Data Protection & Privacy

Privacy Policy

How Scooperdive Ltd collects, processes, and protects your personal data under the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and EU GDPR. We believe in privacy by default: no tracking bloat, no selling your details, ever.

Version: 2.3 Standard: UK GDPR / Data Protection Act 2018 Last Updated: 6th September 2026 Controller: Scooperdive Ltd

🛡️ The Scoop / At a Glance

Privacy Summary
Section 01

Data Controller

For the purposes of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the European Union General Data Protection Regulation (EU GDPR), the data controller is:

Scooperdive Ltd is responsible for determining the purposes and means of processing personal data collected from visitors, account holders, and game server administrators.

Section 02

What Data We Collect

We only collect personal information that is strictly necessary to deliver our game server hosting services, process billing, safeguard infrastructure, and comply with UK legal obligations:

Section 03

Lawful Bases for Processing

Under Article 6 of the UK GDPR, we process your personal data under the following lawful bases:

  • Performance of a Contract (Art. 6(1)(b)): Processing is necessary to provision your game server, maintain panel access, generate recurring invoices, and provide technical support as outlined in our Terms & Conditions.
  • Legitimate Interests (Art. 6(1)(f)): Processing is necessary for our legitimate interests in safeguarding our server network, detecting and preventing fraud or DDoS attacks, troubleshooting bugs, and improving infrastructure performance.
  • Compliance with Legal Obligations (Art. 6(1)(c)): We are legally mandated by UK HMRC (HM Revenue & Customs) and statutory accounting legislation to maintain transactional records, invoices, and tax data for a minimum statutory period.
  • Consent (Art. 6(1)(a)): We rely on your explicit, affirmative consent for non-essential cookies (such as analytics or marketing embeds). You have the right to withdraw this consent at any time via our Cookie Preferences modal.
Section 04

How We Use Your Data

We process your personal information strictly for the following operational purposes:

  1. To deploy, configure, run, and maintain your game server instances and daemon services.
  2. To authenticate your identity on our billing portal and game management panel.
  3. To process recurring renewal payments and issue VAT invoices and receipts.
  4. To detect, mitigate, and investigate malicious activity, port abuse, DDoS attacks, or violations of our Acceptable Use Policy.
  5. To send essential transactional notifications (service deployment details, invoice reminders, password resets, and critical maintenance notices).
  6. To provide technical and billing support via our ticketing system and official Discord channels.
Section 05

Sub-processors & Third-Party Sharing

We do not sell, rent, or trade your personal data. We only share information with trusted third-party service providers (“Sub-processors”) who assist us in operating our services under strict data processing agreements:

Section 06

International Data Transfers

Because Scooperdive operates game server hardware in both the United Kingdom/European Union and the United States (Manassas, VA), your personal data (such as server credentials and operational telemetry) may be transferred across international borders.

Whenever data is transferred outside the UK or European Economic Area (EEA), we ensure adequate legal protections are in place, including UK International Data Transfer Addendums (IDTA), standard contractual clauses approved by the European Commission, or verified adequacy regulations.

Section 07

Data Retention & Erasure Schedules

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:

  • Active Customer Data: Preserved for the active lifecycle of your account.
  • Server Files & Game Worlds: When a server is cancelled or terminated, all game worlds, configuration files, and automated backups are permanently purged within seven (7) to fourteen (14) days.
  • Accounting & Invoices: Retained for six (6) full financial years plus current year following the date of transaction to satisfy UK HMRC tax and corporate audit mandates.
  • Server Access Logs: Rotated and automatically purged every 30 to 90 days, unless required for an ongoing cybersecurity investigation.
Section 08

Your Statutory Rights

Under the UK GDPR and EU GDPR, you have extensive statutory rights regarding your personal data:

To exercise any of these rights, please email [email protected] or submit a ticket through our client desk. We will respond within one (1) calendar month in accordance with UK statutory guidelines.

Section 09

Security Measures

We implement enterprise-grade technical and organizational security measures to protect your personal information against unauthorized access, destruction, loss, or alteration:

  • End-to-end TLS 1.3 encryption across all web interfaces, control panels, and APIs.
  • Cryptographic password hashing utilizing modern memory-hard key derivation algorithms.
  • Optional Two-Factor Authentication (2FA / TOTP) available for all client and panel accounts.
  • Isolated server containerization preventing cross-tenant access to game files.
  • Automated DDoS filtering and perimeter firewalls actively mitigating volumetric network attacks.
Section 10

Children's Privacy

Our services are not directed to children under the age of 13. We do not knowingly collect personal information from individuals under 13. If we become aware that personal data of a child under 13 has been collected without verifiable parental consent, we will take immediate steps to delete such data and terminate the associated account.

Section 11

Contact & Complaints

If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our privacy team:

If you are dissatisfied with our response or believe your data rights have been infringed under UK data protection legislation, you have the statutory right to lodge a complaint with the UK supervisory authority: