Privacy Policy

(EU) REGULATION no. 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL OF 27 APRIL 2016 ON THE PROCESSING AND PROTECTION OF PERSONAL DATA

Pursuant to and for the purposes of Article 13 and Article 14 of Regulation no. 2016/679 of the European parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free flow of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereafter also "Regulation" or "GDPR"), we hereby inform you that the Personal Data you voluntarily provided to European Polytechnical University (hereafter also "EPU" or "University") will be processed in compliance with the regulations in force and with regard to the protection of Personal Data as well as Data- protection principles in pursuit of its legitimate activities as a University.

  1. The Categories of processed Personal Data

    EPU will process the following Personal Data provided by the data subject:

    • Personal Data (such as: Name, Surname, date and place of birth, gender), password, e-mail, telephone number, address and nationality, qualifications (hereafter also "Personal Data" or "Data");
    • Sensitive Data regarding both possible disability rating determined and accreditation body.
  2. Purposes of the processing

    The Personal Data you provided to EPU may be processed for the following purposes:

    1. To enable and manage the enrollment of the subject at the University;
    2. To enable the subject to benefit from specific, necessary, essential and instrumental services, to carry out the studies and the online university life , as well as to carry out the tasks reserved to you for the enrolment of the Subject at the University, such as, in an illustrative and non- exhaustive way, the access to the didactic platform, the technological e-learning tools, the Apps, the interaction service with Tutors and among students, the monitoring of learning, reports about educational activities carried out by students, administrative office services, social networking, videoconference and chat tools. c) Accounting and administration purposes in compliance with the obligations provided by current regulations;
    3. Accounting and administration purposes in compliance with the obligations provided by current regulations;
    4. For marketing purposes, whereas is given specific and valid consent from the subject, such as informative and promotional communications (including the University’s newsletter), advertising materials and/or educational offers, transmitted by any means, including, in an illustrative and non-exhaustive way, postal service, Internet, telephone, e-mail, MMS, SMS from the University or from educational partners of EPU;
    5. For professional profiles research purposes, as a result of recruiting processes carried out by companies or by societies appointed by them;
    6. For the dissemination of photos and videos in order to promote the didactic and teaching methods of the University.

    We remind you that, with reference to the purposes defined in points (a), (b) and (c), the data subject is obliged to provide the personal data. Any refusal and/or incomplete information may prevent:

    • With reference to the purpose defined in point (a): the subscription and enrolment at University;
    • With reference to the purpose defined in point (b): to benefit from services , as well as to carry out the tasks reserved for the enrolment of the Subject at the University;
    • With reference to the purpose defined in point (c): to perform the accounting and administration activities and the right compliance to the current regulations.

    With reference to further purposes defined in points (d), (e) and (f), both the provision and the consent to the processing of personal data for the above mentioned purposes, is optional and subject to explicit consent.

  3. Personal Data processing Modalities

    The processing of the subject’s Personal Data may be implemented through suitable paper, electronic and/or online documents, with logics strictly connected to the aforementioned purposes and, in such a way as to guarantee the protection of privacy and confidentiality of the Data itself.

    The Personal Data of the subject are processed with the aid of IT tools, fairly and lawfully, for the fulfilment of the aforementioned purposes, including the safeguarding of confidentiality, integrity, authenticity, availability and updating, and are safeguarded with proper safety measures. Personal Data may be stored for the period of time necessary for the archiving purposes for which they were collected to or later processed.

    If the user (i) logs in or signs up to the online platform of the University using the social network credentials (such as Facebook or Twitter, hereafter also as "Social Network") or (ii) he/she associates his/her account to a Social Network account of the same user, the subject may receive personal Data from the aforementioned Social Network, in compliance with the Terms and security policy of the Social Network itself. EPU may add information to the user’s Data already collected through its services. Whenever the user intends to share information through these Social Networks, he/she may receive the Data from the latter in accordance with the consent options provided by the user. The Personal Data possibly communicated from the Social Network will be subject to the Terms and Conditions of use of the Social Network.

  4. Addressee or Categories of Addressee of Personal Data

    Data may be communicated to business partners, members of the board of directors or other administrative body, Responsible for Data protection, and the Heads designated by the University and the persons in charge of the processing of Personal Data appointed by Pegaso International in the execution of their duties.

    The Personal Data of the subject may be communicated to any third Party who provides the University with services or instrumental services for the purposes indicated in the previous par. 2 such as, tin an illustrative and not-exhaustive way, dominating societies, subsidiaries, investees and/or affiliates. The Personal Data of the subject may be also communicated to suppliers, contractors, subcontractors, banking and insurance groups and/or other subjects and/or bodies acting on behalf of EPU for:

    • The management and/or maintenance of Internet websites and electronic and/or online tools used by University;
    • The management of subscription/enrolment at the University;
    • The sending of informative and promotional communications, advertising materials and/or educational offers.

    The Personal Data of the subject may be eventually transferred to companies or societies which work as recruiting centers on behalf of companies for Pegaso International. The Personal Data of the subject may be potentially transferred abroad, in compliance with the current regulations, also to non-EU Countries, whereas the University possibly pursues its interests. The transfer to countries outside the EU is carried out in order to provide appropriate guarantees pursuant to Art. 46 or 47 or 49 of the Regulations, in addition to cases in which this is guaranteed by the adequacy decisions of the European Commission.

  5. Duration of the processing and criteria used for Personal Data storage
    1. Duration

      For the purposes referred to in points a), b) and c) of the previous paragraph 2 "Purposes of Processing" of this Regulation, your Personal Data will be processed only for the period needed. For the purposes referred to in points d), e) and f) of paragraph 2 "Purposes of Processing" of this Regulation, your Personal Data will be processed until the possible revocation of consent by the interested Party.

    2. Storage

      The Data will be stored according to the following criteria:

      • The Data processed for registration / enrollment at the University pursuant to points a), b) and c) of paragraph 2 "Purposes of Processing" of this Regulations, will be stored for the entire period of your registration and for a period of 10 years following the interruption of the agreement, except in the case in which there is a need of a further preservation, in order to allow the Pegaso Online University to defend its rights;
      • the Data processed for the purposes referred to in points d), e) and f) of paragraph 2 "Purposes of Processing" of this Regulations, will be stored for a maximum of 24 months.
  6. Rights of the interested Party

    We inform you that at any time, with regard to your Data, you may exercise the rights provided within the limits and conditions set forth in articles 7 and 15-22 of the Regulations. In order to exercise the rights as described below, please contact the Controller of Personal Data Processing through the Privacy office the e-mail address privacy@epubg.eu. A feedback will be provided within the timing established by the GDPR.
    In detail, the interested Party has the right to:

    • Revoke the consent previously given, without compromising the lawfulness of the processing based on consent before the revocation;
    • Request to the Personal Data Controller to access, amend and erase (so-called "right to be forgotten") the Personal Data or restrict the processing of his/her personal Data or to oppose the processing of the personal data.
    • To obtain Data portability;
    • Lodge a complaint to the Guarantor for the Protection of Personal Data if it considers that its rights have been violated.
  7. Processing Controller, Person and Responsible for the Protection of Personal Data

    The processing Controller of your Data is EPU with registered office in Pernik, ul. Sv. Sv. Kiril i Metodiy 23, Bulgaria, in the person of the Legal Representative pro- tempore. Any request relating to your personal Data processed by the University may be sent to the University's registered office, or via e-mail to the address: privacy@epubg.eu.

    The updated list of persons appointed as Responsible pursuant to article 28 of the GDPR is available at the University and may be consulted upon specific request via the modalities indicated above.

    The contact of the Responsible of the Personal Data Protection is dpo@unipegaso.it. This information will be subjected to updates. EPU invites, therefore, the Users who intend to know the processing Personal Data collected by the University, to periodically visit this webpage.

  8. Data Processing Controller

    European Polytechnical University

    As indicated in the information provided pursuant to Regulation (EU) no. 2016/679 of the European Parliament and Council of 27 April 2016, You are aware that the carrying out of activities related to the processing of Personal Data, referred to in points a), b) and c) indicated in par. 2 of the aforementioned information, does not require the consent to processing.

    The consent is optional for the processing of Personal Data referred to in points d), e) and f) indicated in paragraph 2 of the aforementioned Regulation.

    We invite you to send an e-mail to: privacy@epubg.eu if you intend not to authorize the processing of your Personal Data for promotional, marketing and recruiting purposes.

© Epu - European Polytechnical University - 2017 - All rights reserved.