Skip to main content

RGPD

ASSOCIATION NONPOSSUMUS — NPS

Privacy Policy
& Data Protection

Version 1.0 — March 2026 Compliant with GDPR (EU) 2016/679 nonpossumus.org
⚠ Enhanced source protection NONPOSSUMUS processes data from whistleblowers and sensitive sources. Protecting the anonymity and safety of these individuals is a top priority for the association, in accordance with Article 17 of its statutes.

ARTICLE 1

Data Controller

The controller for data collected via the website nonpossumus.org is:

Association NONPOSSUMUS 11 route de Boissy — 78940 La Queue-lez-Yvelines
Represented by Boris LUTZ, President
This email address is being protected from spambots. You need JavaScript enabled to view it.

ARTICLE 2

Collected data and purposes

The association collects only the data strictly necessary for its missions. The table below details each processing activity.

Processing Activity Data Collected Purpose Legal Basis Retention Period
Membership Surname, first name, email, address, nationality, membership fee Membership management Performance of a contract Duration of membership + 5 years
Donations & support Name, email, amount, payment method Accounting and tax processing Legal obligation 10 years (accounting obligations)
Contact form Name, email, message Responding to inquiries Legitimate interest 3 years after last contact
Submitting an alert / testimony Data chosen by the user (option for total anonymity) Publication and dissemination of the alert Explicit consent Duration of publication + 1 year, unless deletion is requested
Newsletter Email address Sending information Consent Until unsubscription
Technical logs IP address, browser, timestamp Site security Legitimate interest Maximum 12 months
Digital assets (crypto donations) Wallet address, amount Accounting processing Legal obligation 10 years

No data is collected for commercial or advertising purposes. The association does not sell any personal data.

ARTICLE 3

Enhanced protection for whistleblowers and sources

ANONYMITY AND PSEUDONYMITY

Reports or testimonies may be submitted entirely anonymously. No identifying data is required. The use of a pseudonym is encouraged.

TECHNICAL PROTECTION MEASURES

  • End-to-end encryption of sensitive communications
  • Strict minimization of metadata collected during submissions
  • Servers hosted in jurisdictions offering a high level of protection
  • Access to source data restricted to the absolute minimum number of authorized individuals
  • Automatic deletion of connection logs following publication or processing

IN THE EVENT OF A JUDICIAL ORDER

In accordance with Article 17 of its statutes, the association cooperates with competent authorities only in the event of a legally grounded judicial order. It commits to defending the rights of its sources and members by all available legal means, and to notifying them to the extent possible and legally permitted.

ARTICLE 4

Data Recipients

Personal data is accessible only to:

  • Authorized members of the Executive Committee (President, Treasurer, Secretary)
  • Members of the Board of Directors in the performance of their duties
  • Strictly necessary technical service providers (hosting provider, secure payment tool), bound by contractual confidentiality obligations compliant with the GDPR

The list of donors is confidential, except with the express written consent of the donor concerned.

No data is transmitted to third parties for commercial, advertising, or political purposes.

ARTICLE 5

International Transfers

Due to the association's international scope, certain data may be processed by service providers located outside the European Economic Area. In such cases, the association ensures that these transfers are covered by appropriate safeguards (European Commission standard contractual clauses, adequacy decisions, etc.).

ARTICLE 6

Your rights

In accordance with the GDPR, you have the following rights regarding your personal data:

Right of access

Obtain a copy of the data concerning you held by the association.

Right to rectification

Have inaccurate or incomplete data corrected.

Right to erasure

Request the deletion of your data, subject to legal retention obligations.

Right to restriction of processing

Request the temporary suspension of the processing of your data.

Right to data portability

Receive your data in a structured, machine-readable format.

Right to object

Object to the processing of your data based on legitimate interest.

Withdrawal of consent

Withdraw previously given consent at any time (e.g., newsletter).

Complaint to the CNIL

Lodge a complaint with the CNIL (cnil.fr) if you believe your rights have not been respected.

To exercise these rights, contact: This email address is being protected from spambots. You need JavaScript enabled to view it.
A maximum response time of one month applies from the receipt of your request.

ARTICLE 7

Cookies and trackers

The nonpossumus.org website uses cookies in the following categories:

  • Essential cookies: indispensable for the site's operation (session, security). No consent required.
  • Audience measurement cookies: if used, only via privacy-friendly tools (e.g., self-hosted Matomo), without transmission to third parties.
  • No advertising cookies or third-party commercial trackers.

You can configure or refuse cookies via the consent banner or your browser settings.

ARTICLE 8

Data security

The association implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Strict access control to databases
  • Secure and regular backups
  • Use of decentralized and resilient infrastructure in accordance with the statutes (Mission 7)
  • Cybersecurity monitoring and regular system updates

In the event of a data breach likely to pose a risk to your rights and freedoms, the association notifies the CNIL within 72 hours and informs you as soon as possible.

ARTICLE 9

Changes to this policy

This policy may be updated to reflect changes in the association's practices or legal obligations. The date of the last update is indicated in the header. In the event of a substantial change, members will be notified by email.