Privacy Policy

1. Data Controller

The controller for personal data collected through the site is the association MUSIP – Musée de l’Info et de la Presse, 13 rue Poissonnière – 75002 Paris – France. Email: bonjour@musip.fr

2. Collected Data and Purposes

Browsing the site does not require creating an account or prior identification of the user. The site does not feature a contact form: contact links are simple “mailto:” links that open the user’s email client.

Newsletter

When a user subscribes to the newsletter, their email address is collected to manage their subscription and send them MUSIP communications.

Subscription is managed exclusively via Brevo and relies on a double opt-in procedure: the user must confirm their subscription after entering their email address.

  • Data: Last name, first name, email address, and your choice regarding mailing audience measurement.

  • Purposes: To send you the museum’s newsletter and, if you have consented, to measure email opens and link clicks to improve our mailings.

  • Legal basis: Your consent, collected via the subscription form and confirmed by a validation email (double opt-in). Consent for mailing audience measurement is separate and optional.

  • Provider: Brevo (data hosted in the European Union).

  • Retention period: Until unsubscription, which is possible at any time via the link present in each email. Inactive subscriber data is deleted after 3 years without interaction, in accordance with CNIL recommendations. You can withdraw your consent to audience measurement at any time via the link provided in each mailing.

  • Choice: Consent to mailing audience measurement can be withdrawn at any time via the link provided in each email, without unsubscribing from the newsletter.

Audience Measurement

  • Data: Pages viewed, date and time of visit, referral site (without parameters), approximate country and city, device type, operating system, browser, screen resolution, outbound link clicks and downloads, anonymized IP address (last two octets removed).

  • Purpose: To produce anonymous traffic statistics to improve the content and usability of the Site.

  • Legal basis: The museum’s legitimate interest in measuring its site’s audience. This measurement is exempt from consent in accordance with CNIL recommendations. You can object to it at any time using the module provided in Article 7.2 [Note: adjust article reference if needed depending on structure, or use the opt-out mechanism below].

  • Provider: Matomo is hosted on the Site’s servers (European Union), and no data is transmitted to third parties.

  • Retention period: Cookies valid for a maximum of 13 months; visit data retained for a maximum of 25 months, then kept solely as aggregated and anonymous statistics.

You can opt out of this tracking by unchecking the box below. Some browsers automatically delete this choice if you do not return to the Site for a certain period: please check this during your future visits.

You can opt out of being tracked on this website. This will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.

You may choose to prevent this website from aggregating and analyzing the actions you take here. Doing so will protect your privacy, but will also prevent the owner from learning from your actions and creating a better experience for you and other users.

Technical Data and Security

  • Data: IP address, connection date and time, requested pages, browser type, operating system, and device type; for security purposes, identifiers entered during login attempts to the administration area.

  • Purposes: To ensure the operation, hosting, and security of the Site, and to protect it against attacks and automated registrations.

  • Legal basis: MUSIP’s legitimate interest in ensuring the proper operation and security of its site.

  • Processing activities concerned:

    • Hosting server technical logs (IONOS): visitor IP addresses are anonymized; retained for a maximum of 8 weeks. WordPress does not log visitor connections itself;

    • Wordfence security extension: logging of security-related traffic (login attempts, blocked requests), retained for a maximum of 30 days;

    • Cloudflare Turnstile: verification, at the time the subscription form is submitted, that it is not filled out by a bot.

The Site does not feature a comment functionality.

Email Exchanges

  • Data: Email address, last name and first name where applicable, message content and replies.

  • Purpose: To respond to requests and follow up on exchanges.

  • Legal basis: MUSIP’s legitimate interest in responding to inquiries addressed to it.

  • Provider: MUSIP email hosting provider (European Union).

  • Retention period: The time necessary to process the request, then 3 years from the last exchange.

Embedded Videos

The Site embeds videos hosted by YouTube, a service provided by Google Ireland Limited. These videos are only loaded with your consent. When accepted, YouTube may set cookies and collect browsing data (IP address, device data, video interactions), which it processes for its own account and in accordance with its privacy policy. Transfers to the United States are possible. You can withdraw your consent at any time using the “Manage Consent” tab displayed at the bottom of each page.

Search Engine Optimization (SEO)

MUSIP uses Google Search Console to monitor the Site’s presence in Google search engine results. This tool does not place any cookies or other trackers on your device. It only provides access to aggregated statistics that do not identify internet users: search queries that triggered the Site, number of impressions and clicks, average position in results, concerned pages, countries, and device types. It also provides technical information regarding the crawling and indexing of Site pages.

Links to Third-Party Sites

The Site contains links to MUSIP’s pages on social media (Facebook, Instagram, LinkedIn, YouTube) and to its crowdfunding campaign on Ulule. These are simple links: no data is transmitted to these services until you click on them. Once on those sites, your data is processed by their respective publishers in accordance with their own privacy policies.

3. Recipients and Processors

Personal data is only accessible to persons and service providers who need it to fulfill the purposes described in this policy, within the limits of their duties.

For the newsletter, MUSIP uses Brevo as a technical provider for managing subscriptions and sending communications.

MUSIP uses the following providers:

  • IONOS SARL: Hosting of the Site, its backups, and the audience measurement tool (European Union);

  • Brevo (Sendinblue SAS): Newsletter management (European Union);

  • Defiant, Inc. (Wordfence): Protection of the Site against attacks (United States);

  • Cloudflare, Inc.: Anti-robot verification for the subscription form via Turnstile service (United States).

YouTube videos embedded on the Site are provided by Google Ireland Limited, which processes data for its own account and not as a processor for MUSIP.

4. Retention Periods

Personal data is kept only for the duration necessary for the purposes for which it was collected, subject to applicable legal obligations.

  • Newsletter: Until unsubscription; deletion of inactive subscribers after 3 years without interaction; after unsubscription, email address retained solely in an opt-out list;

  • Email exchanges: The time necessary to process the request, then 3 years from the last exchange;

  • Audience measurement: Cookies valid for a maximum of 13 months; visit data retained for a maximum of 25 months, then kept solely as aggregated and anonymous statistics;

  • Hosting technical logs: Maximum 8 weeks, with anonymized IP addresses;

  • Security logs: Maximum 30 days; IP address blocks are automatically lifted after their expiration duration;

  • Anti-robot verification: Data used exclusively at the time the form is submitted;

  • Strictly necessary cookies: Remembering cookie choices (Complianz), 6 months, after which the choice is requested again; remembering chosen language (Polylang), 1 year; session and security cookies for the administration area (WordPress, Wordfence), placed only for individuals logging into the Site administration and deleted at the end of the session.

5. Data Security

MUSIP ensures, along with its service providers, the implementation of appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or disclosure:

  • Encryption of communications between your browser and the Site (HTTPS protocol);

  • Regular updates of the content management system and its extensions;

  • A web application firewall and regular scans of the Site to detect malicious files or behaviors;

  • Securing access to the administration area (limiting login attempts, requiring robust passwords, rejecting compromised passwords);

  • Protection of forms against automated registrations;

  • Regular backups of the Site;

  • Authentication of emails sent on behalf of MUSIP;

  • Monitoring of the Site with alerts in the event of a security incident.

In the event of a personal data breach, MUSIP complies with documentation obligations and, where regulatory conditions are met, notification obligations to the CNIL and/or communication to affected individuals.

6. Data Transfers Outside the European Economic Area

Certain providers may, depending on their organization and subcontractors, involve data processing or transfers outside the European Economic Area. When such transfers occur, they are governed in accordance with applicable regulations.

Data processed by IONOS, including that of the Matomo audience measurement tool, remains within the European Union. Brevo, a French company, hosts newsletter data within the European Union.

Certain technical providers are established outside the European Economic Area (EEA), notably in the United States. These transfers are governed by the following appropriate safeguards:

  • Google (YouTube): Google LLC is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of July 10, 2023);

  • Cloudflare, Inc. (Turnstile): Certified under the EU-US Data Privacy Framework;

  • Defiant, Inc. (Wordfence): Transfers governed by standard contractual clauses adopted by the European Commission (Decision 2021/914 of June 4, 2021).

MUSIP will update this clause in the event of any changes to the certification status of these providers or the applicable legal framework.

7. Rights of Data Subjects

In accordance with applicable personal data protection regulations, data subjects may, depending on the processing activity concerned, exercise their rights of access, rectification, erasure, restriction, objection, and, where conditions are met, data portability.

When processing is based on consent, it may be withdrawn at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

A request may be sent to MUSIP through the contact channel indicated in this policy. Proof of identity will only be requested in case of reasonable doubt regarding the identity of the person making the request.

Every data subject also has the right to lodge a complaint with the CNIL.

8. Modification of the Privacy Policy

This policy may be updated to reflect changes to the site, processing activities performed, or applicable regulations. The date of the last update will be indicated on this page: September 24, 2026.