PROTECTION OF YOUR DATA: CONFIDENTIALITY AND INTEGRITY
To protect your data, we will take appropriate measures that are consistent with applicable data protection and data security laws and regulations, including requiring our service providers to use appropriate measures to protect the confidentiality and security of your data.
More in particular, ERTICO has taken and is taking measures to secure them and protect them against any loss, modification or unauthorised access:
- By updating security measures as the technology evolves, as needed (e.g. sites accessible through “https”; password rules have been implemented);
- By ensuring that your data is only accessible to authorised personnel: the personal data is only accessible to the ERTICO workers and subcontractors on a “need-to-now” basis.
More in particular, only collaborators that are responsible for the relevant Activities gain access to personal data being processed;
- By requesting a proof of identity before being able to provide you with any personal information concerning you;
- By performing periodic back-ups and storing the personal data on secure servers;
- By deleting and/or anonymising your data at the end of the retention period (namely as soon as it is no longer needed for the finalities pursued);
- Those who have access to the personal data have followed or will be following trainings in the processing of personal data and how to process your personal data. They are bound by the confidentiality clauses to guarantee the integrity and confidentiality of your data.
Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
Depending on the state of the art, the costs of the implementation and the nature of the data to be protected, we put in place technical and organisational measures to prevent risks such as destruction, loss, alteration, unauthorised disclosure of, or access to your data. If you have reason to think that your interaction with us or your personal data is no longer processed in a secure manner, please reach out to the ERTICO Privacy Office (contact details below section “contact info”).
WHEN DO WE SHARE YOUR DATA?
We do not share any of your data except in the limited cases described here.
If it is necessary for the fulfilment of the purposes described in this Policy, we may disclose your data to the following entities. Access to your data will be granted on a need-to-know basis:
- ERTICO members: due to our global nature, your data may be shared with certain ERTICO affiliated members;
- Service providers: like many businesses, we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as ICT service providers, consulting providers, shipping providers, payment providers, electronic communication service platforms;
- Business partners: we may share your data with trusted business partners so they can provide you with the services you request;
- Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over ERTICO.
- Professional advisors and others: we may share your data with other parties including professional advisors, such as banks, insurance companies, auditors, lawyers, accountants, other professional advisors.
- Upon your request in case of a personal data portability request.
We have taken the necessary steps to ensure that all recipients of your data provide sufficient and appropriate safeguards to ensure the security (including the integrity and confidentiality) of your personal data.
ERTICO of course also closely monitors how the data is being processed by its subcontractors.
Typically, we work with external parties to organisze the events and/or create event / web pages.
The processing of personal data by these parties may be applicable. You can find there additional (layered) privacy notices here.
WHEN DO WE TRANSFER YOUR DATA ABROAD?
Due to our global activities, data you provide to us may be transferred to or accessed by ERTICO partners, and trusted third parties from many countries around the world.
As a result, your data may be processed outside the country where you live, if this is necessary for the fulfilment of the purposes described in this Policy.
If you are located in a country member of the European Economic Area, we may transfer your data to countries located outside of the European Economic Area. Some of these countries are recognised by the European Commission as providing an adequate level of protection.
With regard to transfers from the European Economic Area to other countries that are not are recognised by the European Commission as providing an adequate level of protection, we have put in place adequate measures to protect your data, such as organisational and legal measures (e.g. binding corporate rules and approved European Commission standard contractual clauses). You may obtain a copy of these measures by contacting the ERTICO Privacy Office (contact details below section “contact info”).
As a general rule, your personal data will be hosted in the European Union, and limited to the finality and data retention periods for the data processing.
For the purposes of our mailings, we are asking you your consent through our website, because we are using the campaign platform Mailchimp. If you agree for us to send you mailings via email, the Mailchimp terms and conditions will be applicable. They can be found here: https://mailchimp.com/legal/privacy/. For more information about Mailchimp’s data storage and security, click here: https://mailchimp.com/about/security/.
For surveys, we use Google forms. The following policies apply https://policies.google.com/privacy?hl=en-US by reference.
HOW LONG DO WE KEEP YOUR PERSONAL DATA?
We keep your data for the period necessary to fulfil the purposes for which it has been collected (for details on these purposes, see above section “How do we use your data?”). Please keep in mind that in certain cases a longer retention period may be required or permitted by law. The criteria used to determine our retention periods include:
- How long is the data needed to provide you with our products or services or to operate our business?
- Do you have an account with us? (e.g. as a recurring event partner, ERTICO member or event visitor). In this case, we will keep your data while your account is active or for as long as needed to provide the services to you.
- Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws in the applicable jurisdiction, government orders to preserve data relevant to an investigation, or data that must be retained for the purposes of litigation, or protection against a possible claim.
For ERTICO Congresses, ERTICO creates a new instance (typically a new database and event site) for each Congress. The personal data of each instance is kept during 26 months rolling. This corresponds the registration period for the current event + the event immediately after that event.
Example: The personal data being processed for “Event 2019” is deleted as soon as we can decommission that platform. This is done as soon as N+1 Event is open for submissions. The instance for Event 2019 is “active” in the period from September 2018 until September 2019. The instance for Event 2020 is available in the period from September 2019 to September 2020. The instance of Event 2019 is being decommissioned as soon as the platform for Event 2021 is active for
submissions (= September 2021).
For ERTICO surveys: each survey results containing personal data will only be accessible to the data analysts analysing the data and making the report (need to know basis), and then pseudonymiszed and archived. The archived data will be retained during a period of six months after publication of the final report after which it is deleted.
The works of authorship shared with us and uploaded on our sites (e.g. research papers, articles, PowerPoints etc.) may also contain personal data. If this is the case, in view of the proportionality principle, ERTICO will remove any excess personal data before it further processes them for the Activities. As a general rule, the works of authorship only contain name + surname + affiliation of the author(s).
WHAT ARE YOUR RESPONSIBILITIES?
We would like to remind you that it is your responsibility to ensure, to the best of your knowledge, that the data you provide us with, are accurate, complete and up-to-date. Furthermore, if you share with us data of other people, it is your responsibility to collect such data in compliance with local legal requirements. For instance, you should inform such other people, whose data you provide to us, about the content of this Policy and obtain their prior consent.
WHAT ARE YOUR RIGHTS?
Data protection law provides with various rights relating to the processing of personal data, so that the data subject can continue to exercise sufficient control over the processing of its personal data:
- Right of access and rectification of personal data: You have the right to obtain confirmation from ERTICO on which personal data are being processed. For the sake of facility, you can find most personal data we process already in the Application itself (see the “your profile” section in the Application), where you can also rectify any inaccurate recorded data. Should you also want to rectify the email address or other data we process, please contact us, as indicated above.
- Right to delete personal data: You may request the deletion of your personal data, being understood that when we are processing your personal data based on the execution of the agreement we have with you, we will delete your personal data as soon as the announced retention time has lapsed and/or the agreement is terminated.
- Right to limit the processing of personal data: You may request the limitation of the processing if the accuracy of the personal data is in question and during the period necessary for the verification of their accuracy.
- Right to oppose the processing of personal data: You may object to certain data processing. This is not the case when it comes to the performance of a contract or the performance of a legal obligation or legal action.
Procedure concerning the exercise of rights
Within ERTICO, the data subject can exercise his rights by sending a request to the ERTICO Data Protection Office. ERTICO has the right to ask the person concerned to identify him/herself in order to ensure that the effective exercise of the rights is requested by the person concerned (and not someone else who does not have the right to ask for this information).
ERTICO will respond to the request of the interested party within a maximum of one month.
Otherwise, ERTICO informs the person concerned of the reasons for his/her inaction or the delay in following up with the request.
Of course, if necessary, ERTICO will also make the necessary efforts to inform the recipients of the personal data of the data subject that the data subject is exercising the right to correct, delete or limit the processing.
You can always contact the ERTICO Privacy Office if you would like to:
- review, change or delete the data you have supplied us with (to the extent ERTICO is not otherwise permitted or required to keep such data);
- object to certain data processing operations (e.g., opt-out from marketing communications);
- receive a copy of your data (in a common machine readable format, to the extent it is required by applicable law);
- ask us any other questions related to the protection of your personal data by ERTICO.
For any questions or reasonable inquiry related to the protection of your personal data or regarding this Policy in general, you can contact the ERTICO Privacy Office. The tasks of this office are:
- to align and coordinate approaches to privacy and information security within and across ERTICO’s various activities to ensure a systematic approach;
- to ensure the implementation and enforcement of data protection legislation and the present policy within ERTICO.
ERTICO asks you to send your requests, questions and possible complaints to the mailbox of the service, by email: firstname.lastname@example.org or by post: ERTICO Data Protection Office, FAD Department, Avenue Louise 326 to 1050 Brussels (Belgium).
If you have any questions about this policy or if you wish to make a complaint, you can contact us either via email or by mail using the contact information mentioned above.
You also have the right to lodge a complaint with the Belgian Data Protection Authority: Rue de la Presse 35, 1000 Brussels, +32 (0) 2 274 48 00 +32 (0) 2 274 48 35, email@example.com.
If a new version becomes applicable, ERTICO will post it on its website, and, if applicable, on the other digital locations (such as an event website). We may also request you to re-enroll your consent preferences from time to time.
The previous versions can be found here.