Privacy Policy
|
Controller and privacy contact Data Controller: University of Macedonia Address: 156 Egnatia Street, 546 36 Thessaloniki, Greece VOLUNTEER II project contact: volunteer2@gmail.com Data Protection Officer: dpo@uom.edu.gr | +30 2310 891 901 Effective date: 16 July 2026 | Version 1.0 |
1. Purpose and scope
This Privacy Policy explains how the University of Macedonia processes personal data when you visit the official VOLUNTEER II website, contact the project team, subscribe to project updates, register for project activities, interact with website features or follow links to the project’s official social media pages.
It provides information in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), applicable Greek data-protection and electronic-communications legislation, and relevant guidance from the competent supervisory authorities.
2. Data Controller and contact details
Data Controller: University of Macedonia
Postal address: 156 Egnatia Street, 546 36 Thessaloniki, Greece
VOLUNTEER II project contact: volunteer2@gmail.com
Data Protection Officer of the University of Macedonia: dpo@uom.edu.gr | +30 2310 891 901
3. Personal data we may process
Depending on the website features and project activities used, the following categories of personal data may be processed:
• Technical and log data, such as IP address, date and time of access, requested page, browser type, device information, operating system, referrer, error records and security events.
• Contact data and message content, such as name, email address, organisation, subject and any information voluntarily included in a contact-form message or email.
• Newsletter data, where the newsletter feature is activated, such as name, email address, subscription status, consent record, delivery status and unsubscribe information.
• Cookie and preference data, such as consent choices and identifiers generated by necessary or optional cookies and similar technologies.
• Event or activity data, where online registration is available, such as contact details, organisation, attendance preferences and information required for project administration, accessibility or participation.
• Social media interaction data made available to page administrators by the relevant platform, such as public profile information, comments, messages, reactions and aggregated page insights.
Please do not submit special-category or highly sensitive personal data through the general contact form or ordinary email unless specifically requested through an approved and secure process.
4. Purposes and legal bases
Personal data are processed only where a lawful basis applies and only for the purposes described below.
| Purpose | Data involved | Legal basis | |
| Operate, secure and maintain the website; prevent misuse and investigate technical incidents | Technical and log data | GDPR Article 6(1)(e) – performance of a task carried out in the public interest; and Article 6(1)(c) where a legal obligation applies | |
| Respond to enquiries and manage project communications | Contact details and message content | GDPR Article 6(1)(e) – performance of a task carried out in the public interest | |
| Send newsletters or project updates | Subscriber data and consent records | GDPR Article 6(1)(a) – consent | |
| Manage event registrations and participation | Registration, attendance and accessibility data | GDPR Article 6(1)(e); and consent where optional information requires it | |
| Store optional analytics, media or other non-essential cookies | Cookie identifiers and usage data | GDPR Article 6(1)(a) – consent, together with applicable electronic-communications rules |
|
Comply with legal, funding, audit and records-management obligations |
Relevant records and project evidence |
GDPR Articles 6(1)(c) and 6(1)(e) |
|
Protect legal rights and information systems |
Relevant contact, log and security data |
Applicable legal obligation and/or public-interest basis |
5. Cookies and similar technologies
The website may use strictly necessary cookies to provide core functions, maintain security and store privacy preferences. These cookies do not require consent where they are essential for the operation of the website.
Optional analytics, media, social or marketing technologies must not be activated unless the user has given valid prior consent through the cookie-preference mechanism. Users must be able to accept or reject non-essential cookies and change their preferences at any time through the Cookie Settings link.
The current cookie list, including provider, purpose, category and duration, should be displayed in the website cookie settings or a dedicated Cookie Policy and updated whenever the technical configuration changes.
6. Contact forms and email
When you contact the project through a website form or by email, the information you provide is used to review and respond to your request, route it to the appropriate project partner and maintain a record where necessary for project administration, security or accountability.
Messages sent to volunteer2@gmail.com are processed through Google’s Gmail service. Google may process technical and account-related data in accordance with its applicable service and privacy terms. Users should avoid sending confidential, sensitive or special-category personal data through ordinary email unless specifically requested and appropriate safeguards are in place.
7. Newsletter subscriptions
If the newsletter function is activated, subscription is voluntary and based on consent. The subscription form will explain the type of communications sent, identify the Data Controller, link to this Privacy Policy and provide an easy unsubscribe option in every message.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. A confirmation or double opt-in process may be used to verify the subscription request
8. Social media
The website may link to official VOLUNTEER II pages on Facebook, Instagram and LinkedIn. If you follow a link or interact with those pages, the relevant platform processes personal data under its own terms and privacy policies. Platform operators may use cookies, account information, device data and interaction data for their own purposes.
Project page administrators may receive messages, comments, reactions, public profile information and aggregated statistics made available by the platform. Users should review the privacy settings and policies of each platform before interacting.
Embedded social-media feeds, tracking pixels or third-party social plugins will be used only after an appropriate legal and technical review and, where required, prior user consent.
9. Recipients and service providers
Personal data may be accessed only where necessary by authorised personnel of the University of Macedonia, authorised members of the VOLUNTEER II project team and project partners who need the information for the relevant project purpose.
Data may also be processed by service providers supporting website hosting, technical maintenance, cybersecurity, backups, email, newsletter delivery, analytics, event management, anti-spam or other project functions. Such providers are required to process data only for authorised purposes and under appropriate contractual, confidentiality and security obligations.
Personal data may be disclosed to public authorities, courts, auditors, Programme bodies or other recipients where disclosure is required by law, funding rules, an official request or the protection of legal rights.
10. International data transfers
The University of Macedonia seeks to use service providers that process personal data within the European Economic Area where reasonably possible. Some cloud, email, social media or technical service providers may process data in countries outside the European Economic Area.
Where an international transfer takes place, the University of Macedonia will rely on an applicable lawful transfer mechanism, such as an adequacy decision, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses and any necessary supplementary measures.
11. Retention periods
Personal data are kept only for as long as necessary for the relevant purpose and for any applicable legal, funding, audit, security or records-management obligations. The following retention criteria apply:
• Server and security logs: for a limited period determined by technical and security needs, normally no longer than 12 months, unless a longer period is required for an active incident investigation or legal obligation.
• Contact-form messages and enquiries: normally up to 24 months after the request is closed, unless a longer period is required for project administration, funding obligations or legal claims.
• Newsletter subscriber data: until consent is withdrawn or the newsletter service ends. A minimal suppression record may be kept to ensure that an unsubscribe request is respected.
• Cookie-consent records: for the period necessary to demonstrate and manage consent and to comply with applicable legal obligations.
• Event registrations and attendance evidence: for the project implementation and mandatory Programme audit period, with non-essential personal data deleted or anonymised earlier where possible.
• Project evidence and statutory records: for the period required by applicable law, Programme rules, funding, audit and records-management obligations.
12. Security
The University of Macedonia applies appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure or destruction. Measures may include access controls, secure administration, software updates, backups, encrypted transmission, logging, incident management and oversight of service providers, proportionate to the risks and the nature of the data processed.
No internet service can be guaranteed to be completely secure. Users should avoid sending sensitive information through ordinary email or general website forms.
13. Your rights
Subject to the conditions and limitations of the GDPR, you may have the right to:
• request access to your personal data and information about their processing;
• request correction of inaccurate or incomplete data;
• request erasure of personal data where the legal requirements are met;
• request restriction of processing;
• object to processing based on the performance of a task carried out in the public interest, where applicable;
• receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
• withdraw consent at any time where processing is based on consent; and
• not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.
14. How to exercise your rights
Requests concerning personal data may be sent to volunteer2@gmail.com or to the Data Protection Officer of the University of Macedonia at dpo@uom.edu.gr. Additional information may be requested only where necessary to verify identity and protect personal data. Requests are handled within the time limits provided by applicable law.
15. Right to lodge a complaint
If you believe that your personal data have been processed unlawfully, you may first contact the University of Macedonia or its Data Protection Officer. You also have the right to lodge a complaint with the Hellenic Data Protection Authority:
Hellenic Data Protection Authority, 1-3 Kifissias Avenue, 115 23 Athens, Greece | Telephone: +30 210 6475600 | Email: contact@dpa.gr | Website: www.dpa.gr
16. Children and young people
The website provides general public information and is not intended to collect personal data directly from children through general forms. Where a project activity, educational action, competition, event or media activity involves minors, a separate activity-specific privacy notice and any necessary parental or guardian authorisation will be provided before data are collected or images are published.
17. Automated decision-making
The website does not use personal data for automated decision-making or profiling that produces legal or similarly significant effects. If this changes, this Privacy Policy will be updated before such processing begins.
18. Third-party websites
This Privacy Policy does not apply to external websites or services linked from the VOLUNTEER II website. Users should read the privacy information of the relevant third party before providing personal data or using its services.
19. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect changes in the website, project activities, service providers, cookies, applicable law or guidance. The current version and effective date will be published on this page. Material changes will be communicated through an appropriate website notice where necessary.
20. Contact
For privacy questions or to exercise your rights, please contact:
VOLUNTEER II project contact: volunteer2@gmail.com
Data Protection Officer of the University of Macedonia: dpo@uom.edu.gr | +30 2310 891 901
Postal address: University of Macedonia, 156 Egnatia Street, 546 36 Thessaloniki, Greece.