Trust · Policies
DOC-22
Legal, regulatory and contractual register
The obligations that apply to this service, where each comes from, how it is met, and the privacy notice the data protection obligations require.
How these were identified
Four sources were worked through: what the service does with personal data, the terms of the one supplier it depends on, the licences of the software it ships, and any contract or regulatory relationship it has entered. The last of those is empty, and its emptiness is itself a finding worth recording rather than a blank to be skipped.
This is a determination made by the operator, not legal advice and not a lawyer's opinion. Where a determination is uncertain it is marked as uncertain below rather than resolved in the direction that makes the register look better.
Data protection
The service is offered to the public over the internet with no geographic restriction, so data protection regimes attach on their own terms rather than by anyone's choice. The United Kingdom and European Union general data protection regimes both extend to offering a service to people in those territories, and this service does so by being reachable there.
The one determination not made here: which supervisory authority is the lead one depends on where the operator is established, and that is not recorded on this register. It is the single item in this document that the Owner has to state rather than the service demonstrate, and it is flagged rather than guessed.
What is processed, exhaustively. A display name the player types. A skin identifier they choose. A best score. A timestamp of when the profile was last seen. A random identifier minted by the server and stored in a cookie, which is the key the other four hang from. Server-side, the connecting network address is used as a rate-limit key and is not stored in any record. Nothing else: no email address, no password, no payment detail, no account, no tracking across sites, no advertising identifier, and no profile built from behaviour.
Whether that set is personal data is a real question rather than a rhetorical one. A random pseudonym plus a self-chosen display name is personal data where the display name identifies a person, which it may well, and the honest position is to treat all of it as personal data rather than to argue it away.
Purpose and basis. The purpose is to let a returning player keep their name, their skin and their best score without an account, and to keep a leaderboard that means something. The basis relied on is the legitimate interest in operating the game the player asked to play; there is no consent mechanism because there is nothing collected that the player did not type in order to play.
Retention, stated accurately including the part that is not a clean ninety days. A profile that has never scored is deleted after ninety days without being seen. A profile that holds a best score is kept indefinitely, because deleting it would silently remove entries from a leaderboard the service publishes as a record. The service action log is retained ninety days; per-tank capture logs twenty-four hours; control receipts have no expiry by design, since a receipt that expired would defeat the chain it belongs to.
Rights, and the gap. What is honoured today: nothing about a player is published with an identifier attached, the display name is the only field a player can see about themselves and they can change it at any time, and clearing the cookie ends the association between the person and the profile. What is not honoured today: there is no route by which a player can ask for their profile to be erased, and clearing the cookie orphans a profile rather than deleting it. That is a real shortfall against an erasure right, it is recorded as an assessed risk with treatment outstanding, and it is stated here rather than left for someone to discover.
Disclosure and transfer. Nothing is sold, shared or transferred to any third party. The data sits in the infrastructure provider's storage, which is a processor relationship in substance under the provider's standard terms, and the choice of storage region is not currently constrained by this service.
Supplier terms
The infrastructure provider's terms of service and acceptable use policy apply to everything this service runs. The obligations that actually bite are: staying inside the paid limits, which is enforced by the spend ceiling closing the game rather than billing; not using the platform to serve prohibited content, which a shark game does not; and accepting that the provider may change the platform, which is why the runtime compatibility date is pinned in version-controlled configuration.
These terms are accepted as offered. There is no negotiated agreement and no contract in the commercial sense, because there is no commercial relationship: the service is free, has no revenue, and has no customer.
Intellectual property
This service is published under the MIT licence, and the game engine submodule under the same. The licence is declared in the change record data and in the repository.
Third-party obligations, inventoried rather than assumed. Everything shipped to a browser or into the Worker bundle is MIT-licensed: the rendering library, its React renderer, React and its DOM package. The build-time tooling adds an Apache 2.0 licence and a dual MIT or Apache 2.0 licence, neither of which ships in the artefact. No copyleft licence is present anywhere in the dependency set, so there is no source-disclosure obligation beyond the one this project has already taken on voluntarily by being MIT itself.
The obligation each of these carries is attribution: the licence text and copyright notice must travel with the software. That obligation is met by the licence files present in the distributed source, and it is recorded here so that adding a dependency under a different licence is recognised as a change to this register rather than as an ordinary dependency bump.
Nothing in this service uses third-party assets — no purchased model, texture, font or sound — and no content is reproduced from another work.
Standards, and what they oblige
ISO/IEC 27001:2022 and ISO/IEC 42001:2023 are the criteria this register is written against. They are voluntary: no obligation to conform to either has been imposed on this service by anyone, and no certification body has assessed it.
That is worth stating in a legal register precisely because the rest of this site could be misread as a claim of certification. The register describes itself as a readiness statement rather than a certificate, and this entry is the same statement made where an assessor would look for it.
What does not apply
No contract with a customer, because there is no customer. No service level agreement, because none has been offered. No sector regulation: the service is not financial, not medical, not a marketplace and not a communications provider. No payment card obligations, because no payment is taken and no card data touches the service at any point. No employment obligations, because there are no employees.
No age gate is operated, and this is the second entry in this document where the honest answer is uncomfortable. The service is a free browser game with no account and no data collection beyond a typed name, which is the profile that attracts the lightest treatment under children's privacy regimes, but it makes no attempt to establish whether a player is a child. It is recorded as identified and unresolved rather than omitted.
Keeping this current
Reviewed at each ninety-day cycle, and immediately on any of four triggers: a new field of personal data is collected, a dependency is added under a licence not listed above, a second supplier is introduced, or any contractual or regulatory relationship comes into existence for the first time.
Two items in this document are open rather than met and are carried on the risk treatment plan rather than being quietly resolved here: the absence of an erasure route, and the absence of an established authority contact.