Skip to main content

confidentiality

Association NONPOSSUMUS (NPS) Version 1.0 — March 2026 Compliant with GDPR (EU) 2016/679 nonpossumus.org


⚠️ Enhanced source protection NONPOSSUMUS processes data from whistleblowers and sensitive sources. Protecting their anonymity and safety is an absolute priority for the association, in accordance with Article 17 of its statutes.


Article 1 — Data Controller

The data controller for data collected via the nonpossumus.org website is:

Association NONPOSSUMUS 11 route de Boissy — 78940 La Queue-lez-Yvelines Represented by Boris LUTZ, President 📧 This email address is being protected from spambots. You need JavaScript enabled to view it.


Article 2 — Data collected and purposes

The association collects only the data strictly necessary for its missions. The table below details each processing activity.

Processing Activity Data Collected Purpose Legal Basis Retention Period
Membership Surname, first name, email, address, nationality, membership fee Member management Performance of a contract Duration of membership + 5 years
Donations & support Name, email, amount, payment method Accounting and tax processing Legal obligation 10 years
Contact form Name, email, message Responding to inquiries Legitimate interest 3 years after last contact
Submitting an alert / testimony Data chosen by the user (total anonymity possible) Publication and dissemination of the alert Explicit consent Duration of publication + 1 year, unless deletion is requested
Newsletter Email address Sending information Consent Until unsubscription
Technical logs IP address, browser, timestamp Site security Legitimate interest Maximum 12 months
Digital assets (crypto donations) Wallet address, amount Accounting processing Legal obligation 10 years

No data is collected for commercial or advertising purposes. The association does not sell any personal data.


Article 3 — Enhanced protection for whistleblowers and sources

Anonymity and pseudonymity

Whistleblowing reports or testimonies may be submitted entirely anonymously. No identifying data is required. The use of a pseudonym is encouraged.

Technical protection measures
  • End-to-end encryption of sensitive communications
  • Strict minimization of metadata collected during submissions
  • Servers hosted in jurisdictions offering a high level of protection
  • Access to source data restricted to the absolute minimum number of authorized individuals
  • Automatic deletion of connection logs following publication or processing
In the event of a judicial order

In accordance with Article 17 of its statutes, the association cooperates with competent authorities only in the event of a legally grounded judicial order. It commits to defending the rights of its sources and members by all available legal means, and to notifying them to the extent possible and legally permitted.


Article 4 — Data Recipients

Personal data is accessible only to:

  • Authorized members of the Executive Committee (President, Treasurer, Secretary)
  • Members of the Board of Directors in the performance of their duties
  • Strictly necessary technical service providers (hosting provider, secure payment tool), bound by contractual confidentiality obligations compliant with the GDPR

The list of donors is confidential, except with the express written consent of the donor concerned.

No data is transmitted to third parties for commercial, advertising, or political purposes.


Article 5 — International Transfers

Due to the association's international scope, certain data may be processed by service providers located outside the European Economic Area. In such cases, the association ensures that these transfers are covered by appropriate safeguards: European Commission standard contractual clauses, adequacy decisions, or any other mechanism recognized by the GDPR.


Article 6 — Your rights

In accordance with the GDPR, you have the following rights regarding your personal data:

Right Description
Right of access Obtain a copy of the data concerning you held by the association.
Right to rectification Have inaccurate or incomplete data corrected.
Right to erasure Request the deletion of your data, subject to legal retention obligations.
Right to restriction of processing Request the temporary suspension of the processing of your data.
Right to data portability Receive your data in a structured, machine-readable format.
Right to object Object to processing based on legitimate interest.
Withdrawal of consent Withdraw previously given consent at any time (e.g., newsletter).
Complaint to the CNIL File a complaint with the CNIL (cnil.fr) if you believe your rights have not been respected.

To exercise these rights: 📧 This email address is being protected from spambots. You need JavaScript enabled to view it. A maximum response time of one month applies from the date of receipt. of your request.


Article 7 — Cookies and trackers

The nonpossumus.org website uses cookies in the following categories:

  • Essential cookies: necessary for the site to function (session, security). No consent required.
  • Audience measurement cookies: if used, only via privacy-friendly tools (e.g., self-hosted Matomo), without data transmission to third parties.
  • No advertising cookies or third-party commercial trackers.

You can configure or refuse cookies via the consent banner or your browser settings. For more details, please consult our [Cookie Policy].


Article 8 — Data security

The association implements appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Strict access control to databases
  • Secure and regular backups
  • Use of decentralized and resilient infrastructure (in accordance with Mission 7 of the statutes)
  • Cybersecurity monitoring and regular system updates

In the event of a data breach likely to pose a risk to your rights and freedoms, the association notifies the CNIL within 72 hours and informs you as soon as possible.


Article 9 — Changes to this policy

This policy may be updated to reflect changes in the association's practices or legal obligations. The date of the last update is indicated in the header. In the event of a significant change, members will be notified by email.


Association NONPOSSUMUS — 11 route de Boissy, 78940 La Queue-lez-Yvelines — nonpossumus.orgThis email address is being protected from spambots. You need JavaScript enabled to view it.