Privacy Policy

Last updated: 18 August 2026

This notice is provided under Articles 13–14 of Regulation (EU) 2016/679 (GDPR) and takes into account transparency expectations under Regulation (EU) 2024/1689 (EU AI Act). It explains how RaidRoster processes personal data when you use https://raidroster.eu, the RaidRoster desktop client, and the related World of Warcraft addons.

1. Data controller

Controller: RaidRoster (raidroster.eu). Contact for privacy requests: info@raidroster.eu. If a company legal name / VAT ID is published later on this page, it will replace this operational designation.

2. Scope of the service

RaidRoster provides: (a) download of the desktop client and WoW addons; (b) user accounts; (c) optional Battle.net linking to scan characters/guilds; (d) roster sync between the game addon and our API. The public site no longer publishes guide CMS content.

3. Categories of personal data

  • Account data: email address, display name, password hash, email verification status, session/login metadata.
  • Battle.net / Blizzard data (only if you link the account): BattleTag, account identifiers needed for OAuth, character and guild metadata returned by Blizzard APIs (e.g. names, realms, item level, mythic+ rating, guild membership/ranks).
  • Roster sync data: raid roster fields you or your officers push/pull (roles, notes, attendance-related fields, revision history metadata). Guild officers can sync roster data that may include other players’ character names as they appear in WoW.
  • Technical data: IP address, user-agent, approximate timestamps, security logs, CSRF/session cookies needed to operate the site and API.
  • We do not intentionally collect special-category data (Art. 9 GDPR). Do not put health, political, religious or similar data in notes fields.

4. Purposes and legal bases

  • Provide the account, downloads, Battle.net scan and roster sync you request — Art. 6(1)(b) GDPR (contract / pre-contractual steps).
  • Security, abuse prevention, debugging API/client sync, service integrity — Art. 6(1)(f) GDPR (legitimate interests).
  • Compliance with legal obligations (e.g. responding to lawful requests) — Art. 6(1)(c) GDPR.
  • Optional notifications (e.g. Discord webhook you configure for a guild) or non-essential cookies if introduced — Art. 6(1)(a) GDPR (consent), withdrawable at any time.

5. Automated processing and EU AI Act

RaidRoster’s core features (account, Battle.net sync, roster API, addon distribution) are conventional software and API processing. They are not marketed as an AI system that produces legal or similarly significant effects on individuals.

  • We do not use profiling or automated decision-making under Art. 22 GDPR to grant/deny access to rights, credit, employment, or similar. Roster and character stats are technical game data you choose to sync.
  • If we later offer features that use generative AI or other AI models interacting with users (e.g. assistants), we will clearly disclose that interaction, the purpose, and meaningful information about the logic, consistent with AI Act transparency obligations for the relevant risk class.
  • We do not engage in AI Act prohibited practices (e.g. social scoring by public authorities, untargeted scraping of facial images from the internet for recognition databases, exploitative emotion recognition in the workplace/education as banned).
  • Where any future automated assessment could materially affect a user, we will provide a channel for human review upon request.

6. Recipients and processors

Data may be processed by: hosting/infrastructure providers operating the site and database; Blizzard Entertainment as independent controller of Battle.net when you authenticate there; optionally Discord if a guild configures a webhook (message content you trigger). We do not sell personal data.

7. International transfers

Battle.net OAuth and Blizzard APIs may involve processing outside the EEA (notably the United States). Transfers rely on Blizzard’s applicable safeguards (e.g. Standard Contractual Clauses / other GDPR Art. 46 mechanisms as published by Blizzard). Hosting is configured for the service’s operational region; ask us if you need the current hosting location.

8. Retention

Account and linked character/guild data: kept while the account is active. After deletion request or prolonged inactivity we delete or anonymise within a reasonable period (target: within 30 days after confirmed account deletion, unless a longer retention is required for security/legal claims). Security logs: typically up to 12 months. Backups: rotated according to infrastructure schedules.

9. Your rights

You may request access, rectification, erasure, restriction, portability, and objection where applicable (Arts. 15–21 GDPR). You may lodge a complaint with your supervisory authority (in Italy: Garante per la protezione dei dati personali — https://www.garanteprivacy.it). To exercise rights, email info@raidroster.eu from the address linked to your account.

10. Security

We use industry-standard measures (HTTPS, hashed passwords, authenticated API tokens, access controls). No method of transmission or storage is 100% secure; please use a strong unique password.

11. Cookies and similar technologies

Essential cookies/session storage are used for login, CSRF protection and locale. We do not run advertising trackers on the site-v2 hub. If analytics cookies are reintroduced, we will update this notice and request consent where required.

12. Minors

The service is intended for users who can create a Battle.net / game account under Blizzard’s terms. If you believe a minor’s data was provided without appropriate authority, contact us to delete it.

13. Changes

We may update this notice when the service or law changes. The “Last updated” date at the top will change; significant changes may also be highlighted on the site.