Accommodation & infrastructure
This page describes, in addition to the legal information (Art. 6-III LCEN) and the privacy policy (Arts. 28 and 32 GDPR), the technical infrastructure on which the test.gode.fr site is based and the security measures implemented.
Article 1 — Host and location
Association E-Cosplay, via its service ENUM — Association loi 1901, 42 rue de Saint-Quentin, 02800 Beautor. SIREN : 943 121 517 · RNA : W022006988 · APE/NAF code : 93.29Z — Contact : [email protected].
Servers rented from OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France (RCS Lille Métropole 424 761-419), located in France.
The site, its API and all the data it processes (customers accounts, orders, guarantee requests, messages) are hosted exclusively in France, in data centres located on the territory of the European Union and submitted to the GDPR. No data are stored outside the European Union.
Article 2 — Trade security
All exchanges are encrypted in HTTPS (TLS 1.2 minimum, TLS 1.3 preferred); the unencrypted connection is redirected and the HSTS (HTTP Strict Transport Security) policy requires browser encryption for any subsequent visit.
Deployed security headers: Content-Security-Policy, X-Content-Type-Options (anti-sniffing), Referrer-Policy, X-Frame-Options and frame-ancestors (protection against click hijacking), Permissions-Policy.
Session cookies are signed (HMAC), marked HttpOnly, Secure and SameSite; Accounts receivable passwords are stored in minced and salty form; the administration space is isolated on a separate path, protected by a short session (12 hours) and a strictly limited cookie. Prices and totals are recalculated on the server side of each order, the forms and API are limited in frequency (abuse protection), and the order, account and administration pages are excluded from indexing and cacheting.
Article 3 — Availability and safeguards
The application is containerized and supervised; services are restarted automatically in case of an incident. The data (orders, accounts, warranties, PDF documents) are subject to regular backups, encrypted and stored on a separate medium located in France, with retention allowing restoration in the event of a disaster. Software components are kept up to date and access logs are kept for 12 months for security purposes.
Article 4 — Payment
Card payments are processed by Systempay, payment solution of Lyra Network SAS (approved payment service provider, certified PCI-DSS level 1), on behalf of Banque Populaire, SAS bank Godé. Card data is entered exclusively on the payment page hosted by Lyra; no card data is transmitted or stored on our servers. Transactions are subject to strong 3-D Secure authentication (DSP2) and the result of the payment is transmitted to our server by signed notification (IPN), verified before any order confirmation.
Article 5 — Subcontractors and technical providers
Association E-Cosplay, via its ENUM service – design, hosting, operation and maintenance of the site (France).
OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix — Rental of servers and data centres (France).
Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg — delivery of transactional emails via Amazon SES, Europe region (Paris, eu-west-3). Only e-mails (address of recipient and content of message) pass through this service; no data is retained by AWS beyond routing and technical logs.
Lyra Network SAS, 109 rue de l'Innovation, 31670 Labège — payment platform Systempay (France).
La Poste SA — service Colissimo, 9 rue du Colonel Pierre Avia, 75015 Paris — parcel delivery, label generation and tracking (France and European Union).
E-Cosplay e-sign (E-Cosplay (ENUM)) — electronic signature, time stamping and audit journal of guarantee certificates (hosted in France).
Each subcontractor shall be bound by a contract in accordance with Article 28 GDPR and shall provide sufficient guarantees for the implementation of appropriate technical and organisational measures.
Article 6 — Transfers outside the European Union
No data transfer outside the European Union is carried out in the current operation of the site. Providers established in the Union shall be subject to the GDPR; If one of them were to use a subsequent subcontractor located in a third country, the transfer would be governed by an adequacy decision or the European Commission's standard contractual clauses (Articles 44 to 46 GDPR).
Article 7 — Incident management and reporting of violations
SAS Godé and its subcontractors have implemented a procedure for the detection, qualification and treatment of security incidents. In the event of a breach of personal data, SAS Godé shall notify the CNIL within 72 hours of its becoming aware, where it is likely to create a risk to the rights and freedoms of persons (Art. 33 GDPR), and shall inform the persons concerned as soon as possible when this risk is high (Art. 34 GDPR). A register of violations shall be kept in accordance with Article 33.5.
Article 8 — Reporting of vulnerability
Anyone who finds a security breach on the site is invited to report it responsibly to [email protected] or [email protected], without exploiting it or disclosing data. Pursuant to article L2321-4 of the Defence Code, such a bona fide approach may be addressed to ANSSI. Technical contact: [email protected].