Personal data

Privacy notice

This notice explains what data is used for Grimoire’s private beta, why it is used, how long it is kept and how to exercise your rights.

Last updated: 27 August 2026.
01

Controller and contact

Lionel RAGGINI controls the processing of data for the Grimoire portal and beta programme.

  • Data questions and requests: contact@distantsignal.fr.
  • This notice covers the web portal, access to test releases, updates and feedback you voluntarily submit.
Contact the controller
02

Data processed

Only information needed to run and improve the beta is processed.

  • Identity and account: name, email address, cohort, status, hashed password and any password-change requirement.
  • Beta journey: a technical invitation-open signal, invitation-link visits, sign-ins and download requests, with derived OS, browser and device type but no stored IP address or raw user agent.
  • Voluntary feedback: reports, feature requests, app version, operating system, architecture and a PNG or JPEG screenshot only when you choose one.
  • Updates: only the SHA-256 hash of the update token is retained.
  • No local chess database, game, log or application file is uploaded automatically.
03

Purposes and legal basis

Processing relies on the legitimate interest in operating a secure private beta and improving Grimoire, provided this does not override your rights and freedoms.

  • Create and administer individual access, authenticate testers and distribute authorised releases.
  • Secure the portal, prevent abuse and investigate incidents.
  • Answer testers, fix defects and prioritise improvements.
  • Feedback and screenshots are optional; a screenshot is processed only when you deliberately select it. No direct marketing is performed.
04

Required and optional information

Your name, email address and password are required for an individual beta account.

  • Without them, private access cannot be opened or maintained.
  • Reports, ideas and screenshots are optional; withholding them does not affect beta access.
  • Never submit passwords, tokens or unnecessary personal data in feedback.
05

Recipients and providers

Data is available only to Lionel RAGGINI, authorised beta operators and necessary technical providers.

  • Distant Signal infrastructure hosts and runs the web portal and its PostgreSQL database.
  • GitHub hosts private artefacts used to distribute some test releases.
  • These providers act under their terms and data protection agreements; data is not sold to advertisers.
06

Transfers outside the EEA

GitHub may process some data in the United States or other countries where it or its subprocessors operate.

  • Where no adequacy decision applies, its terms provide for the European Commission’s Standard Contractual Clauses or another recognised transfer mechanism.
  • You may request more information about these safeguards using the contact above.
07

Retention

Beta data is kept for the duration of the programme and for no more than one year after it ends.

  • It is then deleted or anonymised unless a legal obligation requires longer retention.
  • Sessions and rate-limit data expire earlier according to their technical lifetime.
  • You may request earlier deletion, subject to data strictly needed for security or a legal obligation.
08

Your rights

Depending on your circumstances, you may request access, rectification, erasure, restriction, objection and portability.

  • Email contact@distantsignal.fr and identify the account email concerned.
  • Reasonable identity verification may be requested before answering.
  • You may also lodge a complaint with the French data protection authority, the CNIL.
Lodge a complaint with the CNIL
09

Cookies, security and automated decisions

The portal uses only cookies that are essential for authentication and security.

  • No analytics, advertising network or third-party tracking script is loaded; Grimoire records the limited beta journey directly.
  • An email-open signal may come from a mail proxy and therefore does not prove that the message was read.
  • Passwords are hashed, access is individual and private pages are checked server-side.
  • No decision with legal or similarly significant effects is made solely by automated processing.