- PURPOSE AND SCOPE
The protection of your personal data is of high importance to the French Red Cross and the Spanish Red Cross (hereafter “the FRC” and “the SRC” or “us”), joint data controllers, which take all reasonable care to ensure that your personal data is processed safely.
The FRC and the SRC are joint controllers under Article 26 of the General Data Protection Regulation (Regulation (EU) 2016/679 or GDPR) for personal data processed in connection with the use of the website red social innovation (hereafter “the website”), on the basis that the FRC and SRC jointly decide the purposes of the processing of personal data and what means are to be used.
This privacy notice describes how the FRC and the SRC use your personal data when you visit our website.
This privacy notice complies with data protection regulations, including the General Data Protection Regulation 2016/679 (Regulation (EU) 2016/679 or “GDPR”) and the French Data Protection Law (Law nᵒ 78-17 of January 6, 1978).
- PURPOSES AND LAWFUL BASES OF DATA PROCESSING
Your personal data are processed for the following purposes:
- Management and online publication of your project on the website;
- Prospecting and communication activities related to the FRC and SRC’s actions and projects, and surveys about your experience on the website;
- Management and sending of the newsletter and articles published on the website ;
- Management and processing of contact and information requests on the website;
- Management of your possible requests to exercise your personal data protection rights;
- Study and understanding of your website navigation, in particular through analyses and statistics.
The lawful basis upon which the FRC and the SRC process such data are:
- Our legitimate interests, which are the management of the projects on the website; prospecting and communication activities related to the FRC and SRC’s activities and development; and follow-up of relations with our contacts;
- Respect of a legal obligation to which the FRC and the SRC are subject;
- Your consent that you can withdraw at any time, for the processing related to management and sending of the newsletter and articles published on the website and the study and understanding of your website navigation.
- TYPES OF PERSONAL DATA
The following types of personal data are processed by the FRC and the SRC:
Purposes of processing | Types of personal data processed |
Management and online publication of your project on the website | Last name, first name, company, email |
Prospecting and communication activities related to the FRC and SRC’s actions and projects | Last name, first name, email |
Management and sending of the newsletter | Last name, first name, email |
Management and sending of articles published on the website | Email address |
Management and processing of contact and information requests on the website | Last name, first name, email |
Study and understanding of your website navigation, in particular through analyses and statistics | IP address (if you agree to store a cookie on your equipment) |
In the personal data collection forms available on the website (project publication form and contact form), fields marked with a red asterisk must be provided. Otherwise, the FRC and the SRC will not be able to process your request.
4) RECIPIENTS OF PERSONAL DATA
Recipients of your personal data will be the FRC and SRC’s authorised personnel. However, your personal data may be communicated to technical service providers to achieve certain objectives on our behalf (for example, companies in charge of website development and maintenance, website hosting, etc.). These technical service providers:
- have limited access to your personal data, only for the performance of their services;
- have a contractual obligation to use your personal data in accordance with our instructions and with data protection legal provisions;
- are likely to be located outside the European Union, in particular in countries that do not ensure an adequate level of data protection. In this case, these data transfers are covered by appropriate safeguards, in particular the signing of standard contractual clauses adopted by the European Commission.
5) PERIOD FOR WHICH PERSONAL DATA ARE STORED
Purposes of processing | Period for which personal data are stored |
Management and online publication of your project on the website | Until your deletion of your project, or until the deletion of your project by the joint decision of the FRC and the SRC after having informed you in writing |
Prospecting and communication activities related to the FRC and SRC’s actions and projects | Two years from the date of your last contact with the FRC and the SRC, then removal |
Management and sending of the newsletter and articles published on the website | Until the data subject unsubscribes (via the unsubscribe link included in the newsletters or by emails) |
Management and processing of contact and information requests on the website | Until your request is processed, and for one year maximum after your request, then removal |
Study and understanding of your website navigation, in particular through analyses and statistics | 13 months maximum, then removal |
6) FRC AND SRC’S ROLES AND RESPONSIBILITIES
The FRC and the SRC, as joint data controllers, shall:
– process your personal data only for the agreed purposes of processing;
– observe the principle of data minimisation within the meaning of Article 5 (1) c) of the GDPR;
– update your personal data if necessary, at your request or on their own initiative;
– not disclose or allow access to your personal data to anyone other than the permitted recipients;
– provide you with clear and sufficient information on the processing of your personal data, in accordance with Articles 12 to 14 of the GDPR: the FRC and the SRC collect your personal data via the website, and provide you with information notices on each data collection form available on the website. Moreover, the FRC and the SRC publish this privacy notice on the website. The FRC is responsible for the creation and publication of these documents published in French and in English on the website. The SRC is responsible for the creation and publication of these documents published in Spanish on the website;
– respect your rights pursuant to Chapter 3 of the GDPR. The SRC’s Data Protection Officer (available at dpo@cruzroja.es) serves as a point of contact. However in accordance with article 26 of the Regulation EU 2016/679, you may exercise your rights in respect of and against the SRC and the FRC;
– Comply with articles 33 and 34 of the GDPR in the case of a personal data breach: in the case of a personal data breach likely to result in a risk to the rights and freedoms of
natural persons, the French Red Cross (FRC) notifies the personal data breach to the lead supervisory authority: the French Data Protection Authority (the “Commission nationale de l’informatique et des libertés” or CNIL).
In the case of a personal data breach likely to result in a high risk to the rights and freedoms of the data subjects: in accordance with article 34 of the GDPR, the French Red Cross shall communicate the personal data breach to the French speaking data subjects, or the English speaking data subjects in accordance with Article 34 of the GDPR. The Spanish Red Cross shall communicate the personal data breach to the Spanish speaking data subjects in accordance with Article 34 of the GDPR.
7) DATA SECURITY
In order to ensure your data security, the FRC and the SRC implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Our technical service providers are in particular subject to a contractual obligation of security and confidentiality of the personal data they process on our behalf.
8) RIGHTS
Please note that you have the right to access your personal data, and to request that your personal data be rectified. In some cases, you have the right to request that your personal data be deleted, and to request restriction of processing of your personal data.
You also have the right to object to processing of your personal data, to object to processing of your personal data for direct marketing purposes and to data portability.
In accordance with article 26 of the Regulation EU 2016/679, you may exercise your rights in respect of and against the SRC and the FRC.
The SRC’s Data Protection Officer serves as a point of contact. If you wish to make a request, please contact us at dpo@cruzroja.es or at the following address:
Spanish Red Cross
Data Protection Officer
C/ Av. Reina Victoria 26-28
28003 Madrid
If you wish to contact the FRC’s data protection officer, please contact us at dpo@croix-rouge.fr, or by post at the following address:
French Red Cross
Data protection officer
98 Rue Didot
75014 Paris
The FRC and SRC decide that the lead supervisory authority is the French Data Protection Authority (the “Commission nationale de l’informatique et des libertés” or CNIL): If you think that your rights are not sufficiently respected, you can complain to the CNIL, online or by post at the following address:
CNIL
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
If you think that your rights are not sufficiently respected, you can complain to the Spanish Data Protection Authority (AEPD) at www.aepd.es.
9) COOKIES
Cookies are small files consisting of letters and numbers that are placed on your device (computer, smartphone…) and your web browser when visiting this website.
The deposit of cookies on your web browser is subject to your consent, with the exception of technical cookies. During your first visit on the website, a banner informs you of the presence of cookies: you will be prompted to accept or refuse cookies. They will only be stored on your device if you click on “accept cookies”.
You can however withdraw your consent at any time, for all or some of the cookies, except for technical cookies.
You can learn more about the use of cookies on the website by visiting this page.
10) UPDATE OF THIS PRIVACY NOTICE
This privacy notice is subject to change at any time. Please consult it regularly in the dedicated section of the website. You can also access it by clicking on the link appearing on each data collection form on the site.
Last modification: 06/05/2021.