Skip to content
๐Ÿ›ก๏ธ Tabletop Cyber
๐ŸŒ ThreatsLogin

Privacy Policy

Last updated: July 31, 2026
GDPR / LOPDGDD: This policy complies with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD).
1. Data Controller2. Data3. Purpose4. Legal Basis5. Retention6. Recipients7. Stripe8. AI Processing9. Cookies10. Rights11. Minors12. Changes

1. Data Controller

  • Controller: [Owner name / company]
  • Platform: Tabletop Cyber
  • Contact: contacto@tabletopcyber.es
Pending: Upon company incorporation, CIF, registered address and phone will be updated.

2. Personal data we collect

Registration data

DataRequiredPurpose
NameRequiredIdentification
EmailRequiredAuthentication, notifications
Password (hash)RequiredAuthentication (encrypted)
Organization nameOptionalCustom management

Activity data

DataPurpose
Simulation resultsStatistics, progress, history
In-game decisionsEvaluate responses and scoring
Session date/timeHistory and streak

Payment data (Stripe)

We do not store card data. Processed by Stripe as data processor.

3. Purpose of processing

  • Manage account and authentication
  • Provide access to the Platform
  • Store and display results and progress
  • Manage subscriptions and payments (via Stripe)
  • Send service notifications (verification, recovery, alerts)
  • Fulfill legal and tax obligations
No: We do not use your data for advertising, commercial profiling, nor do we sell it to third parties.

4. Legal basis

  • Contract performance (Art. 6.1.b GDPR): Provide the service
  • Consent (Art. 6.1.a GDPR): Notification emails
  • Legal obligation (Art. 6.1.c GDPR): Tax requirements
  • Legitimate interest (Art. 6.1.f GDPR): Security and fraud prevention

5. Data retention

TypePeriod
Active accountWhile active
Activity/simulationsActive + 90 days after cancellation
Payment data (invoices)6 years (tax obligation)
Verification codes15 min after expiry
Security logs90 days

6. Data recipients

ProviderServiceDataLocation
StripePaymentsEmail, payment dataEU/EEA
ResendEmailEmail, nameUSA
Ollama Inc.AI inferenceScenario responses, game contextUSA
HetznerHostingAll (hosted)Germany (EU)
International transfers: Resend and Ollama operate from the USA. Data sent is limited to simulation content (no sensitive personal data). Ollama processes prompts transiently and does not store them or use them for model training. Stripe operates in the EEA.

We do not transfer data to third parties for commercial purposes.

7. Stripe payment processing

  • Stripe stores and processes payment data (card)
  • We only receive subscription status
  • Never do we store card numbers
  • Stripe privacy policy: stripe.com/privacy

8. AI processing and international transfers

How do we use AI?

Tabletop Cyber uses artificial intelligence models to generate dynamic scenarios, evaluate responses, and provide feedback. The responses you write during simulations are sent to AI inference providers for processing.

We currently use Ollama Inc. (USA) as our cloud inference provider. Ollama processes prompts transiently, it does not store them beyond the time needed to generate a response, nor does it use them for model training.

What data is sent

  • The text of your responses to scenarios (simulation content)
  • Game context (scenario, phase, instructions)
  • Technical metadata required for inference (does not include personal registration data)

What data is NOT sent to AI

  • Your name, email or registration data (processed on our servers in Germany, EU)
  • Payment data (processed by Stripe)
  • Sensitive personal data (health, religion, etc., Art. 9 GDPR)
Recommendation: Do not include personal data (real names, emails, company or client data) in your scenario responses. Simulations are designed to practice technical decisions, not to enter personal information.

Legal basis and safeguards

Data transfer to Ollama is carried out under Article 49 of the GDPR (adequate safeguards for international transfers). Ollama declares that it does not use the data for model training and processes it transiently.

If you wish, you can request that your simulations be processed only with local models on servers within the EU, without international transfer. Contact contacto@tabletopcyber.es to enable this option.

9. Cookies

CookiePurposeDurationType
Flask SessionAuthenticationSessionEssential
UI PreferencesInterface30 daysEssential
We do not use: Tracking, advertising, or third-party cookies (Google Analytics, Facebook Pixel, etc.).

10. Your rights (GDPR / LOPDGDD)

๐Ÿ“‹ Access
Request a copy of your data
โœ๏ธ Rectification
Correct inaccurate data
๐Ÿ—‘๏ธ Suppression
Delete your data
โš–๏ธ Limitation
Restrict processing
๐Ÿ“ค Portability
Receive data in structured format
๐Ÿšซ Objection
Object to processing

To exercise them: email admin@tabletopcyber.local

Deadline: Response within 1 month (extendable to 3 in complex cases, Art. 12.3 GDPR).

Complaints to the AEPD - www.aepd.es

11. Protection of minors

  • Minimum age: 16 years (14 with authorization for educational purposes)
  • Minors must register with authorization from parents or guardians.
  • If we detect a minor without authorization, we delete their data

12. Changes

We may update this policy when necessary. Substantial changes will be notified by email 30 days in advance. Continued use implies acceptance.

Questions? admin@tabletopcyber.local

Legal Notice ยท Privacy ยท Terms

ยฉ 2026 Tabletop Cyber (Selfa). All rights reserved.