This policy describes how PromethEUs processes personal data of users and visitors of the prometheus-euro.eu website (the “Site”), in accordance with Regulation (EU) 2016/679 (GDPR).
Version 2026-07-27Updated 27/07/202614 sectionsNo advertising cookies
PromethEUs processes your data only when a legal basis exists (Article 6 GDPR).
Purpose
Main data
Legal basis
Account creation and management
email, username, settings
Performance of a contract (requested service)
Profile functionality
profile data
Contract + user choice (options)
Publishing content (e.g. comments)
content, identifier, timestamp
Contract (feature) + moderation rules
Newsletter
email, status
Consent
Service notifications (security, account)
email
Contract or legitimate interest (as applicable)
Security, fraud prevention and moderation
IP, user-agent, events
Legitimate interest (securing the service)
Legal obligations (if applicable)
necessary elements
Legal obligation
Mandatory nature of data
Data required for account creation/management are mandatory to provide the service.
Profile data marked as “optional” are not mandatory.
Newsletter consent is free: refusal does not prevent use of the Site outside the newsletter.
05
Data recipients
Data are accessible:
to authorized members of the PromethEUs team (access limited by roles and needs),
to providers strictly necessary for operating the Site, acting as processors or independent controllers depending on the case.
Technical providers (examples)
Hosting / email: IONOS (France).
Site security / protection: Cloudflare (depending on configuration).
Mapping / third-party content: external services (tiles, APIs, video players) that may receive technical data (IP, user-agent).
PromethEUs does not sell your personal data.
06
Transfers outside the European Union
Some third-party services (e.g. online fonts, CDNs, embedded videos) may result in access to technical data (including IP address) by entities located outside the EU.
When transfers outside the EU exist, PromethEUs implements appropriate safeguards provided by the GDPR (e.g. standard contractual clauses) and seeks to limit such transfers when possible (e.g. self-hosting resources).
07
Retention periods
PromethEUs keeps data only for as long as necessary for the purposes pursued.
Account: as long as the account is active; deletion/anonymization when the account is closed.
Inactivity: an account with no login for 3 years is deleted automatically, together with the associated data. A warning email is sent 30 days before deletion; simply logging in again before that date keeps the account.
Deletion: after a deletion request, a technical grace period may apply (target: 30 days) before final purge/anonymization.
Newsletter: until consent is withdrawn (unsubscribe); minimal technical evidence of withdrawal may be retained if necessary.
Security/anti-abuse: short retention limited to incident handling (target: <= 30 days), unless required otherwise (disputes, attacks, legal obligations).
Backups: limited retention (target: <= 30 days), with progressive overwrite.
The targets above must match the settings actually in place. In case of divergence, actual practice prevails and this policy must be updated.
08
Cookies and similar technologies
The Site primarily uses strictly necessary cookies (e.g. session cookie) for operation and security.
Strictly necessary cookies
These cookies do not require prior consent (operation/security). Example:
Session cookie (e.g. PHPSESSID): session maintenance/authentication, “session” or short duration.
Non-essential cookies
PromethEUs does not implement advertising or audience measurement cookies to date.
If non-essential cookies are added later, a compliant consent mechanism will be deployed (with refusal as easy as acceptance).
09
Simultaneous watchers (Europe Live)
The Europe Live map shows how many people are watching it at the same time, and — only if you choose to share it — roughly which area they are watching from. These are two separate things.
The counter
No consent is required and no personal data is processed: a random, opaque token is generated for the browser tab, kept for 90 seconds, and never linked to an account. It is regenerated for every new session and deleted when the tab closes.
Sharing your area
Legal basis: your consent (GDPR art. 6.1.a), asked once and refused by default.
Source: your browser’s geolocation, which asks for its own permission. IP-based geolocation is never used — it cannot be consented to.
Precision: your position is rounded to a cell of about 110 km in your browser, before anything is sent. The server never receives a precise position.
Aggregation: only cells holding at least three watchers are shown. A cell with fewer is not displayed at all.
Retention: 90 seconds. Expired rows are deleted on every write.
No IP address is stored or read by this feature. Web server access logs record IP addresses for every HTTP request, as on any website; that is separate from this processing.
Withdrawal: one click in the map settings panel, exactly where you granted it. Your stored cell is erased immediately.
Refusing changes nothing else on the map. Only the ability to see other people’s areas depends on sharing your own.
10
Security
PromethEUs implements appropriate technical and organizational measures, including:
In accordance with the GDPR, you have the following rights: access, rectification, erasure, restriction, objection, portability (under the conditions provided by law).
Where processing is based on your consent (e.g. the newsletter), you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Article 7(3) GDPR). Withdrawal is as easy as giving consent (unsubscribe link in every message or request sent to the address below).
You may also give general or specific directives on the fate of your personal data after your death, in accordance with Article 85 of French Law No. 78-17 of 6 January 1978 (“Informatique et Libertés”).
PromethEUs may request additional information to verify your identity before processing a request.
A response is provided within GDPR time limits (typically 1 month, extendable in certain cases).
12
Complaint
You may lodge a complaint with the competent supervisory authority, notably the CNIL for France.
13
Automated decision-making and profiling
PromethEUs does not carry out any automated decision-making, including profiling, producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR.
The automated anti-abuse measures described in the “Security” section (anti-bruteforce, anti-spam) may temporarily restrict access to the Site; such measures may be contested at any time via the contact address given in the “Your rights” section.
14
Policy updates
PromethEUs may update this policy to reflect changes to the Site, its services, or applicable law. The update date appears in the header.
Information relating to the identity of the publisher, the publication director and the hosting provider of the Site is set out in the Juridisk information.
No section matches your search.Try another word, or clear the search field.
Exercise your rights
Each option opens your email client with the right subject line already filled in, so your request reaches the right process straight away.
Response within 1 month, extendable by two months where the request is complex — you are then informed, with reasons, within one month of its receipt (Article 12(3) GDPR).
Requests drafted in another official language of the Union remain admissible and are processed; translation may however lengthen the handling time.