Skip to content

Privacy

What we hold, and what is public

Short version: we store the minimum needed to run a personnel system, an events calendar and a game server. Your service record is public because that is what a roster is. Your Discord ID and anything real-world are not, and never appear on a public page.

This notice is written to meet the UK GDPR and the Data Protection Act 2018. It tells you what we collect, why we are allowed to, how long we keep it, and what you can make us do about it.

Controller
16X command
Last reviewed
September 2026
Regulator
ICO (UK)

To confirm before publishing: the legal identity of the controller (an individual, or the group by name), a written contact address for data protection requests, and whether the brigade is registered with the ICO. An unincorporated gaming community is usually exempt from the data protection fee, but the controller must still be identifiable.

Why we are allowed to

Our lawful bases

Nearly everything here runs on legitimate interests: you joined a unit that keeps a roster, and a roster that cannot record who holds what rank, who turned out, and who earned which qualification is not a roster. We have weighed that against your privacy and concluded it is what a member reasonably expects on joining. You can object at any time, and the practical answer to a sustained objection is that we close the account.

Purpose Basis
Running the roster and ORBAT Legitimate interests — operating the unit you asked to join, and keeping a verifiable service history.
Signing you in Legitimate interests — there is no account without an identity to attach it to. You choose to sign in with Discord; nothing else is offered.
Matching you in-game Consent. Your Steam ID is only on your record because you or a staff member put it there, and it exists solely to credit your attendance and show your loadout during an operation. Clear it from your service record page and the matching stops; nothing else about your membership changes.
Discipline and audit Legitimate interests — being able to show who changed what, and to deal fairly with a complaint.
Keeping the server secure Legitimate interests — logs that let us find an outage or a misuse of an admin account.

We do not process any special category data — nothing about health, beliefs, ethnicity, politics or sexuality is asked for, and none should be written into a form. We do not make automated decisions about you: a promotion, an award and a discharge are each a decision a person makes and signs.

What we hold

Every category, and who can see it

Data What it is Visible to
Your account Your Discord account id — nothing else. We do not store an email address at all: sign-in asks Discord only for your identity, never your address, and the app sends no email of any kind. There is no password either — Discord is the only way to sign in. Private
Your Discord identity Your Discord user ID, so we can match you to event RSVPs and keep your server roles in step with your rank. We do not store a Discord access or refresh token — sign-in is brokered through Keycloak, which reads your profile once during login and discards the token. Never shown publicly. Private
Your Steam ID A SteamID64, held only if you provided a Steam profile link or a staff member added one for you. It is the only thing connecting a player on the game server to a person on this site. Not shown on any public page. Remove it yourself from your service record page at any time. Staff
Your service record Display name, callsign, rank, unit, billet, qualifications, awards with their citations, operations attended, and every dated record behind those. This is the point of the site. Public
Game session data While you are on our Arma server: the times you connected and disconnected, the in-game name you were using, and — during a logistics-enabled operation — a periodic snapshot of your loadout and remaining ammunition and medical supplies. Recorded for attendance credit and for resupply during the mission. This comes from the game server, not from you. Staff
Mission recordings Where OCAP is running, an after-action recording of an operation — positions, movement and events for every player in the mission, played back on a map. Tied to the in-game name you used. Members
What you write Form submissions — applications, LOA requests, award recommendations, after-action and intelligence reports — and any comments staff leave on them. Internal comments on a submission are visible to staff only. We do not ask for your date of birth. The application asks only that you confirm you are 16 or over, and we take you at your word. Members / staff
Disciplinary records Where a matter has been formally recorded: what happened, who dealt with it and when. Held so that a decision can be explained and reviewed rather than re-argued from memory. Staff
Images you upload Screenshots and unit photographs uploaded to galleries and articles, stored on our own server rather than a third-party host. Please do not upload a picture of a real person who has not agreed to it. Public
Administrative audit trail Every record write and role change is logged with who did it, when, and the before and after state. Where an acting IP address is recorded at all it is stored as a one-way hash, never as an address. Staff
Server logs Ordinary web and game server logs, which include IP addresses, kept for troubleshooting and security. Sysadmin

To confirm before publishing: how long raw web and game server logs are retained before rotation, and whether the host keeps its own copies.

How long

Retention

Data Kept for
Service record For as long as the unit exists. That is the premise of a record-driven system: a discharged member who returns two years later still has their qualifications. Anonymised on request — see your rights, below.
Account and Discord link Until you ask for the account to be removed. There are no stored credentials or Discord tokens to delete, because none are ever kept.
Loadout snapshots Operational data with no value after the mission it was taken during. One snapshot per player per campaign is held and overwritten as the mission runs.
Attendance capture Kept as part of the attendance history it feeds, for as long as the service record it belongs to.
Disciplinary records To confirm — a fixed period after the matter closes is the defensible answer, rather than indefinitely.
Audit log Kept for as long as the records it explains. An audit trail with holes in it does not do its job.
Mission recordings To confirm — how long OCAP recordings are retained.

Who else sees it

Third parties and transfers

We do not sell anything, and we do not share your data for anyone else's marketing. The only organisations involved at all are the ones that make the site work:

  • Discord — sign-in, role sync and event notices. Discord is US-based, so this is a transfer outside the UK, made under the UK extension to the EU standard contractual clauses that Discord's own terms provide.
  • Steam (Valve) — when a custom Steam profile link is pasted, we ask Steam to turn it into a numeric ID. Nothing about you is sent beyond the link itself. Also US-based.
  • YouTube — embedded videos load behind a click-to-play facade, so nothing reaches Google until you press play.
  • Our host — to confirm: who hosts the server and where it physically sits. If it is a UK or EU machine, say so here; if not, the transfer needs naming.

Sign-in is brokered by Keycloak, which we run ourselves on the same infrastructure — it is not a third party.

Your rights

What you can make us do

Under the UK GDPR you have the following rights. Ask any member of command; there is no form and no ticket queue. We will respond within one month, which is the statutory deadline.

  • Access — a copy of everything we hold about you.
  • Rectification — anything wrong corrected. Most of it you can already edit yourself.
  • Erasure — see the question below; it is a real right but not an unlimited one.
  • Restriction — processing paused while a dispute about accuracy is sorted out.
  • Portability — the data you gave us, in a machine-readable file.
  • Objection — to any processing we base on legitimate interests, on grounds relating to your situation.
  • Withdrawing consent — for your Steam ID, which is the one thing we rely on consent for. Clear it from your service record page yourself, or ask staff to.

Exercising any of these is free, and we will not treat you differently for it. If you are not satisfied with how we handle a request, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113. We would rather you came to us first, but you do not have to.

The detail

Questions people actually have

Why is my service record public?

Because a roster that only members can see is not a roster. Rank, unit, billet, qualifications, awards and operations attended are published on your profile so the ORBAT means something to a visitor and so your history is verifiable. It is also the thing members are proudest of — the medal rack exists to be shared.

What is never published: your Discord ID, your Steam ID, your IP address, your real name unless you chose it as your display name, or anything you wrote in a form. Your email address cannot be published, because we never have it.

What do you record while I am playing?

When you connect to our Arma server it records your Steam ID, the name you are playing under, and the times you joined and left. That is how attendance is credited without anyone taking a register. During an operation with logistics enabled it also takes a periodic snapshot of your loadout and what ammunition and medical supplies you have left, so command can arrange resupply.

None of it is published, none of it is linked to you on the site unless your Steam ID is on your record, and none of it leaves our own servers. If your Steam ID is not on your record, the data is recorded against a number that means nothing to us.

Do you use cookies or analytics?

One cookie, for your sign-in session. It is strictly necessary to keep you logged in, which is why there is no consent banner — the Privacy and Electronic Communications Regulations exempt exactly this kind of cookie. No analytics, no advertising, no third-party tracking scripts. YouTube embeds are loaded behind a click-to-play facade, so no player script — and therefore no YouTube cookie — loads until you press play.

What do you share with Discord?

If you link your Discord account, we send role changes to the server when your rank or unit changes, and we post event notices and RSVP buttons to a channel. That is the extent of it. We do not read your messages, and we cannot see servers you are in beyond our own.

Can I have my data deleted?

Yes. Ask any member of command. Your account and Discord link are deleted outright, and your Steam ID with them. Your service record is anonymised rather than destroyed: the records stay, because they are also part of other people's operational history, but they stop being attached to an identifiable person and your profile comes down.

If you would rather everything went, say so — we will do it, but it also removes you from the attendance and award history of operations you were part of.

The right to erasure is not absolute: where we have a legitimate interest in keeping a disciplinary record or an audit entry that explains a decision about someone else, we may keep that and will tell you we have, and why.

Records cannot be deleted. Is that a problem?

Staff can void a record with a stated reason, which strikes it through and shows who voided it and why. Nobody, including a sysadmin, can quietly erase one through the interface. That is deliberate: it is what makes the promotion history and the audit log trustworthy. Removing a person is handled separately, above, and a sysadmin acting on a deletion request can do at the database what the interface will not.

Who has access to the private fields?

Staff roles are scoped to their own part of the order of battle, enforced on the server for every mutation rather than by hiding buttons. Sysadmins have database access, as anyone running a server does. Every administrative action is written to an audit log in the same transaction as the change itself.

How is it kept safe?

The site is served over HTTPS, there are no passwords to steal because sign-in is delegated, permissions are checked on the server for every write, and administrative access is limited to the people who need it. If we ever had a breach likely to put you at risk, we would tell the ICO within 72 hours and tell you without undue delay.

I am under 16.

Then you cannot hold an account here. UK law would allow a 13-year-old to consent to a service like this; our own rule is stricter because of the nature of the community. If an account is found to belong to someone under 16 it is closed and the data removed.

Does this notice change?

When the site starts doing something new with your data, yes. The review date at the top of this page is the honest indicator; a change that materially affects you will be announced in Discord rather than quietly edited in.

Asking about your data

Message any member of the command team on Discord. There is no form and no ticket queue for this — it is a small community and a request goes straight to a person. We will tell you what we hold and act on a request within one month, and usually inside a fortnight.

Open the Discord →