ILLE Paris takes the privacy and security of our members and event participants seriously. As a community operating in France, we handle personal information in accordance with the principles of the European Union’s General Data Protection Regulation (GDPR), including data minimization, purpose limitation, limited retention, transparency, and appropriate security.
This notice explains what information we collect, why we collect it, how we protect it, and when we delete it.
Event registration and Mobilizon
We use Mobilizon, a free and open-source event-management platform, to publish information about our events and, where registration is required, to manage RSVPs.
Information submitted through Mobilizon as part of an ILLE Paris registration is used only for administering the relevant event and related community activities. We encourage participants to read Mobilizon’s own privacy information for details about how the platform itself processes data.
Photography and Social media
ILLE Paris regularly documents its activities through photographs taken during events. Selected photographs may be published on the ILLE Paris website or our social-media accounts to document the life of the community and communicate our activities to a wider audience.
We understand that not everyone is comfortable appearing in photographs. If you do not wish to appear in photographs published by ILLE Paris, please inform the Event Chair before the event begins. We will ensure that you are not included in identifiable photographs selected for publication. If a photograph of you has already been published before issuance of this notice, and you would like us to remove it, then please contact us at ille_paris@protonmail.com.
Participant information for administrative purposes
We aim to collect only the information that is genuinely necessary for administering our community, organizing events, and meeting the security requirements of our venues. We organize two broad categories of events, and the information we process depends on the type of event:
- For open-access gatherings, such as our events at Araku Café, we do not collect any personal information.
- For events organized in collaboration with venues associated with the Embassy of India in Paris, we operate a publically documented identity pre-verification process, which requires processing our first-time attendees’ full legal name, email address, ILLE Paris Member ID (soon to be rolled out), and a copy of their valid passport or national identity document.
Why do we process this information?
Names, email addresses, Member IDs, and participation records are used for following purposes:
- maintaining our membership records
- administering event registrations
- communicating with members and registered participants
- identifying members who have already completed our identity pre-verification process
- maintaining accurate records of ILLE Paris activities
- protecting the safety and integrity of our community and events.
Where identity verification is required. e.g. at the Embassy or SVCC, passport or national ID copies are processed solely for the security and access-control procedure associated with the relevant venue.
How are names and email addresses stored?
Names, registered email addresses, Member IDs, and necessary membership and event records are maintained by the ILLE Paris Executive Council using encrypted Proton services for internal administration.
These records are not, and will never be, sold, used for commercial profiling, or shared with unrelated third parties.
Membership information is retained for as long as it remains necessary for administering the community. When membership ends, the record is reviewed and information that is no longer necessary is deleted or minimized, except where limited retention remains necessary for legitimate administrative, safety, governance, or legal purposes.
How do we handle passports and national ID documents?
First-time attendees of our events at SVCC / Embassy are required to undergo ID pre-verification, which requires submitting a copy of a valid passport or national identity document to ILLE Paris. These documents are treated with at most security. Only the ID Verification Chair has temporary access to these documents in order to facilitate access for the Embassy’s security staff. For this purpose, the document is stored temporarily on an encrypted filesystem, and deleted as soon as the Chair is notified of the verification status by the security staff. These documents are therefore not retained as part of our regular membership records.
The Embassy may independently retain these documents during its security-verification process. Any such retention is and is subject to the Embassy’s own applicable legal, administrative, and data-retention framework and outside ILLE Paris’ direct control. Participants should therefore distinguish between the temporary copy handled by ILLE Paris and any information independently retained by Embassy authorities.
Your rights
Under the GDPR, you have the right to request:
- access to the personal information ILLE Paris holds about you
- correction of inaccurate information
- deletion of information where applicable
- restriction of processing in certain circumstances
- objection to certain forms of processing.
Requests concerning personal information held by ILLE Paris can be sent to ille_paris@protonmail.com. We will confirm your identity before acting on such a request concerning personal data. In case of disputes, you also have the right to lodge a complaint concerning the handling of your personal data with the Commission nationale de l’informatique et des libertés (CNIL), the French data-protection authority.
Our Guardrails
We apply technical and organizational safeguards appropriate to the information we process. These include encrypted storage, restricted access to administrative records, temporary handling of identity documents, separation of sensitive identity documents from ordinary membership data, and deletion of passport or national ID copies once ILLE Paris no longer requires them for verification.
Access to retained personal information is restricted to authorized members of the ILLE Paris Executive Council where access is necessary for an administrative purpose. The Council also follows an internal confidentiality and responsible-use policy.
While the council follows cybersecurity best practices, we also acknowledge that no information system can provide an absolute guarantee against every possible security incident. If ILLE Paris becomes aware of a personal-data breach, we will assess it and respond in accordance with our obligations under applicable data-protection law.