Privacy Policies
1. Serco Privacy Policy
1.1 About Serco Italia S.p.A
This Privacy Policy is released by Serco Italia S.p.A., with registered office at viale dell’Astronomia 13, Cap 00144 (Rome, Italy) (“Serco” or the “Data Controller” or “we” or “us”), which can be contacted at the following email address desp-support@serco.com.
Serco Italia S.p.A. operates DestinE Platform (available at platform.destine.eu) and in this context Serco Italia S.p.A collects and processes data as follows:
(i) upon decision taken by another separate controller (e.g. ESA, EUMETSAT, European Commission etc.) within the framework of the Destination Earth initiative; the information related to the processing of personal data decided upon by such third-party controller is given in the separate privacy notices released by the corresponding third-party and made available on the DestinE Platform, in particular in connection with DestinE Core Service Platform;
and
(ii) upon decision taken by solely Serco Italia S.p.A only, acting in its capacity of separate data controller; for this case, this Serco Privacy Notice applies and made available on the DestinE Platform, in connection with DestinE Platform Services.
1.2 General
Serco Italia S.p.A is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) and any applicable national laws and regulations.
This privacy policy provides information to you about the basis on which any personal data we collect from you, or that you provide to us, will be processed by us, for purposes decided solely by Serco Italia S.p.A., if you are a client of the DestinE Platform, as defined in the Agreement for the provision of DestinE Platform Services (the “T&C”), provided through the site platform.destine.eu (the “Site”).
This privacy policy shall be read in conjunction with our cookies policy ([RD]) and the agreement for the provision of DestinE Platform (the “T&C”). In the event of any conflict or inconsistency between this Privacy Policy and the T&C or Cookies Policy, the provisions of this Privacy Policy shall prevail. This Privacy Policy is intended to comply with the requirements of the General Data Protection Regulation (GDPR) and any applicable national laws and regulations and shall be interpreted and applied in accordance with the GDPR and such laws and regulations.”
In this privacy policy, the terms “we”, “our”, and “us” are used to refer to Serco Italia S.p.A., as the separate Data Controller responsible for your personal information solely in respect and purpose of the development and operation of DestinE Platform decided upon by Serco Italia S.p.A as separate data controller.
Questions, comments and requests regarding this privacy policy are welcomed and should be addressed to the relevant contact above.
1.3 Information we collect from you
We will collect and process the following data about you from your use of our Site:
- Registration data and other information you give us. This is data about you that you give us when you register to use our Site, subscribe to any of the DestinE Platform Services, use the DestinE Platform provided by our Site. The data you give us may include your name, surname, e-mail address, and in case of companies the details of the company.
- Technical information. We also collect technical data, including the Internet protocol (IP) address used to connect your computer to the Internet, MAC addresses, traffic data, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform and cookies, which will be collected in accordance with our cookies policy which comply with the requirements of the General Data Protection Regulation (GDPR) and any applicable national laws and regulations.
1.4 How we use your information
We use information held about you solely in respect of the development and operation of DestinE Platform for the following purposes decided upon solely by Serco Ialia S.p.A::
- to allow you to have access to, and use our Site and use the DestinE Platform Service offer and therefore carrying out our obligations arising from any agreements entered into between you and us and to provide you with the information, products and services that you request from us;
- to carry out appropriate and necessary investigations and discharge our legal and regulatory obligations and duties, including to comply with (to the extent applicable):
- the guidance of any relevant regulatory body;
- the requirements of applicable legislation for the combatting of money laundering, fraud, terrorist financing, bribery, corruption, tax evasion, the provision of financial or other services to persons who may be subject to economic or trade sanctions; and
- any other local laws, regulations, directions, codes of practice, circulars, orders notices or demands which may otherwise apply;
(purposes from a) to b) are jointly defined as the “Contractual Purposes”)
- for fraud prevention purposes within the limits not already required by applicable laws as well as to defend or claim a right, also as part of court proceedings;
- for credit recovery procedures and credit assignment to authorized companies, also by means of third parties;
- for the completion of a potential merger, sale of assets or transfer of all or a material part of its business, by disclosing and transferring your personal data to the third party or parties involved in the transaction as part of the transaction;
(the purposes of letters c) to e) above are jointly referred to as “Legitimate Interest Purposes”)
- with your prior consent, to provide you with marketing communications by means of electronic and physical channels of communication about the services or products we offer and to run surveys solely in respect and purpose of the development and operation of DestinE Platform;
- with your prior consent, to customize the DestinE Platform Services and the marketing communications referred above on your preferences and habits (see Cookies Policy) solely in respect and purpose of the development and operation of DestinE Platform.
(the purposes of letters f) and g) above are jointly referred to as “Marketing Purposes”).
1.5 Legal basis for the processing of your personal data
The General Data Protection Regulation (GDPR) and any applicable national laws and regulations require that we meet certain conditions before we are allowed to use your data in the manner described in this privacy policy. We take our responsibilities under data protection rules extremely seriously, including meeting these conditions.
The processing of your personal data is necessary with regard to the Contractual Purposes as it is essential:
- for the performance of the Terms and Conditions between you and us solely in respect and purpose of the development and operation of DestinE Platform.
- In order for us to fulfil our obligations under such contract, we will need to collect and process your personal data.
- in order to comply with applicable guidance provided by any relevant regulatory body and the obligations under applicable legislation, including anti-money laundering/fraud legislation.
Failure to provide the data for the above purposes will unfortunately mean we cannot provide our services to you, as to allow you to use our service would mean we would be in breach of our legal obligations.
The processing of your personal data with regard to the Legitimate Interest Purposes of Section 2 letter e) is carried out in compliance with article 6, letter f) of the EU General Data Protection Regulation 2016/679 (the “European Privacy Regulation”), for the pursuit of Serco’s legitimate interest to the detection of potential frauds, the recovery of debts towards to company and the performance of the economic activities referred therein, which is adequately balanced with your interest since the data processing is performed within the limits strictly necessary to their performance.
This data processing activity with regard to the Legitimate Interest Purposes is not mandatory and you can object to the data processing at any time through the modalities as per this Privacy Policy.
Finally, the data processing with regard to the Marketing Purposes is based on your prior consent. Such data processing is not mandatory however should you refuse to provide the relevant consent you will not receive marketing communications as per Section 2 letters f) and g). In any case, you can withdraw your consents at any time through the modalities as per this Privacy Policy.
1.6 How do we process your personal data
Your personal data will be processed both electronically and/or manually, in any case in such a way as to guarantee the security, protection and confidentiality of the data, thanks to appropriate administrative, technical, personnel and physical measures against loss, theft and unauthorized use, disclosure or modification.
1.7 How long we keep your information for
Your Personal data will be stored for the period necessary to fulfil the purposes for which the data was collected as outlined in this privacy policy and in accordance with the General Data Protection Regulation (GDPR) and any applicable national laws and regulations. In any case the following retention periods will apply to the processing of your personal data for the purposes indicated below:
- data collected for Contractual Purposes and for Legitimate Interest Purposes is retained during the provision of the services plus a period of 5 years after the termination or withdrawal from the contract with us, except when the detention of the data is necessary to respond or to file a legal action, upon request of the competent authorities or in compliance with the applicable laws;
- data collected for Marketing Purposes relating to the delivery of marketing communications and running of surveys is retained for the duration of the Contract and a subsequent period of 24 months;
- data collected for Marketing Purposes relating to the profiling of your preferences for marketing purposes is retained for a period of 12 months from the time it is collected.
1.8 Disclosure of your information
For the Contractual Purposes, personal data may be transferred to the following categories of recipients located within the EU solely in respect and purpose of the development and operation of DestinE Platform and within the limits as set below:
- third parties service providers entrusted with processing activities that provide hosting cloud services or assistance and advice to Serco, with special but not exclusive reference to technology (in particular, but not exclusively analytics and search engine providers that assist us in the improvement and optimisation of our site and other selected third parties), accounting, administrative, legal, insurance, IT matters;
- EUMETSAT and ECMWF, implementing the Destination Earth Data Lake and the Digital Twins and Digital Twin Engine components of the Destination Earth initiative, for whose services Personal Data transfer is necessary for the performance of their activities;
- affiliates; and
- persons and authorities whose right to access personal data is recognized by law, regulations or provisions issued by legally empowered authorities.
The above-mentioned recipients will process personal data as data controllers, data processors or persons in charge of processing, depending on the circumstances. To know the point of contact for personal data protection matters concerning separate Controllers (which are independently responsible for the collection and processing of personal data they decide upon in respect and purpose of the tasks entrusted to them within the framework of the Destination Earth initiative), please refer to the privacy notices of these separate Controllers.
Management of Your account to DestinE Core Service Platform may render necessary the communication of Your personal Data to the European Commission. Provided this is necessary, a separate privacy statement will be released by the European Commission accordingly.
We will also disclose your personal data to the European Space Agency, for the purposes described in the “ESA Privacy Notice for DestinE Core Service Platform”.
For the Legitimate Interest Purposes, personal data may be transferred to the following categories of recipients located within the EU and within the limits set below:
(a) potential purchaser of Serco and the entities resulting from mergers or any other transformation involving Serco, (b) competent authorities.
For the Marketing Purposes, personal data may be transferred to the following categories of recipients located both within the EU and, within the limits set below:
(a) third parties service providers entrusted with processing activities that provide services or assistance with regard to the delivery of marketing communications solely in respect and purpose of the development and operation of DestinE Platform.
The data processors appointed by Serco include OVHCloud.
1.9 Your rights
You have a number of rights under the General Data Protection Regulation (GDPR) and any applicable national laws and regulations in relation to the way we process your personal data. These are set out below. You may contact us by sending a communication to the email address desp-support@serco.com or by contacting our DPO directly – details below) to exercise any of these rights, and we will respond to any request received from you within one month from the date of the request.
At any given time, you can exercise the following rights:
- to obtain from Serco confirmation of the existence of personal data and to be informed of its content and source, verify its accuracy and request its integration, update or amendment;
- to request the erasure, anonymization or restriction of the processing of personal data processed in breach of the applicable laws;
- to object in whole or in part, on legitimate grounds, to the processing of the data;
- to withdraw the consent to the processing of the data (if and to the extent such a consent is necessary).
You will have the right, in any given moment, to:
- request Serco to limit the processing of your personal data where:
- you contest the accuracy of the personal data until Serco have taken sufficient steps to correct or verify its accuracy;
- the processing is unlawful but you do not want us to erase your personal data;
- Serco no longer needs your personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims; or
- you have objected to processing justified on legitimate interests, pending verification as to whether Serco has compelling legitimate grounds to continue processing.
- object to the processing of your personal data;
- request the erasure of your personal data without undue delay;
- receive an electronic copy of your personal data, if you would like to port your personal data to yourself or a different provider, when Serco is relying upon your consent or the fact that the processing is necessary for the provision of the services and the personal data is processed by automatic means; and
- lodge a complaint with the relevant data protection supervisory authority.
1.10 Transfer of personal data
- Serco shall process (and have processed by its authorised subcontractors or sub-processors) personal Data only in the agreed territory of processing (European Union) solely in respect and purpose of the development and operation of DestinE Platform. Transfer of Personal Data outside the agreed territory shall only take place for the purpose of implementing, managing, monitoring the activities under the T&Cs and solely in respect and purpose of the development and operation of DestinE Platform, and will only concern Data Recipients located in a country or international organisation offering an Adequate Level of Protection.
- The transfer of personal data towards a country not recognized as offering an Adequate Level of Protection may only be done after being authorised by the Serco Data Protection Officer (DPO) and subject to “adequate safeguards with respect to the protection of the Personal Data and data subject’s rights”.
- As “adequate safeguards”, the Parties agreed to adopt the level of protection resulting from the provisions of the EU Standard Contractual Clauses for the Transfer of Personal Data to Third Countries pursuant to Regulation (EU) 2016/679.
1.10.1 The Data Protection Officer
The data protection officer appointed by Serco pursuant to Section 37 of the Privacy Regulation can be contacted at the following email address: dpo@serco.com.
1.10.2 Changes to this Privacy Policy
Any changes to this privacy policy in the future will be posted on this page, and where appropriate, notified to you by email. Please check back frequently to see any updates or changes to this privacy policy.
This policy was last reviewed and updated: October 2024.
2. ESA Privacy Policy
ESA PRIVACY NOTICE FOR DESTINE CORE SERVICE PLATFORM Released by: European Space Agency, as Data Controller for the DestinE Core Service Platform Addressed to individuals whose personal data are collected and processed (“You”) Concerning collection and processing initiated by: ESA EOP Department (hereinafter referred to as the “Department”) Inroduction The European Space Agency (hereafter “the Agency” or “ESA” or “We”) is committed to protecting Personal Data in line with the ESA Framework on Personal Data Protection (herein the “ESA PDP Framework”) available at: http://www.esa.int/About_Us/Law_at_ESA/Highlights_of_ESA_rules_and_regulations composed of:- the Principles of Personal Data Protection adopted by ESA Council on 13 June 2017
- the Rules of Procedure for the Data Protection Supervisory Authority adopted by ESA Council on 13 June 2017
- the Policy on Personal Data Protection (including its Annex entitled “Governance Scheme of the ESA’s Personal Data Protection”) adopted by the Director General of ESA on 1 March 2022 (“ESA PDP Policy”).
- This notice is released by ESA and is intended to describe why and how Your personal data are collected and processed by or on behalf of ESA as separate Data Controller, in relation to the Destination Earth initiative, the DestinE Core Service Platform implementation and the Contribution Agreement (hereinafter Agreement), as well as what rights You have in relation to Your personal data. It also informs You about the contact details of the Data Protection Officer. This privacy notice was last updated on 09/10/2024. It must be read in conjunction with the ESA PDP Framework.
- Other privacy notices may apply, as indicated on the DestinE Platform.
-
How can you contact the Data Protection Officer regarding this notice?
SEPARATE CONTROLLERS: To know the point of contact for personal data protection matters concerning separate Controllers (which are independently responsible for the collection and processing of personal data they decide upon), please refer to the privacy notices of these separate Controllers. Your queries regarding these matters will not be dealt with by ESA or its DPO. |
-
What kinds of personal data are collected and further processed?
- Identity Data: including Your names;
- Copies of identity documents: including copies of Your diplomatic cards, copy of passport (including visa if necessary), the identity card or other identity documents, certificates, Your photograph;
- Contact information: email address;
- Technical data, including online identifiers: for example, internet protocol (IP) address or domain names of the devices utilised, login data, browser data, in particular the type plug-in version, user preferences and history; MAC data, device information, uniform resource identifier (URI) address, time zone setting, operating system and platform and other technology of the devices you are using; geolocation server logs data, log data;
- Other personal information You may provide: in particular the content of exchanges with ESA, for instance assistance data;
- Other data, such as:
- Your messages, date, and time the message was sent;
- the content of the questions you have asked;
- other data mentioned in Your messages;
- feedback and interaction on the tools provided, support requests, etc.
-
How are Your personal data collected or further processed?
-
Why are Your personal data collected and further processed?
What is the purpose of processing Your personal data? | |
IF YOU REQUEST, OR ARE PROVIDED ACCESS, TO YOUR ACCOUNT IN THE DESTINE CORE SERVICE PLATFORM Your personal data are collected and further processed for the following purposes: (i) to manage Your free-of-charge account (e.g. validation, authorization and creation) in DestinE Core Service Platform (herein “Your account”); (ii) to manage access to Your account according to the user access policy; (iii) to exchange correspondence or any types of messages with You about the DestinE Core Service Platform functionalities available via Your Account; (iv) to inform and raise awareness in relation with the DestinE Core Service Platform functionalities accessible via Your account; (v) to perform monitoring of your use via Your account to DestinE Core Service Platform; (vi) to analyse and monitor Your interactions with the DestinE Core Service Platform via Your account; (vii) to deal with your current and future queries or requests submitted via Your account or to otherwise engage with you; (viii) to analyse and monitor Your reactions to content available in the DestinE Core Service Platform via Your account, and initiatives; (ix) to ensure measurement of various criteria in relation to the availability of Your account in DestinE Core Service Platform; (x) to gather statistics with a view to enhancing the user experience of DestinE Core Service Platform; (xi) to identify and track unauthorised access or any attempts to access Your account in DestinE Core Service Platform without permission; to defend ESA’s rights and interests, including to defend ESA from possible liability claims that may arise. The management of Your account on the DestinE Core Service Platform may render necessary the communication of Your personal Data to the European Commission. Provided this is necessary, a separate privacy notice will be released by the European Commission accordingly. | |
IF YOU FORMULATE A REQUEST OR A COMPLAINT IN THE EXERCISE OF YOUR RIGHTS In particular, Your personal data are collected and further processed for the following purposes: (i) to handle any questions or complaints you submit to ESA; (ii) to respond to any request relating to your rights; (iii) to defend ESA from possible liability claims that may arise. | |
IF YOU USE ESA IFORMATION AND COMMUNICATION TECHNOLOGY (IT) INFRASTRUCTURE, TOOLS AND SERVICES (operated by ESA or on behalf of ESA) IN RELATION TO THE DestinE Core Service Platform Your personal data may be collected and further processed for the following purposes: (i) to provide You access to the IT infrastructure, tools and services operated by or on behalf of ESA; (ii) to provide optimal data flow between target environments in an automated manner; (iii) to provide access and proper performance of the service to end-users; (iv) to provide support services and to ensure the management and maintenance of the service; (v) to manage provision of IT services such as identity and access management; incident prevention, management, reporting; (vi) to ensure data subject rights management; (vii) to ensure personal data quality and accuracy. (viii) to provide tools that facilitate transcription, evaluation, reporting or automated processing. |
-
On what legal grounds do We collect and process Your data?
What are the legal basis for processing Your personal data? |
5.1 General basis for processing under ESA PDP Policy The processing referred to in this notice falls under Article 5.2.1 of the ESA PDP Policy, e.g., it is necessary: a) for security; or b) for the performance and implementation of the Contribution Agreement concluded by ESA within its purpose in relation with an activity carried out by ESA in the framework of, and in conformity with, the ESA Convention and the applicable rules and procedures and for the implementation of the DestinE Platform; c) for Your legitimate interest. |
-
In which circumstances may We transfer or provide access to Your personal data?
- providers of cloud/data hosting services,
- providers of platform-maintenance related services,
- providers enabling Us to manage our contracting process,
- providers ensuring the security of our premises,
- providers enabling Us to provide you with working tools, etc.
- providers in charge with the organisation and management of communication activities,
- providers involved in the management of social media accounts,
- providers involved in marketing, advertising activities, managing newsletters, managing statistics and media services,
- providers of website related services.
-
How long do We retain Your personal data for?
-
How do We protect and safeguard Your personal data?
-
What are Your rights as data subject and how can you exercise them?
- the right to be informed about the identity of the data controller, the contact details of the data protection officer, the purpose of the data processing, the data recipients to whom the personal data shall be disclosed, the rights of rectification or erasure of his/her data, the storage time-limits (if any), the practical modalities of exercising the rights, etc. ; this is the purpose of this privacy notice and any other notice referred to herein ;
- the right to access the personal data We process about You; unless you have access to such data via an account, you may send us your request by email to dpo@esa.int ;
- the right to have Your personal data erased, rectified, completed; if you want to review and correct the personal information, you can either do it yourself, in case you have access to such data via an account, or you may send us your request by email to dpo@esa.int ;
- the right to lodge a complaint before the Supervisory authority, in accordance with the latter’s rules of procedure. In case You demonstrate, or have serious reasons to believe, that a data protection incident occurred in relation with Your personal data, following a decision of ESA, you may send notify us thereof by email to dpo@esa.int.
- Your personal data may continue to be processed for the performance of a legal obligation of ESA or where such data is necessary for the establishment, exercise, or defence of legal claims;
- If there are multiple processing concerning You, based on consent, You have to expressly indicate which consent you wish to withdraw.