Personal Data Processing Policy
Personal data provided in connection with the use of this website and its services are processed in accordance with the General Data Protection Regulation (EU) 2016/679 and Legislative Decree no. 196/2003, as amended, “Personal Data Protection Code.” This policy is provided, pursuant to the General Data Protection Regulation (EU) 2016/679, to those who interact with the web services of the AWaTEC27 website, accessible electronically from the address: awatec27.dista.uninsubria.it, corresponding to the homepage of the website. This policy applies only to awatec27.dista.uninsubria.it and not to other websites that may be accessed by the user via hyperlinks.
1) Data Controller, Data Processor, Data Protection Officer
The Data Controller is the University of Insubria, represented by its Rector, with registered office in Varese (VA) at Via Ravasi, 2. The Data Processor for the provision of services is the Department of Theoretical and Applied Sciences, with registered office at Via O. Rossi 9, 21100 Varese (VA). Data subjects may contact the Data Protection Officer to exercise their rights under the GDPR (Articles 12 to 21) using the following email address: privacy@uninsubria.it.
2) Subject of the processing
A. Browsing data: this information is not collected to be associated with identified data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes the IP addresses or domain names of computers used by users connecting to the site, the URI (Uniform Resource Identifier) addresses of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the server response (successful, error, etc.), and other parameters relating to the user’s operating system and IT environment.
B. Cookies: The site uses a technology called “cookies.” Tracking and management of user paths are performed using methods that make the data non-identifiable. Further information can be found in the Cookie Policy section. Session cookies (non-persistent) are used strictly to the extent necessary for safe and efficient site navigation. Cookies are not used to profile users, nor are other tracking methods employed.
C. Data provided by the user: For the use of online services that require authentication, registration, or email sending, personal data freely provided by users are used in various ways:
3) Purposes of data processing:
- To enable navigation on the site;
- To provide the information and services requested;
- To comply with legal obligations or orders from public authorities;
- To ascertain liability in the event of hypothetical computer crimes against the site or its users.
4) Legal Basis for Processing For browsing data
the legal basis for processing is mutual legitimate interest. Consent to provide data is optional and express when accessing the web portal. The legal basis for processing browsing data other than that acquired through cookies lies in the institutional tasks assigned to the Data Controller pursuant to Article 6, paragraph 1, letter e) of the Regulation.
5) Processing Methods
Personal data will be processed using manual, computerized, and electronic means, all of which are suitable to guarantee the security and confidentiality of the data. Specific security measures are observed to prevent data loss, illicit or incorrect use, and unauthorized access, in full compliance with Article 32 of the GDPR. The processing, carried out by the Data Processor on behalf of the Data Controller, the University of Insubria, is related to the purposes described in point 4 and in compliance with the GDPR provisions in Articles 5 to 11 and in compliance with these principles as set forth in the GDPR:
- Lawfulness in compliance with the consent you have given;
- Minimization, meaning the processing uses the minimum amount of data necessary for the purpose for which it was collected;
- Limitation, meaning the processing is limited to the purposes described in point 4;
- Security, meaning the application of the security measures required by international standards and suggested by industry best practices is guaranteed.
- Accuracy: Tools are provided to keep data accurate;
- Integrity: Best data management practices are adopted to minimize data management errors. Log files (relating to activities performed through the service) may be extracted, including through cross-referencing and processing of such data to identify those responsible for abuse and/or illegal activities by data subjects or third parties.
6) Data retention period
Depending on the various purposes and purposes for which they were collected, the data will be retained for the period required by the relevant legislation or for the period strictly necessary to achieve the purposes. In particular, the data collected pursuant to Article 2, for the purposes of managing online services and statistical analysis, are retained for a maximum of 6 months;
7) Subjects or categories of subjects to whom the data may be communicated or who may become aware of it as
Data Processors or Authorized Persons Without express consent (pursuant to Article 6(c) of the GDPR), the Data Controller may communicate the data for the purposes referred to in point 4 to supervisory bodies, judicial authorities, and all other subjects to whom communication is required by law for the fulfillment of the aforementioned purposes. Personal data will not be disseminated. The data may be communicated to internal personnel, who are authorized by the Department of Theoretical and Applied Sciences to process the data necessary for the performance of their duties and for the purpose of fulfilling your requests.
8) Transfer of data abroad
No data transfers abroad are envisaged.
9) Rights of the Data Subject
These are the rights that may be exercised:
- Right of Access: the right to obtain confirmation of whether or not personal data concerning you is being processed, and a copy of the data;
- Right to Rectification: the right to obtain the correction of any inaccurate data;
- Right to Erasure (“to be forgotten”): the right, where the conditions are met, to obtain the erasure of personal data;
- Right to Restriction: the right to obtain the marking of retained personal data with the aim of limiting its processing in the future;
- Right to data portability: the right to obtain from the University of Insubria the transmission of your personal data in a structured, commonly used, and machine-readable format;
- Right to Complain: the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or the supervisory authority of the EU Member State in which the Data Subject habitually resides or works, or of the place where the alleged violation occurred, in relation to processing that they consider to be non-compliant.
To exercise these rights, the Data Subject may contact the Data Protection Officer by sending a request by email to privacy@uninsubria.it.
10) Third Parties
The site does not use third-party content.
11) Changes to this Policy
This Policy may be subject to change. We therefore recommend that you regularly check this Policy and refer to the most up-to-date version.
Cookie Policy
Cookies are text files that are saved on your device (computer, tablet, smartphone, etc.) to enable safe and efficient browsing of the site and to monitor its use. Cookies can be:
- Technical cookies (and subcategories): These are cookies used for browsing or to provide a service requested by the user. They are not used for other purposes.
- Profiling cookies (and subcategories): These are cookies used to track user browsing and create profiles based on their tastes, habits, choices, etc.
- Third-party cookies: These are technical or profiling cookies present on the site but belonging to parties other than the site owner.
Only technical cookies are used on this site. Cookies are not used to profile users, nor are other tracking methods employed.
