Privacy Policy — Abstract (English)
Please note: Legal documents for this site are available in Italian only, as required by Italian law. This is an abstract provided for informational purposes only. The official and legally binding version is the Italian document (Informativa per il trattamento dei dati personali).
IIS Mosè Bianchi — Erasmus+ Portal
Privacy Notice · Version 2.1 — May 2026
1. Data Controller
Istituto Statale di Istruzione Superiore Mosè Bianchi Via Minerva 1 — 20900 Monza (MB), Italy Email: mbis06800p@istruzione.it PEC: mbis06800p@pec.istruzione.it
Data Protection Officer (DPO): Oxfirm S.r.l. — privacy@oxfirm.it
2. Scope
This notice applies to two distinct digital environments:
- Public institutional website (iisbianchi.edu.it): accessible to anyone, no login required.
- Erasmus+ Portal (restricted area): accessible after authentication to students, teachers and school staff. Manages mobility applications, questionnaires and related statistics.
3. Who we collect data from
- Students, including minors (under 18)
- Parents and legal guardians of minor students
- Teachers and administrative staff
- Collaborators and suppliers
- Members of the public using public contact forms
Note on minors: The Erasmus+ Portal processes personal data of minor students. For students under 14, consent must be given or authorised by a parent or legal guardian (art. 8 GDPR).
4. Why we collect data and legal basis
Public website:
- Institutional services (enrolments, communications): art. 6(1)(e) GDPR
- Responding to contact requests: art. 6(1)(b) GDPR
- IT security and system logs: art. 6(1)(c) GDPR
Erasmus+ Portal:
- Managing mobility applications and participant selection: art. 6(1)(e) GDPR
- Publication of selection rankings: rankings are published exclusively in the portal's restricted area, accessible only to authenticated participants, in partially anonymised form (numeric identifier or initial of surname). Not published in the public area of the site. Legal basis: art. 6(1)(e) GDPR.
- PRE and POST mobility questionnaires: art. 6(1)(e) GDPR
- Recording economic disadvantage or special educational needs (SEN/BES), for inclusive selection and Indire/EACEA reporting — optional, does not affect eligibility: art. 6(1)(e) GDPR
- Statistics and reports for Erasmus+ accreditation (Indire, EACEA): art. 6(1)(c) GDPR
- OLS (Online Linguistic Support) level tracking: art. 6(1)(c) GDPR
5. Data we collect
Common data: name, surname, date of birth, email address, authentication credentials, navigation logs and IP addresses.
Erasmus+ Portal specific data: study track, school year, mobility details (destination country, dates, application status), PRE/POST questionnaire responses, OLS language levels, and optionally economic situation (ISEE) or SEN/DSA/disability data.
Photographic and audiovisual materials (§5.3): photographs, videos and audiovisual materials produced during Erasmus+ activities are processed separately according to the specific purpose, each with its own dedicated consent:
- Archival/internal documentation: art. 6(1)(e) GDPR. Retention: 10 years.
- Publication on the Erasmus+ portal and institutional website: explicit consent, art. 6(1)(a) GDPR, withdrawable at any time.
- Publication on social media (Facebook, Instagram, YouTube): separate explicit consent, art. 6(1)(a) GDPR, withdrawable at any time.
- Promotional and Erasmus+ dissemination material: separate explicit consent, art. 6(1)(a) GDPR, withdrawable.
For minor participants, consent is given by the parent or legal guardian via a dedicated release form. Materials for which consent has not been given or has been withdrawn are not published or distributed.
Note — initial phase: the image and video publication feature is disabled in the initial phase of the portal. It will be activated in a second phase, after acquiring the relevant dedicated releases.
6. Third-party processors (art. 28 GDPR)
| Processor | Role |
|---|---|
| Supabase Inc. | Authentication and database infrastructure. Data processed in the EU (Frankfurt, AWS eu-central-1). US transfer governed by EU Standard Contractual Clauses. |
| Vercel Inc. | Hosting and distribution of the Erasmus+ Portal web application. HQ: San Francisco, USA. Distribution servers: global network with EU nodes. Transfer governed by EU Standard Contractual Clauses. Privacy policy: vercel.com/legal/privacy-policy |
| SIDI — MIM | National student records database |
| School management software & Electronic Register | Administrative management and student records |
| Oxfirm S.r.l. | Data Protection Officer |
Note on development tools: The Erasmus+ Portal was developed with the support of generative AI tools (Anthropic PBC — Claude). These tools were used exclusively during the source code development phase. No personal data of portal users is transmitted to external AI systems during normal use of the service.
7. International data transfers
Data is processed on EU servers (AWS eu-central-1, Frankfurt). Supabase Inc. is headquartered in the US: transfers are governed by EU Standard Contractual Clauses approved by the European Commission.
8. Security
- HTTPS/TLS encrypted transmission
- Secure token authentication (Supabase Auth)
- Role-based access control (student, teacher, staff, admin)
- Access and change logs for audit purposes
- No sensitive data stored in plain text
Reinforced measures for special category data: Data relating to economic disadvantage (ISEE), SEN, DSA or disability is subject to additional protection measures: access limited to expressly authorised staff only (Head Teacher, DSGA, Erasmus+ coordinator), stored in pseudonymised form, not included in standard exports, not transmitted to external AI systems, and deleted or aggregated at the end of the school year unless required for Indire/EACEA reporting.
Note — initial phase: fields relating to ISEE, SEN, DSA and disability are disabled in the portal frontend in the initial phase.
9. How long we keep your data
| Data type | Retention period |
|---|---|
| Access logs and navigation data | 12 months |
| Student records | Unlimited (Electronic Register, per AGID guidelines) |
| Erasmus+ mobility and application data | 10 years from end of accreditation period (2024–2027) |
| PRE/POST questionnaire responses | 10 years from end of accreditation period |
| Economic disadvantage / SEN data | Deleted or anonymised at end of school year, unless required for Indire reporting |
10. Your rights
Under the GDPR you have the right to: access your data (art. 15), rectify it (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20), object to processing (art. 21), and withdraw consent at any time (art. 7(3)).
Parents and legal guardians may exercise these rights on behalf of minor students.
You also have the right to lodge a complaint with the Italian Data Protection Authority: www.garanteprivacy.it
11. How to exercise your rights
| Channel | Contact |
|---|---|
| mbis06800p@istruzione.it | |
| PEC | mbis06800p@pec.istruzione.it |
| Contact form | http://www.iisbianchi.edu.it |
| DPO email | privacy@oxfirm.it |
| Post | Via Minerva 1, 20900 Monza (MB), Italy |
The Data Controller will respond within 30 days of receipt.


