Privacy Policy

Glossary

Account - the primary means of accessing to the non-public portions of the Online Learning Agreement platform and for using the Services. The term Account includes the Student’s personal profile and is used to identify them as well as to provide them with a variety of administrative tools.

AUTh or Provider - the Aristotle University of Thessaloniki; the largest university in Greece, which main campus is located in the centre of the city of Thessaloniki and covers an area of about 33.4 hectares. It comprises 10 faculties which consist of 40 schools and 1 single-school faculty. AUTh develops and operates Erasmus Dashboard as well as Online Learning Agreement and offers the Services.

DGEAC - the Directorate-General for Education, Youth, Sport and Culture (DG EAC), a Directorate-General of the European Commission. It is responsible of policies in the field of education, youth, culture, languages, and sport. DGEAC is involved in the identification and promotion of the features of Erasmus Dashboard and Online Learning Agreement.

Erasmus Dashboard - an integrated software solution for Supporting HEIs in managing Erasmus+ mobilities operating in their professional activity. Erasmus Dashboard includes the Erasmus Dashboard web site at www.erasmus-dashboard.eu, as well as all web documents (including images, php- and html files), software, hardware, databases, interfaces, connected media, documentation, applications, updates, version upgrades, and other related components or materials that make up or contribute to the features and functionality of Erasmus Dashboard, including any data, documents, works and other materials added by the Provider.

EUF - non-profit foundation European University Foundation - Campus Europae that, in concert with its member universities, has created and owns Erasmus Dashboard as well as Online Learning Agreement, the Erasmus Without Paper Network, and the Erasmus+ App.

GDPR - the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

HEI - Higher Education Institution.

Main Institutional Account – constitutes the reference Account for a given HEI. the holder of this Account has the responsibility over all the Staff Accounts of the relevant institution. 

The Main Institutional Account holder, when acting as a Data Processor for the given HEI is responsible for establishing and maintaining a record of all personal data processing activities. 

The same HEI, also in the person of the holders of the Main Institutional Account and the relevant Staff Accounts, is also required to ensure that any personal data contained in the various Accounts referable to that HEI has been uploaded, processed and/or communicated in full compliance with the GDPR.

Online Learning Agreement - an integrated software solution for supporting students to manage their Erasmus+ mobilities. Online Learning Agreement includes the Online Learning Agreement web site at www.learning-agreement.eu, as well as all web documents (including images, php- and html files), software, hardware, databases, interfaces, connected media, documentation, applications, updates, version upgrades, and other related components or materials that make up or contribute to the features and functionality of the Online Learning Agreement, including any data, documents, works and other materials added by the Provider. Also referred to as OLA. The Online Learning Agreement platform is hosted on the AUTh premises.

Organisation – the entity which accepts/receives a student for traineeship.

Personal Data - any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Processing - any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Services - any services provided or made available by the Provider via the Erasmus Dashboard and the Online Learning Agreement platforms as well as relevant interconnected tools or relating thereto.

Student - a natural person applying to study at an HEI, using the OLA system, namely via the Online Learning Agreement platform or any Services.

User- Student, HEI or an Organisation.

We – indicates jointly AUTh, and EUF.

Privacy Policy

Dear Data Subject, We wish to inform you that the GDPR provides for the protection of individuals with regard to the processing of Personal Data as a fundamental right, and we take user privacy very seriously.

Pursuant to Article 13 of the GDPR, therefore, We will process your Personal Data according to the present Privacy Policy, which describes how such data is collected, stored, used, communicated and managed in connection with the Online Learning Agreement platform and the related Services.

Please notify us at the address [email protected] without delay should you notice any instances in which any violation of the present Privacy Policy occurs, or if you have questions or concerns about our Privacy Policy or practices. 

Please note that the scope of this Policy is limited to information collected or received by EUF through use of the Services.

Last updated: 1 December 2022

Type of data Processed

Automatically collected data. The computer systems and applications dedicated to the functioning of the Online Learning Agreement platform detect, during their normal operation, some data (whose transmission is implicit in the use of Internet communication protocols) potentially associated with identifiable users. Among the data collected are IP addresses and domain names of computers used by users who connect to the site, URI (Uniform Resource Identifier) of requested resources, the time of the request, the method used to submit the request to the server, the size of the file obtained in reply, the numerical code indicating the status of the response from the server (successful, error, etc..) and other parameters regarding the operating system, browser and computer environment used by the user. These data are processed, for the time strictly necessary, for the sole purpose of obtaining statistical information on the use of the site and to check its regular operation. The provision of such data is compulsory as it is directly related to the web browsing experience.

Data provided voluntarily by the user. The voluntary and explicit communication of Personal Data to us through the Online Learning Agreement platform implies the knowledge of this Privacy Policy, with the relevant request for consent and the eventual compilation of forms specifically prepared for this purpose.

If the Personal Data communicated to us does not belong to the same natural person who communicates it, the latter will be required to explicitly confirm that they have obtained the relevant consent from the Data Subject. In such cases, with the vision of this Privacy Policy and with the above-mentioned confirmation, the subject who communicates the Personal Data also undertakes to hold us harmless in case of false or reticent statements, in particular in case they have not actually obtained the consent to the processing from the relevant Data Subjects. 

The voluntary sending of e-mails to our e-mail addresses does not require further information or requests for consent. 

On the contrary, specific summary information will be reported or displayed if needed in the pages of the site prepared for particular services on request (form). The user must therefore explicitly consent to the use of the data reported in these forms in order to send any request.

Cookies. The Online Learning Agreement platform site uses cookies. The data collected through cookies can be used to access parts of the site or for statistical purposes or to make the browsing experience more pleasant and efficient in the future, trying to assess user behaviour and modify the proposed offer of content according to their behaviour. 

Origin of Processed Personal Data

The Personal Data that We hold in connection with the Online Learning Agreement platform and related Services is collected directly from the Data Subject when they register in the platform as Student users or uploaded by the relevant HEI or Organisation.

Data Controllers

The Data Controllers are: 

Aristotelio Panepistimio Thessalonikis

Kedea Building, Tritis Septemvriou, Aristotle University Campus, 54636 Thessaloniki, Greece

Phone: +302310999000
Email: [email protected]

European University Foundation - Campus Europae

16C rue de Canach 5353 Oetrange, Luxembourg

In particular, for the purpose of the data processing envisioned in this privacy policy, both controllers decide the purposes of the processing jointly, AUTh also has  the responsibility for the specification of higher-level indications received by the other Joint Controller. AUTh is responsible for the implementation and for deciding the means of the processing.

AUTh is also the elected point of contact for all Data Subject requests. 

Purpose of data Processing and legal basis

The processing of users’ Personal Data has its legal basis in their consent and is carried out for the following purposes:

  1. to create the relevant Accounts;
  2. to provide the Online Learning Agreement platform related Services, including to enable the preparation, negotiation, approval and management of the learning agreements;
  3. to improve the web browsing experience;
  4. to use the data contained in the contact e-mails received and, in the forms, to be able to send answers to specific requests, including users support;
  5. to evaluate the behaviour of users in order to conduct research, to create internal reports, and for possible educational purposes; and
  6. to modify the offer of content according to the users’ behaviour;
  7. to communicate our news;
  8. to send service related notifications that may be of importance to continue using the Services, and safety/security notifications related to the participation in programmes featured in our Service.

Personal data may be disclosed to third parties, if this is necessary for the fulfilment of the purposes described above.

We may also process the users’ data in order to pro-actively analyse the system architecture, data models and infrastructure resources in order to offer the Service in the best possible way. This includes, for example, analysis of slow-running database queries, predicting the growth rate of data (in order to allocate resources ahead of time), and analysis of the data contents and format in order to choose the most performant and fitting data models. It is unavoidable that in order to be able to provide the best possible service, We must be able to understand the data, as well as emergent trends in the data. Such analysis is done, whenever practical, in an anonymized manner and with only the above, purely technical or service-oriented purposes in mind.

Mandatory nature or not of the consent

The user’s consent is compulsory while using the Online Learning Agreement platform, and in particular to be able to own an account and correctly execute and manage Learning Agreements, for what concerns the purposes under points 1, 2, and 4 above. For the purposes under points 3 and 8 above, the consent is optional, but the lack thereof may worsen the provision of the Services. For the purposes under points 5, 6, and 7 the consent is optional and will not compromise in any way the provision of the Services, should you desire not to provide your consent for one or more specific purposes, please inform us at the time your Personal Data is communicated to us, or at any time thereafter, by contacting us at the e-mail address [email protected].

Data recipients

In general

Within the limits pertinent to the Processing purposes indicated, Users’ data may be communicated to partners, consulting companies, private companies, appointed by the Data Controllers as Data Processors or for legal obligations or to fulfil some users’ specific requests. In such cases we take all the necessary technical and organisational measures to protect the confidentiality and security of your Personal Data from unauthorised access or against loss, misuse or alteration by third parties. 

Our Services may also depend on third-party tracking tools from our service providers, examples of which include email service provider as well as push-notification service provider. Such third parties may use cookies, APIs, and SDKs in our services to enable them to collect and analyse user information on our behalf. In this context, third parties may have access to information such as your device identifier, MAC address, IMEI, locale (specific location where a given language is spoken), geo-location information, and IP address for the purpose of providing their services under their respective privacy policies.

The possible Data Processors and persons in charge of the Processing will in such cases be punctually identified and at the users’ request be communicated in detail. For any question in this regard, please contact AUTh at the address [email protected].

Please note that in such cases users will be also subject to the relevant third-party privacy policies. For any processing carried out by third parties as Data Processors in relation to the Online Learning Agreement platform and related Services, users may contact AUTh at the address [email protected] or directly such third parties. 

For all other cases of processing by third parties, please contact them directly in the manner indicated in their privacy policies.

In any case, any link to websites, apps or services on the Online Learning Agreement platform referrable to any third party does not constitute or represent sponsorship of or affiliation with such parties.

We may be mandated to disclose Personal Data to comply with laws, regulations, legal processes, or court orders; it may need to process such Data to enforce or withstand their rights; or to protect the rights, property, or safety of its users, or other individuals. This includes exchanging information with other companies and organisations for fraud protection.

Lastly, We may share your information in connection with potential merger, de-merger, acquisition, change of ownership, change of control, or in general extraordinary transaction. In such cases, the users will be notified via email and/or notice on our site of any change in ownership of the Personal Data.

For students

If the Data subject is a Student, some of their Personal Data such as name and surname, e-mail address and other contact information, nationality, study field, home university, host university or receiving organisation, as well as other information concerning their curriculum can be made accessible to the concerned HEIs and Organisations for the provision of the Services, as well as to European Union agencies on the basis of obligations undertaken by us towards them.

Personal Data of Students will not be communicated to HEIs or Organisations without the consent of the concerned Students.

Please note that the concerned HEIs and Organisations may be located in third countries were the GDPR and the consequent safeguards do not apply. In such cases, in the absence of an adequacy decision pursuant to Article 45 GDPR, or of appropriate safeguards pursuant to Article 46 GDPR, any transfer of Personal Data will take place only on one of the following conditions: (i) the User has explicitly consented to the proposed transfer, or (ii) the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the User between us and another natural or legal person.

For HEIs and Organisations

For HEIs or Organisations, some of the personal information of the relevant persons (contact and/or responsible person at HEI and contact person, mentor and/or supervisor at Organisation) contained in the Learning Agreements and/or relevant documentation uploaded in the platform can be made accessible, as well as to the concerned counterparties for the provision of the Services (be them Students, HEIs or Organisations), to European Union agencies on the basis of obligations undertaken by us towards them. 

Also in this cases, the recipients may be located in third countries, and thus any transfer of Personal Data will take place only on one of the following conditions: (i) the User has explicitly consented to the proposed transfer, or (ii) the transfer is necessary for the conclusion or performance of a contract concluded in the interest of the User between us and another natural or legal person.

Period and place of Data retention

The data collected will be stored for a period of time not exceeding the achievement of the purposes for which they are processed (“principle of limitation of storage”, art. 5, GDPR) or according to the deadlines provided for by law, to comply with our legal obligations, to resolve disputes, and enforce our agreements. The verification of the obsolescence of the data stored in relation to the purposes for which they were collected is carried out periodically.

We store the Personal Data on servers located in Ireland, Germany and Greece. EUF may nonetheless store such Data in other countries within the European Union. In such cases, this Privacy Policy will be updated accordingly. 

If and when we transfer Personal Data to affiliated entities or to other third parties across borders and from your country or jurisdiction to other countries or jurisdictions around the world, we will still take all appropriate measures to ensure compliance with the GDPR.

When third parties are involved in the Processing pursuant to this Privacy Policy, Personal Data may be stored on servers outside the European Union. Please remember that in such cases any Processing is also subject to the relevant third parties’ privacy policies. 

Google Login and eduGAIN

When users access the Services using their Google login or eduGAIN dataset, We only use the relevant API to verify their account and ensure security of their data. We only fetch the authentication data and never uses any of the users’ personal information for purposes beyond the limited and express purpose of the Services experience without getting specific opt-in consent from them.

Regardless of the above, this Privacy Policy also apply to the data collected through users’ Google login.

We will not communicate or disseminate any information about any user related to the user's use of any Google button or eduGAIN feature. For the avoidance of doubt, this prohibition includes, but is not limited to, any use of pixels, cookies, or other methods to recognise users' clicks, including on a Google button.

Google may analyse the use of Google+ buttons on the platform, including to ensure compliance with Google policies and to facilitate Google's development of Google+ buttons. By using a Google+ button, We have given Google permission to utilise an automated software program, also called a "web crawler," to retrieve and analyse services associated with a Google+ button, if any.

Further information regarding Google Login is present on the T&Cs related to the Online Learning Agreement platform and on Google’s websites.

Rights of the Data Subjects

Pursuant to GDPR, users (and/or the individuals who communicated the relevant Data) have the right to access the Personal Data provided to us (art. 15 GDPR) and to ask to receive copy of such Data in an intelligible format in order to transmit it to another data controller (art. 20 GDPR). They have the right to obtain their update, rectification or integration (art. 16 GDPR), and to obtain their erasure (art. 17 GDPR). Users also have the right to request the restriction of the Processing of their Personal Data (art. 18 GDPR) or to object, on legitimate grounds, to such Processing (art. 21 GDPR). We inform you, however, that the exercise of such rights may be subject to limitations or exclusions pursuant to the GDPR or other relevant regulations.

Where the users consider that the processing of Personal Data by us has been carried out in violation of the GDPR, without prejudice to any other administrative or judicial remedy, they the right to lodge a complaint with their national supervisory authority, in particular in the Member State of their habitual residence, place of work, or the place where the alleged violation took place.

For any request or communication concerning any of the above-mentioned rights, please send an e-mail to the following address [email protected]. AUTh will respond to any request as soon as possible and in any case within 30 days. 

Users may also object to Personal Data being subject to automated decision-making, including profiling practices. We inform you, however, that We do not carry out any processing that may fall within the aforementioned case. Should this situation change in the future, we will promptly update this Privacy Policy. 

Lastly, the users concerned (and/or the users who communicated the relevant Data) may at any time communicate their intention to withdraw their consent. In such cases, We may continue to Process the relevant Personal Data only in presence of an alternative legal basis for such further Processing.

Modalities of data processing

The Personal Data provided to us will be processed in compliance with the GDPR and the obligations of confidentiality that govern the activity of the Data Controllers. The data will be processed both with computer tools and on paper or any other suitable support, in compliance with the appropriate security measures under Article 5 par. 1 letter F of the GDPR.

Our Policy Regarding Minors

We do not knowingly collect or solicit personal information from anyone under the age of 18 or knowingly allow such persons to use our Services. If you are under such age, please do not send any information about yourself to us, including your name, address, telephone number, or email address. In the event that we learn that we have collected Personal Data from an individual under the age of 18, we will delete such Data as quickly as possible. If you believe that we might have received any Personal Data from or about an individual under the age of 18, please contact us at the address [email protected].

Changes to the Policy

We may update this privacy policy to reflect changes to our Processing and/or Data Protection practices. If we make any material changes, we will notify the users by means of a notice on our sites prior to the change becoming effective. In any case, please visit this Privacy Policy periodically.