Privacy
Privacy Policy
This policy explains what data may be processed within the framework of the Beit Haverim website and digital services, for what reasons, for how long and how to exercise your rights.
Data Controller
contact@beit-haverim.com
Beit Haverim is responsible for the data processing it determines within the framework of the operation of this website and its association tools. Certain platforms used for registration, payment, or external services may also act as data controllers or processors, depending on the service concerned.
A context involving particularly sensitive data
Given the purpose of the Beit Haverim, certain information may, depending on the context, reveal or allow inferences to be made about sensitive data, such as information relating to privacy, sexual orientation, gender identity, religious beliefs, or community membership. We exercise heightened vigilance with this information, restrict access to those who need it, and process it only when there is an appropriate legal basis for doing so. We encourage you to include in your message only the information that is truly relevant to your request.
Contact form
When you use the form, we may process your first name, last name, email address, the reason for your request, your message, the date of submission, and information necessary to follow up on the request. This data is used to respond, direct the request to the appropriate person, ensure its follow-up, and, when necessary, maintain a record of the correspondence.
Depending on the nature of the request, the processing is based on steps taken at your initiative, your consent when required, or the association's legitimate interest in responding to requests and monitoring its activities. When sensitive data is voluntarily provided, it is processed only in accordance with applicable regulations.
Anti-abuse protections can temporarily use a technical fingerprint derived from the IP address to limit automated sending. The raw IP address is not recorded with the message.
Newsletter and communications
To manage the newsletter, we primarily process your email address, the date and source of registration, confirmation status, subscription status, preferences, and information necessary for deliverability and unsubscription. Registration via the website is based on your consent and may include email confirmation.
When you have enabled engagement tracking, we can record when a campaign was opened, when a link was clicked, and the date of that interaction. This metric can be modified independently of your subscription via the preferences management link. Open statistics are indicative only, as some email clients automatically load or intermediary images.
Events, memberships, donations and AssoConnect
Registrations for events, memberships, or donations can be made on AssoConnect. The data entered on this platform is then processed according to the information provided. To facilitate association management, certain useful information can then be synchronized in the AssoConnect administration interface, such as identity, email address, the event or membership in question, the price, the number of places, the amount, the payment status, the transaction reference, and the date.
These data processing operations are for the purposes of managing registrations and memberships, welcoming participants, monitoring payments, accounting, preventing duplicate entries, and managing activities. They are based, as applicable, on the execution of measures necessary for registration or membership, the association's legal obligations, and its legitimate interest in administering its activities.
Gmail/Google Workspace Messaging and Synchronization
The association's email system is used to send transactional messages and receive certain confirmations related to Beit Haverim activities. Automated mechanisms can read messages matching specific criteria from a specially configured mailbox to identify AssoConnect links, update registrations and events in the back office, or detect newsletter non-delivery notifications. This processing is limited to the association's operational needs and is not intended to analyze the general content of the email. Raw non-delivery messages are not retained: only the status, date, affected email address, and a brief technical reason can be associated with the campaign.
Website audience measurement
The site aggregates certain page views and useful interactions to improve content. This theme-specific tracking does not use analytics cookies and does not retain any user identities, raw IP addresses, or individual browsing history. Daily counters are deleted after 400 days.
Campaign allocation
To measure whether a communication link leads to a registration, the website can store a signed token in the browser's session storage, indicating the campaign, channel, and event. This token disappears when the browser session ends. After a AssoConnect registration, a return visit to the website can help link this channel to the transaction received by the organization. For newsletters, individual linking between clicks and registrations is only performed when click tracking is enabled. Conversion tables are not intended to store the buyer's email address.
Push notifications
When push notifications are enabled and you choose to allow them in your browser or on your device, a technical service provider such as OneSignal may process a subscription ID and technical information necessary for distributing notifications. This feature is based on your choice and can be disabled in your browser or device's notification settings.
Social networks, media and external services
The site may display content or offer links from third-party services, including social networks and media outlets. When your browser communicates directly with a third-party service or when you open an external link, that provider may receive technical data such as your IP address and apply its own privacy policy.
Automatic translation
The theme's automatic translation functions are intended for editorial content to be published. They are not designed to send the content of contact forms, subscriber lists, registrations, or other personal data of visitors to a translation service.
Cookies and local storage
This theme does not use advertising or site-specific analytics cookies. Strictly necessary cookies or storage may be used for security, WordPress authentication, the operation of certain interfaces, remembering preferences, and, where applicable, push notifications. External services accessed or integrated from the site may have their own rules.
Recipients and service providers
The data is accessible to authorized Beit Haverim personnel within the limits of their duties. It may also be processed by service providers necessary for the operation of the service, including the hosting provider OVHcloud, the email services Google Workspace / Gmail, AssoConnect for registrations, memberships or payments, and, when activated, the push notification providers or the relevant social media platforms.
Transfers outside the European Economic Area
Some international service providers may process or make data accessible from countries outside the European Economic Area. When such a transfer is applicable to the service used, it must be based on a mechanism provided for by law, such as an adequacy decision or appropriate contractual safeguards. Detailed information on the mechanisms used by each provider can be found in their own policies and contractual documents.
Shelf life
- Contact messages: the time required for processing and then, unless there is a special need, a maximum of 24 months after their completion.
- Newsletter: as long as the subscription is active; after unsubscribing, the minimum information necessary to manage an objection may be kept in order to avoid accidental solicitation.
- Registrations, memberships, donations and payments: for the duration necessary to manage the activity concerned, and then according to the archiving periods required for applicable accounting, tax, evidentiary or legal obligations.
- Aggregated statistics: Maximum 400 days for daily counters.
- Technical history of the campaigns: for the time necessary to manage shipments, errors and internal analysis.
- Failures to connect to the administration: Maximum 30 days in pseudonymized form, without raw IP address or identifier entered.
Security and confidentiality
Beit Haverim implements technical and organizational measures designed to limit data access, protect administrative accounts, reduce misuse, and compartmentalize information as needed. Back-office access is restricted to authorized personnel, and sensitive functions are subject to additional safeguards whenever possible.
To detect abuse of administrative logins, the site may retain technical failure events for 30 days, including the date and a daily fingerprint derived from the IP address. Neither the raw IP address nor the entered username is recorded in this log; the fingerprint changes daily and is used only to roughly distinguish the sources of failures.
Your rights
Depending on the processing in question, you can request access to your data, its rectification, its erasure, the restriction of processing, object to certain processing, request data portability when the conditions are met, or withdraw your consent at any time when it forms the basis of the processing. Withdrawal of consent does not affect processing carried out lawfully beforehand.
To exercise your rights, contact Beit Haverim at the email address provided above or via the contact form. Identity verification may be requested when necessary to prevent data from being shared with the wrong person.
Complaint to the CNIL
If, after contacting us, you feel that your rights have not been respected, you can file a complaint with the National Commission for Information Technology and Freedoms (CNIL).
Evolution of this policy
This policy may be updated when the site, the tools used, or the processing methods change. The date of the last update is shown below.
Last updated: August 28, 2026.