Personal data management policy

Within the framework of the use of the site https://www.medmpaforum.org  (hereinafter referred to as the “Site”), the association MedPAN and SPA/RAC, operators of the Site, is likely to be processing personal data of users connecting to the Site (hereinafter referred to as the “Users” in the plural and the “User” in the singular) defined below.

In order to maintain the User’s trust, MedPAN and SPA/RAC invite the User to read its policy on the matter, which describes the data collected, the use that is made of it, and the rights that the User has with regard to them, in accordance with Law n°78-17 of January 6, 1978, as amended, and the EU Regulation 2016/679 of April 27, 2016.

MedPAN and SPA/RAC commit to not process personal data for purposes other than those mentioned in this privacy policy.

WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?

The entities in charge of processing personal data are:

MedPAN, an association creates under the law of July 1, 1901, declared on March 31, 2016, to the Prefecture of Bouches-du-Rhône, whose registered office is located at 58, Quai du Port, 13002 Marseille, registered in the SIREN register under number 509 161 402.

and

SPA/RAC, the Specially Protected Areas Regional Activity Centre. SPA/RAC is a component of UNEP/MAP-Barcelona Convention. The Centre’s objective is to contribute to the conservation of marine biodiversity in the Mediterranean, in particular through the creation and effective management of marine and coastal protected areas.

The SPA/RAC contact details are as follows

Within the framework of the Site, and in compliance with Law No. 78-17 of January 6, 1978, as amended, and EU Regulation 2016/679 of April 27, 2016, MedPAN and SPA/RAC collect and process a certain amount of personal data relating to the User according to the terms and conditions defined below.

WHAT DATA DO WE COLLECT AND WHY?

The User is informed, on each personal data collection form, of the mandatory nature of the answers by the presence of the mention “(Mandatory)”. If you do not fill in the mandatory information, the service requested involving the processing of such data can not be implemented. 

  1. Creation and use of a Personal Account

The creation of a personal account is necessary to benefit from all the services offered by MedPAN and SPA/RAC and in particular to be able to actively contribute to the Forum process.   

MedPAN and SPA/RAC collect, within the framework of the form of creation of a personal account, the civility, the name and first name of the User, their email address, their telephone number and their postal address.

  • The password is however encrypted and is therefore not readable by MedPAN and SPA/RAC.
  • The e-mail address and the password allow the User to connect to their personal account.
  • The e-mail address allows the User to request the reset of their password in case he forgets it.
  • From the personal Account, the User can consult and modify their personal data.
  • The User can also, if he wishes, communicate additional personal data in the tab “My space”. 
  1. Messages sent to MedPAN and SPA/RAC via the contact form

The User may contact MedPAN and SPA/RAC using the “Contact” form provided on the Site for various reasons (request for information, request for a contribution, etc.)

The data that must be collected is the User’s e-mail address and the message that the User wishes to send to MedPAN and SPA/RAC, the content of which is freely determined by the latter. If the User already has a personal account, their title, first name and surname are compulsorily collected. 

These data are processed in order to respond to the User’s request. 

MedPAN and SPA/RAC may, depending on the nature of the User’s request, ask the User to provide other personal data that may be necessary to process the request, indicating the purpose of this collection. 

  1. Messages sent to MedPAN and SPA/RAC by any other means

The User can contact MedPAN and SPA/RAC by e-mail, by post. In this context, MedPAN and SPA/RAC collect data that the User has voluntarily provided such as contact information and the content of the message that the User wishes to send and whose content is freely determined by the latter.

This data is processed in order to respond to the User’s request. 

MedPAN and SPA/RAC may, depending on the nature of the User’s request, ask the User to provide other personal data that may be necessary to process the request, indicating the purpose of this collection. 

  1. Newsletter

Insofar as the User expressly consents, MedPAN and SPA/RAC use their e-mail address to send them its newsletter by e-mail.

  1. Cookies

MedPAN and SPA/RAC use cookies to collect the User’s navigation data on the Site. The User can read detailed information about the cookies used, the use made of them and the acceptance or opposition to the use of cookies in the Cookies Policy.

HOW LONG DO WE KEEP YOUR DATA?

  1. Personal Account Data

The data collected for the creation of a personal account (Article 2.1) are kept for the time the User has a personal account.

The User may request at any time the deletion of their personal account.

  1. Messages sent to MedPAN and SPA/RAC

Messages sent to MedPAN and SPA/RAC (Articles 2.2, 2.3 and 2.4) are kept by MedPAN and SPA/RAC for the time strictly necessary to process the User’s request.

Depending on the nature of the User’s request, the data communicated may be kept in an intermediate archive for a period of five (5) years for the strict purpose of protecting against possible litigation, to the exclusion of any other purpose.

  1. Newsletter

The User’s e-mail address is used to send newsletters (Article 2.5) for a period of three (3) years from the date of collection or from the last contact from the User (for example, a request for documentation or a click on a hypertext link contained in an e-mail; however, the opening of an e-mail cannot be considered as a contact from the User)

At the end of this three (3) year period, MedPAN and SPA/RAC may contact the User again to find out if he or she wishes to continue receiving its newsletters. In the absence of a positive and explicit response from the User, the sending of newsletters will cease.

  1. Exercising your rights to your data

The requests to exercise rights referred to in Article 7 of this policy entail the processing of personal data that the User communicates for this purpose.

In the event of exercising their rights, the data relating to the User’s request will be kept for a period of five (5) years from the end of the calendar year following the request.

If a copy of the User’s identity document is requested, it is kept for a period of one (1) year, or three (3) years if he/she exercises their right of opposition or deletion.

  1. Cookies

In accordance with the Site’s Cookie Policy:

  • The validity period of the consent to the use of cookies is six (6) months. At the end of this period, the User’s consent will be collected again;
  • Cookies are kept for distinct periods of time, which are specified in the policy relating to cookies. This duration is not extended in any case in case of a new visit to the Site.

WHAT IS THE LEGAL BASIS FOR PROCESSING YOUR DATA?

  1. Consent

The following processing is only carried out if the User expressly gives their consent for the:

  • Creation of a personal account
  • Messages sent to MedPAN and SPA/RAC via the contact form 
  • Receiving of newsletters
  • Cookies not necessary for the functioning of MedPAN and SPA/RAC

All these treatments are based on separate consent.

When the User sends a message to MedPAN and SPA/RAC by any other means (Article 2.4), the User is deemed to have given their consent to the processing of the data he spontaneously communicates to the Company. The same applies when the User spontaneously communicates additional personal data in the “My space” tab.
The User may at any time withdraw their consent to all or part of this processing in accordance with Article 7 of this Privacy Policy relating to the exercise of their rights.

The withdrawal of the User’s consent is only effective for the future and does not call into question the lawfulness of the processing carried out prior to the withdrawal of consent.

  1. Compliance with legal obligations

The data processed in the context of the execution of a request concerning the exercise of the User’s rights allows MedPAN and SPA/RAC to comply with its own legal obligations.

TO WHOM IS YOUR DATA TRANSMITTED?

MedPAN and SPA/RAC are the recipients of all data collected and processed under its responsibility. Only MedPAN and SPA/RAC’s duly authorized personnel may have access to it. 

The subcontractors mentioned in Article 6 below may have access to the data in order to carry out the services for which they are responsible, but may not under any circumstances carry out any other data processing operation, such as the modification or use of the data for other purposes.

In any case, MedPAN and SPA/RAC limit the transfer of Users’ personal data to what is strictly necessary. 

MedPAN and SPA/RAC may also disclose the data collected if it considers such disclosure necessary to comply with the law in force. 

In any case, MedPAN and SPA/RAC will not transfer the personal data of its Users outside the European Union.

WHO ARE OUR SERVICE PROVIDERS? 

MedPAN and SPA/RAC use various subcontractors whose respective missions are to ensure the hosting of the Site’s databases and their maintenance.

MedPAN and SPA/RAC guarantee that its subcontractors present sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that the processing meets the requirements of the EU Regulation 2016/679 and the Data Protection Act. 

Processors may themselves be authorized to subcontract all or part of their operations subject to strict compliance with the provisions of Article 28 of Regulation EU 2016/679 and the provisions of this Privacy Policy. 

MedPAN and SPA/RAC, in its capacity as a data controller, remains the sole interlocutor of the User.

In the event that MedPAN and SPA/RAC become involved in a merger or other form of asset transfer, MedPAN and SPA/RAC undertake to obtain Users’ prior consent to the transfer of their personal data and to maintain the level of confidentiality of their personal data to which Users have consented.

WHAT ARE YOUR RIGHTS AND HOW TO EXERCISE THEM? 

  1. What are your rights?

In accordance with the regulations in force, every User has the following rights with respect to their or her personal data:

  • Access to personal data held by MedPAN and SPA/RAC and information on the processing of such data;
  • To update personal data that are not up to date or that are incorrect;
  • Restrict the way MedPAN and SPA/RAC processes personal data;
  • Request a copy from MedPAN and SPA/RAC of any of the personal data it holds about them;
  • Request the deletion of their or her personal data if it is not processed in order to comply with a legal obligation;
  • Oppose the use of their personal data for a processing that is not based on the performance of a contract, on compliance with a legal obligation, on the absence of opposition, or on consent, in which case the User must withdraw their consent;
  • Withdraw consent to data processing that is based on consent. The withdrawal of consent is only effective for the future and does not affect the lawfulness of the processing carried out previously;
  • Formulate advance directives on the use of their data after their death (e.g.: retention, deletion, disclosure). The User may modify or retract these instructions at any time;
  • Exercise the right to portability on data that the User has actively and consciously declared or generated through their activity. The data must then be returned to the User in a structured, commonly used and machine-readable format. Only data processed in an automated manner and collected on the basis of consent or the execution of a contract are affected by this right.
  1. How to exercise your rights?

2.1 By contacting MedPAN and SPA/RAC:

In order to exercise their rights, Users must send a request, specifying in the subject line of their letter or e-mail that it is a request for information or a complaint relating to their personal data, and will provide proof of receipt of their request.

Any request in this sense should be addressed by either 

MedPAN and SPA/RAC reserve the right to request a copy of the identity document of the person concerned in order to avoid any fraud and/or illicit access to their data. MedPAN and SPA/RAC will respond to the User’s request as soon as possible and at the most within one (1) month from the receipt of the request. 

However, certain personal data may be exempted from such requests under certain circumstances, for example, if it infringes on the rights and freedoms of third parties. If an exception applies, MedPAN and SPA/RAC will inform the User when responding to the request.

2.2 By using the tools and features made available to you

The User may at any time:

  • Modify some of their personal data directly from their personal account ;
  • Withdraw their consent to the processing of their data through cookies by setting their cookies in accordance with what is described in the Policy on cookies;
  • Withdraw their consent to receive newsletters by clicking on the link provided for this purpose in each newsletter email he receives from MedPAN and SPA/RAC.

2.3 Right to file a complaint with the CNIL

The User is informed of their right to lodge a complaint with the competent control authority (the CNIL in France: www.cnil.en), in case of non-compliance with legal and regulatory provisions by MedPAN and SPA/RAC or its subcontractors in the context of the management of their personal data.