Privacy Policy for OrdoBall

Last updated: October 23, 2025

1. Introduction and Data Controller

OrdoBall ("we", "us" or "our") is committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (GDPR). This policy explains how we collect, use, and protect your information when you use our platform.

Data Controller Identity:

  • Legal Entity: EMNEA Anfinsen
  • Address:
  • Data Protection Contact: eirik@emnea.io

2. Personal Data We Collect, Purposes, and Legal Basis

We collect and process the following categories of personal data for the specified purposes and based on the legal grounds outlined below:

A. Account Data

Examples: Name, email address, username, password (encrypted)

Purpose: To establish and manage your user account, verify identity, and provide access to the service.

Legal Basis: Necessary for the performance of a contract (GDPR Art. 6(1)(b))

Retention: Until account deletion + 90 days for administrative cleanup

B. Usage and Competition Data

Examples: Predictions/forecasts, league memberships, scores, rankings, activity logs

Purpose: To enable participation in leagues, calculate results, display public rankings, and manage competitions.

Legal Basis: Necessary for the performance of a contract (GDPR Art. 6(1)(b))

Retention: Duration of the league + 12 months, or until account deletion

C. Technical & Security Data

Examples: IP address, browser type/version, device information, activity logs (access times)

Purpose: To ensure security, integrity, and operational health of the platform, prevent fraud, and diagnose technical issues.

Legal Basis: Legitimate Interest (GDPR Art. 6(1)(f)) - protecting platform and users from misuse

Retention: 90 days for security logs, then anonymised or deleted

D. Communication Data

Examples: Your query via contact form, support tickets, feedback

Purpose: To handle inquiries, provide customer support, and improve the service based on feedback.

Legal Basis: Legitimate Interest (GDPR Art. 6(1)(f)) - to provide responsive customer service

Retention: 6 months after a support ticket is closed

3. Sharing and Disclosure of Personal Data

We do NOT sell, rent, or share your personal data with external companies for marketing or advertising purposes.

However, to operate our service, we must share data with essential external service providers who act as our Data Processors and only process data on our behalf and under our instructions.

Categories of Third-Party Recipients (Data Processors):

  • Hosting and Cloud Services: [Insert name, e.g., Vercel, AWS] for secure data storage and platform operation
  • Email Communication Services: [Insert name, e.g., SendGrid, Resend] for sending system notifications
  • Security Services: [Insert name, e.g., Cloudflare] for network traffic management and DDoS protection

International Data Transfers:

If we transfer your personal data outside the European Economic Area (EEA), we ensure protection by using Standard Contractual Clauses (SCCs) approved by the European Commission or other appropriate safeguards.

4. Data Security

We implement robust technical and organisational measures to protect your personal information. These measures are designed to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.

Our security includes:

  • Encryption of data in transit (HTTPS/SSL) and sensitive data at rest (e.g., password hashing)
  • Access control mechanisms based on the "need-to-know" principle
  • Regular security assessments

5. Cookies Policy

We use cookies to ensure the proper functioning of the service (e.g., keeping you logged in) and to analyse usage patterns. In compliance with the ePrivacy Directive (Cookie Law), we employ a consent mechanism for non-essential cookies.

Essential Cookies:

These are strictly necessary for the operation of the website (e.g., session cookies). No consent is required for these.

Analytical/Preference Cookies:

These are used for tracking site traffic and saving user preferences. We require your explicit consent to use these.

You can manage your cookie preferences through:

  • Our Cookie Consent Banner upon first visit
  • Your browser settings

6. Your Data Protection Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

  • The Right to Access: You have the right to request copies of your personal data.
  • The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • The Right to Erasure ("Right to be Forgotten"): You have the right to request that we erase your personal data, under certain conditions.
  • The Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • The Right to Object to Processing: You have the right to object to our processing of your personal data where the legal basis is Legitimate Interest.
  • The Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organisation, or directly to you, under certain conditions.
  • The Right to Withdraw Consent: Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time.

To exercise these rights, please contact us using the details provided in Section 1. We will respond to your request within one month.

7. Right to Lodge a Complaint

If you have concerns about our processing of your personal data, you have the right to lodge a complaint with the relevant supervisory authority.

Supervisory Authority: The Norwegian Data Protection Authority (Datatilsynet) or your local data protection authority

Contact Details: www.datatilsynet.no

8. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date, or by sending an email notification to registered users.

9. Contact Us

If you have any questions about this privacy policy or our use of your personal data, please contact us:

Email: privacy@ordoball.com

Or via our: Contact Form