Controller and scope
The controller is AI CTO PARTNERS, SIRET 10253537400015, registered in France, at [registered office address — REQUIRED BEFORE LAUNCH]. Privacy contact: [privacy/DPO contact email — REQUIRED BEFORE LAUNCH].
This policy applies to bealegendgames.com, early-access registration, product communications, and—when launched—Be a Legend accounts and associated web services.
Data we process
Depending on your use, we may process email address, account identifiers, display name, locale, timezone, consent records, support communications, security logs, device/browser data, coarse network information, gameplay/account activity, subscription status, and privacy requests.
Do not submit sensitive personal data in free-text support fields. The marketing website does not intentionally request special-category data.
Purposes and legal bases
Early-access registration and requested launch updates: consent. Account creation and delivery of requested game services: contract or pre-contractual steps. Security, abuse prevention, service reliability, and limited product improvement: legitimate interests balanced against user rights. Legal compliance and valid authority requests: legal obligation.
Optional analytics or marketing storage is based on consent and remains disabled until consent. Consent can be withdrawn without affecting prior lawful processing.
Recipients and processors
Authorized AI CTO PARTNERS personnel and contracted processors receive only the data needed for their duties. Hosting uses AWS Amplify Hosting provided by Amazon Web Services EMEA SARL; region: [exact AWS hosting/data region — REQUIRED BEFORE LAUNCH]. Additional email, support, payment, analytics, or distribution providers must be added to this policy and the processor register before activation.
Where data leaves the EEA, AI CTO PARTNERS will use an adequacy decision or appropriate safeguards such as Standard Contractual Clauses, with supplementary measures where required.
Retention
Early-access data is kept until withdrawal or no later than 12 months after the relevant launch campaign unless a new lawful purpose is communicated. Account data is kept while the account is active and then deleted or anonymized according to the operational and legal retention schedule. Security logs are normally kept 30–90 days unless an incident requires longer preservation.
Consent evidence, transactions, disputes, and legal records may be retained for the applicable limitation or statutory period. Final production retention periods must be documented before launch.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing; withdraw consent; and provide instructions where available. Contact [privacy/DPO contact email — REQUIRED BEFORE LAUNCH]. We may need to verify identity and will respond within applicable legal deadlines.
You may complain to Commission nationale de l’informatique et des libertés (CNIL) at https://www.cnil.fr/ or to the competent authority where you live or work.
Security, children, and updates
We apply proportionate access control, encryption, logging, backups, minimization, and incident procedures. No internet service can guarantee absolute security.
The intended minimum age is 16. Age and parental-consent requirements must be validated for each launch territory before accounts are offered to minors.
Material policy changes will be dated and communicated appropriately. Current policy version: 2026-08-07.