Version 2026-09-12 · in force since 12 September 2026
The controller is Simone Ungaro , [email protected] .
The way to reach us in writing is the contact form — we publish no mailbox anywhere on the site, and a message left there goes straight to the administrators.
We have not appointed a data protection officer; we are not required to. Data protection questions go to the administrators through the contact form.
Your name and email address, taken from Discord when you first sign in. If an administrator set your account up instead, the address they used. Where you have set them: a password (held only as a hash), two-factor secrets and recovery codes, and passkeys.
Your Discord user id and nickname, the access tokens that let us act on the permission you gave, and the id of the direct-message channel we use to reach you about a MOSS request. If you connect Challengermode, the id of that account. Google is only ever connected by a league administrator, and only to read the competition spreadsheets.
The names you play under and previous spellings of them, your Ubisoft / Rainbow Six account identifiers, the teams you have been rostered for, the matches and lineups you appeared in, results and standings, and whether the MOSS file for a match was handed in on time. Some of this reaches us from the competition platform (Challengermode), from Ubisoft's published match data, and from the spreadsheets teams fill in — not only from you.
The archive you upload, and everything MOSS put in it: periodic screenshots of your entire screen, the list of processes running on your computer and where their files live, modules loaded into the game, hardware and connected devices, network connections, some system settings, and MOSS's own log. We also keep what our checks made of it and any notes the reviewing administrator wrote.
What you write in the contact form, with the name and address you give there, and the direct messages we send you on Discord about requests and deadlines.
Session records with your IP address and browser, server and error logs, and the record of which version of these documents you accepted, when, and from which IP address.
| What for | Legal basis (GDPR Art. 6) |
|---|---|
| Running your account and letting you sign in | Performance of our agreement with you — Art. 6(1)(b) |
| Taking in MOSS files, checking them, and recording whether you complied | Performance of our agreement with you, under the competition rules you entered — Art. 6(1)(b) |
| Protecting the integrity of the competition, including investigating a suspected breach | Our legitimate interest in a fair competition, and that of every other player in it — Art. 6(1)(f) |
| Publishing standings, results and rosters | Performance of our agreement with you, and our legitimate interest in running a public competition — Art. 6(1)(b) and (f) |
| Answering what you write to us | Our legitimate interest in answering you — Art. 6(1)(f) |
| Keeping the site secure and working, and keeping logs | Our legitimate interest in a secure service — Art. 6(1)(f) |
| Showing that you were given and accepted these documents | Our legal obligation to be able to demonstrate it — Art. 6(1)(c) with Art. 7(1) |
Where we rely on a legitimate interest you can object to it — see your rights below. We do not rely on consent for any of the above, which means none of it is something you can be asked to tick a box for; it also means we cannot use your data for anything else without coming back to you first.
Every archive is screened automatically as soon as it arrives. The checks look for a broken or incomplete recording, remote-control or VPN software, a virtual machine, injected code, known cheat tools, macro hardware, implausible input speed, disabled security software, and mismatches between the file and the account it was handed in for.
Those checks only raise a flag for a human to look at. No decision that affects you — a lost match, a sanction, a ban — is taken by the software alone. A member of league staff reviews the file and decides, and you can ask for that decision to be looked at again through the contact form.
League staff see everything about a submission they are reviewing, including its screenshots. Team managers see the compliance of their own roster — who has handed in a file and who has not — and nothing about any other team. Anyone can see the public parts: standings, results, rosters and the player names in them.
Service providers who process data on our instructions: our hosting and database provider ( Oracle Cloud ), which holds everything above; Discord, when we message you; and Google, where an administrator has connected an account so the competition spreadsheets can be read. Your browser also fetches our fonts from Bunny Fonts, which is used precisely because it logs nothing about visitors.
We sell nothing, run no advertising, and use no analytics or tracking of any kind. We share data with the competition organiser or a tournament platform only where it is needed to settle a case in the competition you entered, and with authorities only where the law requires it.
Discord and Google are established in the United States, so messaging you on Discord or reading a spreadsheet sends data there. Those transfers are covered by the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified under it, and otherwise by the Commission's standard contractual clauses. You can ask us for details of the safeguards in place.
Under the GDPR you can ask us to give you a copy of your data (Art. 15), to correct it (Art. 16), to delete it (Art. 17), to restrict what we do with it (Art. 18), and to hand you or another service the parts you gave us in a portable form (Art. 20). You can object to anything we do on the basis of a legitimate interest (Art. 21).
Ask through the contact form. We answer within one month. Some things survive a deletion request where we are allowed to keep them — a result that stands in a published competition, or evidence behind a sanction — and if that applies to your request we will tell you exactly what is being kept and why.
If you are unhappy with how we have handled it you can complain to a data protection supervisory authority — in our case Garante Privacy (GPDP) , or the authority in the EU or EEA country where you live.
The site is served over HTTPS and passwords are stored hashed, never in a readable form. The tokens for accounts you connect are held on our server and are never sent to your browser. Who can see what is enforced by role: a team manager cannot open another team's data, and archives are served only to people entitled to them rather than from public links. Two-factor authentication and passkeys are available on every account and we recommend turning one on.
We set only what the site needs to work: a session cookie, a cookie protecting forms against cross-site request forgery, and a "remember me" cookie if you sign in with that ticked. Your light or dark theme choice is kept in your own browser's storage. There are no advertising, analytics or tracking cookies, which is why you are not being asked to agree to any.
When what we do with your data changes, this notice gets a new version and you are asked to read it again the next time you sign in. The current version and the date it took effect are at the top of this page.
See also the Terms of use.