1. General provisions
Preamble
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on data protection (hereinafter the GDPR) establishes the legal framework applicable to the processing of personal data. This text strengthens the rights and obligations of data controllers, data processors, data subjects and recipients of data.
Subsequently, and in order to implement the amendments to the GDPR, the French Data Protection Act No. 78-17 of 6 January 1978 was amended by Act No. 2018-493 of 20 June 2018 and by Order No. 2018-1125 of 12 December 2018 relating to data protection.
This policy is implemented by the Lourdes Tourist Office (hereinafter referred to as ‘the organisation’), whose main activities are the development of tourism provision, the promotion of tourist destinations and the marketing of tourism provision in Occitanie.
As part of our activities, we process personal data relating to our customers, partners and prospective customers. To ensure a clear understanding of this policy, it is specified that:
‘customers’ refers to any natural or legal person bound by a contract of any kind with our organisation, it being understood that the organisation’s remit is to work with professional clients in the tourism sector or the general public;
‘partners’ are defined as any natural or legal persons operating in the tourism sector and, as such, maintaining a relationship with our organisation, including, in particular, tourism professionals in the department, project leaders and internal and external investors, holiday package distributors, local authorities and their associations, and institutional partners;
‘prospects’ are defined as any potential customer or contact who receives promotional messages from our organisation, whose data has been collected either directly via contact forms or at events, or indirectly via any of the organisation’s partners.
Purpose and scope
This personal data protection policy is intended to apply in the context of the processing of personal data relating to our customers, partners and prospects.
As such, the purpose of this policy is to fulfil our organisation’s duty to provide information and thereby to set out the rights and obligations of customers, partners and prospects with regard to the processing of their data.
This policy relates only to processing operations for which we are responsible, as well as to data classified as ‘structured’.
The processing of personal data may be carried out directly by our organisation or through a data processor specifically appointed by it.
This policy is separate from any other document that may apply within the contractual relationship between us and our clients, partners and prospective clients. We do not carry out any processing of our clients’, partners’ and prospects’ data unless it relates to personal data collected by or on behalf of our organisation, or processed in connection with our services, and unless it complies with the general principles of the GDPR.
Any new processing operation, or any amendment or deletion of an existing processing operation, will be brought to the attention of clients, partners and prospects by means of an amendment to this policy.
2. Customer data
Types of data collected
Non-technical data (depending on the use case):
identity and identification details (surname, first name, date of birth)
contact details (email, postal address, telephone number)
professional and personal life and leisure activities where necessary (e.g. family composition, means of transport, length of stay, leisure activities, etc.)
bank details (bank account details)
Technical data (depending on the use case):
identification data (IP address)
login details (logs, tokens, etc.)
Consent data (click)
location data
Source of data
We collect data from our customers via:
data provided by the customer (paper forms, purchase orders, contracts, business cards, competitions, information collected at the Office’s reception);
electronic forms or records completed by the customer;
data entered online (website, social media, etc.);
registration for events that we organise or take part in (e.g. travel fairs);
databases shared between several partners, which are updated and managed by all of these partners;
the rental or purchase of databases in exceptional circumstances;
contact details provided via specialist companies or our organisation’s partners.
Purposes
Depending on the circumstances, we process our customers’ data for the following purposes:
customer relationship management;
the sale of holiday packages, services or products, either directly or via distribution partners;
management of events that we organise or in which we participate;
marketing and sales activities;
sending newsletters or news/update feeds;
managing customer accounts;
improving our services (e.g. satisfaction surveys, tourism quality initiatives);
fulfilling our administrative obligations;
community management;
compiling statistics.
Retention periods
The retention period for our customers’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our needs and, in particular, in accordance with the following principles:
Customer data: For the duration of the contractual relationship, plus a further 3 years for customer engagement and marketing purposes, without prejudice to any retention obligations or limitation periods
Technical data: 1 year from the date of collection
Cookies: See the cookies policy
Once the specified retention periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Customers are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
All processing carried out under this policy is legally based on the implementation of contractual or pre-contractual measures.
3. Partner data
Types of data collected
Non-technical data (depending on the use case):
identity and identification (surname, first name)
contact details (email, postal address, telephone number)
professional background (role, job title, etc.)
bank details (bank account details)
Technical data (depending on the use case):
identification data (IP address)
login details (logs, tokens, etc.)
Consent data (click)
location data
Source of data
We collect data from our partners via:
information gathered directly via our partners, in particular via shared databases;
electronic forms or records completed by partners;
registrations or subscriptions to our online services (newsletters, social media).
Purposes
Depending on the circumstances, we process our customers’ data for the following purposes:
managing partner relationships;
networking and coordination activities involving the various partners;
supporting the marketing efforts of partner service providers;
managing events that we organise or in which we participate (trade fairs, workshops, etc.);
raising awareness amongst partner service providers;
activities to identify distribution partners;
compiling statistics.
Retention periods
The retention period for our partners’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our needs and, in particular, in accordance with the following principles:
Partner data: For the duration of the contractual relationship, plus a further 3 years for the purposes of monitoring the relationship, without prejudice to any retention obligations or limitation periods
Technical data: 1 year from the date of collection
Cookies: See the cookies policy
Once the specified periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Partners are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
All processing carried out under this policy is legally based on the implementation of contractual or pre-contractual measures.
4. Prospective customers’ data
Types of data collected
Non-technical data (depending on the specific use case):
identity and identification (surname, first name)
contact details (email, postal address, telephone number)
professional background (role, job title, etc.) and personal/leisure details (e.g. family composition, means of transport, length of stay, leisure activities, etc.)
Technical data (depending on the use case):
identification data (IP address)
connection data (logs, tokens, etc.)
consent data (clicks)
location data
Source of data
We collect data from our prospective customers via:
data provided by the prospective customer (paper forms, business cards, data collected by reception staff, etc.);
electronic forms or records completed by the prospective customer;
data entered online (website, social media, etc.);
registration or subscription to our online services (website, social media);
registration for events that we organise or in which we participate;
databases shared amongst several partners, which are populated and managed by all of these partners;
lists provided by the organisers of events or conferences in which we take part;
databases leased on an exceptional basis;
contact details provided via specialist companies or partners.
Purposes
Depending on the circumstances, we process our prospective customers’ data for the following purposes:
managing our relationship with prospective customers;
management of events that we organise;
sales prospecting activities;
sending our newsletters or news feeds;
managing websites in collaboration with our partners;
promoting our organisation and tourism in Occitanie on social media (Facebook, YouTube, Instagram, Twitter, etc.);
analysing the behaviour of prospective customers;
community management;
compiling statistics.
Retention periods
The retention period for our prospective customers’ data is determined in accordance with the legal and contractual obligations to which we are subject and, where these do not apply, in accordance with our needs and, in particular, in line with the following principles:
Data relating to prospective customers: For 3 years from the date of collection or the last contact initiated by the prospective customer
Technical data: 1 year from the date of collection
Cookies: See the cookies policy
Once the specified periods have elapsed, the data is either deleted or retained after being anonymised, in particular for statistical purposes. It may be retained in the event of pre-litigation or litigation.
Prospects are reminded that deletion or anonymisation are irreversible processes and that we are subsequently unable to restore the data.
Legal basis
The purposes of processing prospective customers’ data set out above are based on the following grounds for lawfulness:
the performance of pre-contractual measures;
our organisation’s legitimate interests;
the prospect’s consent where required by law (for example, in relation to the sending of commercial marketing messages).
5. Recipients of the data
We ensure that data is only accessible to authorised internal or external recipients who are subject to an appropriate duty of confidentiality.
Internally, we determine which recipients may access which data in accordance with an authorisation policy.
All access relating to the processing of personal data of customers, partners and prospective customers is subject to traceability measures.
Furthermore, personal data may be disclosed to any authority legally authorised to receive it. In such cases, we are not responsible for the conditions under which the staff of these authorities access and use the data.
Internal recipients: Authorised staff within our organisation.
External recipients:
Tourism partners who have access to the shared database in which the data may be stored;
Service providers or support departments;
Authorised staff of the departments responsible for auditing (departments responsible for internal audit procedures, etc.);
Banks;
Public authorities and court officials, where applicable.
6. Individuals’ rights
Right of access and to obtain a copy
Customers, partners and prospective customers traditionally have the right to request confirmation as to whether or not data concerning them is being processed.
They also have the right to access their data, i.e. the right to obtain a copy of all information relating to the processing of their personal data.
In such cases, the customer, partner or prospective client must make the request themselves and there must be no doubt as to their identity. Failing this, we reserve the right to request any information necessary to verify their identity, such as a copy of an identity document.
Customers, partners and prospects have the right to request a copy of their personal data that is being processed. However, in the event of a request for an additional copy, we may require customers, partners and prospects to bear the cost of this.
If customers, partners and prospective clients submit their request for a copy of their data electronically, the information requested will be provided to them in a commonly used electronic format, unless otherwise requested.
Customers, partners and prospects are informed that this right of access does not apply to confidential information or data, or to information or data which the law does not permit to be disclosed.
The right of access must not be exercised abusively, i.e. carried out on a regular basis for the sole purpose of disrupting the service concerned.
Updating – revision and rectification
We comply with requests for updates:
automatically for online changes to fields which can be updated either technically or legally;
upon written request from the individual concerned, who must provide proof of their identity.
Right to erasure
The right to erasure for customers, partners and prospects shall not apply where processing is carried out to comply with a legal obligation. Apart from this situation, customers, partners and prospects may request the erasure of their data in the following limited circumstances:
the personal data is no longer necessary in relation to the purposes for which it was collected or otherwise processed;
where the data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing;
the data subject objects to processing necessary for the purposes of the legitimate interests we pursue and there is no overriding legitimate ground for the processing;
the data subject objects to the processing of their personal data for marketing purposes, including profiling;
the personal data has been processed unlawfully.
Right to restriction of processing
Customers, partners and prospective customers are informed that this right does not apply insofar as the processing we carry out is lawful and all personal data collected is necessary for the purposes of such processing.
Right to data portability
We comply with requests for data portability in the specific case of data provided by customers, partners and prospective customers themselves via our online services, and for purposes based solely on the consent of the individuals concerned and the performance of a contract. In such cases, the data is provided to the requester in a structured, commonly used and machine-readable format.
Automated individual decision-making
We do not carry out any automated individual decision-making.
The tools available on our website are intended solely as aids for customers and prospective customers and should not be regarded as anything else.
Post-mortem rights
Customers, partners and prospective customers are informed that they have the right to set out instructions regarding the retention, erasure and disclosure of their data after their death.
Exercising rights
The above rights may be exercised, at the data subject’s discretion, by email or by post using the following contact details: [email protected] or 40 rue de Courcelles, 75008 Paris.
7. Additional provisions
Optional or mandatory nature of responses
Customers, partners and prospective clients are informed whether responses are mandatory or optional by the presence of an asterisk on each form for the collection of personal data submitted to them. Where responses are mandatory, we explain the consequences of failing to provide them.
Right of use
Our organisation is granted by its customers, prospective customers and partners the right to use and process their personal data for the purposes set out above.
However, any enriched data resulting from our processing and analysis, otherwise known as ‘enriched data’, remains our exclusive property (usage analysis, statistics, etc.).
Subcontracting
Please note that we may engage any data processor of our choice in connection with the processing of your personal data. In such cases, we ensure that the data processor complies with its obligations under the GDPR.
We undertake to enter into a written contract with all our data processors and to impose on them the same data protection obligations as we ourselves are subject to. Furthermore, we reserve the right to carry out audits of our data processors to ensure compliance with the provisions of the GDPR.
Cross-border data flows
Our organisation reserves the sole right to decide whether or not to carry out cross-border transfers of the personal data it processes.
In the event of a transfer of personal data to a country outside the European Union or to an international organisation, we will inform you and ensure that your rights are fully respected. Where necessary, we undertake to enter into one or more contracts to provide a framework for cross-border data transfers.
The provisions relating to cross-border data flows are binding on us, except in the cases of derogation provided for in Article 49 of the GDPR.
Record of processing activities
As the data controller, we undertake to maintain an up-to-date record of all processing activities carried out.
This register is a document or application used to record all processing operations that we carry out as the data controller.
We undertake to provide the supervisory authority, upon first request, with the information enabling that authority to verify that processing operations comply with the data protection legislation in force.
8. Security
Security measures
It is our responsibility to define and implement the technical security measures – whether physical or logical – that we deem appropriate to prevent the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of data.
To this end, we may engage any third party of our choice to carry out, as frequently as we deem necessary, vulnerability audits or penetration tests.
In any event, we undertake, in the event of any change to the measures designed to ensure the security and confidentiality of personal data, to replace them with measures offering a higher level of protection. No such change may result in a reduction in the level of security.
Where we subcontract all or part of the processing of personal data, we undertake to contractually require our data processors to provide security safeguards through technical measures to protect such data and appropriate human resources.
Data breach
In the event of a personal data breach, we undertake to notify the CNIL in accordance with the conditions laid down by the GDPR.
If such a breach poses a high risk to customers, partners and prospects and the data has not been adequately protected, we will notify the individuals concerned and provide them with the necessary information and recommendations.
9. Contacts
Data Protection Officer
We have appointed a Data Protection Officer, whose contact details are as follows: [email protected].
In the event of any new processing of personal data, we will consult the Data Protection Officer in advance.
If you wish to obtain specific information or ask a specific question, you may contact the Data Protection Officer, who will provide a response within a reasonable timeframe, taking into account the nature of the question or the information requested.
Should you encounter any issues regarding the processing of your personal data, you may contact the designated Data Protection Officer.
Right to lodge a complaint with the CNIL
Customers, partners and prospective customers affected by the processing of their personal data are informed of their right to lodge a complaint with a supervisory authority, namely the CNIL, if they consider that the processing of their personal data does not comply with European data protection regulations, at the following address:
CNIL – Complaints Department
3 Place de Fontenoy – TSA 80715 – 75334 PARIS CEDEX 07
Tel: 01 53 73 22 22
Updates
This policy may be amended or modified at any time in the event of changes to legislation, case law, decisions and recommendations of the CNIL, or industry practices.
Any new version of this policy will be brought to the attention of customers, prospective customers and partners by any means we may determine, including by electronic means (for example, by email or online).
For further information
For any further information, you may contact the Data Protection Officer (DPO) at the address given above, namely [email protected].
For any other general information on the protection of personal data, please visit the CNIL website.