Legal

Privacy Policy

How Project Oche handles personal data under the GDPR.

Version 1.0Status Pre-launchEffective To be confirmed before real-money launchLast updated To be confirmed before real-money launch

Pre-launch terms. Real-money services are not yet enabled.

1.Who is responsible for your data

Project Oche is the controller responsible for personal data processed through the Project Oche platform.

Project Oche · Populierenlaan 14 · 2821 BB Stolwijk · The Netherlands

Data protection contact: info@projectoche.com. We have not appointed a Data Protection Officer; we are not required to.

2.What we collect

Account data — email address, password (stored only as a secure hash), display name, country, optional avatar, optional scoring-system identifier, account status and role.

Player and competition data — declared and verified three-dart average, division eligibility, tournament entries, waitlist position, check-in status, results, achievements such as highest checkout and 180s, and prize allocations.

Registration and pricing data — the tournaments you register for, the Tournament Entry Amount, Platform Fee and Total Registration Price recorded for that registration, currency, and the registration payment status held on our own records. Real-money payment processing is not yet enabled, so we do not receive or store card numbers or other payment credentials.

Legal acceptance records — the legal bundle and version you accepted, the identifier of the exact immutable legal release, the acceptance timestamp, the tournament the acceptance relates to where applicable, and the pricing shown to you at that moment. These records are evidence of what you agreed to and cannot be edited or deleted by users.

Communications data — transactional emails we send you, their delivery status, and any support, dispute or complaint correspondence.

Technical data — IP address, device and browser information, session and authentication events, security and rate-limiting signals, and administrative audit log entries recording actions taken on your account or entries.

We do not knowingly collect special category data, and we do not ask for it. Please do not include health, biometric or similar sensitive information in free-text fields.

3.Why we process it, and our legal basis

Providing the service — creating and running your account, tournament registration, waitlists, check-in, results and prizes. Legal basis: performance of a contract.

Registration pricing, and future payments and payouts — recording what you owe or paid and, once enabled, taking registration payments and paying prizes. Legal basis: performance of a contract, and legal obligation for accounting records.

Evidence of agreement — storing which legal release you accepted and when. Legal basis: performance of a contract, and our legitimate interest in being able to prove the agreed terms.

Competitive integrity — verifying averages and eligibility, investigating disputes and suspected cheating, and enforcing our policies. Legal basis: legitimate interests in fair competition, and performance of a contract.

Security and abuse prevention — authentication, rate limiting, fraud detection and audit logging. Legal basis: legitimate interests, and legal obligation where applicable.

Service emails — registration confirmations, check-in reminders, result and prize notifications. Legal basis: performance of a contract.

Legal and accounting obligations — tax, financial administration and responding to lawful requests. Legal basis: legal obligation.

Any optional marketing email would be sent only with your consent, and you can withdraw that consent at any time. Withdrawing it does not stop service emails you need to take part in tournaments.

4.Who we share data with

We do not sell personal data. We share it only with processors and partners who need it to deliver the service:

  • our hosting, database and authentication infrastructure provider;
  • our transactional email provider, to deliver service emails;
  • professional advisers, and public authorities where we are legally required to disclose.

We do not currently send personal data to a payment service provider or a payout provider, because real-money payments and payouts are not enabled. When they are enabled, a regulated payment service provider will become a recipient for the data needed to process a payment, refund or payout, and this policy will be updated to name it before the first real-money tournament.

We do not currently send personal data to an automated scoring provider. Scolia is not integrated with the Platform. If an integration is activated, scoring and match data will be shared for the tournaments concerned and this policy will be updated first.

The identity of each named sub-processor will be published here before real-money launch. Processors act on our instructions under a data processing agreement.

Limited competition information is public by design: your display name, country, division, tournament participation, results and published prize allocations may be visible to other players on tournament pages and leaderboards. Your email address and any future payout details are never shown publicly.

5.International transfers

Our providers may process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses together with any additional safeguards required.

You can ask us for information about the safeguards applying to a specific transfer at info@projectoche.com.

6.How long we keep it

  • Account data — for as long as your account is open, and for a limited period afterwards to handle disputes and legal claims.
  • Tournament, result and prize data — retained as part of the competitive record; this may be kept after account closure in a reduced form.
  • Registration, refund and future payout records — kept for the statutory financial retention period, which in the Netherlands is seven years.
  • Legal acceptance records — kept for as long as needed to evidence the agreement, and in any event for the statutory limitation period applying to claims.
  • Security, authentication and audit log data — kept for a period proportionate to security and dispute-handling needs.
  • Email delivery records — kept for a limited period to prove delivery and to troubleshoot.

When a retention period ends we delete the data or irreversibly anonymise it.

7.Your rights

Under the GDPR you have the right to access your data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent.

To exercise a right, email info@projectoche.com from the address on your account. We respond within one month; complex requests may take longer and we will tell you if so.

Some rights are limited. We cannot delete records we must keep for accounting, fraud prevention, evidence of accepted terms or the integrity of a completed competition, and we may keep a minimal record of a banned account to enforce the ban.

If you are unhappy with how we handle your data you can complain to your national supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens.

8.How we protect data

Access to player data is controlled at database level with row-level security, so players can only reach their own records. Administrative actions run through restricted server-side functions and are recorded in an audit log.

Legal releases are immutable once published, and acceptance records cannot be modified or deleted by users.

Passwords are hashed by our authentication provider and checked against known-breached password lists. Traffic is encrypted in transit.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.

9.Children

Project Oche is not intended for anyone under 18. We do not knowingly process data of under-18s; if we discover such an account we close it and delete the data we are not required to keep.

10.Changes to this policy

We may update this policy as the service develops. The version and last-updated date are shown at the top of this page, and each published version is stored as an immutable release. Material changes will be communicated by email or in the Platform.