NEANIAS Atmospheric Flux Densities Service

Privacy Policy

1. Introduction 

The software service NEANIAS Atmospheric Flux Densities Service (“Service”) is operated by Αthena-Research and Innovation Center in Information, Communication and Knowledge Technologies - Athena RC (“Provider”). Elements of the Service (“Service Elements”), be it technology, algorithms, documents, data, other services, processes and other resources, are currently provided by third-parties (“Other Providers”).

The Provider is a Research and Innovation Center with full name Athena-Research and Innovation Center in Information, Communication and Knowledge Technologies, with its headquarters located at Artemidos 6 & Epidavrou, 15125, Marousi, Attiki, Greece.

Specific Service Elements have been produced and maintained with the co-funding of the European Commission, under NEANIAS project [GA 863448]. Service Elements are the sole responsibility of the Provider. Nothing in the Service shall be considered as reflecting the views of the European Commission.

Protecting your personal data is very important to us. Our Privacy Policy is intended to help you understand why we collect your personal information and how we use it. It provides detailed information about when and why we collect your personal information, how we use and process it, how long we keep it, and finally, under what terms we can share it with others.

2. Scope

This Privacy Policy applies to all of you who access and use our Service.

This policy applies solely to personal data and information that the Service collects through its usage or through any electronic communication of the User with the Provider, as indicated on the Service (herein referred to as “Personal Data”).

We may also collect information from you in other ways, including information collected during technical support contacts. If we provide a separate or supplemental notice when we collect personal data from you, that notice will control to the extent of any conflict.

It does not apply to any website of third-party services that the Service may link to. The Service does not endorse, nor is responsible for the content of these websites or third-party services, or their policies or practices.

3. Information Collected

The Service manages different types of data, all in compliance with the current European legislation on Data Protection. Any Data concerning the User is collected to allow the Provider to provide the services.

Required Data

Personal Data

The provision of the Service requires that certain pieces of personally identifiable information are processed. Personal data of yours we process:

Registration information

The Service may utilize services of unaffiliated third-party providers for providing additional features. Those may require that these providers have access to Personal Data such as name, affiliation and email address. These vendors may also provide the Service with this information, so that the Service can keep track of User’s linking to those third-party services. In this case, the information that the User may provide as part of this registration will be subject to both this Privacy Policy and the corresponding statement of the third-party Service.

Operational data

Services and infrastructure management software automatically gather general information from Users, such as IP address, computer type, screen resolution, OS version, domain name, location, date and time of the visit, page(s) visited, time spent on a page, origin from where the User may come into the service, action taken by the user when redirected outside the Service area etc. Some of this information is provided directly by the User's client software (e.g. Web Browser) while the remainder is obtained through cookies and tracking technologies.

Cookies

Any Cookies or other tracking tools used by this Service, or by Other Providers of third-party services used by or through this Service, serve the purpose of providing the service required by the User, in addition to any other purposes described in the present document.

4. Children

The Service is not intended for children.

The Service does not collect knowingly any Personal Data from or about children.

5. Use of Personal Data

The Personal Data required by our Service are processed for the following purposes:

Our Service guarantees that your personal data will not be used for purposes other than those set forth in this policy, without prior notice and where your approval is required.

The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated.

The Provider considers User Personal Data as an asset that is not for sale and will never sell User Personal Data to any third-party.

6. Recipients of personal data

Access to personal data and transaction information is only authorized by employees, affiliates and third parties who process the above data at the Provider’s discretion and only when and to the extent necessary for the above purposes. Personal data may only be transmitted, for the purposes of the above processing, to specific recipients who are employees, and generally affiliates as well as third parties affiliated with the Provider. In addition, the Provider may, without prior notice, disclose your information to the competent judicial and/or administrative authorities to the extent required by applicable laws and regulations, or by judicial decision and/or administrative act.

The Provider makes every effort to control and evaluate when selecting its affiliates to whom it transmits the personal data of those concerned. There is a written agreement between the Provider and any third party, according to which the processing of personal data is carried out under the control of the Provider and only on its order and is subject to the same data protection policy.

7. Interaction with Identity Providers, Social Networks and External Platforms

The Service allows the User to interact with Identity Providers or other external platforms (herein referred to as “third-party Platform”), directly from the user interface of the Service. The information acquired by the Service through this interaction is always subject to the User's privacy settings related to the third-party Platform.

8. Data retention time

The time period for storing data is decided on the basis of the following specific criteria, as appropriate:

9. Your Rights and Choices

As defined in the Regulation (EU) 2016/679 (General Data Protection Regulation), you (as the data subject) have the following Rights:

Before we are able to provide you with any information or correct any inaccuracies, we may ask you to verify your identity and/or provide other details to help us respond to your request.

The Provider reserves the right not to respond to requests generated through third-party applications or automated processes without direct validation of the requests by data subjects using the resources provided by the Service for the exercise of these rights as described in this Policy.

10. Data security

The Provider takes care to guard the security of your personal data. We apply appropriate physical, technical and organizational measures that are reasonably designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, and against all other unlawful forms of processing. We maintain a security program that is proportionate to the risks associated with the processing.

11. Location of Personal Data Storage

The Service is provided via its project managed instance, whose servers are located in Greece and Italy, and provided by a multitude of Providers: CITE – Communication & Information Technologies Experts SA (GR), GARR - Gruppo per l'Armonizzazione delle Reti della Ricerca (IT) and NKUA - National Kapodistrian University of Athens (GR).

The Data is processed at the infrastructures of the aforementioned providers and in any other places where the parties involved in the processing are located. For further information, please contact the Provider.

12. Disclosure of Personal Data to Third-Parties

The Provider processes Personal Data in a proper manner and takes appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction of them.

In addition to the Provider, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of the Service (administration, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the Provider. Specifically:

The updated list of these parties may be requested from the Provider at any time.

As the Service relies on a list of distributed services, in the process of supporting a user request we might have to share Personal Data with Other Providers.

13. Transfer of Data outside EU

We store personal data on servers located in the European Economic Area (EEA). Each organization is required to safeguard personal data in accordance with our contractual obligations and data protection legislation.

14. Law enforcement - compliance

The Provider may use or disclose Personal Data to any third-party (a) if required to do so by law; (b) to comply with legal processes or respond to requests from governmental or public authorities; (c) to prevent, investigate, detect, or prosecute criminal offenses or attacks on the technical integrity of the Service or network; (d) to enforce Terms and Conditions; or (e) to protect the rights, privacy, property, business, or safety of the Provider, its business partners, employees, members, Service Users, or the public. Unless prohibited by applicable law, the Provider shall inform the User if a third-party requests access to Personal Data about the User.

15. Policy modification

This privacy policy may be modified. We will make sure to keep you informed of any changes, but in any event we invite you to visit our website regularly, where the most up-to-date Privacy Policy will be posted.

16. Exercise of your Rights, Inquiries, Objections, Complaints

For exercising your rights, or for any questions, comments, objections or complaints, regarding this Privacy Policy or privacy, security or data protection practices applied, please contact the Provider by email via its designated Data Protection Officer at dpo@athena-innovation.gr

We handle your requests with the utmost care to ensure that your rights are protected. For any requests that may require assumption or disclosure of Personal Data, the User will have to demonstrate legitimate grounds for making the respective requests, as well as provide sufficient evident for the identity of the User.

In some cases we may not be able to process your request directly. However, in any event we will inform you of the progress of your request within one month of the submission of your original request.

You always have the right to complain to the “Hellenic Data Protection Authority (www.dpa.gr)”, if you are concerned about how we have processed your personal data.

Effective Date: 10 June 2021