Account identity and sessions
Clerk user ID, email address, verification state, authentication methods, session and device-security information, MFA or reverification state, and legal-acceptance timestamp. OCG does not store your password.
Privacy notice · 13 July 2026
This notice explains how the administrators of Obsidian Capital Group handle personal information across recruitment, accounts, the member portal, official community spaces, and organised activity.
Effective and last updated 13 July 2026
This notice applies to the community services administered as Obsidian Capital Group.
The administrators of Obsidian Capital Group are the controller for the OCG processing described here. OCG is an unofficial, non-commercial UK player community and is not presented as an incorporated company.
We do not sell personal information, use it for behavioural advertising, or build commercial marketing profiles. Contact recruitment@obsidiancapitalgroup.cc for privacy questions, rights requests, or data-protection complaints.
Our Terms of Service govern participation. Accepting the Terms is contractual; reading or acknowledging this notice does not by itself give consent to all uses of personal information.
Information we handle
Public browsing requires little information. Accounts, membership, messaging, organised activity, and administration create the records described below.
Clerk user ID, email address, verification state, authentication methods, session and device-security information, MFA or reverification state, and legal-acceptance timestamp. OCG does not store your password.
Display name, RSI handle, optional Discord username, timezone or region, biography, headline, local profile imagery, links, experience, ships or skills, availability, divisions, roles, ranks, membership state, directory and activity privacy choices, and last-active marker.
Contact and account identifiers, 18+ confirmation, experience, division interests, availability, voice-comms confirmation, prior organisations, written answers, declarations, application reference, review status, private reviewer notes, assignment, timestamps, and recruitment-email delivery state.
Operation summaries, schedules, access restrictions, invitations, assignments, RSVP or participation state, contribution notes, and organisation-invitation recipient, intended role or division, issuer, acceptor, status, notes, and timestamps.
Conversation membership, recipients, message and reply bodies, drafts, read state, archive, mute and leave choices, blocks, timestamps, and prior and revised bodies when a message is edited. Deletion or moderation may remove the current body while retaining a message shell and necessary history.
Stored in-app notification category, title, body, related record, action link, read and expiry state, and category preferences. Member email preference fields do not currently activate member email delivery; Resend is used for recruitment messages only.
Reporter and subject identifiers, report category and details, relevant content or evidence, resolution, moderator, reasons, timestamps, and actions such as content removal or access restriction across the portal and official OCG spaces.
Operational activity, contribution records, commendations, badge and rank awards, citations, grant or revocation history, rule-review outcomes, visibility, issuer, and linked operation or service records.
Fictional contract assignments, progress, completion notes or evidence references, review decisions, reimbursement descriptions, amounts in fictional units, approval state, and links to completed fictional-ledger entries.
Internal account ownership and authority, fictional balances derived from entries, transfers, postings, approvals, schedules, execution history, escrow parties and decisions, reversals, adjustments, references, and governance metadata. No bank, card, wallet, or real-money data is collected by this system.
Actor and subject identifiers, role and permission snapshots, actions, targets, request or mutation IDs, reasons, bounded action details, timestamps, delivery logs, security events, and a short-lived anti-abuse fingerprint. Audit details can include operational context but are designed to avoid unnecessary dossier content.
Sources and visibility
We avoid importing information that the platform does not need.
The portal does not currently connect to a bank, payment processor, cryptocurrency wallet, or game client, and it does not automatically import game telemetry. Please do not submit special-category or other highly sensitive information unless we specifically and lawfully ask for it.
Public profile information is not exposed through the member directory. Directory access requires a verified member, and profile visibility settings can further limit relevant fields. Messages are shown to their participants and, when reported or lawfully reviewed, authorised moderators.
Recruitment records are limited to authorised recruitment and site administrators. Operational, personnel, recognition, contract, reimbursement, fictional-ledger, and audit records are limited by role, permission, and where applicable division scope. A role label in the browser is not treated as authority.
A one-time organisation invitation token is stored temporarily in your browser session while sign-in continues. The URL fragment is removed; Neon stores only a digest and short non-secret hint, plus invitation lifecycle history.
Purposes and lawful bases
The lawful basis depends on the purpose. A required privacy acknowledgement is not used as a substitute for that analysis.
Where necessary, we process identity, profile, session, message, and service records to create and secure your account, provide the community features you request under the Terms, and take requested steps on a recruitment application or invitation.
We use proportionate information to operate and improve a safe, accountable community; review recruitment and membership; coordinate activities; recognise contributions; maintain fictional governance; prevent abuse; moderate conduct; secure systems; investigate incidents; preserve audit integrity; and resolve disputes. We balance those interests against your rights and reasonable expectations.
We may process information to meet a legal obligation, respond to lawful authority, establish or defend legal claims, protect vital interests, or handle a data-protection complaint. If we introduce an optional use that genuinely relies on consent, we will ask separately and allow withdrawal. The recruitment field named privacyConsent is retained only for technical compatibility; its visible meaning is acknowledgement of this notice.
Cookies and service providers
We use service providers to run the platform; we do not currently use advertising or non-essential analytics cookies.
Clerk sets essential cookies and may use similar local browser storage to keep you signed in, maintain session continuity, prevent abuse, and protect authentication flows. Without them, account and protected member features cannot operate.
The invitation flow also uses browser session storage for the one-time claim token until it is accepted, rejected, or the browser session ends. We do not use that token for tracking or advertising.
Account registration, email verification, authentication, essential session cookies, MFA, security controls, account management, and the legal-acceptance timestamp.
Website hosting, content delivery, server-side application execution, and limited technical or security logs.
Managed Postgres storage for recruitment, profiles, member services, community operations, moderation, fictional-ledger records, and audit history.
Delivery of the full recruitment dossier to the monitored recruitment inbox and a minimal reference receipt to the applicant.
Sharing and international processing
Some providers and community platforms operate in multiple countries.
We disclose information to the providers above only as needed for their service; to authorised administrators and participants according to feature permissions; and to advisers, regulators, courts, emergency services, or law-enforcement bodies where reasonably necessary and lawful. We may share limited information to protect a person, investigate abuse, enforce the Terms, or establish and defend legal rights.
Discord and Cloud Imperium or Roberts Space Industries services are independent platforms, not OCG processors. Information you give them is governed by their own terms and privacy notices. We do not automatically send portal records to them.
Provider infrastructure or support may process personal information outside the UK. Where UK restricted-transfer rules apply to a transfer we initiate, we rely on an available lawful mechanism for that service and transfer, such as UK adequacy regulations or UK-approved contractual safeguards, and consider whether the protection remains appropriate.
Contact us for more information about the relevant provider and transfer mechanism. Provider retention and security practices also apply to the copies they process on our behalf.
Retention
Other records are kept against purpose, integrity, security, and legal criteria rather than an inaccurate blanket promise.
90
Days maximum for a dossier
A completed recruitment dossier, its private review notes, and full structured dossier copies under OCG control are permanently deleted no later than 90 days after submission, whether accepted, declined, withdrawn, or incomplete after submission. Applicant receipts contain a reference and follow-up expectations, not the full answers.
Rate-limit fingerprints are purged after 24 hours. Providers may keep limited delivery, security, backup, or billing metadata under their own schedules and legal duties.
For account, profile, messaging, personnel, invitations, operations, recognition, notifications, contracts, reimbursements, moderation, fictional-ledger, and audit records, we consider whether the record is still needed to provide the service, preserve accurate community or transaction history, manage permissions, investigate security or conduct, resolve a review or dispute, meet a legal duty, or establish and defend legal claims.
Messages use soft deletion and edits preserve previous bodies; a report, resolution, message shell, or edit history may remain when needed for participant context, moderation, security, or audit. Immutable operational, recognition, fictional-ledger, moderation, invitation, and administrative audit history may outlast account closure where deletion would undermine integrity or where continued retention is otherwise necessary and lawful.
Clerk controls closure of its identity account. The OCG profile and platform history are separate. On a valid request, we will delete, anonymise, or restrict optional profile and contact information where required and reasonably possible, but we will not falsify necessary shared or immutable history. We periodically review whether retained records still meet the criteria above.
Your UK privacy rights
Rights depend on the information, purpose, and lawful basis, and some have legal exceptions.
You may object to processing based on our legitimate interests. Tell us which processing concerns you and why. We will stop unless we can show compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed for legal claims.
Email the public contact with your account email, application reference, or another limited identifier that helps locate the record. We may ask for proportionate identity verification and clarification. Rights are normally free, subject to the limited exceptions allowed by law.
Security, complaints, and changes
Start with the public contact so the administrators can identify, investigate, and respond to the issue.
We use role-scoped access, server-side authorisation, MFA or reverification for high-risk actions, validation, rate limits, idempotent mutations, audit history, and provider security controls. Access is limited to people who need it for their community role. No internet transmission or storage system can be guaranteed completely secure.
State that you are making a data-protection complaint, explain the concern and desired outcome, and include only enough detail to locate the relevant information. We will acknowledge receipt within 30 days, make appropriate enquiries without undue delay, keep you informed, and explain the outcome.
You can also complain to the UK Information Commissioner's Office. The ICO generally recommends giving us an opportunity to resolve the issue first.
Make a complaint to the ICO (opens in a new tab)We may update this notice when the services, providers, community governance, or law changes. The latest version and date will remain on this page, and material changes will be highlighted through a reasonable community or website notice where appropriate.
Privacy and rights contact
Use an application reference or account email where possible. Do not send unrelated sensitive information unless requested.