Privacy policy
This policy explains how MONDELICE EVASION collects, uses, protects and retains the personal data of visitors, prospects, clients and partners.
Data controller
The controller responsible for processing carried out through the website is:
No Data Protection Officer has been appointed at this time. Requests are handled directly by MONDELICE EVASION.
Personal data that may be collected
- identity data: surname, first name, title or capacity;
- contact details: email address, telephone number and postal address where necessary;
- information relating to your project: owner or traveller profile, town, property, capacity, dates, travellers, budget, requested services and message;
- business-relationship data: quotation requests, correspondence, services, contracts, invoices and payments;
- technical data: IP address, connection logs, browser, device, pages viewed and security information;
- cookie-consent preferences.
As a rule, MONDELICE EVASION does not request sensitive data. You are advised not to provide such information in free-text fields.
Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Form, email and telephone | Respond to enquiries, assess a project, prepare a quotation or arrange a discussion. | Pre-contractual measures requested by the individual and legitimate interest in responding. |
| Client and service management | Perform services, provide follow-up, communicate and handle complaints. | Performance of a contract. |
| Invoicing and accounting | Issue invoices and comply with tax obligations. | Legal obligation. |
| Marketing | Present services that may be of interest to a prospect or client. | Consent where required or legitimate interest where permitted. |
| Security and maintenance | Prevent fraud, abuse and unauthorised access. | Legitimate interest. |
| Non-essential audience measurement | Understand website use and improve its content. | Consent, except for solutions expressly exempted under the conditions set by the CNIL. |
Required nature of information
Fields identified as required are necessary to process the request. Without them, MONDELICE EVASION may be unable to respond, prepare a proposal or perform the requested service.
Recipients and processors
Data is accessible only to authorised persons within MONDELICE EVASION and, to the extent necessary for their duties, to its technical or professional service providers.
- website host and WordPress maintenance providers;
- form and email service providers;
- storage, backup, security or audience-measurement providers where enabled;
- advisers, accountant, insurer, payment provider or authorised authorities;
- partners necessary to organise a service, where required.
MONDELICE EVASION does not sell personal data.
Transfers outside the European Union
Some digital service providers or social networks may process data outside the European Union. Where such transfers occur, MONDELICE EVASION ensures that they rely on a mechanism recognised by the GDPR, such as an adequacy decision, Standard Contractual Clauses or another appropriate safeguard.
Retention periods
| Category | Indicative period |
|---|---|
| Unsuccessful contact enquiries | Up to 3 years from the last meaningful exchange, unless you object or request deletion. |
| Prospect data | 3 years from collection or the prospect’s last contact. |
| Client and contract data | For the duration of the contractual relationship, then for the applicable statutory limitation periods. |
| Invoices and accounting documents | 10 years from the end of the relevant financial year. |
| Consent and cookie preferences | For as long as necessary to evidence consent and respect the user’s choice. |
| Technical and security logs | Limited to security, diagnostic and evidentiary needs. |
Data may be retained for longer where required by law, litigation or the defence of legal rights.
Security and confidentiality
MONDELICE EVASION implements technical and organisational measures appropriate to the risks, including access restrictions, account protection, component updates, secure communications and backups.
Your rights
Under the conditions provided by the GDPR and the French Data Protection Act, you may request access, rectification, erasure, restriction, objection, withdrawal of consent and data portability where applicable, and define instructions regarding the handling of your data after your death.
Your request may be sent to contact@mondelice-evasion.fr or by post to MONDELICE EVASION, Digue Vieux Bertin, 97190 Le Gosier, France. Proof of identity may be requested only where necessary. You may also lodge a complaint with the CNIL.
Cookies and other trackers
The website may use cookies required for security, operation and consent management, as well as audience-measurement trackers or trackers linked to third-party services where enabled.
Non-essential cookies must be placed only after the user has made a positive choice. Consent may be withdrawn at any time through the website’s cookie-management module.
Social media and external links
The website contains links to MONDELICE EVASION’s Instagram, TikTok and Facebook accounts. When you click a link, you leave the website and the rules of the relevant platform apply.
Minor users
The services are primarily intended for adults. A minor should provide personal data only with the authorisation of their legal representative where required.
Policy updates
This policy may be amended to reflect legal, regulatory, technical or functional developments. The date of the latest update appears at the top of the page.