Your data
Privacy policy
What this site collects, why, and how to exercise your rights.
1. Purpose
This policy describes how Vision Performance Golf collects, uses and protects the personal data of visitors to the Site and of the clients of its services, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (General Data Protection Regulation, hereinafter "GDPR") and the applicable national legislation.
2. Data controller
The data controller is Valentin Peugnet EI, trading as Vision Performance Golf, represented by Valentin Peugnet, [Business domiciliation address, to be completed], France.
Contact for any question about personal data: valentin.peugnet@gmail.com.
No data protection officer has been appointed, as this appointment is not mandatory given the size and activity of the publisher. [To be confirmed by legal counsel]
3. Data collected
The Site does not collect any data without its visitors' knowledge: it uses no audience measurement tool, no advertising tracker and creates no user accounts. Simply browsing the pages does not involve any collection of personal data by the publisher, apart from the hosting provider's technical logs described in point 3.4.
3.1 Contact form
When you use the form on the Contact page, the following data is transmitted to the FormSubmit service, then to the publisher by email:
- name;
- email address;
- playing level (optional);
- content of the message;
- language version of the Site used (French or English);
- date and time of sending;
- IP address, recorded technically by FormSubmit for security purposes and to prevent automated submissions.
The form includes a hidden field designed to filter out robots; it collects no data about human visitors.
3.2 Online booking
Appointments are booked through the Cal.com service, embedded in the Site. When you make a booking, you provide Cal.com with:
- your first and last name;
- your email address;
- the chosen time slot and time zone;
- where applicable, your answers to the questions asked during booking (for example your playing level or a note for the session);
- your telephone number, if the booking form asks for it.
When the booked service is paid, payment is processed by Stripe, the payment provider integrated with Cal.com. Payment data (card number, expiry date, security code) is entered directly on Stripe's secure pages; it never passes through the Site and is never accessible to the publisher, who only receives confirmation of payment and, where applicable, the last four digits of the card.
3.3 Coaching exchanges
In the course of the services, you may voluntarily provide the publisher with information useful for coaching: playing statistics, scorecards, exports from tracking applications, goals, competition reports, session notes. The publisher may also write his own session notes and game plans. This information is kept in the client file and is used only for the service.
Exchanges about form, stress or mental preparation remain within the scope of sports coaching. The publisher does not collect health data within the meaning of the GDPR and asks you not to provide any; if you nevertheless do so, it is processed only with your explicit consent and solely to adapt the service.
3.4 Technical data
The Site's hosting provider may record technical logs (IP address, date, page requested, browser) for security purposes and for the operation of the service. The publisher does not use these logs for audience analysis.
4. Purposes and legal bases
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Responding to a contact request | Form data | Steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR) |
| Managing the booking, delivery and follow-up of services | Booking data, coaching exchanges | Performance of the contract (Article 6(1)(b)) |
| Collecting payments, issuing and keeping invoices | Identity, amount, payment confirmation | Performance of the contract and legal accounting and tax obligations (Articles 6(1)(b) and 6(1)(c)) |
| Ensuring the security of the Site and the embedded services | IP address, technical logs | Legitimate interest of the publisher and its providers (Article 6(1)(f)) |
| Remembering the chosen language | Language preference stored in your browser | Strictly necessary operation of the Site, at your request |
| Processing any sensitive data provided spontaneously | See point 3.3 | Explicit consent (Article 9(2)(a)) |
No data is used for marketing purposes. The Site does not offer a newsletter. The publisher makes no automated decisions producing legal effects concerning you.
5. Recipients and processors
The data is intended for the publisher alone. It is processed on the publisher's behalf by the following providers, acting as processors within the meaning of Article 28 GDPR or, in the case of the payment provider, as a separate controller for its own obligations:
- FormSubmit, the service available at formsubmit.co [country of establishment and transfer safeguards to be checked]: receipt and forwarding of contact form messages;
- Cal.com, Inc. (United States): appointment booking, reminders and calendar management;
- Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., United States): payment processing;
- [Name and address of the hosting provider]: hosting of the Site;
- [Email and client file storage provider]: email and storage of client files.
The publisher does not sell, rent or transfer your data to third parties. It may be disclosed to the competent authorities where required by law.
6. Transfers outside the European Union
Some of the providers listed above are established in the United States or host data there. These transfers are covered by the safeguards provided for in Chapter V of the GDPR: the European Commission's adequacy decision for companies certified under the EU-US Data Privacy Framework, or the standard contractual clauses adopted by the Commission, supplemented where necessary by additional measures. [Applicable safeguard to be checked for each provider: FormSubmit, Cal.com, Stripe, hosting provider, email]. You can obtain a copy of the applicable safeguards by writing to valentin.peugnet@gmail.com.
7. Retention periods
| Data | Retention period |
|---|---|
| Contact requests not followed by a contract | [3 years] from the last exchange |
| Client file (bookings, statistics, session notes, game plans) | Duration of the relationship, then [3 years] from the last service |
| Invoices and accounting records | [10 years] from the end of the financial year, in accordance with accounting and tax obligations |
| Language preference (browser) | Until you delete your browser's site data |
| Hosting provider's technical logs | According to the hosting provider's policy, [period to be checked with the hosting provider] |
At the end of these periods, the data is deleted or anonymised.
8. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your data:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to object, for processing based on legitimate interest;
- right to portability of the data you have provided;
- right to withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out beforehand;
- right to give instructions on what happens to your data after your death, where the applicable law provides for it.
To exercise these rights, write to valentin.peugnet@gmail.com or to the postal address given in point 2. You will receive a reply within one month, which may be extended by two months for complex requests. In case of reasonable doubt about your identity, proof of identity may be requested.
You also have the right to lodge a complaint with the competent supervisory authority: the Commission nationale de l'informatique et des libertés (CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr).
9. Security
The publisher implements technical and organisational measures appropriate to the sensitivity of the data: the Site is served exclusively over HTTPS, there is no exposed database, access to provider accounts is protected by strong passwords and two-factor authentication where the service allows it, and client files are stored in restricted-access spaces. Payments are processed by Stripe, a PCI DSS certified provider. No transmission over the Internet is entirely secure, however; in the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with Article 34 of the GDPR.
10. Cookies and trackers
The Site itself sets no cookies and uses no audience measurement, advertising or visitor tracking tool.
The only item stored in your browser is a language preference, kept in "localStorage" under the name "vp_lang", which remembers the last version (French or English) you viewed. This item is strictly necessary for the operation requested by the visitor, contains no identifying data, is not sent to any server and is not subject to consent. You can delete it at any time by clearing your browser's site data.
Two third-party services are embedded in the Site and may set their own cookies or trackers, subject to their respective policies:
- Cal.com, when the booking calendar is displayed (Contact page) or when you open a booking window from a "Book" button: the calendar script is then loaded from Cal.com's servers, which may use cookies and local storage needed for the booking and for payment through Stripe;
- FormSubmit, when the contact form is sent: your browser communicates with FormSubmit's servers, which may apply their own security measures.
These services are not called when you browse the other pages of the Site without using the booking calendar or the form.
11. Minors
The Site and its services are intended for adults. A minor golfer may only receive a service with the written consent of his or her legal representative, who makes the booking, pays and receives the communications about the coaching. The publisher does not knowingly collect data about minors outside this framework; any data collected without this consent will be deleted on request.
12. Changes to this policy
This policy may be updated to reflect changes to the Site, to the services used or to the regulations. The version in force is the one published on the Site, with its update date. In the event of a substantial change affecting clients with an ongoing programme, they will be informed by email.
Last updated: [Date of publication].