PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA FOR THE ACCESS MANAGEMENT PLATFORM (AMP)
We wish to inform you that Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR") provides for the protection of natural persons with regard to the processing of personal data.
In accordance with this Regulation, your personal data will be processed in compliance with the principles of lawfulness, fairness, transparency, data minimisation, accuracy, integrity, confidentiality and storage limitation, while ensuring the protection of your rights and fundamental freedoms.
The Consorzio Interuniversitario Risonanze Magnetiche di Metallo Proteine (CIRMMP) (hereinafter referred to as the "Data Controller"), with its registered office at Piazza San Marco 4, Florence, Italy, and operational headquarters at Via L. Sacconi 6, 50019 Sesto Fiorentino (FI), Italy, hereby informs users of the Access Platform about the processing of their personal data.
1. Purposes of Processing and Legal Basis
The personal data processed (identification and contact details, authentication credentials, institutional affiliation, information contained in the submitted research proposal, documentation relating to mandatory health and safety requirements where applicable, and technical data generated through the use of the platform) are collected and processed exclusively for the following purposes:
- management of user registration and personal accounts on the Access Platform;
- submission, evaluation and management of applications for access to the Consortium's research infrastructures;
- planning and organisation of scientific activities and laboratory access;
- fulfilment of administrative, accounting, auditing and reporting obligations arising from applicable legislation or funding programmes;
- verification of compliance with mandatory health and safety requirements for users requiring physical access to the laboratories;
- protection of the Consortium's IT systems, research infrastructures and legal rights;
- fulfilment of Open Science and Open Access obligations where required by applicable European or national funding programmes.
The legal bases for processing are: the performance of a contract or pre-contractual measures (Article 6(1)(b) GDPR); compliance with legal obligations (Article 6(1)(c) GDPR); and the pursuit of the legitimate interests of the Data Controller in ensuring the security of its infrastructures, protecting its assets and safeguarding its legal rights (Article 6(1)(f) GDPR).
2. Processing Methods and Mandatory Nature of the Provision of Data
Personal data are processed by electronic and, where necessary, paper-based means, protected by appropriate technical and organisational security measures designed to ensure their confidentiality, integrity and availability.
The provision of personal data is mandatory for the registration on the Access Platform, the submission and evaluation of access requests, and the fulfilment of the applicable legal obligations.
Failure to provide the requested data will make it impossible to register on the platform, submit an application for access or make use of the research infrastructures and related services.
3. Recipients of Personal Data and Transfer of Data Abroad
Personal data are not subject to public disclosure.
They may be communicated exclusively to:
- authorised personnel of the Consortium;
- members of scientific evaluation committees and external experts involved in the assessment of access proposals, limited to the personal data strictly necessary for carrying out their duties;
- public authorities, funding bodies, the European Commission and auditing bodies where required by law or by the applicable funding programme;
- providers of administrative, accounting, legal and IT services appointed, where required, as Data Processors pursuant to Article 28 GDPR.
Where required by European or national funding programmes, only the personal and professional information strictly necessary to fulfil Open Science or Open Access obligations may be made publicly available in accordance with the applicable legislation.
Personal data are stored on servers located within the European Economic Area (EEA).
No transfer of personal data outside the European Economic Area is envisaged. Should such a transfer become necessary, it will be carried out in accordance with Articles 44 et seq. of the GDPR.
4. Data Retention Period
Personal data will be retained for the entire duration of the user's relationship with the Consortium and, subsequently, for the period required by the applicable legal, accounting, administrative and funding obligations (ordinarily up to 10 years after completion of the relevant project or termination of the relationship, unless a longer retention period is required by law).
Documentation relating to health and safety requirements will be retained only for the period established by the applicable legislation and solely for the purposes for which it was collected.
5. Rights of the Data Subject
The Data Subject may exercise the rights provided for in Articles 15 to 22 of the GDPR, including the right of access, rectification, erasure, restriction of processing, objection and, where applicable, data portability, by submitting a request to: This email address is being protected from spambots. You need JavaScript enabled to view it.
The Data Subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) pursuant to Article 77 GDPR.