PRIVACY NOTICE Last updated: 28 July 2026 1. ABOUT THIS NOTICE This notice explains how the operator of the arctic.tf gaming community ("arctic.tf", "we", "us") processes personal data when you use our websites, game servers, community administration features, and related services. arctic.tf is an independently operated gaming community. This notice covers services operated by arctic.tf unless a service presents a separate notice. It is meant to be practical: it describes categories of data and purposes rather than every individual database field or server plugin. External services linked from our website have their own privacy notices. We do not sell personal data, run advertising, or use visitor-tracking analytics. 2. CONTROLLER AND CONTACT Controller: the operator of the arctic.tf gaming community, based in Finland Email: contact@arctic.tf Discord: https://discord.gg/wVfbNvqRKA Steam: https://steamcommunity.com/groups/arctic-tf Email is the preferred way to make a privacy request. 3. DATA WE PROCESS Website, authentication, and operator data - The public website does not use visitor analytics. Our infrastructure and protected operator services process limited request and security data, such as IP address, user agent, requested path, time, response status, and authenticated operator identity. - If you sign in to player-facing website features with Steam, we receive the Steam identifier verified by Steam OpenID. We retrieve and temporarily cache the public profile name and avatar, and link to the associated public Steam profile. We never receive your Steam password. - Authorized administrators and operators may have account details such as name, email address, password hash, Steam identifier, role, permissions, authentication method, login history, and security audit records. If an operator links a Steam or GitHub login, we can store the provider's durable identifier, login or display name, and public profile and avatar URLs. Game-server and player data - Platform and network identifiers, including IP address, Steam identifiers, display names and previous aliases. We may derive an approximate country from an IP address using a local database. Authorized technical administrators can access full network identifiers where needed; less privileged views can redact them. - Connection and technical information, including server, map, connection times and duration, connection method, game or client information, settings, ping, latency, packet loss, and similar network-quality information. - Gameplay and community activity, including teams, scores, deaths, sessions, matches, maps and arenas played, ratings, wins and losses, votes, commands, game events, and saved player preferences. - Content you provide, including public and team chat, reports, appeal text, moderator correspondence, sprays or other uploaded game content, and messages sent to us through community platforms. - Security and moderation information, including reports, warnings, kicks, bans, mutes, gags, reasons, durations, evidence, linked administrative actions, and anti-cheat indicators or detections. When a security check is triggered, evidence can include relevant input, mouse, view-angle, tick, connection, and network information. Recordings and diagnostics - Game sessions may be observed or recorded in SourceTV demos. A recording can contain player identities, gameplay, events, and, depending on the game and server configuration, chat or voice communications. - Server, anti-cheat, chat, command, vote, and administrative logs can contain the information described above. On some servers, console commands, their arguments, and connection fields are included in logs. This can include the game-server password supplied when joining a password-protected server. Do not put secrets or sensitive personal information in website addresses, chat, commands, reports, appeals, sprays, or similar fields, and do not reuse a sensitive password as a game-server password. - Restricted diagnostic systems can collect server and process logs, crash reports, and performance data. During suspected network incidents, they can automatically create short packet captures containing network addresses, protocol details, and limited content from traffic handled by the affected host. Ban appeals If you sign in to view an active enforcement record or submit an appeal, we process your verified Steam identifier, appeal text and timestamps, appeal status, moderator response and identifiers, and a snapshot of the enforcement record. The snapshot can include the player identifier, name, network identifier, reason, duration, type, server, and administrative identifiers. We do not require an email address for the player appeal process. Sources of data We receive data: - directly from you, your game client, browser, or device; - from Valve or Steam when they authenticate your account or provide public profile information; - from our servers, plugins, security tools, and authorized administrators; - from reports or other communications submitted by other players; and - by deriving information such as country, statistics, ratings, or security signals from the data above. 4. HOW AND WHY WE USE DATA We use personal data to: - provide, authenticate, maintain, and configure our websites and game servers; - show live server information, statistics, rankings, match history, recordings, and other community features; - remember player and website preferences; - keep services secure and reliable, prevent cheating and abuse, investigate incidents, enforce community rules, and preserve relevant evidence; - receive reports, review appeals, communicate with players, and keep an accountable record of administrative actions; - diagnose crashes, connection problems, performance issues, and software faults; - produce aggregate service information and improve community services; and - establish, exercise, or defend claims and comply with legal obligations. Providing data is not a statutory or contractual requirement. However, an IP address and the identifiers and technical events used by Steam and the game server are necessary to connect and play. A verified Steam identifier is necessary for authenticated features. If you do not provide the information needed for an optional report or appeal, we may be unable to handle it. 5. LEGAL BASES Most processing is based on our legitimate interests under Article 6(1)(f) of the General Data Protection Regulation (GDPR). Those interests are operating a free gaming community, providing expected multiplayer and community features, securing our systems, preventing cheating and abuse, applying community rules, resolving disputes, maintaining service reliability, and keeping proportionate administrative and historical records. When relying on legitimate interests, we consider the nature and sensitivity of the data, what a player can reasonably expect, the effect of the processing, and available safeguards such as role-based access to non-public fields, configured rolling retention, and an appeal process. You have the right to object, as explained below. We rely on Article 6(1)(c) GDPR where processing is necessary to comply with a specific legal obligation. Establishing, exercising, or defending legal claims can also be a legitimate interest. We do not rely on this privacy notice as consent. Automated server and anti-cheat controls can reject a connection, flag activity, or automatically kick, mute, or ban a player. Eligible active bans and communication restrictions can be appealed for human review; other actions can be raised with the community administrators. We do not use personal data to make decisions that produce legal or similarly significant effects within the meaning of Article 22 GDPR. 6. PUBLIC INFORMATION Multiplayer services are public by nature. Other players and spectators can see information such as your display name, chat, gameplay, team, score, and in-game administrative actions. A Steam identifier is also visible where a game or community feature exposes it. Our public website and downloadable files can make the following available: - Steam display names, identifiers, and profile links; - statistics, ratings, wins and losses, match or duel history, maps or arenas, recent activity, and sanction status; - enforcement records, including the player identifier, name, reason, removal reason, dates, duration, and status; and - SourceTV recording files and related server, map, time, and filename information. A downloadable recording can itself contain the identities, gameplay, events, chat, or voice information described above. Public information can be indexed, copied, or cached by third parties and may remain available elsewhere after we change or remove it. Appeal text and moderator responses are not included in the public ban list. They are available to the authenticated appellant and authorized administrators. Administrators can also access the enforcement snapshot and decision history needed to review and audit the case. 7. COOKIES AND LOCAL PREFERENCES We do not use advertising cookies, cross-site tracking, or visitor analytics. - Steam-authenticated website features use an essential ARCTICSESSID cookie. It identifies a server-side session containing the verified Steam identifier, public profile name, and security state. The login expires after 12 hours. - Protected operator tools use separate essential sessions, normally lasting no more than 24 hours. - Theme and language choices may be stored locally in your browser. They are not used to track you. - Game servers can save preferences linked to your Steam identity, such as interface or gameplay presentation options. These are SourceMod player preferences, not browser tracking cookies. Loading a Steam avatar or other externally hosted content can cause your browser to contact that provider and disclose ordinary request information, such as your IP address and user agent. 8. SHARING AND INTERNATIONAL TRANSFERS We disclose personal data only where relevant to the purposes above: - to authorized community administrators and volunteers according to their responsibilities; - to providers of hosting, networking, database, storage, content delivery, backup, security, and crash-reporting services; - to Valve or Steam for game operation, authentication, public profile information, and platform services; - to configured administration or communication services, such as Discord, and to authentication providers used for operator-only systems, such as GitHub; - to other players and the public as described in the Public Information section; and - to authorities, advisers, or other recipients where reasonably necessary to comply with law, protect people or services, or establish, exercise, or defend legal claims. We do not sell or rent personal data and do not share it for targeted advertising. arctic.tf is operated from Finland, but data is not necessarily kept only in Finland or the European Economic Area (EEA). Public data is accessible worldwide, and some platform or service providers may process data outside the EEA. Transfers for which arctic.tf is responsible are subject to the GDPR's international-transfer rules. Depending on the provider and destination, the applicable safeguard may be an adequacy decision or standard contractual clauses. Providers that act as independent controllers are responsible for their own transfer arrangements and privacy notices. Contact us for information about the safeguard applicable to a particular transfer. Valve privacy notice: https://store.steampowered.com/privacy_agreement/ Discord privacy notice: https://discord.com/privacy GitHub privacy notice: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement 9. RETENTION We keep personal data only for as long as it remains reasonably necessary for the purposes in this notice. We consider the data's sensitivity, the active life of an account or service, whether a sanction or dispute remains relevant, the risk of repeat abuse, the need for evidence and accountability, applicable legal requirements, and technical storage and rotation cycles. In general: - Authorization for a public website login ceases to be valid after 12 hours; operator authorization normally ceases to be valid within 24 hours. Short-lived authentication challenges expire sooner. Related technical rows or files can remain until runtime maintenance removes or replaces them. - The player-facing website treats cached public Steam profile information as stale after 24 hours, but a stale cache file can remain until it is replaced or cleaned up. Provider identity details linked to an operator account are stored with that account and updated when the provider is used again. - Live server state is generally replaced as new observations arrive or players disconnect. A stale diagnostic snapshot can remain until it is refreshed, cleared, or its server record is removed, and relevant events can also appear in logs or evidence. - Ordinary SourceTV recordings managed by the public archive are generally available for about 30 days. Other server-side copies are retained according to their operational, security, evidentiary, or historical purpose. - Where our central server-management system retains detailed events, chat, anti-cheat events, connection-quality data, recordings, or diagnostic captures, routine records are normally kept on a 30-day rolling schedule. Administrative audit and longer-term operational history are normally kept for 365 days. - Ban, communication restriction, report, anti-cheat, appeal, and administrative records can be kept for the life of the sanction and afterwards while needed for appeals, repeat-abuse prevention, evidence, or accountability. Records for permanent sanctions can therefore be long-lived. An appeal snapshot can remain after the underlying enforcement record is removed. - Account, statistics, match-history, rating, preference, and community-history records can be kept while the relevant account, feature, or community service remains active, subject to valid deletion or objection requests. Some legacy game-server logs, security records, uploaded sprays, preferences, and statistics do not have one universal automatic deletion period. They can remain long-lived until operational cleanup or action on a valid privacy request. Data can be retained longer where required by law or while a legal claim or security investigation is pending. 10. YOUR DATA-PROTECTION RIGHTS Depending on the circumstances, the GDPR gives you the right to: - obtain access to your personal data and information about its processing; - correct inaccurate or incomplete personal data; - request erasure of personal data; - request restriction of processing; - object to processing based on our legitimate interests; - receive or transfer data under the portability right when its legal conditions are met; and - withdraw consent at any time if a specific optional activity relies on consent, without affecting earlier lawful processing. These rights are not absolute. For example, we may retain proportionate security or moderation records where our compelling legitimate grounds override an objection, or where data is needed for a legal claim. We will explain any refusal or limitation. To exercise a right, email contact@arctic.tf and identify the relevant Steam account, server, approximate date, and feature if possible. We may verify that you control the relevant Steam account or operator account, but will not ask for more verification data than reasonably necessary. We normally respond within one month. For a complex request, the GDPR permits an extension of up to two further months; if that is necessary, we will tell you within the first month. You may also complain to the Finnish Data Protection Ombudsman or another competent supervisory authority: https://tietosuoja.fi/en/notification-to-the-data-protection-ombudsman 11. CHILDREN AND SENSITIVE INFORMATION Our services are intended for people who are permitted to use Steam and the relevant game, and are not designed for children under 13. We do not ask players for their age or real-world identity, so a Steam identifier does not normally tell us whether a player is a minor. A parent or guardian who believes we hold a child's personal data inappropriately should contact us. Please do not disclose real-world identity, passwords, health information, political or religious beliefs, or other sensitive information in public chat, sprays, commands, reports, or appeals. 12. SECURITY We use measures appropriate to a community service, including access controls, restricted administrative views, password hashing and hashed session or API tokens in protected operator tools, securely generated website authentication tokens, secure website transport, request-forgery and authentication-replay protections, and restricted access to diagnostic material. No online service or storage system can be guaranteed completely secure. 13. THIRD-PARTY SERVICES AND LINKS Steam and other third-party services process data under their own terms and privacy notices. External websites linked from arctic.tf are responsible for their own practices. Steam OpenID verifies control of a Steam account; it does not give us your Steam password. 14. CHANGES We may update this notice when our services or legal obligations change. We will publish the revised notice here, change the date at the top, and give additional notice where a change is important or materially affects players. 15. CONTACT For privacy questions, objections, requests, or concerns: Email: contact@arctic.tf Discord: https://discord.gg/wVfbNvqRKA Steam: https://steamcommunity.com/groups/arctic-tf