Windsurfjournal.com stores visitor data indefinitely by default, a detail buried in the platform’s privacy disclosures that carries real consequences for anyone who has ever filled out a contact form or simply browsed the site.
The platform collects personal information through two main channels. The first is largely invisible: cookies that run during normal navigation, capturing IP addresses, device specifications, browser type and version, operating system details, connection method, and the URLs visited along with timestamps. The second is deliberate. When a visitor submits a message through the contact form, the site collects their name, first name, email address, and the content of their message. One is passive; the other is a conscious act by the user.
That collected data shapes what visitors see. Windsurfjournal.com tailors content and services based on browsing history, stated preferences, and identified interests. Some features require specific information to work, and the site flags which fields are mandatory at the point of entry. Decline to provide required information and access to certain services, functionalities, or sections of the site may be withdrawn.
On retention, the policy is blunt: personal information stays on the platform indefinitely unless a user actively requests deletion. The site says it applies organizational, software, legal, technical, and physical safeguards to protect data confidentiality and prevent unauthorized access, damage, or loss.
Who can see that data? Access is limited to Windsurfjournal.com staff whose job functions require it, all of whom operate under confidentiality obligations. The site may also share data with contractual subcontractors who handle tasks necessary for site operation and user relationship management, without requiring explicit user consent for each transfer. Those subcontractors receive only limited access and must comply with applicable data protection law. Beyond these defined circumstances, Windsurfjournal.com commits not to sell, rent, transfer, or grant third-party access to user data without prior consent, except when legally compelled or when legitimate grounds apply, such as fraud prevention or the defense of legal rights.
French and European data protection law gives users a meaningful toolkit here. Visitors can access their data, correct inaccurate information, request portability or deletion, restrict or object to processing, and withdraw consent for promotional communications sent by email, SMS, telephone, or post. These rights apply whether the information was provided directly to the site or gathered through third-party partners.
Exercising those rights is possible through several routes: adjusting account settings, using the site’s contact section, sending postal mail, or emailing the address listed in the legal notices. Identity verification is required for data access requests, and any identification documents submitted for that purpose are destroyed after processing.
Users who want to go further, or who have a complaint, can contact the French National Commission for Data Protection at www.cnil.fr.
What remains an open question is how many visitors are aware that their data sits on the platform until they ask for it to be removed. The deletion request process exists, but the default is retention, and the burden of action falls entirely on the user.