PRIVACY POLICY
Last updated: July 21, 2026
This Privacy Policy describes how Obsidian collects, uses and protects your personal data in compliance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the French Data Protection Act (Loi Informatique et Libertés, Act No. 78-17 of January 6, 1978, as amended).
Data Controller
The data controller responsible for the processing of your personal data is Obsidian. For any questions regarding your data, you may contact us via the Obsidian Discord server or by email at the address provided in the Contact section below.
Data We Collect
Discord authentication
Discord user ID, username, display name and email address.
Technical data
Hardware identifier (HWID), system configuration, IP address, crash logs and usage statistics.
Payment data
Payment information (credit card, cryptocurrency) is processed directly by our providers (NOWPayments, PayPal) and is never stored on Obsidian servers. We only retain transaction references and amounts for accounting purposes.
Legal Basis for Processing
In accordance with Article 6 of the GDPR, your data is processed on the following legal bases:
- Contract performance — provision of the Services and management of your license (Art. 6(1)(b))
- Legitimate interest — fraud prevention, platform security and abuse detection (Art. 6(1)(f))
- Legal obligation — compliance with accounting and tax requirements (Art. 6(1)(c))
- Consent — improvement telemetry, which can be withdrawn at any time (Art. 6(1)(a))
Purpose of Processing
Your data is used to: authenticate your identity and manage your account, enforce hardware binding (HWID) to prevent unauthorized sharing, process transactions and maintain purchase history, prevent fraud and improve the Software. We do not use your data for advertising purposes and never sell it to third parties.
Data Sharing
We share limited data with the following providers, solely to the extent necessary for their services: NOWPayments and PayPal (payment processing), Discord (authentication). These providers act as data processors under Article 28 of the GDPR and are contractually bound to protect your data. No personal data is shared with other third parties unless required by law or court order.
International Data Transfers
Some of our service providers (Discord) may process data outside the European Economic Area. In such cases, transfers are protected by appropriate safeguards as required by Chapter V of the GDPR, including Standard Contractual Clauses (SCCs) adopted by the European Commission or adequacy decisions.
Data Retention
Account data is retained for the duration of your account. Upon deletion or ban, personal data is purged within 30 days, with the exception of transaction records retained for up to 10 years in compliance with French accounting obligations (Code de commerce, Art. L.123-22) and tax requirements. Crash logs and usage statistics are anonymized after 12 months.
Your Rights (GDPR)
In accordance with the GDPR (Articles 15 to 22) and the French Data Protection Act, you have the following rights:
- Right of access — obtain a copy of your personal data (Art. 15)
- Right to rectification — correct inaccurate data (Art. 16)
- Right to erasure — request deletion of your data (Art. 17)
- Right to data portability — receive your data in a structured format (Art. 20)
- Right to object — oppose processing based on legitimate interest (Art. 21)
- Right to restriction — request limitation of processing (Art. 18)
- Right to withdraw consent — at any time, without affecting prior processing (Art. 7(3))
- Post-mortem directives — define instructions for your data after death (Loi Informatique et Libertés, Art. 85)
To exercise these rights, contact us via the Obsidian Discord server. We will respond within one month. You also have the right to lodge a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés) at www.cnil.fr.
Cookies
Obsidian uses only strictly necessary cookies required to maintain your authenticated session and store your preferences. These cookies are exempt from consent requirements under Article 82 of the French Data Protection Act and the ePrivacy Directive. No third-party tracking, advertising or analytics cookies are used.
Data Security
Your data is stored on secure, encrypted servers. We implement industry-standard security measures in accordance with Article 32 of the GDPR: encryption at rest and in transit, strict access controls, regular security audits, and incident response procedures. In the event of a data breach likely to result in a high risk to your rights, we will notify you without undue delay in accordance with Article 34 of the GDPR.
Minors
The Services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from minors. If we become aware that data has been collected from a minor without parental consent, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be published on this page with a revised date and announced on the Obsidian Discord server. Material changes affecting your rights will be notified at least 30 days in advance.
GDPR-compliant. Your data belongs to you.