Privacy Policy
Last updated: 26 July 2026
1. Data controller
The data controller is Cyril Keime, individual entrepreneur (entrepreneur individuel — EI):
- Address: 15 avenue Victor Hugo, 78400 Chatou, France
- Privacy email: contact@magicbattlefield.com
- Telephone: line being assigned
2. Personal data processed
Depending on how the website is used, the following categories may be processed:
- identity and contact data: email address and, where necessary, billing address;
- order data: products ordered, the configuration chosen, price, date, order number and order status;
- customer-account data, where a visitor creates one: email address, an irreversible hash of the password and the creation date. The password itself is never stored;
- limited payment data: transaction identifier and information returned by the payment provider; full card details are never received by the website;
- download data: download link, expiry date, number of downloads and file preparation status;
- files produced for the Customer: the PDF or STL files generated from the configuration ordered, kept for as long as they are made available;
- messages sent through the contact form: subject, sender's email address and message content;
- withdrawal declarations: family name, given name, email address, order number and product concerned, together with the date and time of receipt;
- technical and security data: IP address, timestamp, browser, access logs and security events.
The website offers no newsletter and carries out no marketing prospection.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Process the order and supply the files | Performance of the contract |
| Send the order confirmation and download links | Performance of the contract |
| Operate a customer account and its order history | Performance of the contract |
| Handle support, defects and statutory guarantees | Performance of the contract and legal obligations |
| Answer messages sent through the contact form | Legitimate interests |
| Receive and handle a withdrawal declaration, and acknowledge it | Legal obligation |
| Maintain accounting and tax records | Legal obligation |
| Secure the website, prevent fraud and retain technical evidence | Legitimate interests |
| Establish or defend legal claims | Legitimate interests |
Data marked as required during checkout is necessary to enter into or perform the contract. Without it, an order cannot be processed.
4. Recipients and service providers
Data is accessible to the controller and, only as needed for their functions, to:
- website and data hosting: Contabo GmbH, Aschauer Strasse 32a, 81549 Munich, Germany;
- sending the website's emails: OVHcloud (SAS OVH, France);
- payment and merchant of record, from the opening of sales: Stripe Managed Payments / Sold through Link, LLC.
Data may also be disclosed to authorities, mediators, professional advisers or courts where required by law or necessary to establish or defend rights.
For a "Sold through Link" transaction, Stripe directly collects payment, Link-account and transaction data and shares with the controller the information needed to supply the product and manage the customer relationship.
Stripe and Link may act as separate controllers for processing connected with payment, security, indirect taxes, transaction support and the Link account. Their own policies are displayed in Stripe Checkout and on Link.
Personal data is never sold, rented or exchanged.
5. Transfers outside the European Economic Area
Website hosting and email sending take place in the European Union.
From the opening of sales, payment processing involves Stripe and Sold through Link, LLC, established in the United States. Such transfers rely on the safeguards recognised by the GDPR, in particular the European Commission's standard contractual clauses and, where applicable, an adequacy decision. Additional information can be requested from contact@magicbattlefield.com.
6. Retention periods
| Data | Indicative period |
|---|---|
| Orders and accounting documents | 10 years from the end of the relevant financial year |
| Customer account | Until the account holder asks for its deletion |
| Download links | 7 days from the order |
| Files generated for an order | For as long as they are made available, then deleted automatically |
| Contact-form messages | Up to 1 year after the request has been handled |
| Withdrawal declarations | 5 years from receipt (evidence that the request was handled) |
| Correspondence and complaints | Up to 5 years after closure, unless a longer dispute requires retention |
| Technical and security logs | Between 6 months and 1 year, unless an incident justifies longer |
At the end of the relevant period, data is erased, anonymised or placed in restricted archival storage where continued retention is legally required.
Database backups are kept on the server solely to restore the site after an incident; they follow a short rotation cycle and are overwritten. They are held under the same access protections as the database itself.
A periodic copy is also kept off the server, on media held by the publisher and located in France, for the same purpose of recovery after an incident. It is disclosed to no one.
7. Rights
Subject to the GDPR, a data subject may exercise:
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restriction;
- the right to object;
- the right to portability where applicable;
- the right to withdraw consent at any time, without affecting earlier processing;
- the right to give instructions concerning their data after their death.
Requests may be sent to contact@magicbattlefield.com. Proof of identity will be requested only where there is reasonable doubt about the requester's identity.
A response will normally be provided within one month, subject to extensions permitted by the GDPR.
Data processed by Stripe and Link for their own purposes falls under their policies; a request may be addressed to them directly.
8. Complaint to the CNIL
A person who considers that their rights have not been respected may lodge a complaint with the French data-protection authority, the Commission nationale de l'informatique et des libertés (CNIL): https://www.cnil.fr/
9. Cookies
Cookies and similar technologies are described in the Cookie Policy.
The website uses only technologies strictly necessary for its operation and security, which do not require prior consent.
10. Security
Reasonable technical and organisational measures are used, including access controls, encrypted communications (HTTPS), passwords stored as irreversible hashes, regular backups, software updates and security logging.
No information system is completely risk-free. Incidents are handled in accordance with applicable legal duties.
11. Automated decisions
The website does not make decisions producing legal or similarly significant effects based solely on automated processing.
Stripe/Link may apply automated fraud, authorisation, risk and compliance controls for Managed Payments under its own policies.
12. Changes
This Policy may be updated to reflect changes to the website, providers or applicable rules. The date at the top identifies the latest version.