GAIN GDPR Privacy Notice
1. Data Controller
GAIN (https://highiqsocieties.com/) is the data controller responsible for processing personal data collected via this website.
2. Personal Data We Collect
We collect only the necessary data to fulfill your membership and site activities, including:
- Account information: username, email, password (securely hashed)
- Game data: chess results, society memberships
- Usage logs: IP address, device/browser type, session times
- Optional profile data: avatar, bio (styled as public unless set private)
3. Purposes & Legal Basis
We process data to:
- Facilitate your membership and gameplay (contract basis)
- Maintain and display score history and society affiliations
- Send essential service notifications (legitimate interest)
- Track sessions and address bugs/security issues (legitimate interest)
All processing is lawful under GDPR Articles 6(1)(b) and 6(1)(f).
4. Data Sharing
We do not sell or share personal data with third parties, except:
- Service providers (e.g. web hosting) under GDPR-compliant contracts
- Legal disclosure if required by law
We do not profile or transfer data outside the EEA.
5. Data Retention
- Account & game data retained as long as your account is active or until deletion
- Log data anonymized or deleted after 12 months
Retention follows the principle of “storage limitation.”
6. Your Rights Under GDPR
You have the right to:
- Access, rectify, or erase your personal data
- Restrict or object to data processing
- Withdraw consent at any time
- Data portability (receive your data in machine-readable format)
- Lodge a complaint with a relevant Data Protection Authority
7. How to Exercise Your Rights
Contact us at:
We will respond within one month. No fees unless requests are manifestly unfounded or excessive.
8. Security Measures
We implement:
- Encrypted connections (HTTPS)
- Secure password storage (bcrypt hashing)
- Regular server updates and patches
- Limited staff access to personal data
These align with GDPR requirements for integrity and confidentiality.
9. Policy Updates
This policy is effective as of July 15, 2025. Updates will be posted with the date, and significant changes communicated via email or site notifications.
10. Consent to Processing
By using our site and registering, you consent to collecting and processing your personal data as described above. You may withdraw consent at any time via your account settings.