Prophecy PROPHECY
  • Home
  • News ▾
    • News
    • Events
    • Live
    • Community Tournaments
  • Compete ▾
    • Teams
    • Tournaments
    • Leaderboards
    • Scrims
    • Scrim Finder
    • Rules
  • Forums
  • Store
  • Memberships
  • Servers
  • Organisation ▾
    • Roster
    • About
    • Discord
    • Tickets
    • Socials
    • Players
Login
CART
Loading cart…
Home
News
News Events Live Community Tournaments
Compete
Teams Tournaments Leaderboards Scrims Scrim Finder Rules
Community
Search Forums Store Memberships Servers
Organisation
Roster About Discord Bot Discord Players Tickets
Login / Register
Legal

Data Protection Policy

Last updated: 8 August 2026

This Data Protection Policy describes how Prophecy Esports (“Prophecy”, “we”, “us”) of New South Wales, Australia, protects the personal information we hold across prophecyesports.com and our related services (the “Services”). It complements our Privacy Policy — which explains what we collect and why — by setting out how that information is secured, stored, retained, and what happens if something goes wrong. We maintain this policy consistent with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and, where applicable to overseas users, the EU/UK GDPR.

Contents 1. Scope 2. Data Protection Principles 3. Security Measures 4. Where Data Is Stored 5. Access Controls 6. Third-Party Processors 7. Retention & Secure Destruction 8. Data Breach Response 9. Your Role in Protecting Your Data 10. Review of This Policy 11. Contact

1. Scope

This policy applies to all personal information collected, held, or processed by Prophecy in connection with the Services — including account and profile data, community content, order and membership records, support communications, and technical logs — regardless of where the individual it relates to is located.

2. Data Protection Principles

We handle personal information according to these principles:

  • Lawfulness & fairness — collected and processed lawfully, fairly, and transparently, as described in our Privacy Policy;
  • Purpose limitation — used only for the purposes it was collected for, or compatible purposes;
  • Data minimisation — we collect only what we need to run the Services;
  • Accuracy — kept accurate and up to date, with self-service tools for you to correct your own information;
  • Storage limitation — kept only as long as needed (see Retention below);
  • Integrity & confidentiality — protected by appropriate technical and organisational measures.

3. Security Measures

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:

  • Encryption of data in transit via HTTPS/TLS across the Services;
  • Passwords stored only as salted cryptographic hashes — we never store plain-text passwords;
  • Payment card processing handled by PCI-compliant payment providers — full card numbers are never stored on our servers;
  • Network-level protection, firewalling, and DDoS mitigation through our hosting and content-delivery providers;
  • Role-based permissions limiting what staff and moderators can access and do, with administrative actions logged in an audit trail;
  • Software kept updated and security patches applied on an ongoing basis;
  • Regular backups to support recovery from data loss or corruption.

4. Where Data Is Stored

Our Services are hosted with reputable third-party hosting and infrastructure providers whose servers may be located outside Australia, including in the United States and Europe. Backups are retained by our hosting providers as part of standard disaster-recovery practice. Wherever data is stored, we take reasonable steps to ensure it is protected consistently with this policy and applicable law, including using providers with recognised security practices and contractual safeguards.

5. Access Controls

Access to personal information within Prophecy is restricted to those who need it to perform their role — for example, administrators processing orders or moderators handling reports. Access is controlled through the Services’ permission system, individual staff accounts, and audit logging of administrative and moderation actions. Staff access is removed when no longer required.

6. Third-Party Processors

We use a small number of trusted third parties to operate the Services — hosting, content delivery and security, payment processing, and email delivery. These providers act on our instructions, may only use personal information to provide their services to us, and are chosen with regard to their security practices. A description of the categories of third parties we share information with is in our Privacy Policy.

7. Retention & Secure Destruction

We retain personal information only for as long as it is reasonably needed for the purposes for which it was collected, to comply with legal obligations (such as tax and transaction records), or to resolve disputes and enforce our agreements. When personal information is no longer required, we take reasonable steps to delete or de-identify it. Residual copies may persist in encrypted backups for a limited period before being cycled out. You may request deletion of your account and personal information at any time, as described in the Privacy Policy.

8. Data Breach Response

If we suspect or become aware of a data breach involving personal information, we will act promptly to:

  • Contain the breach and prevent further unauthorised access;
  • Assess the nature and scope of the information involved and the likely risk of serious harm to affected individuals;
  • Remediate the cause, including patching vulnerabilities and revoking compromised credentials;
  • Notify — where the breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under the Privacy Act, and any other regulators required by applicable law (including under the GDPR where relevant), as soon as practicable;
  • Record and learn — document the incident and improve our controls to reduce the risk of recurrence.

Notifications will describe, to the extent known, what happened, what information was involved, and what steps we and you can take in response.

9. Your Role in Protecting Your Data

Security is shared. We strongly encourage you to:

  • Use a strong, unique password for your Prophecy account and never share it;
  • Be cautious about what personal information you post in public areas such as profiles, forums, and walls;
  • Keep the email account linked to your Prophecy account secure;
  • Log out on shared devices, and tell us immediately via support if you suspect unauthorised access to your account.

10. Review of This Policy

We review this policy periodically and whenever our systems, providers, or legal obligations change materially. The current version will always be posted on this page with the date at the top.

11. Contact

Questions about this policy, or reports of suspected security issues or data breaches, can be sent to:

Prophecy Esports
Attn: Data Protection
New South Wales, Australia
Email: contact@prophecyesports.com
Or via our support tickets.

Prophecy PROPHECY

WE ARE THE FUTURE

Est. 2025

Organisation

About Roster Events Socials

Community

Forums Store Memberships Mobile App Discord Bot
© 2026 Prophecy Esports. All rights reserved.
Privacy Policy · Terms of Service · Data Protection
Prophecy