Privacy Policy

Last updated: June 2026

This Privacy Policy explains how the VETInnovate project collects, uses and protects your personal data when you use our website and services. We are committed to handling your data in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). If anything is unclear, contact us at vetinnovateproject@gmail.com.

What personal data we collect

Depending on how you use the site, we may collect:

  • Account and profile data: your first and last name, email address, password, and the organisation, country and professional role you provide when you register.
  • Assessment and certification data: your responses and results from the self-assessment tool, and the records needed to issue your certificate.
  • Contact data: the content of any message you send through our contact form, together with your name and email address.
  • Technical data: limited information such as your IP address and browser type, processed in server logs by our hosting provider to keep the website secure and available.

We create your account using your email address and a password. We do not offer social or third-party sign-in (such as Google or Facebook), and we do not receive any data about you from such services.

Which data is required and which is optional

To create an account, take part in the VETInnovate project and receive a certificate, we need your name, email address, organisation, country and role, together with your assessment responses where a certificate is requested. If you do not provide these, we cannot create your account or issue your certificate. Providing this information is a requirement to take part in the Erasmus+ project, not a statutory obligation.

Why we use your data and our legal basis

We process your personal data for the following purposes, each with its legal basis under Article 6(1) GDPR:

  • Creating and managing your account and providing the services (including the self-assessment tool and certificates): performance of our agreement with you (Article 6(1)(b)).
  • Responding to messages you send through the contact form: performance of our agreement with you and our legitimate interest in answering enquiries (Article 6(1)(b) and (f)).
  • Keeping the website secure and available (including processing IP addresses in server logs to prevent abuse and troubleshoot problems): our legitimate interests in the security and integrity of the service (Article 6(1)(f)).
  • Reporting, monitoring and audit of the EU funding: compliance with a legal obligation (Article 6(1)(c)) — see “EU funding, monitoring and audit” below.

We do not knowingly collect special-category data (such as health data). If a specific activity ever required it, we would ask for it separately and rely on an appropriate condition under Article 9(2) GDPR.

EU funding, monitoring and audit

As a recipient of Erasmus+ funding, we have reporting, monitoring and audit obligations towards EU and national bodies. You are informed under Article 13(1)(e) GDPR that your personal data may be accessed by:

  • the competent Erasmus+ National Agency administering the grant;
  • the European Education and Culture Executive Agency (EACEA);
  • the European Commission;
  • the European Anti-Fraud Office (OLAF);
  • the European Court of Auditors; and
  • any external auditors or evaluators appointed by them,

solely for programme monitoring, financial control, audit and evaluation. The legal basis is compliance with a legal obligation, and where a partner is a public body, performance of a task in the public interest (Article 6(1)(c) and (e) GDPR). These obligations arise from Regulation (EU) 2021/817 establishing Erasmus+ and Regulation (EU, Euratom) 2018/1046 (the EU Financial Regulation) together with our grant agreement, and this use is a compatible purpose under Article 5(1)(b) GDPR. When EU institutions and bodies process your data, they do so under Regulation (EU) 2018/1725, and their own data-protection notices apply.

Who we share your data with

We do not sell your personal data and we do not use it for advertising. Besides the EU bodies described above, your data is processed only by:

  • our website hosting provider, which hosts the website and sends our service emails (such as account confirmations and certificates) on our behalf and under our instructions;
  • the providers of the website software and plugins we use to operate the site, where applicable and under our instructions.

These providers act as our processors and may use your data only to provide their service to us. We do not use third-party advertising networks or third-party analytics services (such as Google Analytics).

International data transfers

Your personal data is stored and processed on servers located within the European Union. We do not use third-party analytics or advertising that would transfer your data outside the European Economic Area (EEA). If, in future, any service provider we use is located outside the EEA, we will transfer your data only where an appropriate safeguard under Chapter V (Articles 44-49) GDPR is in place — such as a European Commission adequacy decision or Standard Contractual Clauses — and you may request a copy of the relevant safeguard.

Cookies

We use only the cookies necessary for the website to function and to remember your choices. These include a session/login cookie when you sign in, a cookie that remembers your language preference, and a cookie that records your cookie-consent choice. We do not use advertising cookies or third-party analytics or tracking cookies. If any non-essential cookie were ever introduced, it would be set only with your consent, which you can manage at any time through the cookie controls on the site.

How long we keep your data

We keep your personal data only for as long as necessary for the purpose it was collected, as set out below:

  • Account and profile data: for as long as your account remains active, and deleted within a reasonable period after you close your account or make a verified deletion request, unless a longer period is required under “Records required for audit” below.
  • Assessment and certification records: retained for the duration of the VETInnovate project, which ends in February 2028 (the project/grant end date is the criterion that sets this period), after which they are deleted or irreversibly anonymised and kept only in aggregate, non-identifying form for project reporting and statistics.
  • Server and security logs: kept by our hosting provider only for the limited period needed for security and troubleshooting, then deleted.
  • Records required for audit of EU funding: we are legally obliged, under the EU Financial Regulation (Regulation (EU, Euratom) 2018/1046) and our grant agreement, to retain certain records and supporting documents — which may include limited personal data — for five years after the final grant payment (three years for grants of EUR 60 000 or less) so that the European Commission, OLAF, the European Court of Auditors and other competent bodies can carry out checks and audits. Where this applies, we keep that data for the statutory period even after the project ends, restricted to audit purposes only.
  • Backups: residual copies in routine backups are overwritten on our normal backup cycle.

Your rights

Under the GDPR you have the right to:

  • Access your personal data and obtain a copy of it (Article 15).
  • Rectification of inaccurate or incomplete data (Article 16).
  • Erasure (“right to be forgotten”) where applicable (Article 17).
  • Restriction of processing in certain circumstances (Article 18).
  • Data portability — to receive data you provided in a structured, commonly used, machine-readable format where processing is based on consent or contract and carried out by automated means (Article 20).
  • Withdraw consent at any time where we rely on your consent, without affecting the lawfulness of processing before withdrawal (Article 7(3)).

You have the right to object, on grounds relating to your particular situation, at any time to processing based on our legitimate interests (Article 21 GDPR). If you object, we will stop unless we have compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.

You may ask us to delete your data at any time. We will comply unless we are required or permitted to keep it — for example to meet the EU audit obligation described above, or to establish, exercise or defend legal claims (Article 17(3) GDPR) — in which case we will tell you which data we must keep and why, and delete the rest.

To exercise any right, contact us at vetinnovateproject@gmail.com. We will respond within one month (Article 12(3) GDPR).

Automated decision-making

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).

Your right to complain

If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with a data-protection supervisory authority (Article 13(2)(d) GDPR). As the project is coordinated from Spain, you may complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD)www.aepd.es. You may also lodge a complaint with the supervisory authority in your own country of residence or work. A list of national authorities is available from the European Data Protection Board at edpb.europa.eu/about-edpb/about-edpb/members_en.

How we protect your data

We apply appropriate technical and organisational measures to keep your personal data secure, including access controls and encryption of data in transit (HTTPS), and protections against unauthorised access, loss or disclosure. No system is completely secure, but we work to protect your data and to address any incident promptly.

Children

Our services are intended for adult learners and professionals and are not directed at children. We do not knowingly collect data from children without appropriate consent.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and, where appropriate, notify you. Please check back periodically for the latest version.

Contact us

For any question about this policy or your personal data, or to exercise your rights, contact the VETInnovate consortium at vetinnovateproject@gmail.com.