PRIVACY POLICY
The University of Messina undertakes to implement appropriate safeguards for the processing of personal data, in order to ensure and maintain compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation (“GDPR”), and with Legislative Decree no. 196/2003 (“Italian Personal Data Protection Code”) as amended and adapted to the GDPR by Legislative Decree no. 101/2018.
This Privacy and Cookie Policy is addressed to users who access and interact with the website of the MINE 2027 – International Conference on Management of Innovation and Entrepreneurship.
Data Controller
The Data Controller is the University of Messina, in the person of the Rector pro tempore, with registered office at:
University of Messina Piazza Pugliatti 1 98122 Messina, Italy Telephone: 0906768900 Email: rettorato@unime.it PEC: protocollo@pec.unime.it
Data Protection Officer
The Data Protection Officer (“DPO”) is Dr. Daniela Prestipino.
Contact details of the DPO:
Telephone: 0906768355 Email: rpd@unime.it PEC: protezionedati@pec.unime.it
Purposes and legal basis of processing
The processing of personal data associated with the MINE 2027 conference website is connected with the institutional mission of the University of Messina, including teaching, research and third mission activities, as described in the University Statute.
The processing is necessary for the performance of institutional tasks and activities and is carried out in accordance with applicable legislation, respecting human dignity, fundamental rights and freedoms of the persons concerned, including students, University staff, users who interact with the University and stakeholders in general.
As a general rule, the legal basis for processing is Article 6(1)(e) GDPR, namely that processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller. Where applicable, further legal bases provided for by the GDPR, such as consent or legitimate interest, may be specified in relation to specific processing operations.
Personal data may also be processed for institutional information and communication activities relating to the conference, including the publication and dissemination of information on the event, programme, deadlines, venue, participation opportunities and related scientific or organisational initiatives.
Categories of data processed
The website may process personal data relating to identified or identifiable persons.
In particular, the following may be processed:
- data voluntarily provided by users, such as email addresses and other contact details;
- data connected with requests for information sent through the website or through the contact channels made available;
- data generated by interaction with the website;
- data contained in cookies and other tracking tools, as described below;
- traffic data and technical navigation data necessary for the functioning of internet communication protocols.
Personal data are processed in accordance with Article 5 GDPR, lawfully, fairly and transparently, for specified, explicit and legitimate purposes, in compliance with the principles of data minimisation, accuracy and storage limitation, and with the security requirements referred to in Article 32 GDPR.
Recipients of personal data
Recipients of data collected through the website may include, pursuant to Article 28 GDPR, providers of services for the development, provision and operational management of technological platforms, where appointed as processors.
Personal data may also be processed by University staff and authorised persons involved, within the scope of their duties, in the management of the conference website and related institutional communication activities.
Rights of data subjects
Data subjects may exercise the rights provided for in Chapter III of the GDPR, including the right to information and access, the right to obtain a copy of their data, the right to know the origin, purposes, recipients and legal basis of processing, the right to rectification, erasure and restriction of processing, and the right to obtain information on the existence of automated decision-making processes, where applicable.
Data subjects may also object to processing pursuant to Article 21 GDPR and, where processing is based on consent, may withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Data subjects may lodge a complaint with the Italian Supervisory Authority, namely the Garante per la protezione dei dati personali.
To exercise their rights, data subjects may contact the Data Controller or the DPO at the contact details indicated above.
Users are invited to consult this section periodically in order to be informed of updates concerning data protection and related University initiatives.