Back

Terms and conditions | Privacy policy

The present Privacy Policy applies to all Users of the website (https://ai-pioneers-natural-disasters.scify.org/) (hereinafter referred to as the “Users” or the “User” and “Platform” respectively) and forms an integral part of the Platform’s Terms and Conditions. The present Privacy Policy provides the User with general information regarding how the Data Controller uses your personal data and other information required by data protection legislation. In case of future amendment, the User will be provided with necessary updates and information through the update of the present Privacy Policy, uploaded in the Platform.

1. Who is the Data Controller?

1.1. The Company with the company name “SCIENCE FOR YOU” PNPC – SciFY, address: TEPA Lefkippos – NCSR Demokritos / 27, Neapoleos str., 153 41 Ag. Paraskevi, Greece, Telephone: +30 211 400 4192, email: info@scify.org, is the Data Controller for the processing of the User’s Personal Data (hereinafter referred to as “Data Controller”).

1.2. Data Controller’s Contact details: For any issue or concern with regards to the present Privacy Policy and to the processing of User’s personal data or data uploaded by the User to use the Platform, the User can communicate with the Data Controller, by using one of the following alternatives:

By calling at +30 211 400 4192, from Monday to Friday from 09.00 a.m. to 17.00 p.m. EET (Eastern European Time)

By sending an email at the following email address: info@scify.org

By sending correspondence to the following address: TEPA Lefkippos – NCSR Demokritos / 27, Neapoleos str., 153 41 Ag. Paraskevi, Greece

2. What is the purpose and the legal basis for User’s data processing?

2.1. The platform’s operational purpose is to educate the Users on the use of AI for the prevention or response to Natural Disasters.

2.2 Legal basis for processing

The processing of personal data is based on:

(a) Performance of a contract (Article 6(1)(b) GDPR), namely for the creation and management of the User’s account, provision of access to the educational platform, monitoring of course progress, communication related to participation, and issuance of certificates of completion.

(b) Compliance with legal obligations (Article 6(1)(c) GDPR), including tax, accounting and other statutory obligations.

(c) User consent (Article 6(1)(a) GDPR), where applicable (e.g. installation of non-essential cookies, subscription to newsletters).

(d) Legitimate interests (Article 6(1)(f) GDPR), such as ensuring platform security, preventing fraud, and improving the quality of services, provided such interests do not override the fundamental rights and freedoms of Users.

3. Types of data collected

3.1 Personal data

3.1.1 Registration in Data Controller’s lists:

In order for a User to voluntarily receive news from the Data Controller and make use of the Platform, the User should fill in the necessary data: email address, their First and Last Name.

3.1.2. Platform’s communication for reasons related to User’s permitted use of the Platform.

In order for the Platform to communicate with the User for the above purposes, the Data Controller can process all data relating to the User’s registration, uploaded content and data related to the User’s use of the Platform.

3.1.3 Educational and participation data
The Platform processes data related to the User’s participation in the educational programme, including:

  • Course enrollment status
  • Course progress and completion data
  • Assessment or quiz results (where applicable)
  • Challenge interest submission data
  • Certificate issuance records

Such data are necessary for the provision of the educational services and the certification process.

3.1.4 Challenge participation data

In case the User submits an expression of interest or application for participation in AI Challenges, the Platform may process additional information provided voluntarily by the User, such as academic background, skills, motivation statements, or other relevant information necessary for the evaluation and selection process.

3.2 Usage data

We may also collect information on how the webpage is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our webpage that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

4. How the Platform collects data

4.1 The information can be collected by the following ways:
4.1.1 The User accessing the Platform
4.1.2 The User registration in Data Controller’s emailing lists

4.1.3 When the User visits the Platform and agrees to the installation of cookies (in accordance with the Platform’s Cookies Policy in article 11 below) and the collection of the User’s personal data such as IP address, operating system, browser type and version, etc.

5. How long are User’s data stored and when are they deleted?

5.1. User’s registration data:
Without prejudice to User’s deletion/erasure right mentioned below, the Data registered and stored in the User’s registration will be stored as long as the User wishes to make use of the Platform for the purpose mentioned above. In case a User wishes to delete their registration, they can delete their registration through registration’s settings or contact the Data Controller at the above-mentioned contact details.

5.2. Platform’s communication for reasons related to User’s permitted use of the Platform.
Data related to such communication will be stored only as long as the User wishes to use the Platform and maintains their registration. In case a User wishes to delete their registration, they can delete their account through registration’s settings or contact the Data Controller at the above-mentioned contact details.

5.3. Statistical analysis for the optimization of the Website
Regardless of the above-mentioned provisions of article 5, the Data Controller will store and process only necessary data for the period required in order to comply with its obligations imposed by law each time (compliance with fiscal obligations etc).

5.4. Processing of personal data for the purposes of conducting statistical analysis.
Please see cookies policy (article 11) below.

5.5 Specific retention for educational records

Data related to course completion and certificate issuance may be retained for a longer period where necessary for verification purposes, academic integrity, or compliance with funding and audit obligations.
In any case, personal data will not be retained longer than necessary for the purposes for which they were collected, unless required by applicable law.

6. What are User’s rights in relation to the processing of his data and how can he exercise these rights?

6.1 The Data Controller respects User’s right in relation to data processing.

6.2 The User can exercise their rights by contacting the Data Controller at the following contact details: address: TEPA Lefkippos – NCSR Demokritos / 27, Neapoleos str., 153 41 Ag. Paraskevi, Greece, Telephone: +30 211 400 4192, email: info@scify.org.

For User’s facilitation, User’s rights are included in the following table along with a short explanation of each right (reference to articles corresponds to article of GDPR 2016/679):

RightExplanation
Access (article 15)The User can ask the Data Controller to:confirm whether the Data Controller processes User’s personal datagive the User access to data that the User does not disposegive the User other information related to User’s personal data such as which are the data that the Data Controller disposes, what are the purposes of processing, to whom are these data disclosed, whether these data are transferred in foreign countries and how are these data protected, how long are the data stored, what are the User’s rights, how can a complaint be lodged, where were the data taken from to the extent this information is not included in the present Privacy Policy.
Rectification (article 16)The User can ask the Data Controller to rectify inaccurate personal data.The Data Controller can seek to verify the accuracy of the data before rectifying them.
Erasure/deletion (article17)The User can ask the Data Controller to erase their personal data:whenever, when the personal data are no longer needed for the purposes for which they were collectedwhen the User withdraws their consentthe personal data have been unlawfully processedThe Data Controller is not obliged to comply with User’s request to erase their personal data, if the processing of User’s personal data is necessary:
– for compliance with a legal obligation
– for the fulfillment of another legitimate purpose or another legitimate legal basis
– for the establishment, exercise or defense of legal claims
Restriction (article 18)The User can ask the Data Controller to restrict (store but not process) User’s personal data when:their accuracy is contested (see rectification), so that the Data Controller can verify the accuracy of the personal data orthe personal data have been unlawfully processed but the User opposes the erasure of the personal data orthey are no longer necessary for the purposes for which they were collected but the User still needs them for the establishment, exercise or defense of legal claims or there is another legitimate purpose of processing or other legal basis.
Data portability (article 20)When processing is based on consent and the processing is carried out by automated means, the User can ask the Data Controller to receive their personal data in a structured commonly used and machine-readable format or ask the Data Controller to transmit them to another controller directly from the Data Controller. Nevertheless, according to the law, this right refers only to those data that have been given by the User themselves and not to those data that are inferred by the Data Controller based on the data that the User has provided.
Objection (article 21)The User can object at any time to the processing of personal data concerning them which is based on legitimate interest or performance of a task carried out in the public interest.When the User exercises their right to object, the Data Controller has the right to demonstrate compelling legitimate grounds for the processing that override the interest, rights and freedom of the User or for the establishment, exercise or defense of legal claims.
Consent withdrawal (opt-out)The User has the right to withdraw their consent where consent is the basis of processing. Withdrawal is valid for the future.
Supervisory AuthorityThe User has the right to lodge a complaint with the local supervisory authority related to data protection.In Greece the supervisory authority for Data Protection is Data Protection Authority https://www.dpa.gr/
IdentityThe Data Controller takes seriously the confidentiality of all files that include personal data; thus, they are entitled to ask the User proof of their identity if the User submits a request in relation to those files.
CostThe User will not have to pay for the exercise of their rights in relation to personal data unless as provided by law, the request to acquire access to information is unfounded or excessive. In that case the Data Controller can charge the User with a reasonable fee under the specific circumstances. The Data Controller will inform the User of any possible charge before they complete the request.
TimetableData Controller aims at answering at User’s valid requests the latest within one (1) month from their receipt, unless the request is extremely complicated or the User has submitted multiple requests, in which case the Data Controller aims at answering to them within three months. In case the Data Controller needs more than one month for the reasons above mentioned, they will inform the User. The Data Controller may ask the User if they want to explain what exactly they wish to receive or what their concern is. This will help the Data Controller to act more quickly in relation to the User’s request. In any case the User should mention specific and true data and/or facts so that the Data Controller can answer and/or satisfy accurately to the User’s request. Otherwise, the Data Controller reserves their right for any faults that are outside of his control. Additionally, the Data Controller can reject requests that are unfounded, excessive, abusive, made in bad faith or are illegitimate in the framework of the legal provisions.

7.How is data security safeguarded?

7.1 The Data Controller implements all appropriate security measures to ensure protection and confidentiality of personal data among which the following are included:

  1. Strong password policies in all servers
  2. HTTPS protocol for interacting with APIs and Web clients
  3. SSH protocol for server connection
  4. Periodical server updates with latest security fixes

7.2 Please note that only specifically authorized employees of the Data Controller, acting under the authority of the Data Controller and only on their instructions as well as recipients, where necessary, handle the data submitted by the User. For the processing, the Data Controller chooses persons with appropriate qualifications that have sufficient safeguards as to technical knowledge and personal integrity to protect confidentiality. The Data Controller takes all necessary security measures for the protection and safeguard of secrecy, confidentiality and integrity of personal data also through relevant contractual commitments of their associates. In any case the security of the Website may be infringed due to reasons that reside outside of the Data Controller control sphere as well as due to technical or other problems of the net or force majeure or accidental facts. In that case, the security of personal data cannot be guaranteed.

8. Who are the recipients of data?

8.1 The recipients of User’s personal data are associate companies that provide technical infrastructure for the operation of the Website, hosting provider as well as the company that undertakes to send electronic communication related to the operation of the Platform to Users. Where necessary as per applicable laws, the Data Controller will sign agreements with such companies, which refer to the implementation and regular monitoring of security measures. In case third-party service providers (e.g. hosting providers, analytics providers, email communication services, embedded video services such as YouTube) are located outside the European Economic Area (EEA), any transfer of personal data is carried out in accordance with applicable data protection legislation, including the use of Standard Contractual Clauses (SCCs) or other appropriate safeguards as required under Chapter 5 of the GDPR.

8.2. In case the Data Controller receives a request to notify or transfer data following a request by the appropriate Administrative Authority, Attorney, Court or other Authority, they may notify / transfer those data in order to fulfill their duty executed in favor of the public interest towards these authorities (with or without User’s previous notification) in accordance with the appropriate legal provisions. If the User should be previously notified in accordance with the legal provisions, then the User has the right to object to this processing as provided in article 7 above.

8.3. Αs to the professional details of each User, they are available to all registered Users of the Platform for the purposes mentioned above.

9. Communication with the Data Controller


9.1. For any issue related to the present privacy policy, User’s data processing as well as exercise of User’s rights, the User can contact the Data Controller using one of the following ways:
Telephone: +30 211 400 4192
Email: info@scify.org
In case the User becomes aware of any data breach incident, they are kindly requested to notify the Data Controller immediately.

9.2. The present terms are governed and supplemented by the Terms and Conditions and consist along with them a uniform text.

10. Connection to other Websites/social media

This Website connects with other websites through hyperlinks. These websites are not related to the Data Controller’s Website and their content is neither checked nor recommended by the Data Controller. Thus, the accuracy, legitimacy, completeness or quality of their content and legitimacy of the processing of User’s personal data cannot be checked and no guarantee is provided for them. The Data Controller cannot be held liable for them or any damage that may be caused to the User due to or following their use. The Data Controller cannot check the processing of the User’s personal data by those linked Websites and thus does not bear any liability. When the User accesses those websites they should take under consideration that terms and conditions of each website apply. For any issue that may occur as to the content or the use of the linked website, the User should directly contact the operator or administrator of each website. The Data Controller does not approve or embrace the Content or the services of the linked websites, which the User accesses through the Website.

The Website gives the User the possibility to connect and interact with social media following their own initiative and will. In that case the Data Controller is not liable for the processing of User’s data taking place through or by the social media. The User should directly address each specific social media in order to exercise their legitimate rights.

11. Cookies

11.1. The Platform uses cookies to be operational or more efficient in its operation, to improve User’s navigation, to provide User with the full potential of the Platform, to ensure the correct display of the content as well as for analytical and statistical purposes.

11.2. Cookies are small text files stored on a User’s computer when they visit a digital platform, which are used as a means of identifying their computer.

11.3. Cookies apart from absolutely necessary cookies are only installed if the User accepts their installation when they visit this Platform. By accepting cookies when entering this Platform, the User expressly states that they have read and understood the specific terms and conditions regarding the installation, function and purpose of the cookies and that they provide their consent for their use.

11.4. Alternatively, the User may not accept cookies. In this case, only cookies that are technically and functionally necessary for the operation of the Platform will be installed.

11.5. The User can manage the use and installation of cookies at any time through a panel, where they can choose which category of cookies they want to accept and which ones not (or request to install only the technically necessary cookies).

11.6. In particular, the cookies used by the Platform are the following:

11.6.1 Absolutely Necessary Cookies

The absolutely necessary cookies are essential for the proper operation of the Platform. These cookies allow Users to browse and use Platform features such as access to secure areas. These cookies do not recognize User’s individual identity and without them, the smooth operation of the Platform is not possible.

CookieDescriptionDurationTransfer of data to third parties
lp_session_guestA functional cookie set by the LearnPress LMS plugin to maintain a temporary session for guest (non-logged-in) users. It enables course interactions such as quizzes, progress tracking, and AJAX actions during the visit. This cookie does not store personal data and expires automatically at the end of the session or after a short period.1 dayNo
cf_clearanceThis cookie is used by the CloudFlare service to identify trusted web traffic and override any security restrictions based on the visitor’s IP address. It is essential for supporting a website’s security features and in providing protection against malicious visitors.1 yearNo
thimcookie-consentCookies preferences1 yearNo
wordpress_logged_in_*Stores login information15 daysNo
wp_langStores language settings.1 yearNo
wordpress_test_cookieTest cookie1 yearNo
wordpress_sec_*Provides protection against hackers, store account details.15 daysNo
wp-settings-1Stores the user’s settings15 daysNo
wp-settings-time-1Stores the user’s settings regarding the website time15 daysNo

Analytics / Statistics Cookies: These are cookies that evaluate the way visitors use the platform (for example, which pages are visited more often and whether they receive error messages from webpages). These cookies are used for statistical purposes and to improve the performance of the platform.

CookieDescriptionDurationTransfer of data to third parties
_gaUsed to distinguish users for Google Analytics.2 yearsYes
_ga_*Used by Google Analytics to store and count pageviews.2 yearsYes
_gidUsed to distinguish users for Google Analytics.24 hoursYes

12. Children’s Privacy

Our project does not address anyone under the age of 18 (“Children”). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children have provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

13. Terms of Use – Intellectual Property

All educational content, materials, texts, graphics, videos, and other resources provided through the Platform are protected by intellectual property laws and remain the property of the Data Controller or respective licensors.

Users are granted a limited, non-transferable, non-exclusive license to access and use the content for personal educational purposes only.

Reproduction, redistribution, or commercial exploitation is strictly prohibited without prior written consent.

14. Amendments to this Privacy Policy

The Data Controller reserves the right to amend this present Privacy Policy, for example when this is necessary to comply with new requirements imposed by applicable laws, guidelines or technical requirements, or in the course of a revision of the Data Controller’s processes and practices. The User will be notified of any amendment to this Privacy Policy through the Platform. The User should regularly check this Privacy Policy for any amendments.