1. Who is responsible
Perdix is currently operated by Jacob Ellekær Hansen, trading as Perdix. Jacob Ellekær Hansen is the data controller for the processing described in this policy.
Carl Jacobsens Vej 19P, Denmark
[email protected]
If Perdix is later incorporated, this section will be updated before the new entity assumes responsibility for personal data.
2. Data we process
Perdix stores LP snapshots so a linked profile can display progression over time. Local profile caches can include up to 100 recent ranked matches and the public Riot identifiers and gameplay statistics of every participant in those matches.
If Premium launches, Perdix and its announced payment provider will also process the billing and subscription information needed to take payment, administer renewals, issue refunds, and meet accounting obligations. The payment provider and the exact data flow will be disclosed before checkout launches. Perdix does not currently collect payment-card information.
Your name, email address, password, age confirmation, and acceptance of the Terms are required to create a Perdix account; without them, Perdix cannot provide account features. Submitting or linking a Riot ID is optional, but Perdix cannot provide the related profile or analysis feature without it.
Perdix does not use personal data for marketing email and does not collect special-category data intentionally.
3. Riot data and sources
Account details are provided directly by the person creating an account. Riot profile and match data are obtained from Riot Games APIs after someone enters or links a public Riot ID. Data Dragon supplies game assets such as champion, item, and profile images. Perdix does not require proof that the person submitting a Riot ID controls it.
This means Perdix can process information about another League of Legends player—including other participants in a submitted player's matches—without receiving it directly from that player. The categories, purposes, legal bases, recipients, retention periods, and rights for that information are set out in this policy. Perdix generally has no email or other direct contact details for those players, so this public policy is the principal notice provided to them.
Where GDPR Article 14 applies because Perdix did not obtain the information from the player directly, this is the information Perdix makes available to that player. The source is Riot Games' APIs and the information consists of public Riot identifiers, profile/rank data, and match participation and performance data. Perdix will assess whether any additional notice steps are required for a particular use.
Perdix also uses public Riot data in features such as Pro Player Preview, The Masters Race, and representative product examples. You may object to a use associated with your Riot ID by contacting [email protected].
4. Why we use data
- Provide the service
- Create and secure an account; keep a user signed in; link or analyse public Riot IDs; build profile, LP, match-history, and analysis features; save reports; and later administer Premium. The legal basis is performance of a contract or steps requested before entering one (GDPR Article 6(1)(b)).
- Operate safely
- Limit abusive requests, diagnose errors, keep service and access logs, protect accounts, and enforce the Terms. The legal basis is Perdix's legitimate interests in operating a reliable and secure service (Article 6(1)(f)).
- Public Riot analysis
- Retrieve, cache, compare, and display public Riot profile and match information, including public previews and rankings. The legal basis is Perdix's legitimate interest in providing gameplay analysis from data made available through Riot (Article 6(1)(f)), balanced against the limited and game-related nature of that information and the rights described below.
- Improve Perdix
- Evaluate feature performance, fix defects, and improve analytical methods using service and gameplay data. The legal basis is legitimate interests (Article 6(1)(f)). Where practical, Perdix uses aggregated or de-identified information.
- Meet legal duties
- Keep required transaction and accounting records, respond to lawful requests, and establish or defend legal claims. The legal basis is legal obligation (Article 6(1)(c)) or legitimate interests (Article 6(1)(f)), as applicable.
- Consent
- If Perdix later introduces an optional feature that requires consent, it will request consent separately and allow it to be withdrawn (Article 6(1)(a)). Perdix does not currently use consent-based analytics or advertising trackers.
5. Who receives data
Perdix does not sell personal data. Data can be disclosed to:
- Cloudflare, which proxies traffic to the self-hosted Perdix server and can process IP addresses, request metadata, and security information.
- Riot Games, when Perdix requests public account, rank, or match information through Riot APIs. Riot and Data Dragon also provide game assets used by the site.
- Google Fonts, which the browser contacts to load the Oswald typeface and can receive connection information such as an IP address.
- Discord, only if you choose the external “Join Discord” link. Discord then receives the normal information sent when visiting its service.
- A future payment provider, only after Premium checkout launches and after the provider is identified to you.
- Professional advisers, competent authorities, courts, or another operator where disclosure is necessary and lawful, including in connection with a genuine restructuring or transfer of Perdix.
Analysis reports may be shared by users under the Terms of service. Perdix analysis URLs and outputs should not be treated as confidential storage; do not submit information you need to keep secret.
6. International transfers
Perdix is hosted on a physical machine in Denmark. It does not currently use cloud backup storage, although limited local maintenance copies of Riot cache material can exist on storage controlled by Perdix. Cloudflare, Google, Riot Games, Discord, and a future payment provider may process information outside Denmark or the European Economic Area, including in the United States.
Where the GDPR requires a transfer safeguard, the relevant provider may rely on an adequacy decision (including an applicable EU–US Data Privacy Framework certification), the European Commission's standard contractual clauses, or another lawful mechanism. For example, Cloudflare describes its applicable transfer mechanisms in its Data Processing Addendum. Contact Perdix if you want information about the safeguard relevant to your data.
7. Cookies and tracking
When you sign up or log in, Perdix sets perdix_session. It keeps you authenticated for up to 30 days. It is HTTP-only and SameSite=Lax, and is marked Secure over HTTPS. Because it is necessary to provide the requested account service, it does not require optional cookie consent.
The browser may briefly place the email used during an account-flow redirect in session storage; it is removed after it is read and ordinarily disappears when the browser tab or session closes.
Perdix currently uses no analytics, advertising, behavioural-profiling, or marketing trackers.
8. How long data is kept
The periods below are Perdix's retention criteria. Records become eligible for deletion or anonymisation when the relevant period ends and are removed through account deletion, a verified request, or periodic maintenance. Automated inactivity expiry is not currently active, so you should contact Perdix if you want deletion before the next maintenance review.
- Account and linked-profile data, including LP history: eligible for deletion when you delete the account or after 24 months of account inactivity.
- Stored match data, generated analyses, and analysis files: eligible for deletion on a verified deletion request or 12 months after their last use. Data also needed for another user's independently requested history or an identified public feature may be retained under its own lawful basis.
- Sessions: up to 30 days, unless you log out or revoke them earlier.
- Request and security logs: up to 30 days. In-memory rate-limit entries and analysis-job status are normally removed much sooner.
- Premium transaction records: if Premium launches, for the period required by Danish accounting, tax, consumer, and limitation rules.
- Local maintenance copies: Perdix does not currently use cloud backups. Historical local copies of Riot cache material are eligible for deletion under the same criteria above. The self-service controls remove data from the active service, but a request concerning a legacy local copy should also be sent to [email protected] so it can be identified and handled during the retention review.
Perdix may retain a limited record longer where necessary to comply with law, resolve a dispute, prevent fraud, or establish, exercise, or defend a legal claim. Wherever possible, information kept for those reasons is isolated from ordinary use.
9. How data is protected
Perdix uses measures designed to protect data, including password hashing with a unique salt, hashed server-side session tokens, HTTP-only session cookies, HTTPS through Cloudflare in production, request-size and rate limits, restrictive browser security headers, and access controls around account features. Data is stored locally on the self-hosted server in Denmark.
No online service is completely secure. If you believe your account or data is at risk, contact [email protected] promptly.
10. Your data rights
Depending on the circumstances, the GDPR gives you the right to:
- obtain access to your personal data and a copy of it;
- correct inaccurate or incomplete information;
- delete data, including your Perdix account and attributable profile, match-cache, and analysis data;
- unlink a Riot ID and stop future linked-profile updates;
- restrict processing in certain situations;
- receive data you provided in a structured, commonly used, machine-readable format where portability applies;
- object to processing based on legitimate interests, including a public feature associated with your Riot ID; and
- withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing.
Account settings let account holders download their data, unlink a Riot ID, and delete their account. You can also send a request to [email protected]. Perdix may need to verify your identity and ask for the relevant Riot ID or account details. Requests are normally answered within one month, subject to lawful extensions and exceptions.
You may complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, through datatilsynet.dk. You may also contact the supervisory authority where you live or work.
11. Age limits
Perdix is not intended for children under 16 and does not knowingly create accounts for them. If you believe someone under 16 has provided account data, contact Perdix so it can be investigated and removed. Premium purchases require the purchaser to be at least 18 or to have valid authorization from a parent or legal guardian.
12. Automated analysis
Perdix uses automated mathematical and statistical methods to generate gameplay classifications, comparisons, review moments, and recommendations. Those outputs are informational and can be incomplete or wrong. They do not produce legal or similarly significant decisions about a person. Users should apply their own judgment and must not use reports for competitive decision-making.
13. Changes and contact
This policy may change as Perdix develops, including when Premium, a payment provider, new hosting, or optional technologies launch. The effective date will be updated. Material changes will be highlighted on the service or sent to account holders by service email where appropriate before they take effect.
Questions, requests, and privacy concerns can be sent to [email protected] or by post to Jacob Ellekær Hansen, trading as Perdix, Carl Jacobsens Vej 19P, Denmark.