This notice sets out the Privacy Policy in compliance with the obligations arising from national legislation (Legislative Decree No. 196 of 30 June 2003, Code regarding the protection of personal data) and EU legislation (European General Data Protection Regulation No. 2016/679, GDPR) and subsequent amendments. This website respects and protects the privacy of visitors and users, making every possible and proportionate effort not to infringe upon users’ rights. The purpose of this privacy policy is to provide maximum transparency regarding the information the website collects and how it is used. This Privacy Policy applies exclusively to the online activities of this website and is valid for visitors/users of the site. It does not apply to information collected through channels other than this website.
This policy describes how the CESISP website is managed in relation to the processing of personal data of users who visit it, who choose to register and who subscribe to online services.
Visiting the CESISP website may involve the processing of data relating to identified or identifiable individuals (see the following section “Types of Data Processed”).
Registration on the website and subscription to online services give rise to the processing of personal data relating to natural or legal persons.
- DATA CONTROLLER
The data controller is CESISP – Centre for Studies in Economics and Regulation of Services, Industry and the Public Sector at the University of Milan-Bicocca, with its registered office at Piazza dell’Ateneo Nuovo 1, 20126 Milan
- DATA PROCESSOR
Professor Beccarello has been appointed as data processor pursuant to Article 29 of the Personal Data Protection Code.
- PLACE OF DATA PROCESSING
Processing relating to the website’s services takes place primarily at the CESISP headquarters and is carried out by identified staff specifically appointed for the specific purposes of the services requested and subscribed to.
For the processing operations in question, the University may engage the assistance of external companies, consultants, consortia, and software and service providers operating, through identified and authorised personnel, within the scope of the intended purposes and in such a way as to ensure the utmost security and confidentiality of the data.
- TYPES OF DATA PROCESSED
4.1 Website browsing
The IT systems and application procedures used to operate the CESISP website acquire, during their normal operation, certain personal data whose transmission is implicit in the use of Internet communication protocols. This information is not collected to be associated with identified data subjects but, by its nature and through association with data held by third parties, may allow for the identification of users. This category includes, for example, the IP addresses and domain names of the systems used by users to connect to the website. This data is used to obtain anonymous statistical information on the use of the website and to check its correct functioning; it may also be used to ascertain liability in the event of computer crimes against the website itself.
Data may only be disclosed following a request from the judicial authorities in accordance with the law.
4.2 Use of cookies
Cookies are small text strings that a website sends to the user’s browser (e.g. Internet Explorer, Mozilla Firefox or Google Chrome), which stores them and then transmits them back to the same website on the user’s next visit.
The CESISP website uses cookies. The cookies sent by the website are used exclusively for technical reasons, such as to enable authentication to restricted areas or to store the user’s temporary preferences.
The cookies sent by the website are not used in any way for visitor profiling and do not allow the collection of personal information relating to users.
Third-party cookies
The website uses third-party content (via resource embedding techniques); it is therefore possible that, whilst visiting the website, other cookies – both technical and those capable of profiling the user – may be sent by these third parties to the user’s device. The privacy policy and consent to use are the responsibility of the providers of these services; below is a list of the services used and a link to the relevant privacy policies and information regarding the use of cookies from their servers. Google and YouTube (privacy policy: https://www.google.it/intl/it/policies/privacy/ )
Refusing cookies via device settings
Users visiting the site may refuse all or some of the cookies sent by both the site and third-party sites by adjusting the settings available in their browser. For specific instructions regarding your browser, please consult the help section provided with the software or visit the relevant manufacturer’s website.
Disabling cookies may prevent certain services from functioning correctly or prevent access to certain content.
Disable all cookies.
You can refuse consent to the use of cookies by selecting the appropriate setting in your browser.
Below are links explaining how to disable cookies for the most popular browsers (for other browsers you may use, we suggest looking for this option in the software’s help section).
4. Opera
5. Apple Safari
To disable third-party cookies:
Third-party cookies can also be disabled using the methods described in the respective privacy policies and/or made available directly by the third-party company responsible for such processing. To disable only Google Analytics cookies, you can use the Opt-Out add-on provided by Google for major browsers, available at the following address: https://tools.google.com/dlpage/gaoptout?hl=it
To delete cookies already stored on your device:
Even if you withdraw your consent to the use of third-party cookies, cookies may have been stored on your device prior to such withdrawal. For technical reasons, it is not possible to delete these cookies; however, the User’s browser allows them to be deleted via the privacy settings. The browser options include the “Clear browsing data” option, which can be used to delete cookies, site data and plug-ins.
- METHODS AND PURPOSES OF PROCESSING
Personal data is processed using automated tools for the time strictly necessary to achieve the purposes for which it was collected. Specific security measures are observed to prevent data loss, unlawful or incorrect use, and unauthorised access. Personal data provided by the data subject via the website will be processed for the following purposes:
- Research and statistical analysis of aggregated or anonymous data, without the possibility of identifying the user, aimed at measuring the functioning of the website and assessing its usability and interest;
- Completion of forms for the collection of data for the receipt of newsletters or general communications via email;
- Purposes related to the online provision of University services.
This website uses log files in which information collected automatically during user visits is stored. The information collected may include the following:
- Internet Protocol (IP) address;
- Browser type and device parameters used to connect to the website;
- Date and time of visit;
- The web page from which the visitor arrived (referrer) and the page they exited to.
The aforementioned information is processed automatically and anonymously in order to verify the proper functioning of the website and for security reasons; it may be used, in accordance with applicable laws, to block attempts to damage the website itself or to cause harm to other users, or in any case to prevent harmful or criminal activities. Where the website allows comments to be posted, or in the case of specific services requested by the User, the website automatically detects and records certain identifying data of the User, including their email address. Such data is deemed to have been voluntarily provided by the User at the time of requesting the service. By posting a comment or other information, the User confirms that they have read the privacy policy and, in particular, consents to the content posted being freely disseminated, including to third parties. Any information that website Users choose to make public via the services and tools made available to them is provided by the User knowingly and voluntarily, thereby exempting this website from any liability regarding potential breaches of the law. It is the User’s responsibility to verify that they have the necessary permissions to enter personal data of third parties or content protected by national and international regulations. The data collected by the website during its operation is used exclusively for the purposes indicated above and retained for the time strictly necessary to carry out the specified activities.
- RIGHTS OF DATA SUBJECTS
Pursuant to European Regulation 2016/679 (GDPR) and national legislation, the User may, in accordance with the procedures and within the limits provided for by current legislation, exercise the following rights:
1. Access their personal data;
2. Obtain the rectification or erasure of such data or the restriction of its processing;
3. Data portability (a right applicable only to data in electronic format), as governed by Article 20 of EU Regulation 2016/679;
4. To object to the processing;
5. To lodge a complaint with the supervisory authority (Data Protection Authority).
Requests should be addressed to the Data Controller.
RIGHTS REGARDING AUTOMATED DECISION-MAKING PROCESSES
‘Automated’ decisions are those that may be based on data provided directly by the data subjects (e.g. via a questionnaire), or obtained through the observation of individuals (such as location data collected via an app); automated decision-making must not affect the rights or legitimate interests of individuals and must not have a significant impact on the further and distinct expectations of individuals.
The website does NOT use automated decision-making processes.
HOW TO EXERCISE YOUR RIGHTS
How to exercise your rights
To exercise the rights set out above, the User may contact the Data Controller at the following email addresses: cesisp ‘at’ unimib.it, rettorato “at” unimib.it or PEC ateneo.bicocca ‘at’pec.unimib.it.
The Data Controller is required to respond within one month of receiving the request; this period may be extended to three months in the event of a particularly complex request.
UPDATE
This Privacy Policy is updated as of 17/02/2024
Further information is availab
