Privacy & Cookies Policy
Clear information about what the portal stores, why it is needed, how long it is kept and how to exercise your privacy rights.
1. Who is responsible?
- Controller
- Robert Sjöström, operator of Majorhost.se and Majorhost Outbreak
- Privacy contact
- privacy@majorhost.se
- Country
- Sweden
- Postal contact
- Privacy enquiries should primarily be sent to privacy@majorhost.se. Additional contact details can be provided when reasonably required.
Majorhost Outbreak is an independent, non-commercial fan project. It is not operated by or affiliated with Capcom or obsrv.org.
2. Personal data processed
Account and profile
Username, email, password hash, verification state, game scope, display name, biography, avatar metadata, public-profile settings and account condition.
Security and network
IP addresses, browser user-agent, remembered-login metadata, rate limits, security audit events, shared-network detection and Game Auto-login mappings.
Community content
Forum threads and posts, community chat, Looking to Play rooms and chat, private messages, blocks, reports and moderation records.
Game activity
File 1/File 2 account existence, connection state, session start and end times, total playtime, rank, last played time and applicable ban records.
Community role and support
Community role, VIP status, validity dates and an internal reference note. Majorhost does not store payment-card numbers.
Privacy operations
Policy acknowledgements, personal-data requests, administrator responses and incident records where necessary.
3. Purposes and legal bases
Read GDPR Article 6 ↗| Purpose | Legal basis |
|---|---|
| Create and operate accounts, login, game access, profiles, forum, messages and LFG. | Contract / requested serviceArticle 6(1)(b) ↗ |
| Protect accounts, detect abuse, investigate cheating, moderate content and maintain service reliability. | Legitimate interestsArticle 6(1)(f) ↗ |
| Maintain records required by law and respond to authorities where legally required. | Legal obligationArticle 6(1)(c) ↗ |
| Publish optional profile details and optional community visibility choices. | Consent / user choiceArticle 6(1)(a) ↗ |
The rank system is calculated automatically from recorded playtime. It is a community feature and is not used for decisions that produce legal or similarly significant effects. Moderation decisions are reviewed by an administrator.
4. Sources and recipients
Information is provided by you, generated when you use the portal or game servers, or recorded by administrators during moderation and support.
Infrastructure: The portal is self-hosted in Sweden and uses supporting server infrastructure in the European Union.
Recipient categories: VPS and network providers supporting the game, DNS and database services; domain and DNS service providers; and email delivery infrastructure. Personal data may also be disclosed to competent public authorities when required by law. Majorhost does not sell personal data and does not currently use payment providers, advertising networks or analytics tracking.
Access is limited to the administrator and moderators who need the information for their assigned task. No payment provider is currently integrated into the portal. If voluntary donations are enabled later, the privacy policy and recipient information must be updated first.
5. Retention
| Data | Default retention |
|---|---|
| Portal session cookie | Until the browser session ends. |
| Remember me key | Up to 30 days or until revoked. |
| Expired verification/reset tokens and expired remembered sessions | Automatically removed after a short technical grace period. |
| IP addresses in ordinary security and community logs | Anonymized after 90 days unless needed for an active incident, report or legal claim. |
| Closed Looking to Play room history | 90 days when automatic purge is enabled; protected moderation archives follow the separate archive schedule. |
| Resolved moderation reports | 365 days by default. |
| Active account, profile, rank and playtime | While the account remains active, subject to erasure and legal exceptions. |
| Completed privacy requests and incident documentation | Kept for accountability according to the configured compliance schedule. |
| Infrastructure backups | According to the administrator's separate backup-rotation policy. Deletion from backups takes effect as backups expire. |
7. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. You may withdraw consent for optional processing.
Logged-in users can download an automated JSON export and submit a tracked request under Account → Privacy & Personal Data. Requests are normally answered within one month. Identity checks may be required before sensitive information is released or an account is erased.
Erasure is not absolute. Limited information may be retained when necessary for security, the rights of other users, legal claims or a legal obligation.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY).
8. Security incidents and policy changes
Majorhost maintains an internal incident log and response checklist. Incidents are assessed for risk, documented and reported to the competent authority when required. Affected users are informed when the applicable threshold is met.
Material policy changes are announced through the portal. Existing users are shown a new acknowledgement notice when the configured policy version changes.