Gestione Prove Valutative EMC

IT EN

Privacy and cookie notice

Version 1.0 — last update 04/10/2026.

Incomplete configuration: before production go-live the Coordinator must complete the Controller details and retention periods in the privacy configuration page.

This notice provides a concise description of the personal data processing carried out by the EMC proficiency-testing management portal.

Controller and contacts

ControllerTitolare del trattamento da completare
Controller emailTo be completed
AddressTo be completed
Privacy contactprivacy@example.com

Data processed, purposes and legal bases

The portal processes identification and professional data required for accounts and roles, work contact details, laboratory data, information required for tests and contractual/administrative procedures, bookings and sample logistics, operational notifications, application email records and security logs.

Purposes: authentication and access management; test organisation; participation and bookings; contractual/administrative procedures; logistics traceability; operational communications; security, audit and privacy-request management.

Legal bases configured by the Controller: Gestione contrattuale/precontrattuale della prova, legittimo interesse organizzativo e sicurezza del sistema.

Providing data required for the account and test participation is necessary to use the corresponding service functions; without those data the requested access or participation cannot be managed. No automated decision-making or profiling is performed.

Cookies and technical tools

Only technical cookies required for session management, security and language preference are used. No advertising, marketing or profiling cookies are used and, while this configuration remains unchanged, no consent banner is required.

NamePurposeDuration
csrftokenCookie tecnico di sicurezza usato per proteggere i form da richieste non autorizzate CSRF.Variabile secondo configurazione Django
django_languageCookie tecnico di preferenza che memorizza la lingua IT/EN scelta dall’utente; non svolge finalità statistiche, marketing o profilazione.180 giorni, salvo diversa configurazione
sessionidCookie tecnico necessario per mantenere la sessione autenticata e distinguere i ruoli utente.Sessione/browser, secondo configurazione Django

Recipients, processors and transfers

Data are accessible only to authorised persons according to their role and, where necessary, to technical providers such as hosting, email, backup, maintenance and helpdesk providers, to be managed as processors where the applicable conditions are met.

No extra-EEA transfers are currently shown in the configured provider register.

Retention periods

Data are kept for separate periods and no longer than necessary. Operational values can be configured by the Coordinator; longer retention must be based on legal obligations, the protection of legal rights or a documented hold.

CategoryPeriod/criterion
User accountsTo be configured; suggested operational value: 730 days
Participation and bookingsTo be configured; suggested operational value: 1825 days
Sample traceability historyTo be configured; suggested operational value: 1825 days
Contractual/administrative documents10 years where required for accounting/fiscal records or the protection of contractual rights; otherwise only for the time necessary for the relevant purpose.
Operational noticesTo be configured; suggested operational value: 365 days
Application email logsTo be configured; suggested operational value: 365 days
Security/audit logsTo be configured; suggested operational value: 365 days
BackupsTo be configured; suggested operational value: 30 days

Data-subject rights

You may request access, rectification, erasure where applicable, restriction, portability where applicable, objection or information about processing. Requests are handled without undue delay and generally within one month. You also have the right to lodge a complaint with the Italian Data Protection Authority.

Submit privacy request

Security and personal-data breaches

The portal applies role-based access controls and records relevant security and audit events. The Controller maintains internal procedures for backups, incident handling and assessment of any personal-data breach.