My TeamGameInvite friendsHelp
Login

Privacy Policy

Last updated: 4 June 2026

This privacy policy (the "Policy") describes how CYLIMIT collects, uses, retains and protects your personal data when you use our website, application and services (the "Services"). It applies to all users and sets out, where relevant, the additional processing that concerns only French residents under the regime applicable to Monetisable Digital Object Games ("JONUM").

We apply the principle of data minimisation: for each processing operation, we collect only the data strictly necessary for the relevant purpose. Your data is processed in accordance with the General Data Protection Regulation ("GDPR") and French law.

1. Data controller

The controller of your personal data is:

Company : CYLIMIT, a simplified joint-stock company (SAS) with share capital of €1,000

Registration : Paris Trade and Companies Register 917 501 298, SIRET 917 501 298 00017, VAT number FR90917501298

Registered office : 6 rue d'Armaillé, 75017 Paris, France

President : Valentin Gosse

Privacy contact : contact@cylimit.com

This Policy forms an integral part of our Terms of Service. Capitalised terms not defined here have the meaning given to them in those terms. It should also be read together with our Marketplace Terms, our Game Rules, our Responsible Gaming page and our Cookies Policy.

2. Data collected, purposes and legal bases

We process your data for specified purposes, each relying on a legal basis within the meaning of Article 6 (and, where relevant, Article 9) of the GDPR.

Account creation and management : Username, first and last name (declared or verified), email address, phone number, country, password (stored in hashed form, never in clear text), avatar and cover image. Legal basis: performance of the contract (our terms).

Wallet : The public address of your Coinbase embedded wallet, together with the email address, phone number and authentication method associated with that wallet. Legal basis: performance of the contract. See also the section "The blockchain and your data".

Payments : Stripe customer identifier (stripeCustomerId), the last four digits of your card (which we access through Stripe without storing them directly) and your USDC balance. Legal basis: performance of the contract.

Game and competitions : Date of birth, nationality, team line-ups, performance, scores and rankings, as well as the publication of your username and the rewards you have won in leaderboards. Legal basis: performance of the contract.

Referral programme : Email address, invitation code and spending data used to assess whether qualification thresholds are met. Legal basis: performance of the contract.

External account links (at your initiative) : Discord (email and profile details), Twitter / X (id, name, username), sign-in via Google or Facebook (name and email). Legal basis: performance of the contract and/or consent, which you may withdraw at any time by unlinking the account.

Security and fraud prevention : IP address, user agent (browser, device) and transaction details, in order to secure the Services and your account and to detect, prevent and investigate any fraud or breach of our terms. Legal basis: the Company's legitimate interest in protecting its Services and users.

Help and support : The content of your requests to our support team and associated contact details. Legal basis: performance of the contract and legitimate interest in handling your requests.

3. Identity verification (KYC) and biometric data, French residents

If you reside in France and wish to acquire or use NFT cards (blue, pink and yellow rarities), the JONUM regime requires us to verify your identity and that you are of legal age. This verification is carried out by our specialist provider Didit Identity Spain, S.L. (Barcelona, Spain).

The verification process comprises: optical character recognition (OCR) of your identity document, a passive liveness check, a facial comparison between your selfie and the document photo (face match), and analysis of your IP address.

The liveness check and facial comparison constitute the processing of biometric data for the purpose of unique identification, falling within the special categories under Article 9 of the GDPR. The legal basis is Article 9(2)(g) (substantial public interest), grounded in the JONUM regime (SREN Law No. 2024-449, Decree No. 2026-60 and the Order of 4 February 2026).

Allocation of roles: the biometric data (selfie image, facial template) is processed and retained by Didit, acting as a processor; its servers process this data within the European Economic Area (EEA). CyLimit neither receives nor stores any biometric image: through a signed webhook, we receive only the decoded textual identity data (last name, first name, date of birth, document country / type / number), retained only if verification succeeds, together with an identity fingerprint (identityHash). For details of the biometric processing, please refer to Didit's privacy policy.

The identity data resulting from KYC is retained by CyLimit for the period required by our legal and regulatory obligations (see the section "Retention periods").

4. JONUM territorial compliance data, French residents

To determine whether the JONUM regime applies to you and to enforce it, we process data specific to users identified as French residents only.

Jurisdiction determination : Approximate geolocation by IP address on first connection; the address on your identity document (KYC) prevails; a 6-month relocation rule applies where your country of residence changes. Legal basis: legal obligation.

IP address and geolocation history : Your IP address is hashed and never stored in clear text. We keep a geolocation history (country, region and connection date). Legal basis: legal obligation and legitimate interest (preventing circumvention).

Identity fingerprint (identityHash) : A fingerprint computed by hashing your first name, last name and date of birth. Purpose: to prevent the recreation of an account and the circumvention of a self-exclusion measure, and to avoid duplicates. Legal basis: legal obligation and legitimate interest.

Spending and play-time limits : Tracking of your NFT acquisition spending over a rolling 7-day period and of your play time (alerts and automatic logout), in order to enforce the JONUM limits. Legal basis: legal obligation.

Relocation supporting documents : Where your country of residence changes, the proof of address you submit is stored in a private, encrypted storage space, with no public URL, accessible only to our authorised staff via a temporary link, and is subject to manual review. Legal basis: legal obligation.

This compliance data is retained for the period required by the JONUM regulation and our supervisory obligations (see the section "Retention periods"). To learn more about the protective measures, see our Responsible Gaming page.

5. The blockchain and your data

NFT cards (blue, pink and yellow rarities) are non-fungible tokens (ERC-721) issued on a single public blockchain: Base, an Ethereum layer-2 network developed by Coinbase. Your wallet is a Coinbase embedded account (ERC-4337): CyLimit retains only the public address of that wallet, never the keys giving access to it.

Only the following appear on the blockchain: the public address of your wallet, the identifier (tokenId) of your NFTs and the metadata of transactions (purchases, sales, transfers). No other personal data is recorded there by CyLimit.

By their nature, data recorded on a public blockchain is public, immutable and cannot be erased or modified. This technical characteristic constitutes an intrinsic limitation on the right to erasure (Article 17 of the GDPR) for on-chain data.

"White" cards and free cards are not NFTs: they are off-chain game items recorded only in CyLimit's database. Any transfer of NFTs or cryptocurrencies to an external wallet is subject to the terms and privacy policy of the relevant third party (in particular Coinbase); we encourage you to review them before any such transaction.

6. Recipients and processors

We use providers (processors or independent controllers) to deliver, maintain and secure our Services. Each accesses only the data strictly necessary for its task and is bound by contractual data-protection commitments.

  • Account authentication and session management.
  • Provision of the embedded wallet and cryptocurrency conversion (purchase and withdrawal), by a provider acting as an independent controller for its own obligations.
  • Card payments and payment-fraud prevention, by a payment provider acting as an independent controller.
  • Identity verification (KYC) and biometric data processing for French residents (see section 3).
  • Monitoring and indexing of blockchain transactions (deposit detection).
  • Hosting of NFT metadata.
  • Sending of transactional emails (confirmations, notifications) and, based on your opt-in consent, marketing emails.
  • Internal operational and alerting tools, which may contain your email or identity, within the limits of data minimisation.
  • Application hosting and database, within the European Union.

Your data may also be accessed by authorised members of the CyLimit team, and disclosed to the competent authorities (in particular the French national gaming authority and the judicial authorities) where required by law and after verifying the legitimacy of the request.

7. Transfers outside the European Union

Your data is hosted primarily within the European Union. Some of our providers may, however, process data outside the European Economic Area, in particular in the United States.

Where a transfer outside the EEA takes place, we ensure that it is governed by at least one of the following mechanisms:

  • an adequacy decision of the European Commission (Article 45 of the GDPR), in particular the EU-US Data Privacy Framework for certified US providers;
  • standard contractual clauses adopted by the European Commission (Article 46 of the GDPR);
  • adherence to an approved code of conduct or certification mechanism.

8. Retention periods

We retain your data for the period necessary for the purposes described, after which we delete or anonymise it, unless a legal obligation requires longer retention.

Account data : For the entire life of the account, then for the applicable limitation periods.

KYC, identity and JONUM compliance data (spending, play time, geolocation, identityHash) : 5 years from the end of the contractual relationship (closure of your account), in accordance with our legal and supervisory obligations (JONUM regime and anti-money-laundering rules).

Relocation supporting documents : Retained for the period required by our legal territorial-compliance obligations.

Connection and security logs : Retained for a limited period, aligned with security and fraud-prevention needs.

On-chain data : Immutable: permanently recorded on the Base blockchain, it cannot be deleted (see section 5).

Invoices and accounting records : 10 years, in accordance with accounting and tax obligations.

Marketing data : 3 years from your last contact or until you withdraw your consent.

9. Your rights

In accordance with the GDPR, you have the following rights over your data: the right of access, rectification, erasure, restriction, objection, portability, withdrawal of your consent (without retroactive effect) and the right to give instructions on the fate of your data after your death.

The right to erasure cannot be exercised over data recorded on the blockchain (immutable, see section 5) or over data we are required to retain under legal obligations (JONUM and KYC compliance, accounting). For such data, we apply appropriate measures to restrict access.

To exercise your rights, write to us at contact@cylimit.com or by post to CYLIMIT, 6 rue d'Armaillé, 75017 Paris, France. We may ask you for proof of identity. We respond within one (1) month, extendable by two (2) months for complex requests.

You may also lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris (www.cnil.fr), or with the data protection authority of your EU Member State of residence.

10. Deleting your account

You may request deletion of your account by email to contact@cylimit.com. As of today, deletion is handled manually by our teams, generally within approximately 30 days (extendable to three months for complex requests).

Before any deletion request, transfer your NFTs and cryptocurrencies (USDC / ETH) to an external wallet that you control. Any asset remaining on your embedded wallet at the date of deletion may become permanently unrecoverable; CyLimit cannot be held liable for such a loss.

Some data is retained beyond account deletion in respect of our legal obligations (JONUM and KYC compliance, accounting). In order to preserve the history and traceability of the cards you have owned, the username associated with those cards may be replaced by a random string of characters (pseudonymisation). Data already recorded on the blockchain remains immutable.

11. Use by minors

Access to the free, non-NFT features of the platform (in particular play with "white" cards) is subject to no age restriction.

By contrast, the acquisition and holding of NFT cards (blue, pink and yellow rarities), and, for French residents, the application of the JONUM regime, are reserved for persons aged 18 or over. Legal age is verified during KYC from the date of birth on the identity document. Any French-resident account identified as a minor during KYC is blocked for these features.

12. Cookies and local storage

We use only cookies and storage strictly necessary for the operation of the Services: the authentication cookie (__session), your Coinbase wallet session and the storage of your referral code.

We use no advertising cookies and no analytics trackers. As these strictly necessary cookies are exempt from consent, no cookie banner is required at this time. Should we introduce a non-essential tracker, a consent banner would be put in place beforehand.

For more details, see our Cookies Policy.

13. Security

We implement technical and organisational measures designed to protect the confidentiality, integrity and security of your data: secrets management via a dedicated vault, password hashing, storage of sensitive supporting documents in a private, encrypted space, and restriction of access to authorised staff.

We recommend that you choose a strong, unique password, never share it, and keep your wallet access details in a safe place. As no security measure is infallible, we cannot guarantee absolute security, but we undertake to respond diligently to any incident.

14. Data protection contact, updates and governing law

For any question concerning this Policy or your data, you may contact our dedicated data-protection point of contact at contact@cylimit.com or by post to CYLIMIT, 6 rue d'Armaillé, 75017 Paris, France.

We may amend this Policy to reflect changes in our Services or in applicable law. Any significant change will be communicated to you. The applicable version is the one published on our website at the time you use the Services.

This Policy is governed by French law and the law of the European Union. If you are a consumer resident in another EU Member State, you retain the benefit of the mandatory provisions of your country of residence. See also our Legal Notice.

My account
HelpResponsible GamingCookie policyLegals noticeTerms of serviceMarketplace TermsGame RulesPrivacy policy
MarketMy TeamGameInvite friendsPartners
Contact us

Subscribe now to our newsletter to get latest updates and events