Last updated: October 8, 2026
Privacy Policy & Data Protection
Last updated: 9 October 2026
At JSBCloud, protecting your personal data is part of the service. This policy sets out plainly which data we collect, why, who we share it with, how long we keep it and how you stay in control of it. It is drawn up in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and the French Data Protection Act (loi Informatique et Libertés).
JSBCloud is a brand operated by ALTISCORE SAS. This policy covers the public website jsbcloud.com, your client area and all of our services: servers, game servers, web hosting, domain names, Email Pro mailboxes and Altis Studio.
1. Data controller
The controller of your personal data is:
- ALTISCORE SAS, share capital of 105 €
- Trade and Companies Register (RCS) Annecy: 933 804 676
- Registered office: 4A Avenue Auguste Renoir, 74960 Annecy, France
- Data protection contact: [email protected]
We are not required to appoint a data protection officer and we have not appointed one. Questions about your data are handled by management, at the address above. That address carries the "dpo" prefix for historical reasons: it does not designate a data protection officer within the meaning of article 37 of the GDPR.
2. Data we collect
Identity and contact details
- First name and last name. On a business account, the name shown on the account is the company name, the first and last name identifying the person to contact.
- Email address and password. The password is stored as an irreversible hash: we do not know it and cannot give it back to you.
- Phone number, optional.
- Postal address, postcode, city, country.
- For businesses: company name, SIRET number, intra-Community VAT number and the date it was validated.
- Account preferences: language, signature, tone and form of address used by the assistants, newsletter subscription, date of last login.
- Discord user ID and username if you link your Discord account.
Billing and payment
- Orders, quotes, invoices, credit notes, payments, prepaid balance and credits.
- The type and the last four digits of your payment method, or the account address when you pay with an electronic wallet such as PayPal. The full card number and your wallet credentials never pass through our servers: they stay with our payment provider.
- The identifiers of your record with our billing and payment providers.
- If you are a referrer or a referred customer in one of our referral or partner programmes: an irreversible fingerprint, computed with a secret key (HMAC), of each payment method used (card, SEPA direct debit mandate, or PayPal account identifier and address), derived from the information our payment provider sends us. It cannot be used to recover the payment method: it is only used to spot the same payment method being used by a referrer and the customer they referred, or by several customers referred by the same referrer.
Login and security
- IP addresses used to log in and to browse, protocol version (IPv4 or IPv6), country inferred from the information supplied by our anti-DDoS provider, browser and operating system as declared, number and dates of visits.
- Device fingerprint: a fingerprint computed at each login from the subnet of your IP address, your browser and your country, so that we can warn you when a login comes from an unusual device.
- Sessions open on your account.
- Two-factor authentication: application secret stored encrypted, hashes of the codes sent by email, registered passkeys and their last use.
- Activity log: action performed, object concerned, description, IP address and browser.
- IP address bans and refused attempts, including for visitors who are not customers.
- Browser security policy violation reports: page concerned, blocked resource, source file, an extract of the blocked content limited to one kilobyte, IP address, browser.
Use of your services
- The configuration of your services and the matching technical identifiers in our hosting panels.
- Performance readings of your servers every five minutes: processor, memory, network traffic, uptime.
- Service event log, with the author of each action.
- Traffic statistics for the sites you host with us, when you enable that option.
- Public SSH keys you upload.
- Technical secrets required to deliver and maintain your services (root password, panel passwords, FTP passwords), stored encrypted.
- Game nickname when you provide one.
Support
- Tickets, message contents and attachments. Attachments are submitted to an antivirus scan before being stored.
- The rating and comment you leave in the satisfaction survey.
- Log of the emails we send you: recipient, subject, delivery status, any errors, a 500-character extract of the body and a copy of the rendered message. Codes and links containing a token are masked in the extract. Everything is deleted after 90 days.
- When you use our support on Discord: Discord user ID and username, channel concerned, message identifiers, entries in prize draws. If you open a ticket from Discord without holding an account with us, a technical account is created to carry your request, then merged with your real account on the day you link the two.
Artificial intelligence assistants
- The content of your conversations with our assistants, together with the metadata and the cost of each exchange.
- For the game server assistant: an extract of your server console and the differences between configuration files before and after a proposed change.
- For Altis Studio: your instructions and the content of the site produced.
- For the mailbox service: your instructions, the text produced and the sorting labels derived from your messages.
- Proof of your consent: date, IP address, browser and version of the text you accepted.
Email Pro mailboxes
- The addresses of your mailboxes, display name, the text of your automatic reply, quota used.
- The content of your messages, calendars and address books stored on our servers.
- Contact book: name, address, company and free-form notes about your correspondents.
- Mailbox access log: who opened, listed, read, sent, moved, deleted or exported, with the date, the IP address and the browser, including when a third party acts on your behalf.
- Device passwords: label, password hash, last use and last IP address used.
- During a mailbox migration: host, username and password of your previous server, for the duration of the copy.
- If you enable open tracking: subject, recipients and number of opens of the messages you send, together with the IP address and browser of your recipients.
Domain names and DNS
- Full contact details of the registrant: first name, last name, email address, phone number, street, city, postcode, country and company for a business.
- Transfer code (EPP) and the state of WHOIS privacy protection.
- The Cloudflare interface token you entrust to us for the DNS link, stored encrypted, together with the IP address from which the link was created.
People attached to your account
- Technicians you appoint and members of your team: email address, display name, role, status and date of last login.
- Partner and referral programme: PayPal address for payouts and the history of your requests.
Data produced by our teams about your account
- Internal notes written by our staff and a priority customer flag.
- Reasons, durations and scope of the measures taken on your account: general ban, support restriction, assistant restriction, credit freeze.
- Abuse reports passed on by our network partner: IP address targeted, categories, description, evidence and a full copy of the report.
The data in this section is not shown in your client area, but it is personal data: it falls within your right of access and you may ask us for a copy.
Carried over from our previous system
If your account comes from our previous billing system, we keep its original identifier, its support code and the date it was carried over, so that your history stays attached to it.
What is required and what is not
Your first name, last name, email address, postal address and country are necessary to enter into and perform the contract: without them we can neither open your account, nor issue a compliant invoice, nor deliver a service. On a business account, the company name, the SIRET number and, where applicable, the intra-Community VAT number meet a legal invoicing obligation (article L441-9 of the French Commercial Code and article 242 nonies A of annex II to the French General Tax Code): we cannot open a business account without them. The contact details of a domain name registrant are required by the registries: without them, no registration is possible.
Your phone number, your game nickname, the Discord link, your SSH keys and the newsletter subscription are optional: not providing them has no consequence whatsoever on your contract.
3. Purposes and legal bases
| Purpose | What it covers | Legal basis |
|---|---|---|
| Managing your account | Registration, login, client area, preferences | Performance of the contract |
| Delivering and maintaining your services | Provisioning, configuration, monitoring, maintenance, backups | Performance of the contract |
| Billing, collection and debt recovery | Orders, invoices, payments, reminders, balance | Performance of the contract and legal obligation |
| Accounting and archiving of records | Bookkeeping, retention of invoices | Legal obligation |
| Checking the VAT number and the SIREN number | Verification with the competent public authorities | Legal obligation |
| Technical and commercial support | Tickets, Discord channel, satisfaction survey | Performance of the contract |
| Keeping track of the customer relationship | Internal notes written by our staff, support prioritisation | Legitimate interest in remembering our exchanges and in prioritising the accounts that require it, with a right to object |
| Migrating a mailbox | The credentials of your previous server, for the duration of the copy, then erased | Performance of the contract |
| Prize draws and giveaways | Entry, draw, delivery of the prize | Performance of the rules of the draw, which you accept by entering |
| Security, fraud and abuse prevention | Activity log, IP address history, device fingerprint, captcha, bans, handling of abuse reports | Legitimate interest in protecting our infrastructure and our customers |
| Retention of connection logs | Identification of the authors of content and of unlawful acts | Legal obligation (LCEN) |
| Artificial intelligence assistants | Support, game servers, Altis Studio, mailboxes, mail sorting, signature | Consent, requested separately for each use |
| Open tracking for the emails you send from your mailboxes | Tracking pixel in the messages you send | Consent, option disabled by default |
| Traffic statistics for the sites you host with us | Measuring traffic on your own pages, when you enable the option | We act as your processor: the legal basis is yours |
| Newsletter and commercial communications | Sending news and offers | Consent |
| Invitation to leave a review | Your email address sent as a blind copy of the service delivery email | Legitimate interest in obtaining verified feedback on the quality of our services and in reporting on it publicly, with a right to object |
| Referral and affiliate programme | Tracking the origin of a registration, awarding commission, and detecting self-referral by comparing, between the referrer and the referred customer and between customers referred by the same referrer, the payment method fingerprints, who paid their invoices, the normalised contact details (email address, phone number, postal address), the links between accounts (appointed technician, team) and recent IP addresses. A match opens a review by our team: the commissions concerned are held during the review, and none is refused without it | Legitimate interest in paying introducers accurately and in preventing referral fraud, and performance of the contract for our partners |
| Audience measurement on our sites | Traffic statistics for our own pages | Legitimate interest in measuring traffic on our pages in order to fix them, where the measurement is carried out without a cookie; consent as soon as a cookie is set |
| Improving our services | Analysis of usage and incidents, error monitoring, recording of a sample of client area sessions | Legitimate interest in detecting outages and correcting defects in our services |
| Meeting our legal obligations and responding to the authorities | Legal requests, tax and accounting obligations | Legal obligation |
Where we rely on legitimate interest, you may object to the processing on grounds relating to your particular situation. See section 9. For the review invitation, write to us at [email protected] and we will remove your address from those emails.
4. Artificial intelligence assistants
We offer several assistants based on artificial intelligence. They are optional. Refusing them does not prevent you from using the service concerned and has no consequence on your contract or on the quality of your support.
One consent per use
Your consent is requested separately for each of the following uses:
- assistance in support tickets
- the game server assistant
- Altis Studio, for building websites
- processing the content of your Email Pro messages
- automatic sorting of your messages
- drafting your email signature
You may withdraw a consent at any time from your client area. Withdrawal stops the processing for the future. For automatic mail sorting, the labels already computed on your messages are deleted when you withdraw.
We keep a record of your acceptances (date, IP address, browser, version of the text accepted) and of your withdrawals (date, version of the text concerned), for the sole purpose of proving that your consent was properly obtained.
What is sent to the provider
| Assistant | What is sent |
|---|---|
| Support | The account type (business or individual), your country, the list of your ongoing services with the product name, its identifier and its status, and the subject, category, priority and content of your ticket |
| Game servers | Your messages, an extract of your server console, the differences between configuration files before and after a change |
| Altis Studio | Your instructions and the content of the site being built |
| Mailboxes and mail sorting | Your instructions and the content of the messages concerned |
| Signature | The elements you provide for the drafting |
The provider and the country
The default provider is DeepSeek, established in China. Mistral AI, established in France, may be used instead. You may ask us at any time which provider is in service by writing to [email protected].
This transfer to China relies on your explicit prior consent, within the meaning of article 49(1)(a) of the GDPR. We must therefore warn you of the risks: China is not covered by any adequacy decision of the European Commission, its legislation allows public authorities to access data hosted on its territory, and you have no judicial remedy there equivalent to the one available in the European Union. If you do not want any transfer of your data outside the European Union, do not enable the artificial intelligence assistants: that is precisely why they remain optional, and why Mistral AI, established in France, is available as an alternative.
Neither we nor our provider use the content of your exchanges to train models, and we do not resell it: the setting that forbids such use has been enabled on our account with DeepSeek. The provider in service and the date on which that setting was confirmed are published on the "AI data processing" page of your client area (/en/legal/ai-data-processing).
Retention and internal controls
Your conversations with the assistants are kept for the lifetime of your account and deleted when your account is deleted. That period prevails over any other indication shown in your client area.
Specifically authorised members of our staff may view and export these conversations, for moderation and abuse prevention purposes. Such access requires named authorisations.
5. Processing specific to certain services
Domain names
Registering a domain name means passing the registrant identity on to our registrar, InternetBs Corp., established in the Bahamas, and then to the registry of the domain concerned. Part of this information is published in the WHOIS database, which is publicly accessible.
WHOIS privacy protection is disabled by default. If you do not want your contact details published, enable it from your client area or ask us to do it for you. Some extensions require certain fields to be published in any case.
Email Pro mailboxes
The content of your mailboxes belongs to you. We do not read it, except at your express request as part of support, when you enable an artificial intelligence assistant on your mailboxes, in order to respond to a security incident affecting our servers, or in order to comply with a legal request within the limits of that request. Attachments are also submitted to an automatic antivirus scan, with no human reading.
Every access to a mailbox is logged, including when a member of your team or a technician you have appointed acts on your behalf. This log is available to you.
Open tracking of the messages you send is disabled by default. If you enable it, a pixel is added to your outgoing messages and we record the IP address and browser of your recipients. In that case, you are the controller for this processing in relation to your correspondents: it is up to you to inform them and to have a legal basis. We then act as your processor. You may disable tracking at any time.
Servers, game servers and web hosting
We take performance readings of your servers every five minutes and log service events. We only look at the content of your servers in order to carry out a support request, to respond to a security incident or to handle an abuse report.
If you enable traffic statistics on a site you host with us, it is your visitors' data that is measured. You are then the controller for this processing in relation to them: it is up to you to inform them in your own privacy policy. We act as your processor, the measurement stays hosted on our servers, and you may disable it at any time.
Delegated technicians and teams
If you invite a technician or a team member, we collect their email address, display name, role and login dates. You are responsible for informing these people and for the legitimacy of the access you grant them. A view in your client area lets you see their actions on your services. On our side, those people will find in section 6 the information we owe them.
Network abuse reports
The abuse reports targeting our IP addresses are passed on to us by our network partner NetExpert. We match them with the service concerned and keep a copy of the report so that we can account for our decision. A confirmed abuse may lead to the suspension and then the termination of the service. You are informed and may respond before any final measure is taken.
6. If you are not a customer but your data reaches us
Some of the data we process is not given to us by the person it concerns. This section is addressed to those people, in accordance with article 14 of the GDPR. The controller remains ALTISCORE SAS, the rights described in section 9 are exercised with [email protected], and a complaint to a supervisory authority remains possible (section 18).
| Who you are | Where your data comes from | What we process | Why and on what basis | For how long |
|---|---|---|---|---|
| Appointed technician or team member | The customer who invited you | Email address, display name, role, login dates, actions carried out on the customer's services | To open a delegated access for you and to account for it to the customer. Legitimate interest in securing and tracing delegated access | The duration of the access, then the activity log rules. An invitation left unanswered is deleted after 30 days |
| Correspondent listed in an Email Pro address book | The customer who holds the mailbox | Name, address, company and free-form notes about them | To host the customer's address book. The customer is the controller for this processing, we are their processor | For as long as the customer keeps the entry |
| Recipient of a tracked email | The customer who enabled open tracking on their mailbox | IP address, browser, date and number of opens | To tell the customer whether their message was opened. The customer is the controller for this processing, we are their processor | 180 days |
| Visitor to a site hosted with us | Your browser, where the customer has enabled statistics | Pages viewed and traffic data | To measure traffic on the customer's site. The customer is the controller for this processing, we are their processor | 25 months, then aggregation with no individual data |
| Person named in an abuse report | Our network partner NetExpert and the complainants | IP address targeted, categories, description, evidence, full copy of the report | To handle the report and to justify the measure taken. Legal obligation as a host and legitimate interest in stopping abuse | For as long as the file may be useful to establish or defend a legal claim, including after the deletion of the account concerned |
| Domain name registrant entered by a third party | The customer who registered the domain name | First name, last name, address, phone number, email address, company | To register and maintain the domain name with the registrar and the registry. Performance of the contract entered into with the customer and requirement of the registries | The lifetime of the domain name, then the period imposed by the registry |
| Visitor to our sites without an account | Your browser | IP address, browser, refused login attempts, bans | To protect our services. Legitimate interest in protecting our infrastructure and our customers | 12 months |
| User of our Discord support without an account | Your message on Discord | Discord user ID and username, content of your request | To handle your request. Pre-contractual steps taken at your request | The support ticket rules set out in section 8 |
A customer who attaches a person to their account remains responsible for informing that person and for the legitimacy of the access they grant. That does not relieve us of the present information, which we owe you directly.
7. When we act as a processor
When you host with us the personal data of your own users (website, database, mailbox, game server, traffic statistics for your site), you are the controller of that data and we act as your processor within the meaning of article 28 of the GDPR.
The mutual obligations, the list of our sub-processors, the security measures and the fate of the data at the end of the contract are set out in our data processing agreement, appended to our terms and conditions and available on request at [email protected].
This policy describes only the processing for which we are ourselves the controller.
8. Retention periods
We keep your data for as long as is necessary for the purposes for which it was collected, and no longer.
| Data | Retention period |
|---|---|
| Account and active services | For the duration of the contractual relationship |
| Inactive account | Archived after 3 months without a login, then deleted after a further 6 months of archiving. Accounts holding a service in progress are not affected. |
| Account with no service, invoice or ticket | Deleted 6 months after registration |
| Account deletion request | Carried out after a grace period of 30 days |
| Invoices, credit notes, payments and accounting records | 10 years under article L123-22 of the French Commercial Code, and 6 years under article L102 B of the French Tax Procedure Code (Livre des procédures fiscales) |
| Cancelled invoices or invoices left as drafts | Deleted after 30 days. Invoices carried over from our previous system are kept as accounting history. |
| Cancelled, failed or fraudulent orders | Deleted after 30 days |
| Support tickets | 3 years after the ticket is closed |
| Activity and connection logs | 12 months. The purge runs once a month, so deletion may take place up to one month after the deadline. |
| IP address history | 12 months from the last time the address appeared |
| Payment method fingerprints (referral) | 13 months from the last time they appeared, and deleted with the account |
| Log of the emails we send | 90 days, content and metadata included |
| Open tracking for your Email Pro messages | 180 days for opens, 365 days for tracked messages |
| Traffic statistics for our sites | 25 months, then aggregation with no individual data |
| Performance readings of your servers | 40 days for detailed readings, 12 months for consolidated reports |
| Browser security policy violations | 30 days |
| Technical payment events | 30 days |
| Notifications that have been read | 30 days |
| Passwords entered when placing an order | 7 days |
| Custom system images | 7 days |
| Technician accounts left inactive after invitation | 30 days |
| Entries in prize draws | 12 months after the end of the draw, apart from the records needed to deliver the prize |
| Internal notes written by our staff | For the duration of the commercial relationship, with a right to object at any time |
| Conversations with the assistants, device fingerprints, mailbox access logs | Lifetime of the account, deleted with the account |
Log in at least once a year to keep your account: the archiving and then the deletion of an inactive account run automatically on the deadlines set out above.
What happens after a service is terminated
When you terminate a service yourself, its infrastructure and its backups are destroyed on the end date you chose, with no further delay. When we terminate for non-payment, destruction takes place 7 days after termination. For a fixed-term service, it takes place 48 hours after the end date. A termination for a serious breach of our terms leads to immediate destruction. In every case the destruction is irreversible: retrieve your data before the deadline.
Your account itself is not deleted automatically when a service is terminated. It stays open and then follows the inactive account rules described in the table above, unless you ask for it to be deleted.
9. Your rights
The GDPR grants you the following rights over your personal data.
Right of access
Obtain confirmation that data concerning you is being processed and receive a copy of it, including the internal notes written about you.
Right to rectification
Have inaccurate or incomplete data corrected.
Right to erasure
Ask for your data to be deleted, subject to the data the law requires us to keep, in particular accounting records.
Right to restriction of processing
Ask for the processing to be frozen, for example while we check the accuracy of data you contest.
Right to data portability
Receive the data you provided to us in a structured, machine-readable format, or ask for it to be transmitted to another provider.
Right to object
Object, on grounds relating to your particular situation, to processing based on our legitimate interest, and, without having to give a reason, to processing for direct marketing purposes.
Right to withdraw your consent
Withdraw at any time a consent you have given, in particular for the artificial intelligence assistants, open tracking or the newsletter. Withdrawal does not affect what was done before.
Rights in relation to automated decision-making
Not be subject to a decision based solely on automated processing producing significant effects concerning you. See section 13.
Instructions for after your death
Set instructions on what should happen to your data after your death, in accordance with article 85 of the French Data Protection Act. Send them to us at the address given below.
10. Exercising your rights
Directly from your client area
- "Data & Privacy" page (
/settings/data-privacy): download your data, schedule the deletion of your account, cancel that deletion. - "Profile" page (
/settings/profile): correct your identity, your contact details and your company information. - "AI assistant" page (
/settings/ai-assistant): grant or withdraw each of your consents and erase the history of your conversations.
Or by writing to us
- By email: [email protected]
- By post: ALTISCORE SAS, Data Protection, 4A Avenue Auguste Renoir, 74960 Annecy, France
- By ticket: from your client area
We reply within one month of receiving your request. If the request is complex, or if you make several of them, this period may be extended by two months: we then tell you within the first month and explain why. Where we have reasonable doubt about your identity, we may ask you for proof before replying.
What the automatic export contains
Immediately downloadable from your client area:
- your personal information and your billing contact details
- your account settings, including your Discord identifier
- your identifiers with our billing and payment providers
- your subscriptions, your invoices and your payments
- the last 100 entries of your activity log
Provided on request, within one month, and in full: your tickets and their attachments, your domain names, your conversations with the assistants, your IP address history, the whole of your activity log and the log of the emails sent to you. Ask us for these at [email protected].
Deleting your account
You can ask for your account to be deleted yourself, from the "Data & Privacy" page. The deletion is then scheduled and becomes final after 30 days. During that period you may cancel it from the same page.
The self-service deletion button stays unavailable for as long as you still have an active or suspended service, an unpaid invoice, or an unused prepaid balance: the account then carries an ongoing contract, accounting records, or money that belongs to you. Terminate your services first, settle your invoices, and ask us to refund any remaining prepaid balance: the deletion then becomes possible again. This does not deprive you of your right to erasure: write to us and we will examine your request individually, replying within one month and giving reasons for any partial refusal.
What "deletion" means exactly. We irreversibly erase your identity: your name is replaced by a neutral entry, your email address by a technical address with no value, your password is reset at random, and your phone number, address, SIRET number, VAT number and identifiers with our providers are erased. We also destroy more than thirty sets of data attached to your account: IP address history, device fingerprints, passkeys and two-factor authentication, cart, tickets and drafts, conversations with the assistants, contacts, mail filters and tracking, mailbox access logs, consents, coupons, DNS link and the token entrusted to us, calendars and address books, mail imports.
The technical record of your account itself is not destroyed: it carries the invoices the law requires us to keep. It no longer holds your name, your contact details or your identifiers with our providers. Kept for the same reason: your invoices, from which the billing address is removed, your payments, your orders, your quotes, your credit notes and your balances, your credits, referral commissions, your domain names, the audit and email logs from which the link to your account is removed, and the abuse files.
11. Recipients of your data
Within our company
- technical support team
- billing department
- management
Access is limited to what each role requires, and the actions carried out on your account are logged, as is access to the content of your mailboxes.
People you appoint
- the technicians to whom you delegate access to your services
- the members of your business team
Processors
The following providers process data on our behalf. This list is up to date as of 21 September 2026. It is reviewed whenever a provider changes and at least once a year, and any change is reflected in this page, whose update date appears at the top.
| Processor | Purpose | Location and transfer safeguard |
|---|---|---|
| Stripe Payments Europe Ltd. | Payment processing and storage of payment methods | Ireland (EU), with transfers to Stripe, Inc. in the United States covered by the standard contractual clauses of the Stripe data transfer addendum |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Payouts to our partners and referrers | Luxembourg (EU), processor established in the European Union |
| Pennylane | Invoicing, accounting and archiving of invoices | France (EU), no transfer outside the EEA |
| Infomaniak | Relay for our transactional emails | Switzerland, adequacy decision of the European Commission |
| Cloudflare, Inc. | Anti-DDoS protection, web application firewall, captcha, public DNS, filtering of banned IP addresses | United States, standard contractual clauses of its data processing agreement |
| Discord, Inc. | Login with Discord, support channel and internal alerts | United States, standard contractual clauses of its data processing agreement |
| DeepSeek | Artificial intelligence assistants, default provider | China, your explicit prior consent (article 49(1)(a) of the GDPR) |
| Mistral AI | Artificial intelligence assistants, alternative provider | France (EU), no transfer outside the EEA |
| Sentry | Application error monitoring and recording of a sample of client area sessions, with text masked and media blocked | United States, standard contractual clauses of its data processing agreement |
| Slack Technologies | Internal operational alerts, which may mention a customer account | United States, standard contractual clauses of its data processing agreement |
| Trustpilot A/S | Review invitation, sent as a blind copy of the service delivery email, and display of reviews | Denmark (EU), no transfer outside the EEA |
| InternetBs Corp. | Domain name registration and management | Bahamas, transfer necessary for the performance of your contract (article 49(1)(b) of the GDPR) |
| Object storage provider | Keeping our encrypted backups away from the original server | France (EU), no transfer outside the EEA |
| Equinix | Physical hosting of our servers, PA5 site in Paris | France (EU), no transfer outside the EEA |
| Netaris SAS | Technical infrastructure services | France (EU), no transfer outside the EEA |
Our hosting panels, our audience measurement solution, our antivirus and our knowledge base run on our own servers: they are not processors, they are our infrastructure.
Resources loaded by your browser
Some resources are loaded directly from third-party servers when our pages are displayed. Those third parties therefore receive your IP address and the information sent by your browser.
| Resource | Purpose | Operator | Data transmitted |
|---|---|---|---|
| Payment form (js.stripe.com, m.stripe.network) | Securing the payment and preventing fraud | Stripe | IP address, browser |
| Turnstile captcha (challenges.cloudflare.com) | Protection of the login, registration and forgotten password forms | Cloudflare | IP address, browser |
| Main fonts (fonts.bunny.net) | Display of the website and the client area | BunnyWay d.o.o., Slovenia (EU) | IP address, browser |
| Accessibility fonts (fonts.googleapis.com, fonts.gstatic.com, cdn.jsdelivr.net) | Display of the accessibility fonts in the client area, including the dyslexia-friendly font | Google LLC, jsDelivr | IP address, browser |
| Review widget (widget.trustpilot.com) | Display of customer reviews on the public website | Trustpilot | IP address, browser |
Public bodies and registries
- the European Commission, to check your intra-Community VAT number through the VIES service
- the French administration, to check that your SIREN number exists through recherche-entreprises.api.gouv.fr
- Mojang, to convert a Minecraft nickname into an account identifier when you provide one
- the domain name registries, which receive the registrant contact details through the registrar and publish part of them in the WHOIS database
Authorities
Judicial or administrative authorities, only upon a legal request and within the limits of that request.
We do not sell your data and we do not pass it on to anyone for advertising purposes.
12. Transfers outside the European Union
Your data is hosted in France: production in the Equinix PA5 data centre in Paris, encrypted backups on object storage located in France. Some processing nevertheless involves genuine and permanent transfers outside the European Union.
| Recipient | Country | Data concerned | Safeguard |
|---|---|---|---|
| Cloudflare, Inc. | United States | IP address and traffic of every visitor, banned IP addresses | Standard contractual clauses, supplemented where applicable by certification under the Data Privacy Framework between the European Union and the United States |
| Stripe, Inc. | United States | Payment data, email address, billing address, IP address | Standard contractual clauses of the Stripe data transfer addendum, supplemented by the certification of Stripe, Inc. under the Data Privacy Framework |
| Discord, Inc. | United States | Discord identifier and the content of the support messages exchanged through that channel | Standard contractual clauses |
| Sentry | United States | Technical error data, IP address, and session recording for a sample of client area sessions as well as for any session in which an error occurs | Standard contractual clauses |
| Slack Technologies | United States | Content of internal operational alerts, which may mention a customer account | Standard contractual clauses |
| Google LLC, for the accessibility fonts | United States | IP address and browser information | Certification of Google LLC under the Data Privacy Framework between the European Union and the United States |
| DeepSeek | China | The content of your exchanges with the artificial intelligence assistants | Your explicit prior consent, after being informed of the absence of an adequacy decision (article 49(1)(a) of the GDPR) |
| InternetBs Corp. | Bahamas | Contact details of the domain name registrant | Transfer necessary for the performance of the contract you entered into with us (article 49(1)(b) of the GDPR) |
| Infomaniak | Switzerland | Email address and the content of the emails we send you | Adequacy decision of the European Commission |
You may obtain a copy of the safeguards in place by writing to [email protected].
13. Automated decisions
Some measures are triggered without human intervention:
- suspension of a service in the event of non-payment, after the reminders provided for in the contract
- suspension of a service following an abuse report
- temporary ban of an IP address after repeated login attempts
- automatic sorting of your messages, if you have enabled that option
The logic is simple and involves no behavioural scoring: an invoice past its due date after reminders triggers suspension; a number of failed logins from the same IP address over a short period triggers a temporary ban; an abuse report qualified by our network partner triggers the suspension of the service concerned.
These measures may affect you significantly. They are permitted by article 22(2) of the GDPR because they are necessary for the performance of the contract between us (non-payment), required by our obligations as a host (abuse), or based on your consent (mail sorting). In every case they are reversible, and you may obtain human intervention, express your point of view and contest the decision, by opening a ticket or writing to [email protected].
We may also restrict access to your account, to support, to the assistants or to your credits in the event of a breach of our terms and conditions. Those measures are decided by a person, not by an automated process. The reason for the measure and its duration are given to you, and the same route to contest it is open.
14. Data security
We implement appropriate technical and organisational measures:
- encryption in transit (TLS) on the client area, the public website, our administration interfaces and our mailbox services; the legacy protocols still offered on some hosting plans all have an encrypted variant, which we recommend you use
- hosting in France, in the Equinix PA5 data centre in Paris
- passwords stored as an irreversible hash, never in clear text
- technical secrets and tokens you entrust to us stored encrypted
- two-factor authentication and passkeys available on your account
- password confirmation required for sensitive actions, such as adding or removing a payment method and delegating access to a technician
- uploaded files stored in a private area that is not publicly accessible and submitted to an antivirus scan
- anti-DDoS protection, web application firewall and captcha on sensitive forms
- logging of access and actions, on the customer side as well as on the staff side
- regular backups, encrypted and kept away from the original server, on object storage located in France
- access to data limited to the people who need it, through a system of named authorisations
- masking of the text you type and blocking of media in the session recordings sent to our monitoring tool
No system is invulnerable. In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we inform you as soon as possible, in accordance with article 34 of the GDPR, and we notify the CNIL within 72 hours of becoming aware of it, as required by article 33 of the GDPR.
15. Cookies and trackers
The cookies we set
| Name | Purpose | Duration | Set by |
|---|---|---|---|
laravel_session and XSRF-TOKEN | Keep your session open and protect forms against forgery | 120 minutes of inactivity | JSBCloud |
derniere_activite_staff | Automatic logout of our staff accounts | 12 hours | JSBCloud |
appearance | Remembers the light or dark theme | 1 year | JSBCloud |
sidebar_state | Remembers whether the side panel is open or closed | 7 days | JSBCloud |
cart_id | Keeps your cart between two visits | 1 year | JSBCloud |
NEXT_LOCALE | Remembers the language chosen on the public website | 1 year | JSBCloud, on the public website |
price_mode | Remembers whether prices are shown excluding or including tax | 1 year | JSBCloud, on the public website |
referral_link_code | Remembers the referral code you arrived with, so that the referrer can be credited when you register and make your first purchase | 30 days | JSBCloud, on the shared domain .jsbcloud.com |
jsbc_cookie_consent_v1 | Remembers your choice about cookies | 395 days | JSBCloud, on the public website |
__stripe_mid and __stripe_sid | Payment security and fraud prevention | 1 year for __stripe_mid, 30 minutes for __stripe_sid | Stripe |
__cf_bm and cf_clearance | Check that you are not a robot and keep a record of that check | 30 minutes for __cf_bm, 30 days for cf_clearance | Cloudflare |
| Review widget cookies | Display of the Trustpilot widget on the public website | Durations published by Trustpilot in its cookie list | Trustpilot |
In your client area, your language preference is not stored in a cookie: it is kept in your session and in the local storage of your browser. On the public website, it is remembered by the NEXT_LOCALE cookie.
Audience measurement
We use Matomo, installed on our own servers: the traffic statistics are not passed on to anyone.
- On the public website jsbcloud.com, Matomo is configured without cookies and without cross-site tracking. That configuration falls under the exemption set out by the CNIL and therefore does not require your consent. The banner lets you decide about the cookies that are not strictly necessary, and a "Manage cookies" link at the bottom of the page lets you change your mind at any time. Your choice is kept for 395 days.
- In your client area, audience measurement is enabled, but it is anonymous: it sets no cookie, transmits neither your email address nor any account identifier, and is limited to counting page views. No visit can therefore be linked to a person, and your consent is not required for that measurement.
Managing your cookies
- the banner and the "Manage cookies" link at the bottom of the public website
- your browser settings, to block or delete cookies that have already been set
Refusing cookies that are not strictly necessary does not prevent you from using our services. Refusing strictly necessary cookies, on the other hand, prevents you from logging in to your client area and from placing an order.
We do not use any advertising cookie and we do not carry out any targeting. The referral_link_code cookie serves a commercial purpose, crediting the person who referred you, not an advertising one: you can delete it from your browser with no consequence on your use of our services.
16. Minors
Our services are aimed at people with the capacity to enter into a contract. We do not knowingly collect data concerning minors under 15, the age of digital consent in France within the meaning of article 45 of the French Data Protection Act (loi n° 78-17 of 6 January 1978, as amended). If you are a parent or hold parental authority and believe that your child has sent us personal data, write to us at [email protected] and we will delete it.
17. Changes to this policy
This policy changes along with our services, our providers and the regulations. Each version carries a number and a date: the version in force is the one whose update date appears at the top of the document, in each language version. Previous versions are available on request at the contact address.
In the event of a substantial change, in particular a new purpose, a new transfer outside the European Union or the arrival of a new processor receiving your data, we inform you by email or by a notification in your client area before it takes effect.
18. Complaint to a supervisory authority
If you consider that the processing of your data infringes the GDPR, you may lodge a complaint with a supervisory authority. We encourage you to contact us first, but this is not a mandatory step.
- CNIL (Commission Nationale de l'Informatique et des Libertés), the French supervisory authority
- 3 Place de Fontenoy, TSA 80715
- 75334 PARIS CEDEX 07, France
- Telephone: +33 1 53 73 22 22
- Website: www.cnil.fr
If you live or work in another Member State of the European Union, or if the infringement took place there, you may also apply to the supervisory authority of that State. The list is published on the website of the European Data Protection Board.
19. Contact
For any question about this policy or your personal data:
- Email: [email protected]
- Post: ALTISCORE SAS, Data Protection, 4A Avenue Auguste Renoir, 74960 Annecy, France
- Ticket: from your client area

