PRIVACY POLICIES
OF THE CIRCUSCASINO.FR WEBSITE
IN ACCORDANCE WITH EUROPEAN AND SWISS LAW
PRIVACY POLICY OF THE CIRCUSCASINO.FR WEBSITE IN ACCORDANCE WITH GDPR
|
…Did you know? Dear customers and users of the Circuscasino.fr website, New rules came into force in the European Union concerning the protection of your personal data as from 25 May 2018! …. Our website informs you and protects your personal data. Please carefully read our new rules for the Circuscasino.fr website about the protection of your personal data. These rules are independent of any Privacy Policy applicable to the processing of customer data in a physical Circus casino in France or Switzerland. Don’t hesitate to contact us with any questions you may have. |
1. Definitions
The terms listed below have the following definitions:
- Customer Account: the account created on the Website by a CF member customer who has joined the CIRCUS CLUB Loyalty Program; the account allows the customer to access all information on their profile and special offers, news about CF members and information on the CIRCUS CLUB Loyalty Program.
- Personal Data: any information that could be used to directly or indirectly identify a natural person within the meaning of the applicable regulation.
- DPO: the Data Protection Officer responsible for advising the Data Controller and controlling the Data Controller’s compliance with applicable regulations regarding the processing of Personal Data.
- CF: CIRCUS FRANCE GIE, an Economic Interest Group registered in the Paris Trade and Companies Register under number 888437233, having its registered office at 37-39 Boulevard Murat, 75016 Paris, France.
- Service(s): the various services available to Website Users, such as: viewing their personal account and, where possible, editing their personal information; agreeing to receive promotional offers from CF; acquiring Gift Vouchers, Gift Checks and Gift Packs; managing their loyalty points; booking a service; filing a complaint with the relevant customer service, Data Controller or DPO.
- Data Controller: the natural person, Chairman of the Board of Directors and/or CF Director who, alone or together with others, determines the purposes and methods of processing.
- Website: the website accessible at: https://www.circuscasino.fr.
- User: any person aged 18 or over who does not feature on the ministerial list of players prohibited from gaming or the Swiss “VETO” system and who accesses the Website, whether or not they have created a Customer Account.
- Visitor: any natural person who visits the Website.
- Gift Voucher: the document containing the offer, location, validity number, validity date, beneficiary name and description that allows the beneficiary to take advantage of the offer at a CF member establishment. Gift Vouchers may be delivered by post or email or withdrawn directly at the establishment.
- Gift Check: the document showing the amount to be spent, the terms of application, location, beneficiary name, validity number and validity date. Gift Checks may be delivered by post or email or withdrawn directly at the establishment.
- Gift Pack: the package sent by post. A Gift Pack comprises the following items: (i) a Gift Voucher and/or Gift Check including a description of the service; (ii) a pouch or box containing the Gift Voucher.
2.When is my data collected?
The Data Controller collects your Personal Data when you visit the Website as a Visitor or User, when you create a Customer Account in accordance with the current Website General Terms of Use, and when you use the Services.
The Data Controller takes account of the principles of minimizing the amount of data collected and protecting data by design. Consequently, information is only processed if it is relevant, appropriate and limited to what is necessary for the purposes for which it is processed, in accordance with applicable regulations and case law.
3. Collection purposes and length of storage
The information collected is saved in one or more computer files by the Data Controller, notably for the following purposes and lengths of storage:
|
Purpose |
Legal basis |
Category of data |
Length of storage |
|
Making content and Services available on the Website |
User consent |
Cookie |
See Article 7 |
|
Statistical evaluation of Website visits |
User consent |
Cookie |
See Article 7 |
|
Managing Customer Accounts |
User consent |
ID details + Login details |
Throughout the duration of the User’s activity and for no more than three (3) years following the last contact made by the User. |
|
Managing User communication and prospecting campaigns via any means of communication (phone, SMS, post, email) |
Legitimate interest |
ID details + Contact details |
For as long as the User and CIRCUS CLUB Loyalty Program member remains “active”. In the event of no activity for three (3) years, the member status is switched to “inactive” and their data is archived in an intermediate database. |
|
Managing User communication and prospecting campaigns via any means of communication (phone, SMS, post, email) |
User consent |
ID details + Contact details |
Three (3) years following the last contact made by the User. |
|
Managing requests submitted to the Website customer service |
User consent |
ID details + Contact details |
One (1) year following the last contact made by the User. |
|
Managing purchases of products or Services |
Contract |
ID details + Purchase history |
Three (3) years following the last contact made by the User. |
In accordance with the regulations in force, the Data Controller only retains Personal Data for the duration strictly necessary to fulfill the purposes of the processing, unless the User gives their consent for such data to be retained for later use.
Every time processing is started based on the data subject’s consent, they may withdraw their consent at any time under the conditions specified in Article 6.
In the event that a Personal Data collection form must be completed by a User, all mandatory fields are marked with an asterisk (*). Failure to provide the required data, or the subsequent withdrawal of consent by the data subject, shall prevent the Data Controller from proceeding with their request.
4. Communication of Personal Data
The information held by the Data Controller relating to Users and Visitors can be communicated to the following persons:
- The Data Controller’s staff, as well as the staff of sister or subsidiary companies, who are authorized to manage this processing due to their duties;
- Organizations entrusted with an audit or inspection assignment in accordance with applicable regulations;
- The external providers responsible for carrying out Personal Data processing operations on behalf of the Data Controller, who are contractually bound to a security and confidentiality obligation related to this Personal Data (for example, to secure online payments, prevent fraud, carry out website maintenance, collect customers opinions).
- Any person who has access to your Personal Data is bound by a strict obligation to confidentiality.
5. Transferring Personal Data outside the European Union
All of your Personal Data is processed exclusively within the territory of the European Union.
The Data Controller will not transfer your Personal Data outside European territory, except to companies controlled or held by CCF and to external service providers.
In the event that assistance is needed from providers based outside European Union territory, the Data Controller will first and foremost ensure that appropriate measures are put in place to ensure that the Personal Data is transferred within a contractual framework that respects its inherent confidentiality and that the safeguards and security arrangements pertaining to this processing comply with regulations applicable in France and the European Union.
6. Your rights with regard to your Personal Data
In accordance with the regulations in force, you have the following rights with regard to your Personal Data:
- Right to object: You may object to the use for legitimate reasons (except in the case of a legal obligation of the Data Controller) or reuse of your data for solicitation purposes, including commercial solicitation in particular, when placing an order or signing a contract.
- Right to restriction of processing: You may request that some of your data be temporarily frozen.
- Right of access: You may ask the Data Controller whether they hold personal data concerning you and to communicate it to you so that you can check the content.
- Right of rectification: You may request the rectification of inaccurate or incomplete personal data.
- Right to portability: The right to portability entitles you to recover part of your data in machine-readable format. You are free to store this portable data elsewhere or transfer it easily from one system to another for reuse or other purposes.
- Right to erasure: You may request the erasure of your data, except in the case of a legal obligation of the Data Controller.
You also have the option to communicate your instructions to the Data Controller on what should happen to your Personal Data after your death.
Users and Visitors are informed that exercising the rights of objection, erasure and data portability, as well as the right to restriction of processing, is subject to certain conditions and may be refused by the Data Controller if these requests do not correspond to the situations provided for in the regulations regarding Personal Data.
You may exercise your rights by writing to one of the following addresses. Proof of identity may be requested:
- By post: 37-39 Boulevard Murat, 75016 Paris, France
- By email: [email protected]
Requests will be processed in the best possible timeframe, and at the latest within three (3) months, subject to any regulatory extensions, e.g., in the event of a complex request or a high number of requests received.
Finally, if the Data Controller does not fulfill your requests, you have the right to make a complaint to a Personal Data protection authority, namely the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés, or CNIL) within French territory.
7. Cookies
When you visit the Website, cookies are placed on your terminal (PC, smartphone or tablet).
The Data Controller and CCF use cookies, for example, to identify you and to allow you to access your Account.
I. What are cookies?
A cookie is an information file placed on an Internet user’s hard drive by the server of the website they are visiting. A cookie contains multiple data: the name of the server that placed it, an identifier in the form of a unique number and, in some cases, an expiry date. This information is sometimes stored on computer in a plain text file which the server accesses in order to read and register the information.
II. Cookies used by the Website and their purpose
See our Cookie Policy directly on the Website.
III. Accepting and rejecting cookies
You have several options for managing cookies when you browse the Website.
- Via the banner that tells you about the use of cookies on the Website;
- By configuring your web browser.
You can opt to disable cookies at any time.
You can also configure your browser to let you know when cookies are going to be placed on your computer and to ask you to accept or reject them. You can accept or reject cookies on a case-by-case basis, or you can reject them systematically once and for all.
You are hereby reminded that configuring your browser in this way might alter your conditions of access to Website Services, optimum display of the Website or the Website browsing experience, which requires the use of cookies.
If you disable the cookies used by the Website, you may not be able to access some parts of the Website, or some of the settings you selected upon your first visit may not be remembered upon subsequent visits. For example, some pages won’t open, some videos and animations will be impossible to view, or some data may not be stored and will therefore not be filled in automatically upon subsequent visits.
In order to manage cookies in accordance with your expectations, we suggest that you configure your browser in accordance with the cookie purposes mentioned above.
Here is how to control cookies or stop them being saved:
The configuration process is different for each browser. Configuration is described in your browser’s help menu, which will explain how to change your cookie preferences. You can disable acceptance of cookies via your browser by following these instructions:
- Internet Explorer
- In Internet Explorer, click the “Tools” button, and then click “Internet options”.
- Under the “General” tab, click “Settings” under “Browsing history”.
- Click the “View files” button.
- Click the heading of the “Name” column to sort all files in alphabetical order, then scroll down the list until you see file names beginning with the prefix “Cookie” (all cookies have this prefix and generally contain the name of the website that created the cookie).
- Select the cookie(s) containing the name of this website and delete them.
- Close the window containing the list of files, then click twice on “OK” to return to Internet Explorer.
- Firefox
- Go to the browser “Tools” tab and select the “Options” menu.
- In the window that appears, choose “Privacy” then click “Show cookies”.
- Locate the files containing the name of this website, select them and delete them.
- Safari
- In your browser, choose the “Edit” menu, then “Preferences”.
- Click “Privacy”.
- Click “Show cookies”.
- Select the cookies containing the name of this website, then click “Delete” or “Delete all”.
- After deleting the cookies, click “Done”.
- Google Chrome
- Click the tools menu icon. Select “Options”.
- Click the “Advanced options” tab and go to the “Privacy” section. Click the “Show cookies” button.
- Locate the files containing the name of this website.
Select them and delete them.
Click “Close” to return to your browser. - Configuration on a cookie management platform
- You can manage your cookies by going to the cookie management platforms proposed by advertising professionals.
Version dated 29/10/2025
PRIVACY POLICY IN ACCORDANCE WITH THE FADP
|
…Did you know? Dear customers and users of the Circuscasino.fr website, The website is also accessible from Switzerland, where the Federal Act on Data Protection (FADP) of 25 September 2020, and its Ordinance (DPO) which entered into force on 1 September 2023, apply. …. Our website informs you and protects your personal data. Please carefully read our new Privacy Policy for the Circuscasino.fr website about the protection of your personal data. These Policy is independent of any Privacy Policy applicable to the processing of customer data in a physical casino in Switzerland. Don’t hesitate to contact us with any questions you may have. |
1. Definitions
The terms listed below have the following definitions:
- SCCM: Société du Casino de Crans-Montana SA, a company registered in the Canton of Valais Company Register in Switzerland under number CHE – 108.749.616, with the following postal address: Allée Katherine Mansfield 1, 3963 Crans-Montana;
- Data Controller: the private entity (in this case SCCM) which, alone or together with others, determines the purposes and the methods of processing;
- Customer Account: the account created on the Website by a SCCM member customer who has joined the CIRCUS CLUB Loyalty Program; the account allows the customer to access all information on their profile and special offers, news about SCCM members and information on the CIRCUS CLUB Loyalty Program;
- Personal data: all information concerning an identified or identifiable natural person;
- DPO: the Data Protection Officer responsible for advising the Data Controller and controlling the Data Controller’s compliance with applicable regulations regarding the processing of personal data.
- Service(s): the various services available to Website Users, such as: viewing their personal account and, where possible, editing their personal information; agreeing to receive promotional offers from SCCM; acquiring Gift Vouchers, Gift Checks and Gift Packs; managing their loyalty points; booking a service; filing a complaint with the relevant customer service, Data Controller or DPO.
- Website: the website accessible at: https://www.circuscasino.fr.
- User: any person residing in Switzerland aged 18 or over who does not feature on the list of the Swiss “VETO” system and who accesses the Website, whether or not they have created a Customer Account.
- Visitor: any natural person residing in Switzerland who visits the Website.
- Gift Voucher: the document containing the offer, location, validity number, validity date, beneficiary name and description that allows the beneficiary to take advantage of the offer at a SCCM member establishment. Gift Vouchers may be delivered by post or email or withdrawn directly at the establishment.
- Gift Check: the document showing the amount to be spent, the terms of application, location, beneficiary name, validity number and validity date. Gift Checks may be delivered by post or email or withdrawn directly at the establishment.
- Gift Pack: the package sent by post. A Gift Pack comprises the following items: (i) a Gift Voucher and/or Gift Check including a description of the service; (ii) a pouch or box containing the Gift Voucher.
2. When is my data collected?
The Data Controller collects your personal data when you visit the Website as a Visitor or User, when you create a Customer Account in accordance with the current Website General Terms of Use, and when you use the Services.
The Data Controller takes account of the principles of minimizing the amount of data collected and protecting data by design. Consequently, information is only processed if it is relevant, appropriate and limited to what is necessary for the purposes for which it is processed, in accordance with applicable regulations and case law.
The processing is based on a legitimate reason within the meaning of Article 31 of the Federal Act on Data Protection (FADP) (consent, overriding interest, or legal obligation).
3. Collection purposes and length of storage
The information collected is saved in one or more computer systems by the Data Controller, notably for the following purposes and lengths of storage:
|
Processing and its purposes |
Legal basis |
Category of data |
Length of storage |
|
Managing Customer Accounts |
User consent |
ID details + Contact details + Login details |
Throughout the duration of the User’s activity and for no more than three (3) years following the last contact made by the User. |
|
Managing User communication and prospecting campaigns via any means of communication (phone, SMS, post, email)
|
Overriding interest
User consent |
ID details + Contact details |
For as long as the User and CIRCUS CLUB Loyalty Program member remains “active”. In the event of no activity for three (3) years, the member status is switched to “inactive” and their data is archived in an intermediate database. After two (2) further years of inactivity, the member’s data is anonymized. |
|
Managing requests submitted to the Website customer service |
User consent |
ID details + Contact details |
One (1) year following the last contact made by the User. |
|
Managing purchases of products or Services |
Contract |
ID details + Purchase history |
Three (3) years following the last contact made by the User. |
In accordance with the regulations in force, the Data Controller only retains personal data for the duration strictly necessary to fulfill the purposes of the processing, unless the User gives their consent for such data to be retained for later use.
Every time processing is started based on the data subject’s consent, they may withdraw their consent at any time under the conditions specified in Article 6.
In the event that a personal data collection form must be completed by a User, all mandatory fields are marked with an asterisk (*). Failure to provide the required data, or the subsequent withdrawal of consent by the data subject, shall prevent the Data Controller from proceeding with their request.
4. Communication of Personal Data
The information held by the Data Controller relating to Users and Visitors can be communicated to the following persons:
- The staff of the Data Controller and of companies in the same group, who, on the basis of contractual clauses guaranteeing the confidentiality and security of personal data, are authorized to manage such processing;
- Organizations entrusted with an audit or inspection assignment in accordance with applicable regulations;
- The external providers responsible for carrying out personal data processing operations on behalf of the Data Controller, who are contractually bound to contractual clauses guaranteeing the confidentiality and security of personal data (for example, to secure online payments, fight against fraud, carry out site maintenance, collect customers opinions).
Any person who has access to your personal data is bound by a strict obligation to confidentiality
5. Transferring Personal Data outside the European Union
All of your personal data is processed, in principle, within Switzerland or the European Union, which has a level of protection recognized as adequate by the Federal Council.
In the event of recourse to service providers located outside the territory of the European Union, the Data Controller shall first ensure that the transfer has appropriate safeguards in accordance with Articles 16 et seq. of the FADP:
- An adequacy decision issued by the Swiss Federal Council;
- The implementation of standard Swiss contractual clauses recognized by the Federal Data Protection and Information Commissioner (FDPIC);
- -or-
- Any other equivalent protection mechanism recognized by the competent authorities.
6. Your rights for your personal data
In accordance with the regulations in force, you have the following rights with regard to your personal data:
- Right to be informed when your personal data is collected
- Right to object:You may object to the use for legitimate reasons (except in the case of a legal obligation of the Data Controller) or reuse of your data for solicitation purposes, including commercial solicitation in particular, when placing an order or signing a contract.
- Right to restriction of processing:You may request that some of your data be temporarily frozen.
- Right of access:You may ask the Data Controller whether they hold personal data concerning you and to communicate it to you so that you can check the content.
- Right of rectification:You may request the rectification of inaccurate or incomplete personal data.
- Right to portability:The right to portability entitles you to recover part of your data in machine-readable format. You are free to store this portable data elsewhere or transfer it easily from one system to another for reuse or other purposes.
- Right to erasure:You may request the erasure of your data, except in the case of a legal obligation of the Data Controller.
- Right to not be subject to a decision based solely on automated processing (including profiling)
- Right to withdraw your consent
The Users and Visitors are informed that exercising the rights of objection, deletion and portability of the Data, as well as the right of restriction of processing, is subject to certain conditions and may be refused by the Data Controller if these requests do not correspond to the situations provided for in the regulations regarding personal data.
You may exercise your rights by writing to one of the following addresses. Proof of identity may be requested:
- By post: SOCIETE DU CASINO DE CRANS-MONTANA SA, Allée Katherine Mansfield 1, 3963 Crans-Montana
- By email: [email protected]
Requests will be processed in the best possible timeframe, and at the latest within 30 days, subject to any potential extensions, e.g., in the event of a complex request or a high number of requests received.
Finally, if the Data Controller does not fulfill your requests, you have the right to make a complaint to a personal data protection authority, namely the Federal Data Protection and Information Commissioner (FDPIC).