Privacy Policy
This Privacy Policy sets out the basis on which we will process any Personal Data that we may collect
about you as a visitor to our website at www.abyss-project.fr and our customers or potential customers
using our tools and Software as a Service (SaaS) solutions (“Services”), or other business partners or in
any other cases where we specifically state that this policy will apply. This policy further sets out how
we protect your privacy and your rights in respect of our use of your Personal Data. If you are a user of
our Android mobile applications Abyss Cloud and Abyss Memories, please refer to our App Privacy
Policy.
WHO IS THE DATA CONTROLLER?
A “data controller” is a person or organization who alone or jointly determines the purposes for which,
and the manner in which, any personal data is, or is likely to be, processed. In this sense, Abyss Project,
Mehdi "Scylla" Abdelkrim, Saint-Louis, France (“Abyss Project”, “we”, “us”, “our”) is the data
controller. If you have any questions about data protection at Abyss Project in general, you can reach
us by email using contact@abyss-project.fr.
WHAT IS PERSONAL DATA?
Personal data is any information that relates to an identified or identifiable living individual. Different
pieces of information, which collected together can lead to the identification of a particular person, also
constitute Personal Data.
WHAT IS SPECIAL CATEGORY DATA?
Special category data is Personal Data that needs more protection because it is sensitive. This includes
Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs,
trade union membership, genetic data, biometric data. As well as, data concerning health, a person’s
sex life; and a person’s sexual orientation. In order to lawfully process Special Category Data, it is
necessary to consent to the processing
WHY DO WE HAVE A PRIVACY POLICY?
France's Data Protection Act (Law 2018-493 and Ordinance 2018-1125) (“DPA”) and the EU's
General Data Protection Regulation (“GDPR”) control how your Personal Data is used by us. We are
also required to explain which Personal Data we collect from you via our website and services, what
we use it for, when we delete it and how your data is protected.
WHAT ARE THE LEGAL BASES FOR PROCESSING PERSONAL DATA
All Personal Data that we obtain from you via our website will only be processed for the purposes
described in more detail below. This is done within the framework of the DPA and the GDPR and only
if at least one of the following applies: a) you have given your consent, b) the data is necessary for the
fulfillment of a contract / pre-contractual measures, c) the data is necessary for the fulfillment of a legal
obligation, or d) the data is necessary to protect the legitimate interests of our company, provided that
your interests are not overridden.
WHAT PERSONAL DATA DO WE COLLECT FROM YOU?
a) Collection of access data and log files
When you visit our website, we collect the Personal Data that your browser automatically transmits to
our server. This is technically necessary for us to display our website and to ensure its stability and
security. In this sense, we collect the following data: a) IP address of the requesting computer, b) Date
and time of access, c) name and URL of the file accessed, d) website from which the access was made
(referrer URL), e) browser used and, if applicable, the operating system of your device as well as the
name of your access provider. The legal basis is our legitimate interest.
b) Hosting
We do not use a hosting service for the purpose of operating our website and instead our website is self-
hosted. In doing so we process inventory data, contact data, content data, contract data, usage data, meta
data and communication data of our customers, interested parties and visitors ourselves and on our own
Privacy Policy
servers. The legal basis is our legitimate interests in an efficient and secure provision of the website and
services in conjunction with the provision of contractual services.
c) Cookies
For the processing of personal data using cookies and similar technologies on our website, please refer
to our Cookie Policy. The legal basis for the use of cookies is our legitimate interest or your consent
when you agree to the use of technically non-essential cookies as further explained in our Cookie Policy.
d) Cookie consent
As set out in France’s Trust in the Digital Economy Act (L. 34-5 of the Postal and Electronic
Communications Code) (“Act”) and the EU`s Privacy and Electronic Communications Directive
(“PECD”), we need to obtain consent for the use of technically non-essential cookies. For this purpose
we use a cookie consent tool, to obtain your consent to the storage of cookies and to document this
consent. When you enter our website, the following Personal Data is transferred to us via our cookie
consent tool: a) Your consent(s) or revocation of your consent(s); b) Your IP address; c) Information
about your browser; d) Information about your device; e) Time of your visit to our website. The basis
for processing is our legitimate interest and your consent.
e) Economic analyses and market research
For business reasons, we analyze the data we have on business transactions, contracts, enquiries,
browsing behavior etc. The analyses serve us alone and are not disclosed externally and processed using
anonymous analyses with summarized and or anonymized values. For this purpose we use Google
Analytics and you can find more information about Google Analytics in our Cookie Policy. The legal
basis is our legitimate interest and your consent.
f) Google Tag Manager
We use Google Tag Manager, which allows website tags to be managed via an interface. The Google
Tag Manager only implements tags. No cookies are set, and no Personal Data is collected. Google Tag
Manager triggers other tags that may collect data but does not itself access this data. The legal basis for
using Google Tag Manager is our legitimate interest.
g) Contact options
We process and store the Personal Data provided in the contact enquiry solely for the purpose of
processing and responding to your enquiry and contacting you. If you contact us, we will process the
data you provide to respond to you and answer your questions and requests. In doing so, the principle
of data economy and data avoidance is observed in that you only have to provide the data that we
absolutely need from you in order to contact you. These are usually your first and last name, your email
address, the topic selection and the message itself. The legal basis for processing is our legitimate
interest, the provision or initiation of a contractual service and your consent.
h) Registration
As part of the registration process, users provide their email and password. The data provided will be
used for the purposes of creating and using the account and providing and/or using our services.
Alternatively, you are able to sign up using the convenience login and sign up from Discord. For
convenience login and sign up, you will be asked to provide your basic information (i.e., name, email
address, and display picture) linked to your account. When registering via our convenience function,
you agree to the relevant terms and conditions and consent to certain data from your respective profile
being transferred to us.
In the context of the use of our registration and convenience log in and sign up as well as the use of the
user account, the legal basis for the data processing is the fulfillment of our contractual obligations and,
in individual cases, the fulfillment of our legal obligations as well as consent.
Privacy Policy
i) Using our Tools and SaaS Services
If you wish to use our tools and SaaS services (Abyss Crypt, Abyss Cloud, Abyss Memories,
AbyssBanking), we process the data you provide which may include Personal Data, Special Category
Data and non-personal data (“Service Data”). We recognise that you own your Service Data and provide
you with complete control over your Service Data by providing you the ability to a) access your Service
Data, b) share your Service Data, and c) request export or deletion of your Service Data.
When we process Service Data, we become your Data Processor or in other words, we will process the
Service Data involved in your use of our services in accordance with your instructions and shall use it
only for the purpose of providing you our services.
We ensure that access by our employees to your data is only available on a need-to-know basis,
restricted to specific individuals, and is logged and audited. We communicate our privacy and security
guidelines to our employees and enforce privacy and protection safeguards strictly. The legal basis for
the processing of your Service Data is our obligation to fulfill the contract we have with you.
Please note: Some jurisdictions may require you to disclose your use of our Services and us as your
processor in your privacy policy and/or data processing agreement as applicable. For this purpose all
Service Data processed by us will be processed using our own server and take appropriate legal
precautions and corresponding technical and organizational measures to ensure the protection of your
Service Data.
j) Your end users and our Tools and SaaS Services
If you are a Developer and you design, integrate and configure our Tools and SaaS Services into your
developments, we may also process Personal Data, Special Category Data and non-personal data of
your end users (“End User Data”). The End User Data processed by us depends on how you are using
our Tools and SaaS Services and the requests you and/ your end users are submitting. In this sense you
have full control over how you and your end user are using our Services, for example by using
configuration options and settings, and the End User Data that is processed by us.
Further and if you are providing us with End User Data relating to a third party, you agree a) that you
have in place all necessary appropriate consents and b) that such third party has read this Privacy Policy.
You agree to indemnify us in relation to all and any liabilities, penalties, fines, awards, or costs arising
from your non-compliance with these requirements.
The legal basis is the provision of a contractual service. Further and in accordance with the DPA and
the GDPR we act as the Data Processor. Some jurisdictions may require you to disclose your use of our
Services and us as your processor in your privacy policy and/or data processing agreement as applicable.
k) Support ticket
If you create a support ticket, we will request Service Data and, where applicable, End User Data in
accordance with your request, this may include your name, email address and other order related data
you voluntarily provide. The data provided is not shared with third parties and cannot read your data
when it is entered. If you submit a support ticket, we process the data for the purpose of processing and
handling your ticket.
Our employees will also have access to data that you knowingly share with us for technical support or
to import data into our services. We communicate our privacy and security guidelines to our employees
and enforce privacy safeguards strictly. The legal basis of the data processing is our obligation to fulfill
the contract and/or our legitimate interest in processing your support ticket.
l) Payment Data
If you make a purchase for service credits, your payment data will be processed via our payment service
provider Stripe. Payment data will solely be processed through Stripe and we have no access to any
Privacy Policy
Payment Data you may submit. The legal basis for the provision of a payment system is the
establishment and implementation of the contract.
m) Our Community
We process the Personal Data that arises when you use our community services. In particular, this
requires you to join our server and community on Discord. If you contact or connect with us via Discord,
we and Discord are jointly responsible for the processing of your data and enter into a so-called joint
controller agreement. The legal basis is our legitimate interest, your consent or, in some cases, the
initiation of a contract, if any.
n) Administration, financial accounting, office organization, contact management
We process data in the context of administrative tasks as well as organization of our business, and
compliance with legal obligations, such as archiving. In this regard, we process the same data that we
process in the course of providing our contractual services. The processing bases are our legal
obligations and our legitimate interest.
o) Promotional use of your data
We use your data (email) within the legally permissible scope for marketing purposes, e.g., to draw
your attention to special promotions and discount offers via email. In addition, we reserve the right to
use your first and last name as well as your postal address for our own advertising purposes, e.g., to
send you interesting offers and information about our products by post. This serves to protect our
legitimate interests.
DISCLOSURES OF YOUR PERSONAL DATA
We will not disclose or otherwise distribute your Personal Data to third parties unless this is a) necessary
for the performance of our services b) you have consented to the disclosure, c) or if we are legally
obliged to do so e.g., by court order or if this is necessary to support criminal or legal investigations or
other legal investigations or other legal proceedings; or proceedings at home or abroad or to fulfill our
legitimate interests.
INTERNATIONAL TRANSFER
We may transfer your Personal Data to other companies as necessary for the purposes described in this
Privacy Policy. In order to provide adequate protection for your Personal Data when it is transferred,
we have contractual arrangements regarding such transfers. We take all reasonable technical and
organizational measures to protect the Personal Data we transfer.
SOCIAL MEDIA
We are present on social media on the basis of our legitimate interest (currently, X (formerly Twitter)
and Instagram). If you contact or connect with us via social media, we and the relevant social media
platform are jointly responsible for the processing of your data and enter into a so-called joint controller
agreement. The Personal Information collected when contacting us is to handle your request and the
bases are both your consent and our legitimate interest.
In addition, your data may be processed for market research and advertising purposes. For example,
usage profiles can be created from your usage behavior and the resulting interests. This allows, for
example, advertisements to be placed within and outside the platforms that presumably correspond to
your interests. The legal basis is our legitimate interest.
When you visit our social media profiles, we, as the operator of the profile, process your actions and
interactions with our profile (e.g., the content of your messages, enquiries, posts or comments that you
send to us or leave on our profile or when you like or share our posts) as well as your publicly viewable
profile data (e.g., your name and profile picture). Which Personal Information from your profile is
publicly viewable depends on your profile settings, which you can adjust yourself in the settings of your
social media account. The legal basis is our legitimate interest and your consent.
Privacy Policy
HOW LONG DO WE KEEP YOUR PERSONAL DATA?
We will delete your Personal Data when we no longer need such Personal Data, for instance where:
it is no longer necessary for us to retain your Personal Data to fulfill the purposes for which we
had collected it;
we believe that your Personal Data that we hold is inaccurate; or
in certain cases where you have informed us that you no longer consent to our processing of
your Personal Data.
Sometimes, however there are legal or regulatory requirements which may require us to retain your
Personal Data for a specified period, and in such cases we will retain your Personal Data for such
specified period; and we may need to retain your Personal Data for certain longer periods in relation to
legal disputes, and in such cases we will retain it for such longer periods to the extent required.
HOW WE SECURE YOUR PERSONAL DATA
We take appropriate organizational, technical, and physical measures to help safeguard against
accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the
Personal Data we collect and process. However, no method of collection, storage, or transmission is
100% secure. You are solely responsible for protecting your password, limiting access to your devices,
and signing out of websites after your sessions.
LINKED SITES
For your convenience, there may be hyperlinks on our website that link to other websites. We are not
responsible for, and this Privacy Policy does not apply to the privacy practices of any linked websites
or of any companies that we do not own or control. The website links may collect information in
addition to the information we collect.
We do not endorse any of these linked websites, their products, services, or any of the content on their
websites. We encourage you to seek and read the Privacy Policy of each linked website that you visit
to understand how the information that is collected about you is used and protected.
YOUR RIGHTS AND PRIVILEGES
a) Privacy rights
You can exercise the following rights:
The right to access;
The right to rectification;
The right to erasure;
The right to restrict processing;
The right to object to processing;
The right to data portability;
b) Updating your information and withdrawing your consent
If you believe that the information we hold about you is inaccurate or request its rectification, deletion,
or object to legitimate interest processing, please do so by contacting us.
c) Access Request
In the event you want to make a Data Subject Access Request, please contact us. We will respond to
requests regarding access and correction as soon as reasonably possible. Should we not be able to
respond to your request within thirty (30) days, we will tell you why and when we will be able to
respond to your request. If we are unable to provide you with any Personal Data or to make a correction
requested by you, we will tell you why.
d) Complaint to a supervisory authority
Privacy Policy
The Commission nationale de l'informatique et des libertés (CNIL) (www.cnil.fr) is the relevant
authority in France. If you believe that the processing of your Personal Data is not lawful, you can lodge
a complaint with a data protection supervisory authority. We would, however, appreciate the chance to
deal with your concerns before you approach the CNIL or any other supervisory authority.
e) What we do not do
We do not request Personal Data from minors and children;
We do not process special category data without obtaining prior specific consent;
We do not use Automated decision-making including profiling; and
We do not sell your Personal Data.
HELP AND COMPLAINTS
If you have any questions about this policy or the information we hold about you please contact us by
email using contact@abyss-project.fr
CHANGES
The first version of this policy was issued on Saturday, 10th of August, 2024 and is the current version.
Any prior versions are invalid and if we make changes to this policy, we will revise the effective date.