Privacy Policy

 Privacy Policy (GDPR) – Erasmus Krakow

1. General information

This Privacy Policy explains how personal data are collected, used, and protected by the Institute for Work and Career Foundation – Erasmus Krakow in connection with its activities, including Erasmus+ projects.

The data controller is:

Institute for Work and Career Foundation – Erasmus Krakow
KRS: 0000528193
NIP: 6492301554
REGON: 360163312
Registered office: ul. Szlak 77/222, 31-153 Kraków, Poland

Data Protection contact:
Email: jarosz@erasmuskrakow.eu

2. Legal basis for data processing

Personal data are processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), in particular:

  • Article 6(1)(a) GDPR – consent
  • Article 6(1)(b) GDPR – performance of a contract
  • Article 6(1)(c) GDPR – legal obligation
  • Article 6(1)(f) GDPR – legitimate interests (organisation and coordination of Erasmus+ activities)

3. Purposes of data processing

Personal data are processed for the following purposes:

  • organisation and implementation of Erasmus+ mobility projects
  • participant recruitment and selection
  • coordination of internships and traineeships abroad
  • communication with participants and partners
  • project management, monitoring, reporting, and evaluation
  • compliance with Erasmus+ Programme requirements (including audit and financial control by EU institutions)

4. Categories of personal data

We may process the following categories of personal data:

  • identification data (name, surname, date of birth)
  • contact details (email, phone number, address)
  • identity document data (e.g. passport/ID)
  • education and professional background
  • CV and application documents
  • language competencies
  • insurance-related data
  • Erasmus+ documentation data (e.g. Learning Agreement, Europass Mobility, attendance records)

Only data strictly necessary for project implementation are processed (data minimisation principle).

5. Data recipients

Personal data may be shared only with entities necessary for Erasmus+ project implementation, including:

  • partner organisations (Sending and Hosting Organisations)
  • host companies and internship providers
  • mentors and supervisors
  • accommodation and logistics providers
  • insurance companies
  • Erasmus+ National Agencies, EACEA, and the European Commission (for audit and control purposes)

Data are not sold or used for unrelated purposes.

6. International data transfers

Where necessary for project implementation, data may be transferred within the EU/EEA to Erasmus+ partner organisations. All transfers are carried out in compliance with GDPR requirements and the principle of data minimisation.

7. Data retention period

Personal data are stored only for the period necessary for:

  • Erasmus+ project implementation
  • reporting and audit requirements (including EU financial control obligations)
  • legal archiving obligations under EU and national law

After this period, data are securely deleted or anonymised.

8. Data security

We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • access control systems
  • secure IT infrastructure
  • restricted access to personal data
  • confidentiality obligations for authorised personnel

9. Rights of data subjects

Under GDPR, you have the right to:

  • access your personal data
  • rectify inaccurate or incomplete data
  • request erasure of data (“right to be forgotten”), where applicable
  • restrict processing
  • object to processing
  • data portability
  • lodge a complaint with a supervisory authority (Polish Data Protection Authority – PUODO)

10. Automated decision-making

Personal data are not used for automated decision-making or profiling.

11. Personal data in Erasmus+ documentation

Personal data may be used in Erasmus+ documentation, including:

  • Learning Agreement
  • Europass Mobility
  • attendance lists
  • evaluation and reporting documents
  • project and audit documentation

12. Personal data breaches

In the event of a personal data breach:

  • the relevant party will notify other entities without undue delay
  • corrective measures will be implemented
  • where necessary, the breach will be reported to PUODO and/or EU institutions (EACEA / National Agency)
  • where required by GDPR, notification will be made within 72 hours

13. Contact

For any questions regarding data protection, please contact:

Erasmus Krakow – Institute of Work and Career Foundation
Email: jarosz@erasmuskrakow.eu
Website: https://www.erasmuskrakow.eu

14. Updates

This Privacy Policy may be updated to reflect legal changes or Erasmus+ Programme requirements. The current version is always available on this website.