1.Data controller
The controller of the processing described in this Policy is legal entity name, with registered office at registered office, VAT number P.IVA (the Controller).
The Controller may be contacted in respect of any matter arising under this Policy at privacy email address.
2.Scope
This Policy applies to the Students World Platform, comprising the website operated by the Controller, the ambassador pages forming part of it, and the Telegram group opened following a request for an introduction (together, the Service).
This Policy does not apply to the consulting business carried on by the Controller with universities and institutions, which is a separate activity and is not conducted through the Service.
Were a disclosure under clause 5.2 to be made, this Policy would not apply to the processing carried out by the University following it. In respect of that processing the University would determine the purposes and means on its own account and act as an independent controller, and its own privacy policy would apply.
This Policy does not apply to Telegram, which processes messages exchanged in the group under its own terms and privacy policy.
3.Definitions
In this Policy the following expressions bear the following meanings.
- Ambassador
- A student enrolled at a University who is engaged by the Controller and who corresponds with prospective students through the Service under the authority and instruction of the Controller.
- Data subject
- The natural person to whom the personal data described in this Policy relate, being the person requesting an introduction.
- University
- The higher education institution nominated on the ambassador page from which the request for an introduction is made.
- Processor
- A person appointed under Art. 28 GDPR to process personal data on behalf of and on the documented instructions of the Controller.
4.Categories of personal data processed
Data provided by the data subject: name, surname, electronic mail address, and country of origin. Country of origin is collected because it determines which admission, entry and residence requirements apply to the data subject, and is not transmitted to the university.
Data relating to consent: the consents given or withheld, the version of the wording displayed at the time, and the date and time of the act.
Data arising from the Telegram group: the Telegram username and numeric identifier of the data subject, and the messages exchanged in the group.
Data collected automatically upon access: IP address, user agent, referring page, and the date and time of access.
No special categories of personal data within Art. 9 GDPR are requested by the Controller. The data subject is asked not to communicate such data through the Service.
The Controller does not acquire personal data concerning the data subject from third-party sources.
Data collected upon a visit to an ambassador page or a university page, for the purpose described at clause 14.1: a salted, one-way hash of the IP address and user agent, computed afresh for each calendar day. The IP address and user agent themselves are not retained.
5.Purposes of the processing and legal bases
The purposes of the processing, the categories of data processed for each, and the legal basis on which each is carried out are as follows.
Effecting the introduction requested by the data subject
The processing is necessary in order to perform the service requested by the data subject and to take steps at the data subject’s request prior to the provision of that service. The declaration recorded at the same moment is an acknowledgement of this Policy and of the support relationship, and is not the basis upon which the processing is carried out.
- Categories of data
- Name, surname, electronic mail address, and the country of origin stated by the data subject.
- Legal basis
- Art. 6(1)(b) GDPR, performance of a contract
Disclosure of the data subject’s particulars to the nominated university
Not currently carried out.
This disclosure is not presently carried out and no consent to it is presently sought. Should it be carried out, consent will be obtained by affirmative act before any particulars are disclosed, will be sought separately from any other consent, and may be withdrawn at any time under Art. 7(3) GDPR. Upon disclosure the university determines the purposes and means of its own processing and acts as an independent controller in respect of it.
- Categories of data
- Name, surname, and electronic mail address.
- Legal basis
- Art. 6(1)(a) GDPR, consent
Retention of a record of the conversation with the ambassador
The legitimate interests pursued are the supervision and quality assurance of the service, the ability to intervene where a conversation does not progress, and the ability to evidence which ambassador effected the introduction. The data subject is informed of the record before the group is opened, and the assistant maintaining it is present in the group as a disclosed third participant.
- Categories of data
- The messages exchanged in the Telegram group and the Telegram username of the data subject.
- Legal basis
- Art. 6(1)(f) GDPR, legitimate interests
Service communications concerning an introduction already commenced
The legitimate interest pursued is the completion of a process the data subject has initiated. Communications under this purpose are limited to that process and each carries a facility to object, the exercise of which terminates them.
- Categories of data
- Name and electronic mail address.
- Legal basis
- Art. 6(1)(f) GDPR, legitimate interests
Direct marketing communications
Consent is sought separately and is not a condition of any other part of the service. It may be withdrawn at any time under Art. 7(3) GDPR, including by the facility contained in each communication. Upon withdrawal the electronic mail address is entered on a suppression list for the sole purpose of ensuring that no further communication is sent.
- Categories of data
- Name and electronic mail address.
- Legal basis
- Art. 6(1)(a) GDPR, consent
Evidence of the introduction and of the consent given
The legitimate interests pursued are the establishment of which ambassador effected an introduction, the performance of the Controller’s arrangements with the universities with which it works, and the discharge of the Controller’s obligation under Art. 7(1) GDPR to demonstrate that consent was given. Records forming part of the Controller’s accounts are retained for the period prescribed by Italian law.
- Categories of data
- Name, the nominated university, the ambassador, the date and time, the version of the wording assented to, and the IP address and user agent recorded at the moment of assent.
- Legal basis
- Art. 6(1)(f) GDPR, legitimate interests
Security, prevention of misuse, and diagnosis of faults
The legitimate interests pursued are the prevention of fraudulent or automated submissions, the prevention of attempts to misattribute an introduction, and the maintenance and security of the service.
- Categories of data
- IP address, user agent, referring page, and the date and time of access.
- Legal basis
- Art. 6(1)(f) GDPR, legitimate interests
Measuring which content brings students to the Service
The legitimate interest pursued is understanding which ambassador pages and university pages lead a visitor to request an introduction, so that the Controller can direct its own efforts toward what demonstrably works. The daily rotation of the salt prevents the record from being used to follow a visitor from one day to the next, and no cookie or other tracking technology is used to collect it.
- Categories of data
- A salted, one-way hash of the IP address and user agent recorded on each visit to an ambassador page or a university page, computed afresh for each calendar day. The IP address and user agent themselves are not retained.
- Legal basis
- Art. 6(1)(f) GDPR, legitimate interests
6.Nature of the provision of data
The provision of the data listed at clause 4.1, and the declaration made at the same moment, are necessary in order for an introduction to be effected. Where they are not provided, the Service cannot be provided. No further consequence follows.
The consent referred to at clause 5.5 is optional. Its refusal has no effect upon any other part of the Service and is not a condition of it.
There is no statutory or contractual obligation upon the data subject to provide any of the data described in this Policy.
7.Recipients
An Ambassador processes personal data as a person acting under the authority of the Controller within the meaning of Art. 29 GDPR and as a person authorised to process within the meaning of Art. 2-quaterdecies of the Italian Privacy Code. An Ambassador is not a recipient within the meaning of Art. 4(9) GDPR, and the making available of personal data to an Ambassador does not constitute a disclosure to a third party.
Each Ambassador is designated in writing, is authorised to process personal data only upon the instructions of the Controller, is bound by an obligation of confidentiality, and receives no more than the name of the data subject and such information as the data subject communicates within the Group. An Ambassador does not receive the electronic mail address of the data subject.
Personal data may be disclosed to the following recipients and categories of recipients.
- The nominated university
- Where and only where consent under clause 5.2 has been given. The university thereafter acts as an independent controller and its own privacy policy governs its processing.
- Telegram
- The conversation is conducted on Telegram, which processes it under its own terms and privacy policy. The group is private to the data subject, the ambassador and the assistant. No content is published.
- Processors engaged by the Controller
- Providers of hosting, database and electronic mail delivery services, each appointed under a contract satisfying Art. 28 GDPR and acting only on the documented instructions of the Controller.
- Professional advisers and public authorities
- Legal and accounting advisers where necessary, and public authorities where disclosure is required by law.
Personal data are not sold, leased, or disclosed to advertisers or to data brokers, and are not disclosed to any recipient outside the categories set out above.
8.Transfers to third countries
Certain of the recipients identified at clause 7.3, including Telegram, are established outside the European Economic Area.
Where personal data are transferred to a third country that is not the subject of an adequacy decision under Art. 45 GDPR, the transfer is carried out on the basis of the standard contractual clauses adopted by the European Commission under Art. 46(2)(c) GDPR.
A copy of the safeguards relied upon may be obtained on request at privacy email address.
9.Retention periods
Personal data are retained for the periods set out below, determined by reference to the purpose for which they were collected.
- Record of the introduction and of the consent given
- For the duration of the Controller’s engagement with the nominated university in respect of the application, and for five years thereafter, a question as to which ambassador effected an introduction being capable of arising long after enrolment.
- 5 years after the engagement ends
- Record of the conversation with the ambassador
- Twenty-four months from the last message, upon which it is erased.
- 24 months
- Data processed for direct marketing
- Until consent is withdrawn or an objection is made, and in any event not more than twenty-four months from the last interaction of the data subject with a communication sent under that consent.
- 24 months from last interaction
- Suppression list
- Indefinitely. The list contains no more than is required to identify the address and refrain from contacting it, an objection being of no effect if the record of it is erased.
- Indefinite
- Accounting records
- Ten years, being the period prescribed by Art. 2220 of the Italian Civil Code.
- 10 years
Upon expiry of the applicable period the personal data are erased, or irreversibly rendered incapable of being attributed to a data subject.
10.Security of processing
The Controller implements technical and organisational measures appropriate to the risk in accordance with Art. 32 GDPR, including encryption of personal data in transit and at rest and the restriction of access to those persons who require it for the performance of their functions.
Personal data by which a data subject is directly identified are held separately from the remaining records of the Service.
In the event of a personal data breach the Controller shall notify the supervisory authority in accordance with Art. 33 GDPR and, where the breach is likely to result in a high risk to the rights and freedoms of the data subject, shall communicate it to the data subject in accordance with Art. 34 GDPR.
11.Rights of the data subject
The data subject is entitled to exercise the following rights.
- Access
- To obtain confirmation as to whether personal data concerning the data subject are processed, a copy of those data, and the particulars set out in that Article.
- Art. 15 GDPR
- Rectification
- To obtain the rectification of inaccurate personal data and the completion of incomplete personal data.
- Art. 16 GDPR
- Erasure
- To obtain the erasure of personal data where one of the grounds in that Article applies. Where an exemption is relied upon, the Controller shall identify it.
- Art. 17 GDPR
- Restriction of processing
- To obtain the restriction of processing in the circumstances set out in that Article, whereupon the data are stored but not otherwise processed.
- Art. 18 GDPR
- Portability
- To receive personal data provided by the data subject in a structured, commonly used and machine-readable format, and to have those data transmitted to another controller where technically feasible.
- Art. 20 GDPR
- Objection
- To object to processing carried out on the basis of legitimate interests. Where the objection concerns direct marketing, the processing shall cease and no balancing of interests arises.
- Art. 21 GDPR
- Withdrawal of consent
- To withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal or processing carried out on another basis.
- Art. 7(3) GDPR
12.Exercise of rights
The rights set out at clause 11.1 are exercised by written request to privacy email address.
The Controller shall respond without undue delay and in any event within one month of receipt, in accordance with Art. 12(3) GDPR. That period may be extended by two further months where necessary, in which case the Controller shall inform the data subject of the extension and of the reasons for it within the first month.
No fee is charged, save in the circumstances contemplated by Art. 12(5) GDPR.
The Controller may request such further information as is necessary to confirm the identity of the person making the request, in accordance with Art. 12(6) GDPR.
Consent to direct marketing may in addition be withdrawn by means of the facility contained in each communication sent under it, without any request under clause 12.1 being necessary.
14.Measurement of page views
The Controller counts visits to ambassador pages and to university pages forming part of the Service, so as to measure which content brings students to the Service.
No cookie is set for this purpose, and no tracking technology requiring consent under Art. 122 of the Italian Privacy Code is used.
The visitor is identified by a salted, one-way hash of the IP address and user agent recorded at the moment of the visit. The salt changes with the calendar day, so the hash computed for a given visitor on one day differs from the hash computed for the same visitor on the next, and the same person cannot be followed across days.
The IP address and user agent themselves are not retained. What is stored is the hash described at clause 14.3.
This hash is produced by pseudonymisation within the meaning of Art. 4(5) GDPR and remains personal data within the meaning of Art. 4(1) GDPR notwithstanding the salting and the daily rotation. It is not anonymous data.
15.Minors
The Service is not directed to persons under the age of 16, who may not use it.
Where the Controller becomes aware that personal data relating to a person under that age have been provided, those data shall be erased. Any person having knowledge of such a circumstance is invited to notify the Controller at privacy email address.
16.Automated decision-making
No automated decision-making within the meaning of Art. 22(1) GDPR, including profiling, is carried out in respect of the data subject. The Ambassador with whom the data subject is placed in contact is selected by the data subject.
17.Amendments
The Controller may amend this Policy. The version in force is published at this address and bears the version number and date of effect stated at its head.
Where an amendment materially affects the data subject and the Controller holds an electronic mail address for that data subject, notice of the amendment shall be given by electronic mail.
18.Complaints
The data subject has the right to lodge a complaint with a supervisory authority under Art. 77 GDPR. In Italy that authority is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy.
A data subject resident or working in another Member State of the European Economic Area, or in which the alleged infringement occurred, may lodge the complaint with the supervisory authority of that State.
The right at clause 18.1 is exercisable without prior recourse to the Controller. The Controller nevertheless invites any complaint to be addressed to it in the first instance, at the address given at clause 1.2.
For matters other than the processing of personal data, the Controller may be contacted at support email address.