This translation is provided for information only; the French version prevails.
1. Data controller
The data controller for the personal data collected through this site is:
- Organisation
- Association Sportive et Culturelle du Centre de Colombier (ASCCO)
- Address
- Colombier, 97133 Saint-Barthélemy
- Contact email
- contact@association-ascco.com
2. Personal data collected
The informational pages of association-ascco.com use no tracking cookies, no third-party analytics tools (Google Analytics, etc.) and no advertising trackers. Simply browsing the site does not require the collection of any personal data.
However, some features — in particular the member area — require the collection and processing of personal data. Data may be collected in the following cases:
2.1 When you join the association
To join ASCCO, you are redirected to the external platform HelloAsso or to a Google form. The data you enter there (surname, first name, address, email, phone number, children's dates of birth, choice of activities, payment details) is collected and kept by ASCCO to manage your membership.
2.2 When you use the contact form
If you write to us at contact@association-ascco.com, we receive your email address and the content of your message, which we keep in order to reply to you.
2.3 Technical data (server logs)
Our server temporarily keeps (for a maximum of 30 days) technical logs containing: IP address, date and time of the request, page visited, browser type. This data is used solely for the security and proper operation of the site. It is not used for commercial or statistical purposes.
2.4 When you create and use a member account
ASCCO provides a freely accessible member area (account creation on the site), which lets you view your registrations, download your certificates, follow your activity calendar and exchange messages with the board. Creating and using this area involves processing the following data:
- Login credentials: your email address (used as your username) and your password. The password is never stored in plain text: it is protected by a cryptographic hash (Argon2id algorithm) and cannot be read, whether by ASCCO or by any third party.
- Secondary email addresses: you can link other email addresses to your account (for example the one used for a previous registration, or that of a paying parent), after verification, so that all your registrations and certificates are gathered together.
- Session and security data: each time you log in, we record your IP address, your browser type (user-agent) and the login dates. This information protects your account (detection of unusual access, limitation of attempts after repeated failures).
- Messages exchanged with the board: the content of the messages you send to the board through the member area messaging system, together with the replies you receive, is kept to follow up on your requests.
Using the member area sets a cookie that is strictly necessary for your authentication (see section 8). Details on how long this data is kept can be found in section 5.
3. Purposes of processing
Your personal data is used solely for the following purposes:
- Administrative and accounting management of your membership
- Organisation of the activities you are registered for
- Information about the life of the association (newsletter, events)
- Issuing tax receipts where applicable
- Replying to your requests sent by email
- Management of your member area: authentication, viewing your registrations, generating certificates, calendar of your activities
- Messaging between you and the board through the member area
- Security of your account and prevention of fraudulent access (login logging)
- Compliance with legal and accounting obligations
4. Legal basis for processing
The processing of your data is based on:
- The performance of the membership contract you enter into with the association
- Your explicit consent when you fill in our forms
- Compliance with legal obligations (accounting, tax)
- The legitimate interest of the association in communicating with its members
5. Retention period
- Membership data: for the whole duration of your membership, and up to 3 years after your last membership (for outreach purposes)
- Accounting data: 10 years (legal obligation)
- Emails exchanged: up to 3 years after the last exchange
- Member area account (email, hashed password, secondary addresses): for the whole lifetime of the account; deleted at your request or when you ask to close it
- Messages exchanged through the member area messaging system: kept for as long as the account exists
- Login sessions (cookie, IP, user-agent): 30 days maximum, expired sessions being purged automatically
- Technical server logs: 30 days maximum
Beyond these periods, your data is deleted or anonymised.
6. Recipients and processors
Your data is never sold or passed on for commercial purposes. It may be disclosed only to:
- The members of the ASCCO Board (president, vice-president, treasurer, secretary)
- Activity leaders (only the information needed to organise their activity)
- HelloAsso (secure online payment — HelloAsso policy)
- Google LLC (Google Forms registration form — Google policy)
- The French authorities where legally required
Note: if you fill in a HelloAsso or Google form, your data passes through their servers (potentially located outside the European Union in Google's case). If you would rather not use these services, contact us by email to join or register by other means.
7. Your rights
Under the GDPR, you have the following rights over your data:
- Right of access: to know what data we hold about you
- Right to rectification: to correct inaccurate data
- Right to erasure (“right to be forgotten”): to ask for your data to be deleted
- Right to restriction: to temporarily restrict processing
- Right to data portability: to retrieve your data in a reusable format
- Right to object: to refuse the use of your data for certain purposes
- Right to withdraw your consent at any time
To exercise these rights, write to us at contact@association-ascco.com stating your request. You will receive a reply within 1 month at most.
If you have a member account, you can also view and update some of your information directly from your account (linked email addresses, password). To have your account and the associated data deleted entirely, send your request to the email address above.
For security reasons, proof of identity may be requested for the most sensitive requests.
8. Cookies and trackers
The association-ascco.com website uses no tracking cookies, no audience analytics tools and no advertising trackers.
Only cookies that are strictly necessary for the site to work are set. These cookies are not used for tracking and do not require your prior consent, in line with the recommendations of the CNIL (French data protection authority). In practice:
ascco_member_session — session cookie set only when you log in to your member area. It keeps you logged in, contains nothing but a random session identifier (no personal data in plain text) and expires after 30 days, or immediately when you log out.
If you click on external links (Facebook, Instagram, HelloAsso, Google Forms), these third-party sites may set their own cookies. Please refer to their respective privacy policies for more information.
9. Security
ASCCO implements appropriate technical and organisational measures to protect your data against loss, unauthorised access, alteration or disclosure:
- Secure HTTPS connection (valid SSL certificate)
- Server hosted in France (Roubaix, OVH)
- Access to data restricted to board members through individual accounts
- Member area passwords stored in hashed form (Argon2id), never in plain text
- Limitation of login attempts and temporary lockout after repeated failures
- Regular backups
10. Right to lodge a complaint
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, the French data protection authority):
- Address
- CNIL — 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07
- Telephone
- 01 53 73 22 22
- Website
- www.cnil.fr
11. Changes to this policy
This privacy policy may change to reflect changes in our practices or in legislation. The date of the last update is shown at the bottom of this page.
Last updated: 21 June 2026.