1. Data controller
The data controller is Samy Bensalem, trading as Pronetics (Entreprise individuelle, SIREN 924 652 787), publisher of Project Nat20. For any request about your data: contact@project-nat20.com.
The controller's full details and those of the host are given in the legal notice. No data protection officer has been appointed.
Minors. The service is intended for people aged fifteen or over, the age from which a minor's consent is valid in France for an online service. Below that, registration requires the permission of a holder of parental authority, who may at any time ask for the account to be deleted at the address above. No date of birth is asked for: collecting one to check age would create one more piece of data to protect, without stopping anyone from lying.
2. What data is processed?
Account and profile
E-mail address, display name, @handle, password kept only as an Argon2id hash, language, time zone, avatar and biography that you add voluntarily.
Sign-in and security
Session identifier stored as a server-side hash, IP address, browser declared by the device, creation, use and expiry dates of sessions, and the technical and audit events needed to diagnose and protect the service.
Game and content
Adventures, members, scenes, maps, miniatures, portraits, folders, settings, positions, permissions, scene saves, dice rolls, table chat — including discreet conversations between a player and the game master — and imported files. Files may contain whatever information you put in them before importing.
Notebook
The titles and texts of the notes you write in an adventure, their dates and, for a note the game master shares, the list of players who read it.
Payment and billing
If you subscribe to a plan or buy a dice skin: the customer reference assigned by Stripe, the plan or skin concerned, the subscription's status and dates, invoices (number, amounts, status and links) and the evidence of your request for immediate access. Your card details are entered on a page hosted by Stripe: they never pass through Project Nat20 and are never stored here.
Relationships and communications
Invitations, friend list, presence, notifications, direct messages and read state. Project Nat20 does not read these messages for advertising or profiling; they must nonetheless be stored to be delivered to their recipients, and may be examined in the event of a report or a legal obligation.
For announcements sent by e-mail: your address, your display name, your plan when the announcement concerns it, and the date you opted out, if you did.
Discord community: optional linking
If you choose to link Discord from your profile, Project Nat20 stores the numeric Discord account ID, username, global name and avatar reference, together with the link and plan-role synchronisation dates. The OAuth token is used once to read this identity and then immediately revoked; it is never stored. Reports and moderation actions retain the relevant identifiers, reason, acting moderator and date, without copying conversation content.
3. Why, and on what basis?
| Purpose | Main data | Legal basis |
|---|---|---|
| Create and secure the account | E-mail, handle, hashed password, sessions | Performance of the terms of use |
| Provide the multiplayer table | Adventures, content, actions, messages and permissions | Performance of the terms of use |
| Link Discord and grant the requested plan role | Discord ID and public identity, Project Nat20 plan | Performance of the requested service; optional link |
| Protect and moderate the Discord community | Discord IDs, report, reason and action | Legitimate interest in maintaining a safe community |
| Prevent abuse and diagnose failures | IP, device, technical and audit events | Legitimate interest in securing and operating the service |
| Answer requests and obligations | Contact details and what the case requires | Legal obligation or legitimate interest, depending on the request |
| Perform and evidence subscription actions | Identity, e-mail, contract reference, cancellation or withdrawal, dates and processing status | Performance of the contract and legal obligation |
| Sell and invoice plans and dice skins | E-mail, display name, plan or skin, amounts, dates, Stripe references and invoices | Performance of the contract; legal obligation for accounting |
| Keep you informed of changes to the service | E-mail, display name, current plan | Legitimate interest; opt out at any time through the link in every announcement |
Project Nat20 makes no automated decision producing legal effects, and builds no commercial profile from your games.
4. What the other players see
Your display name and handle are needed to invite you and to recognise you. The members of an adventure see the table information their permissions allow: actions, rolls, messages, assets placed and presence. A detailed profile stays private until you make it public.
Direct messages are accessible to their two participants. The operational tools do not make them public; their content may however be processed for delivery, a support request, a report or a legal requirement.
A discreet conversation is read by the player concerned and by the adventure's game masters, and by no one else at the table. Your notebook is read by you alone; a note the game master shares is read, without being editable, by the players they chose, who cannot see who else reads it.
On the public Discord server, your Discord identity, messages and plan role are visible according to the server's settings and roles. A report sent through the bot command is visible only to the moderation team.
5. Recipients and hosting
Depending on need, the data is accessible:
- to you, and to the authorised members of the adventures concerned;
- to the publisher and expressly authorised administrators, solely for operation, security, moderation and support; the current panel shows account and adventure metadata, never the content of direct messages;
- to Infomaniak Network SA, host and technical processor, whose infrastructure used here is located in Switzerland. That company hosts the service and its backups, and delivers the transactional e-mails (address verification, forgotten password, security notices and contractual receipts) as well as announcements;
- to Stripe Payments Europe, Limited, established in Ireland, if you subscribe to a plan or buy a dice skin. Project Nat20 sends it your e-mail address, your display name and an internal account reference; Stripe collects your card and billing details itself, on its own page. It processes them to carry out the payment and, in part, on its own behalf (fraud prevention, financial obligations), under its privacy policy;
- to Discord Netherlands BV for users in the European Economic Area, when you join the server or voluntarily link your account. Discord operates its own service under its privacy policy; for the plan role, Project Nat20 only sends your Discord ID and the role matching your plan;
- to the competent authorities where the law requires it.
Transfer outside the European Union. Switzerland is covered by an adequacy decision of the European Commission: data hosted there benefits from a level of protection recognised as equivalent, so this transfer requires no additional safeguard.
Discord and Stripe also process data in the United States and other countries. Their policies state that, as applicable, they use the EU–U.S. Data Privacy Framework, European Commission standard contractual clauses and adequacy decisions.
No data is sold, rented to advertisers or passed to an advertising network. Project Nat20 uses no behavioural analytics or advertising tracker; Discord linking is optional and controlled from the profile.
6. For how long?
The retention criteria are as follows:
- account, profile and game content: for the life of the account or the adventure, then for as long as their deletion, anonymisation and the settlement of a request require;
- cookie and active session: thirty days at most from when it opened, expiring after seven days without activity, or sooner on sign-out, revocation, suspension or password change;
- address verification: the six-digit code lasts twenty minutes and five attempts, the link in the same message twenty-four hours; password reset link: one hour; address change link: twenty-four hours;
- contracts, cancellation and withdrawal requests and their evidence: during the contractual relationship and then for five years after it ends, as needed to establish, exercise or defend rights;
- invoices and accounting records: ten years from the close of the financial year, as the French Commercial Code requires (art. L. 123-22). Stripe keeps payment data on its side under its own policy and obligations;
- notebook: for as long as you keep the note. A deleted note disappears from everyone's screen at once, then is destroyed permanently thirty days later, along with its shares;
- opting out of announcements: the date of your choice is kept for as long as the account exists, so that it is respected;
- messages, table history and audit: with the space they belong to, for as long as they are useful to continuity, moderation or security;
- Discord link: until you remove it from the profile or delete the account; an unused OAuth state expires after ten minutes. Moderation cases are retained while needed for safety and the defence of rights; the account identifier is removed when the account is deleted;
- technical logs: thirty days, then deleted automatically by system rotation. They contain your IP address and your browser, which diagnosis and defence against abuse require; your session cookie is never written there;
- technical backups: until their normal rotation after the active data has been deleted.
Account deletion happens from your profile, without writing to us. Some rows are then anonymised rather than destroyed: the account row itself carries dice rolls, past memberships and an audit log that do not belong to you alone. Emptied of every identity, it no longer makes you recognisable.
8. Security measures
Project Nat20 uses, among other things, HTTPS, a cookie inaccessible to JavaScript, passwords hashed with Argon2id, sessions stored as hashes with both absolute and inactivity deadlines, rate limiting, server-side permission checks, and temporary links to serve private files.
No system is infallible. If you believe an account or a piece of data has been compromised, revoke the available sessions and use the private channel given on the Contact page.
9. Your rights
Depending on your situation, you may request access, rectification, erasure, restriction and portability of your data, and object to processing based on legitimate interest. You may also set directives about your data after your death.
Two of these rights are exercised without writing to us, from your profile:
- Take your data with you: a JSON file of what your account produced, notebook included. From a private conversation, only your own sentences appear: your correspondent's belong to them.
- Delete your account: immediate and final. Your address, name, handle, description, private conversations — direct messages and discreet conversations with the game master —, notebook and its shares, friendships and imported files are erased; the adventures you run are taken down, and the miniatures you had placed on other players' tables disappear along with their files. The messages you wrote in an adventure's chat stay, without your name: they are the memory of the session for those who played it. Your account row is kept, emptied of every identity, because it carries dice rolls and an audit log that do not belong to you alone.
Write to contact@project-nat20.com stating your @handle and the subject of the request. A reasonable identity check may be asked for, without collecting more than necessary. You may also refer the matter to the French data protection authority, the CNIL.
10. Changes to this policy
Any substantial change is dated on this page. A new purpose, an optional tracker, a payment provider or a significant extension of the administration tools would be the subject of appropriate information before going live. The version in force is the one shown at the top of the document.
