Data protection
Privacy Policy
This policy describes the processing implemented in the current website and the protected purchase-access architecture. Sales and payment processing remain inactive, so provider-specific commercial processing will be added only after the relevant services are finalized.
Pre-launch 1.0 · Last updated 16 September 2026
Controller
The operator’s legal identity has not yet been configured for publication. It will be published before sales open; no identity is inferred or invented here.
Data processed by the current system
Website sessions. Laravel session data supports navigation, CSRF protection, forms, and temporary protected-download access. With the configured database session driver, a session record may include its identifier, payload, last activity, associated administrator identifier where applicable, IP address, and user agent.
Administration. Restricted administrator accounts include identity, email, password hash, role status, authentication session data, and an optional remember-token mechanism. Operational actions may also appear in technical logs.
Pre-launch notification. If the optional form is enabled and you consent, the system stores the normalized email address, consent time, unsubscribe status, notification status, and record timestamps. A genuinely new request receives an immediate confirmation email, followed by one notification when commercial sales open. Duplicate requests and renewed consent do not trigger another confirmation. This does not create a customer account, a newsletter subscription, or a recurring marketing sequence.
Purchase and access records. The architecture can store customer email, order identifiers and amounts, purchased items, entitlement status and platform, and access history needed to provide and support a future purchase. Sales are not currently open, and no payment provider is identified as active in this policy.
Credentials and recovery. Permanent access credentials and short-lived recovery tokens are stored as cryptographic hashes, not as readable secret codes. Recovery records include expiry and use times. No customer account or desktop password is required.
First download evidence. For an eligible entitlement, the website records the date when the first download stream starts and the internal Release served. This supports access administration, customer support, and evidence of digital supply. It does not prove installation or download completion and adds no IP address, fingerprint, device identifier, or desktop telemetry.
Technical logs. Application and infrastructure logs may contain timestamps, request or error context, and technical identifiers needed to operate, secure, and diagnose the service. Complete form submissions, passwords, access codes, and recovery tokens are not intended to be logged.
Purposes and legal grounds
- Requested website functions, future purchase delivery, protected access, recovery, and support may be necessary for pre-contractual measures or performance of a contract.
- Order, accounting, tax, consumer-rights, and dispute records may be retained where a legal obligation or legal claim requires it.
- Session security, abuse prevention, service integrity, and proportionate operational logging may rely on legitimate interests, subject to the required balancing and safeguards.
- The confirmation for a new pre-launch request and the single sales-opening notification rely on the specific consent collected by that form; consent may be withdrawn using the signed unsubscribe mechanism.
Commercial roles, recipients, and any additional legal grounds that depend on the final sales and provider model will be reviewed and published before sales open. This policy is information, not a request for blanket consent.
Retention
The current website session lifetime is 120 minutes of inactivity, subject to normal server-side housekeeping. Customer, order, entitlement, first-download, and support records may need longer retention for access delivery, legal obligations, and claims. Recovery tokens expire after 30 minutes and are eligible for pruning. A final commercial retention schedule will be completed before launch; data will not intentionally be retained longer than needed for the applicable purpose.
Recipients and international processing
Access is limited to authorized administration and the technical services actually required to operate the website. No future hosting, network, email, checkout, or payment provider is presented here as active. Provider-specific recipients, locations, safeguards, and roles will be added after configuration is confirmed and before commercial processing begins.
Future international sales do not remove mandatory privacy or consumer protections that apply in a person’s jurisdiction. Any international transfer mechanism required by the final provider architecture will be documented before launch.
Your rights
Depending on the processing and applicable law, you may have rights of access, rectification, erasure, restriction, objection, and data portability. Where processing relies on consent, you may withdraw that consent without affecting earlier lawful processing. Some rights are conditional and may be limited by legal retention duties or the rights of others.
You may also complain to the competent supervisory authority. For a Belgian operator, this includes the Belgian Data Protection Authority. This does not prevent a complaint to another competent authority where applicable.
Cookies and local storage
The current website uses only necessary cookies and local storage. See the Cookie & Local Storage Policy for the exact current list and preference-interface behavior.