DENIM WEBSITE PRIVACY POLICY

26 April 2023

The DENiM project is committed to respect the right to privacy and the right to data protection of anyone visiting its website (visitors).

This privacy policy provides visitors with the information required by the General Data

Protection Regulation (GDPR).

The website may contain links to other websites. If you follow a link to any of these websites or make use of any third-party services, please be aware that

they have their own privacy policies and that the DENiM project does not assume any responsibility or liability for their processing of personal data.

I. Name & address of the data controller

The Institute of Systems and Technologies for Sustainable Production (ISTePS) of the Department of Innovative Technologies from the Scuola universitaria

professionale della Svizzera italiana (SUPSI) manages the website on behalf of the DENiM project.

Contact Details:

Scuola universitaria professionale della Svizzera italiana (SUPSI)

Dipartimento delle Tecnologie Innovative

Istituto dei sistemi e delle tecnologie di produzione sostenibile

Polo universitario Lugano – Campus Est, Via la Santa 1

CH-6962 Lugano-Viganello

T +41 (0)58 666 66 81

sps@supsi.ch

www.supsi.ch/dti

II. Purposes of data processing

Personal data are processed to the extent of what is necessary for:

First purpose: Enabling the visit of the website by visitors, improving their experience and elaborating statistics

Second purpose: Sending the DENiM newsletter to visitors who expressly asked to receive it

Third purpose: Registering visitors who expressly asked to become informed stakeholder or involved stakeholder through the “Join the community” page and

sending them information and suggestions of participation to the project activities

Fourth purpose: Sending information on the DENiM project to visitors who expressly asked to receive them through the contact page

Fifth purpose: comply with obligations imposed by law leg. to law enforcement agencies)

Personal data are collected when you are navigating through the website and when you are asking to receive the

DENiM newsletters or updates on the DENiM project or to join the community as an informed stakeholder or an involved stakeholder or information on the

DENiM project.

Personal data may be collected and processed when registering for

conferences/trainings/workshops/events, etc, answering surveys, subscribing to newsletters and updates on the project, downloading documents, or using

any collaborative or interactive tool available on the website.

Data will be processed with the aim of answering your requests and keeping administrative records up to date.

You are free to unsubscribe to the newsletter freely at any time.

III. Legal basis for processing personal data

Usual legal basis for processing of personal data in this context are:

Article 6.1 (a) when data subjects (visitors) have consent to the processing of their personal data for one or more specific purposes

Article 6.1 (c) when data processing is necessary for compliance with a legal obligation to which the controller is subject

Article 6.1 (f) when data processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party,

except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data

in particular where the data subject is a child.

Normally, we do not process special categories of personal data.

The legitimate interests pursued are the delivery of the best possible experience when navigating through the website and the promotion of DENiM activities.

It is here the normal legal basis for data processing.

Cookies which are not technically necessary for navigating our website will require your consent.

IV. Categories of processed personal data

Each time the website is accessed and visited, it automatically collects and processes data and information from the system of the accessing

computer such as:

-Internet protocol

-IP address (statistical purpose)

-URL of the website

-Date and time of access

-Browser type and operating system

-the page visited

-amount of transferred data

-access status

-duration and frequency of use

-Cookies (placed on users’ computers)

-Personal data processed when completing on-line forms (contact, information request, etc.)

-Personal data processed for subscribing to the newsletter and for sending the newsletter

The legitimate interest pursued by the data controller is the legal basis for these data processing.

Data are stored in log files.

V. COOKIES

A “cookie” is a piece of information, usually small and identified by a name, that may be sent to your browser by a web site to which you are connecting.

Your web browser will store it for a period of time, and send it back to the web server each time you log in again.

Cookies have many uses: they can be used to memorize your customer ID with a merchant site, the current contents of your shopping cart,

an ID that allows us to track your navigation for statistical or advertising purposes, etc.

The website uses cookies to analyze the website’s audience (such as the number of pages viewed, what region of the world their visitors are from,

the number of visits to the site, and the activity of visitors to the site and how often they return).

IP addresses are also collected as part of the sites traffic analysis because it allows to determine what region of the world the user is located in,

but we do not identify individual visitors.

We use the open-source MATOMO platform to analyze the sites audience and how it is accessed.

This data is processed internally and is not shared with any third parties.

Cookies are kept during: 30 days

You can delete cookies via your browser settings:

-Firefox: via the ‘options’ button, then ‘privacy and security’

-Google Chrome: via the option ‘more tools’ then ‘delete browsing data.

– Microsoft Edge: via ‘settings’, then ‘privacy and security, option ‘delete browsing data

VI. Hosting of the website

The website is hosted by Hostpoint SA, Neue Jonastrasse 60, 8640, Rapperswil-Jona, Switzerland

The data is hosted by a service provider (subcontractor) that offers all guarantees in terms of security and confidentiality;

The data is hosted on the territory of Switzerland;

Access to the data is strictly limited to persons authorised to access and process them;

these persons are subject to the rules on professional secrecy;

The computer equipment is protected in accordance with the state of the art in terms of computer security (firewall, updated antivirus, etc.).

VII. Recipients of personal data

We share some of the collected personal data with our hosting service provider and other technical providers and solely to the extent necessary for the

technical operation of the Website.

If these providers are located outside the EA, we will ensure that they treat your personal data with the same protection as we do.

Some personal data are sent to MATOMO Analytics for monitoring website statistics such as number of accesses, location access, user actions (i.e. downloads,

clicks, pages view, out links, searches).

VIII. Storing duration of personal data

Personal data are deleted as soon as the purpose of the processing is achieved.

Longer data retention may occur when required by law and for liability and archiving

purposes.

IP address are stored for the duration of the session.

Logfiles are stored to ensure the functionality of the Services.

Data are processed to optimize the website and to ensure the security of our system.

Evaluation of the data for marketing purposes does occur. Statistical evaluation of datasets takes place.

To analyze visit metrics of our websites, we collect information from your visits, by registering the IP address or protocol of your device.

When you access any of our web pages, your IP address is automatically stored for the purpose of collecting this information purely for statistical purposes.

As a rule, data analysis is done in anonymous way as much as possible.

After, IP address and log files are completely deleted, unless provided otherwise by law.

IX. Data subject’s rights

Visitors are entitled to exercise the following rights:

-Right to request access to personal data related to them;

-Right to request rectification or deletion of personal data related to them;

-Right to request the limitation of the processing of personal data related to them;

-Right to object to the processing of personal data related to them;

-Right to data portability;

-Right to withdraw consent to the processing of personal data related to them;

-Right to lodge a complaint with the supervisory authorities;

-Right to seek redress;

-Right to object to the processing of their personal data for direct marketing purposes.

To exercise your rights, please contact SUPSI:

Scuola universitaria professionale della Svizzera italiana (SUPSI)

Dipartimento delle Tecnologie Innovative

Istituto dei sistemi e delle tecnologie di produzione sostenibile

Polo universitario Lugano – Campus Est, Via la Santa 1

CH-6962 Lugano-Viganello

T +41 (0)58 666 66 81

sps@supsi.ch

www.supsi.ch/dti