Privacy Policy for Users

Privacy and respect for users' personal data are essential to us.

1. Glossary

Netatoo: refers to the company Netatoo S.A.S. SIRET 48782045800031; also referred to as "we," "our," "us."
Application: refers to the online booking platform BalleJaune and OpenResa, accessible from ballejaune.com and openresa.com.
Club(s): refers to an entity represented by one or more administrators.
User(s): refers to individuals with an account in a club's database.
Administrator(s): refers to the club managers, having access to the Administration section of the application.

2. Introduction

Netatoo SAS (SIRET 48782045800031) provides an online booking platform (ballejaune.com and openresa.com), also referred to as "we," "our," and "us" in this document.

We place great importance on the trust you place in us by choosing our solution for your online bookings. Therefore, we diligently protect the privacy and confidentiality of your personal data.

This privacy policy applies to all our services, whether accessible online or through any other platform or device (hereinafter collectively referred to as "the application").

This document concerns the processing of data related to users of clubs registered on our application. A club user is also referred to as "you" and "your" throughout this document.

By accepting this privacy policy, you consent to the processing of your personal data by Netatoo for the purposes specified below.

3. Processing of Personal Data

Netatoo processes your personal data for the following purposes:

  • Creation of your user account in the club where you are registered.
  • Verification of your identity using authentication mechanisms.
  • Sharing your personal data with the administrators and users of the clubs you are associated with (i.e., clubs that include you in their user list).
  • Management of your bookings in the club where you make reservations.
  • Informing the club administrators about your booking interactions (creation of a booking, cancellation of a booking, modification of a booking).
  • Recording audit information about your booking interactions (for audit purposes by the club).
  • To process your inquiries and provide technical support via email or phone.
  • To contact you regarding relevant issues associated with your personal user account or club account.
  • To monitor unauthorized use or abuse of our services, or to detect, investigate, or prevent activities that may violate our policies or be fraudulent/illegal.
  • Preventing fraudulent, illegal, or malicious activities targeting the application and Netatoo's servers.
  • To process payments you may make in clubs (purchase of booking tickets, payment of a membership fee, etc.).
  • Analyzing trends, administering or optimizing our offerings, monitoring usage or traffic patterns.

4. Personal Data Collected

Netatoo collects the following personal data:

  • First and last name (mandatory)
  • Title (mandatory)
  • Login ID (mandatory)
  • Password, hashed using industry-standard hashing algorithms (BCRYPT).
  • Email address (optional)
  • Full postal address, and in case of online payment, a delivery address and/or billing address (optional)
  • Phone number(s) (optional, depending on the context)
  • Date of birth (optional)
  • Federal license number (optional)
  • Ranking / playing level (optional)
  • Date of medical certificate (optional)
  • Game partner search announcement (optional)
  • Proof / certificate of residence (optional)
  • Medical certificate (optional)
  • File to be uploaded at the club's request (optional)
  • Technical information about the device and Internet browser used (collected solely for the purpose of providing effective customer support, preventing malicious attacks on our services, and providing anonymous statistics to club managers and Netatoo).
  • IP address (this information is retained for 6 months and then destroyed).

If required by the club, Netatoo also provides interfaces that control the collection of credit card information (including billing address information). The collection of this payment information is, however, hosted directly by the relevant payment gateway, and Netatoo never sees or stores this data. Thus, Netatoo never processes raw credit card or payment information - it is managed exclusively by the club's payment gateway account with which you have entered into a booking contract.

We are committed to ensuring that no data is exchanged or sold in any form to third parties.

5. Club Control over Data

Club administrators are able to add new user accounts to their database, and these users can then log into the application from the club's dedicated page to make bookings.

A club administrator who manually adds or modifies another individual's details in the application, for example by manually adding this person as a club member, must have obtained unambiguous consent to this privacy policy from the individual concerned to do so. This consent must be able to be presented upon request to Netatoo and any competent supervisory authority.

6. Rectification, Modification, and Deletion of Your Data

6.1. Data Rectification

You can view and modify the personal data you store with us in the "My Account > Account Details" section of your account.

For security reasons, the last name and first name entered on your account cannot be rectified directly by the user. If you wish to correct this information, you must contact the club, and if the club does not respond to your rectification request within 7 days, we invite you to contact us at support@openresa.com. Our team will then contact the club and we will act according to the club's response.

6.2. Partial Deletion

Certain personal information can be erased without completely deleting your account, such as your postal address, email address, or phone numbers. However, note that depending on the club's account configuration, this information may be required to confirm a booking.

6.3. Complete Account Deletion

Netatoo stores your data as an intermediary between you and the club. Each club is responsible for its own database, and therefore, if for any reason you wish to completely delete your account, you can do so by contacting the club where you hold this account. Club administrators, after ensuring that it is legally and compliantly permissible, can then permanently delete your account and all associated data. To contact the club, go to its login page and click on the "Contact" menu.

If the club does not respond to your account deletion request within 7 days, we invite you to contact us at support@ballejaune.com. Our team will contact the club and we will act according to the response provided.

You agree that all or part of your account information may not be deleted if Netatoo or the club demonstrates that it is legally necessary to retain it (e.g., for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller).

You agree that your account information will continue to exist in our backup files for a maximum period of 90 days after your account is deleted.

Note that certain data, such as your bookings, will not be deleted from the club's database; this data will be "anonymized" so that it is no longer possible to link you to the bookings. This can be useful for the club to avoid altering its statistical data.

7. Data Processors

From time to time, we may engage third-party service providers as data processors for the purposes specified above. Processing by these third parties takes place according to our instructions. These parties are bound by data processing agreements and confidentiality agreements.

You can view the comprehensive list of third-party entities we engage to provide services on our behalf by visiting the "Our Subcontractors and Third-Party Providers" page.

8. Security

In accordance with data protection laws, strict security procedures are observed within Netatoo to prevent misuse of personal data and unauthorized access.

To protect and safeguard the personal data and club data provided to us, we have implemented and use appropriate professional systems and procedures. Additionally, we have implemented and use security procedures and technical and physical restrictions for access to and use of club personal information. Only authorized employees can access personal information in the course of their duties concerning our services.

For more details on the measures in place to secure and protect your data, visit the data security section.

9. Data Breaches

If we become aware of a data breach, we will notify the affected individuals and the competent supervisory authorities no later than 72 hours after becoming aware of it.

10. Cookies

Netatoo exchanges several cookies with your browser. A session cookie is recorded to authenticate you; another cookie helps us protect your account against malicious access. The content of these cookies are machine-generated tokens used for authentication and security purposes. Without these cookies, we would not be able to reliably provide our core services.

Note that other "secondary" cookies are also created by the application to offer you an optimal browsing experience. For example, we record a cookie to remember the clubs you have already logged into. This way, you can easily access different clubs during your subsequent visits to the application.

Finally, through our subcontractors, "third-party cookies" may be exchanged with your browser when you use our application. These cookies are not essential for using our services and can be easily disabled from your web browser preferences.

Refer to the "Data Processors" section of this document for more information about our subcontractors and third-party providers.

11. Credit Card Information

Raw credit card information does not come into contact with the servers on which our application is hosted. All credit card information is managed by online payment gateways such as PayPal or Paybox, via a TLS-secured connection. Netatoo and the clubs cannot access unmasked credit card data.

12. Competent Authorities

We may share and disclose details and information about you to a government or investigative authority if required by law (or any regulation having the force of law), a judicial process, a criminal investigation, a court order, or a subpoena. We may also disclose your personal data if it is strictly necessary for the prevention and detection of criminal acts.

13. Changes to this Statement

Our application is constantly evolving, and as such, we may change the way we collect, transmit, and process personal data and any other information we deem necessary. This statement may therefore be modified from time to time to reflect the latest changes.

Contact Us

Postal Address:
Netatoo SAS - BP 43606 - 54016 NANCY CEDEX FRANCE

Email:
support@openresa.com


Atualizado em quinta-feira, 12 de Junho de 2025