Personal data

Privacy policy

In compliance with GDPR (Regulation (EU) 2016/679) and the French Data Protection Act (loi n° 78-17 of 6 January 1978).

1. Data controller

LA RIBREAUTIÈRE SAS
3 rue de l'Aubépine, 85110 Chantonnay, France
SIREN: 940 322 209
Email: [email protected]
Phone: +33 2 52 43 10 53

For any question relating to the processing of your data or to exercise your rights, please contact us at the above address.


2. Data collected and purposes

Processing Data Legal basis Retention
Newsletter / waiting list Email, first name, intended dates, preferred cottage Consent (art. 6.1.a) Until unsubscribe
Contact form Name, email, subject, message Legitimate interest (art. 6.1.f) 3 years after last contact
Booking (post-opening) Name, email, dates, guests, payment Contract performance (art. 6.1.b) 5 years after stay
Accounting Payment data, invoices Legal obligation 10 years (art. L. 123-22 French Commercial Code)

3. Data recipients

Your data is never sold or shared with third parties for commercial purposes. It may be transmitted to the following sub-processors, who act solely on our behalf and are bound by a processing agreement compliant with art. 28 GDPR:

  • FRANCE NUAGE SAS (France, 85140 Essarts-en-Bocage): site hosting (no transfer outside EU)
  • Swikly SAS (France): security deposit management, post-opening only
  • CM2C (France): consumer mediation, only in case of dispute
  • Email service provider, to be designated: newsletter delivery
  • Accounting firm: accounting records

4. Transfers outside the European Union

No personal data transfers outside the European Union take place as part of the operation of this site. Hosting is provided in France by FRANCE NUAGE SAS, and all sub-processors listed above operate within the EU.


5. Your rights

In accordance with articles 15 to 22 GDPR, you have the following rights over your data at any time:

  • Right of access: confirm that your data is being processed and obtain a copy
  • Right of rectification: correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): request deletion of your data
  • Right to object: object to processing, particularly for prospecting purposes
  • Right to restriction: suspend the processing of your data
  • Right to portability: receive your data in a structured format

To exercise these rights: [email protected]. We respond within one month maximum.

You also have the right to lodge a complaint with the French data protection authority (CNIL):
www.cnil.fr/fr/plaintes


6. Record of processing activities (art. 30 GDPR)

In accordance with article 30 GDPR, LA RIBREAUTIÈRE SAS maintains an internal record of processing activities. The table in section 2 above is its public synthetic version. The full internal version specifies, for each processing activity:

  • Name and contact details of the data controller
  • Purposes of the processing
  • Categories of data subjects and categories of personal data
  • Categories of recipients (sub-processors listed in section 3)
  • Envisaged retention periods
  • General description of technical and organisational security measures (TOM)
  • Any transfers outside the EU (none to date)

The internal record can be shared with any data subject upon reasoned request to [email protected], subject to business confidentiality and to the personal data of other clients.

Sub-processor agreements (art. 28 GDPR)

A data processing agreement (DPA) or equivalent GDPR clauses are signed with each sub-processor listed in section 3:

  • FRANCE NUAGE SAS: hosting, DPA embedded in the service terms
  • Swikly SAS: deposit management, DPA available on their site (to be signed before the booking-mode switch in March 2027)
  • CM2C: consumer mediation, GDPR clause embedded in the membership contract
  • Email service provider (to be designated): DPA to be signed before commercial opening
  • Accounting firm: professional secrecy and applicable legal obligations

Technical and organisational measures (TOM)

  • Encryption in transit: TLS 1.2+ enforced (HSTS preload, Let's Encrypt certificate auto-renewed)
  • Encryption at rest: storage encrypted at the FRANCE NUAGE infrastructure level
  • Administrative authentication: strong unique passwords, password manager, 2FA where available
  • Least privilege: only required accounts have data access; no direct database access for sub-processors
  • Logging: application logs retained 30 days for traceability; no unnecessary personal data in plain logs
  • Backups: encrypted daily backups, retained 30 days, stored in France
  • Security updates: critical patches applied within two weeks (Rust dependencies, Docker base image)
  • Breach notification: in case of confirmed breach, notification to the CNIL within 72 hours (art. 33 GDPR) and to the data subjects when the risk is high (art. 34)

Data protection officer (DPO)

Appointing a DPO is not mandatory for our activity (art. 37 GDPR). However, the SAS president (François-Guillaume Ribreau) is the primary point of contact for any GDPR-related question: [email protected]. Should the volume of processing exceed 10,000 persons per year, the opportunity to appoint an external DPO will be reassessed.


7. Cookies

The site currently uses no third-party cookies and places no trackers requiring consent (analytics, advertising, social networks). If an audience analysis tool were added later, a consent banner would be implemented in accordance with art. 82 of the French Data Protection Act and CNIL guidelines.

Last updated: 11 May 2026