1. About This Policy
In short — this policy explains how OpsCentre handles personal data, who is responsible for it, and what rights you have.
This Privacy Policy explains how Jack Ryan Brolly, trading as OpsCentre, a sole trader operating from Ground Floor, Gallery Building, 65–69 Dublin Road, Belfast, BT2 7HG ("we", "us", "our", or "OpsCentre"), collects, uses, shares, and protects personal data in connection with the OpsCentre Community Management System and all related websites, applications, application programming interfaces, and services (together, the "Service").
We are registered with the Information Commissioner's Office (ICO) on the Data Protection Register — registration reference ZC184449.
This policy should be read together with our Terms of Service, our Acceptable Use Policy, and, where applicable, our Data Processing Addendum. Capitalised terms used but not defined in this policy have the meanings given to them in our Terms of Service.
This policy is written to comply with the UK General Data Protection Regulation (the "UK GDPR") and the Data Protection Act 2018. Where we provide the Service to communities and individuals in the Republic of Ireland or elsewhere in the European Economic Area, we also have regard to the EU General Data Protection Regulation (the "EU GDPR").
2. Key Terms
In short — the main data-protection words used in this policy, in plain language.
In this policy, the following terms have the meanings set out below.
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable living person. |
| Data controller | The party that decides why and how personal data is processed. |
| Data processor | A party that processes personal data on behalf of, and on the instructions of, a controller. |
| Data subject | The living individual to whom personal data relates. |
| Processing | Anything done with personal data, including collecting, storing, using, sharing, or deleting it. |
| Sub-processor | A third-party provider we engage to help deliver the Service, which may process personal data. |
| Platform User | Any person who holds an OpsCentre account. Holding an account is free. |
| Community Director | A Platform User who holds a paid Subscription to operate their own community on the Service. |
3. Our Two Roles: Controller and Processor
In short — we are the controller of your account data, and the processor of the records your community puts into the platform. This distinction matters, so we explain it clearly.
OpsCentre handles personal data in two distinct capacities. Understanding which applies is important, because it determines who is responsible for the data and how you exercise your rights.
3.1 Where we are the data controller
We are the data controller for the personal data we collect and use to provide and operate the Service itself. This includes the personal data of Platform Users and Community Directors — for example, your account details, the email address associated with your account, your date of birth, and the technical and security data described in this policy.
In this capacity, we decide why and how that data is processed, and this Privacy Policy governs it. Where this policy refers to what "we" do with personal data, it refers to this controller role unless we say otherwise.
3.2 Where we are the data processor
We are a data processor for the Content that a Community Director and their community create, upload, and store within the Service — for example, the records, profiles, and other information held in a community's Records Management System and related modules.
In this capacity, the Community Director is the data controller for that Content. They decide what is entered into their community and why; we process it on their behalf and on their instructions, in order to provide the Service. Our handling of that Content is governed by our Terms of Service and, where applicable, our Data Processing Addendum, rather than by this Privacy Policy.
Important: OpsCentre is designed for fictional, in-character roleplay records. Our Acceptable Use Policy requires that real personal data about real, identifiable people is not entered into community records. Where a Community Director or their members nonetheless enter real personal data, the Community Director is the controller responsible for it, and should ensure they have a lawful basis to do so. If you believe your real personal data has been entered into a community on the Service, see Section 12 (Your Rights) and Section 15 (How to Contact Us).
4. What Personal Data We Collect
In short — the personal data we collect as controller — what it is, and where it comes from.
As data controller, we collect and process the following categories of personal data.
| Category | What it includes | Source |
|---|---|---|
| Account identity | Your Discord user ID, username, and avatar. | Provided by Discord when you sign in (see 4.1). |
| Contact details | Your email address. | From Discord at sign-in. |
| Identity details | Your real (legal) name and a chosen display name, each captured once when you first provide them. Your legal name is visible only to a limited number of senior staff, and corrections (for example following a change of name) are made by our staff on request. | Provided by you. |
| Age information | Your date of birth, and an approximate age derived from it. | Provided by you. |
| Subscription status | Whether you hold an active Subscription, and limited related billing metadata. | From our payment provider, Stripe (see Section 6). |
| Technical & security data | Your IP address and browser user agent (recorded each time you sign in), dates and times of activity such as sign-in and key actions (audit and security logs), and security indicators we derive from your IP address on our own systems — for example, whether it appears to belong to a datacentre, VPN, or anonymising network, or is shared with other accounts. We do not send your IP address to any third-party lookup service to produce these indicators, and they are visible only to a limited number of senior staff. | Collected automatically when you use the Service. |
| Communications | Messages you send us, our correspondence with you, and records of platform notices we send to you — including evidence of your acknowledgement of a notice (with the IP address and browser details recorded at the time of acknowledgement). Notices identify the issuing staff role, not a named individual. | Provided by you when you contact us, or generated when we send you a notice. |
4.1 Signing in with Discord
You access the Service using your Discord account, through Discord's standard authorisation process. When you do so, Discord provides us with your Discord user ID, username, avatar, and the email address associated with your Discord account. We do not receive your Discord password. Your use of Discord is governed by Discord's own terms and privacy policy.
4.2 Date of birth and age
We collect your date of birth and derive an approximate age from it for one purpose only: to enforce our age-related rules and our safeguarding and child-protection obligations — for example, that a person must be at least 13 to hold an account, and at least 18 to hold a Subscription, and to support compliance with our Acceptable Use Policy and Terms of Service. We do not use your age for profiling, marketing, or any other purpose. Your date of birth is captured once and cannot ordinarily be changed by you afterwards. Where our Trust and Safety team has reason to believe that the name or date of birth held on an account is inaccurate or has been misrepresented, we may require you to re-confirm those details before you continue using the Service; in that case we keep a record of both the details previously held and the details re-submitted.
4.3 We do not seek special category data
We do not ask for, and do not wish to receive, special category personal data about you (such as data revealing health, racial or ethnic origin, religious beliefs, or sexual orientation) in connection with your account. Please do not provide such data to us unless we specifically and lawfully request it.
5. Why We Use Your Personal Data, and Our Lawful Bases
In short — the purposes we use your data for, and the legal ground for each. We always have a lawful basis.
As data controller, we process your personal data for the purposes set out below. For each purpose, we rely on one or more lawful bases under the UK GDPR.
| Purpose | Lawful basis |
|---|---|
| To create and administer your account and provide the Service to you | Performance of a contract with you (our Terms of Service) |
| To process Subscriptions, determine community status, and manage billing | Performance of a contract; compliance with a legal obligation (financial record-keeping) |
| To enforce our age rules and safeguarding and child-protection obligations | Compliance with a legal obligation; our legitimate interests in operating a safe Service |
| To keep the Service secure, prevent and detect abuse, and prevent the evasion of sanctions or bans | Our legitimate interests in protecting the Service, our users, and the public |
| To maintain audit logs and meet our accountability obligations | Compliance with a legal obligation; our legitimate interests |
| To communicate with you about the Service, including service notices | Performance of a contract; our legitimate interests in keeping you informed |
| To respond to your enquiries and requests, including data rights requests | Compliance with a legal obligation; our legitimate interests |
| To comply with the law and respond to lawful requests from authorities | Compliance with a legal obligation |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests and rights, and we balance them accordingly. You have the right to object to processing based on legitimate interests, as described in Section 12. Where we rely on consent for any specific processing, you may withdraw that consent at any time.
6. Payments
In short — Stripe handles your payment details — we don't store your card data, only whether your subscription is active.
Payments for Subscriptions are processed by Stripe, our third-party payment provider. When you make a payment, your payment card and transaction details are collected and processed by Stripe directly, as a separate data controller for that payment data, in accordance with Stripe's own privacy policy and the applicable card-industry security standards. We do not receive or store your full payment card details.
From Stripe, we receive and retain only limited information necessary to operate the Service — principally whether you hold an active Subscription, which we use to determine the status of your community, together with limited related billing metadata. We retain billing and transaction records as required to meet our legal and financial record-keeping obligations (see Section 9).
7. Who We Share Personal Data With
In short — we use a small number of trusted providers to run the Service. We do not sell your data.
We do not sell your personal data. We share personal data only as described below.
7.1 Our service providers (sub-processors)
We use the following trusted third-party providers to deliver and operate the Service. Each processes personal data only as necessary for its function, and is bound by appropriate contractual obligations to protect it.
| Provider | What they do |
|---|---|
| Stripe | Payment processing for Subscriptions. |
| Discord | Account sign-in and authentication. |
| Railway | Hosting and database infrastructure for the Service. |
| Cloudflare | Content delivery, performance, and security protection (including protection against malicious traffic). |
| Microsoft | Business email and communications used in operating the Service. |
| Resend | Sending transactional and service emails to you (such as notices and account-related emails). |
We keep this list under review and will update this policy if our providers change. We may engage additional or replacement providers to deliver the Service, and where we do, we will ensure appropriate safeguards are in place.
7.2 Other disclosures
We may also disclose personal data: to comply with the law or a valid legal request from a law enforcement, safeguarding, or regulatory authority; to establish, exercise, or defend legal claims; to protect the rights, safety, or property of OpsCentre, our users, or the public; and in connection with a reorganisation or transfer of our business, in which case we will ensure the recipient continues to protect your personal data.
8. International Transfers
In short — some of our providers are based outside the UK. Where data is transferred abroad, we make sure it stays protected.
Some of our service providers are located, or process data, outside the United Kingdom — including in the United States. Where personal data is transferred outside the UK (and, where relevant, outside the European Economic Area), we take steps to ensure it remains protected to the standard required by UK data protection law.
Depending on the provider and destination, these safeguards include relying on a country that has been formally recognised as providing an adequate level of protection, or putting in place an approved data transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to the European Commission's Standard Contractual Clauses, or an equivalent approved mechanism. You may contact us for further information about the safeguards in place for a particular transfer.
9. How Long We Keep Personal Data
In short — we keep your data while your account is active. Closing your account removes your access but does not itself delete your data — you can ask us to erase it — and we keep limited details longer where we need them for safety, security, or the law.
We keep personal data only for as long as we need it for the purposes set out in this policy, and in line with our legal obligations.
9.1 General retention
In general, we retain the personal data associated with your account for as long as your account remains active. Closing your account removes your access to the Service and your community memberships, but does not itself delete the personal data associated with the account: that data is retained so that your account can be reinstated if you sign in again. If you do not wish your data to be retained in this way, you may ask us to erase it (see Section 12), and we will delete or anonymise it except where we need to retain certain data for the specific reasons set out below.
9.2 Retention for security and the prevention of abuse
We retain a limited set of personal data beyond the erasure of your account data where it is necessary to keep the Service and its users safe — in particular, to detect and prevent abuse, and to prevent individuals who have been sanctioned or removed from evading those measures by creating new accounts. Where a person has been permanently excluded from the Service, this record includes their Discord account identifier. Where we have established that an account holder is under 13, we erase the personal data we hold about them and retain only irreversible keyed cryptographic hashes of their Discord identifier and email address; these cannot be reversed to reveal the underlying information and are used solely to prevent the same person from regaining access.
We rely on our legitimate interests for this retention. We hold only the minimum data necessary for this purpose, we keep it secure and separate from general account use, and we review its continued necessity. You may object to this retention (see Section 12); where you do, we will consider whether our legitimate interests in protecting the Service and the public override your request, and we will tell you the outcome.
9.3 Retention for legal and financial obligations
We retain billing and transaction records, and other records we are legally required to keep, for the periods required by applicable law (for example, tax and accounting records are typically retained for at least six years). We also retain limited records where necessary to establish, exercise, or defend legal claims.
10. How We Protect Personal Data
In short — we take appropriate measures to keep your data secure, including access controls and audit logging.
We take appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include access controls and role-based permissions, separation of community data within the Service, audit logging of access to and changes of records, encrypted connections, and the use of reputable infrastructure providers.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. However, we maintain procedures to identify, manage, and where required report personal data breaches, including notifying the Information Commissioner's Office and affected individuals where the law requires us to do so.
11. Children and Young People
In short — you must be at least 13 to hold an account and 18 to subscribe. We don't knowingly collect data from children under 13.
The Service is not directed at children under the age of 13, and you must be at least 13 years old to hold an account. You must be at least 18 years old to hold a Subscription and operate a community as a Community Director.
We use the date of birth you provide to enforce these age requirements, as described in Section 4.2. We do not knowingly collect personal data from children under 13. If you believe a person under 13 is using the Service, please report this to our Trust and Safety team at [email protected] so that we can take appropriate action, including as a safeguarding matter. Where we establish that a person using the Service is under 13, we block their access and erase the personal data we hold about them, retaining only the irreversible hashed identifiers described in Section 9.2 so that the same account cannot be re-created.
Where a person aged between 13 and 17 holds an account, we are mindful of our responsibilities towards young people, and our Acceptable Use Policy and safeguarding measures are designed with their protection in mind.
12. Your Rights
In short — you have rights over your personal data — to see it, correct it, delete it, and more. Here's how to use them.
Under the UK GDPR, you have the following rights in relation to the personal data for which we are the controller:
- The right to be informed — to be told how we use your personal data — which is the purpose of this policy.
- The right of access — to obtain a copy of the personal data we hold about you.
- The right to rectification — to have inaccurate personal data corrected, or incomplete data completed.
- The right to erasure — to ask us to delete your personal data in certain circumstances.
- The right to restrict processing — to ask us to limit how we use your personal data in certain circumstances.
- The right to data portability — to receive certain personal data in a portable format, or have it transferred, in certain circumstances.
- The right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Rights relating to automated decision-making — as described in Section 13.
12.1 How to exercise your rights
To exercise any of these rights, please contact us at [email protected]. We will respond without undue delay and within one month, as required by law. We may need to verify your identity before acting on a request. These rights are generally free to exercise, although we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, as permitted by law.
Where the personal data concerned is Content held within a community (for which we are the processor and the Community Director is the controller), we may need to direct your request to, or act on the instructions of, the relevant Community Director. We will tell you if this is the case.
13. Automated Decision-Making
In short — we don't make automated decisions about you that have a legal or similarly significant effect without a person involved.
We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing without human involvement. Where the Service supports enforcement actions such as sanctions, those actions involve human review and judgement; they are not taken by automated means alone. Automated security indicators (for example, flags suggesting the use of a VPN, a datacentre IP address, or an IP address shared with other accounts) are used only to inform review by our staff; they do not by themselves restrict your account.
14. Cookies and Similar Technologies
In short — we only use essential cookies needed to make the Service work and keep it secure. We don't use tracking or advertising cookies.
We use only strictly necessary cookies and similar technologies — those required to operate the Service, such as keeping you signed in and maintaining the security and integrity of your session. These are essential to providing the Service you have requested.
We do not use analytics, advertising, profiling, or other non-essential tracking cookies. Because the cookies we use are strictly necessary, they do not require your consent. If this changes, we will update this policy and, where required, ask for your consent.
15. How to Contact Us, and How to Complain
In short — contact our data protection address with any questions — and you can complain to the ICO if you're unhappy.
If you have any questions about this policy or about how we handle your personal data, or if you wish to exercise your rights, please contact us:
- Data protection contact: [email protected]
- Data Protection Officer: OpsCentre has a designated Data Protection Officer, who is also our data protection contact and can be reached at the address above. We are not required to appoint a statutory Data Protection Officer under the UK GDPR, and have designated one on a voluntary basis.
- Postal address: OpsCentre, Ground Floor, Gallery Building, 65–69 Dublin Road, Belfast, BT2 7HG
- EU representative: We have not appointed a representative in the European Union at this stage. If you are in the EU/EEA, you can raise any data protection matter directly with our Data Protection Officer at the address above, and you retain the right to complain to your local supervisory authority.
15.1 Complaining to the ICO
If you are unhappy with how we have handled your personal data, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. You can contact the ICO at ico.org.uk, or by telephone on 0303 123 1113. We would, however, appreciate the opportunity to address your concerns before you approach the ICO, so please consider contacting us first.
If you are located in the Republic of Ireland or elsewhere in the European Economic Area, you may also have the right to complain to your local data protection supervisory authority. In Ireland, this is the Data Protection Commission (dataprotection.ie).
16. Changes to This Policy
In short — we may update this policy, and we'll tell you about significant changes.
We may update this policy from time to time to reflect changes in the Service, in our practices, or in the law. When we make changes, we will revise the version number and effective date at the top of this policy. Where the changes are significant, we will take reasonable steps to bring them to your attention, such as through a notice within the Service. Your continued use of the Service after a change takes effect indicates your acknowledgement of the updated policy.
To be viewed in conjunction with https://www.opscentre.uk/legal/dpa
End of Privacy Policy