ERASMUS PRIVACY POLICY – STUDENT

The participation of students in the Erasmus program at Saint Louis Music Center S.r.l. involves the collection of information that constitutes personal data in accordance with d.lgs. 196/2003 and ss.mm.ii. (hereinafter, the “Code“) as well as Regulation (EU) 2026/679 (hereinafter, the “GDPR“).

1. DATA CONTROLLER

The Data Controller is Saint Louis Music Center S.r.l. (“the Company“), headquartered at Via Cimarra 19/B, Rome CF and VAT 05731131008 (hereinafter, the “DataController” or “Saint Louis“) and provides Erasmus students and, through them, those to whom the data transmitted (hereinafter, the “DataSubjects”, Students” or “Students“), the privacy policy under Art. 13 of the GDPR. This information on the processing of personal data is also understood to be given to your emergency contact in accordance with Art. 14 of the GDPR. In this regard, you agree to make this disclosure to your emergency contact in the event that in the course of your relationship with the Controller, you disclose your personal data to the Controller.

At any time you can contact the Holder at the following contact details: privacy@saintlouis.eu or at the above address. The Owner has not identified a Data Protection Officer (DPO or DPO), as it is not subject to the designation requirement under Art. 37 of the Regulations.

2. DATA PROCESSED.

The data processed are those provided by the student through the Erasmus application. More specifically, it is the following data reported to the Student:

Biographical, Contact, Curricular, and Study Pathway Data.

The data processed through the submission of the appropriate Erasmus application are the Student’s first name, last name, place and date of birth, nationality, residence/domicile, (hereinafter, the “Personal Data“), as well as telephone number, e-mail (hereinafter, the “Contact Data“), all further data contained within the Student’s curriculum (hereinafter, the “Curricular Data“) and all data related to the Student’s studypath(hereinafter, the “Study Path Data“).

Insurance and Banking Data

In the case of selection, Data related to insurance coverage taken out by the Interested Party (hereinafter, the “Insurance Data“) will also be processed. In the case of a scholarship award, the bank details and Identifying Data of the account holder (hereinafter, the “Bank Data“) will also be processed. The Identifying Data of the person identified as the emergency contact is also processed.

The data listed above may be generically identified below as “Data.”

3. PURPOSE AND LEGAL BASIS FOR PROCESSING

Data collected are processed for: (i) The management of Erasmus project applications; (ii) Notices and communications regarding the outcome of the participation process; (iii) the organizational management of activities with the host institution and the agencies involved; (iv) the disbursement of contributions; (v) the management of accounting and administrative obligations.

The legal bases on which the processing of the Data referred to in puti (i), (ii), (iii), (iv) and (v) are: the execution of pre-contractual measures and obligations arising from the contract to which the Interested Party is a party (Art. 6, para. 1, lett. (b) of the GDPR) and the fulfillment of legal obligations to which the Controller is subject (Art. 6, para. 1, lett. (c) of the GDPR).

Should it become necessary, the Data Subject’s Data may also be used against the legitimate interest of the owner to carry out defensive activities or assert or defend a right in court (Art. 6(1)(f) of the GDPR).

4. RECIPIENTS OF DATA COMMUNICATION

The Data conferred may be known to the (i) internal personnel expressly authorized to process the Data Subject’s Data in order to carry out the activities pertaining to the area in which they work; (ii) to the host institution for operations related to the project in which the Respondent is participating; and (iii) to the Bodies and Institutions (such as: European Commission, Ministry of University and Research) towards which the Company has specific legal obligations; from the external entities that the Controller uses and, precisely: (iv) by the company providing accounting and tax consulting services for administrative accounting purposes related to the existing relationship and the legal obligations to which the Company is subject; (v) by financing companies in the case of specific requests from the Interested Party itself, (vi) from banking institutions for handling payments and collections arising from the existing relationship, (vii) by IT companies that perform support activities on the systems used by the Data Controller for data processing, (viii) by consultants for litigation management and legal assistance in the event of any litigation for which their involvement is necessary.

It should be noted that some of the persons indicated operate as data controllers and that communication to those who operate as autonomous data controllers is carried out without requiring the consent of the Data Subject if prescribed by legal obligations or necessary to carry out the obligations arising from the contractual relationship or the legitimate interest indicated in the purposes of processing.

The Data Subject may also request from the Data Controller the list of individuals who will act as data processors (in which case, they are appointed in writing by the Data Controller, pursuant to Article 28 of the GDPR, and will process personal data on behalf of the Data Controller) or as autonomous data controllers. However, communication is limited only to the categories of Data whose transmission is necessary for the performance of the activities and purposes pursued.

Lastly, it should be noted that, as stated in the announcement, the ranking list of selected students, indicating the scholarship recipients, is posted on the Notice Board and published on the Society’s website, resulting in access to the data by those who access the Society’s premises and the dedicated area of the website. These data will remain published for three months after publication.

5. PLACE OF DATA PROCESSING

The Company uses in-house IT tools on company premises and the platform provided by the European Commission to manage and report on Erasmus projects.

Data will be transferred outside the EU in the event that the student has selected a country outside the EU and, therefore, in the event that a disclosure of data to the host institution is necessary in order to carry out the adhered project and, in that case, the Data Controller will ensure that the transfer is made in accordance with the GDPR and, in particular, in accordance with Articles 45 (Transfer on the basis of an adequacy decision) and 46 (Transfer subject to adequate safeguards) of the GDPR.

6. PROCESSING METHODS, STORAGE PERIOD AND SECURITY MEASURES

The Data collected are processed by computer and paper-based means by authorized personnel, in compliance with the security requirements prescribed by current regulations to prevent data loss, illegal or incorrect use and unauthorized access. The Data provided through the application are kept for the time strictly necessary to evaluate the application and the processing of the ranking list and then deleted in the case of non-selection, except in cases of defensive needs (which may require further storage).

In the case of selection, the Data conferred and acquired during the relationship will be kept for the duration of the project and for as long as necessary to fulfill the obligations underlying the processing. More precisely the Data contained in the Erasmus project applications and releases will be retained for a period equal to that required by the statute of limitations, subject to the need to protect the interests of the Holder and the Student in civil law. In any case, this is without prejudice to any defensive needs for which the Data may be retained beyond the terms indicated.

7. COMPULSORINESS OF DATA PROVISION

The provision of the Data referred to in paragraph 3. (i), (ii), (iii), (iv) and (v) is optional, but without it, it will not be possible to submit the application and participate in the project.

8. RIGHTS OF THE DATA SUBJECT

Data Subjects are holders of rights conferred by the GDPR. In particular, under Articles 15-22 of the GDPR they have the right to request and obtain the indication: (i) Of the origin of personal data; (ii) Of the purposes and methods of processing; (iii) of the logic applied in case of processing carried out with the aid of electronic tools; (iv) of the identification details of the owner and responsible parties; (v) of the individuals or categories of individuals to whom the personal data may be communicated or who may become aware of them in their capacity as managers or appointees.

In addition, Interested Parties have the right to obtain:

  1. access,update, rectify or, when they have an interest,supplement the data;
  2. the cancellation, transformation into anonymous form or limitation of data processed in violation of the law, including data whose retention is not necessary in relation to the purposes for which the data were collected or subsequently processed;
  3. A statement that the operations referred to in paras. (a) and (b) have been brought to the attention, also as regards their content, of those to whom the data have been communicated or disseminated, except where this proves impossible or involves the use of means manifestly disproportionate to the right protected.

In addition, the Interested Parties have:

  1. The right to withdraw consent at any time if the processing is based on their consent;
  2. The right to data portability (the right to receive all personal data concerning them in a structured, commonly used, machine-readable format);
  3. the right to object:
    1. in whole or in part, for legitimate reasons to the processing of personal data concerning them, even if relevant to the purpose of collection;
    2. in whole or in part, to the processing of personal data concerning them for the purpose of sending advertising or direct sales material or for carrying out market research or commercial communication;
    3. where personal data are processed for direct marketing purposes, at any time to the processing of their data carried out for that purpose, including profiling insofar as it is related to such direct marketing;
  4. should they believe that the processing concerning them violates the GDPR, the right to lodge a complaint with a Supervisory Authority (in the Member State where they usually reside, in the Member State where they work, or in the Member State where the alleged violation occurred). The Italian supervisory authority is the Garante per la protezione dei dati personali, based at Piazza Venezia no. 11, 00187 – Rome (http://www.garanteprivacy.it/).

In order to exercise your rights, you can always contact the Controller at the contact details above.

keyboard_arrow_up