PRIVACY POLICY

The purpose of this Privacy Policy is to inform you about the way in which your personal data is collected and processed. The data concerning the user that we may need to collect and process in the context of his use of the Site, are processed in accordance with:

  • The French law of January 6, 1978 as amended and the European Regulation n ° 2016/679 / EU of April 27, 2016 known as "RGPD".
  • The convention on cybersecurity and the protection of personal data adopted at the African Union summit on June 27, 2014.

We may change this Policy at any time by updating this page.
We therefore invite you to regularly consult our Policy for you ensure that you are in agreement with its terms.

SUMMARY :
1. Personal data collected
2. Purposes and legal basis of the processing of your personal data
3. Cookie Information
4. How long your personal data will be kept
5. Recipients of your personal data
6. Countries to which we transfer your personal data
7. Security of your personal data
8. Information about your rights


1. Personal data means any information about you that allows you to identify you, directly or indirectly, by reference to identification data (surname, first name, etc.) or to several elements that are specific to you.
Depending on your career path and your actions (such as: creating an online account, subscription to a newsletter), we may be led to collect, depending on the case, different types of personal data from you concerning :
- Identity data: last name, first name, civil status
- Contact data: email address, phone number, postal address, online account identifier
- Order data: transaction number and history, amount of order
- Payment data: credit card number, due date, number on the back of the card, the cardholder
- Connection data: IP address, geolocation (if accepted) express from you)
- Behavioural data: history of your purchases, browsing data on our website.

Credit card data are not processed directly but via two sub-processing providers : STRIPE and PAYPAL according to the payment methods chosen at the time of your order.

When you provide data, you undertake to communicate only that which concerns you in a personal capacity, and you guarantee that this information is accurate and does not violate any standards or infringe the interests or rights of third parties.

2. Purposes and legal basis of the processing of your personal data Only the personal data necessary for the purposes pursued are collected.

We collect and process your personal data on the basis and for the purposes set out below:
When the processing of your data is necessary for the conclusion and execution of the contract between us.
Here the legal basis is contractual necessity. The DPMR indicates more precisely on this subject that the processing is "necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the request of the data subject".
Within this framework, your personal data may be used for the following purposes:
- management of your customer account online ;
- online reservation and purchase of products ;
- management of your customer service requests;
- customer relationship management ;
- participation in contests.
In order to improve the conditions of our relations, they can also be used for these purposes:
- improvement of our website and your browsing comfort (display on our website of offers related to the products you have purchased or consulted on our website).
- Sending information related to the products and/or services you have ordered from us;
- organization of promotional operations in particular through social networks;
- realization of statistical studies.

When the processing of your data is based on our legitimate interest. The DPMR specifically states that the processing is "for the purposes of the legitimate interests pursued by the data controller or by a third party".
Within this framework, your personal data may be used for the following purposes:
- to know your preferences in order to be able to better personalize our offers, and to address
proposals that better correspond to the needs and desires of our customers

We may also be required to process your data due to a legal obligation. More specifically, the DPMR states that this processing is "necessary for compliance with a legal obligation to which the data controller is subject".

Finally, we process your data when you have given your consent, by ticking a box, accepting the collection of your data for a given purpose. More specifically, the DP Regs state that in this case "the person concerned has consented to the processing of its personal data for one or more specific purposes".
Within this framework, your personal data may be used for the following purposes:
- Email communication of offers and information from the website
There is no legal obligation for you to provide us with your personal data.
However, we draw your attention to the fact that we cannot provide you with the requested service if you do not communicate the information presented as necessary (identified by an asterisk) on our collection forms (e.g. the online account creation form).

By definition, the data not identified as necessary being optional, you are free to communicate them to us or not, but if you consent to communicate them to us, they will enable us to improve the service offered and/or to send you information likely to be of interest to you (on products and/or services similar to those you have purchased or consulted).

3. Cookie Information

What is a cookie?
A cookie is a small text file placed on your computer when you visit a site or view an advertisement. It contains information on the navigation carried out on the pages of the site. In your computer, cookies are managed by your internet browser. You can configure their use by following the procedure indicated on your browser.

What is the purpose of the cookies used by the site?
Cookies allow us to collect and recognize your browsing preferences during a subsequent visit to our site, so that it can be optimized and personalized according to your preferences. They make your interaction with our sites faster and more efficient. Cookies may also be used to provide you with advertisements related to your interests.
Here is a list of the different categories of cookies used on our site:
- Cookies required
These cookies are necessary for the operation of our site and allow you to use its main functions (such as: use of the shopping cart and other payment functions on our site, access to your customer account). Without these cookies, you will not be able to use our sites normally.

- Analytical cookies
These are cookies deposited as a result of the use on our sites of third party analysis tools (Google Analytics) that allow us to know the use and performance of our sites in the form of statistics and audience measurement in order to improve our services. These cookies are not used for commercial purposes.

How to set cookies?
You can configure your web browser at any time, in order to activate and/or disable cookies on a case-by-case basis, and/or delete those saved on your computer. Nevertheless, your navigation could be find it altered according to the settings you choose to make, by particularly if you decide to disable the necessary functional cookies. In order to manage cookies as closely as possible to your expectations we invite you to configure your browser taking into account the purpose of the cookies such as as mentioned above.

More information about cookies: on the site of the CNIL https://www.cnil.fr/fr/cookies-les-outils- pour-les-maitriser

4. How long your personal data will be kept

We keep your personal data for the duration necessary for the performance of our services and/or for the duration of the contractual relationship that unites us and/or to ensure the protection of our interests, in particular in the event of a claim or action.
Beyond this period, your personal data will either be deleted or made anonymous so that they can no longer identify you.

Below is a summary of the shelf life by type of treatment purpose.

Shelf life before deletion or anonymization :
Online customer account management -> During the period of use then 3 years from the last activity
Information on online purchases of seats, tickets, products -> 3 years to count from the transaction
Information on complaints and exercise of your rights (access, rectification, opposition, etc.) -> Duration strictly necessary for the management of your complaint

5. Recipients of your personal data

SPIADOR is the recipient of your personal data as data controller and/or our subcontractors, who may need it for the purposes for which your personal data is processed.
Access to personal data is strictly limited to SPIADOR's employees and agents, who are authorised to process them by virtue of their functions, or to third parties under contract with us for the performance of outsourced tasks necessary for the management of the service offered. Our subcontractors have limited access to the data concerning you that is strictly necessary, and they are obliged towards us to use it in accordance with the provisions of the applicable regulations.

Apart from these cases, we undertake not to sell, rent, transfer or give access to third parties to the data without your prior consent, unless we are obliged to do so for a legitimate reason (legal obligation, fight against fraud or abuse, exercise of the rights of defence, etc.).

6. Pays vers lesquels nous transférons vos données
Nous nous assurons auprès de nos prestataires qui interviennent pour la mise en œuvre de nos différents services et susceptibles d’avoir accès à vos Données pour la réalisation des services concernés, que ceux-ci assurent un niveau de protection suffisant et approprié dans l’éventualité d’un transfert de Données hors de l’Union Européenne.
Une partie de vos Données (données de paiement, relatives aux transactions effectuées auprès de nous) est susceptible d’être transférée aux Etats-Unis aux fins de réalisation de nos services de paiement par notre sous-traitant STRIPE en charge du paiement par internet. Ce prestataire est un tiers de confiance qui garantit des mesures de protection des données adéquates et utilise le Bouclier de protection des données Suisse-É.-U. reconnue par la Commission européenne comme offrant un niveau de protection adéquat aux données à caractère personnel transférées par une entité européenne vers des entreprises établies aux Etats-Unis.

Find out more about the protective shield : https://www.cnil.fr/fr/cnil-direct/question/quels- sont-les-benefices-du-…

IONOS hosts the site's database on its server in the EU.

7. Security of your personal data

SPIADOR and its subcontractors implement appropriate technical and organisational measures to guarantee a level of security in the processing of personal data. It is adapted to the risks of loss, access, modification, alteration, unauthorised disclosure or destruction thereof.
We ensure that our subcontractors present sufficient guarantees to ensure the implementation of security and confidentiality measures for the personal data to which they have access in the exercise of their missions as defined by the applicable regulations in this area.

Regarding online purchases, payments by credit card are secured by the PCI DSS protocol for STRIPE. PAYPAL uses the same protocol. No banking data is stored on our servers.
The site www.spiador.com has an SSL certificate which guarantees the encryption of the data during the transit of the data to the subcontractors in charge of the payments of the site. More broadly, the site is hosted by IONOS. It keeps the entire site database on their server. IONOS complies with the PCI DSS protocol.
The IONOS login and registration services are completed via a secure HTTPS / SSL server.

In the event of a breach of security and/or confidentiality of your personal data, a communication will be made, within the applicable deadlines, to the CNIL, as well as to your attention as the case may be.

8. Information about your rights

In accordance with the French Data Protection Act of 6 January 1978 as amended and with European Regulation n°2016/679/EU of 27 April 2016 (applicable from 25 May 2018), you have the right to access, rectify, transfer and delete your personal data or to limit the processing of your personal data. You can also, for legitimate reasons, oppose the
traitement des données vous concernant. Pour exercer vos droits vous pouvez contacter SPIADOR en charge de ces questions :
- By email to: contact@spiador.com

For any claim or complaint concerning a request to exercise a right, we thank you to indicate in the subject of your email, or your mail, the mention "Claim" or "Complaint".
In order to process your request as well as possible, please fill in your first and last name, e-mail address and attach a copy of your ID. We will answer you as soon as possible and in any case within one month to
Upon receipt of your request, which may be extended for an additional month depending on the complexity of the request.
If, however, you consider that we have not treated your personal data in accordance with the regulations in force, you have the possibility of lodging a complaint with the CNIL: https://www.cnil.fr/fr/plaintes