Privacy Policy

As part of our commitment to data protection and transparency, you will find below essential information regarding cookies, exercising your rights, the GDPR (General Data Protection Regulation), and a FAQ to answer your main questions.

L’utilisateur est informé que des cookies peuvent s’installer sur son navigateur. Un cookie est un petit fichier que va déposer un site internet sur votre ordinateur pour y stocker des informations qui vous sont propres.

Sur ce site, des cookies sont utilisés pour analyser son audience via le service Matomo.

Dans tous les cas l’utilisateur peut librement gérer et effacer ses cookies de son navigateur. Pour ce faire, vous pouvez suivre les liens suivants en fonction du navigateur utilisé : Google Chrome, Mozilla Firefox ou Microsoft Edge.

S'opposer à la mesure d'audience

Nîmes Métropole is committed to taking all necessary measures to guarantee the security and confidentiality of the information provided by the user.

The data controller is Nîmes Métropole, represented by its President, Vincent Bouget, 3 rue du Colisée – 30947 Nîmes cedex 9.

The Data Protection Officer can be contacted by email at the following address: dpd@nimes-metropole.fr.

In accordance with the Regulation, any natural person has the right to request from the data controller access to their personal data, its rectification or erasure, or a restriction of processing concerning them, as well as the right to object to processing and the right to data portability.

These rights can be exercised at any time, upon sending proof of identity:

  • By mail : 3 rue du Colisée – 30947 – Nîmes cedex 9
  • Electronically

You also have the right to lodge a complaint with a supervisory authority.

Nîmes Métropole is committed to not selling or otherwise commercializing information and documents submitted by users through online processes, and to not disclosing them to third parties, except as required by law. Users retain full control over their submitted information and may modify or delete it at any time

The General Data Protection Regulation (hereinafter referred to as “GDPR”) has been applicable since May 25, 2018. The commitments stemming from the GDPR are part of an approach initiated by the 1995 directive. Indeed, we strive, by default, to guarantee the security of identities, property, and personal data from the very design of our activities (privacy by design).

In order to best meet the obligation of transparency, we invite our users, constituents, clients, suppliers, and other internal and external partners to review our Privacy and Personal Data Protection Policy.

Generally speaking, you can visit the nimes-metropole.fr website without providing any personal information. In any case, you are under no obligation to provide this information to Nîmes Métropole.

However, Nîmes Métropole may, in certain cases, ask you to provide your personal information.

By providing this information, you expressly consent to its processing by Nîmes Métropole for the purposes indicated below and at the end of each form.

If you refuse, you may not be able to access certain information or services you have requested.

1- Identity and contact details of the data controller

Nîmes Métropole – 3 rue du colisée 30947 NIMES CEDEX 9

2- Data collection and origin

All data concerning Users is collected directly from them.

Nîmes Métropole is committed to obtaining the consent of its Users and/or allowing them to object to the use of their data for certain purposes, whenever necessary.

In all cases, Users are informed of the purposes for which their data is collected via the various online data collection forms.

3- Types and purposes of the data collected

Nîmes Métropole may process your Personal Information to provide you with the service(s) you requested online (contact form). This data is collected via the contact form you fill out directly.

Nîmes Métropole only collects data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

4- Type of data processed

Nîmes Métropole is likely to process the following data concerning you:

  • Name, surname
  • Email address

5- Destinataires

Only Nîmes Métropole receives your Personal Information. This information, whether in individual or aggregated form, is never shared with a third party.

6- Shelf life

Your Personal Information is kept by Nîmes Métropole for as long as necessary to carry out the activities concerned, unless you request to close your account and exercise your right to be forgotten – and in compliance with and within the limits of the legal obligations to retain documents relating to these activities.

7- Use of data collected outside our platform

The data collected by our platform is never transferred or sold to third parties.

8- Data Protection and Privacy Rights

You have the following rights regarding your Personal Information, which you can exercise by writing to us at the postal address mentioned in point 1:

  • Right to information about the processing of your data.
  • Right of access and rectification.
  • Right to request the restriction of the processing of your data.
  • Right to erasure of your data.
  • Right to object to automated decision-making.
  • Right to object to the processing of your data.
  • Right to data portability.

You have the option to exercise your rights regarding this data:

  • by filling the form here and
  • by returning it, along with a document proving your identity, to the following email address: dpd[at]nimes-metropole.fr

This document will be destroyed once the request has been processed.

You can also file a complaint with the National Commission for Information Technology and Civil Liberties (CNIL). You will find all the information on the CNIL website.

1. What is the GDPR?

The GDPR is the General Data Protection Regulation. It is the new European data protection regulation that will come into effect on May 25, 2018.

This regulation aims to:

  • Protecting the privacy of European citizens
  • Unifying data protection laws within the EU
  • Redefining how companies process and manage personal data in all countries worldwide.
  • It therefore aims to ensure that personal data is acquired only with the explicit consent of each individual.

2. Who is affected?

The GDPR applies to both the public and private sectors, as well as to associations, from the moment an organization processes and uses the personal data of a resident of the European Union. It therefore applies to businesses and local authorities within the EU.

3. What is a DPO (or DPD)? What is their role?

The DPO (Data Protection Officer) is a person responsible for ensuring compliance and security of processing within the entity for which he/she has been appointed.

The DPO's role role is to:

  • Inform the organization and its employees about the GDPR
  • Ensure compliance with the GDPR
  • Serve as the point of contact with the CNIL (French Data Protection Authority)

It is mandatory for public bodies, organizations that require high levels of oversight (banks, insurance companies, etc.) but also organizations that process so-called “sensitive” data, such as health information for example.

4. What is personal data?

Personal data is “any information relating to an identified or identifiable natural person” (Article 4 of the GDPR).

Whether confidential or public, private or professional, any information that meets this definition is considered personal data.

This data can be:

  • Indirectly identifying: taken in isolation, this data does not immediately reveal who this information belongs to. However, when combined with another database, it is possible to identify a person. For example: an employee ID number, a phone number.
  • Directly identifying: data is identifying if it is associated with an element that clearly indicates the identity of the individuals. For example: last name, first name, email address, photo, etc.
  • A combination of information that allows for the identification of a person. The information alone does not allow for the direct or indirect identification of a person. However, the combination of several elements can uniquely identify a single individual. For example: a person who is a fan of video games + date of birth + practices boxing + place of residence + employer's name + enjoys jazz + place of birth + gender

5. What is sensitive data?

Sensitive data forms a specific category of personal data.

This includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.

6. What is a data controller?

The data controller is the legal entity (company, municipality, etc.) or natural person who determines the purposes and means of processing, that is, the objective and how it is achieved. Generally, this is the legal entity represented by its legal representative.

7. What is the processing of personal data?

“Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means.” (Article 4 of the GDPR)

8. What are the rights of the people concerned?

Individuals whose personal data is being processed have rights that allow them to maintain control over information concerning them.

  • The right to information
  • Obtaining consent
  • The right to object

Everyone has the right to object, for legitimate reasons, to the processing of their data, unless it is required by law (e.g., tax records).

  • The rights of access and rectification

Anyone can:

  • Access all information concerning her
  • Know the origin of the information concerning him/her
  • Access the information on which the data controller based a decision concerning him/her (for example, the factors that may have been used to deny you a promotion or the score assigned by a bank that led to the rejection of your loan application)

The right of access can be exercised:

  • In writing: by post, accompanied by a copy of an identity document. Ideally, by registered mail with return receipt requested.
  • In person: with presentation of identification. You may be accompanied by a person of your choice. The consultation must last long enough for you to take notes conveniently and completely. You may request a copy of the data.

Note:

The data controller may:

  • Refusing an access request: In this case, the data controller must provide reasons for their decision and inform the requester of the available appeal procedures and deadlines.
  • Not responding to requests that are clearly excessive, particularly due to their number, repetitive nature, or systematic character (for example, a request for a full copy of a recording every week).
  • When the data controller has no data on the individual exercising their right of access (for example, the data has been deleted or the organization has no data on the individual), they must nevertheless respond to the requester within one month.

The right of access must be exercised in compliance with the rights of third parties.

  • The right to portability

“Everyone has the right to receive the personal data concerning him or her which he or she has provided to a controller, to reuse it, and to transmit it to another controller.” (Article 20 of the GDPR).

  • In what cases can people's rights be limited?

Certain processing operations which pursue important public interest objectives may justify limiting the scope of individuals’ rights, including the right to object.