WebNIR

Web tools for the assessment of occupational exposure to Non-Ionizing Radiation

GDPR

Information on the processing of personal data pursuant to EU Regulation 2016/679

Introduction

This document explains what information is collected when you visit our website, as well as how and why this information comes collected and used. We take your privacy seriously and are proactive in ensuring the necessary steps are taken to protect your data personal.

This information is provided only for this site and not for other websites that may be consulted via links contained herein site.

This information complies with the Guidelines for Public Websites administration.

In the following, WebNIR refers to WebNIR. Strumenti Web per la valutazione dell'esposizione occupazionale alle Radiazioni Non Ionizzanti.

Contacts

  1. Data controller: National Research Council (CNR), Piazzale Aldo Moro, 7 - 00185 Rome, Italy, contact e-mail: privacy@cnr.it;
  2. CNR Data Protection Officer: Ing. Raffaele Conte, e-mail from contact: rpd@cnr.it;
  3. Internal CNR–IFAC manager: the Director of the Institute, e-mail from contact: direttore@ifac.cnr.it.

TYPES OF DATA PROCESSED

Navigation data

The IT systems and applications dedicated to its operation website detect, during their normal operation, some data (which transmission is implicit in the use of Internet communication protocols) not associated with directly identifiable users.

The data collected includes the IP addresses of the computers used from users who connect to the site, the addresses in URI (Uniform Resource Identifier) of the requested resources, the time of the request, the method used in submitting the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given from the server (success, error, etc.) and other parameters relating to the system operating and the IT environment used by the user.

This data is processed for the time strictly necessary and only in order to obtain anonymous statistical information on the use of the site and for check its regular functioning.

USE OF COOKIES AND OF BROWSER STORAGE

What cookies are

Cookies are (name, value) pairs that a website has the browser store, and that the browser sends back with every later request. They serve, for instance, to keep the site from forgetting that you have already signed in to a restricted area while you move from one page to the next.

Which cookies this site uses

This site uses technical cookies only, that is, those strictly necessary to provide the service the user asked for. It does not profile users, does not collect browsing statistics, hosts no third-party cookies and uses no advertising or audience-measurement tool. This is the complete list:

NamePurposeCreated whenLifetime
PHPSESSID Holds together the requests of one visit: chosen language, access profile, protection of forms against forged submissions. On the first page opened. Until the browser is closed; data on the server expire after 12 hours of inactivity.
remember Recognises those who asked to stay signed in, without asking for the credentials again. It holds two random values; only the digest of the second is kept in the database, so its content cannot be reused by anyone reading the database. The password never goes into a cookie. Only if stay signed in is ticked when signing in. 10 days, and it is deleted on sign-out.
cookie_notice Remembers that the opening notice has been read, so it is not shown again on every page. When the notice is closed. 180 days.

Browser local storage

Some pages keep display preferences in the browser's local storage. Unlike cookies, these data are never sent to the site: they stay on the device and only serve to find things as they were left.

ItemWhereContentLifetime
csrf_reload All pages. One instant in time, to keep a page from reloading in a loop when the form protection expires. Until the tab is closed.
gestdb_load Restricted area, database management. One query passed from a page to the next. Deleted right after being read.

They are cleared from the browser together with the site data.

Connections to other sites

Pages are served entirely by this site: scripts, stylesheets, fonts and images do not come from external services. Opening a page therefore discloses the IP address to no third party, and no content is embedded from other sites. External links appearing in the texts open only if the user chooses them.

Why no consent is requested

Technical cookies require no consent under Article 5(3) of Directive 2002/58/EC, Article 122(1) of the Italian Personal Data Protection Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021. Since no consent is collected, there is no choice to change or to withdraw, and the notice shown on the first visit is there only to inform. Should the site ever adopt non-necessary tools, a real consent request would appear, with the possibility of refusing and of changing one's mind at any time.

How to prevent storage

Anyone who prefers to have nothing stored can block cookies in their own browser, following the vendor's instructions:

Public pages remain readable. Access to the restricted area, however, is not possible without the session cookie: that is what keeps the sign-in valid from one page to the next.

Personal data: collection and use

While using our website, you may be asked to provide personal data (name, address, e-mail, account details, etc.). Self if requested, we will use this data to administer the processes and the databases of our website which guarantee the possibility of taking advantage of the program developed within the project WebNIR. We will ensure that all personal data provided is stored securely in accordance with the General Protection Regulation of data (EU) 2016/679.

User Rights

As a user you can verify the details you have sent to CNR-IFAC by contacting us at the following e-mail address: direttore@ifac.cnr.it.

Our security procedures mean that we may require proof identity before revealing information, including your e-mail address.

You can also contact us with the same method to modify, correct or request that your personal data be deleted in relation to to the aforementioned accounts at any time. For your convenience, this may be performed independently using the appropriate interface, executing the log in with your e-mail address.

Please note, however, that if you have shared data with others through i social media channels, such data may remain visible, even if your account has been deleted on our site.

You can request a readable copy of the personal data we hold at any time and this request will be processed within one month (a provided that there are no excessive burdens and that it does not compromise the privacy of other people). To do this, please contact us at the following address e-mail: direttore@ifac.cnr.it.

As a user you can request that your data be transferred to another system.

What data do we collect?

We collect the following personal data from those who decide to register to take advantage of the processing programs:

  1. Name and surname
  2. E-mail
  3. Name and address of the belonging
  4. Telephone

Why is this data collected?

We collect personal information for allow the authenticated user, within the scope of the project WebNIR:

  • to access sections of the site not open to the public
  • upload data to the database and the CNR-IFAC server
  • consult confidential data

How will the data be stored?

The data will be stored in the project management database WebNIR, which resides on our server.

Treatment methods

CNR–IFAC adopts all the safety measures required by the Regulation (EU) No 2016/679 to protect the data collected, in order to avoid the risks of loss or theft of data, unauthorized access, illicit and incorrect use.

How will the collected data be used?

Names and addresses will be used solely for the purposes declared by CNR–IFAC and will not be made available for any other purpose or to any other party, excluding legal obligations.

How long do we keep your data?

CNR–IFAC will not retain your personal data for the purpose of carrying out of the research activity and in any case for a period not exceeding 5 years from project closing date WebNIR (31/05/2025). If required by law or if reasonably necessary to satisfy the regulatory requirements, resolve disputes, prevent fraud and abuse, or enforce our policies, we may retain some of your data for a period limited time, even after closing the relevant account.

Optional nature of data processing

Apart from what is specified for navigation data, the provision of data through this website, or communications transmitted on a basis voluntary by the user himself to CNR–IFAC, it is always optional in nature; however, in case of failure to provide the data marked as mandatory, CNR–IFAC will not be able to provide the User with the service required, in this case participation in the WebNIR project.

Right to update our privacy policy

It should be noted that in order to constantly comply with the law and indications of the CNR headquarters we are constantly reviewing how we process and we protect the data. Therefore, changes to our policy may occur at any time.

Complaints and disputes

Complaints or questions relating to data protection and privacy must be addressed to the data protection officer of the CNR, e-mail of contact: rpd@cnr.it.

There is also the right to lodge a complaint with the Authority national control body (Guarantor for the protection of personal data).

Keywords: GDPR