Uitgebreide informatie over de verwerking en bescherming van uw persoonlijke gegevens.
Laatst bijgewerkt: Mei 2026
BTPCraft SAS ("Company", "Platform", "btpcraft.com") is the data controller for all personal data processed through our services. BTPCraft operates two primary services: an AI-powered matching platform (btpcraft.com) and a Minecraft server (mc.btpcraft.com).
Data Controller Information:
Legal Framework:
This Privacy Policy complies with the following legal instruments:
For residents of France and the European Union, the CNIL (Commission Nationale de l'Informatique et des Libertés) is the lead supervisory authority for cross-border data processing activities.
We collect and process the following categories of personal data for the specified purposes:
A. Account Data (collected during registration):
B. Profile Data (provided voluntarily):
C. Minecraft Server Data:
D. Technical Data (automatically collected):
E. Payment Data:
Special category data (Article 9 GDPR — health data, criminal convictions, biometric data, political opinions, religious beliefs, trade union membership) is NEVER collected unless voluntarily provided with explicit consent for a specific, stated purpose.
Your personal data is processed exclusively for the following purposes, each supported by a specific legal basis under the GDPR and the Loi Informatique et Libertés:
Automated Decision-Making: BTPCraft does not engage in automated decision-making that produces legal effects concerning data subjects (GDPR Art. 22). The AI matching algorithm provides recommendations only; all final decisions regarding employment, contracting, or platform access involve human intervention.
Profiling: Limited profiling is conducted for the purpose of matching workers with suitable job opportunities based on skills, certifications, and professional experience. You have the right to object to this profiling at any time (GDPR Art. 21).
| Purpose | Legal Basis (French Law / GDPR) | |
| --- | --- | --- |
| Account creation, management, and authentication | Contract performance (Art. 6(1)(b) GDPR) | |
| AI-powered job/talent matching and recommendations | Contract performance (Art. 6(1)(b) GDPR) | |
| Platform security, abuse prevention, and fraud detection | Legitimate interest (Art. 6(1)(f) GDPR) | |
| Minecraft anti-cheat enforcement and server moderation | Legitimate interest (Art. 6(1)(f) GDPR) | |
| Communication between users (messaging, applications) | Contract performance (Art. 6(1)(b) GDPR) | |
| Billing, invoicing, and payment processing | Contract / Legal obligation (Art. 6(1)(b)/(c) GDPR) | |
| Customer support and dispute resolution | Legitimate interest (Art. 6(1)(f) GDPR) | |
| Marketing communications (only with explicit consent) | Consent (Art. 6(1)(a) GDPR) | |
| Service improvement, analytics, and product development | Legitimate interest (Art. 6(1)(f) GDPR) | |
| Compliance with legal and regulatory obligations | Legal obligation (Art. 6(1)(c) GDPR) | |
| Establishment, exercise, or defense of legal claims | Legitimate interest (Art. 6(1)(f) GDPR) |
Your personal data is shared with third parties only in the following limited circumstances, each governed by appropriate contractual safeguards:
A. Service Providers (Data Processors and Sub-Processors):
All service providers are contractually bound by Data Processing Agreements (DPA) compliant with GDPR Art. 28 and are prohibited from using your data for any purpose other than providing services to BTPCraft.
B. Sub-Processor Engagement: BTPCraft engages sub-processors only with prior written authorization. A list of current sub-processors is maintained and updated at least annually. You may request a complete list by contacting dpo@btpcraft.com.
C. Legal Compliance and Law Enforcement:
We may disclose your data if required by:
D. Business Transfers:
In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity. You will be notified via email and platform notice at least 30 days prior to such transfer, and your data will continue to be protected under this Privacy Policy unless you consent otherwise.
E. International Transfers:
Your data is primarily processed within the European Economic Area (EEA). When data is transferred to countries outside the EEA, we ensure an equivalent level of protection through one of the following mechanisms:
Your personal data is NEVER sold, rented, or traded to third parties for marketing or commercial purposes.
As a data subject, you have the following rights under the GDPR (EU) and the Loi Informatique et Libertés (France):
GDPR Rights (Chapter III, Art. 15-22):
1. Right of Access (Art. 15) — obtain confirmation of whether your data is processed and receive a copy of your data
2. Right to Rectification (Art. 16) — request correction of inaccurate or incomplete data
3. Right to Erasure (Art. 17) — "Right to be Forgotten"; request deletion of your data where the legal basis no longer applies
4. Right to Restrict Processing (Art. 18) — limit how your data is used pending resolution of a dispute
5. Right to Data Portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format
6. Right to Object (Art. 21) — object to processing based on legitimate interests, including profiling
7. Rights related to Automated Decision-Making (Art. 22) — not to be subject to decisions based solely on automated processing
8. Right to Withdraw Consent (Art. 7(3)) — withdraw consent at any time without affecting the lawfulness of prior processing
CCPA Rights (California Residents):
1. Right to Know — request disclosure of data collected, used, shared, or sold
2. Right to Delete — request deletion of personal information (subject to certain exceptions)
3. Right to Opt-Out — opt out of the sale or sharing of personal information (we do not sell data)
4. Right to Correct — request correction of inaccurate personal information
5. Right to Non-Discrimination — no penalty or discrimination for exercising your CCPA rights
How to Exercise Your Rights:
Response Times and Procedures:
Right to Lodge a Complaint:
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority:
Your personal data is retained only as long as necessary for the purposes described in this policy, in accordance with the principle of storage limitation (GDPR Art. 5(1)(e)):
Upon Account Deletion or Data Erasure Request:
After account deletion, you will lose access to all platform features, including purchased digital content, matching history, and messaging records.
| Data Category | Retention Period | Legal Basis / Reference |
| --- | --- | --- |
| Account data | Until account deletion + 30 days (grace period) | User request / GDPR Art. 17 |
| Profile data | Until account deletion + 30 days | User request |
| Minecraft gameplay data | Duration of active account + 6 months | Legitimate interest / CNIL guideline |
| Payment records and invoices | 10 years from end of business relationship | Tax obligation / French Commercial Code Art. L. 123-22 |
| Communication logs (messages) | 2 years from last activity | Legitimate interest |
| Technical logs (IP, browser, device) | 12 months (rolling) | Security / Legitimate interest |
| Marketing consent records | Until consent withdrawal + 3 years | Regulatory requirement / CNIL guideline |
| Cookie consent records | 6 months | ePrivacy Directive / CNIL guideline |
| Backup data | Maximum 90 days (encrypted, access-limited) | Security / Data integrity |
| Legal hold data | Duration of legal hold + applicable retention | Legal obligation |
We implement industry-standard technical and organizational measures to protect your personal data, in compliance with GDPR Art. 32 and the Loi Informatique et Libertés:
Technical Measures:
Organizational Measures:
Data Breach Notification Procedure (GDPR Art. 33-34):
In the event of a personal data breach that poses a risk to your rights and freedoms:
1. Detection and containment: immediate action to stop the breach and preserve evidence
2. Risk assessment: evaluation of potential impact on data subjects within 24 hours
3. CNIL notification: within 72 hours of becoming aware of the breach (GDPR Art. 33)
4. Data subject notification: without undue delay if the breach poses a high risk (GDPR Art. 34)
5. Remediation: implementation of corrective measures to prevent recurrence
6. Documentation: all breaches, regardless of severity, are documented per GDPR Art. 33(5)
This Cookie Policy explains how BTPCraft uses cookies and similar tracking technologies on btpcraft.com and mc.btpcraft.com, in accordance with the ePrivacy Directive (2002/58/EC), the GDPR, and CNIL guidelines (Recommendation No. 2020-092).
What Are Cookies: Cookies are small text files stored on your device by your web browser. They enable websites to recognize your device, remember your preferences, and provide analytics.
Types of Cookies We Use:
1. Essential / Strictly Necessary Cookies (Always Active — No Consent Required):
- Session cookie (btpcraft_session): maintains your login session — duration: session
- CSRF token (XSRF-TOKEN): protects against cross-site request forgery — duration: session
- Load balancing cookie: ensures consistent server routing — duration: session
- These cookies are necessary for the platform to function and are exempt from consent requirements under ePrivacy Art. 5(3) and CNIL guidelines.
2. Functional / Preference Cookies (Consent Required):
- Language preference (i18n_redirected): remembers your selected locale — duration: 12 months
- Theme preference (theme): saves your UI customization (light/dark mode) — duration: 12 months
- Cookie consent preference (cookie_consent): stores your consent choice — duration: 6 months
3. Analytics and Performance Cookies (Consent Required):
- Google Analytics 4 (_ga, _ga_*): anonymized page view and interaction tracking — duration: up to 24 months
- IP anonymization (anonymizeIp) is enabled; no personally identifiable information is transmitted
- Session recordings (Sentry): aggregated usage patterns without keystroke logging — duration: session
- These cookies help us understand how users interact with our platform to improve the experience.
4. Third-Party Cookies:
- Payment processor cookies (Paddle): strictly necessary for payment flow, controlled by Paddle's privacy policy
- Social media sharing widgets (if you choose to share content): controlled by the respective social platform
- These cookies are set only when you interact with the corresponding feature
Cookie Consent Management:
Managing Cookies via Browser Settings:
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or regulatory guidance. Material changes will be notified as follows:
Notification of Material Changes:
1. Email notification to the address associated with your account (at least 15 days before effective date)
2. Prominent notice on the platform (homepage banner or notification bar)
3. In-app notification for registered users
4. Update to the "Last Updated" date at the top of this page
If we make material changes that affect your rights or involve new processing purposes, we will obtain your explicit consent where required by applicable law (GDPR Art. 5(1)(b) — purpose limitation principle).
Historical version tracking:
Changes take effect on the date specified in the notification. Continued use of the Platform after the effective date of material changes constitutes acceptance of the updated policy, unless you have expressly objected or withdrawn consent where required.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Data Controller:
BTPCraft SAS
Email: info@btpcraft.com
Subject Line: "Data Protection Inquiry"
Data Protection Officer (DPO):
Email: dpo@btpcraft.com
Subject Line: "FAO: Data Protection Officer"
Response Times:
Supervisory Authorities:
www.cnil.fr — +33 (0)1 53 73 22 22
Online complaint form: cnil.fr/en/plaintes
Minecraft Server-Specific Information:
For data related to mc.btpcraft.com (Minecraft UUID, gameplay data, chat logs), all terms of this policy apply equally. In-game data collection is strictly limited to what is necessary for anti-cheat enforcement, server security, and gameplay continuity. Minecraft-related data subject requests should specify "Minecraft Data Request" in the subject line.