— Privacy Policy & GDPR

This policy sets out what personal data iSET Most z.ú. processes, why, on what legal basis, how long we keep it and what rights you have. It is written to be understood without a legal background.


1. Who we are

The controller is iSET Most z.ú., U Stadionu 3554, 434 01 Most, Czech Republic, Company ID 29811678, VAT CZ29811678 ("iSET", "we").

For anything concerning personal data, write to info@isetmost.eu

2. What this policy covers

Processing carried out when you visit www.isetmost.eu, when you contact us, when you apply for a post, when you take part in our research, and in the administration of projects and contracts.

Our site links to third-party pages. We are not responsible for their processing — read their own policies.

3. What we process and why

Website visitors

  • Data: IP address, browser type, pages viewed, time of access

  • Purpose: running, securing and debugging the site

  • Legal basis: legitimate interest — Art. 6(1)(f)

  • Retention: 12 months

Enquiries and correspondence

  • Data: name, e-mail, telephone, content of your message

  • Purpose: answering you and any follow-up

  • Legal basis: legitimate interest — Art. 6(1)(f)

  • Retention: 3 years from last contact

Newsletter subscribers

  • Data: name, e-mail

  • Purpose: sending news about our work

  • Legal basis: consent — Art. 6(1)(a)

  • Retention: until consent is withdrawn

Job applicants

  • Data: CV, contact and qualification details

  • Purpose: running the recruitment

  • Legal basis: pre-contractual steps — Art. 6(1)(b)

  • Retention: 6 months, longer only with consent

Staff and collaborators

  • Data: identification, payroll and employment records

  • Purpose: the employment relationship and statutory duties

  • Legal basis: contract and legal obligation — Art. 6(1)(b), (c)

  • Retention: as required by law; payroll 30 years

Research participants

  • • Data: as defined per project; pseudonymised where possible

  • • Purpose: scientific research and publication

  • • Legal basis: consent, or legitimate interest with Art. 89 safeguards

  • • Retention: per the project data management plan

Partners and suppliers

  • Data: contact and invoicing details of representatives

  • Purpose: performing contracts, project and grant administration

  • Legal basis: contract and legal obligation — Art. 6(1)(b), (c)

  • Retention: 10 years (tax documents)

Equality monitoring

  • Data: sex-disaggregated data, reported in aggregate

  • Purpose: delivering the Gender Equality Plan and EU conditions

  • Legal basis: legal obligation and legitimate interest — Art. 6(1)(c), (f)

  • Retention: aggregate retained; individual records 3 years

4. Legal bases

We do not process personal data without a legal basis. We rely on the following under Article 6 GDPR:

  • Article 6(1)(a) — consent — newsletter, non-essential cookies, research participation, event photography

  • (b) — performance of a contract — suppliers, clients, staff and collaborators

  • (c) — legal obligation — accounting, tax, archiving, employment records

  • (f) — legitimate interest — running and securing the website, answering enquiries, protecting property and rights, scientific research where your interests do not override ours

Special categories of data — health data in research, for example — are processed only where an exemption under Article 9(2) applies: normally your explicit consent (point a) or scientific research with the safeguards of Article 89(1) (point j).

5. Who we share data with

We do notsell personal data. We share it only with those who need it for their role:

  • Processors — hosting and e-mail provider, IT support, accountants, survey tools — acting only on our documented instructions

  • Project partners — only as far as the project requires, under a consortium agreement

  • Funding bodies — the European Commission and national agencies, for monitoring and audit

  • Public authorities — only where the law requires it

Every processor is bound by a data processing agreement under Article 28 GDPR.

6. Transfer outside the EU

We process data in the EU and EEA by preference. Where a processor operates outside that area, the transfer is made only under an adequacy decision (Article 45) or standard contractual clauses (Article 46). We will send you the current list of processors on request.

7. Security

Weapply technical and organisational measures proportionate to the risk: role-based access control, encryption in transit (TLS) and at rest on portable devices, backups, pseudonymisation of research data where feasible, and regular staff training.

If a breach occurs that poses a risk to your rights, we report it to the Office for Personal Data Protection within 72 hours and, where the risk is high, tell you directly.

8. Your rights

You have the following rights over your data:

  • Access (Art. 15) — know whether and what data we hold about you, and get a copy

  • Rectification (Art. 16) — correct inaccurate data and complete incomplete data

  • Erasure (Art. 17) — have data deleted where no ground for further processing exists

  • Restriction (Art. 18) — limit processing temporarily, for example while accuracy is checked

  • Portability (Art. 20) — receive your data in a machine-readable format where processing rests on consent or contract and is automated

  • Objection (Art. 21) — object to processing based on legitimate interest; to direct marketing, always and without giving reasons

  • Withdraw consent (Art. 7) — at any time, without affecting earlier lawful processing

  • Automated decisions (Art. 22) — not be subject to a decision based solely on automated processing — iSET carries out no such decision-making or profiling

Exercise them by e-mail to info@isetmost.eu or in writing to our registered address. We reply without undue delay and within one month; for complex requests this may be extended by two further months, and we will tell you if it is. Exercising your rights is free unless a request is manifestly unfounded or excessive.

To avoid disclosing data to the wrong person, we may ask you to verify your identity.

9. Data protection officer

iSET is not a public authority and does not carry out activities that would require a Data Protection Officer under Article 37 GDPR. We have therefore not appointed one. Data protection is handled by iSET management, and the contact point is info@isetmost.eu

We review this assessment periodically. If the scope of our processing changes we will appoint an Officer and update this page.

10. Childern

Our services are not directed at children under 15 and we do not knowingly collect their personal data. A child may take part in research only with the consent of a legal guardian.

11. Changes to this policy

We may update this policy. Material changes will be announced on the site, and where processing rests on consent we will ask for consent again. Previous versions are archived and available on request.


This policy is an information notice under Articles 13 and 14 GDPR. It does not replace contractual terms or legal advice.