Article 1 - Purpose
1.1. This policy describes how your personal data is collected and processed when you use this website: what data, what for, on what basis, for how long, who has access to it, and what rights you can exercise.
1.2. It is drawn up in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data, known as the « GDPR », and with French Act No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, as currently in force.
Article 2 - Data controller and contact
2.1. The data controller is VIKING SMR, SARL, whose registered office is located at 416 Route des Gorges, 07150 Vallon-Pont-d’Arc, France.
2.2. For any question relating to your personal data, or to exercise the rights described in the article « Your rights » below, you may write to us at contact@viking-bateaux.com or call us on +33 (0)4 75 88 08 87.
Article 3 - Data collected and its origin
3.1. We only collect the data necessary for the purposes described in the article « Purposes, legal bases and retention periods ». Mandatory form fields are marked as such: if they are not filled in, your request cannot be processed. The other fields are optional.
3.2. The Website is not designed to collect so-called sensitive data within the meaning of Article 9 of the GDPR, such as data revealing origin, opinions, health or beliefs. We invite you not to send us any through the forms; if you do so nevertheless, it is used only to process your request and is not retained beyond that.
3.3. The data processed through the Website comes from you: what you send us, and what your browsing generates technically.
3.4. When you use the contact form, we collect your surname, your first name, your email address, where applicable your telephone number, the subject of your request, the desired descent date, the number of people, as well as the content of your message.
3.5. During your visit, our server technically records your IP address, the date and time of your connection, the pages viewed, as well as the type of browser and device used.
Article 4 - Purposes, legal bases and retention periods
4.1. Each processing operation pursues a specific purpose, rests on a precise legal basis and is subject to a limited retention period.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Responding to your contact request | Our legitimate interest in responding to enquiries addressed to us | 3 years from our last exchange |
| Drawing up a quotation and corresponding before a contract is concluded | Performance of pre-contractual measures taken at your request | 3 years from the last exchange, if the quotation is not followed up |
| Measuring the audience of the website | Your consent | Lifetime of the trackers stated in the cookie policy; data for 25 months at most |
| Sending you advertising tailored to your interests | Your consent | Lifetime of the trackers stated in the cookie policy; data for 25 months at most |
| Ensuring the security of the website and preventing abusive use | Our legitimate interest in protecting our information system | 12 months |
4.2. On expiry of the periods stated, your data is deleted or anonymised. It may however be retained beyond that, in restricted-access archive form, for the sole period necessary to comply with our legal obligations, in particular accounting and tax obligations, or to establish and defend a legal claim.
4.3. No decision producing legal effects concerning you is taken solely on the basis of automated processing, and your data is not subject to any profiling within the meaning of Article 22 of the GDPR.
Article 5 - Recipients of your data
5.1. Your data is intended for authorised persons within our organisation, within the limits of their duties.
5.2. It may be disclosed to the following providers, acting as processors within the meaning of Article 28 of the GDPR, for the sole purposes described above and on documented instructions from us:
| Recipient | Role | Data location |
|---|---|---|
| Indigo Theory, SARL, 120 Route de Bessas, 07150 Vagnas | Hosting, maintenance and technical support of the website | France and European Union |
| Infomaniak Network SA | Technical hosting infrastructure, as a sub-processor | Switzerland, data centres in Europe |
| Brevo (Sendinblue SAS) | Delivery of messages sent from the contact form | France and European Union |
| Cloudflare, Inc. | Protection of forms against automated submissions | United States |
| Google Ireland Limited and Google LLC | Audience measurement and advertising | Ireland and United States |
5.3. Each of these providers is bound by a contract containing the guarantees required by Article 28 of the GDPR, in particular as regards confidentiality, security and deletion of data at the end of the service.
5.4. Your data is neither sold, nor rented, nor exchanged. It may however be disclosed to administrative or judicial authorities where the law requires us to do so.
Article 6 - Transfers outside the European Union
6.1. Some of the providers mentioned in the article « Recipients of your data » are established outside the European Union, or transfer data there. These transfers are governed by one of the mechanisms provided for in Chapter V of the GDPR.
6.2. For providers established in the United States, the transfer rests on the European Commission's adequacy decision of 10 July 2023, where the provider is certified under the EU-US Data Privacy Framework. Failing certification, it rests on the standard contractual clauses adopted by the European Commission, together with appropriate supplementary measures.
6.3. You may obtain a copy of the safeguards put in place by writing to us at the contact details given in the article « Data controller and contact ».
Article 7 - Security
7.1. We implement appropriate technical and organisational measures to protect your data against unauthorised destruction, loss, alteration, disclosure or access: encryption of communications between your browser and the website, restriction of access to authorised persons only, keeping software components up to date and regular backups.
7.2. No system offers absolute security. In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be informed under the conditions provided for in Article 34 of the GDPR.
Article 8 - Your rights
8.1. You have the following rights over your personal data:
- right of access: to obtain confirmation that your data is being processed and to receive a copy of it (Article 15);
- right to rectification: to have inaccurate data corrected or incomplete data completed (Article 16);
- right to erasure: to obtain the deletion of your data in the cases provided for by the regulation (Article 17);
- right to restriction of processing: to obtain its suspension, in particular while a challenge is being examined (Article 18);
- right to portability: to receive, in a structured and machine-readable format, the data you have provided to us, or to have it transmitted to another controller (Article 20);
- right to object: to object to processing based on our legitimate interest, and at any time and without reason to direct marketing (Article 21);
- right to withdraw your consent at any time, where processing rests on it, without that withdrawal affecting the lawfulness of what was done beforehand (Article 7.3);
- right to give directions concerning the retention, erasure and disclosure of your data after your death (Article 85 of the French Act of 6 January 1978).
8.2. These rights are exercised at the contact details given in the article « Data controller and contact ». We reply within one month of receiving your request. This period may be extended by two months owing to the complexity or the number of requests; you are then informed within the month following your request.
8.3. We do not ask you for proof of identity as a matter of principle. Such proof may only be required from you in the event of reasonable doubt as to your identity, in accordance with Article 12.6 of the GDPR, and is then limited to what is strictly necessary to dispel that doubt.
8.4. Exercising these rights is free of charge.
8.5. If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - www.cnil.fr
Article 9 - Cookies and other trackers
9.1. The trackers placed during your browsing, their purposes, their lifetime and the arrangements for your consent are described by the cookie policy, available at /en/cookie-policy/.
9.2. You may at any time review, change or withdraw your choices from the « Manage my cookies » link in the footer of the website.
Article 10 - Links to third-party websites
This website may contain links to websites that we do not operate. This policy does not apply to those websites, whose own privacy policies we invite you to consult.
Article 11 - Updates
11.1. This policy may be modified to take account of changes in the website or in the applicable regulations. The applicable version is the one published on the date you consult it.
11.2. Last updated : 27 August 2026.