Privacy Policy
Effective Date: January 1, 2026 • Last Revised: March 2026
1. Overview & Data Controller
This Privacy Policy outlines how Choicegrd Nocturne Media Ltd ("Choicegrd", "we", "us", or "our"), registered in France under Company Registration Number FR88492019481 at 148 Rue du Faubourg Saint-Denis, 75010 Paris, collects, processes, and protects personal data obtained through choicegrd.forum.
As an independent registry and editorial directory of European nocturnal street markets, we prioritize user privacy, absolute minimalism in telemetry collection, and stringent compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR) and the California Consumer Privacy Act (CCPA).
2. Categories of Information Collected
We process information under two primary categories:
- Directly Provided Information: When you submit market suggestions, vendor reviews, editorial corrections, or contact messages via our forms, we collect your name, email address, company affiliation (if applicable), and the raw message payload.
- Automated Device & Usage Telemetry: Anonymized server log entries including IP addresses (truncated/hashed), browser type, operating system, referring URL, time spent on venue profile pages, and interface language settings to calculate continental time zones for the "Open Tonight" clock.
3. Legal Grounds for Processing (GDPR Article 6)
We process your personal data strictly under valid legal bases:
- Consent (Art. 6(1)(a)): You provide unambiguous consent when saving cookie preferences or subscribing to our weekly dispatch digest.
- Legitimate Interests (Art. 6(1)(f)): Processing essential server logs to guarantee network security, mitigate Distributed Denial of Service (DDoS) attempts, and maintain accurate market directory caches.
- Contractual Performance (Art. 6(1)(b)): Fulfilling editorial listing agreements submitted by night market organizers and local vendor syndicates.
4. Data Retention Schedule
We do not retain personal data longer than necessary for the operational purposes stated. Inquiry submissions submitted via our contact terminal are retained for a maximum of 180 calendar days before automated purge. Anonymized web server access logs are deleted on a rolling 30-day schedule.
5. User Rights Under European Law (GDPR)
Under Chapter III of the GDPR, visitors residing in the European Economic Area possess the following enforceable rights:
- Right of Access (Art. 15): Request a copy of all personal records associated with your email identifier.
- Right to Rectification (Art. 16): Correct inaccurate, outdated, or incomplete vendor information.
- Right to Erasure (Art. 17): Demand permanent deletion ("Right to be Forgotten") of all personal metadata.
- Right to Restrict Processing (Art. 18) & Data Portability (Art. 20): Receive your structured data in machine-readable JSON format.
To exercise any statutory right, contact our designated Data Protection Officer at [email protected]. We respond within 30 business days without fee.
6. International Data Transfers & Third-Party Processors
All primary database nodes and web servers are physically situated within European Union jurisdictions (Frankfurt, Germany and Paris, France). In rare scenarios where third-party infrastructure providers operate edge points outside the EEA, standard contractual clauses (SCCs) approved by the European Commission are strictly executed.