Your data
Sommières Town Hall / Sommières Castle undertakes to ensure that the processing of your data complies with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
The purpose of this article is to list all the data that the website may process, in particular personal data.
1- Data processed
The information collected via this website is intended exclusively for its owner; none of this information will therefore be sold or disclosed to a third party.
In accordance with the provisions of Law No. 78-17 of 6 January 1978 on data processing, files and freedoms, you have the right to access, rectify, amend and delete data concerning you.
To do so, you may contact us either:
- via the website’s contact form via le formulaire de contact du site
- by post to our postal address par courrier adressé à notre adresse postale
DATA COLLECTED
Contact form
• Purposes of data processing
o To enable the processing of enquiries submitted online
• Categories of data processed
o Surname and first name
o Email address
o Telephone number
o Full address
• Categories of data subjects
o All visitors using the contact form
• Recipients of the data
o Sommières Town Hall / Château de Sommières
• Transfers of data outside the EU
o No information will be transferred to a third party outside the European Union
• Retention period
o This data is retained indefinitely
SERVER LOG FILES
The following data is collected to ensure the proper functioning of the website and any email accounts.
Web server:
the date and time of connection
the address of the resource (page, image, etc.) requested
the IP address
the software used (“user agent”)
Technical data: protocol, standard, type of request, response returned, data size, etc.
Data retention period: 13 months
Email server:
the date and time of connection (sending and receiving)
the email address(es)
the IP address
Technical data: protocol, standard, request type, response returned, results of anti-spam and anti-virus scans, server-to-server connection data, etc.
Data retention period: 13 months
COOKIES
This data is stored on the visitor’s computer with the aim of improving the user experience and measuring the website’s audience.
Cookies necessary for the functioning of the website and the server
A session ID cookie: PHPSESSID
Created by the “HTTP server”, it temporarily identifies a unique user.
Data retention period: expires at the end of the session (2)
A load-balancing cookie: SERVERID
Created by HAProxy, it improves navigation (availability, speed) on the website.
Data retention period: expires at the end of the session (2)
Cookies for customising the user interface:
X_LANG
Created by the website, this cookie remembers the language selected by the user.
Data retention period: 12 months
X_LAST_VISIT
Created by the website, this cookie records the date of a user’s last visit.
Data retention period: 12 months
Audience measurement (‘analytics’) cookies:
_pk_ses.xxx
Created by Piwik / Matomo (1), this cookie temporarily identifies a unique user for the purpose of generating website traffic statistics.
Data retention period: expires at the end of the session (2)
_pk_id.xxx
Created by Piwik / Matomo (1), this cookie distinguishes new visitors from regular visitors in order to generate website traffic statistics.
Data retention period: 13 months
- Third-party cookies:
YOUTUBE & VIMEO
Videos from YouTube or Vimeo may be embedded on certain pages.
If the user decides to view them, cookies may be placed on their device, of which we inform them in advance.
The number, purpose and lifespan of any cookies placed by YouTube and Vimeo are the responsibility of the respective websites.
2 – Security measures for stored data
It is virtually impossible to detail all security measures, but here is a non-exhaustive list of them:
Weekly anti-virus scan of our website
Anti-spam and anti-virus scanning of incoming and outgoing emails
Strong encryption of our passwords
Restricted access rights to files
‘Least privilege’ firewall rules
HIDS (automatic blocking of attackers/suspicious behaviour/following too many failed authentication attempts).
Encrypted backups stored off-site on another server and in a different data centre
Monitoring of security vulnerabilities in our tools and bulletins issued by CERTFR
Monitoring of ANSSI best practices and recommendations
Isolation of websites and tools
...
(1) Piwik / Matomo is free and open-source web analytics software; Piwik is an alternative to Google Analytics.
Our Piwik / Matomo instance is configured to anonymise the data it collects.
(2) In IT and telecommunications, a session is a period during which a computer device – your computer – is communicating with a server – our server.
Once your connection is interrupted (logging out of the site, closing the browser, etc.), your session ends.
...