Privacy Policy

Introduction

Note: Before getting into our privacy policy, we want to make one thing clear. We respect your privacy and take great care to safeguard it. We do not sell your data. This policy does not exist to collect your data for sale. For the necessary operation of The Forge (billing being one example) we must collect some personal data. We inform you below on what information we need to collect, for what purpose we need it, and how it is processed.

We must process some of your personal data so that you can enjoy our roleplaying gaming platform – a hosting service and so much more. The purpose of this document is for you to find out how we process your personal data, and inform you of your rights. Please read it carefully, and in case you have any questions feel free to contact us by using information mentioned further in our policy.

Who are we? We determine the purpose and means of processing of your personal data ('data') and we are considered to be a controller under the General Data Protection Regulation. We are The Forge, based in Quebec, Canada, GST/QST ID 767105067. We operate this Website and the Platform where you can enjoy our products and services.

Purpose of processing, categories of personal data and legal bases

In order to register on our Platform, purchase our services and enjoy them afterwards we have to collect and process certain personal data. Some of the data is a statutory or contractual requirement, or a requirement necessary to enter into a contract. If you decide not to disclose such data to us, you will be unable to use our Platform. More information about what data we collect, for what purposes, and our legal basis for that can be found in the table below.

Categories of personal dataPurpose of processingLegal basis for processing
Name, email address, passwordTo create an account and to be able to access the platform, purchase products and service and be able to use them continuouslyProcessing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
Payment details including credit card details and/or associated PayPalTo successfully charge a transaction and calculate the correct tax jurisdiction for our users.Processing is necessary for the fulfillment of a contract to which the data subject is party.
Third party accounts connected by the user for login.To allow the user to associate their account with an existing third-party account, and to use it for login purposes.Subject can voluntarily connect third-party services for their convenience and terminate these connections at any time.
IP AddressTo correctly charge VAT/sales tax per user jurisdiction, and ensure correct functionality of the website.Processing is necessary to comply with EU taxation law requiring taxation to be made based on the IP address location of the user.
Game usage details, including when a game is accessed, how long it is accessed, and activity logs.To provide relevant usage statistics for users, and ensure informed customer service support.Processing is necessary as part of our performance of a contract to provide necessary services to the end user, and perform vital maintenance toward those services.

Legitimate interest as a legal basis

In cases where we process your personal data on a basis of legitimate interest, we carefully balance your interests against ours. If your interests and fundamental rights and freedoms override the legitimate interest pursued by us, we will find another legal basis or we will not process personal data for that purpose. You can always contact us to find out how we applied the legitimate interest assessment for the particular processing activity.

Recipients of the personal data

We have to share some or all of your personal data with third parties ('Recipients'), so that you can use our platform and enjoy our services. Recipients help us operate our Platform. These are hosting companies, third party IT services who help us operate the Platform, authorities where required by law, payment processors among others.

They can be independent controllers, joint-controllers or processors (e.g., hosting companies). For more information on this you can always contact us.

Transfers of personal data to third countries

We may transfer some of your personal data to third parties in other countries and/or outside of Quebec, as mentioned above. We will only do this to pursue legitimate interests as outlined above, and will not sell your data to third parties.

If you are in the European Union at the time of collection of your personal data, and we transfer your personal data outside the European Union or European Economic Area, we export information to countries deemed to provide adequate level of protection of personal data by the European Commission, or we use standard contractual clauses approved by the European Commission. You may contact us to obtain a copy of such safeguards by using contact details in the Contact Details section.

We also use contractual or other means to provide a comparable level of protection while the information is being processed by a third party. Where we export personal data to third countries such data may be accessible to law enforcement and national security authorities of that jurisdiction and subject to laws of such third countries.

For details on which third parties we may transfer your information to, see here.

Retention period and protection of your personal data

Data collected to open your account is kept while the account is active. We need to store certain information such as your transaction history and IP location for at least 10 years in order to comply with tax law in Quebec, the EU, and other taxable jurisdictions.

We employ appropriate technical and organizational measures to protect your personal data. These safeguards are intended to prevent the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed. These measures include, but are not limited to standard web encryption technologies, firewall protections, access control policies, and other standard security practices.

Your rights

You may exercise your rights by contacting us or our Data Protection Officer as described in relevant sections of this privacy policy.

Right of access
You can always contact us to find out if we process your personal data, and where that is the case, to acquire additional information about the purpose of processing, recipients, to receive copies of personal data processed and similar.

Right to rectification
If you think that some of your personal data is inaccurate or outdated, you can rectify them through your profile or contact us so that we could do it for you.

Right to erasure
Where conditions prescribed by laws are met and you request erasure of your personal data, we will fulfill your request and delete your personal data.

Right to restriction of processing
You can request us to restrict your data from further processing where permitted by Law (e.g., where your data is inaccurate).

Right to data portability
We deliver your data in a structured, commonly used electronic format. You have the right to request to have this data transferred to another controller where legal requirements are met.

Right to object
You can always object to processing of your personal data. If your personal data is processed for direct marketing purposes, including profiling related to direct marketing, we will stop processing your personal data for those purposes.

Where we process your personal data on a basis of legitimate interest or the processing is necessary or the performance of a task carried out in the public interest we will stop processing your personal data, unless our legitimate grounds for the processing override your interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.

Right to withdraw consent
If we process your personal data on a basis of your consent, you can always withdraw your consent. Withdrawal of your consent does not affect lawfulness of processing prior to that.

Use of cookies

Our website uses cookies. We use cookies in order to enable our website to function properly and to ensure that personal data is processed in a safe manner.

Cookie NameFirst/Third PartyDomainInformation it collects/storesDurationPurpose
Forge session cookiesFirsthttps://forge-vtt.com/Website theme and language preferences, and login session.14 daysTo correctly serve users with their chosen preferences, and ensure security for logged in users.
Foundry VTT session cookieFirstAny user-controlled subdomain under https://forge-vtt.com/User login session and client settingsUntil the Foundry VTT session idles or is stopped.To provide convenient re-access upon refreshing the Foundry VTT session.

Right to lodge a complaint with supervisory authority

If you are unhappy with how we process your personal data, you may contact us first to try to clarify your concerns.

In any case you may lodge a complaint with a relevant supervisory authority. List of authorities in the European Union can be found here.

The Commission d'accès à l'information du Québec is responsible for overseeing and enforcing the Quebec provincial access and privacy laws

The Office of the Privacy Commissioner of Canada provides advice and information for individuals about protecting personal information and enforces the Personal Information Protection and Electronic Documents Act.

Contact details

You may contact us by writing to our email address, at [email protected].

Contact details of our Data Protection Officer

Our Data Protection Officer monitors compliance with applicable privacy laws. You may contact them by writing to the email address above.