Privacy policy
PERSONAL DATA PROCESSING NOTICE
Institutional website — www.iasaeu.it
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR)
This notice describes how personal data of users who browse the institutional website of IASA – Institute of Advanced Science for Agriculture (hereinafter “IASA” or the “School”) are processed, as well as of those who subscribe to the newsletter or submit their application for the PhD Courses by e-mail. This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”) to anyone interacting with the services offered through the Site.
1. Data Controller
The Data Controller is IASA – Institute of Advanced Science for Agriculture, a non-state higher education institution with special status, endowed with private legal personality and scientific, teaching, administrative and accounting autonomy, established by Decree-Law no. 25 of 14 March 2025, converted with amendments by Law no. 69 of 9 May 2025, with registered office in Jolanda di Savoia (FE), info@iasaeu.it, in the person of the Rector pro tempore, who also has legal representation in court.
For any request concerning the processing of personal data, the data subject may contact the Data Controller at the following e-mail address: privacy@iasaeu.it.
2. Data Protection Officer (DPO)
IASA has appointed Dr. Jacopo Liguori as Data Protection Officer (“DPO”), who can be contacted at the following address: dpo@iasaeu.it. The data subject may contact the DPO for any matter concerning the processing of their personal data and the exercise of the rights provided for under the GDPR.
3. General principles of processing
The processing of personal data collected through the Site is based on the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity and confidentiality set out in Art. 5 GDPR. IASA collects only the data necessary for the purposes described below and does not carry out any form of user profiling or disclosure to third parties for marketing purposes on behalf of parties other than IASA.
4. Categories of data processed, purposes and legal bases
4.1 Browsing the Site
In the course of normal browsing, the computer systems and software procedures used to operate the Site acquire certain data (IP addresses, browser type, operating system, pages visited, access times), the transmission of which is inherent in the use of Internet communication protocols.
Such data are used solely to derive anonymous statistical information on the use of the Site and to check its correct functioning, and are deleted immediately after processing. The legal basis is the Data Controller's legitimate interest in ensuring the security and correct functioning of the Site (Art. 6(1)(f) GDPR). Any use of technical, analytical or profiling cookies is governed by the specific Cookie Policy available on the Site at www.iasaeu.it .
4.2 Newsletter subscription
Users who subscribe to the newsletter through the form on the Site voluntarily provide their e-mail address. Such data are processed exclusively for sending periodic communications relating to the institutional, teaching, research and event activities organised by IASA.
- Legal basis: free, specific and informed consent of the data subject (Art. 6(1)(a) GDPR), given at the time of subscription, including through a double opt-in mechanism.
- Provision of data: optional. Failure to subscribe has no consequences for the user.
- Withdrawal: consent may be withdrawn at any time, with effect for the future, by clicking the unsubscribe link at the bottom of each communication, or by writing to the Data Controller or the DPO. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Retention: data are retained until consent is withdrawn and, in any event, for no longer than 24 months from the user's last interaction with the communications received, unless consent is withdrawn earlier.
4.3 Application to PhD Courses in response to the call for applications
Admission to IASA's PhD Courses takes place exclusively through a public competitive procedure based on merit criteria, in accordance with the University Statute and regulations. Interested candidates submit their application, accompanied by their curriculum vitae and any other documents required, to the e-mail address indicated in the call published by IASA.
The data processed at this stage include, by way of example: personal and contact details, education and academic qualifications, professional and research experience, language skills, and any other data entered by the candidate in the application or CV in response to the call.
- Legal basis: fulfilment of obligations laid down by sector-specific legislation governing admission to PhD courses (Law no. 341 of 19 November 1990, Ministerial Decree no. 270 of 22 October 2004, Law no. 210 of 3 July 1998, Art. 4), as this involves data collected in the context of a public competitive procedure governed by law, and not processing based on consent or contract; fulfilment of obligations under sector-specific legislation, with particular reference to Art. 6(1)(c) GDPR.
- Provision of data: mandatory for participation in the selection procedure; failure to provide the data results in the impossibility of being admitted for evaluation.
- Special categories of data (Art. 9 GDPR): candidates are invited not to include in the application or CV data not necessary for the evaluation (e.g. photograph, health status, ethnic origin, religious or trade union beliefs, political opinions), unless expressly requested in the call for legitimate purposes (e.g. requests for accommodation for candidates with disabilities). If present, such data are processed with enhanced security measures and limited to what is strictly necessary for the procedure.
- Retention: data are retained for the duration of the competitive procedure and, subsequently, for the time necessary to cover any deadlines for challenging the administrative acts of the selection, in accordance with the legislation applicable to competitive procedures.
- Recipients: selection committee, any external members involved in the evaluation, Ministry of University and Research, within the limits provided for by sector-specific legislation.
4.4 Requests for information and general contacts
Data provided by the user through any contact forms, institutional e-mail addresses or telephone numbers published on the Site are processed solely to respond to the requests received, on the basis of the performance of pre-contractual measures or the performance of a contract (Art. 6(1)(b) GDPR) or of IASA's legitimate interest in managing its institutional correspondence (Art. 6(1)(f) GDPR). Provision of the data is optional but necessary in order to receive a response.
5. Processing methods and security measures
Personal data are processed using IT and telecommunications tools, with logic strictly related to the purposes indicated, and in any event in such a way as to guarantee the security and confidentiality of the data, including through the adoption of appropriate technical and organisational measures pursuant to Art. 32 GDPR (by way of example: access restricted to authorised personnel, secure transmission protocols, backup systems and access controls).
6. Disclosure and categories of data recipients
The personal data collected may be disclosed, for the purposes indicated above and within the limits strictly necessary, to the following parties:
- IASA's internal bodies and staff competent in relation to the specific purpose (Rector, Director General, Scientific-Teaching Area Managers/PhD Course Coordinators, Faculty Board), for the evaluation of PhD applications;
- BF S.p.A. and the companies controlled or promoted by it, identified in IASA's Statute, within the limits of their respective competences and the relationships governed by the Statute, internal regulations or specific agreements, where they contribute to the provision of the educational offering, institutional activities or the supply of the means and services necessary to pursue IASA's institutional purposes;
- the provider of the Site hosting and management service, as Data Processor pursuant to Art. 28 GDPR, limited to the data necessary for the provision of the service;
- any provider of the newsletter delivery platform, as Data Processor pursuant to Art. 28 GDPR;
- the Ministry of University and Research and other public bodies, where required by specific regulatory or statutory obligations applicable to IASA;
- external commissioners and members of selection committees, limited to the data of candidates involved in the relevant procedures.
Data are in no case disseminated or disclosed to third parties for marketing purposes independent of those of IASA.
7. Transfer of data outside the EU
Should it become necessary, in the context of institutional activities or services connected with the operation of the Site, to transfer personal data to parties established in countries outside the European Union or the European Economic Area, such transfer will take place exclusively in compliance with Articles 44 et seq. of Regulation (EU) 2016/679 (GDPR).
In particular, the transfer will be carried out on the basis of an adequacy decision of the European Commission or, in the absence thereof, through the adoption of the appropriate safeguards provided for by applicable legislation, such as, by way of example, the standard contractual clauses approved by the European Commission or other suitable instruments provided for by the GDPR.
The mere fact that data subjects originate from third countries does not in itself entail any international transfer of personal data, as processing remains carried out by the Data Controller in compliance with applicable European and national legislation.
8. Retention period
Without prejudice to what has already been indicated for the individual purposes in the preceding paragraphs, personal data are retained for the time strictly necessary to achieve the purposes for which they were collected, in compliance with the principles of minimisation and storage limitation, and in any event within the limits provided for by any legal obligations.
9. Rights of the data subject
As a data subject, the user may exercise at any time, within the limits and under the conditions provided for by Articles 15-22 GDPR, the following rights:
- right of access to their personal data (Art. 15);
- right to rectification of inaccurate data or completion of incomplete data (Art. 16);
- right to erasure (“right to be forgotten”), in the cases provided for by law (Art. 17);
- right to restriction of processing (Art. 18);
- right to data portability, where applicable (Art. 20);
- right to object to processing (Art. 21);
- right to withdraw consent given at any time, without prejudice to the lawfulness of processing carried out prior to withdrawal (Art. 7(3)).
These rights may be exercised by sending a request to the Data Controller or to the Data Protection Officer at the contact details indicated in paragraphs 1 and 2.
10. Right to lodge a complaint
Without prejudice to any other administrative or judicial remedy, the data subject who believes that the processing of their personal data has taken place in violation of applicable law has the right to lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority), the competent supervisory authority in Italy, with registered office in Piazza Venezia 11, 00187 Rome, or to bring the matter before the competent courts.
11. Changes to this notice
This notice may be subject to changes or updates, including in relation to regulatory or organisational changes. Any changes will be published on this page, with an indication of the date of the last update.
Last updated: 06/08/2026