This document constitutes our Record of Processing Activities (ROPA) as required by GDPR Article 30. It provides a comprehensive overview of all personal data processing activities carried out by The Spencer Website.
Last Updated: 2026-05-20 ยท Review Frequency: Annually or upon significant changes
1. Overview
The Spencer Website processes personal data for the operation of our gaming platform, community features, and related services. This ROPA documents all processing activities to ensure transparency and regulatory compliance.
1.1 Legal Basis for Processing
| Purpose |
Legal Basis |
Description |
| Account Management |
Contract Performance (Art. 6(1)(b)) |
Processing is necessary for the performance of our service contract with users |
| Payment Processing |
Contract Performance (Art. 6(1)(b)) |
Processing is necessary for payment transactions |
| Security & Fraud Prevention |
Legitimate Interests (Art. 6(1)(f)) |
Processing is necessary for security and fraud prevention |
| Analytics & Improvement |
Legitimate Interests (Art. 6(1)(f)) |
Processing is necessary for service improvement and analytics |
| Marketing Communications |
Consent (Art. 6(1)(a)) |
Processing based on explicit user consent |
2. Data Controller Information
2.1 Controller Details
| Field |
Information |
| Controller Name |
The Spencer Website |
| Website |
https://thespencerwebsite.com |
| Contact Email |
support@thespencerwebsite.com |
| Data Protection Officer |
Not required (under 250 employees, no regular large-scale processing) |
| Representative in EEA |
Not required (no offering of goods/services to EEA data subjects) |
2.2 Joint Controllers
The Spencer Website acts as the sole data controller for all processing activities described in this document.
3. Processing Activities
3.1 User Account Management
| Aspect |
Details |
| Purpose |
User registration, authentication, account management |
| Data Categories |
Username, email address, password hash, IP address, user agent, account creation date, last login timestamp |
| Data Subjects |
Registered users, guest account users |
| Legal Basis |
Contract performance (Art. 6(1)(b)) |
| Retention |
Account active: Duration of account + 3 years after closure |
| Security |
Argon2id password hashing, HTTPS encryption, session hardening |
3.2 Payment Processing
| Aspect |
Details |
| Purpose |
Membership subscription processing, payment management |
| Data Categories |
Payment status, plan type, transaction timestamps, Stripe session IDs, IP address at time of transaction |
| Data Subjects |
Paying subscribers |
| Legal Basis |
Contract performance (Art. 6(1)(b)) |
| Retention |
7 years for financial records (tax compliance) |
| Third Parties |
Stripe (payment processor) - data processed under Stripe's privacy policy |
3.3 Device Fingerprinting & Security
| Aspect |
Details |
| Purpose |
Fraud prevention, account sharing detection, security monitoring |
| Data Categories |
IP address (SHA-256 hashed), browser user agent, screen resolution, GPU/WebGL renderer, canvas fingerprint hash, installed fonts hash, timezone, platform (OS) |
| Data Subjects |
All website visitors and users |
| Legal Basis |
Legitimate interests (Art. 6(1)(f)) - security and fraud prevention |
| Retention |
90 days for active security logs, 1 year for threat intelligence data |
| Security |
SHA-256 hashing for IPs, encrypted storage, access logging |
3.4 Usage Analytics
| Aspect |
Details |
| Purpose |
Service improvement, user behavior analysis, performance monitoring |
| Data Categories |
Page views, session data, game analytics, feature usage, performance metrics |
| Data Subjects |
All website visitors (with cookie consent) |
| Legal Basis |
Legitimate interests (Art. 6(1)(f)) with consent for cookies |
| Retention |
13 months for analytics data (aggregated) |
| Consent |
Required via cookie consent banner |
3.5 AI Chat Services
| Aspect |
Details |
| Purpose |
AI assistant functionality, conversational features |
| Data Categories |
Chat messages, AI responses, selected persona, conversation timestamps |
| Data Subjects |
Users who engage with AI chat features |
| Legal Basis |
Contract performance (Art. 6(1)(b)) |
| Retention |
90 days for chat logs, then automatic deletion |
| Third Parties |
Groq (AI provider) - messages processed for AI responses |
3.6 User Profile & Content
| Aspect |
Details |
| Purpose |
User profiles, community features, content management |
| Data Categories |
Nickname, description, about section, profile picture URL, uploaded images, user-generated content |
| Data Subjects |
Users with profiles |
| Legal Basis |
Contract performance (Art. 6(1)(b)) |
| Retention |
Account active: Duration of account; Account closed: 30 days |
| Security |
Admin approval for profile pictures, content moderation |
3.7 Communication & Support
| Aspect |
Details |
| Purpose |
Customer support, internal messaging (Smail), notifications |
| Data Categories |
Message content, sender/receiver information, timestamps, support inquiries |
| Data Subjects |
Users of messaging and support features |
| Legal Basis |
Contract performance (Art. 6(1)(b)) |
| Retention |
Messages: 90 days; Support tickets: 2 years |
4. Data Categories
4.1 Personal Data Processed
| Category |
Examples |
Sensitivity |
| Identification Data |
Username, email address |
Medium |
| Authentication Data |
Password hashes, session tokens |
High |
| Technical Data |
IP address, user agent, device fingerprint |
Medium |
| Transaction Data |
Payment status, subscription details |
High |
| Usage Data |
Page views, game analytics, feature usage |
Low |
| Communication Data |
Chat messages, support inquiries |
Medium |
| Profile Data |
Nickname, description, profile pictures |
Low-Medium |
5. Data Subjects
5.1 Categories of Data Subjects
- Website Visitors - Individuals who visit the website without creating an account
- Guest Account Users - Temporary passwordless accounts for community tier access
- Registered Users - Individuals with full accounts across all membership tiers
- Paying Subscribers - Users with premium or lifetime memberships
- Minors - Users under 18 (with parental consent) and under 13 (with verified parental consent)
5.2 Special Category Data
The Spencer Website does not process special category data as defined in GDPR Article 9 (race, ethnicity, political opinions, religious beliefs, biometric data, health data, etc.) with the exception of potential inferred data from user interactions which is not explicitly collected or stored.
6. Third-Party Data Sharing
6.1 Data Processors
| Processor |
Purpose |
Data Shared |
Location |
| Stripe, Inc. |
Payment processing |
Payment status, transaction IDs (no card data stored) |
USA |
| Groq |
AI chat processing |
Chat messages for AI responses |
USA |
6.2 Data Processing Agreements
All data processors are bound by their respective privacy policies and terms of service. For Stripe and Groq, data processing is conducted under standard commercial agreements that include GDPR-compliant data protection clauses.
7. International Data Transfers
7.1 Transfer Mechanisms
Personal data may be transferred to countries outside the EEA as follows:
- United States - Data transferred to Stripe, Groq, and Google
- Reliance on Standard Contractual Clauses (SCCs) where applicable
- Adequacy decisions under UK-US Data Bridge
- Processor compliance with GDPR through commercial agreements
7.2 Transfer Safeguards
All international transfers are protected by:
- HTTPS/TLS encryption for data in transit
- Contractual data protection clauses
- Processor compliance with applicable data protection laws
- Regular review of processor compliance
8. Data Retention Periods
8.1 Retention Schedule
| Data Category |
Retention Period |
Rationale |
| Account Data |
Account duration + 3 years after closure |
Legal compliance, dispute resolution |
| Payment Records |
7 years |
Tax compliance, financial regulations |
| Security Logs |
90 days (active), 1 year (threat intelligence) |
Security monitoring, incident response |
| Analytics Data |
13 months (aggregated) |
Service improvement, business analytics |
| Chat Logs |
90 days |
Moderation, safety, abuse prevention |
| Messages (Smail) |
90 days |
Operational efficiency, storage management |
| Support Tickets |
2 years |
Customer service, quality assurance |
| Cookie Consent |
6 months |
User preference management |
8.2 Data Deletion
Data is securely deleted upon expiration of retention periods or upon user request (account deletion). Deletion methods include:
- Secure file deletion for stored documents
- Database record deletion or anonymization
- Backup cleanup after retention period
9. Security Measures
9.1 Technical Security Measures
- Encryption: HTTPS/TLS 1.3 for all data in transit
- Password Security: Argon2id hashing with PEPPER_SECRET
- Session Management: Secure cookies, session fixation protection, user-agent binding
- Input Validation: CSRF protection, XSS prevention, SQL injection prevention
- Access Controls: Role-based access control, principle of least privilege
- Monitoring: Security logging, threat detection, rate limiting
9.2 Organizational Security Measures
- Access Policies: Limited administrative access, need-to-know basis
- Training: Security awareness for personnel with data access
- Incident Response: Documented breach response procedures
- Regular Reviews: Security assessments, policy updates
10. Data Subject Rights
10.1 Rights Under GDPR
Data subjects have the following rights:
- Right to Access (Art. 15) - Obtain confirmation and copy of personal data
- Right to Rectification (Art. 16) - Request correction of inaccurate data
- Right to Erasure (Art. 17) - Request deletion of personal data ("right to be forgotten")
- Right to Restrict Processing (Art. 18) - Limit processing of personal data
- Right to Data Portability (Art. 20) - Receive data in structured, machine-readable format
- Right to Object (Art. 21) - Object to processing based on legitimate interests
- Right to Withdraw Consent (Art. 7(3)) - Withdraw consent at any time
- Right to Lodge Complaint (Art. 77) - File complaint with supervisory authority
10.2 Exercising Rights
Data subjects may exercise their rights by:
- Email: support@thespencerwebsite.com
- Subject line: "Data Subject Rights Request"
- Response time: Within 30 days of receipt (extendable by 60 days for complex requests)
- Verification: Identity verification required before processing requests
10.3 Automated Decision Making
The Spencer Website does not use automated decision-making, including profiling, that produces legal or similarly significant effects on data subjects.