Privacy Policy
Last updated: 30 September 2026
1. Who We Are and What This Policy Covers
This Privacy & Cookies Policy explains how personal data is collected and processed through the CIRCULARIS project website (“the Website”).
CIRCULARIS is a Horizon Europe research and innovation project funded by the European Union under Grant Agreement No. 101292246.
The project is coordinated by the University of Piraeus Research Center (UPRC).
For the processing of personal data carried out specifically through the CIRCULARIS Website, UPRC acts as data controller, unless otherwise stated for a particular project activity or service.
| Data Controller | University of Piraeus Research Center (UPRC), Al. Papanastasiou 91, Piraeus 185 33, Greece |
| Project contact | coordinator@circularis-heu.eu |
| Website | circularis-heu.eu |
| Grant Agreement | No. 101292246 |
| Legal framework | Regulation (EU) 2016/679 (GDPR), applicable Greek data-protection legislation, and Article 15 of the applicable EU Grant Agreement |
Where consortium partners or external service providers process personal data in connection with Website activities, access is limited to what is necessary for their role and appropriate data-protection arrangements are applied where required.
2. Personal Data We Collect and Why
We collect personal data only for specified, explicit and legitimate purposes and only to the extent necessary for those purposes.
Where legitimate interest is relied upon as the legal basis, the interests of the project are balanced against the rights and reasonable expectations of data subjects.
| Activity | Data Categories | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
| General contact form | Name, email address, organisation where provided, message content | Responding to enquiries concerning the CIRCULARIS project | Art. 6(1)(f) GDPR — legitimate interest in responding to project-related enquiries | Up to 2 years from receipt, unless ongoing correspondence requires longer retention |
| Project communication | Name, email address, organisation, professional role where provided | Communicating with stakeholders concerning project activities, collaboration or dissemination | Art. 6(1)(f) GDPR — legitimate interest in project communication and stakeholder engagement | For the duration necessary to handle the communication or project activity |
| Events, workshops and webinars | Name, organisation, email address and other information required for participation | Managing participation in CIRCULARIS dissemination, stakeholder engagement and project events | Art. 6(1)(b) GDPR where registration is requested by the participant and/or Art. 6(1)(f) GDPR for project dissemination activities | Normally up to 12 months following the event |
| Website technical operation and security logs | IP address, browser/user-agent information, timestamps, requested resources, error and security logs | Maintaining Website availability, security and integrity and detecting technical problems, abuse or unauthorised access | Art. 6(1)(f) GDPR — legitimate interest in network and information security | Normally up to 90 days, unless longer retention is necessary to investigate a security incident |
| Cookie consent management | Consent preferences, consent status, timestamp and relevant technical identifiers | Recording and managing visitors' cookie choices and demonstrating compliance with applicable consent requirements | Art. 6(1)(c) GDPR where required for proof of consent | According to the applicable cookie-consent configuration |
| Publication of project content | Names, affiliations, professional roles, photographs or other information relating to project participants, authors, speakers or contributors where applicable | Communication, dissemination and visibility of CIRCULARIS project activities and results | Art. 6(1)(c) GDPR where required by Grant Agreement obligations and/or Art. 6(1)(f) GDPR for dissemination of a publicly funded research project | For the duration of the Website and any additional period required by applicable project, reporting or record-keeping obligations |
Where information must be retained for audits, reviews, investigations, legal proceedings or obligations arising from the Grant Agreement, it may be kept beyond the standard retention period until the relevant procedure is completed.
3. Cookies and Similar Technologies
The Website may use cookies and similar technologies necessary for its operation and, where applicable, additional technologies requiring user consent.
Strictly Necessary Cookies
Strictly necessary cookies may be used to:
- maintain Website functionality;
- maintain WordPress administrator sessions;
- provide security features;
- store visitors' cookie-consent preferences.
These cookies do not require consent where they are strictly necessary for providing the Website or a service explicitly requested by the visitor.
Optional Cookies
Analytics, marketing, embedded-media or other optional cookies will only be activated where required consent has been obtained through the Website's cookie-management mechanism.
Visitors may manage or withdraw their consent at any time using the Website's cookie-preference controls.
Withdrawal of consent does not affect the lawfulness of processing that took place before consent was withdrawn.
If new analytics, advertising or third-party tracking technologies are introduced, this Policy and the Website's cookie information will be updated accordingly before those technologies are activated.
4. Who We Share Data With
Personal data collected through the CIRCULARIS Website is shared only where necessary for Website operation, project implementation, communication, dissemination, reporting, security or compliance with legal and contractual obligations.
Website Hosting and Technical Service Providers
Personal data may be processed by service providers responsible for:
- Website hosting;
- server infrastructure;
- Website maintenance;
- email delivery;
- security;
- backup services;
- cookie-consent management.
Such providers act under appropriate contractual and data-protection arrangements where required, including processor obligations under Article 28 GDPR.
CIRCULARIS Consortium Partners
Personal data may be shared with CIRCULARIS consortium partners where necessary for their role in project implementation, including:
- responding to project-related enquiries;
- organising project activities;
- conducting dissemination and stakeholder-engagement activities;
- managing events;
- fulfilling reporting obligations;
- carrying out research and innovation activities where applicable.
Access is limited to what is necessary for the relevant activity and remains subject to applicable confidentiality and data-protection obligations.
European Commission, European Research Executive Agency and Competent EU Bodies
Personal data may be made available to the European Commission, the European Research Executive Agency (REA), auditors or other competent European Union bodies where required for project monitoring, reporting, checks, reviews, audits or investigations under the Grant Agreement or applicable EU law.
Supervisory Authorities
Personal data may be disclosed to the competent data-protection supervisory authority where required by law or in connection with the exercise of data-subject rights, complaints or regulatory investigations.
Courts, Legal Advisers and Public Authorities
Personal data may be disclosed where required by applicable law or where necessary for the establishment, exercise or defence of legal claims.
CIRCULARIS does not sell or rent personal data.
Personal data collected through the Website is not provided to third parties for their independent advertising or marketing purposes.
5. International Transfers
Personal data processed through the CIRCULARIS Website should, where possible, be stored and processed within the European Economic Area (“EEA”).
Where a service provider processes personal data outside the EEA, transfers will take place only where an appropriate mechanism under the GDPR applies.
This may include:
- an adequacy decision under Article 45 GDPR;
- Standard Contractual Clauses under Article 46 GDPR;
- additional technical and organisational safeguards where required;
- another lawful transfer mechanism available under the GDPR.
Where relevant, this Policy will be updated to identify material international transfers arising from Website services.
6. Your Rights Under the GDPR
Depending on the circumstances, you have the following rights concerning your personal data:
- Right of access — Article 15 GDPR;
- Right to rectification — Article 16 GDPR;
- Right to erasure — Article 17 GDPR;
- Right to restriction of processing — Article 18 GDPR;
- Right to data portability — Article 20 GDPR;
- Right to object — Article 21 GDPR;
- Right to withdraw consent — Article 7(3) GDPR;
- Right to lodge a complaint with a supervisory authority — Article 77 GDPR.
Certain rights may be restricted where continued processing or retention is required by law, the Grant Agreement, audit obligations or for the establishment, exercise or defence of legal claims.
To exercise your rights in relation to Website processing, contact: coordinator@circularis-heu.eu
Requests will normally be answered within one month in accordance with Article 12 GDPR. This period may be extended by up to two additional months where necessary because of the complexity or number of requests.
You may also submit a complaint to the competent supervisory authority.
Hellenic Data Protection Authority
Kifisias 1–3
115 23 Athens, Greece
https://www.dpa.gr/
You may also lodge a complaint with the supervisory authority in your country of residence, place of work or place of the alleged infringement.
7. How We Protect Your Data
Appropriate technical and organisational measures are applied to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include:
- HTTPS/TLS encryption for Website traffic;
- access controls for Website administration;
- restricted administrative privileges;
- regular software and security updates;
- backup and recovery procedures;
- security monitoring and logging;
- procedures for managing security incidents and personal-data breaches;
- appropriate confidentiality obligations for authorised personnel.
Where a personal-data breach is likely to result in a risk to individuals' rights and freedoms, the competent supervisory authority will be notified where required under Article 33 GDPR.
Affected individuals will also be notified where the breach is likely to result in a high risk, in accordance with Article 34 GDPR.
8. Links to Other Websites
The CIRCULARIS Website may contain links to external websites, including:
- CIRCULARIS consortium partners;
- European Commission websites;
- the EU Funding & Tenders Portal;
- research organisations;
- project-related initiatives;
- social-media platforms;
- external publications and resources.
CIRCULARIS is not responsible for the privacy practices of external websites.
Visitors should review the applicable privacy notices of those services before providing personal information.
Processing performed by European Union institutions, bodies and agencies is subject to their applicable data-protection framework, including Regulation (EU) 2018/1725 where relevant.
9. Changes to This Policy
This Privacy Policy may be updated to reflect:
- changes to Website functionality;
- new project services;
- changes in service providers;
- new categories of data processing;
- regulatory or legal requirements.
The date of the current version is displayed at the beginning of this Policy.
Where changes materially affect how personal data is processed, appropriate information will be provided through the Website or other suitable communication channels.
10. Contact
For questions concerning this Privacy Policy or the processing of personal data through the CIRCULARIS Website:
| Project Coordinator | University of Piraeus Research Center (UPRC) |
| Coordination Office | Al. Papanastasiou 91, Piraeus 185 33, Greece |
| Project email | coordinator@circularis-heu.eu |
| Dissemination & Media | press@circularis-heu.eu |
| Website | circularis-heu.eu |
| Grant Agreement | No. 101292246 |
11. Legal References
- Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR);
- applicable Greek legislation concerning the protection of personal data;
- Regulation (EU) 2018/1725 where processing is carried out by EU institutions, bodies, offices or agencies;
- Horizon Europe Grant Agreement No. 101292246;
- Article 15 — Data Protection of the applicable EU Model Grant Agreement.