Privacy and cookie notice
Version 1.0 — last update 04/10/2026.
Incomplete configuration: before production go-live the Coordinator must complete the Controller details and retention periods in the privacy configuration page.
This notice provides a concise description of the personal data processing carried out by the EMC proficiency-testing management portal.
Controller and contacts
| Controller | Titolare del trattamento da completare |
|---|---|
| Controller email | To be completed |
| Address | To be completed |
| Privacy contact | privacy@example.com |
Data processed, purposes and legal bases
The portal processes identification and professional data required for accounts and roles, work contact details, laboratory data, information required for tests and contractual/administrative procedures, bookings and sample logistics, operational notifications, application email records and security logs.
Purposes: authentication and access management; test organisation; participation and bookings; contractual/administrative procedures; logistics traceability; operational communications; security, audit and privacy-request management.
Legal bases configured by the Controller: Gestione contrattuale/precontrattuale della prova, legittimo interesse organizzativo e sicurezza del sistema.
Providing data required for the account and test participation is necessary to use the corresponding service functions; without those data the requested access or participation cannot be managed. No automated decision-making or profiling is performed.
Cookies and technical tools
Only technical cookies required for session management, security and language preference are used. No advertising, marketing or profiling cookies are used and, while this configuration remains unchanged, no consent banner is required.
| Name | Purpose | Duration |
|---|---|---|
| csrftoken | Cookie tecnico di sicurezza usato per proteggere i form da richieste non autorizzate CSRF. | Variabile secondo configurazione Django |
| django_language | Cookie tecnico di preferenza che memorizza la lingua IT/EN scelta dall’utente; non svolge finalità statistiche, marketing o profilazione. | 180 giorni, salvo diversa configurazione |
| sessionid | Cookie tecnico necessario per mantenere la sessione autenticata e distinguere i ruoli utente. | Sessione/browser, secondo configurazione Django |
Recipients, processors and transfers
Data are accessible only to authorised persons according to their role and, where necessary, to technical providers such as hosting, email, backup, maintenance and helpdesk providers, to be managed as processors where the applicable conditions are met.
No extra-EEA transfers are currently shown in the configured provider register.
Retention periods
Data are kept for separate periods and no longer than necessary. Operational values can be configured by the Coordinator; longer retention must be based on legal obligations, the protection of legal rights or a documented hold.
| Category | Period/criterion |
|---|---|
| User accounts | To be configured; suggested operational value: 730 days |
| Participation and bookings | To be configured; suggested operational value: 1825 days |
| Sample traceability history | To be configured; suggested operational value: 1825 days |
| Contractual/administrative documents | 10 years where required for accounting/fiscal records or the protection of contractual rights; otherwise only for the time necessary for the relevant purpose. |
| Operational notices | To be configured; suggested operational value: 365 days |
| Application email logs | To be configured; suggested operational value: 365 days |
| Security/audit logs | To be configured; suggested operational value: 365 days |
| Backups | To be configured; suggested operational value: 30 days |
Data-subject rights
You may request access, rectification, erasure where applicable, restriction, portability where applicable, objection or information about processing. Requests are handled without undue delay and generally within one month. You also have the right to lodge a complaint with the Italian Data Protection Authority.
Submit privacy requestSecurity and personal-data breaches
The portal applies role-based access controls and records relevant security and audit events. The Controller maintains internal procedures for backups, incident handling and assessment of any personal-data breach.