CIRCUSCASINO.FR WEBSITE RULES

ON PERSONAL DATA PROTECTION

 

…Did you know?

Dear customers and users of the Circuscasino.fr website,

New rules came into force in the European Union concerning the protection of your personal data as from 25 May 2018!

…. Our website informs you and protects your personal data.

Please carefully read our new rules for the Circuscasino.fr website about the protection of your personal data. These rules are independent of any Privacy Policy applicable to the processing of customer data in a physical Circus casino in France or Switzerland.

Don’t hesitate to contact us with any questions you may have.

  

1. Definitions

 The terms listed below have the following definitions:

  • Customer Account: the account created on the Website by a CF member customer who has joined the CIRCUS CLUB Loyalty Program; the account allows the customer to access all information on their profile and special offers, news about CF members and information on the CIRCUS CLUB Loyalty Program.
  • Personal Data: any information that could be used to directly or indirectly identify a natural person within the meaning of the applicable regulation.
  • DPO: the Data Protection Officer responsible for advising the Data Controller and controlling the Data Controller’s compliance with applicable regulations regarding the processing of Personal Data.
  • CF: CIRCUS FRANCE GIE, an Economic Interest Group registered in the Paris Trade and Companies Register under number 888437233, having its registered office at 37-39 Boulevard Murat, 75016 Paris, France.
  • Service(s): the various services available to Website Users, such as: viewing their personal account and, where possible, editing their personal information; agreeing to receive promotional offers from CF; acquiring Gift Vouchers, Gift Checks and Gift Packs; managing their loyalty points; booking a service; filing a complaint with the relevant customer service, Data Controller or DPO.
  • Data Controller: the natural person, Chairman of the Board of Directors and/or CF Director who, alone or together with others, determines the purposes and methods of processing.
  • Website: the website accessible at: https://www.circuscasino.fr.
  • User: any person aged 18 or over who does not feature on the ministerial list of players prohibited from gaming or the Swiss “VETO” system and who accesses the Website, whether or not they have created a Customer Account.
  • Visitor: any natural person who visits the Website.
  • Gift Voucher: the document containing the offer, location, validity number, validity date, beneficiary name and description that allows the beneficiary to take advantage of the offer at a CF member establishment. Gift Vouchers may be delivered by post or email or withdrawn directly at the establishment.
  • Gift Check: the document showing the amount to be spent, the terms of application, location, beneficiary name, validity number and validity date. Gift Checks may be delivered by post or email or withdrawn directly at the establishment.

Gift Pack: the package sent by post. A Gift Pack comprises the following items: (i) a Gift Voucher and/or Gift Check including a description of the service; (ii) a pouch or box containing the Gift Voucher.

2.When is my data collected?

The Data Controller collects your Personal Data when you visit the Website as a Visitor or User, when you create a Customer Account in accordance with the current Website General Terms of Use, and when you use the Services.

    The Data Controller takes account of the principles of minimizing the amount of data collected and protecting data by design. Consequently, information is only processed if it is relevant, appropriate and limited to what is necessary for the purposes for which it is processed, in accordance with applicable regulations and case law.

    3. Collection purposes and length of storage

    The information collected is saved in one or more computer files by the Data Controller, notably for the following purposes and lengths of storage:

    Purpose Legal basis Category of data Length of storage
    Making content and Services available on the Website User consent Cookie See Article 7
    Statistical evaluation of Website visits User consent Cookie See Article 7
    Managing Customer Accounts User consent ID details + Login details Throughout the duration of the User’s activity and for no more than three (3) years following the last contact made by the User.
    Managing User communication and prospecting campaigns via any means of communication (phone, SMS, post, email) Legitimate interest ID details + Contact details For as long as the User and CIRCUS CLUB Loyalty Program member remains “active”. In the event of no activity for three (3) years, the member status is switched to “inactive” and their data is archived in an intermediate database.
    After two (2) further years of inactivity, the member’s data is anonymized.
    Managing User communication and prospecting campaigns via any means of communication (phone, SMS, post, email) User consent ID details + Contact details Three (3) years following the last contact made by the User.
    Managing requests submitted to the Website customer service User consent ID details + Contact details One (1) year following the last contact made by the User.
    Managing purchases of products or Services Contract ID details + Purchase history Three (3) years following the last contact made by the User.

    In accordance with the regulations in force, the Data Controller only retains Personal Data for the duration strictly necessary to fulfill the purposes of the processing, unless the User gives their consent for such data to be retained for later use.

    Every time processing is started based on the data subject’s consent, they may withdraw their consent at any time under the conditions specified in Article 6.

    In the event that a Personal Data collection form must be completed by a User, all mandatory fields are marked with an asterisk (*). Failure to provide the required data, or the subsequent withdrawal of consent by the data subject, shall prevent the Data Controller from proceeding with their request.

    4. Communication of Personal Data

    The information held by the Data Controller relating to Users and Visitors can be communicated to the following persons:

    • The Data Controller’s staff, as well as the staff of sister or subsidiary companies, who are authorized to manage this processing due to their duties;
    • Organizations entrusted with an audit or inspection assignment in accordance with applicable regulations;
    • The external providers responsible for carrying out Personal Data processing operations on behalf of the Data Controller, who are contractually bound to a security and confidentiality obligation related to this Personal Data (for example, to secure online payments, prevent fraud, carry out website maintenance, collect customers opinions).
    • Any person who has access to your Personal Data is bound by a strict obligation to confidentiality.

    5. Transferring Personal Data outside the European Union

    All of your Personal Data is processed exclusively within the territory of the European Union.

    The Data Controller will not transfer your Personal Data outside European territory, except to companies controlled or held by CCF and to external service providers.

    In the event that assistance is needed from providers based outside European Union territory, the Data Controller will first and foremost ensure that appropriate measures are put in place to ensure that the Personal Data is transferred within a contractual framework that respects its inherent confidentiality and that the safeguards and security arrangements pertaining to this processing comply with regulations applicable in France and the European Union.

    6. Your rights with regard to your Personal Data

    In accordance with the regulations in force, you have the following rights with regard to your Personal Data:

    • Right to object: You may object to the use for legitimate reasons (except in the case of a legal obligation of the Data Controller) or reuse of your data for solicitation purposes, including commercial solicitation in particular, when placing an order or signing a contract.
    • Right to restriction of processing: You may request that some of your data be temporarily frozen.
    • Right of access: You may ask the Data Controller whether they hold personal data concerning you and to communicate it to you so that you can check the content.
    • Right of rectification: You may request the rectification of inaccurate or incomplete personal data.
    • Right to portability: The right to portability entitles you to recover part of your data in machine-readable format. You are free to store this portable data elsewhere or transfer it easily from one system to another for reuse or other purposes.
    • Right to erasure: You may request the erasure of your data, except in the case of a legal obligation of the Data Controller.

    You also have the option to communicate your instructions to the Data Controller on what should happen to your Personal Data after your death.

    Users and Visitors are informed that exercising the rights of objection, erasure and data portability, as well as the right to restriction of processing, is subject to certain conditions and may be refused by the Data Controller if these requests do not correspond to the situations provided for in the regulations regarding Personal Data.

    You may exercise your rights by writing to one of the following addresses. Proof of identity may be requested:

    • By post: 37-39 Boulevard Murat, 75016 Paris, France

    Requests will be processed in the best possible timeframe, and at the latest within three (3) months, subject to any regulatory extensions, e.g., in the event of a complex request or a high number of requests received.

    Finally, if the Data Controller does not fulfill your requests, you have the right to make a complaint to a Personal Data protection authority, namely the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés, or CNIL) within French territory.

    7. Cookies

    When you visit the Website, cookies are placed on your terminal (PC, smartphone or tablet).

    The Data Controller and CCF use cookies, for example, to identify you and to allow you to access your Account.

    I. What are cookies?

    A cookie is an information file placed on an Internet user’s hard drive by the server of the website they are visiting. A cookie contains multiple data: the name of the server that placed it, an identifier in the form of a unique number and, in some cases, an expiry date. This information is sometimes stored on computer in a plain text file which the server accesses in order to read and register the information.

    II. Cookies used by the Website and their purpose

    See our Cookie Policy directly on the Website.

    III. Accepting and rejecting cookies

    You have several options for managing cookies when you browse the Website.

    • Via the banner that tells you about the use of cookies on the Website;
    • By configuring your web browser.

    You can opt to disable cookies at any time.

    You can also configure your browser to let you know when cookies are going to be placed on your computer and to ask you to accept or reject them. You can accept or reject cookies on a case-by-case basis, or you can reject them systematically once and for all.

    You are hereby reminded that configuring your browser in this way might alter your conditions of access to Website Services, optimum display of the Website or the Website browsing experience, which requires the use of cookies.

    If you disable the cookies used by the Website, you may not be able to access some parts of the Website, or some of the settings you selected upon your first visit may not be remembered upon subsequent visits. For example, some pages won’t open, some videos and animations will be impossible to view, or some data may not be stored and will therefore not be filled in automatically upon subsequent visits.

    In order to manage cookies in accordance with your expectations, we suggest that you configure your browser in accordance with the cookie purposes mentioned above.

    Here is how to control cookies or stop them being saved:

    The configuration process is different for each browser. Configuration is described in your browser’s help menu, which will explain how to change your cookie preferences. You can disable acceptance of cookies via your browser by following these instructions:

    • Internet Explorer
    • In Internet Explorer, click the “Tools” button, and then click “Internet options”.
    • Under the “General” tab, click “Settings” under “Browsing history”.
    • Click the “View files” button.
    • Click the heading of the “Name” column to sort all files in alphabetical order, then scroll down the list until you see file names beginning with the prefix “Cookie” (all cookies have this prefix and generally contain the name of the website that created the cookie).
    • Select the cookie(s) containing the name of this website and delete them.
    • Close the window containing the list of files, then click twice on “OK” to return to Internet Explorer.
    • Firefox
    • Go to the browser “Tools” tab and select the “Options” menu.
    • In the window that appears, choose “Privacy” then click “Show cookies”.
    • Locate the files containing the name of this website, select them and delete them.
    • Safari
    • In your browser, choose the “Edit” menu, then “Preferences”.
    • Click “Privacy”.
    • Click “Show cookies”.
    • Select the cookies containing the name of this website, then click “Delete” or “Delete all”.
    • After deleting the cookies, click “Done”.
    • Google Chrome
    • Click the tools menu icon. Select “Options”.
    • Click the “Advanced options” tab and go to the “Privacy” section. Click the “Show cookies” button.
    • Locate the files containing the name of this website.
      Select them and delete them.
      Click “Close” to return to your browser.
    • Configuration on a cookie management platform
    • You can manage your cookies by going to the cookie management platforms proposed by advertising professionals.

    Version dated 29/10/2025

     

    RULES RELATING TO PERSONAL DATA PROTECTION

    …Did you know?

    Dear clients,

    New rules came into force in the European Union concerning the protection of your personal data as from 25 May 2018!

    …. Your casino informs you and protects your personal data.

    Please carefully read our new rules about the protection of your personal data. Don’t hesitate to contact us with any questions you may have. 

    1. Why do we have rules regarding personal data protection?
    Holding company CIRCUS CASINO FRANCE SAS holds the full share capital and voting rights of the following companies (hereinafter the “Subsidiaries”):
    – SOCIETE CASINO ALLEVARD SAS
    – SOCIETE DU CASINO DE BRIANÇON SAS
    – SOCIETE DU CASINO DE CARNAC SAS
    – SOCIETE DU CASINO DE PORT-LEUCATE SAS
    – SOCIETE DU CASINO DE VALS-LES-BAINS SAS
    – SOCIETE DU CASINO DE CAZAUBON BARBOTAN-LES-THERMES SAS
    – SOCIETE DU CASINO DE BALARUC SAS
    – CLUB CIRCUS PARIS SAS
    – SOCIETE DU CASINO DE CRANS-MONTANA SA (Switzerland)
    CIRCUS CASINO FRANCE and GIE CIRCUS FRANCE (“CCF”), under which the Subsidiaries constitute members or customers of said Group, process the personal data (“Personal Data”) of their customers and the visitors of the Subsidiaries’ various official websites (“the Customers”) for the purposes and within the limits defined in the rules herein concerning personal data protection (hereinafter the “Privacy Policy”).
    CCF has always been mindful of protecting Personal Data and takes care to comply with the applicable laws and regulations when processing said Personal Data, in particular Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the “GDPR”), which came into force on 25 May 2018, and, for the CCF Group’s Swiss entities, the new Federal Act on Data Protection of 25 September 2020, which came into force in Switzerland on 1 September 2023 (hereinafter the “nFADP”).
    The GDPR and the nFADP impose new obligations; the CCF undertakes to comply with said obligations and inform its Customers thereof. In this Privacy Policy, CCF wishes to communicate all necessary and useful information regarding the data processed by CCF, the type of processing and the purposes of processing, as well as to define the rights and obligations of CCF and the Customers regarding the processing of their Personal Data.
    The Privacy Policy came into force on 6 November 2025 and shall apply as from said date to each subsequent visit by a Customer to any of the operating websites managed by the Subsidiaries. In accordance with the Rules in question, the Privacy Policy aims to cover:
    – the processing of Personal Data that CCF is legally required to perform. This processing is outlined in Article 3.1 of the Privacy Policy;
    – the processing of Personal Data for the purposes of allowing Customers to access the Subsidiaries’ establishments and benefit from their respective casino game offerings, as well as any data processing required for the necessary and legitimate purposes outlined in Article 3.2 of the Privacy Policy;
    – the processing of Personal Data that is subject to the Customers’ prior, free and explicit consent, for the purposes described in Article 4.
    In accessing an operating website managed by the Subsidiaries or any of the aforementioned entities’ websites, the Customers are deemed to have read and agreed to the Privacy Policy. The Privacy Policy is attached to and forms an integral part of the registration form that Subsidiaries submit to the Customers for signature whenever they visit a Subsidiary’s establishment; it can also be viewed at any time on www.circuscasino.fr.
    Customers hereby warrant that the data and information communicated to CCF Subsidiaries is correct.

    2. CCF and data controller contact details
    CCF may be contacted for all questions regarding the protection of its Customers’ personal data as follows:
    – By post: 37-39 Boulevard Murat, 75016 Paris, France.
    – By email: [email protected]
    The data controller for CCF is Mr. Sébastien Leclercq. Each Subsidiary has its own data controller, with said role being fulfilled by the Manager, General Manager or Deputy General Manager (Articles 3 and 5 of the GDPR, Article 7 of the nFADP).
    CCF has also appointed a data protection officer (the “DPO” in accordance with Article 37 of the GDPR and Article 10 of the nFADP), who may be contacted by email at the above address. The DPO is responsible for monitoring and ensuring the compliance of CCF’s processing of Customer Personal Data.

    3. Personal Data processing not requiring Customer consent
    3.1. CCF’s legal obligations and the processing required for the Subsidiaries’ commercial offers
    In accordance with the legal and regulatory obligations binding all licensed operators, for the purposes of authenticating and allowing Customers to access Subsidiaries’ establishments, take part in games and take advantage of the commercial offers available, CCF is required to process the following Personal Data for the purposes outlined below. This processing of Personal Data is carried out by CCF and its Subsidiaries and does not require Customers’ consent in accordance with Article 6.1.b) and c) of the GDPR and, for Swiss entities, Articles 31 and 34 of the nFADP.
    The Personal Data communicated by the Customer is saved on a register, as described in Article 7.1, which is controlled by the Subsidiaries and remains under their responsibility at all times.
    a. What data is processed?
    The following Personal Data is subject to processing:
    – first name(s), surname, as well as, if applicable, the Customer’s pseudonym, date and place of birth, nationality, occupation, language, gender, home/postal address, national registration number (or identity card or passport number), existence of a gaming ban (ministerial bans), customer number and, if applicable, their email address and landline or mobile phone number;
    – bank details used for deposit transactions and winnings withdrawals, as well as their amounts;
    – the Customer’s image, notably via the Subsidiaries’ video surveillance systems;
    – the identity card or any legal documents used for the authentication of Customers;
    – ongoing commercial promotions or those in which the Customer took part;
    – all other information exchanged between the Subsidiaries and the Customer, via any method or medium whatsoever, including by email, in connection with the Customer’s registration or during the commercial relationship.
    b. What processing is carried out by CCF?
    Processing consists of the collection, recording, storage, viewing, organization, use, reconciliation or any other necessary or useful action in accordance with the statutory and regulatory provisions referred to in Article 3.1.c) herein. Processing may also involve the forwarding of Personal Data:
    – to the judicial and administrative authorities, in particular the French Data Protection Authority (CNIL), the Swiss Federal Data Protection and Information Commissioner (FDPIC) and/or any other third party duly authorized by the regulations in force (Article 51 of the GDPR and Article 4 of the nFADP);
    – to any of CCF’s providers and/or Subsidiaries whose services are integral to its casino game offer, the list of which may be obtained upon request from the data controller referred to in Article 2.
    Personal Data may be processed by CCF on any medium whatsoever, whether electronic or paper, including text messages and email.
    c. What are the purposes of this processing?
    1) CCF is required to process Personal Data as described in Articles 3.1.a) and b) herein in order to fulfill its legal and regulatory obligations, in particular in accordance with the following statutory provisions:

    – French Data Protection Act no. 78-17 of 6 January 1978, as amended (Loi informatique libertés);
    – Articles L.561-1 et seq. of the French Monetary and Financial Code regarding TRACFIN (the French unit for intelligence processing and action against illicit financial networks, i.e. the fight against money laundering and terrorism financing and limiting the use of cash);
    – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
    For Switzerland:

    – The new Federal Act on Data Protection (“nFADP”) of 25 September 2020, which entered into force on 1 September 2023;
    – The provisions laid out under the “Memorandum concerning the federal act on the total revision of the federal act on data protection and the amendment of other acts dated 15 September 2017” published on 14 November 2017;
    – The Data Protection Ordinance (“DPO”) of 31 August 2022, which entered into force on 1 September 2023.
    2) CCF also processes the Personal Data referred to in Article 3.1.a) for the purposes of authenticating Customers to allow them to access the establishments operated by the Subsidiaries, as well as their respective websites, and to benefit from the corresponding game offering. This processing is carried out to ensure:
    – the management of Customer registrations and accounts;
    – the management of Customer deposits and winnings;
    – the communication of information to Customers regarding current and future games and commercial operations offered by CCF Subsidiaries.
    3.2. Other processing not requiring Customer consent
    CCF also processes Personal Data for the legitimate purposes outlined below. This processing of Personal Data carried out by CCF does not require Customers’ consent in accordance with Article 6.1.f) of the GDPR and Articles 31 and 34 of the nFADP.
    The Personal Data communicated by the Customer is saved on a register, as outlined in Article 7.1 herein, which is controlled by CCF and its respective Subsidiaries and remains under their responsibility at all times.
    a. What Personal Data is processed?
    The following Personal Data is subject to processing:
    – first name(s), surname, as well as, if applicable, the Customer’s pseudonym, date and place of birth, nationality, occupation, language, gender, home/postal address, national registration number (or identity card or passport number), existence of a gaming ban (ministerial bans), customer number and, if applicable, their email address and landline or mobile phone number;
    – the Customer’s activity within the establishments operated by CCF Subsidiaries;
    – bank details used for deposit transactions and winnings withdrawals, as well as their amounts;
    – the Customer’s image, notably via the Subsidiaries’ video surveillance systems;
    – the identity card or any legal documents used for the authentication of Customers;
    – the Customer’s browsing and activity history on www.circuscasino.fr, including their login history (browser data, IP address), particularly through cookies;
    – ongoing commercial promotions or those in which the Customer took part;
    – all other information that can be exchanged between CCF, its Subsidiaries and the Customer, via any method or medium whatsoever, including by email, in connection with the Customer’s registration or participation in games operated by CCF Subsidiaries.
    b. What processing is carried out by CCF?
    Processing consists of the collection, recording, storage, viewing, organization, use and reconciliation of the Personal Data referred to in Article 3.2 a) herein. It also involves the transfer of this Personal Data to third parties, a list of which may be obtained upon request from the contact person referred to in Article 2 herein, including to other gaming hall or casino operators, whether they are direct and indirect partners of CCF, for security, prevention or anti-fraud purposes.
    Personal Data may be processed by CCF and its Subsidiaries on any medium whatsoever, whether electronic or paper, including text messages and email.
    c. What are the legitimate purposes of this processing?
    CCF and its Subsidiaries process the Personal Data referred to in Article 3.2.a) herein for the following legitimate purposes:
    – promotion, advertising and marketing relating to the offer of new casino games or games of chance, or any similar product, as well as the Subsidiaries’ hotel and catering services, including by text message, telephone call, email and paper or electronic newsletter;
    – the security of establishments operated by CCF Subsidiaries, along with fraud prevention;
    – the withdrawal or delivery of winnings, prizes and gifts won by Customers;
    – participation in events, tournaments, tombolas, contests and promotional offers relating to the games operated by CCF Subsidiaries;
    – performance of satisfaction surveys, statistical studies, trend analyses and market surveys for the purpose of improving gaming or Customer information services or Customer protection;
    – responsible gaming and the prevention of gaming dependency;
    – with regard to the images saved by CCF Subsidiaries’ video surveillance systems, Customer refunds in the event of any breakdown or any disputes arising in any of the establishments operated by the Subsidiaries.

    4. Processing of Personal Data subject to Customer consent
    By using the gaming services offered by CCF Subsidiaries, the Customer expresses their free, specific, informed and unequivocal intention to expressly authorize CCF and its Subsidiaries to process the Customer’s Personal Data in accordance with the regulations in force, within the limits and for the purposes defined below and without prejudice to the processing referred to in Article 3 herein.
    The Personal Data communicated by the Customer is saved on a register, as outlined in Article 7.1 herein, which is controlled by CCF and its Subsidiaries and remains under their responsibility at all times.
    The Customer also benefits from rights, including the right to withdraw their consent at any time, according to the terms and conditions defined in Article 5.7 herein.
    4.1. Nature of the Personal Data processed
    CCF and its Subsidiaries process the following data:
    – first name(s), surname, as well as, if applicable, the Customer’s pseudonym, date and place of birth, nationality, occupation, language, gender, home/postal address, national registration number (or identity card or passport number), existence of a gaming ban (ministerial bans), customer number and, if applicable, their email address and landline or mobile phone number;
    – the bank details used for deposit transactions and winnings withdrawals, as well as their amounts;
    – the identity card or any legal documents enabling the Customers’ authentication;
    – the Customer’s activity within the establishments operated by CCF Subsidiaries;
    – images, notably from the Subsidiaries’ regulated video surveillance system, as well as, if applicable, the data and images published on social media;
    – history of participation in tournaments, contests or events, and the result of said participation, as well as gaming information (stakes, winnings and bet timestamps, as well as the machines on which the Customer plays and the points collected under the CIRCUS CLUB loyalty program);
    – the Customer’s browsing and activity history on www.circuscasino.fr, including their login history (browser data, IP address), particularly through cookies;
    – all other information that can be exchanged between CCF, its Subsidiaries and the Customer, via any method or medium whatsoever, including by email, in connection with the Customer’s registration or participation in games operated by CCF Subsidiaries.
    The Personal Data communicated by the Customer is saved on a register, as outlined in Article 7.1 herein, which is controlled by CCF and its Subsidiaries and remains under their responsibility at all times.
    4.2. Processing
    Processing consists of the collection, recording, storage, viewing, organization, use and reconciliation of the Personal Data referred to in Article 3.1 herein. It also consists of the transfer of said Personal Data to third parties, a list of which may be obtained upon request submitted to the contact person referred to in Article 2 herein, including other gaming hall or casino operators for marketing purposes, whether they are direct or indirect partners of CCF, as well as to CCF’s partners participating in promotions.
    Personal Data may be processed by CCF and its Subsidiaries on any medium whatsoever, whether electronic or paper, including text messages and email.
    4.3. Purposes of Personal Data processing
    Personal Data is collected and processed by CCF and its Subsidiaries for the following purposes:
    – promotion, advertising and marketing, to the extent authorized by law, including the loyalty program, relating to the offer of casino game and betting services, including text messages, telephone calls, paper or electronic newsletters and emails, that do not fall under Article 3.2.c) herein, such as the online casino, game of chance and betting activity operated by CCF or any other casino or game of chance company, whether it is a direct or indirect partner of CCF, including advertising and marketing to the extent authorized by law, including the loyalty program related to it;
    – participation in events, tournaments, tombolas, contests and promotional offers not related to casino games and games of chance;
    – communications relating to winners and Customers’ winnings in connection with their participation in tournaments, tombolas, contests or events, notably communication via the www.circuscasino.fr or www.mycircus.net websites;
    – development of new casino games and betting offers, both offline and online;
    – performance of satisfaction surveys, statistical studies, trend analyses and market surveys for the purposes of management, marketing and reporting, including profiling, outside the scope of the purpose outlined in Article 3.2.c) herein.

    5. CCF Customers and their rights
    Without prejudice to Articles 3 and 6.2 herein, Customers may exercise their right of rectification, objection and restriction of processing in accordance with the following terms and limits.
    5.1. Right of access
    a. CCF and its Subsidiaries make the following information available to Customers:
    – the identity and contact details of the data controller;
    – the contact details of the data protection officer (according to French or Swiss law);
    – the Personal Data processed;
    – the purposes of the Personal Data processing and the legal basis for such processing;
    – the recipients or categories of recipients of the Personal Data, if applicable;
    – and, where applicable, the data controller’s intention to transfer the Personal Data to a country located outside the European Union or the European Free Trade Association and either (i) the existence (or absence) of an adequacy decision adopted by the European Commission or, (ii) in the absence of such a decision, the safeguards offered by the third country in question and the measures implemented to obtain a copy of the Personal Data.
    – The possibility to object to the automated processing of their data, for instance through profiling, unless a just cause renders such processing by CCF or its Subsidiaries necessary, as well as the possibility to object to any processing of their Personal Data for direct marketing purposes (in Switzerland, CCF follows the principle of obtaining the Customer’s express consent whenever profiling or the processing of sensitive Personal Data is to be carried out, in accordance with Article 6 of the nFADP).
    b. Customers have the right to request, at any time, access to all the information listed in this Article and in Article 5.1, by sending said request to the contact person referred to in Article 2.
    1.3.1 Customers have the right to obtain a copy of their Personal Data that is processed. CCF and its Subsidiaries reserve the right to demand payment for any costs arising from requests for an additional copy of the Personal Data; these costs will be calculated on the basis of administrative costs incurred for the request, up to a maximum of €20.
    c. Customers are entitled to obtain said access to or said copy of the Personal Data in a structured format that complies with technical standards in force when the request for access is submitted.
    5.2. Right to rectification
    CCF and its Subsidiaries make every effort to ensure that Customers’ Personal Data is correct and up to date; Customers are obliged to request the rectification and updating of their Personal Data as soon as this data becomes incorrect or incomplete.
    The right to rectification may be exercised upon request sent to the data controller referred to in Article 2 herein, in accordance with Article 16 and Recital 65 of the GDPR and, for the Swiss Subsidiaries, Article 32 of the nFADP.
    5.3. Right to object
    CCF and its Subsidiaries authorize Customers to object to the processing of all or part of their Personal Data for the following reasons:
    – the data is inaccurate;
    – the processing is no longer required for the purposes for which the data was collected;
    – the Customer withdraws their consent;
    – the data has been subject to illegal processing.
    Moreover, CCF and its Subsidiaries authorize Customers to object to:
    – automated processing of their data, such as profiling, unless a just cause renders this processing by CCF necessary;
    – any processing of their Personal Data for direct marketing purposes, including profiling if it is linked to said direct marketing.
    The right to object may be exercised upon request sent to the data controller referred to in Article 2 herein.
    5.4. Right to be forgotten
    CCF and its Subsidiaries also undertake to respond to any request for erasure of Personal Data (right to be forgotten) as soon as possible, when:
    – the processing is no longer required for the purposes for which the data was collected;
    – the Customer withdraws their consent;
    – the data has been subject to illegal processing, or must be deleted due to a legal obligation;
    – the Customer objects to the automated processing of their data, such as profiling, and there is no just cause rendering this processing by CCF necessary;
    – the Customer objects to the processing of their Personal Data for direct marketing purposes, including profiling if it is linked to such direct marketing.
    5.5. Right to restriction of processing
    Customers also have the right to obtain from CCF or its Subsidiaries the restriction of the processing of their Personal Data when:
    – the Customer considers their Personal Data to be incorrect, for as long as is needed for CCF and its Subsidiaries to verify the accuracy of said Personal Data;
    – the processing is illegal but the Customer does not wish their data to be deleted, but rather requests a restriction of the processing of said data;
    – the Customer objects to automated processing, including profiling or the processing of their Personal Data for direct marketing purposes, and it is necessary to verify the legitimacy of the reasons for which CCF and its Subsidiaries intend to continue said processing;
    – CCF and its Subsidiaries no longer have need of the processed Personal Data but the data subject wishes said Personal Data to be saved for the purposes of acknowledging, exercising or defending their rights in court.
    The right to restriction of processing may be exercised upon request sent to the contact referred to in Article 2 herein.
    5.6. Transferring data to a data controller
    Customers are authorized to transfer their Personal Data to another data controller without CCF being able to prevent this.
    Provided such a transfer is technically possible, Customers are authorized to ask CCF or the relevant Subsidiary to have this transfer carried out directly by their data controller.
    5.7. Terms and conditions
    The rights of the Customer recognized by CCF and its Subsidiaries must be exercised by contacting the data controller referred to in Article 2 herein.
    CCF and its Subsidiaries will respond to these requests within one month and will keep a record for this purpose.
    5.8. Notification
    CCF and its Subsidiaries will notify the Customer of any erasure or rectification of data carried out in accordance with Articles 5.2 and 5.4 herein, unless such notification proves impossible or requires a disproportionate effort on their part.
    This notification will be done by email or letter sent to the address provided by the Customer.

    6. Personal Data location, storage and retention period
    6.1. CCF and its Subsidiaries will store Customers’ Personal Data in a format enabling its identification and availability and in accordance with appropriate and secure methods.
    The data is stored and hosted within the European Union, which offers all the necessary and useful security guarantees in light of technical standards in force.
    6.2. Customers’ Personal Data is stored by CCF and its Subsidiaries for the purposes defined under Articles 3 and 4 herein for a period of five (5) years for all purposes listed under Article 3.1 (subject to different periods depending on the type of data and regulatory requirements, as specified in each Subsidiary’s processing activity register); CCF and its Subsidiaries therefore reserve the right to store Customers’ Personal Data for all purposes required by law as a result of their gaming and betting activities. Customers represent that they have been informed and agree, in accordance with TRACFIN regulations (in particular Article R.561-22-2 of the French Monetary and Financial Code), that CCF and its Subsidiaries are required to keep a photocopy of the identity card or proof of ID used to identify the Customer for at least five (5) years as from the Customer’s last day of activity.
    6.3. For Swiss Subsidiaries, the Personal Data retention period may vary depending on the requirements laid down in the following legal frameworks:
    – The Federal Act of 10 October 1997 on Combating Money Laundering and Terrorist Financing (Anti-Money Laundering Act, AMLA, SR 966.0);
    – The Ordinance of 11 November 2015 on Combating Money Laundering and Terrorist Financing (Anti-Money Laundering Ordinance, AMLO, SR 955.01);
    – The Ordinance of the Federal Gaming Board on the Diligence of Casinos in Combating Money Laundering and Terrorist Financing (FGB Anti-Money Laundering Ordinance, AMLO-FGB, SR 955.021).

    7. Liability of CCF, its Subsidiaries and their data processors
    7.1. CCF and its Subsidiaries agree to process Customers’ Personal Data in a legal, fair and transparent manner with regard to the Customer concerned. All processing must comply with the provisions of applicable regulations and this Privacy Policy.
    CCF and its Subsidiaries have put in place a register of processing activities which they will keep up to date, in accordance with Article 30 and Recital 82 of the GDPR and, specifically for Switzerland, Article 12 of the nFADP. This register is controlled by CCF and/or its relevant Subsidiary, under whose responsibility it shall remain at all times. The register sets out the purposes of processing and the categories of data subject and Personal Data.
    CCF and its Subsidiaries will implement all reasonable and appropriate methods to ensure the confidentiality, integrity and availability of the Personal Data they process. These technical and organizational measures are regularly evaluated and updated.
    Technical measures notably include a firewall and a video surveillance system.
    Organizational measures mainly include internal audits, in addition to any inspections conducted on CCF and its Subsidiaries by the French Data Protection Authority (CNIL) or the Swiss FDPIC.
    If necessary, with the help of the data protection officer, CCF and its Subsidiaries will carry out an impact analysis when processing is liable to cause a heightened risk for Customers.
    7.2. Customers’ Personal Data shall not be transferred to third parties other than those authorized in accordance with the recommendations of the CNIL and the FDPIC, the authorities, providers and CCF’s partners, unless required for the purposes laid out in Articles 3.1, 3.2 and 4 herein, namely if:
    • the transfer becomes compulsory by law, regulation or injunction of an administrative or judiciary authority;
    • the transfer proves necessary for the provision of gaming services by an establishment operated by a Subsidiary or for handling a Customer complaint;
    • the Customer gives their consent for such transfer.
    CCF’s partner will not be considered as a data processor unless it processes Customers’ Personal Data on behalf of CCF or one of its Subsidiaries. CCF and its Subsidiaries decline all responsibility regarding the processing of Customers’ Personal Data (i) by any partner providing its own services in its own name and on its own behalf or (ii) if CCF and its Subsidiaries prove that they are not accountable for any damage caused.
    Where CCF or any of its Subsidiaries is acting as the partner’s data processor, it is agreed that CCF or its Subsidiary shall only be held liable for any damage caused by the processing of Personal Data in breach of the GDPR (Article 28 and Recital 80), the nFADP (Article 9) or this Privacy Policy (i) if they have breached the regulatory obligations specifically incumbent on data processors, or (ii) if they have acted outside of or contrary to the partner’s lawful instructions. Similarly, CCF or its Subsidiaries cannot be held liable under any circumstances if they prove that the incident that caused the damage was in no way attributable to them.
    7.3. When processing is carried out by a data processor on behalf of CCF and its Subsidiaries, CCF and its Subsidiaries undertake to provide sufficient guarantees for the implementation of appropriate technical and organizational measures and, more generally, regarding compliance with the provisions of the GDPR (Article 28 and Recital 80) and the nFADP (Article 9). In particular, the data processor shall be required to comply with regulatory provisions and, consequently, to keep a register.
    7.4. CCF and its Subsidiaries agree to notify the CNIL or the FDPIC, as referred to in Article 8.3 herein, of any security incidents linked to processed Personal Data that could pose a risk to the rights and freedoms of the data subjects concerned at the earliest opportunity and, if possible, within a maximum of 72 hours after the date on which CCF and its Subsidiaries became aware of the incident, in accordance with Articles 33 and 34 of the GDPR and Article 24 of the nFADP.
    CCF and its Subsidiaries will record any security incidents and take the necessary organizational and technical measures in order to resolve such incidents as soon as possible.
    CCF and its Subsidiaries will also inform the Customers concerned, insofar as the Personal Data breach presents a heightened risk for Customers’ rights and freedoms; the Customers will be informed by email or letter sent to the address they have provided.

    8. Other provisions
    8.1. Personal Data register
    As the data controller, CCF and/or its Subsidiaries shall keep a register of all their processing activities. This register contains all information relating to the type of data processed, data subjects, the potential recipients to whom the data is communicated (where applicable), the purposes for which the data is processed, the data retention period and a general description of the technical and organizational security measures implemented.
    The Personal Data communicated by the Customer is saved, as well as the processing carried out and its purposes, in a register that is controlled by CCF and its Subsidiaries and remains under their responsibility at all times. This register includes, in addition to the aforementioned information:
    – a description of the purposes of the processing;
    – a description of the categories of data subject and Personal Data;
    – the categories of recipients to whom the Personal Data has been or will be communicated, including any recipients in third countries or international organizations;
    – the stipulated deadlines for erasure of the various categories of data;
    – a general description of the technical security measures.
    8.2. Entire agreement – Amendments to the Privacy Policy
    The Privacy Policy contains all contractual provisions binding on Customers, without prejudice to the general provisions applicable to Customers during any visit to establishments managed by CCF Subsidiaries. These provisions therefore remain applicable for all matters unrelated to Personal Data protection.
    CCF and its Subsidiaries reserve the right to amend the Privacy Policy. Any amendments shall be binding on Customers immediately upon their next visit to an establishment operated by a CCF Subsidiary. CCF undertakes to mention the date of publication of the Privacy Policy in force on https://www.circuscasino.fr.
    8.3. Data protection authority
    Customers of French Subsidiaries have the right to request additional information or file a complaint with the French Data Protection Authority (CNIL) at the following address:
    Commission nationale de l’informatique et des libertés
    3 Place de Fontenoy
    TSA 80715
    75334 PARIS CEDEX 07 FRANCE

    Customers of Swiss Subsidiaries have the right to request additional information or file a complaint with the FDPIC at the following address:

    Préposé fédéral à la protection des données et à la transparence (PFPDT)
    Feldeggweg 1
    Switzerland – 3003 Bern