Privacy Policy

Human Sea Bridge is operated by Pont de Mer Humanitaire. We protect personal data entrusted to us through our medical, humanitarian, educational and nonprofit work, collect only what is necessary and apply enhanced safeguards to health data.

Data controller: Pont de Mer Humanitaire, French nonprofit association, RNA W294013670, SIRET 102 440 484 00016, 3 impasse Deyrolle, 29900 Concarneau, France.
Data-protection contact: contact@pontdemerhumanitaire.org
Last updated: 29 August 2026.

1. Data, purposes and legal bases

ProcessingMain dataPurposeLegal basis
Contact requestsIdentity, contact details, message, organisationReply and route the requestPre-contractual steps or legitimate interests in managing correspondence
Medical or humanitarian supportIdentity, family and administrative circumstances, strictly necessary medical information, consent and coordination recordsAssess the situation, prepare a usable file and coordinate a realistic pathwayExplicit consent for health data; vital interests only in exceptional cases where the person cannot consent; applicable legal obligations
Educational supportIdentity, contact details, academic record, administrative documentsAssess and coordinate continuity of studyConsent and pre-contractual steps
Donations, fees and membershipsIdentity, contact details, amount, transaction status and referenceProcess payment, issue records, keep accounts and manage the relationshipPerformance of the transaction, legal obligation and legitimate anti-fraud interests
Volunteers, partners and applicationsIdentity, contact details, skills, availability, organisationAssess the proposal and organise cooperationPre-contractual steps and legitimate interests
NewsletterEmail address and proof of consentSend the requested updatesConsent, withdrawable at any time
Audience and securityAnonymised IP address, technical data and security logsMeasure use, prevent abuse and maintain the serviceLegitimate interests; Matomo is configured without audience-measurement cookies

2. Sensitive data and children

Do not send medical records through a general form. After initial contact, we provide an appropriate channel. Health data is accessible only to authorised people and is shared with a professional, hospital or institution only when necessary for the pathway and under an appropriate legal framework. For a child, we seek the legal guardian’s authority and take the child’s best interests into account.

3. Recipients and processors

Data may be received, strictly within each recipient’s role, by authorised members of the organisation; hosting, maintenance, email and fundraising providers; Stripe for payments; banking and accounting providers; and, for an individual case, the healthcare professionals, hospitals, universities, humanitarian organisations or competent authorities needed to assess it. We do not sell personal data.

4. International transfers

Some providers or partners may be outside the European Economic Area. We check the applicable mechanism, such as an adequacy decision, Standard Contractual Clauses, a GDPR derogation or another appropriate safeguard. For an international humanitarian or medical pathway, the person is informed of necessary disclosures and possible risks before consent, except where the law permits action in a vital emergency.

5. Retention

  • General enquiries: up to 3 years after the last useful exchange.
  • Support files: during active follow-up, then restricted archiving for up to 5 years where needed for continuity, evidence or legal claims; earlier deletion or anonymisation where possible.
  • Accounting records, donations and fees: 10 years where accounting or tax law requires it.
  • Unsuccessful applications, volunteers and partners: up to 3 years after the last contact; contracts and evidence for the applicable statutory periods.
  • Newsletter: until consent is withdrawn or 3 years after the last interaction; proof of consent may be retained for the applicable limitation period.
  • Raw Matomo data: no more than 13 months; technical and security logs: no more than 12 months unless an incident justifies longer evidential retention.

6. Your rights

You may request access, rectification, erasure, restriction and, where applicable, portability, and may object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Email contact@pontdemerhumanitaire.org or write to the address above. Proof of identity is requested only where there is reasonable doubt.

You may also lodge a complaint with the French Data Protection Authority (CNIL) or, where applicable, your local supervisory authority.

7. Security and updates

We use access controls, data minimisation, backups, encryption where appropriate and awareness measures for authorised people. If a breach presents a risk, we apply GDPR notification and communication duties. This policy may change; the date above identifies the current version.

8. Matomo audience measurement

Matomo is self-hosted and configured without audience-measurement cookies, with IP anonymisation and without advertising or cross-domain identification. You may nevertheless opt out below.

Your Matomo choice

You may choose to prevent this website from aggregating and analysing the actions you take here. Doing so will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.

Payments, memberships and recurring donations through Stripe

When you make a donation, set up monthly support or pay a membership fee, we process the identity, contact, transaction and payment-status information needed to complete the payment, issue confirmations, keep our accounting records, manage the donor or member relationship and prevent fraud. Card details are entered only on Stripe’s secure hosted pages and are not stored by Pont de Mer Humanitaire.

The legal bases are performance of the requested transaction or membership agreement, compliance with our accounting and tax obligations, and our legitimate interests in securing payments and managing the relationship. Payment data is transmitted to Stripe and, where necessary, to our authorised accounting, banking, hosting and technical providers. These recipients act only within their respective responsibilities and access rights.

Transaction and accounting records are retained for the statutory periods applicable to the organisation. Operational contact and payment-status data is kept only for as long as needed to manage the donation, recurring support or membership and any related dispute. Stripe applies its own retention periods under its privacy policy. Payment, donation and membership data is not used for marketing without separate consent.

You may exercise your data-protection rights using the contact details shown on this website. You may manage or cancel monthly support through the secure Stripe customer portal.

Privacy-friendly audience measurement

We use self-hosted Matomo solely to produce anonymous statistics and improve the site. No audience-measurement cookie is placed. IP addresses are anonymised; user identification, cross-domain tracking and advertising features are disabled. You may nevertheless opt out below.

You may choose to prevent this website from aggregating and analyzing the actions you take here. Doing so will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.