Vai al contenuto principale
Co-funded by the Erasmus+ Programme of the European Union
IIS Mosè Bianchi — Istituto di Istruzione Superiore Bianchi Monza
Logo del programma Erasmus+ dell'IIS Bianchi

IIS Bianchi · Monza

Privacy Policy

This is an informal English abstract for information only.

The Italian version is the official and legally binding document.

Privacy Policy — Abstract (English)

Please note: Legal documents for this site are available in Italian only, as required by Italian law. This is an abstract provided for informational purposes only. The official and legally binding version is the Italian document (Informativa per il trattamento dei dati personali).


IIS Mosè Bianchi — Erasmus+ Portal

Privacy Notice · Version 2.1 — May 2026


1. Data Controller

Istituto Statale di Istruzione Superiore Mosè Bianchi Via Minerva 1 — 20900 Monza (MB), Italy Email: mbis06800p@istruzione.it PEC: mbis06800p@pec.istruzione.it

Data Protection Officer (DPO): Oxfirm S.r.l. — privacy@oxfirm.it


2. Scope

This notice applies to two distinct digital environments:

  • Public institutional website (iisbianchi.edu.it): accessible to anyone, no login required.
  • Erasmus+ Portal (restricted area): accessible after authentication to students, teachers and school staff. Manages mobility applications, questionnaires and related statistics.

3. Who we collect data from

  • Students, including minors (under 18)
  • Parents and legal guardians of minor students
  • Teachers and administrative staff
  • Collaborators and suppliers
  • Members of the public using public contact forms

Note on minors: The Erasmus+ Portal processes personal data of minor students. For students under 14, consent must be given or authorised by a parent or legal guardian (art. 8 GDPR).


4. Why we collect data and legal basis

Public website:

  • Institutional services (enrolments, communications): art. 6(1)(e) GDPR
  • Responding to contact requests: art. 6(1)(b) GDPR
  • IT security and system logs: art. 6(1)(c) GDPR

Erasmus+ Portal:

  • Managing mobility applications and participant selection: art. 6(1)(e) GDPR
  • Publication of selection rankings: rankings are published exclusively in the portal's restricted area, accessible only to authenticated participants, in partially anonymised form (numeric identifier or initial of surname). Not published in the public area of the site. Legal basis: art. 6(1)(e) GDPR.
  • PRE and POST mobility questionnaires: art. 6(1)(e) GDPR
  • Recording economic disadvantage or special educational needs (SEN/BES), for inclusive selection and Indire/EACEA reporting — optional, does not affect eligibility: art. 6(1)(e) GDPR
  • Statistics and reports for Erasmus+ accreditation (Indire, EACEA): art. 6(1)(c) GDPR
  • OLS (Online Linguistic Support) level tracking: art. 6(1)(c) GDPR

5. Data we collect

Common data: name, surname, date of birth, email address, authentication credentials, navigation logs and IP addresses.

Erasmus+ Portal specific data: study track, school year, mobility details (destination country, dates, application status), PRE/POST questionnaire responses, OLS language levels, and optionally economic situation (ISEE) or SEN/DSA/disability data.

Photographic and audiovisual materials (§5.3): photographs, videos and audiovisual materials produced during Erasmus+ activities are processed separately according to the specific purpose, each with its own dedicated consent:

  • Archival/internal documentation: art. 6(1)(e) GDPR. Retention: 10 years.
  • Publication on the Erasmus+ portal and institutional website: explicit consent, art. 6(1)(a) GDPR, withdrawable at any time.
  • Publication on social media (Facebook, Instagram, YouTube): separate explicit consent, art. 6(1)(a) GDPR, withdrawable at any time.
  • Promotional and Erasmus+ dissemination material: separate explicit consent, art. 6(1)(a) GDPR, withdrawable.

For minor participants, consent is given by the parent or legal guardian via a dedicated release form. Materials for which consent has not been given or has been withdrawn are not published or distributed.

Note — initial phase: the image and video publication feature is disabled in the initial phase of the portal. It will be activated in a second phase, after acquiring the relevant dedicated releases.


6. Third-party processors (art. 28 GDPR)

ProcessorRole
Supabase Inc.Authentication and database infrastructure. Data processed in the EU (Frankfurt, AWS eu-central-1). US transfer governed by EU Standard Contractual Clauses.
Vercel Inc.Hosting and distribution of the Erasmus+ Portal web application. HQ: San Francisco, USA. Distribution servers: global network with EU nodes. Transfer governed by EU Standard Contractual Clauses. Privacy policy: vercel.com/legal/privacy-policy
SIDI — MIMNational student records database
School management software & Electronic RegisterAdministrative management and student records
Oxfirm S.r.l.Data Protection Officer

Note on development tools: The Erasmus+ Portal was developed with the support of generative AI tools (Anthropic PBC — Claude). These tools were used exclusively during the source code development phase. No personal data of portal users is transmitted to external AI systems during normal use of the service.


7. International data transfers

Data is processed on EU servers (AWS eu-central-1, Frankfurt). Supabase Inc. is headquartered in the US: transfers are governed by EU Standard Contractual Clauses approved by the European Commission.


8. Security

  • HTTPS/TLS encrypted transmission
  • Secure token authentication (Supabase Auth)
  • Role-based access control (student, teacher, staff, admin)
  • Access and change logs for audit purposes
  • No sensitive data stored in plain text

Reinforced measures for special category data: Data relating to economic disadvantage (ISEE), SEN, DSA or disability is subject to additional protection measures: access limited to expressly authorised staff only (Head Teacher, DSGA, Erasmus+ coordinator), stored in pseudonymised form, not included in standard exports, not transmitted to external AI systems, and deleted or aggregated at the end of the school year unless required for Indire/EACEA reporting.

Note — initial phase: fields relating to ISEE, SEN, DSA and disability are disabled in the portal frontend in the initial phase.


9. How long we keep your data

Data typeRetention period
Access logs and navigation data12 months
Student recordsUnlimited (Electronic Register, per AGID guidelines)
Erasmus+ mobility and application data10 years from end of accreditation period (2024–2027)
PRE/POST questionnaire responses10 years from end of accreditation period
Economic disadvantage / SEN dataDeleted or anonymised at end of school year, unless required for Indire reporting

10. Your rights

Under the GDPR you have the right to: access your data (art. 15), rectify it (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20), object to processing (art. 21), and withdraw consent at any time (art. 7(3)).

Parents and legal guardians may exercise these rights on behalf of minor students.

You also have the right to lodge a complaint with the Italian Data Protection Authority: www.garanteprivacy.it


11. How to exercise your rights

ChannelContact
Emailmbis06800p@istruzione.it
PECmbis06800p@pec.istruzione.it
Contact formhttp://www.iisbianchi.edu.it
DPO emailprivacy@oxfirm.it
PostVia Minerva 1, 20900 Monza (MB), Italy

The Data Controller will respond within 30 days of receipt.