Personal data

Privacy policy

This policy describes how PromethEUs processes personal data of users and visitors of the prometheus-euro.eu website (the “Site”), in accordance with Regulation (EU) 2016/679 (GDPR).

Version 2026-07-27 Updated 27/07/2026 14 sections No advertising cookies
01

Purpose and scope

It applies to processing carried out:

  • when browsing the Site (technical data),
  • when creating and using an account,
  • when subscribing to the newsletter,
  • when publishing content (e.g. comments),
  • when implementing security and moderation measures.
02

Data controller

The entity that determines the purposes and means of the processing described below — the “controller” within the meaning of Article 4(7) GDPR — is:

Controller PromethEUs
Legal form Non-profit association governed by the French Law of 1 July 1901
Registered office
Identifiers RNA W923012514 · SIREN 108 025 065
Privacy contact
Data protection officer None appointed — appointment is not mandatory at this stage (Article 37 GDPR).

The full identity of the publisher and of the publication director is set out in the Mențiuni Legale.

03

Data processed

Data provided directly

Depending on the features used, PromethEUs may process:

  • Account: email address, username/profile name, account settings; hashed password (never in plain text).
  • Profile (optional): photo, banner, biography, links, country, date of birth (if provided).
  • Newsletter: email address, subscription/unsubscription status, technical traces related to registration.
  • Published content: comments and associated metadata (date/time, account identifier).

Note: if certain data (phone/postal address) are exchanged by email in a one-off context, they are not collected via a dedicated Site form.

Data collected automatically

When accessing the Site and for security purposes, PromethEUs may process:

  • Technical data: IP address, user-agent, timestamps, session information, technical identifiers.
  • Security data: anti-abuse events (anti-bruteforce, anti-spam, abnormal access detection), blocklists.
04

Purposes and legal bases

PromethEUs processes your data only when a legal basis exists (Article 6 GDPR).

Purpose Main data Legal basis
Account creation and managementemail, username, settingsPerformance of a contract (requested service)
Profile functionalityprofile dataContract + user choice (options)
Publishing content (e.g. comments)content, identifier, timestampContract (feature) + moderation rules
Newsletteremail, statusConsent
Service notifications (security, account)emailContract or legitimate interest (as applicable)
Security, fraud prevention and moderationIP, user-agent, eventsLegitimate interest (securing the service)
Legal obligations (if applicable)necessary elementsLegal obligation

Mandatory nature of data

  • Data required for account creation/management are mandatory to provide the service.
  • Profile data marked as “optional” are not mandatory.
  • Newsletter consent is free: refusal does not prevent use of the Site outside the newsletter.
05

Data recipients

Data are accessible:

  • to authorized members of the PromethEUs team (access limited by roles and needs),
  • to providers strictly necessary for operating the Site, acting as processors or independent controllers depending on the case.

Technical providers (examples)

  • Hosting / email: IONOS (France).
  • Site security / protection: Cloudflare (depending on configuration).
  • Mapping / third-party content: external services (tiles, APIs, video players) that may receive technical data (IP, user-agent).

PromethEUs does not sell your personal data.

06

Transfers outside the European Union

Some third-party services (e.g. online fonts, CDNs, embedded videos) may result in access to technical data (including IP address) by entities located outside the EU.

When transfers outside the EU exist, PromethEUs implements appropriate safeguards provided by the GDPR (e.g. standard contractual clauses) and seeks to limit such transfers when possible (e.g. self-hosting resources).

07

Retention periods

PromethEUs keeps data only for as long as necessary for the purposes pursued.

  • Account: as long as the account is active; deletion/anonymization when the account is closed.
  • Inactivity: an account with no login for 3 years is deleted automatically, together with the associated data. A warning email is sent 30 days before deletion; simply logging in again before that date keeps the account.
  • Deletion: after a deletion request, a technical grace period may apply (target: 30 days) before final purge/anonymization.
  • Newsletter: until consent is withdrawn (unsubscribe); minimal technical evidence of withdrawal may be retained if necessary.
  • Security/anti-abuse: short retention limited to incident handling (target: <= 30 days), unless required otherwise (disputes, attacks, legal obligations).
  • Backups: limited retention (target: <= 30 days), with progressive overwrite.

The targets above must match the settings actually in place. In case of divergence, actual practice prevails and this policy must be updated.

08

Cookies and similar technologies

The Site primarily uses strictly necessary cookies (e.g. session cookie) for operation and security.

Strictly necessary cookies

These cookies do not require prior consent (operation/security). Example:

  • Session cookie (e.g. PHPSESSID): session maintenance/authentication, “session” or short duration.

Non-essential cookies

PromethEUs does not implement advertising or audience measurement cookies to date.

If non-essential cookies are added later, a compliant consent mechanism will be deployed (with refusal as easy as acceptance).

09

Simultaneous watchers (Europe Live)

The Europe Live map shows how many people are watching it at the same time, and — only if you choose to share it — roughly which area they are watching from. These are two separate things.

The counter

No consent is required and no personal data is processed: a random, opaque token is generated for the browser tab, kept for 90 seconds, and never linked to an account. It is regenerated for every new session and deleted when the tab closes.

Sharing your area

  • Legal basis: your consent (GDPR art. 6.1.a), asked once and refused by default.
  • Source: your browser’s geolocation, which asks for its own permission. IP-based geolocation is never used — it cannot be consented to.
  • Precision: your position is rounded to a cell of about 110 km in your browser, before anything is sent. The server never receives a precise position.
  • Aggregation: only cells holding at least three watchers are shown. A cell with fewer is not displayed at all.
  • Retention: 90 seconds. Expired rows are deleted on every write.
  • No IP address is stored or read by this feature. Web server access logs record IP addresses for every HTTP request, as on any website; that is separate from this processing.
  • Withdrawal: one click in the map settings panel, exactly where you granted it. Your stored cell is erased immediately.
  • Refusing changes nothing else on the map. Only the ability to see other people’s areas depends on sharing your own.
10

Security

PromethEUs implements appropriate technical and organizational measures, including:

  • access control (roles),
  • anti-abuse protection (anti-bruteforce/anti-spam),
  • logging of sensitive actions,
  • backups and restoration procedures.
11

Your rights

In accordance with the GDPR, you have the following rights: access, rectification, erasure, restriction, objection, portability (under the conditions provided by law).

Where processing is based on your consent (e.g. the newsletter), you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR). Withdrawal is as easy as giving consent (unsubscribe link in every message or request sent to the address below).

You may also give general or specific directives on the fate of your personal data after your death, in accordance with Article 85 of French Law No. 78-17 of 6 January 1978 (“Informatique et Libertés”).

Exercise of rights: support@prometheus-euro.eu (subject: “GDPR — Exercise of rights”).

PromethEUs may request additional information to verify your identity before processing a request.

A response is provided within GDPR time limits (typically 1 month, extendable in certain cases).

12

Complaint

You may lodge a complaint with the competent supervisory authority, notably the CNIL for France.

13

Automated decision-making and profiling

PromethEUs does not carry out any automated decision-making, including profiling, producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.

The automated anti-abuse measures described in the “Security” section (anti-bruteforce, anti-spam) may temporarily restrict access to the Site; such measures may be contested at any time via the contact address given in the “Your rights” section.

14

Policy updates

PromethEUs may update this policy to reflect changes to the Site, its services, or applicable law. The update date appears in the header.

Information relating to the identity of the publisher, the publication director and the hosting provider of the Site is set out in the Mențiuni Legale.

No section matches your search. Try another word, or clear the search field.

Exercise your rights

Each option opens your email client with the right subject line already filled in, so your request reaches the right process straight away.

French, German, Spanish and English accepted.

Response within 1 month, extendable by two months where the request is complex — you are then informed, with reasons, within one month of its receipt (Article 12(3) GDPR).

Requests drafted in another official language of the Union remain admissible and are processed; translation may however lengthen the handling time.