PRIVACY POLICY – PERSONAL DATA PROTECTION

 

(CERMA Project – Erasmus+ KA220-HED)

1. Introduction

This website is part of the European project:

CERMA – Project Nº 2024-1-SK01-KA220-HED-000243758
Funded by the European Union Erasmus+ Programme – Cooperation partnerships in higher education (KA220-HED).

The protection of personal data is a priority for the project consortium. All processing of personal data is carried out in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR)

  • Applicable national data protection laws

  • Erasmus+ Programme communication and dissemination obligations

This privacy policy applies only to data collected through this website:
https://cermaproject.eu/


2. Data Controllers (Joint Controllers – Art. 26 GDPR)

The personal data collected through this website are processed jointly by the project consortium partners for the purpose of implementing project activities.

Project Coordinator (Main Contact Point):
Technical University of Košice (TUKE)
Slovakia

The consortium partners listed on the project website act as Joint Controllers for the processing strictly related to project implementation, dissemination and communication activities.

For matters related to the website technical management:

Website technical manager (Data Processor):
SiTeS / S-Innovations
Email: leonardo@sinnovations.org

The technical manager only processes data under instructions of the consortium.


3. Purpose of Processing

Your personal data may be processed for the following project-related purposes:

  • dissemination of project results

  • academic and institutional communication

  • responding to contact requests

  • newsletter subscription

  • stakeholder engagement

  • reporting and accountability obligations to the European Commission / EACEA

  • website security and maintenance

  • statistical analysis of website usage

Your data will never be used for commercial advertising purposes.


4. Legal Basis for Processing (Art. 6 GDPR)

Different legal bases apply depending on the activity:

ActivityLegal basis
Contact form communicationArt. 6(1)(e) Public interest (EU funded project dissemination)
Newsletter subscriptionArt. 6(1)(a) Consent
Website analyticsArt. 6(1)(a) Consent
Security & technical logsArt. 6(1)(f) Legitimate interest (security)
Project reporting to EU authoritiesArt. 6(1)(c) Legal obligation

5. Categories of Data Collected

Automatically collected data

  • IP address

  • browser and device information

  • operating system

  • visited pages and navigation behaviour

  • date and time of access

Data provided voluntarily

When you contact us or subscribe to the newsletter:

  • name

  • email address

  • organisation (optional)

  • message content


6. Recipients of Data

Your personal data may be accessed only by:

  • authorised members of the project consortium

  • the European Commission / EACEA (only when required for project reporting)

  • website service providers acting as processors

We do not sell, rent or commercially share personal data.


7. Third-Party Services Used

Google Analytics

Used for statistical analysis of website usage.
Data is collected only after consent through the cookie banner.

Google may process data according to its privacy policy.

Mailchimp

Used exclusively to send project newsletters.
Subscription requires explicit consent and includes an unsubscribe link in every email.


8. Data Transfers Outside the EU

Some service providers (e.g. Google or Mailchimp) may process data outside the European Economic Area.
Such transfers are protected through Standard Contractual Clauses approved by the European Commission.


9. Data Retention Period

Personal data will be kept only as long as necessary:

Data typeRetention period
Contact requestsmax. 12 months
Newsletter subscriptionuntil withdrawal of consent
Analytics datamax. 14 months
Project documentationup to 5 years after final EU project payment (financial regulation requirement)

10. Your Rights

Under GDPR you have the right to:

  • access your personal data

  • correct inaccurate data

  • request deletion

  • restrict processing

  • object to processing

  • data portability

  • withdraw consent at any time

To exercise your rights contact:
leonardo@sinnovations.org

You also have the right to lodge a complaint with your national Data Protection Authority.


11. Data Security

Appropriate technical and organisational security measures are applied to prevent:

  • unauthorised access

  • data loss

  • misuse or alteration

Only authorised project personnel may access personal data.


12. Policy Updates

This policy may be updated to reflect legal or project changes.
The latest version will always be available on this website.