Legal
Privacy policy
This page says what we know about you, why we need it and what you can do about it. It is written to be read, not to be survived: if something here is unclear, mail us and we will explain it in plain words.
1. Who is responsible for your data
Zentrax Milsim organises milsim airsoft events and runs this platform: your account, the ticket shop, your operator profile, the waivers you sign, your team and your chip. For everything we do with your data here, Zentrax Milsim is the controller in the sense of the GDPR.
We have not appointed a data protection officer, because we are not required to. Requests and questions go to one mailbox, info@zentrax.eu, and a person of the organisation answers them. If you want to use one of the rights in section 10, see section 13. We answer within one month.
2. What we collect
- Account. Your name, email address, password (stored hashed, never readable), and the language you use the site in.
- Operator profile. Callsign, date of birth, your classes and roles, your optics and night-vision declarations, your team, and whether you intend to bring a vehicle.
- Safety data. Emergency contact, and the medical information you choose to give us (allergies, medication, conditions a marshal should know about in an incident). You decide whether to fill this in; see section 5.
- Orders. What you bought, for which event, and the order reference. Payment itself happens at Sweettickets: card details never reach us and we never store them.
- Signed documents. Your event rules acknowledgement, the player waiver and, if it applies, the vehicle waiver: a fingerprint of the exact text you agreed to, your typed signature, the moment you signed and the IP address you signed from.
- Chip and check-in. Your chip number, when it was issued and until when it is valid, your check-in at the gate, your chrono result, and what your chip did on the field (see section 6).
- Discord. Your Discord user ID and username, if you link your account so we can put you in the right faction channels.
- Photos and video. Images and footage made at the event by us or by a photographer working for us. See section 8.
- Technical data. Server logs of your visits (IP address, browser, pages, timestamps) and the strictly necessary cookies that keep you logged in. See section 12.
We only ask for what an event actually needs. In practice that is:
3. Why we use it, and on what legal basis
- To run the event you bought a ticket for. Registration, faction assignment, check-in, chrono, your chip, your passport and the emails around it. Legal basis: the contract between you and us.
- Safety on the field. Age check, emergency contact, medical notes, and the evidence that you read the event rules and signed the waiver. Legal basis: our legal obligation to run a safe event and our legitimate interest in being able to prove that we did, plus your consent for medical data.
- Reminders and service messages. Mail and Discord messages about your incomplete profile, your unsigned waiver, and the week before the event. Legal basis: the contract. You can switch off everything that is not strictly necessary in your account settings.
- Bookkeeping and tax. Order and invoice data. Legal basis: our legal obligation.
- Keeping the platform working and secure. Logs, abuse and fraud prevention, backups. Legal basis: our legitimate interest.
- Photos and video for our own communication. Legal basis: our legitimate interest in reporting on the event, balanced against your interests, and your consent for anything where you are clearly the subject. See section 8.
4. What we never do
We do not sell your data. We do not rent it out, we do not trade it with other organisers, and we do not hand your player list to advertisers. We do not profile you for advertising, and nothing on this platform decides anything about you automatically without a human being able to look at it.
5. Medical and emergency information
Medical information is a special category of personal data under the GDPR, so we treat it separately. You are never obliged to fill it in. If you do, you give explicit consent for us to use it for one purpose only: helping you, or letting emergency services help you, during the event.
It is visible to the organisation and to the medical team, not to your team mates and not to other players. You can change or remove it in your profile at any time, and we delete it after the event unless an incident report requires us to keep it.
6. The chip, the tracker and ATAK
The chip and tracker are used exclusively to operate in-game props. They do not transmit GPS data and are not used for safety monitoring or any other purpose. The chip holds an operator identity and a faction, not your name and not your personal details.
What they produce is game data: which faction held an objective, and who armed or defused a prop. We use it to run the game, to settle the score, to build your event history in your passport and, afterwards and in anonymous form, to see how an event went and design the next one.
ATAK (technically CIVTAK) does share your location. For that reason, its use is mandatory for all players.
If you report your chip lost, we deactivate it immediately, so nobody can play under your identity. The game data behind your event history is anonymised after twelve months (see section 9).
8. Photos and video at the event
Milsim is photographed. We and the photographers working with us make images of the event and use them on our site, in our mails and on our social channels, because a report of the weekend is part of what we do.
If you are recognisable and clearly the subject of an image, you can ask us to take it down and we will, without asking why. Write to the address in section 13 and describe the image. We cannot control what other participants publish; that is between you and them.
9. How long we keep it
- Account and operator profile. As long as you have an account, and one year after your last event.
- Signed waivers and event rules acknowledgements. Five years after the event. These are evidence: they are never edited. A signed waiver stays valid; a later update of its text does not ask you to sign again.
- Order and invoice data. Seven years, because the law says so.
- Medical and emergency data. Deleted after the event, unless an incident report needs it.
- Chip and game data. Your event history stays in your passport; the detail behind it is anonymised after twelve months.
- Server logs. Twelve months.
When you delete your account we remove your profile and your contact details. The rows we are legally required to keep, waivers and invoices, stay for the periods above and nothing more.
10. Your rights
You can see your data, correct it, export it, and have it deleted. You can object to processing we base on a legitimate interest, ask us to restrict it, and withdraw a consent you gave us, including for medical data and for images.
Most of it you can do yourself in your account settings: your profile, your notification preferences, an export of your data and deleting your account. For anything else, write to us. We answer within one month and we never charge you for a first request.
Withdrawing a consent does not undo what we did while it was valid, and it does not remove evidence we are obliged to keep.
11. Players under 18
Our events are for players of 18 and over: the account, the waiver and the event rules acknowledgement all check your date of birth, and a younger player cannot buy a ticket here. The minimum age of each event is stated with the event, so a stricter age is possible, never a lower one.
If we ever admit a younger player at a specific event, a parent or legal guardian signs the waiver and the event rules acknowledgement, and their contact details become the emergency contact. We do not create accounts for children under 16.
12. Security and cookies
Access to the platform runs over HTTPS, passwords are stored hashed, and access to player data inside the organisation is limited by role: a team leader sees their team, an admin sees what an admin needs. Backups are encrypted. If a data breach puts you at risk, we tell you and the supervisory authority.
We use two kinds of cookie, both strictly necessary: the session cookie that keeps you logged in, and the token that protects forms against abuse from another site. They are set by this domain, they hold no profile of you, and they disappear when you log out or when they expire. The language you read the site in is part of your account, not a cookie.
On the public pages Microsoft Clarity sets analytics cookies to measure how the site is used (see section 7). There are no advertising cookies. You can block or delete cookies in your browser settings at any time.
13. Contact and complaints
Questions, requests and takedown notices go to info@zentrax.eu. Put "privacy" in the subject so it reaches the right person.
If you would rather write on paper, ask by mail and we send you the postal address the same day.
If you are not happy with how we handled it, you can complain to the Belgian Data Protection Authority, Gegevensbeschermingsautoriteit, Drukpersstraat 35, 1000 Brussels, or to the supervisory authority of the country you live in.
Mail: info@zentrax.eu
14. Changes to this policy
When we change this text we publish a new version with a new date, and we keep the old versions. If a change matters to you, for example a new purpose or a new recipient, we mail you before it takes effect.