory authority:
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk | Helpline: 0303 123 1113