1. Data controller#
Association FreshPerf, with registered office at 398 Avenue Lucien Cohen, 13430 Eyguières, France, is the controller for the processing described in this policy.
- Data protection contact: [email protected]
This policy covers freshperf.fr, the client area and the related hosting services. It does not cover the data you choose to process on your own servers: there, you are the controller and we act as a processor (see section 9).
2. Data we process#
Account and identification data
Email address, first and last name, phone number, postal address, and for a business customer the company name and EU VAT number. Passwords are never stored in clear text: only a cryptographic hash is kept. If you enable two-factor authentication, the corresponding secret is stored encrypted.
If you sign in with GitHub, Google or Discord, we receive your technical identifier and email address from that service, solely to create or link your account. We receive neither your password nor your contacts.
Order and billing data
Orders, subscribed services, invoices, credit notes, payments, account balance movements and promotional code usage. When you save a payment method, we keep only a token reference provided by our payment provider, the brand, the last four digits and the expiry date. Your full card number never transits through, and is never stored on, our servers.
Service-related technical data
Instance identifiers, assigned IP addresses, hostnames, subdomains, the public SSH keys you upload, console sessions and administration operation logs (start, stop, backup, reinstall).
Support data
Ticket content, the attachments you send and the history of your exchanges with our teams.
Security and connection data
Connection IP addresses, user agent, dates and outcomes of authentication attempts, active sessions, audit logs of sensitive actions, and infrastructure technical logs.
Communication data
A log of transactional emails sent and their delivery status, client-area notifications, and your communication preferences.
Referral programme data
Referral code, the link between referrer and referee, commissions and, when you request a cash withdrawal, the payout details you provide (IBAN or PayPal email address). These details are used to execute the transfer and retained under accounting obligations.
3. Purposes and legal bases#
| Purpose | Legal basis |
|---|---|
| Account creation and management, delivery and administration of services | Performance of the contract |
| Orders, payments, invoicing, debt recovery | Performance of the contract and legal obligation |
| Technical support and handling of complaints | Performance of the contract |
| Retention of invoices and accounting records, tax obligations, retention of identification data required by French law | Legal obligation |
| Systems security, prevention and detection of fraud and abuse, network integrity | Legitimate interest |
| Service improvement and aggregated usage statistics | Legitimate interest |
| Referral programme management | Performance of the contract |
| Marketing communications and audience measurement | Consent |
| Establishment, exercise or defence of legal claims | Legitimate interest |
4. What we do not do#
We do not sell or rent your personal data. We do not share it with data brokers or advertising networks, and we carry out no solely automated decision-making producing legal effects concerning you.
We do not inspect the content of your servers or of your databases. Technical access only occurs in the limited cases described in section 5 of the Terms of Service: necessity for delivering the service, your own request as part of support, a request from an authority, or a security incident.
Our administrative teams may temporarily access your client area for support purposes, in a traceable way. Every such access is logged.
5. Recipients and processors#
Your data is accessible to authorised members of our teams, within the limits of their duties. It may be disclosed to the following categories of recipients:
| Recipient | Role |
|---|---|
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payment and refund processing, fraud prevention |
| Our email delivery provider | Sending transactional emails |
| GitHub, Google, Discord | Authentication, only if you choose that sign-in method |
| Cloudflare | Bot protection on the account and contact forms and on the recommendation assistant (Turnstile) |
| Komoot (Photon service) | Address suggestions while filling in the billing form |
| PostHog (PostHog Cloud EU, Frankfurt — Germany) | Site audience measurement, only if you consented to it, and under a pseudonymous identifier |
| Accountant, legal counsel, debt collection agencies | Accounting obligations and defence of our rights |
| Administrative and judicial authorities | Upon a lawfully grounded request or order |
The sign-up, sign-in, password reset and contact forms, as well as the offer recommendation assistant, are protected by Cloudflare Turnstile. The check runs in invisible mode: no checkbox and no image puzzle is shown to you, and the verification happens in the background as you use the form. On that occasion Cloudflare processes technical signals (IP address, TLS fingerprint, User-Agent header, site key and originating domain) for the sole purpose of telling a visitor apart from a bot, with no profiling and no advertising targeting. That processing is described in Cloudflare's Turnstile Privacy Addendum, which supplements Cloudflare's privacy policy.
Data hosting, document storage (invoices, attachments) and technical monitoring are carried out on our own infrastructure, without relying on a third-party cloud provider.
6. Transfers outside the European Union#
Your data is hosted and processed within the European Union. Some of our processors - in particular the payment provider, Cloudflare and, if you use it, the third-party authentication provider - belong to international groups that may carry out processing outside the European Union. Such transfers are framed by the European Commission's standard contractual clauses or by an adequacy decision, with supplementary measures where necessary. A copy of the applicable safeguards can be obtained at [email protected].
7. Retention periods#
| Data | Retention |
|---|---|
| Customer account and identification data | Until the account is deleted, which you can request at any time (see "Your rights"). We do not delete inactive accounts on our own initiative: your client area, past orders and history stay available until you ask for them to be erased. |
| Content of your servers and backups | 30 days after the service ends |
| Invoices, credit notes and accounting records | 10 years (article L.123-22 of the French Commercial Code) |
| Saved payment methods | Until you delete them or they expire |
| Closed payment intents | 90 days |
| Expired sessions | 30 days |
| Connection and audit logs, and identification data retained under French law | 12 months |
| Administrator access logs to a customer account | 90 days |
| Support tickets | Lifetime of the customer account they belong to, then erased along with it |
| Transactional email log | 12 months |
| Referral programme data | Duration of participation, then the accounting retention period for payouts |
Once these periods expire, data is deleted or anonymised. Some data may be kept longer, with restricted access, where necessary for the establishment, exercise or defence of legal claims, or to comply with a legal obligation.
8. Security#
We implement appropriate technical and organisational measures: encryption of data in transit, encryption of sensitive secrets at rest, cryptographic hashes for passwords, two-factor authentication available on every account, environment segregation, access control and logging of administration actions.
As no system is infallible, it is also up to you to protect your credentials, enable two-factor authentication and secure the systems you deploy. In the event of a data breach likely to result in a high risk to your rights and freedoms, we will inform you as provided for by the GDPR.
9. Data of your own users#
When you run a server - a game server in particular - and process data about your players or users on it (nicknames, IP addresses, connection logs, messages), you are the controller for that processing. We then act only as a processor within the meaning of Article 28 GDPR, for the sole provision of the infrastructure.
It is your responsibility, in particular:
- to have a legal basis for that processing;
- to inform your users and answer their requests to exercise rights;
- to define your own retention periods and your own application-level security measures;
- to obtain, where relevant, the consent of minors on the terms provided by applicable law.
A data processing agreement compliant with Article 28 GDPR is available on request at [email protected].
10. Your rights#
Under the General Data Protection Regulation and the French Data Protection Act, you have the following rights:
- Access: obtain confirmation that your data is processed and receive a copy of it.
- Rectification: correct inaccurate or incomplete data - most of it can be edited directly from your client area.
- Erasure: request deletion of your data, subject to our legal retention obligations.
- Restriction: request the temporary freezing of a contested processing operation.
- Objection: object to processing based on our legitimate interest, on grounds relating to your particular situation.
- Portability: receive, in a structured format, the data you provided to us.
- Withdrawal of consent: at any time, for processing that depends on it, without affecting the lawfulness of prior processing.
- Post-mortem directives: define directives on what happens to your data after your death.
These rights can be exercised at [email protected]. We may ask for proof of identity in case of reasonable doubt. We respond within one month, extendable by two months for complex requests.
If you consider that your rights are not respected, you may lodge a complaint with the French data protection authority, cnil.fr.
12. Minors#
Our services are not intended for people under 15 and subscribing requires legal capacity. If you become aware that a minor has provided us with data without the authorisation of the holder of parental responsibility, report it to [email protected]: we will delete the account and the associated data.
13. Changes to this policy#
We may update this policy to reflect legal or technical developments or changes in our processing. Any material change is notified to you by email or in your client area before it takes effect. The date of the last update is shown at the top of this page.