Nuit d'Extase · Détente et Spa

Privacy Policy

Last updated:

We take GDPR and client confidentiality seriously. This page explains what we collect, why, how long we keep it, and your rights. Final details (processors, transfers, DPO) should be completed with your hosting and legal advisors before launch.

Data controller

Processing is carried out by Détente et Spa (SARL), SIRET 999 702 277 00016, as controller for Nuit d'Extase and Détente et Spa activities.

Registered office: Saint-Amand-les-Eaux (59230), France — the full registered address appears in the legal notice and in your signed-in client area.

Data protection contact: use the address on your booking confirmation or the website contact form (Contact page), with “GDPR” in the subject line.

Data collected and purposes

Booking data: identity, contact details, stay dates, amounts, payment history (necessary to perform the contract).

Technical data: cookies and logs for security and service improvement, subject to consent where required.

Marketing: email and/or SMS only with separate, explicit opt-in.

Access codes (e.g. smart lock): sent by email or SMS for your booking, based on contract performance and legitimate interest in property security.

Legal bases

Contract performance; legal obligations (invoicing, accounting); legitimate interests (security, fraud prevention); consent for marketing and non-essential cookies.

Retention

Booking and accounting records are kept as long as required by law (often several years — confirm with your accountant).

Marketing data until consent is withdrawn or after a defined period of inactivity, in line with CNIL-style practice.

Your rights

You may request access, rectification, erasure, restriction, objection, and data portability where applicable.

You may withdraw consent for marketing at any time.

You may lodge a complaint with your supervisory authority (in France: CNIL, www.cnil.fr).

Security

Appropriate technical and organisational measures are applied (HTTPS, professional hosting, data minimisation). Payment, email, SMS, and lock providers act as processors under GDPR-compliant agreements.