GDPR Record of Processing Activities (ROPA)

Complete documentation of personal data processing under GDPR Article 30.

Updated May 20, 2026 Version 1.0

This document constitutes our Record of Processing Activities (ROPA) as required by GDPR Article 30. It provides a comprehensive overview of all personal data processing activities carried out by The Spencer Website.

Last Updated: 2026-05-20 ยท Review Frequency: Annually or upon significant changes

1. Overview

The Spencer Website processes personal data for the operation of our gaming platform, community features, and related services. This ROPA documents all processing activities to ensure transparency and regulatory compliance.

1.1 Legal Basis for Processing

Purpose Legal Basis Description
Account Management Contract Performance (Art. 6(1)(b)) Processing is necessary for the performance of our service contract with users
Payment Processing Contract Performance (Art. 6(1)(b)) Processing is necessary for payment transactions
Security & Fraud Prevention Legitimate Interests (Art. 6(1)(f)) Processing is necessary for security and fraud prevention
Analytics & Improvement Legitimate Interests (Art. 6(1)(f)) Processing is necessary for service improvement and analytics
Marketing Communications Consent (Art. 6(1)(a)) Processing based on explicit user consent

2. Data Controller Information

2.1 Controller Details

Field Information
Controller Name The Spencer Website
Website https://thespencerwebsite.com
Contact Email support@thespencerwebsite.com
Data Protection Officer Not required (under 250 employees, no regular large-scale processing)
Representative in EEA Not required (no offering of goods/services to EEA data subjects)

2.2 Joint Controllers

The Spencer Website acts as the sole data controller for all processing activities described in this document.

3. Processing Activities

3.1 User Account Management

Aspect Details
Purpose User registration, authentication, account management
Data Categories Username, email address, password hash, IP address, user agent, account creation date, last login timestamp
Data Subjects Registered users, guest account users
Legal Basis Contract performance (Art. 6(1)(b))
Retention Account active: Duration of account + 3 years after closure
Security Argon2id password hashing, HTTPS encryption, session hardening

3.2 Payment Processing

Aspect Details
Purpose Membership subscription processing, payment management
Data Categories Payment status, plan type, transaction timestamps, Stripe session IDs, IP address at time of transaction
Data Subjects Paying subscribers
Legal Basis Contract performance (Art. 6(1)(b))
Retention 7 years for financial records (tax compliance)
Third Parties Stripe (payment processor) - data processed under Stripe's privacy policy

3.3 Device Fingerprinting & Security

Aspect Details
Purpose Fraud prevention, account sharing detection, security monitoring
Data Categories IP address (SHA-256 hashed), browser user agent, screen resolution, GPU/WebGL renderer, canvas fingerprint hash, installed fonts hash, timezone, platform (OS)
Data Subjects All website visitors and users
Legal Basis Legitimate interests (Art. 6(1)(f)) - security and fraud prevention
Retention 90 days for active security logs, 1 year for threat intelligence data
Security SHA-256 hashing for IPs, encrypted storage, access logging

3.4 Usage Analytics

Aspect Details
Purpose Service improvement, user behavior analysis, performance monitoring
Data Categories Page views, session data, game analytics, feature usage, performance metrics
Data Subjects All website visitors (with cookie consent)
Legal Basis Legitimate interests (Art. 6(1)(f)) with consent for cookies
Retention 13 months for analytics data (aggregated)
Consent Required via cookie consent banner

3.5 AI Chat Services

Aspect Details
Purpose AI assistant functionality, conversational features
Data Categories Chat messages, AI responses, selected persona, conversation timestamps
Data Subjects Users who engage with AI chat features
Legal Basis Contract performance (Art. 6(1)(b))
Retention 90 days for chat logs, then automatic deletion
Third Parties Groq (AI provider) - messages processed for AI responses

3.6 User Profile & Content

Aspect Details
Purpose User profiles, community features, content management
Data Categories Nickname, description, about section, profile picture URL, uploaded images, user-generated content
Data Subjects Users with profiles
Legal Basis Contract performance (Art. 6(1)(b))
Retention Account active: Duration of account; Account closed: 30 days
Security Admin approval for profile pictures, content moderation

3.7 Communication & Support

Aspect Details
Purpose Customer support, internal messaging (Smail), notifications
Data Categories Message content, sender/receiver information, timestamps, support inquiries
Data Subjects Users of messaging and support features
Legal Basis Contract performance (Art. 6(1)(b))
Retention Messages: 90 days; Support tickets: 2 years

4. Data Categories

4.1 Personal Data Processed

Category Examples Sensitivity
Identification Data Username, email address Medium
Authentication Data Password hashes, session tokens High
Technical Data IP address, user agent, device fingerprint Medium
Transaction Data Payment status, subscription details High
Usage Data Page views, game analytics, feature usage Low
Communication Data Chat messages, support inquiries Medium
Profile Data Nickname, description, profile pictures Low-Medium

5. Data Subjects

5.1 Categories of Data Subjects

  • Website Visitors - Individuals who visit the website without creating an account
  • Guest Account Users - Temporary passwordless accounts for community tier access
  • Registered Users - Individuals with full accounts across all membership tiers
  • Paying Subscribers - Users with premium or lifetime memberships
  • Minors - Users under 18 (with parental consent) and under 13 (with verified parental consent)

5.2 Special Category Data

The Spencer Website does not process special category data as defined in GDPR Article 9 (race, ethnicity, political opinions, religious beliefs, biometric data, health data, etc.) with the exception of potential inferred data from user interactions which is not explicitly collected or stored.

6. Third-Party Data Sharing

6.1 Data Processors

Processor Purpose Data Shared Location
Stripe, Inc. Payment processing Payment status, transaction IDs (no card data stored) USA
Groq AI chat processing Chat messages for AI responses USA

6.2 Data Processing Agreements

All data processors are bound by their respective privacy policies and terms of service. For Stripe and Groq, data processing is conducted under standard commercial agreements that include GDPR-compliant data protection clauses.

7. International Data Transfers

7.1 Transfer Mechanisms

Personal data may be transferred to countries outside the EEA as follows:

  • United States - Data transferred to Stripe, Groq, and Google
    • Reliance on Standard Contractual Clauses (SCCs) where applicable
    • Adequacy decisions under UK-US Data Bridge
    • Processor compliance with GDPR through commercial agreements

7.2 Transfer Safeguards

All international transfers are protected by:

  • HTTPS/TLS encryption for data in transit
  • Contractual data protection clauses
  • Processor compliance with applicable data protection laws
  • Regular review of processor compliance

8. Data Retention Periods

8.1 Retention Schedule

Data Category Retention Period Rationale
Account Data Account duration + 3 years after closure Legal compliance, dispute resolution
Payment Records 7 years Tax compliance, financial regulations
Security Logs 90 days (active), 1 year (threat intelligence) Security monitoring, incident response
Analytics Data 13 months (aggregated) Service improvement, business analytics
Chat Logs 90 days Moderation, safety, abuse prevention
Messages (Smail) 90 days Operational efficiency, storage management
Support Tickets 2 years Customer service, quality assurance
Cookie Consent 6 months User preference management

8.2 Data Deletion

Data is securely deleted upon expiration of retention periods or upon user request (account deletion). Deletion methods include:

  • Secure file deletion for stored documents
  • Database record deletion or anonymization
  • Backup cleanup after retention period

9. Security Measures

9.1 Technical Security Measures

  • Encryption: HTTPS/TLS 1.3 for all data in transit
  • Password Security: Argon2id hashing with PEPPER_SECRET
  • Session Management: Secure cookies, session fixation protection, user-agent binding
  • Input Validation: CSRF protection, XSS prevention, SQL injection prevention
  • Access Controls: Role-based access control, principle of least privilege
  • Monitoring: Security logging, threat detection, rate limiting

9.2 Organizational Security Measures

  • Access Policies: Limited administrative access, need-to-know basis
  • Training: Security awareness for personnel with data access
  • Incident Response: Documented breach response procedures
  • Regular Reviews: Security assessments, policy updates

10. Data Subject Rights

10.1 Rights Under GDPR

Data subjects have the following rights:

  • Right to Access (Art. 15) - Obtain confirmation and copy of personal data
  • Right to Rectification (Art. 16) - Request correction of inaccurate data
  • Right to Erasure (Art. 17) - Request deletion of personal data ("right to be forgotten")
  • Right to Restrict Processing (Art. 18) - Limit processing of personal data
  • Right to Data Portability (Art. 20) - Receive data in structured, machine-readable format
  • Right to Object (Art. 21) - Object to processing based on legitimate interests
  • Right to Withdraw Consent (Art. 7(3)) - Withdraw consent at any time
  • Right to Lodge Complaint (Art. 77) - File complaint with supervisory authority

10.2 Exercising Rights

Data subjects may exercise their rights by:

  • Email: support@thespencerwebsite.com
  • Subject line: "Data Subject Rights Request"
  • Response time: Within 30 days of receipt (extendable by 60 days for complex requests)
  • Verification: Identity verification required before processing requests

10.3 Automated Decision Making

The Spencer Website does not use automated decision-making, including profiling, that produces legal or similarly significant effects on data subjects.