Privacy Policy


Privacy Policy

Last updated: July 19, 2026

This Privacy Policy explains which personal data is processed when you use la2base.com (the “Website”, the “Service”, “we”, “us” or “our”), why and on what legal grounds it is processed, to whom it may be disclosed, how long it is retained, and what rights are available to users.

Merely using the Website does not constitute consent to every type of processing. Where consent is required for a particular processing activity, it will be requested separately and may be withdrawn at any time.

1. Data Controller

The controller responsible for the processing of personal data is: Alexander Ott.

Address: comming.

Privacy contact email: [email protected].

You may also contact us using the contact form.

2. Personal Data We Process

2.1. Registration and account data

  • username;

  • email address and email verification status;

  • password hash — passwords are not stored in plain text;

  • user ID and technical account attributes;

  • registration date, last login time and account status;

  • two-factor authentication data and recovery codes, if the user enables 2FA;

  • notification, language and appearance preferences.

2.2. Profile data

Users may voluntarily provide additional information, including an avatar, display name, profile description, and links to websites or social media accounts. Some profile information may be publicly visible.

2.3. Content and activity

  • articles, forum topics, posts, comments and uploaded files;

  • ratings, reactions, poll responses and bookmarks;

  • private messages and notifications;

  • drafts, where the user uses an editor;

  • reports, support requests, appeals and records of moderation measures.

Users must not publish personal data relating to another person without an appropriate legal basis or permission.

2.4. Support enquiries

When the contact form is used, we may process the sender’s name, email address, subject and content of the enquiry, any attached file, the submission date, and other information required to review and respond to the request.

2.5. Technical data and security logs

When the Website is accessed, our servers and security infrastructure may automatically process:

  • IP address;

  • date and time of the request;

  • the requested page and referring URL;

  • browser type and version, operating system, language and device characteristics;

  • session identifiers, cookies and similar technical identifiers;

  • information about errors, suspicious requests, login attempts and security-related activity.

2.6. Analytics data

Where the user has consented to analytics, the Website uses Google Analytics 4 (G-ZKD9TD53T2) and Yandex Metrica (10081075).

These services may process information about the user’s device and browser, approximate location, referral source, pages visited, and interactions with the Website. Session Replay, click maps and link tracking are enabled in Yandex Metrica.

Further information about the cookies and similar technologies used by the Website is available in our Cookie Policy.

3. Sign-In Through Third-Party Services

3.1. Google

For registration and sign-in through Google, the Website requests the openid, email and profile permissions.

After the user approves the request, Google may provide the Website with the Google account identifier, email address and its verification status, name, display name, profile picture and other basic profile information covered by those permissions.

The Website does not receive the user’s Google password. For more information, see the Google Privacy Policy.

3.2. Telegram

Registration and sign-in through Telegram use the Telegram Login Widget and the @La2base_bot bot.

After the user approves authentication, Telegram may provide the Website with the Telegram account ID, first name, last name, username, profile photo URL, authentication date and a cryptographic signature used to verify the authenticity of the response.

The Website does not receive the user’s Telegram password, telephone number, contact list or private messages through the Telegram Login Widget. For more information, see the Telegram Privacy Policy.

3.3. Discord

The Website may offer registration and sign-in through Discord OAuth 2.0.

When the identify permission is used, Discord may provide the Website with the Discord account ID, username, display name, avatar and other basic profile information.

If the Website also requests the email permission and the user grants it, Discord may provide the email address associated with the account and its verification status.

The Website does not receive the user’s Discord password, private messages, server list, contacts or other information unless separate permission for that information has been requested and granted.

For more information, see the Discord Privacy Policy.

Users may decline third-party authentication and, where available, register using the standard registration method. Access previously granted to a third-party application may be revoked through the relevant provider’s account settings.

4. Sources of Personal Data

We receive personal data:

  • directly from the user when they register, complete their profile, publish content, send messages or contact us;

  • automatically when the Website is used, through server logs, cookies and similar technologies;

  • from the authentication provider selected by the user — Google, Telegram or Discord;

  • from other users, for example where the user is mentioned or another user reports content published by them.

5. Purposes and Legal Bases

Purpose

Categories of data

Legal basis

Registration, sign-in, account management and provision of Website functions

Registration data, profile, preferences, content and activity

Performance of our agreement with the user and steps taken at the user’s request before entering into that agreement

Sign-in through Google, Telegram or Discord

Provider account ID and profile information authorised by the user

Steps taken at the user’s request to provide the selected sign-in method and, where required, consent

Security, abuse prevention and protection of legal rights

IP address, login and activity logs, device information, reports and moderation records

Our legitimate interests in securing the Website and its users, preventing fraud and establishing, exercising or defending legal claims

Support and handling enquiries

Contact details, enquiry content and attachments

Performance of our agreement, steps taken at the user’s request and our legitimate interest in supporting the Service

Sending essential service communications

Email address, account ID and notification preferences

Performance of our agreement and protection of account security

Analytics and improvement of the Website

Usage data, cookies and technical identifiers

The user’s prior consent

Compliance with legal obligations and binding requests from authorised bodies

Data required in the particular circumstances

Compliance with a legal obligation

Where processing is based on legitimate interests, we consider the nature of the data, the user’s reasonable expectations, the necessity of the processing and its potential effect on the user’s rights.

The user may object to such processing where provided by applicable law.

6. Recipients of Personal Data

We do not sell personal data. Personal data may be disclosed or made accessible, only to the extent necessary, to the following categories of recipients:

  • providers of hosting, databases, file storage, backups and technical support;

  • Cloudflare and other providers of content delivery, network infrastructure and protection against attacks;

  • email service providers used to deliver service communications;

  • Google and Yandex, where the user has consented to analytics;

  • Google, Telegram or Discord where the user selects the corresponding registration or sign-in method;

  • contractors and professional advisers who are subject to confidentiality obligations;

  • courts, law-enforcement agencies and other competent authorities where disclosure is required by law or necessary to protect legal rights;

  • a successor in connection with a restructuring, sale or transfer of the Service, subject to applicable legal requirements.

Public profile information and content published by users are accessible to other visitors and may be indexed by search engines. Users should take this into account before publishing information.

7. International Data Transfers

Some service providers may process personal data in countries other than the user’s country.

Where required, appropriate safeguards are used, such as an adequacy decision, standard contractual clauses or another legally permitted transfer mechanism.

Users may request additional information about the safeguards used by contacting us through the details provided in this Policy.

8. Data Retention

We retain personal data only for as long as necessary for the relevant purpose, taking into account the duration of the account, legal requirements, security needs, backup cycles and the establishment, exercise or defence of legal claims.

  • Account data are retained while the account is active and, following deletion, for a limited period required to complete deletion, restore backups, prevent abuse and comply with legal obligations.

  • Security logs and information about login attempts are retained for a period justified by security and incident-investigation requirements.

  • Support enquiries are retained until they have been resolved and for an additional period required to document the response and protect legal rights.

  • Public content may be deleted, anonymised or retained as part of a discussion where necessary to preserve the integrity of the conversation, protect the rights of other users or comply with the law.

  • Backup copies are deleted or overwritten in accordance with the applicable backup cycle.

  • Cookie and analytics identifier retention periods are described in the Cookie Policy and the relevant provider documentation.

9. Security

We use proportionate technical and organisational safeguards, including encryption in transit, access restrictions, cryptographic password hashing, secure cookie attributes, security event logging and backups.

No method of transmission or storage is completely secure. Users are responsible for protecting their passwords, 2FA codes and devices through which their accounts are accessed.

10. User Rights

Depending on applicable law, users may have the right to:

  • obtain information about the processing and a copy of their personal data;

  • correct inaccurate or complete incomplete data;

  • request deletion of personal data;

  • restrict processing;

  • object to processing based on legitimate interests;

  • receive data they provided in a structured, commonly used and machine-readable format and transmit those data to another controller where the right to data portability applies;

  • withdraw consent at any time without affecting the lawfulness of processing carried out before its withdrawal;

  • lodge a complaint with a competent data protection authority.

To exercise these rights, submit a request using the contact details in Section 1. To protect the account, we may request reasonable proof of identity.

These rights may be restricted where permitted by law, including where necessary to protect the rights of others, security or legal claims.

11. Account Deletion

Users may request deletion of their account using the available account function or the contact form.

Account deletion does not always result in the immediate deletion of every record. Certain data may temporarily remain in backups or security logs, or where retention is required by law or necessary to protect legal rights.

Public posts and comments may be deleted or anonymised, taking into account the structure of discussions and the rights of other users. Before deleting an account, users may separately delete content available to them or request that it be reviewed.

12. Children

The Service is not intended for children below the age at which they may independently use the relevant online service and provide consent under the law of their country.

Where permission from a parent or legal guardian is required, an account may be created and used only with that permission.

If you believe that a child has provided personal data without the required permission, please contact us so that we can review the matter and take appropriate action.

13. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal effects concerning a user or similarly significantly affect them, unless the user is specifically informed and such processing is permitted by applicable law.

14. Third-Party Links

The Website may contain links to third-party resources. We do not control their content or data-processing practices.

Users should review the relevant privacy information before providing personal data to a third-party service.

15. Changes to This Policy

We may update this Policy where the Website, our service providers or legal requirements change. The current version will be published on this page together with its effective date.

We will provide notice of material changes through the Website or another appropriate method. If a new processing activity requires consent, consent will be requested separately before that processing begins.

16. Contact and Complaints

For questions about personal data or to exercise your rights, contact:

[name of the controller]
[postal address]
[privacy contact email]

Contact form: la2base.com/en/contact.

If the user is located in the European Economic Area, they may also lodge a complaint with the data protection authority in the country of their habitual residence, place of work or the alleged infringement.