Dear Data Subject, we would like to inform you that “European Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data” (hereinafter referred to as the “GDPR”) provides for the protection of natural persons with regard to the processing of personal data as a fundamental right. Pursuant to Article 13 of the aforementioned Regulation, we hereby inform you that:
The Data Controller of your personal data is Fondazione Università Bicocca, with registered office at Piazza dell’Ateneo Nuovo 1, 20126 Milan (MI), Italy, which is responsible for the lawful and proper use of your personal data and may be contacted for any information or request at privacy@fondazionebicocca.it.
The Data Controller will process your personal data, including:
The personal data held by the Data Controller is collected directly from the data subject.
Your personal data is processed for the following purposes and on the following legal bases:
Furthermore, data may be processed in anonymized and/or aggregated form to improve the web browsing experience and for statistical purposes (Art. 6(1)(f) GDPR – legitimate interest). Your data may also be processed to comply with obligations imposed by laws, regulations and/or EU legislation, or by supervisory and regulatory authorities (Art. 6(1)(c) GDPR – legal obligation).
To the extent relevant to the processing purposes indicated above, your data may be disclosed to: a) the website hosting service provider, appointed as Data Processor pursuant to Art. 28 GDPR; b) analytics platform providers (where applicable), appointed as Data Processors; c) newsletter/email marketing service providers (where applicable), appointed as Data Processors; d) public or judicial authorities, where required by law. Data Processors are specifically identified and the relevant list is available upon request.
In connection with the technical services used to operate the website (hosting, analytics, email marketing), your personal data may be transferred to third countries outside the European Economic Area. In such cases, the transfer takes place on the basis of: a) an adequacy decision by the European Commission (where available); b) Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU); c) the provider’s participation in the EU-US Data Privacy Framework (for transfers to the United States). No transfer outside the EU takes place for data processed exclusively on infrastructure located within the European Union.
The data collected will be retained for the following periods: a) browsing data and technical logs: 6 months from collection; b) data provided through contact forms: 12 months from the request; c) technical cookies: for the duration of the browsing session; d) analytics cookies (where applicable): as specified in the Cookie Policy, and in any case no longer than 13 months; e) newsletter-related data: until consent is withdrawn or the user unsubscribes. Once the above periods have expired, the data will be deleted or irreversibly anonymized. The obsolescence of retained data is reviewed periodically.
The data subject always has the right to: a) request access to their data from the Data Controller (Art. 15 GDPR); b) obtain the rectification of inaccurate data (Art. 16 GDPR); c) obtain the erasure of data (Art. 17 GDPR); d) obtain restriction of processing (Art. 18 GDPR); e) receive the data in a structured, commonly used format – data portability (Art. 20 GDPR); f) object to processing on legitimate grounds (Art. 21 GDPR); g) object at any time to the processing of their data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing (Art. 21(2) GDPR); h) withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR). These rights may be exercised by writing to the Data Controller’s email address indicated above. The Data Controller will respond within 30 days of the request (Art. 12(3) GDPR). The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) if they believe that the processing of their data is contrary to applicable legislation.
The personal data provided by you will be processed in compliance with the aforementioned legislation and the confidentiality obligations governing the activities of the Data Controller. Data will be processed using IT systems, paper-based records, and any other suitable medium, in compliance with appropriate security measures pursuant to Art. 5(1)(f) GDPR.
The provision of browsing data (technical logs) is necessary for the operation of the website; failure to provide such data makes browsing the website impossible. The provision of data through contact forms is optional; failure to provide such data will make it impossible for the Data Controller to respond to the user’s request. Consent to the newsletter is optional; failure to provide consent will only result in the inability to receive the Data Controller’s periodic communications.
This Privacy Policy does not apply to other websites that may be accessed through links available on websites under the Data Controller’s domain. The Data Controller cannot be held responsible in any way for third-party websites.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.