Privacy Policy
This policy is published pursuant to Regulation (EU) 2016/679 (GDPR), Articles 13 and 14 — information to be provided where personal data are collected from the data subject.
1. Identity of the data controller
The data controller is a self-employed individual operating as a sole trader (micro-entrepreneur):
| Name | Michelet Samuel |
|---|---|
| Status | Self-employed individual (sole trader — micro-entrepreneur) |
| Address | 20 rue Bartayrès, 65100 Lourdes, France |
| contact@lourdes-massabielle.org | |
| Phone | None |
| SIRET | 903 472 108 00013 |
The portal does not have a Data Protection Officer (DPO) — this designation is not mandatory for a sole trader (GDPR Art. 37). Any request regarding personal data may be sent to contact@lourdes-massabielle.org.
2. Data processing and legal bases
2.1 Business directory (paid listings)
Purpose: publication and management of listings for Catholic establishments in Lourdes; invoicing and accounting.
Legal basis: performance of a contract (Art. 6(1)(b)) + legal accounting obligation (Art. 6(1)(c)).
Data collected: name, position, professional contact details (address, phone, email), establishment SIRET number, billing data (amount, date, payment method: cheque, cash or IBAN transfer).
Mandatory fields: name, email and SIRET are required for a paid listing. Phone and position are optional.
Retention: listing data for the duration of the contract + 3 years (prospecting). Invoices: 10 years (Art. L. 123-22 French Commercial Code). Unsuccessful listing claims: 12 months.
Recipients: portal publisher, Cloudflare (hosting), Brevo (claim notification email).
2.2 Multilingual prayer wall
Purpose: enabling visitors to submit a prayer intention, moderate it and publish it temporarily on one of the 11 language prayer walls on the portal (fr, en, es, it, de, pt, pl, hi, ta, sw, ms).
Legal basis: consent (Art. 6(1)(a)) + explicit consent (Art. 9(2)(a)) — prayer intentions may reveal religious beliefs and sometimes health data, which constitute special category data within the meaning of GDPR Article 9.
Consent collection: a dedicated, unchecked checkbox with clear wording is presented before each submission. You may withdraw your consent at any time via the page /prier/mes-donnees (accessible via magic link) or by writing to contact@lourdes-massabielle.org.
Data collected: email address (required — identification via magic link), intention text (free text), wall language, timestamp. A SHA-256 hash of the email is retained for the anti-spam counter. The IP address is hashed in logs.
Moderation: intentions are analysed by an automated moderation system (artificial intelligence, Claude Sonnet 4.6 by Anthropic). Before being sent to this system, your data are pseudonymised: the email, IP address and first name are removed. Only a pseudonymous identifier and the intention text are transmitted. The moderation score determines automatic publication (high score), referral to human moderation by the publisher (intermediate score) or automatic rejection with a stated reason (low score).
Retention: your intention is displayed for 3 days, then moves to "expired" status. It is permanently deleted 30 days after submission. Maximum 2 submissions per person every 15 days. AI moderation logs are retained for a maximum of 6 months.
Recipients: portal publisher (human moderation), Cloudflare (EU hosting), Brevo (magic link delivery only — never the intention content), Anthropic (AI moderation — pseudonymised data only, transfer to USA governed by SCCs 2021 and DPF).
2.3 Donations via Stripe
Purpose: collection of voluntary contributions to support the portal and accounting.
Legal basis: performance of a contract (Art. 6(1)(b)) + legal accounting obligation (Art. 6(1)(c)).
Data collected: email (required), name (optional), donation amount and date, type (one-off or monthly), currency, Stripe transaction identifiers. No payment card data is stored by the portal — these are processed directly by Stripe on its servers.
Retention: accounting data for 10 years (Art. L. 123-22 French Commercial Code). Donor contact details for thank-you purposes: 3 years after the last donation.
Recipients: portal publisher (accounting), Stripe Payments Europe Ltd (payment processing, Dublin), Brevo (thank-you email), Cloudflare (hosting).
Important: donations are voluntary contributions. The publisher, as a self-employed individual taxed on non-commercial profits (BNC), cannot issue an official tax receipt (CERFA form). No CERFA receipt will be provided.
2.4 Newsletter
Purpose: periodic sending of news, spiritual information and events relating to Lourdes and pilgrimage.
Legal basis: consent (Art. 6(1)(a)) — active opt-in with unchecked checkbox.
Data collected: email (required), first name (optional), preferred language (optional).
Retention: 3 years from the last active contact (click on a link in an email). Thereafter, deletion or request for re-consent.
Right to unsubscribe: each email contains a one-click unsubscribe link (Art. L. 34-5 CPCE). The suppression list is retained for a minimum of 3 years to prevent unwanted solicitations.
Recipients: portal publisher, Brevo / Sendinblue SAS (email delivery, OVH France hosting).
2.5 Contact form
Purpose: responding to questions, information requests or suggestions from visitors.
Legal basis: legitimate interest (Art. 6(1)(f)) — responding to a request from the individual concerned.
Data collected: name (optional), email (required), message subject (optional), message content.
Retention: 12 months after the last exchange, then deletion. If the request leads to a directory contract or newsletter subscription, data moves to the relevant processing activity.
Recipients: portal publisher, Cloudflare (transit and hosting), Brevo (transactional notification).
3. Recipients and processors
Personal data are processed by the following sub-processors, all bound by a data processing agreement (DPA) compliant with GDPR Article 28:
| Sub-processor | Role | Registered office | Data hosting |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, security | USA (San Francisco) | EU (R2 jurisdiction EU) |
| Brevo (Sendinblue SAS) | Newsletter, transactional email, magic links | France (Paris) | OVH France |
| Stripe Payments Europe, Ltd | Donation processing | Ireland (Dublin) | EU + USA |
| Make.com (Celonis SE) | Directory workflow automation | Germany (Munich) | EU (eu1 or eu2) |
| Anthropic (Anthropic Ireland, Ltd) | AI moderation of prayer wall | Ireland / USA | USA (pseudonymised data only) |
No personal data is sold, rented or transferred to third parties for commercial purposes.
4. International transfers
Some sub-processors are located in the United States. These transfers are governed by:
- The EU-US Data Privacy Framework (DPF): European Commission adequacy decision of 10 July 2023 (C(2023)4745). Cloudflare, Brevo (via Sendinblue Inc.), Stripe (via Stripe LLC), Celonis (via Celonis Inc.) and Anthropic PBC are DPF certified.
- Standard Contractual Clauses (SCCs) 2021 version: Implementing Decision (EU) 2021/914 of 4 June 2021. These SCCs are incorporated into the DPAs of all sub-processors.
- Additional safeguards: encryption in transit (TLS 1.3) and at rest (AES-256), pseudonymisation of prayer wall data before any transfer to Anthropic.
For the prayer wall specifically: only the pseudonymised intention text (without email, IP or first name) is transmitted to Anthropic. Anthropic contractually guarantees that data will not be used for model training (Commercial Terms §C). API retention is 7 days, after which data is automatically deleted.
5. Cookies and trackers
The Lourdes-Massabielle.org portal sets no third-party cookies. For full details, please consult the Cookie policy.
As no cookies or trackers subject to consent are set on the lourdes-massabielle.org domain, no cookie banner is displayed (in accordance with CNIL guidelines n° 2020-091 of 17 September 2020).
6. Data security
The portal implements the following technical and organisational measures (GDPR Art. 32):
- Encryption in transit: TLS 1.3 (Cloudflare native + HSTS preload).
- Encryption at rest: AES-256 GCM (D1 database), application-level encryption of prayer wall emails (Web Crypto API).
- Pseudonymisation: mandatory before any call to the AI moderation API.
- Access control: admin authentication via Cloudflare Zero Trust One-Time PIN, MFA on all third-party accounts.
- Anti-bot: Cloudflare Turnstile invisible on all forms (no cognitive CAPTCHA).
- Logging: access logs retained for 6 months, protected against modification.
- Backups: daily, encrypted, stored in a separate EU zone.
7. Your rights
Under GDPR Articles 15 to 22, you have the following rights:
Right of access (Art. 15): you may obtain confirmation that data concerning you are being processed, and receive a copy.
Right to rectification (Art. 16): you may request correction of inaccurate or incomplete data.
Right to erasure (Art. 17): you may request deletion of your data, except where a legal retention obligation applies (notably accounting — 10 years).
Right to restriction (Art. 18): you may request suspension of processing in certain circumstances (disputed accuracy, objection pending examination).
Right to data portability (Art. 20): for processing based on consent or a contract, you may receive your data in a structured format (JSON or CSV).
Right to object (Art. 21): for processing based on legitimate interest (contact form), you may object to processing on grounds relating to your particular situation.
Right to withdraw consent: for the prayer wall and newsletter, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of prior processing.
Right to lodge a complaint: you have the right to lodge a complaint with the CNIL (French Data Protection Authority): cnil.fr/fr/plaintes.
8. How to exercise your rights
By email: contact@lourdes-massabielle.org
For the prayer wall: via the page /prier/mes-donnees, accessible by magic link (the same identification system as for submitting an intention).
For the newsletter: one-click unsubscribe link in each email.
Response deadline: maximum 1 month from receipt of your request (GDPR Art. 12(3)). This period may be extended by 2 months in cases of complexity; you will be informed within one month of your request.
Identity verification: to protect your data, we may ask you to verify your identity before processing your request. We will never ask for disproportionate documentation.
9. Automated decision-making
The prayer wall uses an automated moderation system based on artificial intelligence (GDPR Art. 22). This system assigns a score to each submitted intention based on criteria of dignity, relevance and compliance with the portal's values. Decisions are as follows:
- High score: automatic publication.
- Intermediate score: referral to human moderation by the publisher.
- Low score: automatic rejection with a stated reason.
You have the right to contest an automated decision, to express your point of view and to obtain human intervention from the publisher by writing to contact@lourdes-massabielle.org (GDPR Art. 22(3)).
10. Minors
The portal does not intentionally collect personal data from minors under 15 years of age (French threshold, Art. 45 of the Data Protection Act). If a minor under 15 wishes to submit a prayer intention, the consent of the person holding parental authority is required (GDPR Art. 8).
11. Changes to this policy
This policy may be updated to reflect regulatory developments or changes to processing activities. The date of last update appears at the top of this document. In the event of a substantial change, notice will be given on the portal.
Legal references
| Source | Reference |
|---|---|
| GDPR | Regulation (EU) 2016/679, Art. 6, 8, 9, 12–22, 28, 32, 44–49 |
| French Data Protection Act | Law n° 78-17 of 6 January 1978, as amended, Art. 45 (minors) |
| CNIL — Cookies | Guidelines n° 2020-091 of 17 September 2020 |
| French Commercial Code | Art. L. 123-22 (10-year accounting retention) |
| SCCs 2021 | Implementing Decision (EU) 2021/914 |
| DPF | Adequacy decision C(2023)4745 of 10 July 2023 |