ICOS ERIC Privacy Policy, website users

Last updated: 30 July 2018

This privacy policy can also be accessed as PDF document.

Scope

This policy describes how we, ICOS ERIC, use your personal data when you visit the ICOS ERIC website www.icos-ri.eu or the ICOS Carbon Portal website www.icos-cp.eu. ICOS Central Facilities and National Networks run and maintain their own websites. Their domain names are usually www.icos-name.country or www.icos-country.eu. This policy doesn’t apply to those websites.

Who is responsible for my data?

ICOS ERIC is the data controller. That means we are responsible for collecting your data and looking after it.

What data is used?

We ask for your email address when logging into the Carbon Portal, when submitting a reference to BibBase, when subscribing to our newsletter, and in the feedback form. These functions can’t be used without providing an email address. Your email address is erased when it no longer serves a purpose, for example after unsubscribing from our newsletter. Processing is based on your consent.
You have the option to fill out contact information and ORCID id for your public Carbon Portal profile. Providing information is fully voluntary. It’s used for contacting you, and to record your ICOS-related publications to the ICOS publication list. It’s also used to update your ORCID profile with your contributed data, and usage and citation statistics of this data. For ORCID’s privacy policy, please see here: https://orcid.org/footer/privacy-policy. Year of birth and gender are also voluntary information, only used for statistical purposes. Carbon Portal profile information is stored until you delete your account. Processing is based on your consent.
Your IP address is recorded when downloading data from the Carbon Portal. We use IP addresses to record unique downloads over time and country. Processing is based on our legitimate interest in analyzing the spread of ICOS RI data over time.
A cookie is a tiny file that is created on your computer upon visiting a website, which then communicates with websites. We use a cookie containing your Carbon Portal login status and expiry time. Denying this cookie necessarily prevents Carbon Portal login. This cookie expires after approximately a day. Processing is based on your consent.
We use Google Analytics to monitor and analyze the use of our site. It uses cookies to distinguish you from other site visitors. For Google’s privacy policy, please see here: https://policies.google.com/privacy. Denying Analytics cookies doesn’t affect site use, and they expire after two years since last site visit. Processing is based on your consent.

Who gets my data?

Personal data can only be used for the purpose it was first collected for. Carbon Portal profile data and reference submissions are handled in accordance with scientific customs.
We won’t transfer your personal information outside of ICOS Research Infrastructure unless wotherwise mentioned. For information about the infrastructure, please see here: https://www.icos-ri.eu/icos-research-infrastructure.
Google transfers its Analytics data to the United States. Google is covered by the EU-US Privacy Shield Framework. The framework protects the fundamental rights of anyone in the EU whose personal data is transferred to the United States for commercial purposes. The European Commission has also issued a decision declaring the United States as ensuring an adequate level of personal data protection.

Data security

Our websites and services use SSL encryption. All services run through a reverse proxy, which only allows the programmatic access built into the application programming interface of the services. The servers are only accessible for admins from a select number of machines with fixed IP addresses from Lund University, Sweden. ICOS ERIC runs its own dedicated two servers through Carbon Portal, which are physically located at LUNARC computing center at Lund University. The university doesn’t have access to the servers.

What rights do I have?

Unconditional rights

You have these rights by law.
Access to the personal data. You have the right to a copy of your processed data, so you can check the data itself.
Rectification. You have the right to have incorrect data corrected.
Complaint. You have the right to lodge a complaint with a supervisory authority. Contact Finnish Data Protection Ombudsman here: https://tietosuoja.fi/en/contact-information.
Object to processing. Where processing data is based on our legitimate interests, you have the right to object to the processing. The processing stops until we demonstrate compelling legitimate grounds for the processing. A document assessing our legitimate interests and their relationship with you will be provided to you.

Conditional rights

These rights apply if certain conditions are met.
Erasure. You might have the right to have your data removed from our storage, for example when you withdraw consent for processing. If there are grounds for erasure, we will take reasonable steps to have it erased from third party databases as well.
Restriction of processing. You might have the right to have us restrict the processing of your data, for example when we don’t need the data anymore, but you require it for a legal claim.
Portability. You have the right to have your data transmitted to another controller without hindrance from ICOS ERIC when the processing is based on your consent or a contract between you and us.

Exercising your rights

If you have a question regarding our privacy policy, wish to exercise any of your rights, or feel dissatisfaction with our use of your data, please contact dpo@icos-ri.eu. We will perform our duties without undue delay within one month of your request. That period may be extended by two further months where necessary, considering the complexity and number of the requests.

For further information about your rights and exercising them, please see here: https://tietosuoja.fi/en/know-your-rights.

Changes to this policy

We will inform you of any material changes to this policy with a notice on our website.

Fokke and Sukke guarantee your privacy cartoon