Privacy Policy

Last updated: 20 February 2026

1. Who We Are

This Service (including tournanaut.com and app.tournanaut.com) is operated by:

MLSoftware OÜ
Registry code: 16089373
Ristiku tn 53-7, 10320 Tallinn, Estonia
Email: [email protected]

We act as a data controller for account and platform data described below.


2. Personal Data We Collect

2.1 Account and Authentication Data

When you create an account or sign in, we collect:

  • Email address
  • Encrypted password hash (if using email login)
  • Auth0 user ID
  • Google account ID (if using Google login)
  • Display name or profile name (if provided)
  • Login timestamps
  • IP address and security logs

Authentication services are provided through Auth0. When you use Google login, we receive limited profile data (email, name, Google ID). We do not access your Google Drive, contacts, or other Google data.


2.2 Tournament Data

We process:

  • Participant names or nicknames
  • Teams
  • Match results
  • Tournament structures and related information

Tournament organisers determine what data is entered into the system.


2.3 Technical Data

We collect:

  • IP address
  • Browser type and device information
  • Security and access logs

2.4 Support Communications

If you contact us, we process the personal data you include in your message.


2.5 Data We Do Not Intentionally Collect

We do not intentionally collect:

  • Dates of birth
  • Special category (sensitive) data
  • Unnecessary personal information

Users must not upload sensitive personal data.


3. How We Use Personal Data

We use personal data to:

  • Provide and maintain user accounts
  • Operate tournament management features
  • Authenticate users
  • Maintain platform security
  • Provide support
  • Comply with legal obligations

Legal bases under GDPR:

  • Performance of contract
  • Legitimate interests (security, service improvement)
  • Consent (for optional cookies)

4. Cookies and Tracking

We use:

Essential Cookies

Required for:

  • Login sessions
  • Security
  • Core functionality

These do not require consent.

Non-Essential Cookies

Used for:

  • Analytics
  • Performance monitoring
  • Other optional tracking

These are only activated after you provide consent via our cookie banner.

You may:

  • Accept all
  • Reject non-essential cookies
  • Modify preferences at any time via “Cookie Settings”

We store consent logs including timestamp, consent status, and version of the banner shown.


5. Third-Party Processors

We use contracted service providers including:

  • Auth0 (authentication services)
  • Google (if Google login is used)
  • Hosting providers
  • Email service providers
  • Analytics providers (if enabled)

These providers act as data processors under contractual agreements.


6. International Transfers

Some providers may process data outside the European Union.

Where transfers occur, we rely on:

  • EU Standard Contractual Clauses (SCCs)
  • UK Transfer Addendum (if applicable)
  • EU-US Data Privacy Framework (if applicable)

7. Data Controller and Processor Roles

7.1 Account Data

MLSoftware OÜ acts as data controller.

7.2 Tournament Participant Data

If you create or manage a tournament and upload participant data:

  • You are the data controller
  • We act as a data processor

We process organiser-submitted data solely under your instructions for operating the Service.


8. Data Retention

  • Account data: retained until account deletion
  • Tournament data: retained while active and for a limited period after
  • Security logs: retained for approximately 90 days
  • Consent logs: retained for audit and compliance purposes

Data may be retained longer if required by law.


9. Security

We implement appropriate technical and organisational measures, including:

  • TLS encryption
  • Secure password storage
  • Access controls
  • Firewall protection

However, no system is completely secure. Use of the internet carries inherent risks.


10. Your Rights

Under GDPR, you may:

  • Access your data
  • Correct inaccurate data
  • Request deletion
  • Restrict processing
  • Object to processing
  • Withdraw cookie consent

Contact: [email protected]

We respond within one month (extendable where legally permitted).


11. Children’s Privacy

The Service is not intended for children under 13.
We do not knowingly collect personal data from children under 13.


12. Changes to This Policy

We may update this Privacy Policy. The updated version will be posted on this page with a new revision date.

Scroll to Top
Cookie Consent