Privacy Policy

Privacy Policy

I. General data

In this privacy policy the measures that have been implied to protect your privacy are mentioned. The protection of the personal privacy of the Online E-Learning Platform ERIS Institute (afterwards mentioned as “the Platform”) users will be addressed in this privacy policy.

This privacy policy will inform you of which person related data will be collected and/or stored when using the applications, the reasons why we do this and which control measurements are available to you.

It is important to ERIS Institute that the terms that are applied by the legislator are correct and explained in an understandable fashion, therefore the different terms used in this privacy policy are explained more elaborately.

a) The responsible for data processing

What/who is the responsible for data processing?

The responsible for data processing is the person of the institution that is responsible for the collection of the personal data when visiting the website and when filling in the forms on the website.

It is of the utmost importance that we are, as controller of the processing, always reachable for possible questions and remarks regarding the privacy policy.

Therefore, ERIS Institute has assigned an Official for Data Protection or Data Protection Officer.

Please find below our information:

  • Controller of processing: ERIS Institute
  • Department: Data Protection
  • Address: C/Sant Quintí, 89 08027
  • City: Barcelona
  • E-mail: dpd@santpau.cat

  • Telephone: +34 93 553 76 85

Acknowledgement and adjustment

By using the Platform, the associated applications and filling in of the forms you acknowledge to have taken cognisance of the provisions and measures in this privacy policy.

ERIS Institute reserves the right to adjust its policy at any time, provided that the users are notified via the website or via e-mail. The adjustments become effective after publication.

b) Applicable law

The processing of personal data within ERIS Institute is subject to the European regulation 2016/679 of the European Parliament and the Counsil of April 27th 2016 concerning the protection of the natural person in relation to the processing of personal data and concerning the free traffic of these data, as well as the law of July 30th 2018 concerning the protection of the natural person with regards to the processing of personal data.

II. Collection of personal data

a) Definition personal data

Under the name of ‘personal data’ we mean all data or information (e.g. name, phone number, e-mail address, birth date, enterprise number …) that is related to an identified or identifiable natural person. By the broad formulation a lot of data are concidered personal data.

b) The use of our Platform and applications

By using our website/Platform a number of personal data will be collected in various ways:

  • The personal data will be shared by the user himself/herself.
  • The personal data we receive by using our services.

The different ways of collecting the personal data are subjected to specific provisions and conditions in the privacy legislation. That is why it is important that the differences between before mentioned ways are explained.

The personal data are communicated by the person himself/herself

With every login and authentication procedure you are asked to provide personal data (user name, password) to gain access to the Platform.

In addition, you can be asked to provide personal identification data, an image of yourself, the function, qualifications, … through our online services. This is necessary to create your profile on the Platform, so you can appeal upon the services provided by us (subscription for courses, participation in tests and evaluations, publication of course results and the search for other participants on the Platform). Before mentioned data need to be provided to us by yourself.

Dependent on the application, below mentioned categories of personal data can be requested:

Type of personal data

Description of personal data

Security

Password

Personal identification data

Name, e-mail address, title

Professional experience

Academic and professional interests, disciplines, specialities

Professional competence

Diploma’s, certificates, number of executed operations

Media use

LinkedIn profile, Twitter profile, PubMed en ResearchGate

Publications

Books, articles, reports, audiovisual imagery

Current position

Employer, place of employment, title


The data that are provided by you are considered correct and complete. When sharing incorrect data, we are reserved the right to deny you, as user, the access to the Platform and its services.

Automated collection of personal data

By visiting our website various personal and other data are collected automatically using cookies and tracking technologies:

Type of personal data

Description of personal data

Electronical identification data

IP-addresses, cookies, time of connection…

Electronical localization data

Estimated location, setting…

Surfing behaviour

What pages are being looked at, how long a page is being looked at, clicks, hits….

Through which channel you are visiting our website

Search terms, through which webpages our website is being visited

Which device is being used

Pc, smartphone, tablet…

Which system software is being used

Windows, Android, Apple…

Which browser is being used

IE, Mozilla, Chrome…


With this automated collection your direct identification data are not being registered or kept track of.

Conform the Telecommunication Law we will of course, if needed, ask for your explicit consent for the use of cookies and tracking technology.

III. Justifications and purposes of the processing

a) Definition processing

The processing of the personal data concerns all possible operations or a whole of operations, whether or not automated, such as e.g. the collection, the structuring, the saving, the consulting, the updating, the use, the combining, the erasing or the destroying of personal data. ERIS Institute can make use of processors for some of these processes, this concerns natural or legal persons, government agencies, services or other bodies that process personal data under the supervision of ERIS Institute.

b) Execution of the Agreement

Education and training

Before you can subscribe to our services you have to make a profile on the Platform prior to the subscription. When setting up this profile various personal data will be requested, as previously mentioned in point II.b.1, that are useful for the organization of the education, courses, evaluations and tests. After completion of your online profile you will be asked by ERIS Institute to do some tests and excercises, before and after the trainings, so that we can share with you the data concerning your personal growth and development after participating in our trainings.

Customer management

By making an agreement between parties, various data can be requested and/or collected that are necessary to conclude the agreement.

Without these data there is no possibility to make any agreement, therefore all data provided by you are required to be correct and complete.

When sharing incorrect data we are reserved the right to break the agreement and we will make a reservation for damages.

Overview of the processing

The below table shows the processing processes based on the legal basis of “execution of the agreement” and indicate which personal data is being processed.

Processing of personal data

Type of personal data

Description of personal data

Purpose of processing

Platform – Pupil administration

Security

Password

Authentication en identification

Platform – Pupil administration

Personal identification data

Name, e-mail address, title

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Platform – Pupil administration

Professional experience

Academic and professional interests, disciplines, specialities

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Platform – Pupil administration

Professional competence

Diploma’s, certificates, number of executed robotic surgeries

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Platform – Pupil administration

Media use

LinkedIn profile, Twitter profile, PubMed en ResearchGate

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Platform – Pupil administration

PublicationsBooks, articles, reports, audiovisual imagery

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Platform – Pupil administration

Current position

Employer, place of employment, title

Set-up of an online profile with the aim of interprofessional contact, participation in courses, spreading expertise

Evaluation and tests

Personal identification data

Name, e-mail address, title

Tests of participants, communicating personal progress

Evaluation and tests

Evaluation

Evaluation of the performance, possibilities

Tests of participants, communicating personal progress

Courses

Personal identification data

Telephone number

Follow-up of the booking

Courses

Lifestyle habits

Preferences concerning composition of meals

Provision of currect meals

Customer management

Personal identification data

Name, address, e-mail, telephone number…

The administration of the client management and the facturation

Customer management

Identification data, other than the national insurance number, issued by the governmentVAT-number

The administration of the client management and the facturation

c) Legitimate interest

Adjustment and regulation of participants’ training

As member of the Platform you have the possibility to fill in the “Participant Profile”, in which you are asked to provide various professional data that demonstrate your experience. These data are linked to your profile, are processed by ERIS Institute, but are not visible to third persons or other members of the Platform. The collected information will be used in a confidential way by ERIS Institute. Based on the collected data, ERIS Institute can develop her courses as well as validate the best trainings for individual participants.

Direct Marketing

To keep you informed, ERIS Institute will keep you in the loop of new courses, trainings and events that could interest you as member, based on your data. In case you are no longer interested to be informed by us, you can unsubscribe, non-bindingly, at all times.

Overview of the processes

Processing of personal data

Type of personal data

Description of personal data

Purpose of processing

Development of courses

Personal identification data

Name, e-mail address, title

Adjustment and regulation of the training to the profile of the participants

Development of courses

Professional experience

Academic and professional interests, disciplines, specialities

Adjustment and regulation of the training to the profile of the participants

Development of courses

Medical data

Relevant medical conditions

Adjustment and regulation of the training to the profile of the participants

Direct marketing

Personal identification data

Name, e-mail address

Sending of newsletters, offering of courses

d) Consent of the subject

Filling in the participant form

As a member of the Platform you have the possibility to fill in the “Participant Profile” so we can take this into account at the evaluation.

These data are linked to your profile, are being processed by ERIS Institute, but are not visible to third persons or other members of the Platform.

The collected information will be used in a confidential manner by ERIS Institute.

Based on the collected data, ERIS Institute can develop her courses as well as validate the best trainings for individual participants.

An overview of the processes

Processing of personal data

Type of personal data

Description of personal data

Purpose of processing

Developing courses

Medical data

Relevant medical conditions

Adjustment and regulation of the training to the profile of the participants

IV. Quality and balancing of interests

As processing manager, we watch over the quality and legality of the personal data that is being collected and processed. We take every necessary measure to delete or improve the data that is inaccurate or incomplete.

When collecting and processing the available personal data we only collect and process the personal data that is useful for reaching our processing purposes. No excessive data nor data that “might someday” be applicable will be collected or processed by us.

V. Retention period of personal data

The personal data will be collected for the entire period that is necessary for the accomplishment of our processing purposes. A longer retention period or further processing than necessary for reaching our goals will not be implemented.

Below you will find a subdivision of the activities to explain these terms more elaborately.

Processing activity

Retention period

Date of commencement term

Legal basis

Platform – Participant administration

20 years

From January 1st of the year that follows on the last subscription for a training

Contractually

Evaluation and tests20 yearsFrom January 1st of the year that follows on the last subscription for a trainingContractually

Trainings

20 years

From January 1st of the year that follows on the last subscription for a training

Contractually

Customer management

7 years

From January 1st following the facturation date

Art. 354 WIB92

Development trainings

Indefinate

 

Anonymous data

Direct marketing20 yearsFrom January 1st of the year following the last subscription for a trainingContractually


The personal data are collected according to the term as described above, to be deleted or at least anonymized afterwards, after which identification of the subject is no longer possible, unless this is necessary for the execution of an ongoing agreement or in the context of a legal obligation, judicial or police investigation.

VI. Transmission of personal data

ERIS Institute can forward your personal data to others. For this a distinction must be made between processors and other third persons (not processors).

The transmission of your personal data to processors.

The transmission is necessary for the achievement of our goals, namely for the proper functioning of the website and systems.

The transmission is necessary if there is a legal obligation to transmit your personal data or on request of judiciary authorities or police forces

The transmission of anonymized data for scientific purposes

The results of the tests, participant profile and the follow up questionnaires, which were obtained before and after participating in the courses, are anonymized and afterwards sent to centers for scientific research with the aim of publications of scientific articles, comparative research, …

Transmission to third persons

Upon your request your data can be transmitted to third persons, such as hotels and taxi companies.

VII. Rights of the subject

a) General

According to the legal provisions, ERIS Institute is as data controller responsible to inform you thoroughly in regards to the collection and processing of personal data. This privacy policy hereby applies as personal notification.

Depending on the selected legal basis for the processing certain rights can be executed. In order to offer a clear overview, a schematic summary of your rights has been portrayed.

Processing ground

Rights of the subject

Necessary for the execution of an agreement

Right to view

Necessary for the execution of an agreement

Right to rectify

Necessary for the execution of an agreement

Right to object

 

Necessary for the execution of an agreement

Right to restriction of the processing

Necessary for the execution of an agreement

Right to be forgotten

Necessary for the execution of an agreement

Right of data portability

Necessary for the execution of an agreement

Right to file a complaint

Necessity to execute the agreement

Right to view

Necessity to execute the agreement

Right to rectify

Necessity to execute the agreement

Right to object

Necessity to execute the agreement

Right to be forgotten

Necessity to execute the agreement

Right to restrict the processing

Necessity to execute the agreementRight to file a complaint

Permission of the subject

Right to view

Permission of the subject

Right to rectify

Permission of the subject

Right to object

Permission of the subject

Right to be forgotten

Permission of the subject

Right to restrict the processing

Permission of the subject

Right to file a complaint

b) Right to view

You have the right to obtain inclusive from ERIS Institute on whether or not your personal data will be processed. If your personal data are processed you can have access to your data in all our files with additional information about the processing purposes, the categories of personal data, possible receivers of your personal data, the retention period, complaints procedure, …

Furthermore, you can request a copy of your personal data, without additional administrative costs. Mind you, when you request multiple copies ERIS Institute will charge you a fair compensation.

You can consult the procedure to exercise this right in point g.

c) Right to rectify

As subject you have the right to rectify all incomplete or incorrect personal data that relate to your person.

With the term “rectify” it is meant that you can have wrong personal data

changed or even removed.

The correctness and the quality of your personal data is of great importance for the achievement of our goals.

You can consult the procedure to exercise this right in point g.

d) Right to object

You have the right to object. The legal provisions provide a general right to object as well as an objection in regards to direct marketing.

Therefore you have, as user/subject, a general right to object.

General right to object:

You can object against the processing of your personal data when the data are incomplete in accordance to the processing purposes or not submitted or when the data of which the registration, the communication or the storage are forbidden or when the data are saved longer than the specified storing time.

When your personal data are legitimately processed you can object against processing, conform the legal provisions of the privacy legislation, due to serious and justified reasons that are connected to your specific situation.

You are required to prove serious and justified reasons to prevent further processing.

Right to object on the subject of direct marketing:

You can object against processing of your personal data for direct marketing purposes, free of charge and without any motivation.

You can consult the procedure to exercise this right in point g.

e) Right to be forgotten

Without unreasonable delay you can have your personal data deleted. This is on the condition that:

The personal data are no longer necessary for the purposes for which they were collected or processed;

You withdraw the permission for specific purposes;

The personal data are unlawfully processed;

The personal data must be erased to meet the legal obligation; You can consult the procedure to exercise this right in point g.

f) Right to receive personal data

According to the legal provisions of the AVG the subject has the right to request his or her personal data, which are in the possession of ERIS Institute, in a structured, common and machine readable way.

This can be requested for personal use as well as for transmission to a third processing responsible other than ERIS Institute.

If it is technically possible for us, you can request the electronical transmission of your personal data to an other enterprise.

You can consult the procedure to exercise this right in point g.

g) Procedure to exercise rights

When you wish to exercise the before mentioned rights you are required to send your request (motivated or not) accompanied by proof of your identity, more specifically a copy of the front side of your ID, by mail or e-mail to:

ERIS Institute

C/Sant Quintí, 89 | 08025 Barcelona

Phone: +34 93 553 70 99 | Email: info@eris-eu.eu 

After receival of your request we will act as fast as possible and in any case within the month.

Depending on the complexity of the request, this term can be extended with two months. You are notified when such an extension takes place.