Who processes your data?
STELLARR STUDIO, 163 rue du Canal, 27500 Pont-Audemer, France, is responsible for the processing described here. Contact us at contact@stellarrstudio.com. The company’s and OVHcloud’s contact details appear in the legal notice.
When you contact us
The form sends your enquiry to the site’s server, which routes it by email to contact@stellarrstudio.com. It collects your name, email address, company if provided, subject and message. Required fields are identified; without them we cannot send and process your enquiry.
This information helps us understand your needs, assess your project and reply. Sending an enquiry does not subscribe you to a marketing list. Avoid including passwords, sensitive data or confidential documents: an initial discussion is enough to define an appropriate channel if your project requires one.
Why this information is used
When you request a quote or preliminary assessment, necessary information is processed to take the pre-contractual steps you request. For general questions, processing relies on our legitimate interest in responding to enquiries. Preventing abusive submissions reflects our legitimate interest in protecting the form. Information is not reused to profile you or make an automated decision about you.
Who receives your enquiry?
Studio staff responsible for your enquiry can access the exchanges. OVHcloud hosts the pages and receiving server. Brevo, a Sendinblue service, provides email delivery through its SMTP relay: your enquiry and the addresses needed for delivery are transmitted to it. The studio’s inbox then retains the email.
The relay is described in Brevo’s SMTP documentation. Conditions applying to the provider, subprocessors and any transfers are described in its terms of service and privacy policy.
Protecting the form
The ALTCHA bot check is hosted with the site. It performs a calculation in your browser and has our server verify the result, without sending your message to an external CAPTCHA service. This integration does not set a tracking cookie.
To limit abuse, the server temporarily uses a protected fingerprint of the IP address to count requests over a fifteen-minute window. Raw IP addresses are not retained in these counters. Challenges expire after ten minutes. Request fingerprints and technical identifiers help limit duplicates for twenty-four hours; they do not contain message text. Expired entries are removed from memory during subsequent requests or periodic cleanup every minute.
The server does not create a contact database or write messages into application logs. Those logs contain a technical identifier and processing status. Infrastructure and email logs are also governed by hosting and provider settings.
For how long?
General enquiries are retained for the time needed to resolve them. For a project enquiry that does not lead to a contract, our reference period is a maximum of three years from your last contact, with earlier review if exchanges are no longer useful. If a contract is concluded, necessary information joins the customer file and follows the periods applicable to its management and legal obligations.
This reference period guides inbox review. The site does not automatically delete received emails or delivery-provider logs. It follows the CNIL’s three-year reference for prospects; that reference does not require every message to be kept for three years.
Your rights
You can request access, correction or erasure of your data, and restriction of processing. Depending on the circumstances, you can also object to processing based on legitimate interest or request portability of relevant data. Email contact@stellarrstudio.com, specifying your request and the address you used to contact us. Additional verification is requested only if there is reasonable doubt about your identity.
You can read the CNIL’s information about your rights and complain to it if you believe your data is not processed under the applicable rules.
Your Stellarr account
ALTCHA also protects sign-up, sign-in, password-reset requests and confirmation-link resends. The calculation runs in your browser without an external CAPTCHA service or advertising cookie. A protected IP fingerprint binds each challenge to the request: it expires after ten minutes and can be used once. Associated counters cover fifteen minutes; expired entries are removed during new requests or hourly cleanup.
Creating an account requires a public name, email address and password. The password is stored in a derived, hashed form and is never shown to the studio. Address verification, sessions, account settings and deletion requests provide and secure the service you request. Registration does not subscribe you to commercial communications.
Confirmation links expire after one hour and reset links after thirty minutes. A session lasts up to seven days before expiry or renewal through account use. The browser type associated with a session helps you recognise your connections. You can revoke sessions, export information and request deletion from your account.
Email confirmations, reset links and password-change alerts are service messages necessary for account management and security. Brevo’s SMTP relay delivers them using your address and the service message’s content. They do not subscribe you to a newsletter. No password is included in these emails.
To protect sign-in against abusive attempts, authentication counters temporarily use the IP address and action type. These entries are deleted after two days during hourly cleanup. Other application quotas use protected fingerprints. Expired sessions and invalid links are also removed.
Your profile and photo
You can add a public handle, short biography, website link and photo. These are optional. Profile visibility is off by default: your biography, link and photo are not shown to other readers until you enable visibility. Your public name remains associated with contributions even when your profile is private. Timezone and display preferences adapt your account area.
Your photo is uploaded to the studio server and re-encoded as WebP for display; source-file metadata is not copied into this version. No third-party photography or avatar service is called. Removing the photo or making the profile private closes access to other visitors. Old photos unused for more than a day are cleaned up during a new upload or profile update; this does not instantly delete every copy.
Your community contributions
Topics, replies, public name, contribution dates and reputation are visible to forum readers. Level and rank are calculated from reputation and are not a certification. Choose a pseudonym if you do not want to display your identity. Do not publish sensitive data, secrets or information about others without an appropriate reason.
The NodeBB forum engine is hosted as a studio service. It receives a technical identifier, your public name and actions needed for discussion; the sign-in bridge does not transmit your Stellarr password or email address. Reports and moderation decisions are accessible to authorised people to protect discussions. Initial publications may require approval.
Forum images and videos
Uploaded files are stored on the studio server with a technical identifier, your account identifier, format, dimensions, size and upload date. Video duration is also recorded. The displayed filename is normalised. Images and videos are re-encoded for display and their original metadata is not copied; this does not obscure faces, voices, text or other information visible in the content.
Before publication, media can be accessed by its owner and administrators. When attached to an authorised post, that post’s readers can view it. Content awaiting moderation stays private. Hiding media or removing its reference from a post closes the corresponding public access; the team retains access needed to investigate a report. Recipients may nevertheless keep copies outside the site.
Unattached media can be deleted from your media area. Media without links is also deleted from thirty days onward during automatic maintenance in bounded batches; service interruptions or a backlog may delay cleanup. Files attached to a publication or post awaiting moderation are preserved for reading and moderation follow-up. Ask the studio to remove them if needed.
Hiding content is not physical erasure, and an account-related request should also identify the relevant publications or media. Technical orphan files no longer corresponding to a registered media item may be removed after twenty-four hours during the same maintenance. Backups and operational logs follow their own retention cycles and are not instantly erased by an interface action.
Marketplace resources
An order retains the resource, price, accepted licence, date, payment status and technical references needed to make it available. File access is tied to your account. When payments are open, Stripe processes them on its dedicated page: Stellarr Studio does not receive your full card number or security code. Read Stripe’s privacy policy for the provider’s processing.
Account and contribution data remain stored to provide the service. Orders and supporting records also follow contractual and accounting obligations and dispute handling requirements. Deletion requests trigger human review: they do not automatically erase purchases or public contributions. The studio explains which elements are deleted, anonymised or retained and why. Inactive-account policy must preserve access rights to acquired content, following the CNIL’s recommendations.
Authorised studio staff access information necessary for support, sales and moderation. Logs of administrative actions, publication and resource access are kept for one hundred and eighty days before hourly cleanup. Account and order processing provides the requested service; abuse prevention and moderation rely on the legitimate interest in protecting it.
Browsing, search and demonstrations
The site includes no advertising tool. Internal counters add views by page and day for ninety days, without a visitor identifier or individual journey. Logos, fonts, scripts and the three demonstration videos are served from the same hosting as the pages.
General search uses a local index in your browser. Blog and forum searches query the server to find published content. Their terms are added neither to site-traffic counters nor to the community engine’s search statistics. Infrastructure logs may nevertheless contain requested addresses. Interactive demonstrations are illustrative and do not access your documents or systems.
Local videos are silent and loop while visible. You can pause them. A reduced-motion preference keeps playback manual.
Your YouTube and Google Maps choices
These services are disabled by default. Each integration requires your consent and a click on the content. Loading sends Google technical information, including your IP address. Your choice is stored in the browser for six months and can be withdrawn using “Manage my preferences” in the footer. Read the service and storage details.
Links to Moon AI, Google Maps, LinkedIn and the press open websites with their own policies. Withdrawing consent on Stellarr Studio does not delete data already transmitted to those services.
