Privacy Policy
Privacy Policy (GDPR) – Erasmus Krakow
1. General information
This Privacy Policy explains how personal data are collected, used, and protected by the Institute for Work and Career Foundation – Erasmus Krakow in connection with its activities, including Erasmus+ projects.
The data controller is:
Institute for Work and Career Foundation – Erasmus Krakow
KRS: 0000528193
NIP: 6492301554
REGON: 360163312
Registered office: ul. Szlak 77/222, 31-153 Kraków, Poland
Data Protection contact:
Email: jarosz@erasmuskrakow.eu
2. Legal basis for data processing
Personal data are processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), in particular:
- Article 6(1)(a) GDPR – consent
- Article 6(1)(b) GDPR – performance of a contract
- Article 6(1)(c) GDPR – legal obligation
- Article 6(1)(f) GDPR – legitimate interests (organisation and coordination of Erasmus+ activities)
3. Purposes of data processing
Personal data are processed for the following purposes:
- organisation and implementation of Erasmus+ mobility projects
- participant recruitment and selection
- coordination of internships and traineeships abroad
- communication with participants and partners
- project management, monitoring, reporting, and evaluation
- compliance with Erasmus+ Programme requirements (including audit and financial control by EU institutions)
4. Categories of personal data
We may process the following categories of personal data:
- identification data (name, surname, date of birth)
- contact details (email, phone number, address)
- identity document data (e.g. passport/ID)
- education and professional background
- CV and application documents
- language competencies
- insurance-related data
- Erasmus+ documentation data (e.g. Learning Agreement, Europass Mobility, attendance records)
Only data strictly necessary for project implementation are processed (data minimisation principle).
5. Data recipients
Personal data may be shared only with entities necessary for Erasmus+ project implementation, including:
- partner organisations (Sending and Hosting Organisations)
- host companies and internship providers
- mentors and supervisors
- accommodation and logistics providers
- insurance companies
- Erasmus+ National Agencies, EACEA, and the European Commission (for audit and control purposes)
Data are not sold or used for unrelated purposes.
6. International data transfers
Where necessary for project implementation, data may be transferred within the EU/EEA to Erasmus+ partner organisations. All transfers are carried out in compliance with GDPR requirements and the principle of data minimisation.
7. Data retention period
Personal data are stored only for the period necessary for:
- Erasmus+ project implementation
- reporting and audit requirements (including EU financial control obligations)
- legal archiving obligations under EU and national law
After this period, data are securely deleted or anonymised.
8. Data security
We apply appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- access control systems
- secure IT infrastructure
- restricted access to personal data
- confidentiality obligations for authorised personnel
9. Rights of data subjects
Under GDPR, you have the right to:
- access your personal data
- rectify inaccurate or incomplete data
- request erasure of data (“right to be forgotten”), where applicable
- restrict processing
- object to processing
- data portability
- lodge a complaint with a supervisory authority (Polish Data Protection Authority – PUODO)
10. Automated decision-making
Personal data are not used for automated decision-making or profiling.
11. Personal data in Erasmus+ documentation
Personal data may be used in Erasmus+ documentation, including:
- Learning Agreement
- Europass Mobility
- attendance lists
- evaluation and reporting documents
- project and audit documentation
12. Personal data breaches
In the event of a personal data breach:
- the relevant party will notify other entities without undue delay
- corrective measures will be implemented
- where necessary, the breach will be reported to PUODO and/or EU institutions (EACEA / National Agency)
- where required by GDPR, notification will be made within 72 hours
13. Contact
For any questions regarding data protection, please contact:
Erasmus Krakow – Institute of Work and Career Foundation
Email: jarosz@erasmuskrakow.eu
Website: https://www.erasmuskrakow.eu
14. Updates
This Privacy Policy may be updated to reflect legal changes or Erasmus+ Programme requirements. The current version is always available on this website.