Appearance and language
This page explains which data is processed on MFmWebSite, why, under which legal basis and for how long — including forum, courses, news, games, support and professional services modules.
Last updated: June 23, 2026
This policy applies to processing carried out via MFmWebSite (the site you are currently on), its subdomains, related applications (e.g. MFmGames / CheeseCards) and APIs. It covers public browsing, accounts, published content (reviews, courses, comments, forum messages, tickets, notes), contact and pre-quote forms, the support page, and technical processing required for security and operation.
SaaS products, applications and sites published by the editor and linked to MFmWebSite (e.g. MFmTools, MFmGames, CheeseCards), when accessed through a verified link (shared account, SSO, subdomain or explicit referral from this site), are covered by this policy by default, unless the relevant service states otherwise.
The data controller is Marvin Forget-Mandras. Processing is carried out to provide requested features, manage accounts, secure the platform, and handle support requests.
Depending on context, legal bases include service performance, legitimate interest (security, abuse prevention, improvement), legal obligations, and consent where required.
Data is kept for a period proportionate to each purpose. Account data and related content are generally retained while the account is active, then handled under the applicable deletion/termination process.
Technical data: login logs ~1 month (IP included), 2FA trusted IP ~30 days, ip-api.com cache 24 h (language) / 30 days (history). Registration/email tokens: 24 h. Pre-quotes: commercial and legal retention.
Data is never sold. Access limited to administration and moderation. Technical providers possible (hosting, email). Third parties by feature: Ko-fi, Google Maps (after consent), RSS feeds, Open-Meteo / French public services (Actu France), ip-api.com (IP only — language if enabled, history location). MFmGames/CheeseCards: own policy. Sensitive data encrypted or hashed.
Some third-party providers (Google) may transfer data outside the EU under appropriate legal safeguards (Data Privacy Framework).
With no saved preference, the site determines the interface language in the order below and stores the result (session and `language` cookie, 1 year):
Change anytime via the language selector. Legal basis: legitimate interest.
Your IP (and sometimes User-Agent) is logged at sign-in for account security and abuse prevention.
Indicative retention: ~1 month (logs), ~30 days (2FA trusted IP).
To show approximate location in login history, the IP may be sent to ip-api.com (30-day server cache).
Data is not sold. IP logging remains necessary for authentication.
Under GDPR and applicable data protection laws, you may exercise the following rights within legal limits:
The following actions are available directly from this page or your security settings:
HttpOnly cookies (e.g. login session, CSRF) cannot be read or removed from the browser. Sign out to invalidate the session.
Cookies and Symfony session (auth, CSRF, flows). Preferences: language (`language`, see dedicated section), RSS feeds (`actu_feed_lang`), Actu France (`actu_france_location`, 1 year). localStorage: language, theme, Maps consent, local quote draft.
Third-party RSS feeds (links to sources). Actu France: Open-Meteo, data.economie.gouv.fr, geo.api.gouv.fr. Google Maps after consent. Donations via Ko-fi. CheeseCards/MFmGames: SSO, own terms. ip-api.com may receive your IP (language if enabled, history location) — ip-api.com legal notices.
For any data protection question or to exercise your rights, you can open a private ticket (logged-in account) or a public ticket (no login) on the tickets page, which also displays a contact e-mail, or write to us directly at support@marvinfm.fr. Identity verification may be requested before handling a request involving personal data.
This policy may evolve with technical, functional, or legal changes. The version in force is the one published on this page with its update date.