ERASMUS PRIVACY POLICY – FACULTY AND STAFF

Dear Sir / Dear Madam,

Saint Louis Music Center S.r.l. (“the Company“), headquartered at Via Cimarra 19/B, Rome CF and VAT 05731131008, (hereinafter, the “Owner“), provides as the Data Controller of your personal data and pursuant to Art. 13 of Regulation (EU) 2016/679 (hereinafter referred to as “GDPR“), in your capacity as a “Data Subject“, i.e. a natural person to whom the personal data subject to the processing described below relates, appropriate information about the basic elements of the processing performed by us.

This information on the processing of personal data is also understood to be given to your emergency contact in accordance with Art. 14 of the GDPR. In this regard, you agree to make this disclosure to your emergency contact in the event that in the course of your relationship with the Controller, you disclose your personal data to the Controller.

At any time you can contact the Holder at the following contact details: privacy@saintlouis.eu or at the above address. The Owner has not identified a Data Protection Officer (DPO or DPO), as it is not subject to the designation requirement under Art. 37 of the Regulations.

1. DATA PROCESSED.

Personal Data collected by the Owner for the purpose of possible participation in the Erasmus program include:

  1. Your personal data and additional identifying information about you, such as your first and last name, nationality, date of birth, place of birth, residential address, tax code, VAT number;
  2. Your contact information, such as e-mail address and phone number;
  3. Your bank details (such as IBAN and/or any other bank details and/or data that may be necessary for the proper performance of the Holder’s payment obligations to you);
  4. the details of your identification documents, should it be necessary for the purpose of the execution of the existing relationship with the Holder;
  5. Your data related to insurance coverage;
  6. Your data related to transfers, board and lodging;
  7. your curriculum vitae as well as any personal information you may and voluntarily provide to the Controller for the purpose of the eventual establishment of the relationship with the Controller;

The Holder may also process the personal data of your emergency contact always to the extent that this is necessary for the management of the employment relationship related to the Erasmus program or in the context of social security and/or welfare practices: this privacy policy applies to such processing as relevant.

2. PURPOSE OF PROCESSING AND LEGAL BASIS

Your personal data, or personal data related to your emergency contact, will be processed by the Controller for the following processing purposes:

Purpose

Legal Basis

a) Contractual obligations, exclusively for purposes related to the existing relationship and its execution and to fulfill the provisions of the concluded collaboration with you related to participation in the Erasmus project. They fall under this purpose: (i) the management of Erasmus project applications and the preparation of a ranking list; (ii) Notices and communications regarding the outcome of the procedure; (ii) the organizational management of activities with the host institution and the agencies involved.

The legal basis for the processing consists of Art. 6(1)(b) of the GDPR, i.e., the processing is necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the request of the data subject.

b) Administrative-accounting purposes., that is, to carry out activities of an organizational, administrative, financial and accounting nature, such as internal organizational activities and activities functional to the fulfillment of contractual and pre-contractual obligations. This includes, but is not limited to, reimbursement of travel costs and room and board expenses.

The legal basis for the processing consists of Art. 6(1)(b) of the GDPR, i.e., the processing is necessary for the performance of a contract to which the data subject is party or for the performance of pre-contractual measures taken at the request of the data subject.

c) Legal obligations, i.e., to comply with obligations under the law, an authority, GDPR or European legislation, arising from your contract with the Owner relating to participation in the Erasmus project.

The legal basis for the processing consists of Art. 6(1)(c) of the GDPR, i.e., the processing is necessary to comply with a legal obligation to which the Data Controller is subject.

d) for the protection of the rights and interests of the Holder in judicial and/or extrajudicial proceedings, as well as in administrative proceedings or arbitration and conciliation procedures in cases provided for by law.

The legal basis consists of Art. 6(1)(f) of the GDPR i.e. the processing is necessary for the pursuit of the legitimate interest of the Data Controller or third parties.

3. RECIPIENTS OF DATA COMMUNICATION

Data will be disclosed and may be known: (i) by internal personnel expressly authorized to process the Data in order to carry out the activities pertaining to the area in which they work pursuant to Art. 29 of the GDPR; (ii) by the host institution for transactions related to the project in which the data subject participates and to Entities and Institutions (such as: European Commission) to which the Company has specific legal obligations; (iii) by the company providing services in the field of labor consulting, (iv) by banking institutions for handling payments arising from the existing relationship, (v) by financing companies in the case of specific requests by the Interested Party itself, by banking institutions for the management of payments and collections arising from the existing relationship; (vi) by IT companies that perform support activities on the systems used by the Data Controller for data processing; and (vii) by consultants for litigation management and legal assistance in the event of any litigation for which their involvement would be necessary.

You may also request from the Data Controller the list of the aforementioned individuals who will act as data controllers (in which case, they are appointed in writing by the Data Controller, pursuant to Article 28 of the GDPR, and will process personal data on behalf of the Data Controller) or as autonomous data controllers.

It is also specified that these parties will only be able to process the data necessary for the type of service provided and that, as indicated in the notice, the ranking of the selected interested parties, is posted on the Notice Board and published on the Holder’s website, resulting in access to the data by those who access the Holder’s premises and the dedicated area of the website. These data will remain published for three months after publication.

In any other case, your Data will not be disclosed to third parties, will not be disseminated in any way, and in any case never outside the employment contract.

Finally, it should be noted that the Holder has appointed as System Administrators: the gentlemen named in the list available to employees within the company bulletin board and/or intranet. Such persons, appointed in writing by the Data Controller, pursuant to the General Provision of the Data Protection Authority “Measures and expedients prescribed for data controllers of processing operations carried out by electronic means with regard to the attribution of system administrator functions – November 27, 2008,” may have access to your personal data. For further information, i.e., to obtain a complete and updated list of appointed System Administrators, please write to the Owner via the methods indicated in paragraph 1 above.

4. PLACE OF DATA PROCESSING

Your personal data may be transferred outside the European Union, that is, if a country outside the EU is selected. In such a case, the Data Controller will ensure that the transfer of the data also to the host institution is carried out in accordance with the Applicable Legislation and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision), 46 (Transfer subject to adequate safeguards) et seq. of the GDPR.

5. PROCESSING METHODS, STORAGE PERIOD AND SECURITY MEASURES

The Data Controller will process the Data with and without the aid of electronic, computerized or automated tools, taking specific and adequate logical, organizational and technical security measures to prevent the loss of the Data or their unauthorized or unlawful use.

Personal data will be kept for the time strictly necessary, and subsequently deleted in case of non-selection, to carry out the purposes outlined in paragraph 3 above, i.e. evaluation of the application to participate in the project and preparation of the ranking list. In the case, however, of selection they will be kept for the duration of the project and for a subsequent period of 3 years. In both cases, this is without prejudice to the need to protect the interests and rights of the Holder in judicial and/or extrajudicial proceedings and any retention periods provided for by laws or regulations.

6. COMPULSORINESS OF DATA PROVISION

Providing your personal data-and, where required, those of your emergency contact-is optional but necessary, as failure to do so will make it impossible for the Owner to evaluate your application and possibly initiate, if selected, collaboration concerning the Erasmus project.

7. RIGHTS OF THE DATA SUBJECT

You, as a Data Subject (i.e., subject to whom the Data refers), have rights conferred by the GDPR.

In particular, in accordance with Articles 15-22 of the GDPR, you have the right to request and obtain information on(i) the origin of your personal data;(ii) the purposes and methods of processing;(iii) the logic applied in case of processing carried out with the aid of electronic instruments;(iv) the identification details of the Data Controller and the persons in charge; and(v) the subjects or categories of subjects to whom the personal data may be communicated or who may become aware of them as managers or appointees.

In addition, you have the right to obtain:

  1. access,update, rectify or, when interested,supplement your personal data;
  2. the deletion, transformation into anonymous form or blocking of your personal data processed in violation of the law, including data whose storage is not necessary in relation to the purposes for which the data were collected or subsequently processed;
  3. A statement that the operations referred to in paras. (a) and (b) will be brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except where this proves impossible or involves the use of means manifestly disproportionate to the right protected.

In addition, you have:

  1. The right to withdraw consent at any time if the processing is based on your consent;
  2. (in cases only where the processing carried out is based on your consent and/or where your personal data are processed by the Controller to fulfill its obligations under the employment contract concluded with you) the right to data portability, the right to restriction of processing of personal data and the right to erasure (“right to be forgotten”);
  3. The right to object in whole or in part, on legitimate grounds to the processing of personal data concerning you, even if relevant to the purpose of collection;
  4. should you believe that the processing concerning you violates the GDPR, the right to lodge a complaint with a Supervisory Authority (in the member state where you normally reside, where you work, or where the alleged violation occurred). The Italian supervisory authority is the Garante per la protezione dei dati personali, based at Piazza Venezia no. 11, 00187 – Rome (http://www.garanteprivacy.it).

In order to exercise your rights, you can always contact the Controller at the contact details above.

keyboard_arrow_up