1. Who we are and what we do?
XENIOS consortium (hereinafter referred to as the “Company” or “we” or “our”), a consortium, with email address firstname.lastname@example.org, and website www.xenios-project.eu, is mainly engaged in developing the EU funded program XENIOS, which is a combined application platform for the protection and promotion of cultural and tourist sites.
For the purposes of providing its professional services, the Company may proceed to the collection and processing of natural persons’ personal data in accordance with Greek legislation in force, as well as with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter “GDPR”) and thus it may act as a “data controller”.
2. What personal information do we collect and how we collect it?
We may collect and further process different types of personal data in the course of operating our business and providing our services. These data may include:
- Basic personal data and contact information, such as your name, job title, postal address, business address, telephone number, mobile phone number, fax number and email address;
- Financial and tax-related data, such as payment related information necessary for processing payments as well as for fraud prevention, such as bank account details, credit/debit card numbers, security code numbers and other related billing information, TIN etc.;
- Records of your communication and visits to our premises.
- Recruitment related data such as your Curriculum Vitae, your education and employment history, details of professional memberships and other information relevant to potential recruitment to the Company;
- Website Usage data, such as details of your visits to our website or information collected through cookies.
- Any other personal data related to you that you may provide.
We may collect your personal data through a variety of means and in different ways.
- You may provide the personal information to us directly, for example through the completion and submission of a form on our website, by corresponding to us via email, letter or telephone or in person during a visit to our premises or your participation in the events that we organize;
- We may collect the information from third party sources, such as when we receive information about you from collaborators and external consultants with whom you may already have a business relationship, for the purposes of further cooperation with our Company;
- We may collect the information from publicly available sources.
3. How do we use your personal data and for what purposes?
In particular, we use the personal data:
- To provide products and services you may have requested;
- To manage our business operations and administer our clients’ business relationship with us, including processing payments, accounting, auditing, billing, supporting services;
- To analyze and improve our services to and communications with you;
- To protect the security of and manage access to our premises, IT systems, communication systems and our website and prevent and detect security threats, fraud or other criminal or malicious activities;
- For investigating purposes and to prevent unauthorized access to the services and other illegal activities;
- To identify persons authorized to trade on behalf of our clients, customers, suppliers and/or service providers;
- To comply with our legal and regulatory obligations, including reporting to and/or being audited by national and international regulatory bodies;
- To comply with court orders and/or defend our legal rights; and
- To communicate with you on the latest developments, announcements, and other information about us, via newsletters, briefs etc., upon your explicit consent;
- For the assessment of qualifications and the probability of recruitment in our Company,
- To facilitate your presence at the events we organize and offer you the appropriate service,
- For any other purpose related and/or ancillary to any of the above or any other purpose for which your personal data was provided to us.
Any potential marketing-related communication will only be carried out after you have opted in and we will provide you the opportunity to opt out anytime, if you do not wish to continue receiving marketing-related communication from us. We will not use your personal data for taking any automated decisions affecting you or creating profiles other than as described above.
4. What is the lawful basis for processing your personal data?
We process any personal data that we collect as above, based on the following lawful bases:
- The personal information we hold and process, is necessary for the performance of our services contractor other agreement, to which our clients are a party, or to supply the products and perform the services that our clients have otherwise requested.
- The personal information we collect and process may also be necessary for our legitimate business interests, in terms of offering the best possible solutions to our clients, in managing our everyday business needs, in providing our clients or prospective clients with information about the products and the services we offer, and about which they have expressed an interest or that we believe will be of benefit to them.
- In some cases, our ground for collecting and processing the information is based on your explicit consent to our collection and processing of your personal information, such as -for example- when we communicate with you in terms of providing relevant marketing information, when you submit your CV in order for it to be assessed, or for your participation in scientific conferences and similar events that we are organizing.
- We may also process your personal data in order to comply with a legal obligation to which the Company is subject and for the fulfillment of regulatory and statutory obligations or court or other orders (e.g. compliance with tax procedures, Anti-Money Laundering procedures, fraud detection, ensuring of traceability etc.).
5. Who we share your personal data with?
We do not sell or rent or exchange or transfer your personal data or personally identifiable information that has been collected by us, as part of a customer list or similar transaction, to any third party.
We may only share your personal data with the following indicative categories of recipients:
- Banking Institutions, Insurance Institutions, Lawyers or other legal specialists (including mediators), consultants or experts or other professional advisors as the case may be (e.g. financial, business or other advisors), auditors, chartered accountants, scientific officers engaged in the course of the services we provide to our clients or prospective clients;
- We may share your personal data with courts, government, regulatory or other public authorities;
6. For how long do we retain your personal data?
In general, we will retain your personal data for as long as is necessary for the fulfillment of the purposes for which this data was collected and any other permitted linked purpose.
When the processing of personal data is related to the establishment, exercise or defense of legal claims, we will retain your personal data until the time limit for claims has expired or the claims have been settled, or in order to comply with legal requirements regarding the retention of such data.
Our retention periods are also based on our business needs and good practice.
7. Security of Personal Data
We store your personal data securely on our servers, which are managed internally as well as with third party storage providers.
We maintain the appropriate technical and organizational security measures to protect the personal data that we hold on our networks and systems, from unauthorized access, disclosure, alteration, misuse, loss and destruction. The security measures indicatively include physical, technical, administrative, electronic and procedural safeguards, firewalls, physical access controls to our data centers and information access authorization controls. Our security procedures also mean that we may occasionally request proof of identity, in order to verify your identity before communicating with you or disclosing any personal information to you.
While we try our best to safeguard your Personal Data, once we receive it, especially as regards the data received through our website, no transmission of data over the Internet or any other public network can be guaranteed to be 100% secure.
8. Use of third party applications and services that interact with our services
We use Google Maps from Google Inc. (1600 Amphitheater Parkway Mountain View, CA 94043, USA) on our website. By using the features of this map, data will be transmitted to Google.
To see what data Google collects and what this data is used for, visit https://www.google.com/intl/en/policies/privacy/.
We may integrate elements of social media services on our website to display pictures, videos and texts. By visiting pages representing these elements, data is transferred from your browser to the respective social media service and stored there. We do not have access to this data.
The following links will take you to the pages of the respective social media services where it is explained how they handle your data:
- Facebook Data Policy: https://www.facebook.com/about/privacy
On this website we may use features of Facebook, a Social Media Network of Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2 Ireland.
You can read about what features (social plug-ins) Facebook provides on https://developers.facebook.com/docs/plugins/.
By visiting our website information may be transmitted to Facebook. If you have a Facebook account, Facebook can associate that information with your personal account. If you do not want that, please log out of Facebook.
On this website we may use the video service YouTube of the company YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.
By accessing pages of our website that have integrated YouTube videos, data is transmitted to YouTube, where it is stored and evaluated.
If you have a YouTube account and you’re signed in, this information will be associated with your personal account and the data stored in it.
To see what data Google collects and what this data is used for, visit https://www.google.com/intl/en/policies/privacy/
On this website we may use features of the Social Media Network Instagram, of Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA.
We can display images and videos of Instagram content with the embedding function (Embed-Function).
By calling up pages that use such functions, data (IP address, browser data, date, time, cookies) are transmitted to Instagram, where they are stored and evaluated.
If you have an Instagram account and are signed in, this information will be associated with your personal account and the data stored in it.
On our website we may use functions of the Social Media Network LinkedIn of the company LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA.
By calling up pages that use such functions, data (IP address, browser data, date and time, cookies) are transmitted to LinkedIn, where they are stored and evaluated.
If you have a LinkedIn account and are signed in, this information will be associated with your personal account and the data stored in it.
On our website we may use Facebook Pixel of Facebook, a social media network of the company Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbor, Dublin 2 Ireland.
The code implemented on this page can evaluate the behavior of visitors who have come to this website from a Facebook ad. This can be used to improve Facebook ads and this data is collected and stored by Facebook. The collected data is not visible to us but can only be used within the scope of advertisements. By using the Facebook pixel code, cookies are also set.
By using Facebook pixel, visiting our website is communicated to Facebook so that visitors get to see suitable ads on Facebook. If you have a Facebook account and are logged in, the visit to this website will be associated with your Facebook user account.
To find out how Facebook pixel is used for advertising campaigns, visit https://www.facebook.com/business/learn/facebook-ads-pixel.
You can change your ad settings on Facebook at https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen, if you’re signed in to Facebook.
At http://www.youronlinechoices.com/ you can manage your preferences regarding usage-based online advertising. You can disable or enable many providers at once or change settings for individual providers.
More information about Facebook’s data policy can be found at https://www.facebook.com/policy.php.
9. Other technologies we incorporate on this website
1. TLS encryption with https
We use https in order to transmit data securely over the Internet (data protection through technology design Article 25 paragraph 1 GDPR). By using TLS (Transport Layer Security), an encryption protocol for secure data transmission over the Internet, we can ensure the protection of confidential data.
You can acknowledge the use of this safeguarding measure for the data transfer at the small lock symbol in the upper left corner of the browser and the use of the scheme https (instead of http) as part of our Internet address
We use Google Fonts from Google Inc. (1600 Amphitheater Parkway Mountain View, CA 94043, USA) on our website.
You do not need to sign in or have a password in order to use Google Fonts. Furthermore, no cookies are stored in your browser.
The files (CSS, fonts) are requested through the Google domains fonts.googleapis.com and fonts.gstatic.com. According to Google, the requests for CSS and fonts are completely separate from all other Google services. If you have a Google Account, you do not need to worry about your Google Account information being sent to Google while using Google Fonts. Google records the use of CSS (Cascading Style Sheets) and the fonts used and stores this data securely. We will check in detail what the data storage exactly looks like.
1. What are Google Fonts?
Google Fonts (formerly Google Web Fonts) is an interactive directory with over 800 fonts that Google LLC provides for free use.
Many of these fonts are published under the SIL Open Font License, while others have been released under the Apache License. Both are free software licenses. Thus, we can use them freely without paying royalties
2. Why do we use Google Fonts on our website?
With Google Fonts we can use fonts on our own website and do not have to upload them on our own server. Google Fonts is an important building block in order to keep the quality of our website high. All Google fonts are automatically optimized for the Web, and this saves data volume and is a great advantage especially for mobile device use. When you visit our page, the low file size ensures fast loading time. Furthermore, Google fonts are so-called secure web fonts. Different image synthesis systems (rendering) in different browsers, operating systems and mobile devices can lead to errors. Such errors can partially distort texts or entire websites visually. Thanks to the fast Content Delivery Network (CDN), there are no cross-platform issues with Google Fonts. Google Fonts supports all major browsers (Google Chrome, Mozilla Firefox, Apple Safari, Opera) and works reliably on most modern mobile operating systems, including Android 2.2+ and iOS 4.2+ (iPhone, iPad, iPod).
So we use the Google Fonts in order to make our entire online service as beautiful and consistent as possible. According to Article 6 Paragraph 1 f GDPR, this already constitutes a “legitimate interest” in the processing of personal data. In this case, “legitimate interest” means legal as well as economic or ideal interests that are recognized by the legal system
3. What data does Google store?
When you visit our website, the fonts will be reloaded via a Google server. This external call sends data to the Google servers. This way, Google also recognizes that you or your IP address is visiting our website. The Google Fonts API is designed to reduce the collection, storage and use of end-user data to what is needed for efficient font delivery. Incidentally, API stands for “Application Programming Interface” and serves, among other things, as a data transmitter in the software area.
Google Fonts securely stores CSS and font requests on Google and is thus protected. Through the collected usage figures, Google can determine the popularity of the fonts. Google publishes the results on internal analysis pages, such as Google Analytics. In addition, Google also uses data from its own web crawler to determine which websites use Google Fonts. This data is published in Google Fonts’ BigQuery database. BigQuery is a Google web service for companies that want to move and analyze large amounts of data.
It should be kept in mind, however, that any Google Font request will also automatically transfer information such as IP address, language settings, browser screen resolution, browser version, and browser name to the Google servers. It is not clear or is not clearly communicated by Google whether this data is also stored.
If you would like to receive our newsletter, we need your email address that will allow us to verify that you are the owner of the email address provided and that you agree to receive the newsletter.
We use a double opt-in procedure, so you receive only the emails you have agreed to get from us. In order for a potential subscriber to sign up for a newsletter, they have to complete all the steps of this process. This process is complete once a user has clicked on the confirmation link in the double opt-in email. Their email address will be activated in your contact list only once they have confirmed their subscription.
We use this data exclusively for sending information and offers you have requested.
MailChimp is the email marketing platform we use. This means your information is transmitted to MailChimp-c/o The Rocket Science Group, LLC. MailChimp is prohibited from selling your data and from using it for purposes other than sending email. MailChimp undergoes annual verification with a U.S. based third party-outside compliance reviewer under the Privacy Shield verification program, and they have certified their compliance with the EU-U.S./Swiss-U.S. Privacy Shield Frameworks.
More Info: https://mailchimp.com/about/security/
When you give us the permission to store your email address and to send you marketing emails, you can revoke this consent at any time via the unsubscribe link found on the bottom of every email receive
10. What rights do you have with respect to personal data?
Right of Access:
You have the right to access to the personal data that is being processed by us and if necessary, to receive a copy of that data and/or supplementary information with respect to their processing.
Right to Rectification (Article 16 GDPR):
If the personal information that we hold about you is inaccurate or incomplete, you have the right to rectify, update or amend it, by contacting us at the abovementioned contact details. Alternatively, you may send us a relevant request at the following email address: email@example.com
Right to erasure (“Right to be forgotten”) (Article 17 GDPR):
You have the right to ask us to delete or remove your personal information in some circumstances, such as where we no longer need it or if you withdraw your consent (where applicable).
Right to restrict processing (Article 18 GDPR):
You have the right to request the restriction of the processing of your personal data in certain circumstances, such as where you contest the accuracy of your personal data or when the processing is unlawful and you object to the erasure of your personal data and you request the restriction of its use instead of its erasure, when your personal data is not required for the purposes of processing, however it is required for the establishment, exercise or defense of legal claims, and when you object to processing and pending the verification whether our legitimate grounds override your rights.
Right to object processing (Article 21 GDPR):
You have the right to object at any time to processing of your personal data in cases where this is required for the purposes of legitimate interests we pursue as data controllers.
Right to data portability (Article 20 GDPR):
You have the right, in certain circumstances, to obtain personal information that you have provided to us in a structured, commonly used and machine readable format, and to transfer it another data controller in order to reuse it or ask us to transfer this to a third party.
Right to withdraw the consent:
If we rely on your consent as our lawful basis for processing your personal data, you have the right to withdraw that consent at any time. However, please note that withdrawal of your consent does not affect the legality of consent-based processing during the period before such consent was revoked.
Right to lodge a complaint with the Hellenic Data Protection Authority:
To exercise any of your aforementioned rights you have the right to lodge a complaint to the Hellenic Data Protection Authority (www.dpa.gr), Phone Number: +30 210 6475600, Fax: +30 210 6475628, Email Address: firstname.lastname@example.org
In addition, Data protection measures are always subject to technical innovations. For this reason, we kindly ask you to inform yourself about our data protection measures at regular intervals by consulting our data protection policy herein.