Privacy Policy
Note: this policy operates under the Etaf principle of stewardship, Knowledge revealed, Fate respected, Source acknowledged, Flame applied only where consent permits.
1. Data Controller
The data controller for personal data processed through this platform is:
Ridoco
KVK: 95439609
BTW: NL005153257B49
De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
Phone: +31 6 49154776
Email: contact@ridoco.com
2. Data Ridoco Collects
2.1 Account data
When you register or log in via Discord OAuth2, Ridoco receives and stores:
- Discord User ID, username, display name, avatar URL
- Email address (if authorized)
- OAuth2 access and refresh tokens (stored securely)
2.2 Platform-generated data
- Profile data: Username, display name, avatar, banner, about me, status
- Activity data: Activity points, rank, participation records
- Currency: Essence of Hell (EoH) balance and transaction history
- Linked accounts: Steam ID, Minecraft UUID, Patreon, and other linked services
- Subscriptions: Subscription tier, provider, payment references
- Content: Forum posts, comments, submissions you create
2.3 Automatically collected data
- IP address (for security and rate limiting)
- Browser User-Agent string
- Essential cookies for session management
2.4 Licence checks from software you bought and host yourself
If you bought EclipseCP and installed it on your own server, that installation contacts this site to confirm your key is still valid. It does so once a day on a schedule, and again when an administrator re-checks a key by hand or enters a new one. The call carries four things: your licence key, a fingerprint the installation generated for itself, the site address it is configured with, and a one-time random value. It carries nothing about your visitors or your members.
Ridoco keeps the following against your licence record:
- a SHA-256 hash of that fingerprint, the site address, and the date the installation first activated, as one entry per installation;
- the time of the most recent check and a running count of checks;
- a truncated SHA-256 hash of the IP address the check came from. The address itself is not stored.
The one-time value is not kept. Ridoco processes this to perform the licence agreement (Art. 6(1)(b)) and to stop one key being run on more installations than it was sold for, which is Ridoco's legitimate interest (Art. 6(1)(f)). It is not metering: nothing here counts your page views, your members, your orders or your revenue, and none of it can change what you were charged or limit what your installation does. Section 6 says how long it is kept.
3. Legal Basis for Processing
Ridoco processes your personal data under the following legal bases (GDPR Art. 6):
- Contract performance (Art. 6(1)(b)): Account management, service delivery, currency transactions
- Legitimate interest (Art. 6(1)(f)): Security, fraud prevention, service improvement
- Consent (Art. 6(1)(a)): Non-essential cookies, marketing communications
- Legal obligation (Art. 6(1)(c)): Tax records for purchases, lawful requests
4. How Your Data Is Used
- Authenticate and manage your account
- Display your profile, content, and activity on the platform
- Process currency transactions and maintain financial records
- Deliver subscription benefits and rank rewards
- Moderate content and enforce community rules
- Send service-related notifications
- Generate aggregate, anonymized analytics
5. Data Sharing
Your personal data is never sold. The providers below process data on Ridoco's instructions under a data processing agreement, except where noted otherwise.
- netcup GmbH, and the Anexia group companies it relies on. Server hosting, databases and backups. Processed in Germany and Austria (EU).
- Stripe and PayPal. Payment processing. They also act as independent controllers for their own fraud prevention and regulatory duties. Processed in the EU and the United States.
- Google. Business email, and analytics and advertising measurement where you have consented. Processed in the EU and the United States.
- Sentry. Application error and crash reporting, which can include your IP address and account identifier. Processed in the EU and the United States.
- Discord. Authentication, community features and bot integrations. Processed in the United States.
- AI features. By default, AI runs on Ridoco's own infrastructure and no data you submit is sent to a third-party AI provider. Automated consistency and rule checks on content you submit always run on that infrastructure and nothing is sent outward. AI assistant (chatbot) replies run on it too by default; an optional external tier is off by default and is used only if Ridoco enables it or you supply your own provider key, in which case replies are processed by an external AI provider (currently Google Gemini) in the United States.
- Connected services: When you link accounts (Discord, Steam, Patreon), data is shared with those services per their privacy policies.
- Law enforcement: When required by applicable law or valid legal process.
6. Data Retention
Deleting your account starts a 30-day recovery window, during which the account is hidden but recoverable. After that window your identity is erased: your name, email, password, profile text, uploaded avatar and banner, linked game and chat identifiers, and the free text you wrote are overwritten or deleted.
- Account data: Retained while active. Identity erased after the 30-day recovery window. The account row itself is kept as an anonymous key, because payment records reference it and deleting it would destroy them.
- Transaction records: Retained for 7 years, with the customer name and email required on them, because Dutch tax law obliges Ridoco to keep them (art. 52 lid 4 AWR, art. 35a Wet OB 1968). After 7 years that identity is erased too and only the amounts remain.
- Software licence records: A sold licence is a contract, so the record described in section 2.4 is kept for 7 years under that same tax rule, after which the identifying fields on it are erased.
- Content: Comments, threads and tickets you wrote are replaced with a removal marker rather than deleted outright, so that replies from other members keep their context.
- Session cookies: Expire per session or after configured timeout.
- What cannot be reached automatically: some records are keyed to a Discord or Steam identity rather than to your site account, including community applications, game server join logs and in-game event records. Erasing your site account does not clear these. Ask Ridoco and they are cleared by hand.
Erasure of accounts is performed by an operator-run process, so it is not always instantaneous once the 30-day window closes. If you want confirmation that your erasure has been carried out, contact Ridoco.
7. Your Rights (GDPR Art. 15-22)
As an EU/EEA resident, you have the right to:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Correct inaccurate data
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Request restriction of processing
- Portability (Art. 20): Receive your data in machine-readable format
- Objection (Art. 21): Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent
To exercise these rights, please open a support ticket first. If unavailable, email contact@ridoco.com (or privacy@doombringerz.com as a secondary). Ridoco responds within 30 days. You may also lodge a complaint with the Autoriteit Persoonsgegevens (AP) in the Netherlands.
8. International Data Transfers
Ridoco's servers are in the European Union. Some of the providers listed in section 5 are based in the United States or may process data there, in particular Discord, Google, Sentry, Stripe, PayPal, and any optional external AI provider you enable. Where that happens, the transfer relies on one or both of:
- the EU to US Data Privacy Framework, where the provider is certified under it;
- the European Commission's Standard Contractual Clauses, together with additional technical measures such as encryption in transit.
You can request a copy of the relevant safeguards using the contact details in section 12.
9. Data Security
- Passwords stored as irreversible cryptographic hashes
- All data in transit encrypted via TLS/HTTPS
- Access restricted to authorized personnel
- Session tokens stored in secure, httpOnly cookies
10. Children's Privacy
In the Netherlands the age of digital consent under Art. 8 GDPR is 16. This platform is not directed at children under 16, and Ridoco does not knowingly collect their personal data without parental authorisation. Registration asks for a date of birth and applies an age gate. Contact Ridoco if you believe a child has provided personal data, and Ridoco will delete it.
11. Changes
Ridoco may update this policy. Material changes are communicated via the platform. Continued use after changes constitutes acceptance.
12. Contact
Ridoco
De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
KVK: 95439609 | BTW: NL005153257B49
Email: contact@doombringerz.com
Phone: +31 6 49154776