GDPR Policy
How EnGarde Games complies with the EU General Data Protection Regulation (Reg. 2016/679) and the UK GDPR. This document is the rights-focused companion to the broader Privacy & Legal policy — it tells you what you can do about your data.
01 Scope
This policy applies to personal data EnGarde Games processes when you use engarde.lt, the EnGarde CCG, the tabletop boxed game, the EnGarde RPG, EnGarde Radio & TV, and any tournament we run, including online events.
02 Data controller
EnGarde Games, UAB · Vilnius, Lithuania · dpo@engarde.lt. We have appointed a Data Protection Officer; their address is the same.
03 Lawful bases we rely on
- Contract (Art. 6(1)(b)) — account creation, gameplay, tournaments you signed up for, payments.
- Legal obligation (Art. 6(1)(c)) — invoicing, tax, anti-fraud, statutory retention.
- Legitimate interest (Art. 6(1)(f)) — anti-cheat, abuse moderation, server logs, security, defending legal claims. Always balanced against your rights.
- Consent (Art. 6(1)(a)) — analytics & marketing cookies, optional emails, media-release at events. Withdrawable any time.
04 Your rights
If our processing concerns you, you have the right to:
- Access a copy of the personal data we hold (Art. 15).
- Rectify inaccurate or incomplete data (Art. 16).
- Erase your data — the "right to be forgotten" (Art. 17). For tournament registrations, this triggers a hard delete from the SQLite store.
- Restrict our processing while we evaluate (Art. 18).
- Portability — receive your data in a machine-readable format (Art. 20).
- Object — including a free, unconditional right to object to direct marketing (Art. 21).
- Withdraw consent at any time without affecting earlier processing (Art. 7).
- Lodge a complaint with a supervisory authority (Art. 77).
05 How to exercise these rights
- Email privacy@engarde.lt from the address tied to your account.
- Or use the in-product Delete account button on your profile — it soft-deletes immediately and anonymises after 30 days.
- For tournament data: the organiser also accepts deletion requests at events@engarde.lt; we delete the row from our database within 7 days.
We respond within 30 days as required by Art. 12(3). We may extend by 60 more days for complex cases; we will tell you within the first 30 if that applies.
06 Retention
See the Privacy & Legal retention table for full periods. In summary:
- Active accounts & gameplay state — while the account exists.
- Deleted accounts — 30-day soft-delete window, then anonymised.
- Transaction records — 10 years (Lithuanian accounting law).
- Tournament registrations — until the event closes + 24 months, or sooner on request.
- Server / security logs — 90 days rolling.
07 International transfers
Most processing stays in the EEA. Where data is transferred outside it (e.g. a CDN PoP), we rely on either an adequacy decision of the European Commission or the Standard Contractual Clauses (Commission Decision 2021/914), with technical safeguards (TLS in transit, AES-256 at rest, access controls). Transfer impact assessments are available on request.
08 Breach response
If a personal-data breach is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours as required by Art. 33, and tell affected users without undue delay (Art. 34). Our incident-response playbook is summarised at /trust.
09 Complaints
You may complain to your local supervisory authority. For Lithuanian users that is the State Data Protection Inspectorate — vdai.lrv.lt. You retain this right whether or not you contact us first.