1.Purpose and legal basis for the Processing
Any and all personal data that is in the possession of the Controller, or that may be requested by the Controller, is necessary to subscribe you to the newsletter and will only be used for the purposes of the newsletter’s subscription and sending.
The legal basis for the processing of your personal data for the purposes indicated above is your consent to the processing of your personal data. By ticking the boxes at the end of this policy you give your consent to the data processing. You can withdraw the consent contacting the data controller.
2.Methods of processing
Your personal data will be recorded and stored in electronic format. This knowledge and storage of personal data of the Data Subject is necessary in order to process it according to the above-stated purposes. All changes to such data should be immediately communicated to Eurac Research in order to ensure the data’s correct processing.
A valid email address is required in order to receive the newsletter, The email address you provide will be reviewed for the purposes of determining whether you are in fact the owner of the email address or whether the actual owner of said address is authorized to receive the newsletter. When subscribing to the newsletter, Eurac Research will store your IP address, as well as the date and time you subscribed. This serves to protect us in the event that a third party improperly and without your knowledge makes use of your email address to subscribe to our newsletter. Our subscription process uses the secure “double opt in” guidelines, in which the subscriber first receives an email confirmation that prompts him/her to safely subscribe to the newsletter.
The newsletter service uses web beacons, cookies, Google Analytics and similar tracking technologies to recognize and follow when an account has been opened, and which links in the newsletter have been clicked by its recipient.
3.Information on the retention period of personal data
Your personal data will be stored for the time period necessary for the purposes for which it was collected.
4. Obligatory or voluntary nature of providing the requested data and possible consequences of failure to provide such data
The provision of your personal data is voluntary, but any refusal to provide such data will not allow the correct use of the services.
5.Recipients of the data processed and Transfer of data
The recipients of the data are the data processor, which were formally bound by means of a data processing agreement, the persons in charge of data processing activities, authorized and instructed by the data controller to data processing activities.
Some of your Personal Data are transferred to Recipients who may be established outside the European Economic Area. The Controller ensures that the processing of Personal Data by these Recipients is carried out pursuant to the Applicable Law.
We use MailChimp to send our newsletter to our subscribers. As part of your subscription, your data will be communicated to and processed by MailChimp. MailChimp is a service provided by The Rocket Science Group LLC, USA. The data that is stored when you register for the newsletter (i.e., email address, full name, IP address, and time and date of registration) will be sent to a server operated by The Rocket Science Group in the United States and stored there in accordance with the requirements of the EU-US Privacy Shield Framework. MailChimp is self-certified in compliance with Privacy Shield.
The Data Processing Agreement between MailChimp and Eurac Research is dated 21.12.2017.
Further information about the data protection offered by MailChimp: http://mailchimp.com/legal/privacy/
6.Existence of automated decision-making process
There are no automated decision-making processes.
7.Identity of the Controller and DPO
Data Controller: Eurac Research, Viale Druso 1, 39100 Bolzano
DPO: nomination within 25.05.2018
8.The Data Subject’s Rights
At any time, the Data Subject has the right to request from the controller access to and rectification or erasure of personal data or restriction of processing as well as the right to data portability and the right to lodge a complaint with a supervisory authority. Where the processing is based on the consent, the Data Subject has the right to withdraw consent at any time. The Data Subject may also exercise all other rights pursuant to current data protection regulations (artt. 15 et seq. GDPR) by writing to the email privacy@eurac.edu.
You may cancel your newsletter subscription at any time and revoke your consent to the storage of your data. Revocation of consent to receive the newsletter constitutes a revocation of consent for tracking your data and for transferring your data to MailChimp; separated revocations are not possible.