Privacy Policy
Human Sea Bridge is operated by Pont de Mer Humanitaire. We protect personal data entrusted to us through our medical, humanitarian, educational and nonprofit work, collect only what is necessary and apply enhanced safeguards to health data.
Data controller: Pont de Mer Humanitaire, French nonprofit association, RNA W294013670, SIRET 102 440 484 00016, 3 impasse Deyrolle, 29900 Concarneau, France.
Data-protection contact: contact@pontdemerhumanitaire.orgLast updated: 29 August 2026.
1. Data, purposes and legal bases
| Processing | Main data | Purpose | Legal basis |
|---|
| Contact requests | Identity, contact details, message, organisation | Reply and route the request | Pre-contractual steps or legitimate interests in managing correspondence |
| Medical or humanitarian support | Identity, family and administrative circumstances, strictly necessary medical information, consent and coordination records | Assess the situation, prepare a usable file and coordinate a realistic pathway | Explicit consent for health data; vital interests only in exceptional cases where the person cannot consent; applicable legal obligations |
| Educational support | Identity, contact details, academic record, administrative documents | Assess and coordinate continuity of study | Consent and pre-contractual steps |
| Donations, fees and memberships | Identity, contact details, amount, transaction status and reference | Process payment, issue records, keep accounts and manage the relationship | Performance of the transaction, legal obligation and legitimate anti-fraud interests |
| Volunteers, partners and applications | Identity, contact details, skills, availability, organisation | Assess the proposal and organise cooperation | Pre-contractual steps and legitimate interests |
| Newsletter | Email address and proof of consent | Send the requested updates | Consent, withdrawable at any time |
| Audience and security | Anonymised IP address, technical data and security logs | Measure use, prevent abuse and maintain the service | Legitimate interests; Matomo is configured without audience-measurement cookies |
2. Sensitive data and children
Do not send medical records through a general form. After initial contact, we provide an appropriate channel. Health data is accessible only to authorised people and is shared with a professional, hospital or institution only when necessary for the pathway and under an appropriate legal framework. For a child, we seek the legal guardian’s authority and take the child’s best interests into account.
3. Recipients and processors
Data may be received, strictly within each recipient’s role, by authorised members of the organisation; hosting, maintenance, email and fundraising providers; Stripe for payments; banking and accounting providers; and, for an individual case, the healthcare professionals, hospitals, universities, humanitarian organisations or competent authorities needed to assess it. We do not sell personal data.
4. International transfers
Some providers or partners may be outside the European Economic Area. We check the applicable mechanism, such as an adequacy decision, Standard Contractual Clauses, a GDPR derogation or another appropriate safeguard. For an international humanitarian or medical pathway, the person is informed of necessary disclosures and possible risks before consent, except where the law permits action in a vital emergency.
5. Retention
- General enquiries: up to 3 years after the last useful exchange.
- Support files: during active follow-up, then restricted archiving for up to 5 years where needed for continuity, evidence or legal claims; earlier deletion or anonymisation where possible.
- Accounting records, donations and fees: 10 years where accounting or tax law requires it.
- Unsuccessful applications, volunteers and partners: up to 3 years after the last contact; contracts and evidence for the applicable statutory periods.
- Newsletter: until consent is withdrawn or 3 years after the last interaction; proof of consent may be retained for the applicable limitation period.
- Raw Matomo data: no more than 13 months; technical and security logs: no more than 12 months unless an incident justifies longer evidential retention.
6. Your rights
You may request access, rectification, erasure, restriction and, where applicable, portability, and may object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Email contact@pontdemerhumanitaire.org or write to the address above. Proof of identity is requested only where there is reasonable doubt.
You may also lodge a complaint with the French Data Protection Authority (CNIL) or, where applicable, your local supervisory authority.
7. Security and updates
We use access controls, data minimisation, backups, encryption where appropriate and awareness measures for authorised people. If a breach presents a risk, we apply GDPR notification and communication duties. This policy may change; the date above identifies the current version.
8. Matomo audience measurement
Matomo is self-hosted and configured without audience-measurement cookies, with IP anonymisation and without advertising or cross-domain identification. You may nevertheless opt out below.
Your Matomo choice