General Provisions
Preamble
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on data protection (hereinafter the GDPR) sets out the legal framework applicable to the processing of personal data. This legislation strengthens the rights and obligations of data controllers, data processors, data subjects and recipients of data.
Subsequently, and to implement the amendments to the GDPR, Law No. 78-17 of 6 January 1978, known as the Data Protection Act, was amended by Law No. 2018-493 of 20 June 2018 and by Order No. 2018-1125 of 12 December 2018 on data protection.
This policy is implemented by the Lozère Departmental Tourism Committee (hereinafter referred to as ‘the organisation’), whose main activities are the development of tourism provision, the promotion of tourist destinations and the marketing of tourism provision in the department of Lozère.
As part of our activities, we process personal data relating to our customers, partners and prospective clients. To ensure a clear understanding of this policy, it is specified that:
- ‘Clients’ refers to any natural or legal person who has entered into a contract of any kind with our organisation, it being understood that the organisation is intended to work with clients in the tourism sector or the general public;
- ‘Partners’ refers to any natural or legal persons operating in the tourism sector and, in that capacity, maintaining relations with our organisation, such as, in particular, tourism professionals in the department, project leaders and internal and external investors, holiday package providers, local authorities and their associations, and institutional partners
- Prospects are defined as any potential customer or contact who receives promotional messages from our organisation and whose data has been collected either directly via contact forms or at events, or indirectly via any of the organisation’s partners.
Purpose and scope
This personal data protection policy is intended to apply in the context of the processing of personal data relating to our customers, partners and prospective customers.
As such, the purpose of this policy is to fulfil our organisation’s duty to provide information and thereby to set out the rights and obligations of customers, partners and prospective customers with regard to the processing of their data.
This policy relates only to processing operations for which we are responsible, as well as to data classified as ‘structured’.
The processing of personal data may be carried out directly by our organisation or through a data processor specifically appointed by it.
This policy is separate from any other document that may apply within the contractual relationship between us and our customers, partners and prospects. We do not carry out any processing of our clients’, partners’ and prospects’ data unless it relates to personal data collected by or on behalf of our organisation, or processed in connection with our services, and unless it complies with the general principles of the GDPR.
Any new processing operation, or any amendment to or deletion of an existing processing operation, will be brought to the attention of clients, partners and prospects by means of an amendment to this policy.
Customer data
Types of data collected
Non-technical data (depending on the use case)
- identity and identification (surname, first name, date of birth, username, customer number)
- contact details (email, postal address, telephone number)
- work-life balance, where necessary
Technical specifications (depending on the application)
- identification data (IP address)
- login details (including logs and tokens)
- acceptance data (click)
- location data
Source of the data
We collect data from our customers via:
- data provided by the customer (paper form, purchase order, contract, business card);
- electronic forms or documents completed by the customer;
- data entered online (website, social media, etc.);
- registration for events that we organise;
- databases shared amongst several partners, which are populated and utilised by all of these partners;
- the rental or purchase of databases on an exceptional basis;
- provision of contact details through specialist companies or our organisation’s partners.
Aims
Depending on the circumstances, we process our customers’ data for the following purposes:
- customer relationship management;
- the sale of holiday packages, either directly or through distribution partners;
- management of the events we organise;
- sending newsletters or news feeds;
- management of customer accounts;
- improving our services;
- compliance with our administrative obligations;
- community management;
- compilation of statistics.
Retention periods
The retention period for our customers’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our own requirements, and in particular in accordance with the following principles:
Customer data: For the duration of the contractual relationship, plus a further 3 years for customer engagement and marketing purposes, without prejudice to any retention obligations or limitation periods.
Technical data: 1 year from the date of collection.
Cookies: See the cookie policy.
Once the specified periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Customers are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
The processing operations we carry out under this policy are all legally based on the implementation of contractual or pre-contractual measures or, in certain cases, the customer’s consent (e.g. sending marketing messages).
Data from partners
Types of data collected
Non-technical data (depending on the use case):
- identity and identification (surname, first name, date of birth, username)
- contact details (email, postal address, telephone number)
- professional background (role, job title, etc.)
Technical specifications (depending on the application):
- identification data (IP address)
- login details (including logs and tokens)
- acceptance data (click)
- location data
Source of the data
We collect data from our partners via:
- information gathered directly from partners, in particular via shared databases;
- electronic forms or records completed by the partners;
- registrations or subscriptions to our online services (newsletter, social media).
Aims
Depending on the circumstances, we process our customers’ data for the following purposes:
- partner relationship management;
- the certification of sites and facilities for the sectors entrusted to the organisation;
- tourism engineering projects (assessments and feasibility studies, support with project development and grant applications);
- networking and consultation activities involving the various partners;
- initiatives to support partner service providers in bringing their services to market;
- management of the events we organise (trade fairs, workshops, etc.);
- training programmes for partner service providers;
- searches for distribution partners;
- compilation of statistics.
Retention periods
The retention period for our partners’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our needs and, in particular, in line with the following principles:
Customer data: For the duration of the contractual relationship, plus a further 3 years for the purposes of monitoring the relationship, without prejudice to any retention obligations or limitation periods.
Technical data: 1 year from the date of collection.
Cookies: See the cookies policy.
Once the specified periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Partners are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
The processing operations we carry out under this policy are all legally based on the implementation of contractual or pre-contractual measures.
Prospect data
Types of data collected
Non-technical data (depending on the use case):
- identity and identification (surname, first name, date of birth, username)
- contact details (email, postal address, telephone number)
- professional background (role, job title, etc.)
Technical specifications (depending on the application):
- identification data (IP address)
- login details (including logs and tokens)
- acceptance data (click)
- location data
Source of the data
We collect data on our prospective customers from:
- information provided by the prospective customer (paper form, business card, etc.);
- electronic forms or documents completed by the prospective customer;
- data entered online (website, social media, etc.);
- registration or subscription to our online services (website, social media);
- registration for events that we organise;
- databases shared amongst several partners, which are populated and utilised by all of these partners;
- a list provided by the organisers of events or conferences in which we take part;
- database rental on an exceptional basis;
- provision of contact details through specialist firms or partners.
Aims
Depending on the circumstances, we process our prospective customers’ data for the following purposes:
- prospect relationship management;
- management of the events we organise;
- sending out our newsletters or news feeds;
- website management in collaboration with our partners;
- a campaign to promote our organisation and tourism in the Lozère department on social media (Facebook, Twitter, YouTube, Instagram, etc.);
- behavioural analysis of prospective customers;
- community management;
- compilation of statistics.
Retention periods
The retention period for our prospective customers’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our needs and, in particular, in line with the following principles:
Customer data: For 3 years from the date of collection or the last contact initiated by the prospective customer.
Technical data: 1 year from the date of collection.
Cookies: See the cookies policy.
Once the specified retention periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Prospects are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
The purposes of processing prospective customers’ personal data set out above are based on the following grounds for lawfulness:
- the performance of pre-contractual measures;
- our organisation’s legitimate interest;
- the prospect’s consent where required by law (for example, when sending commercial marketing messages).
Recipients of the data
We ensure that data is only accessible to authorised internal or external recipients who are subject to an appropriate duty of confidentiality.
Internally, we determine which recipients may access which data in accordance with an authorisation policy.
All access relating to the processing of personal data of customers, partners and prospective customers is subject to traceability measures.
Furthermore, personal data may be disclosed to any authority legally authorised to receive it. In such cases, we are not responsible for the conditions under which the staff of those authorities access and process the data.
Internal recipients
Authorised staff within our organisation (staff responsible for marketing, customer relationship management, service providers and prospective clients, administrative staff, and IT staff) and their line managers.
External recipients
- Tourism partners who access the shared database in which the data may be contained;
- service providers or support services;
- authorised staff of the departments responsible for auditing (statutory auditors, departments responsible for internal audit procedures, etc.);
- the administration, or a court officer where applicable.
Human rights
Right of access and right to a copy
Customers, partners and prospective clients traditionally have the right to request confirmation as to whether or not data concerning them is being processed.
They also have the right to access their data, that is, the right to obtain a copy of all information relating to the processing of their personal data.
In such cases, the customer, partner or prospective customer must make the request themselves and there must be no doubt as to their identity. Failing this, we reserve the right to request any information necessary to verify their identity, such as a copy of an identity document.
Customers, partners and prospective clients have the right to request a copy of their personal data that is being processed. However, in the event of a request for an additional copy, we may require customers, partners and prospects to bear the cost of this.
If customers, partners and prospects submit their request for a copy of the data electronically, the information requested will be provided to them in a commonly used electronic format, unless otherwise requested.
Customers, partners and prospects are informed that this right of access does not apply to confidential information or data, or to information or data which the law does not permit to be disclosed.
The right of access must not be exercised abusively, that is to say, carried out on a regular basis for the sole purpose of disrupting the service concerned.
Update – revision and correction
We comply with requests for updates:
automatically for online changes to fields that can be updated for technical or legal reasons;
or upon written request from the individual concerned, who must provide proof of their identity.
Right to erasure
The right to erasure for customers, partners and prospective customers shall not apply in cases where the processing is carried out to comply with a legal obligation. Apart from this situation, customers, partners and prospective customers may request the erasure of their data in the following limited circumstances:
personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
where the data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing;
the data subject objects to processing necessary for the purposes of the legitimate interests we pursue and there is no overriding legitimate ground for the processing;
the data subject objects to the processing of their personal data for marketing purposes, including profiling;
the personal data has been processed unlawfully.
Right to restriction
Customers, partners and prospective clients are informed that this right does not apply insofar as the processing operations we carry out are lawful and all personal data collected is necessary for the purposes of such processing.
Right to data portability
We comply with requests for data portability in the specific case of data provided by customers, partners and prospective customers themselves via our online services, and for purposes based solely on the consent of the individuals concerned and the performance of a contract. In such cases, the data is provided to the requester in a structured, commonly used and machine-readable format.
Automated individual decision-making
We do not carry out any automated individual decision-making.
The tools available on our website are intended solely as aids for customers and prospective customers and should not be regarded as anything else.
Post-mortem law
Customers, partners and prospective clients are informed that they have the right to issue instructions regarding the retention, erasure and disclosure of their data after their death.
Exercising rights
The above rights may be exercised, at the data subject’s discretion, by email or by post using the following contact details: [email protected].
Supplementary provisions
Whether answers are optional or compulsory
Customers, partners and prospective clients are informed whether responses are mandatory or optional by the presence of an asterisk on each form used to collect personal data submitted to them. Where responses are mandatory, we explain to them the consequences of failing to provide a response.
Right of use
Our organisation is granted by its customers, prospective customers and partners the right to use and process their personal data for the purposes set out above.
However, the enriched data resulting from our processing and analysis, otherwise known as ‘enriched data’, remains our exclusive property (usage analysis, statistics, etc.).
Subcontracting
We would like to inform you that we may engage any data processor of our choice in connection with the processing of your personal data. In such cases, we ensure that the data processor complies with its obligations under the GDPR.
We undertake to enter into a written contract with all our data processors and to impose on them the same data protection obligations as we ourselves are subject to. Furthermore, we reserve the right to carry out audits of our data processors to ensure compliance with the provisions of the GDPR.
Cross-border flows
Our organisation reserves the sole right to decide whether or not to carry out cross-border transfers of the personal data it processes.
In the event of a transfer of personal data to a country outside the European Union or to an international organisation, we will inform you and ensure that your rights are fully respected. We undertake, where necessary, to enter into one or more contracts to provide a legal framework for cross-border data transfers.
The provisions relating to cross-border data transfers are binding on us, except in the cases of derogation provided for in Article 49 of the GDPR.
Record of processing activities
As the data controller, we undertake to maintain a record of all processing activities carried out.
This record is a document or application used to list all the processing operations we carry out in our capacity as data controller.
We undertake to provide the supervisory authority, upon first request, with the information necessary to enable that authority to verify that our processing operations comply with the data protection legislation in force.
Safety
Security measures
It is our responsibility to define and implement the technical security measures – whether physical or logical – that we deem appropriate to prevent the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of data.
To this end, we may engage any third party of our choice to carry out, as frequently as we deem necessary, vulnerability audits or penetration tests.
In any event, we undertake, in the event of any change to the measures designed to ensure the security and confidentiality of personal data, to replace them with measures offering a higher level of performance. No such change shall result in a reduction in the level of security.
Where we subcontract all or part of the processing of personal data, we undertake to contractually require our data processors to provide security guarantees through technical measures to protect such data and by deploying appropriate human resources.
Data breach
In the event of a personal data breach, we undertake to notify the CNIL in accordance with the conditions set out in the GDPR.
If such a breach poses a high risk to customers, partners and prospects, and the data has not been adequately protected, we will notify the individuals concerned and provide them with the necessary information and recommendations.
Contacts
Data Protection Officer
We have appointed a Data Protection Officer, whose contact details are as follows: Mr Eric Barby, Racine law firm, 40 rue de Courcelles, 75008 Paris, [email protected].
In the event of any new processing of personal data, we will consult the Data Protection Officer in advance.
If you wish to obtain specific information or ask a specific question, you may contact the Data Protection Officer, who will provide a response within a reasonable timeframe, taking into account the nature of the question or the information requested.
Should you encounter any issues regarding the processing of your personal data, you may contact the designated Data Protection Officer.
Right to lodge a complaint with the CNIL
Customers, partners and prospective customers whose personal data is being processed are informed of their right to lodge a complaint with a supervisory authority, namely the CNIL, if they consider that the processing of their personal data does not comply with European data protection regulations, at the following address:
CNIL – Complaints
Department, 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07
. Tel: 01 53 73 22 22
Development
This policy may be amended or modified at any time in the event of changes to legislation, case law, decisions and recommendations of the CNIL, or industry practice.
Any new version of this policy will be brought to the attention of customers, prospective customers and partners by any means we may determine, including by electronic means (for example, by email or online).
For further information
For any further information, please contact the DPO at the address given above, namely [email protected].
For any other general information on the protection of personal data, please visit the CNIL website: www.cnil.fr.