This English text is a faithful translation of the French version. In the event of any discrepancy or ambiguity between the language versions, the interpretation most favourable to the consumer applies.
1. Purpose and scope
This Privacy Policy describes how UPARIS (SAS) (hereinafter “we”, “us” or “our”) collects and processes the personal data of users, prospects and clients via the www.uparisclub.com website (the “Site”).
This policy applies exclusively to processing carried out via www.uparisclub.com, unless otherwise stated.
2. Data controller – Contact details
The data controller is:
UPARIS (SAS) – Share capital: €100,000 Address: 102 avenue des Champs-Élysées, 75008 Paris, France Tel.: +33 1 79 61 76 96 Email: contact@uparis.org SIRET: 829 456 136 00029 VAT (intra‑EU): FR66829456136 Atout France registration: IM075170050
For any question relating to data protection or to exercise your rights: contact@uparis.org (subject: “GDPR – Personal data”). We have not appointed a data protection officer (DPO), as our activity is not subject to that requirement (Article 37 GDPR).
3. Personal data processed
Depending on your browsing, communications and/or booking, we may process the following categories of data:
3.1. Identification and contact data
Name, first name, title, date of birth, nationality, email, phone, country of residence, language, emergency contact (name, phone, relationship); where applicable, passport details (invitation letter for the Schengen visa, pre-departure questionnaire).
3.2. Booking and trip‑related data
Booked trip, dates, options, information necessary for organization (logistics, operational constraints), exchanges with customer service, and communication history.
3.3. Data of other Travelers (multi‑Traveler bookings)
When the Client adds one or more Travelers to the booking, we process data strictly necessary to perform the Contract (e.g., identity and information useful for organization). The Client declares being authorized to provide this data and undertakes to have informed the Travelers, in particular about the T&Cs and this Privacy Policy.
3.4. Payment data
Payments are processed by a payment provider. We do not store the full bank card number. We may retain information necessary for proof and accounting management (status, reference, amount, invoice).
3.5. Technical and browsing data
IP address, technical logs, cookie identifiers, browser/device type, pages visited, browsing events, language settings (according to your cookie choices and browser settings).
3.6. Sensitive data (health) – only if necessary
Certain activities may require, for safety reasons, relevant information (e.g., allergies/contraindications). This information is requested only if necessary, in optional fields, and access is limited to authorized persons. It is processed on the basis of your explicit consent (Article 9.2.a GDPR), which you give by filling it in; you may withdraw it at any time by asking us to erase it.
3.7. Checkout draft data (temporary storage)
To improve the user experience during the booking process, we may temporarily store checkout form data (participant information, billing details, consent choices) on our servers. This enables:
- Checkout recovery: If you refresh the page or navigate away, your progress is preserved.
- Cross-device continuity: You can start a booking on one device and continue on another.
Storage duration: Checkout draft data is automatically deleted after 30 days of inactivity or immediately upon successful booking completion (when data is transferred to permanent booking records).
Legal basis: Legitimate interest (improving user experience and reducing booking abandonment). This temporary storage is proportionate and includes automatic expiration to ensure compliance with data minimization principles.
4. Purposes of processing
We process your data in particular to:
- handle your requests (questions, quotes, information);
- manage your bookings (file creation, confirmation, invoicing, trip organization, participant management);
- perform the contract (provider coordination, logistics, pre‑departure information, assistance);
- customer service and complaints (follow‑up, resolution, mediation/dispute);
- comply with legal obligations (accounting, invoicing, evidence);
- site security and fraud prevention;
- site improvement and audience measurement (according to your cookie choices);
- communication/marketing (newsletter/offers) according to applicable rules and your choices;
- the departure WeChat group, if you have chosen to join it (section 6).
5. Legal bases
Processing is based, depending on the case, on:
- performance of the contract or pre‑contractual measures (booking, organization, assistance);
- compliance with legal obligations (e.g., accounting, dispute management);
- the establishment, exercise or defence of legal claims (in particular keeping the identity of the Travellers of a paid booking, see section 8);
- our legitimate interest (security, service improvement, fraud prevention), subject to your rights;
- your consent where required (non‑essential cookies, certain prospecting, use of your image, departure WeChat group, etc.); for health data, your explicit consent (section 3.6).
The data marked as mandatory in our forms are necessary for the conclusion and performance of the Contract: without them, the booking cannot be processed. We do not take any decision based solely on automated processing producing legal effects concerning you (Article 22 GDPR).
You can withdraw your consent at any time when processing is based on it.
6. Recipients – Processors
Your data are accessible, within the limits of their needs, to:
- our authorized staff (operations, support, accounting);
- travel providers necessary to perform the trip (accommodation, guides, carriers, etc.);
- technical providers (hosting/infrastructure, maintenance, emailing/CRM, support tools, payment provider, anti‑fraud, audience measurement subject to consent), acting as processors.
We require our providers to commit to confidentiality and security in accordance with applicable regulations.
Departure WeChat group: for practical exchanges before and during the Trip (meeting point, weather, safety instructions), we create a group for each departure on WeChat, a third-party messaging service operated by the Tencent group. Joining it is optional: you agree to it through a separate checkbox at booking, unticked by default (legal basis: your consent, Article 6.1.a GDPR); you may decline to join it, or withdraw your consent at any time by leaving the group, without any effect on your booking, and essential information is also sent to you by email. If you have agreed, we send you the group’s QR code after payment (through our staff or through a personal link sent by email, which expires at the end of the Trip), which you scan to join; a WeChat group QR code is only valid for 7 days, we renew it and you can ask for a new one from our official WeChat account uparis_outdoor. If you join the group, the following are visible to the other members: your WeChat name or nickname, your profile photo and your WeChat ID, and the messages, photos and files you post there. Tencent processes these data as an independent controller, under its own terms of use and privacy policy, outside the European Economic Area, in countries that do not necessarily benefit from an adequacy decision of the European Commission and without appropriate safeguards within the meaning of Article 46 GDPR: the transfer of the data we ourselves post in the group is based on your explicit consent, given when you choose to join it (Article 49.1.a GDPR). We post there only practical information about the Trip and take care not to share any of your booking data there (contact details, identity documents, health data). Our staff, including the official uparis_outdoor account, take part in these groups with WeChat accounts registered outside mainland China. We keep with your booking whether you joined the group (joined or not), for the same period as the booking (section 8).
7. Data location – Transfers outside the EEA
7.1. Hosting and infrastructure
- Customer data / back‑end: infrastructure and customer data hosted on Oracle Cloud Infrastructure – Frankfurt region (Germany).
- Backup copies: replica of the invoices and encrypted database backups on Oracle Cloud Infrastructure – Marseille region (France); standby server and encrypted copy of the backups in France. These data remain within the European Union.
- Front‑end / security / performance: the Site uses Cloudflare services (delivery network, security, storage of the Site’s images and of the photos published with reviews) which may involve technical processing of certain data (e.g., logs, IP) via a distributed infrastructure.
7.2. Transfers outside the EEA and safeguards
When certain providers may result in transfers of data outside the European Economic Area, we implement appropriate safeguards (notably standard contractual clauses – SCCs, and, where applicable, additional measures), or rely on an adequacy decision of the European Commission (for example for Switzerland, or for US companies certified under the EU-U.S. Data Privacy Framework). The transmission to a tourism service provider located outside the EEA of the data necessary for the performance of your Trip is based, in the absence of such a decision, on Article 49.1.b GDPR (performance of the contract). For the departure WeChat group, see section 6.
You can request a copy of the applicable safeguards (e.g., SCCs), subject to the protection of confidential information, by writing to contact@uparis.org.
8. Retention periods
We keep your data only for as long as necessary for the purposes pursued. When these periods end, the data are automatically deleted or anonymised (daily process); we keep no archive of data that could identify you beyond these periods. Anonymised statistical data derived from orders (trip, dates, amounts, age bands, countries, acquisition channel) are kept without time limit: they no longer make it possible to identify you and are therefore no longer personal data.
8.1. Periods by category of data
| Data | Retention period | Reason |
|---|---|---|
| Customer account (e‑mail address) | Until the account is deleted (by you from your account page, or on request) | Account management |
| Identity of the Travellers of a paid booking (last name, first name, date of birth, nationality, phone, e‑mail) and billing details | 3 years after the end of the trip in our active database, then restricted-access intermediate archiving (see 8.4) until 10 years after the end of the trip, then anonymised | Establishment, exercise or defence of legal claims (liability for bodily injury: 10‑year limitation period, French Civil Code art. 2226; GDPR art. 17(3)(e)) and accounting obligations |
| Bookings, payments and refunds (amounts, dates, statuses) | 10 years after the end of the trip; only amounts, dates and statuses are kept afterwards, for statistics (linked to your account for as long as it exists) | Accounting obligations (French Commercial Code art. L123‑22) |
| Invoices (PDF files) | 10 years from their issue, then deleted automatically | Accounting and tax obligations |
| Health and assistance data entered when booking (medical conditions, allergies, diet, special needs, emergency contact) | 90 days after the end of the trip | Running the trip safely, handling incidents reported after the return |
| Pre‑departure questionnaire (passport, emergency contact, insurance, flights, sizes) | 90 days after the end of the trip; only the “questionnaire completed” status is kept | Organising the trip |
| Questionnaire access link | 7 days after the end of the trip | Access to the questionnaire |
| Unpaid or unfinished orders (abandoned drafts, failed payments, orders expired or cancelled without any payment) | 1 year after the order expired or was cancelled (or, for an abandoned draft, after it was last modified), then anonymised; traveller and billing data deleted as soon as the account is deleted | Account management |
| Checkout draft (form in progress) | 30 days, then deleted automatically (see 3.7) | Resuming the booking |
| Departure WeChat group: the group’s QR code (an image we supply, containing no data about you); personal access link sent by email; whether you joined (joined or not) | QR code: until 30 days after the end of the Trip, then deleted; personal link: expires at the end of the Trip; join status: kept with the booking (same periods) | Departure WeChat group (consent) |
| Waiting list (e‑mail, phone, notes) | 30 days after the departure date concerned; offer links: 7 days after the offer ends | Waiting list management |
| Saved trips (favourites) | Until you remove them or delete the account | Service you requested |
| Published reviews | Until removed; when the account is deleted, the text and rating stay online without a name or link to the account, and the photos are deleted | Information for other travellers |
| Cookie choices (proof of consent) | 13 months | CNIL guidance |
| Audience measurement and marketing attribution (UTM), with your consent | 12 months at most; deleted as soon as you withdraw your consent. The acquisition channel of an order (source, medium, campaign, landing page without parameters, dates) is kept with the order and anonymised at the same time as the order; it is deleted as soon as you withdraw your consent or delete your account. | CNIL guidance |
| Sign‑in links, account deletion confirmation link and sessions | Sign‑in link: 15 minutes; confirmation link: 30 minutes; session: 30 days; deleted at the latest 1 day after expiry | Security |
| Security and access logs (sign‑ins, permissions, access to sensitive data by our team) | 1 year | Service security |
| Financial and booking operation logs (orders, payments, refunds, invoices, cancellations, transfers, seat reservations, departure status changes, account deletions) | 10 years; the personal data they contain are anonymised together with the booking | Accounting audit trail and proof of operations |
| Our team’s conversations with the internal AI assistant | 1 year | Internal support |
| Commercial prospecting | Until you withdraw your consent or object, or after a reasonable period of inactivity | Consent |
| Encrypted database backups | 13 months at most (automatic rotation) | Business continuity (see 8.3) |
| Disputes | Duration of the proceedings and limitation periods | Defence of our rights |
8.2. Deleting your account
From your account page (“Privacy & personal data” section) you can download a copy of your data (JSON file) and ask for your account to be deleted; we e‑mail you a confirmation link, valid for 30 minutes. Deletion erases your profile, saved trips, waiting‑list entries, cookie choices, marketing data, questionnaire answers and the health and assistance data of your bookings, deletes the photos of your reviews (the text and rating stay online without your name) and ends all your sessions. The identity of the Travellers, the billing details and the records of paid bookings are kept for the period stated above, no longer linked to an active account, then anonymised. If a trip is upcoming or in progress, or a payment or cancellation is pending, please ask our customer service to delete the account.
8.3. Backups
Our backups are encrypted and stored in the European Union (Germany, France) for 13 months at most. Deleted or anonymised data disappear from the backups when they expire. If a backup ever had to be restored, the account deletions and anonymisations carried out since its date would be applied again before the service is put back online.
8.4. Intermediate archiving
Your booking data is kept in our active database for 3 years after the end of your trip, so that we can follow up on your file (customer service, claims, new bookings). After that period it is moved to intermediate archiving until it is anonymised, 10 years after the end of the trip: your identification data (travellers’ names, contact details, date of birth, billing address, any passport details and emergency contacts still held) is no longer visible to our staff nor retrievable by a search; only non-identifying accounting and business data (amounts, dates, trip, order and invoice numbers) remains available. Access to archived data is restricted to a small number of administrators, only for a justified reason (legal or accounting obligation, establishment, exercise or defence of legal claims, request from an authority), and every access is justified and logged. Invoices, as accounting records, are kept for 10 years (French Commercial Code, article L123-22). You can always view your own bookings from your account.
9. Security
We implement appropriate technical and organizational measures: access control and limitation of authorizations, segregation, encryption of communications and backups, logging of our team’s access to sensitive data, minimization (automatic deletion or anonymisation when the periods in section 8 end). Despite these measures, no system offers absolute security.
10. Cookies and trackers
The Site uses:
- strictly necessary cookies (operation, security, cart/order if applicable);
- optional cookies (audience measurement, personalization, marketing), subject to your consent.
You can accept, refuse, or configure cookies via the banner during your first visit, then change your choices at any time via Manage my cookies. To learn more: Cookie Policy.
11. Your rights
In accordance with the GDPR, you have, in particular, the following rights: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent (if applicable).
From your account page: the “Privacy & personal data” section lets you download a copy of your data (rights of access and portability, JSON file) and delete your account (right to erasure, see section 8.2).
Exercising your rights: write to contact@uparis.org (subject: “GDPR – Personal data”). We may request proof of identity in case of reasonable doubt about the requester’s identity.
The right to erasure does not apply to data we must keep to comply with a legal obligation or for the establishment, exercise or defence of legal claims (GDPR art. 17(3)); these data are kept only for the periods stated in section 8.
You may also set out directives concerning the retention, erasure and communication of your data after your death (Article 85 of French Law No. 78-17 of 6 January 1978), and object at any time to commercial prospecting.
You may also lodge a complaint with the competent supervisory authority (in France: the CNIL, www.cnil.fr).
12. Policy updates
We may modify this policy to reflect legal, technical, or operational changes. The version published on the Site is the version applicable on the date of consultation.