Privacy Notice for Operations Portal - EOSC Instance

- Last update : 07/10/2022
Name of the Service Operations Portal
Description of the Service The Operations Portal service (hereinafter referred to as: “the service” or “Operations Portal”) is composed of 2 parts :
  • the EOSC Metrics portal which is a portal aggregating data from Google Analytics and Jira Helpdesk system . These figures are consolidated and provided through different tables and reports . The final aim of this portal is to create automatically reports for EC commission.
  • And the second part The Service Order Management Back Office [SOMBO] which is a tool design to track trace of all the orders received by the marketplace and to propose different actions on these orders .

This privacy notice describes how we, the EGI Foundation (hereinafter referred to as "we" or "the Data Controller"), collect and process data by which you can be personally identified (“Personal Data”) when you use the service.
Data Controller EGI Foundation
Science Park 140
1098 XG Amsterdam
Netherlands.
Data protection officer EGI Foundation Data Protection Officer
Science Park 140
1098 XG Amsterdam
Netherlands
E-mail: dpo@egi.eu
Jurisdiction and supervisory authority Jurisdiction: NL, Netherlands EGI Foundation's lead supervisory authority is the Dutch Data Protection Authority.
They can be contacted at : https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-us
Personal data processed The service may process the following personal data:

Identification data:
  • Name
  • Identification number
  • E-mail address
  • Affiliation

Behavioural data:
  • Usage data
  • Technical logs with timestamps

Data allowing conclusions on the personality:
  • Memberships
  • Information about group/VO membership
Purpose of the processing of personal data The purpose of the collection, processing and use of the personal data mentioned above is:

  • To provide the service functions, i.e. to identify users and provide access to the tools with the proper access levels..
  • To monitor and maintain service stability, performance and security
Legal basis The legal basis for processing personal data is: Legitimate interests pursued by the controller or by a third party according to Art. 6 (1) (f) GDPR. Personal data will not be used beyond the original purpose of their acquisition.
If a forwarding to third parties should be necessary to answer an inquiry or to carry out a service, the consent of the data subject is considered to have been given when using the respective function or service.

In particular, the data you provide to us will not be used for marketing.
For the purposes given in this privacy policy, personal data may be passed to the following third parties:

Within the EU / EEA:
  • CNRS (CC-IN2P3, resource provider, sub-contracted data processor)
  • Users of the Operations Portal can access different data depending on their role
  • The records of your use and technical log files produced by the Service components may be shared, via secured mechanisms, for security incident response purposes with other authorised participants in the academic and research distributed digital infrastructures authorised by EOSC Future governance, only for the same purposes and only as far as necessary to provide the incident response capability where doing so is likely to assist in the investigation of suspected misuse of Infrastructure resources.
Outside the EU / EEA:
  • Users of the Operations Portal can access different data depending on their role
Any data transfer to a third country outside the EU or the EEA only takes place under the conditions contained in Chapter V of the GDPR and in compliance with the provisions of this privacy policy.
Your rights You can exercise the following rights at any time by contacting our data protection officer using the contact details provided in the Data Protection Officer section:
  • Information about your data stored with us and their processing
  • Correction of incorrect personal data
  • Deletion of your data stored by us
  • Restriction of data processing, if we are not yet allowed to delete your data due to legal obligations
  • Objection to the processing of your data by us
  • Data portability


You can complain at any time to the supervisory data protection authority (DPA) responsible for you. Your responsible DPA depends on your country and state of residence, of your workplace or of the presumed violation.
A list of the supervisory authorities with addresses can be found at https://edpb.europa.eu/about-edpb/board/members_en. You can contact EGI Foundation's lead supervising authority using the contact details provided in the Jurisdiction and Supervisory Authority section.
Data retention and deletion The records of your use and technical log files produced by the service components will be deleted or anonymised after, at most, 18 months
Security We take appropriate technical and organisational measures to ensure data security and the protection against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access.
Based on AARC Policy development kit (licenced under CC BY-NC-SA 4.0)