Privacy Policy
This document explains what data we process, why, for how long, and what you can require from us.
Last updated: 5 October 2026
Two distinct roles
For your customer account data — your e-mail, your organisation, your billing — S&E Studio is the data controller.
For the data of your server’s players, you are the controller: you decide what is collected and why. We then act as a processor, on your instructions. It is up to you to inform your players and to have a legal basis.
Account data
We process: e-mail address, display name, password hash, sessions and sign-in IP addresses, organisation and role, language and theme preferences.
Legal basis: performance of the contract. Retention: for the life of the account, then three years for evidence and accounting purposes.
Billing data
We keep the Stripe customer identifier, the subscription and invoice history, and any tax information you provide for the affiliate programme.
No card data is stored or even received by our servers: it is entered directly with Stripe. Retention: ten years for accounting records, as required by law.
Data about your server’s players
Depending on what you enable, the resource may send us:
- the player’s account identifiers (license, Steam, Discord, FiveM);
- their nickname, playtime, sessions and disconnections;
- their sanctions, staff notes and the action log;
- their inventory and money, if you enable that module;
- their position on the map, and the screenshots or recordings your staff requests.
Player IP addresses are encrypted at rest. Hardware identifiers are not collected.
Retention: you control it. Logs and snapshots follow your plan’s retention, Cloud files expire per their setting, and the “Reset” and “Purge” tools in your area let you erase on demand.
Processors
We rely on the following providers:
- Stripe Payments Europe, Ltd. (Ireland) — payments and invoicing. No card data ever reaches our servers.
- OVH SAS (France) — server and database hosting.
- Resend, Inc. (United States) — transactional e-mail (confirmation, password reset, invitations).
- Cloudflare, Inc. (United States) — attack protection and site delivery.
- Discord, Inc. (United States) — only if you link your Discord server or use Discord sign-in.
Transfers outside the European Union
Servers and the database are located in France. Some providers are established in the United States; those transfers rely on the European Commission’s standard contractual clauses or on the EU–US Data Privacy Framework.
Cookies
The site uses no advertising cookies and no third-party analytics trackers.
The only cookies set are strictly necessary: the authentication session, the language, the theme, and the affiliate identifier when you arrive through a referral link. They do not require prior consent.
Your rights
You have the right to access, rectify, erase, restrict, object and port your data. You can exercise them at the address below, and we answer within one month.
A player who wishes to exercise their rights should contact the operator of the server concerned, who is the controller. We assist them on request.
You may also lodge a complaint with the CNIL if you believe your rights are not respected.
Security
Passwords are stored as hashes, sensitive identifiers and IP addresses are encrypted, traffic is served over HTTPS, and backoffice access is governed by roles and permissions with an append-only audit log.
Contact
For any question about your data: [email protected].