The present Privacy Policy describes the means and purposes of the processing of personal data through the website www.thromborisk.eu (hereinafter the ‘Website’) carried out by the ThromboRisk consortium, particularly as Lynkeus, partner of the ThromboRisk consortium and responsible of website design and maintenance, in its quality of Data Controller (hereinafter ‘LYN’ or ‘Controller’). This Privacy Policy applies to anyone who accesses the Website or otherwise interacts with the web services offered on the Website (i.e., the ‘User’).
The processing of the User’s personal data will take place in compliance with the applicable data protection legislation, with particular regard to Regulation (EU) 2016/679 (the ‘GDPR’) concerning the protection of natural persons with regard to the processing of personal data, as well as free movement of such data.
DATA CONTROLLER
The Controller is Lynkeus S.r.l., with its registered office at Via Livenza 6, 00198 Rome, Italy.
THE WEBSITE
This Website aims to provide information regarding ThromboRisk, a 4-year (1 Feb 2026 – 30 Jan 2030) doctoral training network funded by the European Research Executive Agency under Grant Agreement No 101227706.
It has been designed to minimise the collection and the processing of Users’ personal data, as well as to exclude the processing of such data in all cases when the purposes described below can be achieved with different and more privacy-preserving means.
CATEGORIES OF PERSONAL DATA COLLECTED
Traffic and Internet data
The computer systems and software procedures used to operate the Website acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols.
This category of data includes, among others, IP addresses, browser type, operating system, the domain name and website addresses from which the User logs in or out, the information on pages visited by User within the Website, the time of access, time period of User’s staying on a single page, the internal path analysis and other parameters regarding the User’s OS and computer environment.
These technical/IT data are collected and used only in an aggregated and not immediately identifiable manner. They could be used to ascertain responsibilities in case of crimes against the Website, or upon public authorities’ request.
In order to consent to the collection of this category of data, the Website uses cookies. Please, read the Cookie Policy of this Website for any further information about them.
Personal data provided by the User
The provision of personal data by the User (e.g., name, surname, email address) implies the acquisition of such data by LYN and its subsequent processing for the sole purposes set out below.
PURPOSE AND LEGAL BASES OF THE PROCESSING
The User’s personal data will be processed by the Processor solely for the following purposes:
- Allowing the User to easily and correctly navigate the Website. This processing is necessary to operate the Website and allow the User to access its contents, in accordance with Art. 6.1, b) of the GDPR;
- Fulfil any request made by the User through the registration form available on the Website. This processing is necessary to provide Users with information regarding their registration, in accordance with Art. 6.1, b) of the GDPR;
- Complying with the obligations set forth by applicable laws and regulations, and to ascertain responsibilities in case of any computer crimes against the Website. As this processing is mandatory by law, the user’s consent is not required according to Art. 6.1, c).
METHODS OF THE PROCESSING, DATA RETENTION AND DATA SECURITY
The personal data are collected and processed lawfully and fairly, solely for the purposes described above and in accordance with the fundamental principles established by the applicable legislation.
Personal data may be processed either manually, through information technology tools, or electronically, but always under technical and organisational measures that ensure their security and confidentiality, especially to prevent any risk arising from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data.
The processing operations will be carried out only by persons who have been duly authorised and instructed by the Controller.
COMMUNICATIONS TO THIRD PARTIES
The personal data collected by the Processor will not be shared or communicated to third parties unless with the specific consent of the data subject or as otherwise required by applicable laws.
Should the communication to third-party suppliers or partners of Lynkeus Srl (e.g., service providers, hosting providers, IT companies, communication agencies) be necessary for organisational, administrative or support needs, it will be the Controller’s responsibility to appoint such parties as additional data processors by virtue of the capacity, experience and reliability demonstrated.
It remains understood that the Users’ personal data may be made available to third parties, such as competent authorities and police authorities, whenever required by applicable law or by an order issued by them.
DATA RETENTION
The personal data will be kept in a format that allows the User’s identification only for the time strictly necessary to fulfil the purposes for which the data have been originally collected and, in any case, within the limits set forth by applicable laws and regulations, as well as to enforce or protect the rights of the Controller, where necessary.
In particular, the data provided by the User for the InnovaHeart registration will be retained for up to 36 months.
When no longer necessary, the data will be immediately cancelled or made anonymous.
TRANSFER OF DATA ABROAD
The User’s personal data will not be transferred outside the European Economic Area (hereinafter, the ‘EEA’).
In any case, should a transfer of the data outside the EEA become necessary in the future, it will be carried out in accordance with the provisions of the GDPR and the User will be timely informed about this processing.
REDIRECT TO OTHER WEBSITES
The Website includes links that allow the User to connect to other websites operated by third parties. The Controller assumes no responsibility for the processing of personal data that may occur through or in connection with third parties’ websites.
Therefore, each User who accesses such web pages and/or social platforms through the Website must carefully read the relevant privacy policies to better understand how their personal data will be processed by third parties, which, as autonomous controllers, will provide and manage such websites.
DATA SUBJECTS’ RIGHTS
In compliance with applicable law, Users can exercise their rights at any time, including:
- Accessing their personal data, obtaining evidence of the purposes pursued by the Controller, the categories of data involved, the recipients to whom they may be disclosed, the applicable storage period, and the existence of automated decision-making processes;
- Having incorrect personal data referred to them, rectified without delay;
- Having their data erased in the cases provided for by the law;
- Obtaining restrictions to processing, where possible;
- Requesting portability of the data provided to the Data Controller, i.e., receiving them in a structured, commonly used and machine-readable format, also for transmitting such data to another controller, without any hindrance by the Controller, in all situations where it is required by the law in force;
- Objecting to the processing of their data for marketing and commercial purposes;
- Easily withdrawing any consent they have previously given, without this affecting in any manner the lawfulness of the processing operations carried out before;
- Lodging a complaint to the data protection Supervisory Authority (please, find here the list of the Data Protection Authorities in Europe).
To exercise these rights, or for any further information and/or clarifications, please write to the Controller by sending an email to info@thromborisk.eu.