Last updated: May 24, 2026

Le Club de la Paix Association places particular importance on protecting the personal data of visitors and donors to the website www.clubdelapaix.org. This policy describes how your data are collected, used and protected, in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and the French Data Protection Act of January 6, 1978, as amended.

Data Controller

The controller of the data collected on the website is:

Le Club de la Paix Association
25 rue des Trois Tilleuls, 77000 Vaux-le-Pénil
RNA Number: W772010562

Represented by its President, Mr. William Illouz.

Contact for any request relating to personal data: privacy@clubdelapaix.org

Data Collected and Purposes

2.1 When You Make a Donation

When you make a donation through the website, the following data are collected:

First and last name
Email address
Donation amount and frequency (one-time or monthly)
Payment data (bank card number, expiration date, security code)

Purpose: processing the donation, sending a payment receipt, communication relating to your support.

Legal basis: performance of the donation contract (Article 6.1.b GDPR).

Important: banking data neither pass through nor are stored on the association’s servers. They are processed directly by our payment provider Stripe (see section 4).

2.2 When You Contact Us

When you contact us through the contact form or by email, the following are collected:

First and last name
Email address
Message content

Purpose: responding to your request.

Legal basis: the legitimate interest of the association in responding to requests addressed to it (Article 6.1.f GDPR).

2.3 Technical Browsing Data

During your visit, the server records in its technical logs:

IP address
Browser type and version
Pages visited and timestamps

Purpose: website security, detection of malicious behavior, anonymous audience statistics.

Legal basis: the legitimate interest of the association in securing its website (Article 6.1.f GDPR).

Retention Period

Data TypeRetention Period
Donation-related data10 years (accounting obligation)
Contact data (form, email)3 years from the last contact
Server technical logsMaximum 1 year
CookiesSee section 6

Upon expiration of these periods, the data are deleted or anonymized.

Recipients and Processors

Your data are never sold or transferred to third parties for commercial purposes. They are accessible only to authorized members of the association’s management and to the following technical processors:

Stripe (Payment)

Payments are processed by Stripe Payments Europe Limited (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland), a PCI-DSS Level 1 certified provider. Stripe directly processes your banking data in order to execute the transaction. Its privacy policy is available at stripe.com/fr/privacy.

Infomaniak (Hosting)

The website and its database are hosted by Infomaniak Network SA (Rue Eugène-Marziano 25, 1227 Les Acacias, Geneva, Switzerland). The servers are located in Switzerland, in data centers powered by renewable energy. Infomaniak complies with GDPR requirements and applies Swiss data protection law (LPD).

WordPress / WP Charitable (Software)

The website operates using the open-source software WordPress and the WP Charitable extension, which locally manage the donation form and related data. These tools do not transmit any data to their publishers.

The association reserves the right to add other technical providers in the future (transactional email service, privacy-friendly audience measurement tool, etc.), which will be notified in an updated version of this policy.

Transfers Outside the European Union

To Switzerland (Infomaniak)

The website is hosted in Switzerland by Infomaniak. Switzerland is covered by a European Commission adequacy decision (renewed on January 15, 2024), recognizing that the country provides a level of data protection substantially equivalent to that of the European Union. No additional safeguards (standard contractual clauses, BCRs) are therefore required for this transfer.

To the United States (Stripe)

As Stripe may transfer certain data to the United States, such transfers are governed by the Standard Contractual Clauses adopted by the European Commission and, where applicable, by the Data Privacy Framework certification mechanisms to which Stripe adheres.

No other transfers of data outside the European Union are carried out.

Cookies and Trackers

The website uses a limited number of cookies, classified into two categories:

Strictly Necessary Cookies (Exempt from Consent)

WordPress session cookies: placed only if you log into an account (administrative area). Duration: session.

Stripe cookies: placed on the donation page to ensure transaction security and prevent fraud. Duration: varies according to Stripe (up to 1 year).

No Advertising or Audience Measurement Cookies

The website does not use Google Analytics, Matomo, Meta Pixel, or any other advertising or audience measurement tracker at the date of publication. Therefore, no consent is required for simple browsing of the website.

If an audience measurement tool is added in the future, a GDPR-compliant consent banner will be implemented.

Your Rights

In accordance with GDPR and the French Data Protection Act, you have the following rights regarding your personal data:

Right of access: obtain confirmation that data concerning you are being processed and obtain a copy of them.

Right of rectification: request correction of inaccurate or incomplete data.

Right to erasure (“right to be forgotten”): request deletion of your data, within the limits provided by law (in particular the 10-year accounting obligation for donations).

Right to restriction of processing: request temporary suspension of the processing of your data.

Right to object: object to the processing of your data for legitimate reasons.

Right to data portability: receive your data in a structured and commonly used format.

Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before such withdrawal.

Right to define instructions concerning the fate of your data after your death.

How to Exercise Your Rights

To exercise any of these rights, send your request, together with a copy of proof of identity, to:

privacy@clubdelapaix.org

or by postal mail to:

Le Club de la Paix Association
25 rue des Trois Tilleuls, 77000 Vaux-le-Pénil

The association undertakes to respond within a maximum period of one month from receipt of your request.

Complaint to the CNIL

If you believe that your rights are not being respected, you may file a complaint with the French Data Protection Authority (CNIL):

CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Telephone: 01 53 73 22 22
www.cnil.fr

Security

The association implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, disclosure or destruction:

Encryption of communications through the HTTPS protocol (SSL certificate)

Hosting on secure servers located in Switzerland

Restricted access to data limited to authorized members of the association

Regular updates of the WordPress software and its extensions

Amendments

This policy may be updated to reflect legal, technical or organizational developments. The date of the last update appears at the top of the document. Substantial modifications will be brought to the attention of donors by email.