Privacy policy
Last updated: 4 October 2026.
This policy explains what personal data is collected on www.pecheado.com (website, blog, booking area and newsletter), why it is collected, how long it is kept and how to exercise your rights, in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and the French “Informatique et Libertés” law of 6 January 1978, as amended.
1. Who is responsible for your data?
The data controller is the CEPS association – Centre Enseignement Pêche Sportive, publisher of the pecheado.com website:
- Registered office: Mairie de Baraize, Rue Fontaine St-Cloud, 36270 Baraize, France;
- Administrative address: 3, chemin de Saugére – Lieu-dit Chamorin, 36270 Baraize, France;
- SIRET: 411 243 058 00012;
- Telephone: +33 2 54 47 24 59;
- Contact: through our contact form.
2. What data do we collect, why, and on what legal basis?
Contact form
- Data: last name, first name, date of birth, email address, telephone number, course(s) you are interested in, message and IP address (for security purposes).
- Why: to answer your request and give you information about our camps.
- Legal basis: pre-contractual steps taken at your request and the association’s legitimate interest in replying to the people who contact it (Article 6.1.b and 6.1.f GDPR).
- Please note: your request is kept in the association’s contact management tool. Your address is recorded there and you receive a confirmation email. You can unsubscribe at any time (see section 5).
Newsletter (blog)
- Data: email address, name (optional), IP address and date of subscription.
- Why: to send you the association’s news (camps, dates, blog updates).
- Legal basis: your consent (Article 6.1.a), which you can withdraw at any time.
Blog comments
- Data: name, email address (never published), message and IP address.
- Why: to publish your comment after moderation and to fight unwanted messages.
- Legal basis: your consent and the association’s legitimate interest in protecting its blog against spam.
- Please note: your name and message are publicly visible once the comment is approved.
Booking area
- Your account: email address, password (stored in encrypted form, never readable), last name, first name, telephone number.
- The participant(s): last name, first name, date of birth, sex, telephone number, postal address, weight, height, shoe size (for equipment) and whether they have fished before.
- Camp documents: health form and other documents, signed online by the legal guardian, as well as any supporting documents you upload (for example a health record or certificates).
- Electronic signature: signer’s name and email address, declaration, date, document fingerprint, IP address, browser used and a one-time code sent by email (these items serve as proof of signature).
- Booking and payments: weeks and options chosen, amounts, due dates, payment method, transaction identifiers (never your card number) and any cancellations.
- Messaging and emails: exchanges with the association in your area and a history of the service emails sent (confirmation, deposit and balance reminders).
- Why: to register and host participants, ensure their safety and health during the camp, and manage payments, due dates and cancellations.
- Legal basis: performance of the camp contract (Article 6.1.b), the association’s legal obligations (accounting, hosting minors – Article 6.1.c), legitimate interest for account security and proof of signature (Article 6.1.f). For health data: explicit consent of the legal guardian (Article 9.2.a), given through the health form.
Security and technical logs
- Data: IP address, login attempts, request rate limiting, session identifier.
- Why: to protect the website and the booking area against attacks, fraud and automated submissions.
- Legal basis: the association’s legitimate interest (Article 6.1.f).
3. Minors and health data
Our camps are intended for children and teenagers. Information about a minor is provided by a parent or legal guardian, who creates the account and signs the documents.
Health data (health form, supporting documents) is used only to ensure the participant’s safety and care during the camp. It is accessible only to authorised persons within the association and is deleted 24 months after the end of the camp. You may ask for it to be deleted sooner.
4. Payments
Depending on the methods offered when you book, you can pay by bank transfer, PayPal, bank card (Stripe) or in instalments (Alma). Payment is processed by the provider you choose, whose own privacy policy applies. The association does not see or store your card number: it only receives confirmation of the payment, its amount and a transaction identifier.
5. Information emails, tracking and unsubscribing
Emails sent by the association (confirmations, information about camps) may contain an invisible image and tracking links that show whether the message was opened and which links were clicked, in the form of statistics for each message.
You can unsubscribe at any time using the link in each information email, or by writing to us. Your address is then placed on an exclusion list so that you are not contacted again.
6. Who receives your data?
- the CEPS association (authorised persons only);
- OVH SAS (2 rue Kellermann, 59100 Roubaix, France): hosting of the website and databases, and the mail service used to send emails;
- the payment providers (PayPal, Stripe, Alma) for online payments;
- Google: Google Maps map embedded on some pages (see the cookie policy);
- the competent authorities, where the law requires it.
Your data is neither sold nor passed on to third parties for commercial purposes.
7. Transfers outside the European Union
The website and its databases are hosted in France. Some providers (PayPal, Stripe, Google) may process data outside the European Union, under appropriate safeguards provided for by the GDPR (standard contractual clauses, adequacy decisions).
8. How long do we keep your data?
- Unconfirmed booking: automatically deleted after 24 hours. Confirmed booking with no deposit paid within the deadline: automatically deleted.
- Health data and supporting documents: 24 months after the end of the camp.
- Customer account and booking data: until your account is deleted. You can delete it yourself from your area or ask us to do so. Accounting data (amounts, due dates) may be kept without your identity to meet legal accounting obligations.
- Contacts and newsletter: until you unsubscribe or ask for deletion.
- Blog comments: for as long as the comment is published; deleted on request.
- Security logs: login attempts 7 days; request rate limiting 2 days; one-time signature codes 2 days.
- Cookie banner choice: 30 days.
9. Security
The website uses a secure connection (HTTPS). Passwords are stored in an irreversible encrypted form. The administration area is reserved for authorised persons. Forms are protected against automated submissions (honeypot field, security check, limit on the number of attempts).
10. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability regarding your data. You may also withdraw your consent at any time, without affecting processing already carried out, and give instructions on what happens to your data after your death.
To exercise your rights: write to us through the contact form mentioning “GDPR”, or by post to the administrative address given above. We may ask for proof of identity if in doubt. We reply within one month. In the booking area you can view and edit your details and delete your account.
If you believe your rights are not being respected, you may lodge a complaint with the CNIL (the French data protection authority): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France – www.cnil.fr.
11. Cookies
Details of the cookies used on this website can be found in our cookie policy.
12. Changes to this policy
We may update this policy, in particular if the way the website works changes. The date of the latest update is shown at the top of this page.