GDPR policy

Definitions

The publisher: the individual or legal entity that publishes online services intended for the general public: Patricia Biron
The website: all websites, web pages and online services provided by the publisher: www.chandima.org
The user: the person using the website and the services: You

Nature of the data collected

In connection with the use of the website, the publisher may collect the following categories of data relating to its users: – Personal details, identity and identification data, etc.: when completing the contact form

Data aggregation

Aggregation using non-personal data

We may publish, disclose and use aggregated information (information relating to all our users or to specific groups or categories of Users, which we combine in such a way that an individual user can no longer be identified or singled out) and non-personal information for the purposes of industry and market analysis, demographic profiling, promotional and advertising purposes, and other commercial purposes.

Cookies

Cookie retention period

In accordance with the CNIL’s recommendations, the maximum retention period for cookies is 13 months from the date they are first placed on the user’s device; this is also the period for which the user’s consent to the use of these cookies remains valid. The lifespan of cookies is not extended with each visit. The user’s consent must therefore be renewed at the end of this period.

Purpose of cookies

Cookies may be used for statistical purposes, in particular to optimise the services provided to users, by processing information relating to the frequency of visits, the personalisation of pages, as well as the actions carried out and the information viewed.

Please be aware that the publisher may place cookies on your device. Cookies store information relating to your browsing activity on the service (the pages you have visited, the date and time of your visit, etc.), which we may access during your subsequent visits.

Retention of technical data

Retention period for technical data

Technical data is retained for the period strictly necessary to fulfil the purposes set out above.

Retention period for personal data and anonymisation

Manual deletion of data

Data erasure procedures are in place to ensure that data is effectively deleted once the retention or archiving period required to fulfil the specified or mandated purposes has elapsed. In accordance with Law No. 78-17 of 6 January 1978 on data processing, files and civil liberties, you also have the right to have your data deleted, which you may exercise at any time by contacting the publisher.

Guidance in the event of a security vulnerability detected by the publisher

Notification to users in the event of a security breach

We are committed to implementing all appropriate technical and organisational measures to ensure a level of security appropriate to the risks of accidental, unauthorised or unlawful access to, disclosure, alteration, loss or destruction of your personal data. In the event that we become aware of any unlawful access to your personal data stored on our servers or those of our service providers, or of any unauthorised access resulting in the materialisation of the risks identified above, we undertake to:

  • Report the incident to you as soon as possible;
  • To investigate the causes of the incident and inform you of them;
  • Take the necessary measures, within reason, to minimise the negative effects and harm that may result from the incident in question.

Limitation of liability

Under no circumstances shall the obligations set out in the paragraph above regarding notification in the event of a security breach be construed as any admission of fault or liability in relation to the occurrence of the incident in question.

Amendment to the GDPR policy

In the event of any changes to this GDPR policy, the publisher undertakes not to substantially lower the level of privacy without first informing the data subjects.