Privacy Policy

Pursuant to the General Data Protection Regulation (GDPR – EU Regulation 2016/679)

This Privacy Policy describes the methods of collection, use, storage, and protection of the personal data of users who consult and use the services offered on the website https://www.openfashion.eu (hereinafter, the “Site”). This policy is provided in accordance with Article 13 of EU Regulation 2016/679 (GDPR) and applicable national legislation on the protection of personal data.

1. Data Controller

The data controller of the personal data collected through the Site is: Owner: Camara de Comercio Italiana Barcelona Registered Office: Carrer de Balmes, 195, 4º – 2ª, Sarrià-Sant Gervasi, 08006 Barcelona, ​​Spain Contact Email: openfashionerasmus@gmail.com

2. Type of Data Collected

Depending on the use of the Site and the services requested (e.g., browsing, registration on the e-learning/MOOC platform, newsletter subscription, submission of contact forms), the following categories of data may be processed:

A. Browsing Data

The computer systems and software procedures used to operate this Site acquire, during their normal operation, some personal data whose transmission is implicit in the use of Internet communication protocols. This category includes IP addresses, domain names of computers used by users, URI/URL addresses of requested resources, the time of the request, the method used to submit the request to the server, and other parameters related to the user’s operating system.

B. Data provided voluntarily by the user

Registration and profile data (Training platform/MOOC): first name, last name, email address, profession, organization/company affiliation, country of residence, and any training preferences. Contact forms or newsletters: name, email address, and any additional information entered in messages or request fields.

C. Cookies and tracking technologies

The Site uses technical cookies necessary for proper functioning and, with your consent, analytical or profiling cookies. For further details, please refer to the specific Cookie Policy available on the Site.

3. Purpose of the Processing and Legal Basis

Personal data is processed for the following purposes, distinguished by legal basis:

Purpose of the processing Legal Basis (pursuant to the GDPR)
Allow navigation on the Site and technical use of the contents. Legitimate interest of the Data Controller (Art. 6, par. 1, letter f)
Provision of requested services (e.g., registration on the OpenFashion platform, participation in courses, downloading guidelines or materials). Performance of a contract or pre-contractual measures (Art. 6, par. 1, letter b)
Respond to inquiries submitted via contact forms or email. Execution of pre-contractual measures or legitimate interest (Art. 6, par. 1, lett. b/f)
Sending informational communications, newsletters, and updates on OpenFashion project activities. Explicit consent of the interested party (Art. 6, par. 1, letter a)
Fulfillment of legal, accounting, and tax obligations, including reporting obligations under European funding programs (e.g., Erasmus+). Fulfilment of a legal obligation (Art. 6, par. 1, letter c)

4. Data Processing and Storage Methods

Data processing is carried out primarily through IT and electronic means, using methods strictly related to the purposes indicated and, in any case, in a manner that guarantees the security and confidentiality of the data, minimizing the risk of loss, destruction, or unauthorized access. The data will be retained for the time strictly necessary to achieve the purposes for which it was collected:
  • Browsing data is deleted immediately after its statistical analysis (except where required by judicial authorities to investigate crimes).

  • Data related to registration on the platform or MOOC will be retained until the user deactivates the account or until the formal conclusion and audit deadlines of the reference project.

  • The data used to send the newsletter will be retained until the interested party revokes their consent (opt-out).

5. Scope of Communication and Data Recipients

Personal data will not be disclosed to unspecified parties. However, for the purposes described above, the data may be disclosed to:

  • Accredited partners of the OpenFashion project involved in the technical and educational management of the platform.

  • Third parties appointed as Data Processors (e.g., hosting service providers, IT services, email sending platforms).

  • Competent authorities and supervisory bodies for the fulfillment of legal obligations or for fund reporting (e.g., Erasmus+ National Agencies, European Commission).

6. Transfer of Data Outside the EU

The Data Controller manages and stores personal data on servers located within the European Union. If it becomes necessary to transfer data to third countries outside the European Economic Area (EEA), such transfer will occur only with an adequacy decision from the European Commission or following the signing of the Standard Contractual Clauses (SCC).

7. Rights of the Data Subject

Users may exercise the rights provided for in Articles 15 et seq. of the GDPR at any time by sending a written request to the Data Controller’s email address. These rights include:

  • Right of access: Obtain confirmation as to whether or not personal data concerning you is being processed and receive a copy of it.

  • Right to rectification: Request the correction of inaccurate data or the completion of incomplete data.

  • Right to erasure (right to be forgotten): request the deletion of your data if the legal grounds for retention no longer apply.

  • Right to restriction: request the temporary blocking of processing in specific cases.

  • Right to portability: receive your data in a structured, commonly used format and transfer it to another controller.

  • Right to object: to the processing of your personal data for reasons relating to your particular situation or for direct marketing purposes.

  • Withdrawal of consent: to withdraw consent previously given at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) if they believe that the processing violates the provisions of the GDPR.

8. Updates to the Policy

This Privacy Policy was last updated on May 25, 2026. The Data Controller reserves the right to make changes or updates as a result of legislative changes or the implementation of new features on the Site. Changes will be published on the Site.