GDPR & EU COMPLIANT // PRIVACY POLICYVERSION 1.0.0
Privacy Policy
Comprehensive privacy declaration explaining the collection, processing, storage, encryption, and protection of personal data under Regulation (EU) 2016/679 (GDPR).
Effective Date: 22.08.2026
Last Revised: 22.08.2026
Legal Entity: EssenByte Solutions
Contact: [email protected]
CHAPTER I
General Provisions & Identity of the Controller
Article 1. Legal Framework & Data Controller
(1)
This Privacy Policy governs the manner in which personal data is collected, utilized, stored, shared, and safeguarded during the access and use of the ScoreEngine cloud platform, available at scoreengine.online and across all its subdomains.
(2)
Data processing is conducted in strict compliance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR) and applicable national legislation (Law no. 190/2018).
(3)
The platform operator and unified authentication controller is: EssenByte Solutions. Data Protection Officer (DPO) / Privacy Contact: [email protected] / [email protected]. General inquiries: [email protected].
CHAPTER II
Legal Status: Data Controller vs. Data Processor
Article 2. EssenByte Solutions as Data Controller
(1)
The Company acts as Data Controller for: registration, identity, and contact details of direct Clients (account holders, legal representatives, instance administrators); financial, invoicing, and transaction records collected in connection with ScoreEngine license purchases; and technical telemetry, security logs, and connection records generated across the global scoreengine.online platform.
Article 3. EssenByte Solutions as Data Processor
(1)
Regarding personal data entered, uploaded, or collected by Clients (event organizers) via allocated Event Instances (e.g. data of athletes, competitors, referees, volunteers, identity credentials), EssenByte Solutions acts exclusively as a Data Processor.
(2)
The Client provisioning the instance is the sole Data Controller and bears full legal responsibility for lawful collection, securing consent, and informing data subjects.
(3)
Technical obligations between Controller and Processor are exhaustively governed by the Data Processing Agreement (DPA - Art. 28 GDPR), accessible at: scoreengine.online/legal/dpa.
CHAPTER III
Categories of Personal Data Processed
Article 4. Data Collected Directly from Clients & Authenticated Users
(1)
Account & Unified Authentication (SSO) Data: Full name, email address, telephone number, irreversibly hashed password (bcrypt/argon2), unique User ID, assigned administrative role.
(2)
Invoicing & Fiscal Data: Name of legal entity / individual, fiscal registration details, billing address, IBAN, transaction history (credit card data is processed exclusively by accredited payment gateways; the Provider never stores full card numbers or CVV/CVC codes).
(3)
Support & Communication Records: Messages submitted via helpdesk tickets, technical assistance inquiries, and correspondence records.
Article 5. Data Collected Automatically via Infrastructure (Logs & Telemetry)
(1)
Traffic & Navigation Data: IP address, browser type and version, operating system, screen resolution, visited subpages, timestamps, session duration, and referrer URL.
(2)
Technical Audit Logs: Automated event recordings in instances (ranking changes, logins, data exports, point overrides), maintained for security audits and operational integrity.
(3)
Session Identifiers & Technical Cookies: JSON Web Tokens (JWT) and cookies strictly necessary for session persistence. Details are set forth in the Cookie Policy: scoreengine.online/legal/cookie-policy.
Article 6. Special Regime for High-Risk Data (National IDs, Passports, Visas)
(1)
Where custom forms configured by Organizers collect sensitive identification data (such as National Identification Numbers, passport copies/series, sports medical records, or visa documents): such data is stored exclusively in encrypted instance databases; EssenByte Solutions does not analyze, extract, or share this data for its own purposes; and legal justification under GDPR Articles 6 and 9 rests solely with the Client (Organizer).
CHAPTER IV
Purposes & Legal Bases for Processing
Article 7. Legal Bases for Processing
(1)
Processing of personal data by EssenByte Solutions is grounded upon the following legal bases under Regulation (EU) 2016/679:
•
Providing SaaS services & ScoreEngine instances (SSO account data, contact details, system roles) — Art. 6(1)(b) GDPR (Contract performance / Terms of Service).
•
Billing, fiscal accounting & financial management (Fiscal identity, invoicing address, transaction logs) — Art. 6(1)(c) GDPR (Legal obligation).
•
Platform security, fraud prevention & breach investigation (Connection logs, IP addresses, audit records) — Art. 6(1)(f) GDPR (Legitimate interest in system integrity).
•
Technical support & helpdesk ticket resolution (Conversation history, configuration parameters) — Art. 6(1)(b) GDPR (Contract execution).
•
Automated scoring calculations & API integrations (Telemetry payloads, match scores, technical keys) — Art. 6(1)(b) & (f) GDPR (Contract & Legitimate interest).
CHAPTER V
Data Security, Multi-Tenant Architecture & Encryption
Article 8. Multi-Tenant Logical Isolation
(1)
The ScoreEngine architecture guarantees logical segregation of data across each event instance. Database queries and file access are strictly isolated and authorized via cryptographic tenant credentials.
(2)
No Client or End User can access or query data stored within another client's instance without explicit authorization.
Article 9. Encryption & Security Safeguards
(1)
In-Transit Encryption: All data transmitted between users, APIs, and ScoreEngine is encrypted using modern TLS 1.3 / HTTPS cryptographic protocols.
(2)
At-Rest Encryption: Databases, persistent volumes, and automated backup archives utilize industry-standard AES-256 encryption.
(3)
Comprehensive architectural details, DDoS mitigations, and compliance specifications are available at: scoreengine.online/legal/security-compliance.
Article 10. Programmatic Access & API Interfaces
(1)
API interactions are authenticated exclusively via secure tokens (API Keys / Bearer Tokens), subject to strict rate limiting and audit logging. Governing terms: scoreengine.online/legal/api-terms-of-service.
CHAPTER VI
Data Retention, Passive Archiving & Deletion
Article 11. Active Data Retention Periods
(1)
Client account data and SSO credentials are retained throughout the active lifecycle of the account.
(2)
Accounting and financial records are preserved in accordance with mandatory statutory fiscal timeframes (5 to 10 years).
(3)
Technical security logs and IP connection records are retained for a standard duration of 90–180 days before automated rotation or anonymization.
Article 12. Post-Expiration Passive Retention Framework
(1)
Upon expiration of an event instance, it enters passive archival mode (Read-Only) for 1 month to 1 calendar year to enable organizer archives and data exports.
(2)
Following expiration of the passive period, all databases, files, and backups associated with that instance are permanently and irreversibly purged from production systems.
CHAPTER VII
Data Recipients & International Transfers
Article 13. Categories of Recipients (Technical Sub-processors)
(1)
Data may be transferred strictly to the extent technically necessary to: EU-based secure cloud infrastructure and data center providers; accredited online payment processors; transactional SMTP and system notification services; and competent public or law enforcement authorities solely under mandatory legal obligation.
Article 14. Transfers Outside the European Economic Area (EEA)
(1)
Data processed by ScoreEngine is primarily hosted within European Union data centers.
(2)
Where global edge providers (e.g. CDN or DDoS protection) process metadata outside the EEA, such transfers are safeguarded via European Commission Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework.
CHAPTER VIII
Algorithmic Modules & Artificial Intelligence (AI)
Article 15. Algorithmic Processing & Absence of Automated Legal Decisions
(1)
ScoreEngine does not utilize automated decision-making producing legal or similarly significant effects concerning data subjects within the meaning of GDPR Article 22.
(2)
Scoring, ranking, and matchmaking algorithms execute strictly according to sporting parameters manually defined by the Client.
(3)
AI-assisted modules are governed by the AI Terms & Governance: scoreengine.online/legal/ai-terms-governance.
CHAPTER IX
Data Subject Rights & Exercise Mechanisms
Article 16. Catalog of Data Subject Rights (GDPR Articles 15–22)
(1)
Every data subject whose personal data is processed by EssenByte Solutions as Controller holds: Right of Access; Right to Rectification; Right to Erasure ('Right to be Forgotten'); Right to Restriction of Processing; Right to Data Portability (JSON/CSV); Right to Object; Right not to be subject to automated individual decision-making; and Right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP - dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, Romania).
Article 17. Exercise Mechanism
(1)
Requests to exercise rights regarding data processed by EssenByte as Controller should be submitted in writing to: [email protected]. Inquiries are processed free of charge within 30 calendar days.
(2)
Important: For participants/athletes whose data is stored within a private event instance, requests must be submitted directly to the Tournament Organizer (the Data Controller).
CHAPTER X
Data Breach Management Protocol
Article 18. Incident Response Measures & Notification
(1)
In the event of a confirmed security incident affecting the confidentiality, integrity, or availability of personal data: the Provider will investigate and contain the incident promptly; notify the supervisory authority (ANSPDCP) within 72 hours where required by law; and notify affected Clients without undue delay with all necessary technical details.
(2)
External security research is coordinated via the Responsible Disclosure Policy (scoreengine.online/legal/responsible-disclosure) and Bug Bounty Policy (scoreengine.online/legal/bug-bounty-policy).
CHAPTER XI
Amendments & Final Provisions
Article 19. Updates to the Privacy Policy
(1)
EssenByte Solutions reserves the right to periodically update this Privacy Policy to reflect operational, technical, or regulatory developments.
(2)
The current version is permanently accessible at: scoreengine.online/legal/privacy-policy.
(3)
In the event of substantial modifications affecting user rights, notification will be dispatched via email or prominent administrative dashboard alerts.
Have legal, DPA, or compliance inquiries?
Our compliance officer and legal counsel at EssenByte Solutions are available to review custom federation DPAs, enterprise MSAs, or answer regulatory questions.