Privacy Policy
Your privacy matters. This policy explains transparently what data we collect, why, how long we keep it and how you can exercise your rights.
The essentials in a few lines
- We only collect data strictly necessary for your account (first name, last name, email, hashed password).
- Your data is never sold, rented or shared with third parties.
- The website uses no advertising or analytics cookies: only a technical session cookie is set.
- You can access, rectify, export or delete your data at any time upon request.
- For any question: contact@about-sxm.com
Preamble
This privacy policy supplements the legal notice of the website. Its purpose is to inform users clearly, fairly and transparently of the conditions under which their personal data is collected and processed on the website published under the brands About SXM and Guide Saint-Martin.
It complies with the following texts:
- Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data ("GDPR");
- French Data Protection Act no. 78-17 of 6 January 1978 ("Loi Informatique et Libertés");
- Directive 2002/58/EC of 12 July 2002 ("ePrivacy");
- Guidelines and recommendations of the French data protection authority (CNIL).
Effective date: April 24, 2026. Last updated: October 1, 2026.
Data controller
Within the meaning of article 4.7 of the GDPR, the data controller is the website publisher (see Legal notice, §1). The controller alone determines the purposes and means of the processing activities carried out.
The website has not appointed a Data Protection Officer (DPO), as this appointment is not mandatory under article 37 of the GDPR given the nature and volume of processing activities. Any request may nevertheless be sent directly to the publisher at contact@about-sxm.com.
Our data processing activities
The website carries out the processing activities listed below. No processing of so-called "sensitive" data within the meaning of article 9 of the GDPR (health, political opinions, religious beliefs, sexual orientation, etc.) is performed.
| Processing | Data | Purpose |
|---|---|---|
| User account | First name, last name, email, password (bcrypt-hashed), creation/modification dates, email verification status | Creation and management of the members' area, secure authentication |
| Email verification | Email, unique temporary token, timestamp | Validating the email address at registration |
| Password reset | Email, temporary token, expiry timestamp | Enabling secure recovery of lost access |
| Login session | Session identifier (technical session cookie) | Maintaining authentication during browsing |
| Email contact | Email, message content | Handling your request, answering your questions |
| Newsletter | Email, language, accepted consent text, sign-up page, anonymized IP address, sign-up, confirmation and unsubscribe dates | Sending you the website newsletter, only if you requested and confirmed it |
| Technical logs | IP address, timestamp, HTTP request, user-agent | Security, intrusion detection, legal obligations |
Newsletter
You only subscribe at your own request, through the form at the bottom of every page, by ticking a box that is never pre-ticked. A confirmation email is then sent to you: your address is only subscribed after you click the button it contains (double opt-in). Without confirmation, it is automatically deleted after 7 days.
To prove your consent, we keep the date of your subscription and confirmation, the exact text you accepted, the page you subscribed from and your anonymized IP address (its last part is erased).
Every email contains a one-click unsubscribe link. After you unsubscribe, your address is kept for 3 years in an opt-out list, so that we never write to you again, then deleted. You can also contact us to exercise your rights (access, rectification, erasure).
Legal bases for processing
Each processing activity is based on one of the legal grounds set out in article 6.1 of the GDPR:
- Performance of a contract or pre-contractual measures (art. 6.1.b): creation and management of the user account, authentication, password reset.
- Legitimate interest (art. 6.1.f): securing the website (logs, fraud detection), service improvement, responding to email inquiries. This legitimate interest is balanced against the rights and freedoms of data subjects and does not override their interests.
- Legal obligation (art. 6.1.c): retention of certain technical logs to respond to requests from judicial authorities (art. 6-II of the French LCEN, decree no. 2011-219).
- Consent (art. 6.1.a): newsletter subscription, and any further processing not covered by the above bases. Consent is freely given, specific, informed and unambiguous (box never pre-ticked and double opt-in by email) and may be withdrawn at any time, in one click, from every email.
Recipients of the data
Internal access
Only the publisher has access to the data, strictly limited to what is necessary for the performance of editorial and technical duties.
Processors
In accordance with article 28 of the GDPR, certain technical service providers act as processors, under the responsibility and documented instructions of the publisher:
- Host: IONOS SARL (France, EU), hosting of the website and database.
- Email provider: IONOS SARL (France, EU), used for verification, password reset and newsletter confirmation emails. Data transmitted is limited to the email address and content strictly necessary.
Each processor provides sufficient guarantees regarding the implementation of the technical and organisational measures required by the GDPR. A processing agreement compliant with article 28.3 of the GDPR governs their involvement.
Legally authorised authorities
Data may be disclosed to judicial, administrative or prosecution authorities upon duly issued legal requisition (article 6-II of the LCEN).
No commercial transfer
Your data is never transferred, rented or sold to third parties for commercial, advertising or prospecting purposes.
Transfers outside the European Union
Data is processed and stored within the European Union (IONOS hosting – Sarreguemines, France).
No data is currently transferred to a country outside the European Economic Area (EEA). Should such a transfer become necessary in the future, it would only be carried out in the presence of:
- an adequacy decision of the European Commission (art. 45 GDPR), or
- appropriate safeguards such as standard contractual clauses (art. 46 GDPR), or
- one of the derogations set out in article 49 GDPR.
Users would be informed through an update of this policy.
Retention periods
In accordance with the storage limitation principle (art. 5.1.e of the GDPR), data is kept only for the period strictly necessary for the purposes pursued:
| Data | Duration |
|---|---|
| Active account | As long as the account is not deleted by the user |
| Inactive account | Archived after 3 years of inactivity, then deleted |
| Email verification token | 24 hours (deleted after use or expiry) |
| Password reset token | 1 hour (deleted after use or expiry) |
| Session cookie | Browser session (deleted on close) |
| Technical logs (IP, requests) | Maximum 1 year (CNIL guidance) |
| Email correspondence (contact) | 3 years from last contact |
| Unconfirmed newsletter subscription | 7 days, then automatic deletion |
| Newsletter subscriber | Until unsubscription |
| Address unsubscribed from the newsletter (opt-out list) | 3 years after unsubscription, then deletion |
| Encrypted technical backups | Maximum 30 days rolling |
At the end of these periods, data is either securely deleted or irreversibly anonymised for statistical purposes.
Data security
The publisher implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks (art. 32 GDPR), in particular:
- Password hashing using the bcrypt algorithm (PHP
password_hashfunction): passwords are never stored or transmitted in clear text; - Encrypted HTTPS connection (TLS) for all exchanges between the browser and the server;
- Single-use, time-limited tokens for email verification and password reset;
- Protection against SQL injection (prepared statements) and against CSRF and XSS attacks;
- Database compartmentalisation and strict control over administrator access;
- Regular encrypted backups enabling restoration in the event of an incident;
- Regular updates of software components and security patches.
Data breach
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, the publisher will notify the CNIL within 72 hours (art. 33 GDPR) and, if the risk is high, inform the data subjects as soon as possible (art. 34 GDPR).
Protection of minors
In accordance with article 8 of the GDPR and article 45 of the French Data Protection Act, the direct offer of information society services to a minor is lawful only where the minor is at least 15 years old. Below this age, consent must be given jointly by the minor and the holder of parental responsibility.
The website is not specifically aimed at minors. If you are under 15, you must not create an account without the permission of a parent or guardian. If we learn that an account has been created by a minor under 15 without parental authorisation, it will be deleted without delay.
Changes to this policy
This privacy policy may evolve to reflect legislative, regulatory, technical or organisational changes. Any substantial change will be brought to users' attention:
- through an update of the effective date and last updated date at the top and bottom of the document;
- where applicable, through direct notification (information banner or email) if the changes significantly affect your rights.
We recommend that you check this page regularly.