— Privacy Policy & GDPR
This policy sets out what personal data iSET Most z.ú. processes, why, on what legal basis, how long we keep it and what rights you have. It is written to be understood without a legal background.
1. Who we are
The controller is iSET Most z.ú., U Stadionu 3554, 434 01 Most, Czech Republic, Company ID 29811678, VAT CZ29811678 ("iSET", "we").
For anything concerning personal data, write to info@isetmost.eu
2. What this policy covers
Processing carried out when you visit www.isetmost.eu, when you contact us, when you apply for a post, when you take part in our research, and in the administration of projects and contracts.
Our site links to third-party pages. We are not responsible for their processing — read their own policies.
3. What we process and why
Website visitors
Data: IP address, browser type, pages viewed, time of access
Purpose: running, securing and debugging the site
Legal basis: legitimate interest — Art. 6(1)(f)
Retention: 12 months
Enquiries and correspondence
Data: name, e-mail, telephone, content of your message
Purpose: answering you and any follow-up
Legal basis: legitimate interest — Art. 6(1)(f)
Retention: 3 years from last contact
Newsletter subscribers
Data: name, e-mail
Purpose: sending news about our work
Legal basis: consent — Art. 6(1)(a)
Retention: until consent is withdrawn
Job applicants
Data: CV, contact and qualification details
Purpose: running the recruitment
Legal basis: pre-contractual steps — Art. 6(1)(b)
Retention: 6 months, longer only with consent
Staff and collaborators
Data: identification, payroll and employment records
Purpose: the employment relationship and statutory duties
Legal basis: contract and legal obligation — Art. 6(1)(b), (c)
Retention: as required by law; payroll 30 years
Research participants
• Data: as defined per project; pseudonymised where possible
• Purpose: scientific research and publication
• Legal basis: consent, or legitimate interest with Art. 89 safeguards
• Retention: per the project data management plan
Partners and suppliers
Data: contact and invoicing details of representatives
Purpose: performing contracts, project and grant administration
Legal basis: contract and legal obligation — Art. 6(1)(b), (c)
Retention: 10 years (tax documents)
Equality monitoring
Data: sex-disaggregated data, reported in aggregate
Purpose: delivering the Gender Equality Plan and EU conditions
Legal basis: legal obligation and legitimate interest — Art. 6(1)(c), (f)
Retention: aggregate retained; individual records 3 years
4. Legal bases
We do not process personal data without a legal basis. We rely on the following under Article 6 GDPR:
Article 6(1)(a) — consent — newsletter, non-essential cookies, research participation, event photography
(b) — performance of a contract — suppliers, clients, staff and collaborators
(c) — legal obligation — accounting, tax, archiving, employment records
(f) — legitimate interest — running and securing the website, answering enquiries, protecting property and rights, scientific research where your interests do not override ours
Special categories of data — health data in research, for example — are processed only where an exemption under Article 9(2) applies: normally your explicit consent (point a) or scientific research with the safeguards of Article 89(1) (point j).
5. Who we share data with
We do notsell personal data. We share it only with those who need it for their role:
Processors — hosting and e-mail provider, IT support, accountants, survey tools — acting only on our documented instructions
Project partners — only as far as the project requires, under a consortium agreement
Funding bodies — the European Commission and national agencies, for monitoring and audit
Public authorities — only where the law requires it
Every processor is bound by a data processing agreement under Article 28 GDPR.
6. Transfer outside the EU
We process data in the EU and EEA by preference. Where a processor operates outside that area, the transfer is made only under an adequacy decision (Article 45) or standard contractual clauses (Article 46). We will send you the current list of processors on request.
7. Security
Weapply technical and organisational measures proportionate to the risk: role-based access control, encryption in transit (TLS) and at rest on portable devices, backups, pseudonymisation of research data where feasible, and regular staff training.
If a breach occurs that poses a risk to your rights, we report it to the Office for Personal Data Protection within 72 hours and, where the risk is high, tell you directly.
8. Your rights
You have the following rights over your data:
Access (Art. 15) — know whether and what data we hold about you, and get a copy
Rectification (Art. 16) — correct inaccurate data and complete incomplete data
Erasure (Art. 17) — have data deleted where no ground for further processing exists
Restriction (Art. 18) — limit processing temporarily, for example while accuracy is checked
Portability (Art. 20) — receive your data in a machine-readable format where processing rests on consent or contract and is automated
Objection (Art. 21) — object to processing based on legitimate interest; to direct marketing, always and without giving reasons
Withdraw consent (Art. 7) — at any time, without affecting earlier lawful processing
Automated decisions (Art. 22) — not be subject to a decision based solely on automated processing — iSET carries out no such decision-making or profiling
Exercise them by e-mail to info@isetmost.eu or in writing to our registered address. We reply without undue delay and within one month; for complex requests this may be extended by two further months, and we will tell you if it is. Exercising your rights is free unless a request is manifestly unfounded or excessive.
To avoid disclosing data to the wrong person, we may ask you to verify your identity.
9. Data protection officer
iSET is not a public authority and does not carry out activities that would require a Data Protection Officer under Article 37 GDPR. We have therefore not appointed one. Data protection is handled by iSET management, and the contact point is info@isetmost.eu
We review this assessment periodically. If the scope of our processing changes we will appoint an Officer and update this page.
10. Childern
Our services are not directed at children under 15 and we do not knowingly collect their personal data. A child may take part in research only with the consent of a legal guardian.
11. Changes to this policy
We may update this policy. Material changes will be announced on the site, and where processing rests on consent we will ask for consent again. Previous versions are archived and available on request.
This policy is an information notice under Articles 13 and 14 GDPR. It does not replace contractual terms or legal advice.
