Privacy policy
How the Confederation processes personal data.
Last updated: to be completed — version 0.1 (draft).
1. Who is responsible for your data?
The controller of your personal data is the Universal Masonic Confederation ("Confederation HH").
Exact registered name, legal form, SIREN/RNA number and postal address: to be completed. Site: confederationhh.org.
Data Protection Officer (DPO)
For any question or to exercise your rights, contact our DPO: details to be completed (for example dpo@confederationhh.org).
2. Why we process your data, and on what legal basis
We process your data for the following purposes, each grounded in a GDPR legal basis:
| Purpose | Legal basis |
|---|---|
| Manage your account and membership (profile, lodge affiliation) | Performance of the membership contract (Art. 6(1)(b)) — to be confirmed |
| Let you communicate via internal messaging and access content | Performance of the contract / legitimate interest (Art. 6(1)(b) or 6(1)(f)) |
| Ensure security and traceability and prevent abuse | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
| Respond to your requests to exercise your rights | Legal obligation (Art. 6(1)(c)) |
Legitimate interest pursued (Art. 6(1)(f)): ensuring system security, access traceability and the prevention of abuse (anti-bot).
3. Sensitive data: your masonic membership (Article 9)
Your affiliation to a lodge reveals your masonic membership, which is a special-category ("sensitive") data within the meaning of Article 9 GDPR.
The legal basis for this processing is still to be settled by counsel, among the following options:
- Option A (Art. 9(2)(d)): the processing is carried out in the course of the legitimate activities of a not-for-profit body with a philosophical aim and relates solely to our members or former members; your membership data is not disclosed outside the Confederation without your consent.
- Option B (Art. 9(2)(a)): you give your explicit consent to the processing of your masonic membership and may withdraw it at any time, which results in the deletion of the data concerned.
Specific safeguards applied to this sensitive data
- Hosting in France (European Union): your data is stored in data centres located in Paris.
- Encryption of data, with encryption keys held by the Confederation (and not by the host alone).
- Privacy by design: your profile photo is accessible only via a temporary, secure, authorisation-gated link; no member list is publicly viewable.
- Access strictly limited to authorised persons, with an audit log of access.
- No external disclosure of your membership without a legal basis.
4. What data do we process?
Depending on how you use the site, we process the following categories of data:
- Account: email address, password (stored securely and irreversibly with Argon2id — we never know your password in clear text) and profile information.
- Avatar: your photograph, if you upload one (technical metadata, including any geolocation, is automatically stripped from the image).
- Affiliation: your lodge(s) of membership (sensitive data, Art. 9 — see section 3).
- Private messaging: the content and metadata of your internal exchanges.
- Content: articles and events you take part in.
- Security: connection data, sessions and anti-bot signals (see section 9).
5. Who has access to your data? Host and processors
Your data is accessible to authorised persons of the Confederation and to our processors, who act on our instructions:
| Processor | Role | Location |
|---|---|---|
| OVH SAS (Roubaix, France) | Hosting (servers and file storage) | France / EU — Paris |
| Dalgis Kest | Development and maintenance of the site | European Union — to be completed |
| Cloudflare (Turnstile) | Anti-bot protection of forms | To be completed (location / transfer) |
Each processor is bound by a data processing agreement (DPA) compliant with Article 28 GDPR. Your data is kept within the European Union (Paris).
6. Does your data leave the European Union?
In principle, no: your data is stored and processed in France (Paris). Exceptional maintenance or security operations could involve remote access from a country outside the European Union; such transfers are then governed by the European Commission's Standard Contractual Clauses (EU Decision 2021/914) concluded with our host. Our host is a French company and includes no US company among its group of entities able to access the data. A copy of these safeguards can be obtained from the DPO.
7. How long do we keep your data?
| Data | Duration |
|---|---|
| Account and membership data | For the duration of your membership |
| After a deletion request | Permanent deletion within 30 days |
| Security (audit) log | 730 days (about 2 years) |
| Login sessions | Until they expire |
| Messaging and content | To be completed |
8. What are your rights?
In accordance with the GDPR, you have the following rights, which you may exercise with the DPO:
- Right of access (Art. 15): obtain a copy of your data — we provide a JSON export.
- Right to rectification (Art. 16): correct inaccurate data.
- Right to erasure (Art. 17): delete your data; deletion, including your avatar, takes effect within 30 days.
- Right to portability (Art. 20): retrieve your data in a structured, machine-readable format (JSON).
- Right to restriction of processing (Art. 18).
- Right to object (Art. 21).
- Withdrawal of consent at any time, if the processing of your membership relies on your consent (Art. 7 / Art. 9(2)(a)) — without retroactive effect.
Response time: one month, extendable by two months in complex cases.
Complaint: you may at any time lodge a complaint with the CNIL — Commission Nationale de l'Informatique et des Libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
9. Cookies and anti-bot protection
- Session cookies: strictly necessary for the site to work (keeping you logged in); they do not require consent.
- Cloudflare Turnstile: at sign-up, an anti-bot device ("captcha") checks that you are not an automated program; it may process technical signals from your browser and your IP address. Details of the data sent to Cloudflare: to be completed.
- No audience-measurement or third-party cookies are used by default; any future addition would require obtaining consent.
10. Is providing your data mandatory?
- Email, password and affiliation are necessary to create and manage your member account; without this data, membership and access to member services cannot be provided.
- The avatar is optional: its absence has no effect on your membership.
- Whether the other fields are mandatory or optional is yet to be specified.
11. Automated decisions and profiling
No decision producing legal effects or significantly affecting you is taken solely by automated means, and no profiling is carried out. The anti-bot device serves only to distinguish a human from a program and does not constitute an automated decision within the meaning of Article 22 GDPR.
12. The origin of your data (Article 14)
Your data is collected directly from you (sign-up, management of your account, uploading your avatar); Article 13 GDPR applies. We do not collect your data from third parties.
13. Changes
This policy may change. Any substantial change will be notified to you. The date of the last update appears at the top of this page.