Last updated: 7 May 2026
Preamble
The European Society of Scientific Acupuncture (hereinafter “ESSA” or the “Association“), publisher of the website accessible at the URL https://www.scientific-acupuncture.eu (hereinafter the “Website“), attaches the utmost importance to the protection of the personal data of the natural persons interacting with the Website (hereinafter the “Data Subjects“) and undertakes to process such data in strict compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR“), as well as with the French Law n° 78‑17 of 6 January 1978, as amended, on Information Technology, Data Files and Civil Liberties (hereinafter the “French Data Protection Act“).
The present privacy policy (hereinafter the “Policy“) is intended to inform Data Subjects, in a concise, transparent, intelligible and easily accessible form, in clear and plain language, of the conditions under which ESSA collects, processes, stores, transmits and protects their personal data, and of the rights conferred upon them by the applicable regulations.
Article 1 — Data Controller
The data controller, within the meaning of Article 4(7) of the GDPR, is:
European Society of Scientific Acupuncture
A non‑profit association governed by the French Law of 1 July 1901
Currently undergoing formal declaration with the Préfecture de Police of Paris pursuant to Article 5 of the said Law
Registered office: 9, rue Quentin Bauchart – 75008 Paris, France
Email: contact@scientific-acupuncture.eu
In view of the size of the Association and the nature of its processing activities, ESSA is not required, pursuant to Article 37 of the GDPR, to designate a Data Protection Officer. Any request relating to the processing of personal data, or to the exercise of the rights set out in Article 5 below, shall be addressed to ESSA at the contact details set out hereinabove.
Article 2 — Data Processed, Purposes and Legal Bases
In its current configuration (a holding page pending the official launch of the full Website, scheduled for autumn 2026), the Website implements the limited processing operations described below, in accordance with the principles of lawfulness, fairness and transparency, purpose limitation and data minimisation set out in Article 5(1) of the GDPR.
2.1 Subscription to the Launch Announcement List
(a) Categories of data processed: the Data Subject’s email address; the date and time of subscription; proof of consent (validation of the double opt‑in confirmation link).
(b) Purposes of processing: (i) to send the Data Subject the official announcement of the launch of the Website; and (ii) where applicable, to send occasional information regarding the Association’s scientific activities, publications and events.
(c) Legal basis: the consent of the Data Subject, within the meaning of Articles 6(1)(a) and 7 of the GDPR, collected by means of a double opt‑in mechanism guaranteeing the free, specific, informed and unambiguous nature of such consent. The Data Subject may withdraw his or her consent at any time, under the conditions set out in Article 5 below.
2.2 Server Logs and Technical Browsing Data
(a) Categories of data processed: IP address; type and version of the browser used; pages consulted on the Website; date and time of connection.
(b) Purpose of processing: to ensure the security, integrity and proper technical functioning of the Website, and to prevent any fraudulent use or attempted intrusion.
(c) Legal basis: the legitimate interest of the Association, within the meaning of Article 6(1)(f) of the GDPR, consisting in ensuring the security of its information system, such interest having been duly balanced against the rights and freedoms of the Data Subjects.
2.3 Email Correspondence
(a) Categories of data processed: the email address of the sender and the content of any message addressed to ESSA.
(b) Purpose of processing: the handling of and response to the requests addressed to the Association.
(c) Legal basis: the legitimate interest of the Association, within the meaning of Article 6(1)(f) of the GDPR, in responding to the requests addressed to it.
Article 3 — Recipients of the Data
3.1 The personal data collected through the Website shall under no circumstances be sold, rented, exchanged or transferred to third parties for commercial purposes.
3.2 Such data may be disclosed to the following service providers, acting in the capacity of “processors” within the meaning of Article 4(8) of the GDPR and bound to ESSA by a contract complying with the requirements of Article 28 of the GDPR, providing in particular sufficient guarantees as to the implementation of appropriate technical and organisational measures:
| Processor | Subject‑matter of the processing | Hosting location |
|---|---|---|
| Brevo (Sendinblue SAS) | Management of the subscription list and dispatch of electronic communications | France / European Union |
| OVH Cloud | Hosting of the Website | France / European Union |
3.3 Personal data may further be communicated, where applicable, to any administrative or judicial authority duly empowered to request access thereto, in accordance with the legal and regulatory provisions in force.
3.4 In the current state of its operations, the Association does not carry out any transfer of personal data outside the European Union or the European Economic Area. Should such transfers become necessary in the future, they shall be carried out exclusively to (i) third countries benefiting from an adequacy decision adopted by the European Commission pursuant to Article 45 of the GDPR or, failing that, (ii) on the basis of the appropriate safeguards provided for in Articles 46 and 47 of the GDPR, in particular standard contractual clauses adopted by the European Commission.
Article 4 — Retention Periods
In accordance with the principle of storage limitation set out in Article 5(1)(e) of the GDPR, personal data shall be retained for no longer than is necessary for the purposes for which they are processed, in accordance with the following retention periods:
| Category of data | Retention period |
|---|---|
| Email address (subscribers having validated the double opt‑in) | Until withdrawal of consent, or, at the latest, three (3) years from the last active contact with the Data Subject |
| Email address (double opt‑in not validated) | Thirty (30) days, after which automatic deletion shall occur |
| Server logs | Twelve (12) months from their collection |
| Email correspondence | Three (3) years from the last exchange with the Data Subject |
Upon expiry of the applicable retention period, personal data shall be deleted or anonymised in such a manner that the Data Subject can no longer be identified, whether directly or indirectly.
Article 5 — Rights of Data Subjects
5.1 In accordance with Articles 15 to 22 of the GDPR and Articles 49 et seq. of the French Data Protection Act, Data Subjects shall have the following rights with respect to their personal data:
(i) the right of access to personal data concerning them (Article 15 GDPR);
(ii) the right to rectification of inaccurate or incomplete data (Article 16 GDPR);
(iii) the right to erasure, also known as the “right to be forgotten” (Article 17 GDPR);
(iv) the right to restriction of processing (Article 18 GDPR);
(v) the right to data portability (Article 20 GDPR);
(vi) the right to object to processing (Article 21 GDPR);
(vii) the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of such consent prior to its withdrawal (Article 7(3) GDPR); and
(viii) the right to formulate directives concerning the fate of one’s personal data after death, in accordance with Article 85 of the French Data Protection Act.
5.2 Exercise of rights. Any request for the exercise of the foregoing rights shall be addressed to ESSA at the email address dpo@scientific-acupuncture.eu, accompanied, where reasonable doubt exists as to the identity of the requester, by any document enabling such identity to be verified. ESSA shall reply within a maximum period of one (1) month from receipt of the request, in accordance with Article 12(3) of the GDPR. This period may be extended by a further two (2) months, having regard to the complexity and the number of requests, in which case the Data Subject shall be informed of such extension and of the reasons for the delay within one (1) month from receipt of the request.
5.3 Unsubscription. Each electronic communication sent by ESSA includes a one‑click unsubscription link, accessible at the foot of the message.
5.4 Right to lodge a complaint. Without prejudice to any other administrative or judicial remedy, every Data Subject shall have the right to lodge a complaint with a supervisory authority, in particular with the Commission nationale de l’informatique et des libertés (CNIL), situated at 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, www.cnil.fr, where he or she considers that the processing of personal data concerning him or her infringes the GDPR or the French Data Protection Act.
Article 6 — Cookies and Similar Technologies
6.1 In its current version (a holding page), the Website does not deposit any audience measurement, advertising, profiling or third‑party cookie on the User’s terminal equipment.
6.2 Only cookies which are strictly necessary for the provision of an online communication service expressly requested by the User may be deposited (in particular: session cookies, security cookies, language preference cookies). In accordance with Article 82, paragraph 2, of the French Data Protection Act, such cookies are exempt from the requirement of prior consent.
6.3 Upon the official launch of the full Website, the present Article shall be updated and, where applicable, a cookie consent management interface shall be implemented in order to obtain, in compliance with Article 82 of the French Data Protection Act and the recommendations of the CNIL, the prior, free, specific, informed and unambiguous consent of Users for the deposit of any cookie not falling within the exemption referred to in paragraph 6.2 above.
Article 7 — Security Measures
7.1 In accordance with Articles 5(1)(f) and 32 of the GDPR, ESSA implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks presented by the processing, in particular against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
7.2 Such measures include in particular:
(i) the encryption of communications between the User’s terminal and the Website by means of the HTTPS protocol (TLS);
(ii) restricted access to the administration interfaces of the Website and of the email service provider, on a need‑to‑know basis;
(iii) the implementation of robust authentication procedures for administrator accounts, including, where the service so permits, multi‑factor authentication;
(iv) the regular updating of the WordPress content management system and of the extensions installed thereon.
7.3 In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, ESSA shall notify the CNIL within seventy‑two (72) hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where such breach is likely to result in a high risk, the Data Subjects concerned shall be informed without undue delay, in accordance with Article 34 of the GDPR.
Article 8 — Amendments to the Policy
ESSA reserves the right to amend the present Policy at any time, in particular to take account of changes in legislation, case law or technology, or upon the official launch of the full Website scheduled for autumn 2026. Any substantial amendment shall be brought to the attention of Data Subjects by means of a notice on the present page, accompanied by an update of the date set out at the head of the Policy. Data Subjects are invited to consult the Policy regularly. Continued use of the Website after such amendments shall be deemed to constitute acknowledgement thereof.
Article 9 — Contact
For any question relating to the present Policy or to the processing of personal data carried out by ESSA, the Data Subject may contact the Association at the following address:
European Society of Scientific Acupuncture
contact@scientific-acupuncture.eu