Privacy notice · 13 July 2026

A defined purpose. A defined lifetime.

This notice explains how the administrators of Obsidian Capital Group handle personal information across recruitment, accounts, the member portal, official community spaces, and organised activity.

Effective and last updated 13 July 2026

Who controls your information.

This notice applies to the community services administered as Obsidian Capital Group.

The administrators of Obsidian Capital Group are the controller for the OCG processing described here. OCG is an unofficial, non-commercial UK player community and is not presented as an incorporated company.

We do not sell personal information, use it for behavioural advertising, or build commercial marketing profiles. Contact recruitment@obsidiancapitalgroup.cc for privacy questions, rights requests, or data-protection complaints.

Our Terms of Service govern participation. Accepting the Terms is contractual; reading or acknowledging this notice does not by itself give consent to all uses of personal information.

Information we handle

Records follow the service you use.

Public browsing requires little information. Accounts, membership, messaging, organised activity, and administration create the records described below.

Account identity and sessions

Clerk user ID, email address, verification state, authentication methods, session and device-security information, MFA or reverification state, and legal-acceptance timestamp. OCG does not store your password.

Profile and personnel

Display name, RSI handle, optional Discord username, timezone or region, biography, headline, local profile imagery, links, experience, ships or skills, availability, divisions, roles, ranks, membership state, directory and activity privacy choices, and last-active marker.

Recruitment dossiers

Contact and account identifiers, 18+ confirmation, experience, division interests, availability, voice-comms confirmation, prior organisations, written answers, declarations, application reference, review status, private reviewer notes, assignment, timestamps, and recruitment-email delivery state.

Operations and invitations

Operation summaries, schedules, access restrictions, invitations, assignments, RSVP or participation state, contribution notes, and organisation-invitation recipient, intended role or division, issuer, acceptor, status, notes, and timestamps.

Messages and edit history

Conversation membership, recipients, message and reply bodies, drafts, read state, archive, mute and leave choices, blocks, timestamps, and prior and revised bodies when a message is edited. Deletion or moderation may remove the current body while retaining a message shell and necessary history.

Notifications and preferences

Stored in-app notification category, title, body, related record, action link, read and expiry state, and category preferences. Member email preference fields do not currently activate member email delivery; Resend is used for recruitment messages only.

Reports and moderation

Reporter and subject identifiers, report category and details, relevant content or evidence, resolution, moderator, reasons, timestamps, and actions such as content removal or access restriction across the portal and official OCG spaces.

Activity and recognition

Operational activity, contribution records, commendations, badge and rank awards, citations, grant or revocation history, rule-review outcomes, visibility, issuer, and linked operation or service records.

Contracts and reimbursements

Fictional contract assignments, progress, completion notes or evidence references, review decisions, reimbursement descriptions, amounts in fictional units, approval state, and links to completed fictional-ledger entries.

Fictional-ledger history

Internal account ownership and authority, fictional balances derived from entries, transfers, postings, approvals, schedules, execution history, escrow parties and decisions, reversals, adjustments, references, and governance metadata. No bank, card, wallet, or real-money data is collected by this system.

Administration and security

Actor and subject identifiers, role and permission snapshots, actions, targets, request or mutation IDs, reasons, bounded action details, timestamps, delivery logs, security events, and a short-lived anti-abuse fingerprint. Audit details can include operational context but are designed to avoid unnecessary dossier content.

Sources and visibility

You, community activity, and essential services.

We avoid importing information that the platform does not need.

Where information comes from

  • Information you submit in recruitment, profile, message, report, operation, contract, reimbursement, and other portal forms.
  • Actions and decisions recorded by other participants or authorised administrators, such as invitations, RSVP state, awards, reviews, moderation, and fictional-ledger approvals.
  • Clerk identity and session state, plus limited hosting, delivery, and anti-abuse information from our service providers.

The portal does not currently connect to a bank, payment processor, cryptocurrency wallet, or game client, and it does not automatically import game telemetry. Please do not submit special-category or other highly sensitive information unless we specifically and lawfully ask for it.

Who can see what

Public profile information is not exposed through the member directory. Directory access requires a verified member, and profile visibility settings can further limit relevant fields. Messages are shown to their participants and, when reported or lawfully reviewed, authorised moderators.

Recruitment records are limited to authorised recruitment and site administrators. Operational, personnel, recognition, contract, reimbursement, fictional-ledger, and audit records are limited by role, permission, and where applicable division scope. A role label in the browser is not treated as authority.

A one-time organisation invitation token is stored temporarily in your browser session while sign-in continues. The URL fragment is removed; Neon stores only a digest and short non-secret hint, plus invitation lifecycle history.

Purposes and lawful bases

Why we use personal information.

The lawful basis depends on the purpose. A required privacy acknowledgement is not used as a substitute for that analysis.

Contract and requested steps

Where necessary, we process identity, profile, session, message, and service records to create and secure your account, provide the community features you request under the Terms, and take requested steps on a recruitment application or invitation.

Legitimate interests

We use proportionate information to operate and improve a safe, accountable community; review recruitment and membership; coordinate activities; recognise contributions; maintain fictional governance; prevent abuse; moderate conduct; secure systems; investigate incidents; preserve audit integrity; and resolve disputes. We balance those interests against your rights and reasonable expectations.

Legal duties and consent

We may process information to meet a legal obligation, respond to lawful authority, establish or defend legal claims, protect vital interests, or handle a data-protection complaint. If we introduce an optional use that genuinely relies on consent, we will ask separately and allow withdrawal. The recruitment field named privacyConsent is retained only for technical compatibility; its visible meaning is acknowledgement of this notice.

Cookies and service providers

Essential identity, hosting, storage, and mail.

We use service providers to run the platform; we do not currently use advertising or non-essential analytics cookies.

Essential storage

Clerk sets essential cookies and may use similar local browser storage to keep you signed in, maintain session continuity, prevent abuse, and protect authentication flows. Without them, account and protected member features cannot operate.

The invitation flow also uses browser session storage for the one-time claim token until it is accepted, rejected, or the browser session ends. We do not use that token for tracking or advertising.

Clerk

Account registration, email verification, authentication, essential session cookies, MFA, security controls, account management, and the legal-acceptance timestamp.

Vercel

Website hosting, content delivery, server-side application execution, and limited technical or security logs.

Neon

Managed Postgres storage for recruitment, profiles, member services, community operations, moderation, fictional-ledger records, and audit history.

Resend

Delivery of the full recruitment dossier to the monitored recruitment inbox and a minimal reference receipt to the applicant.

Sharing and international processing

Limited recipients, potentially global infrastructure.

Some providers and community platforms operate in multiple countries.

When information is shared

We disclose information to the providers above only as needed for their service; to authorised administrators and participants according to feature permissions; and to advisers, regulators, courts, emergency services, or law-enforcement bodies where reasonably necessary and lawful. We may share limited information to protect a person, investigate abuse, enforce the Terms, or establish and defend legal rights.

Discord and Cloud Imperium or Roberts Space Industries services are independent platforms, not OCG processors. Information you give them is governed by their own terms and privacy notices. We do not automatically send portal records to them.

Processing outside the UK

Provider infrastructure or support may process personal information outside the UK. Where UK restricted-transfer rules apply to a transfer we initiate, we rely on an available lawful mechanism for that service and transfer, such as UK adequacy regulations or UK-approved contractual safeguards, and consider whether the protection remains appropriate.

Contact us for more information about the relevant provider and transfer mechanism. Provider retention and security practices also apply to the copies they process on our behalf.

Retention

Fixed limits where the system has them.

Other records are kept against purpose, integrity, security, and legal criteria rather than an inaccurate blanket promise.

90

Days maximum for a dossier

Recruitment and anti-abuse limits

A completed recruitment dossier, its private review notes, and full structured dossier copies under OCG control are permanently deleted no later than 90 days after submission, whether accepted, declined, withdrawn, or incomplete after submission. Applicant receipts contain a reference and follow-up expectations, not the full answers.

Rate-limit fingerprints are purged after 24 hours. Providers may keep limited delivery, security, backup, or billing metadata under their own schedules and legal duties.

Member and operational records

For account, profile, messaging, personnel, invitations, operations, recognition, notifications, contracts, reimbursements, moderation, fictional-ledger, and audit records, we consider whether the record is still needed to provide the service, preserve accurate community or transaction history, manage permissions, investigate security or conduct, resolve a review or dispute, meet a legal duty, or establish and defend legal claims.

Messages use soft deletion and edits preserve previous bodies; a report, resolution, message shell, or edit history may remain when needed for participant context, moderation, security, or audit. Immutable operational, recognition, fictional-ledger, moderation, invitation, and administrative audit history may outlast account closure where deletion would undermine integrity or where continued retention is otherwise necessary and lawful.

Account closure is not blanket erasure

Clerk controls closure of its identity account. The OCG profile and platform history are separate. On a valid request, we will delete, anonymise, or restrict optional profile and contact information where required and reasonably possible, but we will not falsify necessary shared or immutable history. We periodically review whether retained records still meet the criteria above.

Your UK privacy rights

Ask, correct, restrict, or object.

Rights depend on the information, purpose, and lawful basis, and some have legal exceptions.

Rights that may apply

  • Access personal information and receive supporting information about its use.
  • Correct inaccurate information or complete information that is incomplete.
  • Request erasure or restriction where the legal conditions apply.
  • Receive portable information you supplied where processing is automated and based on consent or contract.
  • Withdraw consent at any time for an optional use that actually relies on consent, without affecting earlier lawful processing.
  • Complain about how personal information or a rights request has been handled.

Your right to object

You may object to processing based on our legitimate interests. Tell us which processing concerns you and why. We will stop unless we can show compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.

Email the public contact with your account email, application reference, or another limited identifier that helps locate the record. We may ask for proportionate identity verification and clarification. Rights are normally free, subject to the limited exceptions allowed by law.

Security, complaints, and changes

A monitored route for privacy concerns.

Start with the public contact so the administrators can identify, investigate, and respond to the issue.

Security and access

We use role-scoped access, server-side authorisation, MFA or reverification for high-risk actions, validation, rate limits, idempotent mutations, audit history, and provider security controls. Access is limited to people who need it for their community role. No internet transmission or storage system can be guaranteed completely secure.

Data-protection complaints

State that you are making a data-protection complaint, explain the concern and desired outcome, and include only enough detail to locate the relevant information. We will acknowledge receipt within 30 days, make appropriate enquiries without undue delay, keep you informed, and explain the outcome.

You can also complain to the UK Information Commissioner's Office. The ICO generally recommends giving us an opportunity to resolve the issue first.

Make a complaint to the ICO (opens in a new tab)

Notice changes

We may update this notice when the services, providers, community governance, or law changes. The latest version and date will remain on this page, and material changes will be highlighted through a reasonable community or website notice where appropriate.

Privacy and rights contact

Use an application reference or account email where possible. Do not send unrelated sensitive information unless requested.

recruitment@obsidiancapitalgroup.cc