Privacy Policy
This policy explains what personal data we handle on tourismeiffel.com, why, on what lawful basis, and what your rights are under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the French Data Protection Act (Loi Informatique et Libertés).
1. Who we are (the controller)
The controller of personal data processed via this website is the editorial team of TourismEiffel.com (see the imprint for full company details). Contact for privacy matters: [email protected]. Our supervisory authority in France is the CNIL (Commission nationale de l'informatique et des libertés).
2. What data we collect and why
| Category | Data | Purpose | Retention |
|---|---|---|---|
| Server logs | IP address (truncated after 30 days), timestamp, request URL, response code, user-agent | Security, troubleshooting, abuse detection | 90 days |
| Essential cookies | Session identifier, consent record | Basic site function | Session / 12 months |
| Contact form | Name, email, message content | Reply to your enquiry | 12 months after last correspondence |
| Analytics (optional) | Anonymised aggregate visit counts, referrer categories, screen size | Improve content quality | 26 months |
3. Lawful bases (GDPR Art. 6)
- Server logs and essential cookies: legitimate interest (Art. 6 (1) f) — operating a secure, functioning website.
- Contact form: consent (Art. 6 (1) a) — you submit the form voluntarily.
- Analytics: consent (Art. 6 (1) a) — you actively opt in via our cookie banner. If you decline, no analytics data is collected.
4. Who has access to your data
We share personal data only with our hosting provider (netcup GmbH, Karlsruhe, Germany), our content-delivery provider (Cloudflare, Inc., San Francisco, USA), and email delivery for replies. Each operates under a Data Processing Agreement per Art. 28 GDPR. We do not sell your data. We do not use third-party advertising trackers, retargeting pixels, or social-network integrations.
5. International transfers
Cloudflare's global edge network may cache non-personal static assets outside the EEA. Standard Contractual Clauses (SCCs) approved by the European Commission apply to any transfer of personal data outside the EEA (Art. 46 GDPR).
6. Your rights
Under Articles 15–22 GDPR you have the right to:
- ask what data we hold about you and receive a copy (right of access);
- have inaccurate data corrected (rectification);
- ask us to delete your data (erasure), subject to legal retention obligations;
- restrict processing under certain conditions;
- receive your data in a machine-readable form (portability);
- object to processing based on legitimate interest;
- withdraw consent at any time — this does not affect prior lawful processing;
- lodge a complaint with the CNIL (cnil.fr).
To exercise any of these rights: [email protected]. We respond within 30 days.
7. Cookies
See our detailed Cookie Policy. You can change your preferences at any time from the "Cookie preferences" link in the footer.
8. Children
This site is not directed at children under 15. We do not knowingly collect personal data from children. If we learn we have inadvertently done so, we will delete it.
9. Data security
TLS 1.3 encryption for all connections. Server hardening, minimal privilege, encrypted backups, and quarterly security review. See our Security Policy for details.
10. Changes to this policy
Material changes will be flagged on the site and by updating the date at the top. This is version 2, dated 22 September 2026.