TourismEiffelTicket Info
Legal · Updated 22 September 2026

Security Policy

How we protect this site and the personal data of visitors who reach out to us. Version 1, effective 22 September 2026.

1. Scope

This policy applies to tourismeiffel.com, its subdomains, and any personal data processed on its behalf.

2. Technical measures

3. Organisational measures

4. Data-breach handling

If we become aware of a personal-data breach, we assess its scope within 24 hours, contain the issue, and — per GDPR Article 33 — notify the CNIL within 72 hours if the breach poses a risk to individuals. Affected users are informed directly per Article 34 when the risk to their rights is high.

5. Responsible disclosure

We appreciate security researchers who follow responsible-disclosure practices. If you find a vulnerability:

  1. Report it to [email protected] (PGP key available on request).
  2. Provide enough detail for us to reproduce the issue.
  3. Give us reasonable time (at least 30 days) to remediate before public disclosure.
  4. Do not exploit the vulnerability beyond what is needed to demonstrate it, and do not access data belonging to other users.

We commit to acknowledging your report within three working days, keeping you informed of progress, and — with your consent — crediting you in our security acknowledgements.

6. What is out of scope

7. Compliance references

GDPR (Regulation (EU) 2016/679), French Loi Informatique et Libertés, ISO/IEC 27001 and 27002 as an inspiration (not certified). We follow the OWASP Top 10 and CIS Critical Security Controls when designing site infrastructure.

8. Version history

Version 1, dated 22 September 2026 — initial publication.