PRIVACY POLICY
How we collect, use and protect your personal data.
This document is an English translation of the French original.
It is provided so that our English-speaking customers can read our terms in their own language.
Only the French version has legal value. If a sentence here differs from the French text, the French text applies. The French original is available at winheberg.com/autres/legal/politique-de-confidentialite.
1. Who are we?
Winheberg is a sole trader business operated by Maxime Wussow (SIRET number: 883 153 314 00017), specialising in Gaming, VPS and Cloud hosting and related services. The registered office is located at: Rue Chaussade, Bâtiment 2 - 43260 Saint-Julien-Chapteuil, France.
As data controller, we take the confidentiality of your personal data very seriously and ensure its protection in accordance with the General Data Protection Regulation (GDPR) and applicable French law.
2. What data do we collect?
We collect various information about you, either provided directly by you or gathered automatically as you browse. The categories of data collected include:
- Contact details: surname, first name, email address, telephone number.
- Billing details: postal address, payment information (through a secure provider).
- Sign-in data: username and password to access your client area.
- Technical information: IP address, browser type, time zone, operating system.
- Browsing data: pages visited, visit duration, collected through cookies.
2.1 Data we do NOT accept for processing
Winheberg is not HDS-certified (French certification for hosting health data) and under no circumstances accepts the collection, processing or hosting of the following categories of personal data:
- Health data (French Public Health Code): medical records, patient files, test results, treatment histories, prescriptions;
- Biometric data used for identification purposes (Art. 9(1) GDPR): facial recognition, fingerprints, iris recognition, DNA analysis;
- Genetic data: DNA profiles, genetic markers;
- Data relating to criminal convictions and offences: criminal records, judicial history;
- Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or concerning sex life and sexual orientation.
Consequences of non-compliance
If Winheberg detects the presence of such data hosted on its servers, Winheberg will proceed with:
- Immediate suspension of access to the services without prior notice;
- Complete and permanent deletion of the data;
- Termination of the service contract with no indemnity or refund;
- Reporting to the competent authorities (CNIL, law enforcement) where the breach presents a risk to the rights and freedoms of others.
Alternatives for sensitive data
If you need to host health data or sensitive data, we recommend turning to HDS-certified hosting providers that meet the requirements of the French Public Health Code:
https://esante.gouv.fr/offres-services/hds/liste-des-hebergeurs-certifies
3. Why do we collect your data?
- To deliver our services: order management, payments and hosting.
- To provide customer support: resolving technical issues and offering assistance.
- To improve our services: analysing the user experience to optimise our performance.
- To communicate with you: sending information and commercial offers, only where you have given your consent.
- To meet our legal obligations: retention of invoices and tax records.
4. Legal basis for processing
Data processing is based on the following legal grounds:
- Performance of the contract (Art. 6(1)(b) GDPR): order management, service activation, billing, customer support.
- Consent (Art. 6(1)(a) GDPR): sending commercial communications by email (Art. L34-5 of the French Postal and Electronic Communications Code) and setting analytics cookies that are not strictly necessary.
- Explicit consent (Art. 9(2)(a) GDPR): processing of biometric data (facial matching) as part of KYC identity verification through Stripe Identity, where the Client expressly and separately consents to it during the verification process. This consent may be withdrawn at any time without prejudice to access to the service. Should it be refused, an alternative verification method is offered.
- Legal obligation (Art. 6(1)(c) GDPR): retention of accounting records, obligations under the French LCEN and the Digital Services Act, responses to judicial requests.
- Legitimate interest (Art. 6(1)(f) GDPR): infrastructure security, prevention of abuse, automated analysis of files hosted by Clients (antivirus, network behaviour analysis) for security purposes and to combat unlawful activity.
5. Sharing your data
We neither sell nor rent your personal data. It may nonetheless be shared with:
- Payment providers: to process your payments (Stripe, PayPal and Paysafecard).
- KYC identity verification: where verification is required, Winheberg uses Stripe Identity (Stripe Inc., United States — certified under the EU-US DPF) to validate identity documents. Where the Client expressly and separately consents, verification by facial matching (biometric data) may also be carried out. Stripe Identity processes this data under its own responsibility. Winheberg receives only the outcome of the verification.
- Hosting and technical providers: to deliver our hosting services (Cloudflare).
- The game server management panel is hosted by Winheberg on its own infrastructure, located at the nLighten Lyon LYS1 datacentre – 45 Rue Francis de Pressensé, 69100 Villeurbanne, France. Access to this panel is routed through the Cloudflare network (reverse proxy, network protection). The web hosting panel (Plesk) is hosted by Winheberg on its own infrastructure at the same datacentre and is reachable directly, without an intermediate proxy.
- Web hosting security: for antivirus protection and detection of malicious files on Plesk web hosting services (CloudLinux Inc., Imunify360 — United States).
- Customer review management providers: for handling feedback (Trustpilot).
- Domain name registration providers: for registering and managing your domain names (Netim).
- Customer support provider: for the online chat (Tidio LLC, United States).
6. Your rights
- Right of access: obtain a copy of the data concerning you.
- Right to rectification: correct inaccurate information.
- Right to erasure: request the deletion of your data in certain situations.
- Right to restriction: temporarily restrict the use of your data.
- Right to object: refuse the processing of your data on legitimate grounds.
- Right to portability: retrieve your data in a structured format or transfer it to a third party.
- Post-mortem directives: set instructions concerning the retention, erasure and communication of your data after your death, in accordance with Article 85 of Act No. 78-17 of 6 January 1978.
- Right not to be subject to automated decision-making: Winheberg does not take decisions producing legal effects based solely on automated processing (Art. 22 GDPR). Any automated measure (fraud detection, precautionary suspension) is subject to human review on request.
To exercise your rights, contact us at dpo@winheberg.com. A copy of proof of identity may be requested where there is serious doubt as to your identity. We will respond within one month, as required by law.
7. Data security
We implement appropriate measures to protect your data against:
- Loss.
- Unauthorised access.
- Disclosure or alteration.
- These measures include encryption and firewalls.
As part of infrastructure security, Winheberg may automatically analyse files hosted by Clients (web hosting, Discord bots, VPS) using malware detection tools (antivirus, network behaviour analysis). This analysis is carried out for the sole purposes of security and combating unlawful activity. The legal basis for this processing is Winheberg's legitimate interest (Art. 6(1)(f) GDPR).
In the event of a personal data breach likely to result in a risk to your rights and freedoms, Winheberg undertakes to notify the CNIL within 72 hours in accordance with Article 33 GDPR, and to inform you without undue delay where that risk is high, in accordance with Article 34 GDPR.
8. Cookies and similar technologies
We use cookies to operate and improve our services. These cookies break down as follows:
Essential cookies (necessary):
- Session cookies: keeping you signed in to the client area (duration: session)
- Preference cookies: language, theme (duration: 1 year)
- Security cookies: CSRF protection, Cloudflare verification (duration: session to 24 hours)
These cookies do not require your consent, as they are strictly necessary for the site to function.
Analytics cookies (optional):
- Traffic analysis cookies: pages visited, visit duration (duration: 13 months at most)
These cookies are set only after you consent. You may manage your preferences at any time through the cookie manager available in the footer of our site, or through your browser settings.
Refusing analytics cookies does not affect how the site works.
9. Data retention
Your personal data is kept for periods proportionate to its purpose:
| Type of data | Retention period |
|---|---|
| Client account data (name, email, telephone) | Duration of the contract + 3 years after the end of the business relationship |
| Billing data (invoices, payments) | 10 years (tax obligation — Art. L123-22 of the French Commercial Code) |
| Technical logs and access records (IP address, timestamp, actions) | The period necessary for infrastructure security, dispute handling and compliance with applicable legal obligations, within the limit of the ordinary limitation period |
| Browsing data (analytics cookies) | 13 months at most |
| Prospect data (enquiries without a subscription) | 3 years after the last contact |
| Support data (tickets, exchanges) | Duration of the contract + 3 years |
Once these periods expire, the data is deleted or irreversibly anonymised.
10. International data transfers
Some of our providers are established outside the European Union. The safeguards applied are as follows:
- Google LLC (Analytics, Tag Manager): certified under the EU-US Data Privacy Framework (DPF), adequacy decision of the European Commission dated 10 July 2023.
- CloudLinux Inc. (Imunify360 — web hosting security): transfer framed by the standard contractual clauses (SCCs) adopted by the European Commission (Decision 2021/914).
- Tidio LLC (customer support): transfer framed by the standard contractual clauses (SCCs) adopted by the European Commission (Decision 2021/914).
- Stripe / Stripe Identity / PayPal (payments and KYC identity verification): certified under the EU-US Data Privacy Framework (DPF).
- Paysafecard (Paysafe Group) (payments): transfer framed by the standard contractual clauses (SCCs) adopted by the European Commission (Decision 2021/914).
- Cloudflare: certified under the EU-US Data Privacy Framework (DPF).
11. Changes to the Privacy Policy
We may update this policy at any time. Any significant change will be communicated through our website or by email. We encourage you to review this page regularly.
12. Contact
For any question or complaint regarding this policy, contact us:
- Email: dpo@winheberg.com
- Telephone: +33 9 72 14 79 11
You may also lodge a complaint with the CNIL (the French data protection authority) if your rights are not respected.