Personal data

As a user of this Website (“user”), you are informed that, for a simple visit of the Website, the only personal data processed, if any, is the one processed for Cookies.

If you use the forms made available or avail yourself of services provided by us through this Website, we collect and use your personal data to respond to you and to provide you with these services.

We are careful to protect your privacy in carrying out this processing of your personal data.

We present all the information relating to the processing of your personal data, your rights and how to exercise them.

Data controllers

As the registry for the « .paris » domain name extension, the City of Paris implements the processing of personal data of users with Afnic, its service concessionaire for the management of « .paris »; the City of Paris and Afnic are joint data controllers.

The City of Paris (DICOM, City of Paris, 4, rue de Lobau, 75196 PARIS CEDEX 04 – France) and Afnic can be contacted at the following coordinates:

The French Association for Internet Naming in Cooperation (Afnic) 

Association governed by the law of July 1, 1901 

Registered with the Yvelines Prefecture under number 0784012789 

Intra-Community VAT number FR72414757567 

Headquarters located at 7 avenue du 8 mai 1945, 78280 Guyancourt, France

Email: support@afnic.fr 

Phone: 01-39-30-83-00

Principles & Commitments 

In the context of your use of the Website, we implement personal data processing in accordance with the international rules in force regarding domain names (rules defined by the stakeholders within the Internet Corporation for Assigned Names and Numbers (ICANN)) and in compliance with the applicable provisions for the protection of personal data, and in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 applicable from 25 May 2018 (hereinafter the “General Data Protection Regulation” or “GDPR”).

Always available in the Website footer, we publish the pages “Personal data” and update them as and when necessary, to provide information relating to the processing of data of users of the Website so as to ensure information and transparency regarding this processing.

Your personal data are processed in a manner that ensures appropriate security in compliance with the legal framework relating to the protection of personal data, which are collected lawfully, fairly and in a transparent manner for specified, explicit and legitimate purposes and are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. These accurate, complete and where necessary updated data are kept for as long as necessary for the said purposes. 

We limit its processing of personal data to what is strictly necessary and clearly indicates for each processing operation:

  • Its purpose;
  • Its lawful basis;
  • Its duration;
  • The categories of data processed;
  • Whether the data are collected directly or indirectly;
  • Whether the data collected are mandatory or optional;
  • Their recipients;
  • Any transfers outside the European Union (EU) with measures to adequately protect your data.

We do not process your data for automated decision making, including profiling. We do not further process your data for a purpose other than those defined in this page.

Exercise of your rights and freedoms

It’s simple! 

1. Your rights
As a data subject of at least one processing operation of the data of users of the Website, you have rights and freedoms, namely the rights of access, objection, rectification and erasure of the data, the right to restrict processing, the right to withdraw your consent, if given, at any time, the right to lodge a complaint with a supervisory authority and the right to lay down guidelines for the retention, erasure and communication of personal data in the event of death.

2. Exercise your rights – Contact the DPO (Data Protection Officer)

Any request for information and/or any other exercise of your rights under the French Data Protection Act regarding the personal data processing defined and listed herein, shall be made as follows:

By email to dpo@afnic.fr

By post to:

Association Française pour le Nommage Internet en Coopération

A l’attention de la Déléguée à la protection des données

7 avenue du 8 mai 1945

78280 Guyancourt

France

List of processing operations 

1. The list

The personal data processing operations carried out on the Website are the followings:

  • The website and newsletters
  • Social networks
  • Management of abuse and disputes in .paris 
  • Requests for disclosure of personal data in .paris
  • Handle injunctions and orders for domain name operations in .paris
  • Personal rights and freedoms
  • Information systems security management (ISS)
  • Management of alerts under the French Data Protection Act and notifications of personal data breaches

The description of each processing operation is available to you in the dedicated entries below or directly via the interactive table of contents.

For processing of personal data of holders of .paris domain names, we invite you to consult the information relating to the processing of holders’ data.

>> Find out more about the processing of holders’ data

2. Understanding the description of a processing operation

In order to provide comprehensible and simple access, we present the information relating to each processing operation in the form of a fact sheet in accordance with the following model:

Name of the processing operation

1. Purpose: we process your data for specified, explicit and legitimate purposes

2. Lawful basis: The processing is necessarily on one of the following lawful bases:

  • Your consent (Article 6-1 (a) of the GDPR) 
  • In performance of a contract with the data subject or in preparation for such contract (Article 6-1 (b) of the GDPR)
  • In compliance with legal obligations (Article 6-1 (c) of the GDPR)
  • To protect your vital interests or those of a third party (Article 6-1 (d) of the GDPR)
  • In the performance of a public service role (Article 6-1 (e) of the GDPR)
  • For the pursuit of our legitimate interests or those of a third party, while respecting your interests or fundamental rights and freedoms regarding the protection of your personal data (Article 6-1 (f) of the GDPR)

3. Duration not exceeding that necessary for the purposes defined; this total duration is the duration of active retention plus that of subsequent retention in the archives

4. Categories of data processed adequate, relevant and limited to what is necessary in relation to the purposes defined (data minimisation)

5. How the data are collected:

  • Direct collection, the data are collected from you 
  • Indirect collection, the data are collected from a third party identified and authorised to communicate your data to us

6. Nature of the data: they may be required (pursuant to a legal requirement, for a contract, etc.) or optional, in many cases with consequences if they are not provided.

7. Recipients: the natural or legal person, public authority, department or any other body that receives communication of your data, whether or not from a third party

8. Transfers outside the EU: this refers to the possibility of your data being transmitted to a recipient in a third country or an international organisation subject to adequate protection measures. A copy of these measures can be sent to you upon request to dpo@afnic.fr

The description of each processing operation is available to you in the dedicated entries below or directly via the interactive table of contents.

Management of the website and newsletters

1. Purpose

Administrative processing of the website and newsletters allows us to:

  • Communicate about the «.paris» extension: registry policies, FAQs, news, blogs, testimonials, guides, presentation of domain names, extensions, presentation of the registration procedures in .paris, presentation of accredited registrars, consultation of the Whois/RDAP database… 
  • Manage subscriptions (registration/unsubscription) and newsletters (routing and audience measurement) 
  • Manage requests made via the contact form or by email

2. Lawful basis: Consent (Article 6.1.a of the GDPR) given by subscribing to the newsletter and/or by a contact request via a form or by email

In execution of a contract (art. 6 – 1. b/ of the RGPD) i.e. the general and special conditions of the website relating to the service used

3. Duration: 

1/ At the end of one year following the end of the processing of the request expressed in the form or email. 

In case of dispute, retention for the entire duration of the dispute until the exhaustion of all legal remedies.

2/ Newsletter. End of sending upon unsubscription. Opt-out management: by unsubscribing. Retention of opt-outs for 2 rolling years. Once a person is unsubscribed, they no longer appear in the active contacts database. Retention for 3 years plus the current year.

3/ Removal of publication from the Website upon request and as of the date of its implementation without retroactive effect given the nature of the web

4. Categories of data processed

1/ Via the contact form First name/Last name, email address, subject, and message of the contact request Exchanges following the request

2/ Via the newsletter subscription Email address, language Routing data and audience measurements: from the first sending, a user profile is created with an activity log that tracks part of their activities (opening, reading time, clicks, and unsubscription). Audience measurement (behavioral tracking): The option is unchecked in Preferences to not collect information and to generate anonymized statistics

3/ Via the published content: first name/last name, profession, testimonial, photo…

5. How the data are collected: Direct collection

6. Nature of the data: Necessary for the provision of the communication services concerned

7. Recipients:

For the hosting of the website: Ecritel, 84 Rue Villeneuve, 92110 Clichy, registered with the Nanterre Trade & Companies Register under No 332 484 021 https://www.ecritel.fr/fr/

For the management, maintenance of the website and Afnic’social networking: SPINTANK, 32 Rue Alexandre Dumas, 75011 Paris – SIRET 490 067022 00049 – https://spintank.fr/

For the routing of newsletters/e-mails and audience measurements: Sarbacane Software, 3 avenue Antoine Pinay, Parc d’activités des 4 vents, 59510 Hem, France registered with the Lille Métropole Trade & Companies Register under No. 509 568 598 – https://www.sarbacane.com

Provider for video hosting on YouTube (service provided by Google LLC via Google Ireland Limited, company under the Irish laws société de droit irlandais (Numéro d’immatriculation : N°368047/Numéro de TVA AVT N°: IE6388047V) Gordon House, Barrow Street Dublin 4 Irlande): autonomous data controller whose Privacy Policy is published at this address: https://policies.google.com/privacy?hl=fr

8. Transfers outside the EU

No, apart from what is published on the website which is by its nature accessible without territorial limit

Management of .paris social media accounts

1. Purpose

The administrative processing of its social network accounts allows us to:

  • Administer the accounts technically (creation, publications) 
  • Use social networks to access our content published on these networks 
  • Interact (publicly or through private messaging) with subscribers and other users of the platforms 
  • Increase the visibility and notoriety of the .paris extension.
  • Prepare usage statistics

2. Lawful basis: For the pursuit of the legitimate interests of Afnic and the City of Paris in respect of the freedoms and fundamental rights relating to the protection of personal data (Article 6-1 (f) of the GDPR)

3. Duration: The data are stored for as long as the social network concerned exists, unless the user exercises the right of erasure or objection. 

We do not configure and do not have data concerning you from the accounts and cookies operated by social networks. Consequently, only those responsible for these networks can respond to technical requests concerning the cookies used and the exercise of your personal rights.

4. Categories of data processed: Data visible by default on social networks. Data made public by the user in the context of the configuration of his or her account on each of the social networks. Data on use of the social network for the production of anonymous statistics

5. How the data are collected: Direct and indirect collection

6. Nature of the data: Necessary in the case of voluntary access by the user to our available content and interaction with the user

7. Recipients: For information publicised by the user, the public at large; otherwise only authorised persons in Afnic and the City of Paris

8. Transfers outside the EU: No, apart from what is published on social networks which is accessible without territorial limit. The data needed to prepare statistics may be processed outside the European Union, depending on the data management policy put in place by the person responsible for each social network.

Management of abuse and disputes in .paris

1. Purpose

Managing abuse and dispute cases in .paris allows us to: 

1/ Manage requests related to abuse and disputes in .paris:

  • Management and processing of abuse reports: eligibility and compliance checks with .paris registry policies, cybersquatting reports, etc.
  • Fast-track suspensions under the URS procedure.
  • Management and processing of requests under alternative dispute resolution procedures.

2/ Monitor domain names registered during election periods to detect and manage abuse:

  •     Identify existing domain names using the name of a declared or potential candidate.
  •     Daily detection of new registrations using the name of a political figure.
  •     Classify domain names (OK / To monitor / Problematic).
  •     Enable escalation, in case a problematic domain name is detected, to quickly manage the identified abuse.

2. Lawful basis: In performance of a contract (Article 6 – 1. b/ of the GDPR) => .paris registry policies.

3. Duration: 

1/ Management of requests related to abuse and disputes in .paris: Data is retained by Afnic for the duration of the contract with the City of Paris, .paris registry, and by ICANN. In case of judicial or extrajudicial proceedings, data is retained by Afnic until the end of the procedure plus the legal prescription period. 

2/ Monitoring of domain names registered during election periods to detect and manage abuse: Data is retained throughout the election period, then deleted no later than 6 months after the elections in question in Paris. In case of implementation of one of the dispute resolution procedures, the durations defined above in 1/ are applied.

4. Categories of data processed: 

1/ Management of requests related to abuse and disputes in .paris 

For the applicant: First name, last name, email address, company name, phone number, postal address, report. 

For the holder of the disputed domain name: Domain name, personal data of the holder recorded in the whois database and those exchanged during the abuse & dispute procedure, operations on the domain name. 

2/ Monitoring of domain names registered during election periods to detect and manage abuse: 

For the political figures concerned by the election period: first name, last name, or other identifier used in the domain name (e.g., year, political party). 

For the holders of .paris domain names registered during the election period: Creation date, Registered .paris domain name, registrar name, Holder type (individual/organisation), First and last name of the holder (if an individual), Company name (if a legal entity) , NIC handle, Analysis of the domain name risk (OK / To monitor / Problematic), Comments, Domain name usage: example website

5. How the data are collected: 

1/ Management of requests related to abuse and disputes in .paris: Direct collection for the applicant and indirect collection for the holder of the disputed domain name

2/ Monitoring of domain names registered during election periods to detect and manage abuse: Indirectly via the registrars (.paris Extranet) and web consultation.

6. Nature of the data: Necessary for the purposes

7. Recipients: Internal services in charge of the Abuse & Dispute procedure. City of Paris (.paris registry, data controller). Alternative dispute resolution bodies. Registrars concerned by the disputed domain names.

Management of requests for disclosure of personal data in .paris

1. Purpose

The administrative processing of requests for disclosure of personal data or lifting of anonymity allows us to: 

  • Reveal the identity and contact details of a private individual domain name holder subject to restricted publication 

-> upon well-grounded request of a third party for the pursuit of the applicant’s legitimate interests, while respecting the holder’s interests or fundamental rights and freedoms regarding the protection of his/her personal data (Article 6-1 (f) of the GDPR) ; 

-> in response to the exercise of a communication right in compliance with legal obligations and/or public service role (Article 6-1 (c) & Article 6-1 (e) of the GDPR) authorizing investigative powers of public authorities

  • Manage requests and generate statistics

2. Lawful basis:

For third-party applicants, in performance of a contract (Article 6 – 1. b/ of the GDPR) => the application form. 

For .paris domain name holders, in performance of a contract (Article 6 – 1. b/ of the GDPR) => .paris registry policies and in particular those of ICANN on the processing of personal data. 

For representatives of public authorities, in performance of a public service mission or legal obligations (Article 6 – 1. c/ of the GDPR), i.e., the legal basis for investigative powers and the right of communication exercised.

3. Duration: Six months, then deleted

4. Categories of data processed: 

The data identifying the applicants and their representatives. 

In the case of applicant’s legitimate interests: The data contained in the form and in documents attached thereto. The processing of the form. The data identifying the domain name holder in respect of whom the request is made.

In response to the exercise of a communication right: The data contained in the request and in documents attached thereto. The identifying data provided by the domain name holder in respect of whom the request is made: data identifying the holder. 

The administrative and operational data on the domain name concerned for the public authorities in application of the law or for third parties in application of a court ruling.

5. How the data are collected: Direct collection except for the registrant’s data which is an Indirect collection of data collected from the registrar

6. Nature of the data: For applicants: obligatory, since without the data the request cannot be processed. For holders: erroneous identification data can lead to procedures calling their portfolio of domain names into question in application of the .paris registry policies.

7. Recipients

Regarding applicant’s personal data: The internal Afnic departments concerned.

Regarding personal data, object of the Request for disclosure of personal data: the applicant and, if any, his/her representative on the legal basis they invoke such as:

  • For the pursuit of the applicant’s legitimate interests, while respecting the holder’s interests or fundamental rights and freedoms regarding the protection of his/her personal data (Article 6-1 (f) of the GDPR) ; 
  • In compliance with legal obligations and/or public service role authorizing investigative powers of public authorities (Article 6-1 (c) & Article 6-1 (e) of the GDPR) 

The legal basis invoked by the applicant is in its sole responsibility; the applicant (or public authority) commits itself to receive and use the personal data received only for the purposes defined in its request on the legal basis invoked

Regarding personal data of the applicant and, if any, his/her representative, exclusively in the case of applicant’s legitimate interests: the domain name holder as soon as he or she exercises his or her right to information (data subjects right) received by Afnic before the data purge.

Handle injunctions and orders for domain name operations in .paris

  1. Purpose

Administrative processing to handle injunctions/requests and orders for domain name operations allows us to: 

  • Receiving and managing injunctions from authorized public authorities (e.g., legal basis)
  • Receiving and managing court orders
  • Taking action on domain names in accordance with injunctions and orders
  • Exchanges relating to the implementation of injunctions and orders
  • Compiling anonymized statistics
  1. Lawful basis: 

In accordance with our legal obligations (Art. 6 – 1. c/ of the GDPR), namely (i) for orders issued by the DGCCRF (French Directorate General for Competition, Consumer Affairs and Fraud Control), Article L45-2 of the French Postal and Electronic Communications Code and §C of 2° of Article L.521-3-1 of the French Consumer Code, (ii) for orders, the applicable code of procedure.

  1. Duration: 

Retention in active database for the entire duration of the required measures. Transfer to archive database at the end of processing for a period of 5 years. 

For exchanges, retention in active database for the entire duration of the required measures + 2 months, then purging.

Domain name operations: indefinite duration in the registry database.

  1. Categories of data processed: 

For injunctions: the identifying details of the person making the request, the domain name subject to the injunction, the context of the injunction, the signature and identity of the representative of the public authority

For orders: the identifying details of the judicial officer and representatives of the judiciary, the domain name subject to the order, details of the applicant and their representative, the context of the order

For operations on the domain name following an injunction: blocking and/or deletion and/or transfer of the domain name to the competent authority; dates of operations carried out

For the enforcement of orders: freezing of the domain name, blocking of the domain name, deletion of the domain name, transmission to the applicant of the identifying data of the domain name holder; dates of operations carried out

Exchanges relating to the implementation of injunctions and orders

  1. How the data are collected: 

Direct collection for representatives of public authorities and judicial bodies. Indirect collection for data relating to the holder and parties to disputes

  1. Nature of the data:

The data requirement is mandatory and necessary for us to implement injunctions and orders.

  1. Recipients: 

The relevant internal departments. The registrar of the domain name concerned. The beneficiary specified in the order requesting in .paris to transmit the identifying data of the domain name holder.

Personal rights and freedoms

1. Purpose

The administrative processing of personal rights and freedoms allows us to:

– Manage requests to exercise the rights of access, objection, rectification and erasure of data, restriction of processing, the right to withdraw consent, to lodge a complaint with a supervisory authority and to lay down guidelines regarding the retention, erasure and communication of personal data in the event of death 

– Manage requests for access to and erasure of personal data in the event of identity theft in registering a domain name

2. Lawful basis: In compliance with our legal obligations (Article 6-1 (c) of the GDPR): Chapter 3 of the GDPR

3. Duration: One year in current files followed by three years in intermediate files in the event of the exercise of the right of objection

4. Categories of data processed: Your identification data. Your request and its processing

5. How the data are collected: Direct collection

6. Nature of the data: The requirement for your data is regulatory and failure to provide them may prevent the processing of your request

7. Recipients: The internal departments concerned. The registrars responsible for the domain names concerned by the request, if any

Information systems security management (ISS)

  1. Purpose

The processing of Information systems security management (ISS) allows us to:

  • Supervision of the access authorization policy for users and administrators to the information systems used.
  • Regular processing of security logs from various information systems (applications, servers, equipment, metrology/supervision systems, intrusion detection)
  • Management of vulnerabilities and security incidents (collection of incident data, exploitation, management of corrective measures and actions)
  • Management of requests addressed to the Information Systems Security Manager and monitoring of IS projects
  • Management of individual authentication certificates (electronic signature)
  • Management of follow-up actions 
  • Production of activity statistics
  1. Lawful basis: 

In compliance with our legal obligations (Article 6-1 (c) of the GDPR) namely those resulting from the Law No. 2018-133 of 26 February 2018 on various provisions adapting to European Union law in the field of security – Directive (EU) 2016/1148 of 6 July 2016 concerning measures to ensure a high common level of security of network and information systems across the Union

  1. Duration: 

– Data required to supervise access authorizations to information systems: Purge when user account is deleted or not used for one year.

– Data in logs: Six months, then purge.

– Data required to monitor vulnerabilities and security incidents: purged after five years, except in the case of legal proceedings (retained for the duration of the proceedings).

  1. Categories of data processed: 

Identification data, rights by user profile, history of user actions according to rights, statistical reports

  1. How the data are collected: 

Direct collection 

  1. Nature of the data: 

The requirement of the data is necessary for the purposes

  1. Recipients: 

Where applicable, our technical service providers, as well as law enforcement agencies and the competent courts

Management of alerts under the French Data Protection Act and notifications of personal data breaches

  1. Purpose

The administrative processing of alerts under the French Data Protection Act and notifications of personal data breaches allows us to:

  • Receive and act on the alerts received
  • Analyse the alerts received, undertake any investigations that may be necessary of all pertinent persons and entities and produce reports/summaries
  • Keep journals and monitor measures and actions
  • Manage any notifications (CNIL (French Data Protection Agency) and data subjects)
  • Manage any follow-ups decided on 
  • Produce statistics on activity
  1. Lawful basis: 

In compliance with our legal obligations (Article 6-1 (c) of the GDPR) namely those resulting from Articles 32ff of the GDPR

  1. Duration: 

The data relating to a notification of a personal data breach are kept for ten years from the closing of the case.

  1. Categories of data processed: 

Identification data, work contact details, working life.

Data concerned by alert or even data breach

In the event of a breach, the risk analyses, exchanges and follow-ups with data subjects

  1. How the data are collected: 

Direct and indirect collection depending on the data

  1. Nature of the data: 

The requirement of the data is necessary for the purposes

  1. Recipients: 

Departments charged with investigating and managing alerts and breaches. Depending on their respective needs, the following may receive all or part of the data:

  • authorised members and agents of the CNIL;
  • in the event of a notification concerning cross-border processing for which the CNIL is the leading authority, the data may be sent to the other data protection authorities concerned.
  • Our partners concerned by the alerts or indeed data breaches

Stay connected to .paris

Stay up to date every two months with news, tips and inspiration to grow your online presence with .paris.