Privacy policy
Last updated: August 18, 2026.
This policy describes the processing carried out by inad.info and its administration. The French version constitutes the reference version.
Data controller
National Institute of Divinatory Arts (INAD)
8 rue de Nesle, 75006 Paris, France
Telephone: +33 (0)1 40 35 70 89
Email: contact@inad.info
Purposes, data and legal bases
- Memberships and directory: identity, contact details, association status, professional presentation, photography and choice of publication. When requested, the address shown on the public profile is kept separate from the private postal address used for the membership card, personalised display plaque and INAD correspondence. The private postal address is never published. These processing operations are used to manage the associative relationship and the requested publication. Depending on the case, they are based on the associative contract, consent to optional elements and the legitimate interest of INAD in keeping its directory up to date.
- Requests and contact: identity, contact details and content of the request, in order to respond to it. The processing is based on the requested process or the legitimate interest in processing the exchanges.
- HelloAsso Payments: identity of the payer, amount, status and technical references of the payment, for reconciliation, accounting and anti-fraud purposes. Banking data is collected by HelloAsso and is never transmitted to INAD. The processing is based on the requested process and legal obligations.
- Comments: the chosen name and the message are published. For new comments, the plain email address is not kept: it is transformed into a pseudonymous imprint used for abuse prevention. Technical fingerprints of the IP address and browser are used for quotas and reporting. Publication is based on your consent; security and moderation on the legitimate interest of INAD and its moderation obligations.
- Administration and security: administrator accounts, audit logs, incidents and technical data necessary for security, on the basis of legitimate interest and security obligations.
- First-party audience measurement: visited page, time, general source, optional campaign, device category, browser family and country. Limited events measure contact or payment clicks, shares, downloads, media starts, reading milestones and technical performance. Search and form text is never recorded. The country is determined locally from the IP address, after which the IP address is immediately discarded. A random identifier limited to 30 minutes links pages from the same visit. It produces statistics only for INAD, without advertising, individual profiling, cross-site tracking or disclosure to a third party. It is based on INAD’s legitimate interest in understanding and improving its website.
- INAD social networks: when an administrator links a Meta Page, the Page identifier, permissions and necessary token are encrypted. INAD never receives the Facebook password.
For historical profiles, INAD distinguishes in its records between photographic authorization attested by the data controller, the technical image upload date and evidence of previous publication of contact details. Any new publication of a photograph or optional contact detail requires separate confirmation of the practitioner’s request.
Information specific to comments
The name and message fields are intended to be public. The requested email is not displayed and is not kept in plain text for a new comment. Comments that are obviously advertising, abusive, repetitive, contain several links or sent abnormally quickly may be placed on hold for moderation. No advertising profiling or decisions with legal effect are made. You can report a comment or consult the rules.
Recipients and subcontractors
The data is accessible only to persons authorized by INAD and, to the extent necessary, to its service providers: Heroku/Salesforce for the application and PostgreSQL, Cloudinary for images, HelloAsso for payments, Papertrail for technical logs and SMTP2GO, configured for processing in the European Union, for messages required for access, membership and its administration. Non-essential reminders follow the communication preferences on record.
Video or audio players and Google Maps never load before an explicit click. The facade identifies the relevant provider. After that click, the provider receives technical data including your IP address and may apply its own policy. Links to Facebook, X or other sites are simple links and do not load any social script on inad.info.
Transfers outside the European Economic Area
Some providers may process data in the United States or other countries. INAD selects service providers offering a recognized mechanism, in particular the EU–US data protection framework where it applies, or standard contractual clauses. Applicable warranties can be requested at the contact address above.
Retention periods
- anti-abuse counters: up to 25 hours;
- visits to a personal renewal link: 13 months;
- first-party audience visits: 13 months;
- comment reports: 24 months after their processing;
- published comments: for the duration of publication of the page or until an admissible request, with anonymization or withdrawal when it is preferable to preserve the editorial context;
- membership and directory data: during the associative relationship, then up to 5 years for proof and defense of rights, subject to accounting obligations;
- payment documents and entries: 10 years when accounting rules require it;
- administration logs: 5 years at most, except for incidents requiring justified retention;
- Meta token: until the Page is disconnected or a deletion request is made.
Cookies and local storage
The site uses no advertising cookies or third-party analytics. Its first-party audience measurement uses only a random identifier kept in the current tab for no more than 30 minutes. It cannot identify a person. You may disable or enable it at any time. The opt-out choice is remembered for 13 months. The Rails session cookie named _inad_session is strictly necessary for form security and authenticated spaces. It is protected by the Secure, HttpOnly and SameSite=Lax attributes and expires after 12 hours at the latest. External content is loaded only after your contextual click.
Your rights
You can request access, rectification, erasure, limitation or portability where applicable, object to processing based on legitimate interest and withdraw consent at any time without calling into question previous operations.
Send your request to contact@inad.info or to INAD headquarters. Specify the data concerned. Identification is only requested in cases of reasonable doubt. INAD responds in principle within one month. You may also lodge a complaint with the CNIL.
Consult the deletion procedure, the legal notices and the moderation policy.