Privacy Policy

Last updated

This is the privacy policy of Aevonix B.V., trading as Frenzy ("Frenzy", "we", "us", or "our"), a sabotage leaderboard at frenzy.run. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Dutch implementing legislation.

1. Controller contact details

NameAevonix B.V., trading as Frenzy
Established inThe Netherlands
Business registrationKVK 42123774, VAT NL869834216B01
Registered addressHeresstraat 1, 9665 NV Oude Pekela, the Netherlands
Privacy emailhello@frenzy.run
Websitehttps://frenzy.run

We are not required to appoint a Data Protection Officer (DPO). For privacy questions or to exercise any of the rights below, email hello@frenzy.run.

2. What personal data we process

2.1 Account data

2.2 Entry data

Your account email is never shown publicly and is never attached to your entry on any public page — only the entry's own public fields above are.

Public listings. Rank, name, tagline, logo, and click count on the board are public — anyone can see them, including search engines. Do not submit a destination if you do not want that information shown. To show a logo, we fetch publicly available metadata (favicon, Open Graph image) from the URL you submit; that fetch may disclose to the destination that Frenzy requested the page. If your site's own metadata doesn't yield a usable icon, we also try two public favicon lookup services — DuckDuckGo's and Google's — sending them only the bare domain, nothing about you or any visitor; neither is contacted when anyone other than us looks at the board.

2.3 Attack, shield and payment data

2.4 Technical and security data

2.5 Email communications

Every email Frenzy can send you, in full: a login link when you sign in; a submission confirmation when you submit an entry while logged out, which is the link that actually creates it; a confirmation link when you set or change your notification address; a "you got frenzied" notice when one of your entries is attacked; a receipt when you pay for an attack or for shield charges; a moderation notice if we hide or remove one of your entries; and, only for an account that asked for a login link and never clicked it, up to three reminders before that unverified account is deleted (§6). That is the complete list. We do not send marketing email, and there is no newsletter to be added to.

The two receipts are the one kind you cannot turn off, and that is deliberate: they are the record of money you actually paid us, including the payment reference your bank will ask for. Opting out of notices never suppresses them, because charging someone and then withholding the receipt would be both wrong and the surest way to leave you unable to recognise a charge on your statement. They carry no unsubscribe header for the same reason. Everything else above is either something you asked for by clicking, or the frenzied notice, which you can opt out of at any time.

The "you got frenzied" email is capped to a few per hour so one attacker can't turn it into a mail bomb. The frenzied email carries a one-click unsubscribe: your mail client's own unsubscribe button acts on it directly (RFC 8058), and the link inside the email opens a page with a confirm button. Nothing is unsubscribed by a link merely being visited or previewed, so a mail scanner, prefetcher, or corporate link rewriter cannot silently opt you out of a notification you wanted.

3. Cookies

Frenzy sets exactly one cookie: __Host-frenzy_session, an HTTP-only, signed login-session cookie, kept for up to 30 days, or until you log out or delete your account. Logging out and deleting your account both invalidate the cookie on our side and not only in your browser, so an old copy of it stops working rather than quietly staying valid for the rest of the 30 days. It is strictly necessary — it's how we know you're logged in — so it needs no consent banner under the ePrivacy rules, and we don't use it for advertising or tracking. We run no analytics and set no advertising or third-party tracking cookies. If that ever changes, we'll update this section and add a consent banner before we do it.

3a. Sponsor slots

Some boards show a sponsor slot. Those are sold directly by us and the image is a file on our own server: there is no ad network, no third-party script, no third-party cookie, and no pixel. Nothing about you is sent anywhere when one is shown to you.

We do count sponsor slots, because a sponsor is entitled to know what they bought. When a page containing a slot is rendered we add one to a counter on the sponsor's own row, and when someone clicks a slot we add one to a click counter on that same row. That is the whole of it: two running totals attached to the advertisement, no cookie, no identifier, and nothing recorded about the visitor, the visit, or which visits belong together. We can tell a sponsor how many times their image was served; we cannot tell them — or ourselves — anything about who saw it. Counting how many times we displayed something is not tracking you, and keeping that distinction is exactly why these slots use no beacon and no browser storage.

4. Purposes and legal bases

PurposeLegal basis (GDPR art. 6)
Account creation and passwordless loginPerformance of contract (art. 6(1)(b))
Submitting and verifying an entryPerformance of contract (art. 6(1)(b))
Processing an attack purchasePerformance of contract (art. 6(1)(b))
Processing a shield purchase and crediting its chargesPerformance of contract (art. 6(1)(b))
Emailing you a receipt for a purchasePerformance of contract (art. 6(1)(b)) — transactional, and not subject to opt-out
Charging and accounting for VAT or local sales tax on a purchaseLegal obligation (art. 6(1)(c))
Keeping the public record of an attack after an entry or account is deletedLegitimate interests (art. 6(1)(f)) — the buyer's record of what they paid for, and a public board whose numbers are real
Rate limiting and abuse prevention (hashed IP)Legitimate interests (art. 6(1)(f))
Keeping web server access logs for security and abuse investigationLegitimate interests (art. 6(1)(f))
Reviewing abuse reportsLegitimate interests (art. 6(1)(f))
Sending the “you got frenzied” emailLegitimate interests (art. 6(1)(f)) — opt out any time
Verifying your identity through X, if you choose to sign in that wayPerformance of contract (art. 6(1)(b)) — only when you start it

We do not build profiles of you as a person and make no automated decisions with a legal or similarly significant effect on you.

5. Sub-processors and third parties

We never sell personal data. We share it only as follows:

RecipientRolePurposeData sharedTransfer outside EEA
MollieIndependent controllerAttack payment processingThe email you give Mollie at checkout, payment statusMollie B.V. is an EU (Dutch) company; any transfer by its own sub-processors outside the EU is governed by Mollie's own privacy notice
X (Twitter)Independent controllerOptional login and identity verification — only if you choose “Continue with X”That you signed in to Frenzy with X; in return we receive your X account id, handle and avatar URLYes — X Corp. is a US company, and what it does with the sign-in is governed by its own privacy notice, not ours
ContaboProcessorApplication/database hosting; self-hosted outbound email (DirectAdmin/Exim on the same infrastructure — there is no separate third-party transactional email vendor)All account, entry, and attack data; for email, the recipient address and message contentNo — Germany (EU)

The Role column distinguishes two relationships: a processor acts only on our instructions (GDPR art. 28); an independent controller decides its own purposes for the data it receives — Mollie processes your payment for its own regulatory and fraud-prevention obligations, governed by its own privacy notice, not just ours.

6. Retention periods

Data typeRetentionReason
Account data (email address, login timestamps)Until you delete your accountThere is a delete-account control on your account page: it deletes the account, its entries, and its login tokens straight away. You can also ask us by email instead.
An account that requested a login link but never clicked it (email address only — nothing was ever verified)Deleted automatically after 30 days, with reminder emails on day 7 and day 15 and a final notice on day 26An unclicked login link means nothing was ever proven about that email address, so we don't keep it indefinitely on the strength of a request alone. This never applies to an account that has actually logged in, by email or by X.
Entry dataUntil you delete the entry, we remove it, or you delete your accountProduct feature — your entry stays on the board while it is active. Deleting it does not delete the attack records it appears in; see the next row.
Attack records (positions, amounts, timestamps, and the entry name and domain as they were at the time)Kept indefinitely, as part of the public leaderboard's permanent history — including after either entry, or either account, is deletedSomeone paid for every one of these. Deleting your entry or your whole account takes you off the board, but the attacks you bought and the attacks bought against you stay public and stay attributed to the name and domain in use when they happened. This is the one thing account deletion does not reach — see §8. Your email address was never part of the record.
Shield purchase records (pack, charges, amount, payment reference, and the defended entry's name and domain as they were at the time)Kept indefinitely as a financial record — but the link to your account is removed when you delete itSomeone paid for every one of these, and tax law requires us to be able to account for the money. Unlike an attack record it is never published. Deleting your account severs the account link on these rows, so what remains says what was bought and for how much, not who bought it; deleting the entry likewise severs the entry link, leaving only the name-and-domain snapshot from the time.
Hashed IP addresses (rate limiting)Until the rate-limit window ends, then deleted by a sweep that runs at most once an hourKept only long enough to enforce a short, fixed window. The sweep is what makes that a real bound rather than an intention — without it the rows would sit there forever.
Login tokens (hashed, single-use)Deleted once used or expired, by that same hourly sweep — and immediately when you delete your accountA login link is single-use and short-lived, so the hashed row has no purpose afterwards. We never store the plaintext link that was emailed to you.
Web server access logs (plaintext IP, timestamp, request, user agent)Rotated and deleted by the host's log rotation, no longer than 30 daysSecurity and abuse investigation only. Not analytics, not joined to your account, and not used to build any profile of you.
Abuse reportsRetained for moderation historyNeeded to spot repeat abuse and to justify a removal decision if it is challenged.

7. Security

If a personal data breach poses a risk to your rights and freedoms, we report it to the Dutch data protection authority within 72 hours of becoming aware of it (GDPR art. 33), and notify affected users without undue delay if the risk is high (GDPR art. 34).

8. Your rights

RightDescription
Access (art. 15)Request what data we hold about you
Rectification (art. 16)Have inaccurate data corrected
Erasure (art. 17)Delete your account and its data yourself from your account page, or ask us to
Restriction (art. 18)Have processing temporarily restricted
Portability (art. 20)Receive your data in a machine-readable format
Objection (art. 21)Object to processing based on legitimate interests

We respond within one month.

You do not have to email us to exercise erasure. There is a delete account control on your account page that immediately deletes your account, its entries, and its login tokens, and invalidates any session cookie for it. What deletion cannot reach is the public record of attacks bought or received (§6). We keep those on overriding legitimate grounds — the record of what other people paid for, and the integrity of a board whose entire premise is that its numbers are real — which is a recognised limit on erasure where processing rests on legitimate interests (art. 17(1)(c), read with art. 21(1)). Those records never contained your email address, and after deletion they carry only the entry name and domain as they stood at the time of the attack. If you think that balance is wrong in your case, tell us at hello@frenzy.run and we will look at it individually.

9. Children

Frenzy is for adults (see Terms §2 Eligibility). We do not knowingly collect personal data from children. If you believe a child has used the Service, contact hello@frenzy.run and we will delete the data we can identify.

10. Complaints

If you are unhappy with how we handle your data, contact hello@frenzy.run first. You also have the right to lodge a complaint with your national data protection authority — for the Netherlands, that is the Autoriteit Persoonsgegevens.

11. Changes to this policy

We may update this policy when the service or applicable law requires it. For material changes we will notify active account holders by email at least 30 days before the change takes effect.