Zum Hauptinhalt springen

Julia & Georges
Fonds de Dotation
« Le Miffre »
668 ch. des Marquets
84220 Roussillon
France

PHONE: + 49 160 808 34 93 (GER & EN)
MAIL: info@b34qqmyk.myrdbx.io
SIREN: 924 389 752 00024

Julia & Georges
Fonds de Dotation
« Le Miffre »
668 ch. des Marquets
84220 Roussillon
France

PHONE: + 49 160 808 34 93 (GER & EN)
MAIL: info@b34qqmyk.myrdbx.io
SIREN: 924 389 752 00024

Privacy Policy

We take the protection of your personal data seriously. This policy explains what we collect, why, on what legal basis, who sees it and how long we keep it, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and French data protection law (Loi Informatique et Libertés).

1. Who we are

Fonds de Dotation Julia & Georges
« Le Miffre »
668 chemin des Marquets
84220 Roussillon
France
E-mail: info@julia-georges.fr
SIRET: 924 389 752 00024

The foundation is the data controller. We have not appointed a data protection officer; we are not required to. Write to the address above for anything in this policy.

2. What this policy covers

Three different things happen on this site, and they are not the same in data protection terms:

  • Visiting the pages. No account, no form, no tracking.
  • Writing to us by e-mail.
  • Applying for a residency, and everything that follows from an offer — the application form, the participant details, the agreement, and the report after the stay.

Sections 3 and 4 cover the first two. Section 5 onwards covers the application, which is where almost all of the personal data lives.

3. Visiting the website

When you open a page, our host records the usual server log data: IP address, date and time, browser type and version, operating system, referring page and the pages you opened. This is needed to deliver the site and to detect attacks. The legal basis is our legitimate interest in a working and secure website, Article 6(1)(f) GDPR. Log files are kept for a short period and then deleted.

We use no cookies for analytics, advertising or tracking, no analytics tool, no social media plug-ins and no third-party embeds. Only technically necessary data is processed. Under current CNIL guidance no cookie banner is required for this.

Fonts. The public pages of this site load Google Fonts, a service of Google Ireland Limited, which transmits your IP address to Google and may involve servers in the United States. The legal basis is our legitimate interest in a consistent presentation, Article 6(1)(f) GDPR. See https://policies.google.com/privacy. The application area loads no external fonts, no external scripts and no third-party content of any kind — nothing you type into the form is exposed to another provider.

4. Writing to us by e-mail

If you write to us we process what you send: your name, your address and the content of your message. The legal basis is our legitimate interest in answering, Article 6(1)(f) GDPR, or the steps prior to a contract, Article 6(1)(b) GDPR. We delete correspondence once the matter is settled, unless we are required to keep it.

5. Applying for a residency

Applications are made through the form on this site. They are no longer accepted by e-mail, and there is no paper form.

What we collect, and when

While you fill in the form. A draft is created as soon as you enter a valid e-mail address in step 1, so that you can stop and come back. We store what you have entered so far, together with a long random link that we e-mail to you once.

When you send the application we hold:

  • for each participant, between two and eight people: first name, last name and form of artistic practice, and optionally a personal web page;
  • for the lead applicant additionally: e-mail address and, optionally, telephone number. All our letters go to this address and to no other;
  • an optional collective name;
  • a biography of up to 300 words and a project proposal of up to 500 words;
  • the portfolio — either one joint portfolio or one per artist, as a link, as uploaded files, or both;
  • a CV for the lead applicant, and optionally for the others;
  • the dates you ask for: the stretch of time you could come, the length of stay, and an optional note about your dates;
  • your acceptance of this policy, with the time and the version of the text you accepted;
  • a reference number, and the language you used.

If we offer you a place, we ask for what the agreement needs, for each person travelling: date of birth, nationality, postal address, telephone number and e-mail address. Optionally a photograph.

The agreement itself, in both versions: the copy we signed and sent, and the copy you signed and uploaded.

After the stay, if you send it: your report, your answers to our three questions, and any photographs, together with your decision on whether we may publish them.

What we deliberately do not ask for

No passport or identity card numbers, and no upload of any identity document. The fields do not exist, not even as optional ones. The French fiche de police applies to paid tourist accommodation, not to a foundation giving rooms free of charge; we issue no visa invitations and take no deposit. Without a purpose, collecting the data is the problem, not storing it.

We also ask you not to send us special categories of data — health, religion, political opinion, trade union membership and the like. We do not need them and we do not want them in the file.

Why we process it, and on what legal basis

  • Receiving, reading and assessing your application, and deciding on it: Article 6(1)(b) GDPR, steps taken at your request before a contract, and Article 6(1)(f) GDPR, our legitimate interest in running a fair selection.
  • Keeping your draft so you can come back to it: Article 6(1)(b) GDPR.
  • Writing to you about your application, the agreement and your stay: Article 6(1)(b) GDPR.
  • The residency agreement and the details it needs: Article 6(1)(b) GDPR.
  • Publishing photographs or material from your stay: Article 6(1)(a) GDPR, your consent, given separately and withdrawable at any time.
  • Security of the site and the files: Article 6(1)(f) GDPR.
  • Keeping documents we are legally obliged to keep: Article 6(1)(c) GDPR.

Providing the data is voluntary, but an application cannot be assessed without it, and an agreement cannot be drawn up without the participant details.

If you apply as a group

Applications are always made by a group of two to eight people, and one of you — the lead applicant — enters the others‘ data and signs the agreement on behalf of all of you. Please make sure everyone in your group knows that their data is being given to us and has seen this policy. Everyone named in an application has the same rights as set out in section 9, whether or not they filled the form in themselves.

Who sees your application

  • The board of the foundation — four members, who read, rate and decide. They are volunteers and bound to confidentiality. No one else has access to the board area.
  • Our hosting provider, Raidboxes GmbH, Germany, which operates the servers.
  • Our e-mail provider, Host Europe GmbH, Germany, which delivers our letters to you.

Both are located in Germany and act on our instructions under a data processing agreement in accordance with Article 28 GDPR. We do not sell your data, we do not pass it to anyone for their own purposes, and we do not use it to advertise anything.

Nothing is decided automatically

There is no automated decision-making and no profiling within the meaning of Article 22 GDPR. Applications are read and rated by people, and the decision is taken by the board in a meeting.

How long we keep it

  • Unfinished drafts and their files: until the deadline, then 30 days, then deleted.
  • Applications that are not offered a place: up to six months after the decision, then deleted.
  • Applications that are offered a place: for the residency and its follow-up.
  • Participant details, meaning date of birth, postal address and telephone number: deleted once the season is closed and your report has arrived. Names stay with the application; addresses and telephone numbers do not.
  • The signed agreement: for as long as the law requires us to keep contracts.
  • Your report and photographs, where you gave us the rights: until you withdraw consent, or until we no longer use them.
  • The record of your acceptance of this policy: as long as the data it relates to.

Deletion removes the uploaded files as well as the database entries. Deadlines run automatically; nobody has to remember them.

6. Files you upload

Portfolios, CVs and the signed agreement are stored outside the publicly reachable directory and are delivered only after we check that the person asking is allowed to see them. There is no public link to your files. Every upload is checked for file type and size on the server, not only in your browser, and only PDF, JPG and PNG files are accepted.

7. Your draft link

The link we e-mail you opens your application without a password. Anyone who has the link can see and change what is in it, so treat it like a key and do not post it anywhere public. Tell us if you lose control of it and we will invalidate it.

8. Where your data is processed

Your data is processed and stored in the European Union. If any service outside the EU ever becomes necessary, we will name it here and put the safeguards required by Chapter V of the GDPR in place first. The single exception today is the loading of Google Fonts on the public pages, described in section 3; the application area is free of it.

9. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21) and data portability (Art. 20), and the right to withdraw a consent at any time with effect for the future (Art. 7(3)). Withdrawing consent does not affect what we did lawfully before.

Write to info@julia-georges.fr. We answer within one month. If you ask us to delete an application that is still being assessed, we will delete it and it will no longer be considered.

You also have the right to lodge a complaint with the supervisory authority:

Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
https://www.cnil.fr

10. Data security

We use appropriate technical and organisational measures to protect your data against unauthorised access, loss and misuse: encrypted transport, access to the board area only for named members, files outside the public directory, and deletion deadlines that run on their own.

11. Changes to this policy

We update this policy when the law or the site changes. The current version is always on this page, with its version number and date at the top. When you accept it while applying, we record which version you accepted, so that you can always see what you agreed to.