Trust-IT Services srl, with registered offices in Via Francesco Redi 10, 56124 Pisa (PI), Italy — VAT and Fiscal Code IT01870130505, PIC 906664821 (“Trust-IT”, “we”, “us”) — is committed to protecting the online privacy of the users of the EOSC-CONNECT website at [www.eosc-connect.eu] (the “Website”), including participants in the EOSC-CONNECT Open Calls for Financial Support to Third Parties (“FSTPs”), National Node operators, registered members, event attendees and newsletter subscribers.
This Privacy Policy explains what personal data EOSC-CONNECT collects through the Website and related services, why, on what legal basis, for how long, who it is shared with, and what rights you have as a data subject. It has been drafted in line with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and with the data-protection obligations set out in Article 15 of the EOSC-CONNECT Grant Agreement (Horizon Europe Grant Agreement No 101288616).
EOSC-CONNECT is a project funded by the European Union's Horizon Europe programme under grant agreement No 101288616, coordinated by CSC – Tieteen tietotekniikan keskus Oy (CSC), Finland, and implemented by a consortium of 18 beneficiaries and 4 affiliated entities across 14 countries. Trust-IT leads Task 1.2 (management of the FSTP Open Calls) and Task 1.3 (engagement, dissemination, exploitation and the Website), and is therefore the entity primarily responsible, as data controller, for personal data collected through the Website and the FSTP Open Call platform. Where personal data is transferred to the European Commission / European Research Executive Agency (REA) for grant-management purposes, that processing is carried out by REA as an independent controller under Regulation (EU) 2018/1725 and its own Portal Privacy Statement (see Section 7).
Contents
1. Data Controller(s)
2. Personal data processed
a. Registered members and general website use
b. FSTP Open Calls (Financial Support to Third Parties)
c. Events, workshops and National Node engagement activities
d. Newsletters and communications
e. Special categories of personal data
f. Other persons’ personal data
g. Browsing data
h. Cookies
3. Purposes of processing
4. Legal bases for processing
5. Recipients of personal data – Data Processors
6. International transfers – non-EU/EEA National Nodes
7. Other recipients – the granting authority (European Commission / REA)
8. Retention of personal data
9. Data subjects’ rights
10. Security measures
11. Amendments
Annex A – EOSC-CONNECT Consortium
1. Data Controller(s)
Trust-IT Services srl is the data controller for all personal data processed through the EOSC-CONNECT Website, the general enquiry form, the newsletter, the registration of Website accounts, and the FSTP Open Call platform (see Section 2.b), in its capacity as leader of Tasks 1.2 and 1.3 of the EOSC-CONNECT Grant Agreement.
For personal data submitted directly to individual consortium partners in the course of their own National Node activities (e.g. a national workshop organised locally by SURF, ZBW, CSC or another beneficiary), that partner acts as data controller for the data it collects. A full list of consortium partners is provided in Annex A of this Policy.
You can contact us with any questions related to this Privacy Policy or to Trust-IT's personal data processing practices by writing to:
• Email: info@eosc-connect.eu (or the Website's contact form)
• Data Protection contact / DPO: Michele Nannipieri, Trust-IT Services srl – privacy@trust-itservices.com
2. Personal data processed
When you use the Website, EOSC-CONNECT collects and processes information about you which allows you to be identified, either directly or in combination with other information. This information (“Personal Data”) is collected either because you choose to provide it, or through the routine technical operation of the Website.
a. Registered members and general website use
If you create an account on the Website, subscribe to updates, submit a general enquiry, or otherwise engage with EOSC-CONNECT's collaborative areas, you may be asked to provide:
• Name and surname
• Professional title, organisation name and type (e.g. research institution, SME, National Node operator)
• E-mail address
• Country of residence / affiliation
• Gender (collected only where required for the statistical monitoring information EOSC-CONNECT must provide to the European Commission on project performance)
Mandatory fields are marked as such in the relevant forms; it is not possible to complete registration, subscription or submission if a mandatory field is left incomplete.
b. FSTP Open Calls (Financial Support to Third Parties)
EOSC-CONNECT operates a Financial Support to Third Parties (FSTP) scheme, worth up to EUR 500,000, distributed through two Open Calls (a “Pilot Launch” Open Call and a second Open Call) for up to 10 grants of approx. EUR 50,000 each. The FSTPs support third-party data and service providers — including data repositories — in onboarding resources onto the EOSC National Nodes participating in the project. Open Calls are managed by Trust-IT (Task 1.2) through a customised instance of the TRUST-GRANTS™ cascading-grants platform, operated together with Trust-IT's affiliated entity COMMpla Srl.
When you apply to an FSTP Open Call, or are involved in its evaluation, review or monitoring, EOSC-CONNECT may process:
• Applicant and Principal Investigator identification data (name, role, contact details)
• Legal name, country, VAT/registration details and bank details of the applicant organisation
• Proposal content, including budget, milestones and activity description
• Evaluation records (scores and comments produced by the Evaluation Committee, composed of consortium partners)
• Third-Party Project Agreement (TPPA) data, once a proposal is selected
• Monitoring, reporting and financial data relating to the implementation of the funded activity, collected by Trust-IT over the up-to-9-month duration of each funded project
Consistent with the transparency obligations of the FSTP scheme, the legal name and country of successful applicants, together with a description of the supported proposal, will be published on the EOSC-CONNECT website once evaluation is concluded. No other personal data relating to applications is published.
c. Events, workshops and National Node engagement activities
EOSC-CONNECT organises cross-country workshops, training events and “Node Stories” activities to engage National Nodes and the wider EOSC community. When you sign up to attend an event, webinar or workshop (in person or online), you may be asked to provide your name, organisation, e-mail address, dietary or accessibility requirements (see Section 2.e), and attendance dates.
d. Newsletters and communications
EOSC-CONNECT will include registered members and event participants in specific mailing lists to send informative newsletters and communications about project news, Open Calls, workshops and EOSC Federation developments, unless you opt out.
e. Special categories of personal data
The EOSC-CONNECT ethics self-assessment (Grant Agreement, Annex 1) confirms that no special categories of personal data (Art. 9 GDPR) are collected by design as part of the project's activities. Certain areas of the Website (e.g. free-text fields in enquiry forms, event sign-up forms asking about dietary or accessibility needs) could incidentally capture information revealing health conditions, religious practices or similar. We ask that you do not disclose sensitive personal data unless strictly necessary, and where you choose to do so, we will only process it with your explicit consent and solely to accommodate your request (e.g. arranging suitable catering or access at an event).
f. Other persons' personal data
Certain fields on the Website (e.g. free-text messages, TPPA correspondence, National Node contact lists) may allow you to submit information about other individuals (e.g. colleagues, co-applicants). If you do so, you are responsible for ensuring you have a lawful basis (e.g. their consent) for sharing that information with us, and for informing them of this Privacy Policy.
g. Browsing data
As is standard for websites, the Website's operation involves the collection of technical information about visitors as part of routine server operation: IP address, country, device and browser type, the pages requested, the time of the request, the response status, and similar parameters. This information is used to compile statistics on Website use, to ensure correct operation, to restore the Website following technical failures, and to detect faults or abuse. Save for this last purpose, this data is not kept for more than 60 business days.
h. Cookies
The Website uses cookies. A summary of the categories used, and how you can manage them, is provided in the Cookie Policy section of this document; the full, up-to-date list of cookies is available in the Website's dedicated cookie banner/settings panel.
3. Purposes of processing
EOSC-CONNECT processes your Personal Data, collected through the Website, for the following purposes:
• Service provision: to create and maintain your registered account, allow you to participate in collaborative project areas, verify your identity, and respond to enquiries and support requests.
• FSTP Open Call management: to administer the Open Call lifecycle — publication, eligibility checks, evaluation, contracting (TPPA), fund disbursement, monitoring and impact reporting (feeding into Deliverable D1.3 – OC Results and Impact) — and to publish the results of successful proposals as required by the transparency rules applicable to the scheme.
• Events/Webinars: to process your registration for EOSC-CONNECT events, workshops and “Node Stories” activities, and to manage attendance.
• Marketing and dissemination: to send newsletters and other project communications, and to promote EOSC-CONNECT activities, the National Node blueprint and Open Calls through the Website and social media.
• Compliance: to comply with EOSC-CONNECT's legal and contractual obligations, including its obligations to the granting authority under Article 15 (Data Protection), Article 20 (Record-Keeping) and the FSTP-specific provisions of the Grant Agreement.
• Analytics: to understand how the Website is used and to improve it.
• Misuse/fraud prevention: to detect and prevent fraudulent activity or misuse of the Website or the FSTP scheme, including conflict-of-interest checks in the Open Call evaluation process.
4. Legal bases for processing
• Service provision – performance of a contract with you (Art. 6(1)(b) GDPR). Providing this data is not mandatory, but without it we cannot provide the Service you request.
• FSTP Open Call management – for applicants, performance of pre-contractual steps and of the Third-Party Project Agreement (Art. 6(1)(b) GDPR); for evaluation, monitoring and publication of results, EOSC-CONNECT's legitimate interest and legal obligation in operating a transparent, auditable cascading-grant scheme under Horizon Europe rules (Art. 6(1)(c) and (f) GDPR), and Trust-IT's contractual obligations towards the granting authority under the Grant Agreement.
• Events/Webinars – performance of a contract with you for registration and attendance (Art. 6(1)(b) GDPR); publication of attendee/participant lists and “Node Stories”, where applicable, is based on legitimate interest (Art. 6(1)(f) GDPR) or your consent.
• Marketing – your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal.
• Compliance – necessary for compliance with EOSC-CONNECT's legal obligations, including under the Grant Agreement and applicable Horizon Europe rules (Art. 6(1)(c) GDPR).
• Analytics and Misuse/Fraud prevention – legitimate interest in the sound administration, security and improvement of the Website and the Open Calls (Art. 6(1)(f) GDPR).
Special categories of data (Section 2.e) are processed only on the basis of your explicit consent (Art. 9(2)(a) GDPR).
5. Recipients of personal data – Data Processors
Your Personal Data may be shared with the following categories of recipients, acting as data processors on our behalf or as independent (joint) controllers where indicated:
• COMMpla Srl (Via Francesco Redi 10, 56124 Pisa, Italy) – Trust-IT's affiliated entity, co-operator of the TRUST-GRANTS™ FSTP/Open Call platform.
• The EOSC-CONNECT Evaluation Committee, composed of representatives of consortium partners, for the purpose of evaluating FSTP proposals. Evaluators are bound by confidentiality and conflict-of-interest rules.
• Consortium beneficiaries and affiliated entities involved in Task 1.3 (engagement, dissemination) and in leading National Node activities in their respective countries – see the consortium list in Annex A – to the extent necessary to organise workshops, training and National Node onboarding you take part in.
• Website hosting, e-mail and IT infrastructure providers engaged to operate and maintain the Website and its services.
• Professional advisers (accounting, legal, tax) engaged by Trust-IT in relation to the administration of the FSTP grants.
More information on these processors, and copies of the relevant data-processing agreements, is available upon written request to info@eosc-connect.eu.
6. International transfers – non-EU/EEA National Nodes
EOSC-CONNECT's consortium and National Node activities extend to four countries outside the EU/EEA: Norway, Switzerland, Serbia and North Macedonia.
• Transfers to Norway (EEA/EFTA) and Switzerland (subject to a European Commission adequacy decision) are treated as intra-EEA transfers and do not require additional safeguards.
• Transfers to Serbia and North Macedonia (non-adequate third countries) are carried out on the basis of the European Commission's Standard Contractual Clauses (SCCs) or another valid transfer mechanism under Chapter V GDPR, entered into with the relevant consortium partner (IPB for Serbia; UKIM for North Macedonia).
No personal data is knowingly transferred outside these arrangements. Where the FSTP scheme results in a grant to a third party established outside the EU/EEA, the same safeguards will be applied before any personal data is shared.
7. Other recipients – the granting authority (European Commission / REA)
Under Article 15 of the EOSC-CONNECT Grant Agreement, personal data relating to the implementation, management and monitoring of the grant (e.g. data of researchers or staff involved in reported activities) may need to be transferred to the granting authority — the European Research Executive Agency (REA), under powers delegated by the European Commission. That processing is carried out under the responsibility of REA as an independent data controller, in accordance with Regulation (EU) 2018/1725 and the European Commission's Funding & Tenders Portal Privacy Statement.
Where your Personal Data is transferred to the granting authority for this purpose, EOSC-CONNECT will inform you and provide you with the Portal Privacy Statement, available at: https://ec.europa.eu/info/funding-tenders/opportunities/docs/2021-2027/common/ftp/privacy-statement_en.pdf (or successor URL published by the European Commission).
EOSC-CONNECT may also be required to disclose Personal Data to public authorities where required by applicable law or a binding order (e.g. tax authorities, OLAF, the European Court of Auditors, in line with Article 25 of the Grant Agreement).
8. Retention of personal data
• Service provision / Website accounts: kept for as long as your account remains active, plus a reasonable period thereafter to protect Trust-IT's legitimate interests relating to potential liability.
• FSTP Open Call data: proposal, evaluation, contracting and monitoring data are kept for the duration of the funded activity and, thereafter, for the record-keeping period required of beneficiaries under Article 20 of the Grant Agreement towards the granting authority (audits and controls may be carried out for a period after the final payment, as set out in the Grant Agreement).
• Events/Webinars: kept for the period necessary to organise and report on the event, plus any period required to demonstrate compliance with EU funding and dissemination rules.
• Marketing: kept from the moment you give consent until it is withdrawn.
• Browsing data: not kept for more than 60 business days, save where needed to investigate faults or abuse.
More information on applicable retention periods is available upon written request to info@eosc-connect.eu.
9. Data subjects' rights
As a data subject, you are entitled to exercise the following rights vis-à-vis Trust-IT (as data controller), at any time:
• Access your Personal Data (and/or obtain a copy of it), and information about how it is processed;
• Rectify or update inaccurate or incomplete Personal Data;
• Request erasure of your Personal Data, where processing is unnecessary or unlawful;
• Request restriction of processing, in specific circumstances set out in the GDPR;
• Exercise your right to data portability;
• Object to processing based on legitimate interest, on grounds relating to your particular situation;
• Withdraw your consent at any time, where processing is based on consent (e.g. Marketing, special categories of data), without affecting the lawfulness of prior processing.
You can exercise these rights by writing to info@eosc-connect.eu, or via the Website's contact form. You can unsubscribe from marketing communications at any time using the link at the bottom of every marketing e-mail, or via your account preferences.
You are also entitled to lodge a complaint with the competent supervisory authority for the protection of personal data — in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it) — or with the supervisory authority of your own country of residence, if you believe the processing of your Personal Data is unlawful.
10. Security measures
Trust-IT and the consortium partners involved in processing implement appropriate technical and organisational measures to protect Personal Data against unauthorised access, alteration, disclosure or destruction, consistent with the confidentiality and data-protection obligations set out in Article 15 of the Grant Agreement. Access to Personal Data is restricted to personnel who need it to implement, manage and monitor the relevant activity, and who are bound by confidentiality obligations.
11. Amendments
This Privacy Policy entered into force on 01/09/2026. Trust-IT, on behalf of the EOSC-CONNECT consortium, reserves the right to amend or update this Privacy Policy, including as a result of changes in applicable law or in the project's activities. Material changes will be notified on the Website, and you are invited to review this page periodically.
Annex A – EOSC-CONNECT Consortium (data recipients for National Node / dissemination activities)
- CSC CSC – Tieteen tietotekniikan keskus Oy Finland Coordinator (BEN)
- GRNET National Infrastructures for Research and Technology Greece BEN
- CNRS Centre National de la Recherche Scientifique France BEN
- INRAE Institut National de Recherche pour l'Agriculture, l'Alimentation et l'Environnement France AE (of CNRS)
- IRD Institut de Recherche pour le Développement France AE (of CNRS)
- INRIA Institut National de Recherche en Informatique et Automatique France BEN
- ICSC Centro Nazionale di Ricerca in HPC, Big Data and Quantum Computing Italy BEN
- INFN Istituto Nazionale di Fisica Nucleare Italy AE (of ICSC)
- GARR Consortium GARR Italy BEN
- Sikt Sikt – Kunnskapssektorens tjenesteleverandør Norway BEN
- Sigma2 Sigma2 AS Norway AE (of Sikt)
- ZBW Deutsche Zentralbibliothek für Wirtschaftswissenschaften – Leibniz-Informationszentrum Wirtschaft Germany BEN
- SURF SURF BV Netherlands BEN
- VR Vetenskapsrådet – Swedish Research Council Sweden BEN
- TU Graz Technische Universität Graz Austria BEN
- OKMAPS Open Knowledge Maps – Verein zur Förderung der Sichtbarkeit wissenschaftlichen Wissens Austria AE (of TU Graz)
- TU Wien Technische Universität Wien Austria BEN
- UKIM Ss. Cyril and Methodius University in Skopje North Macedonia BEN
- IPB Institut za Fiziku Serbia BEN
- CSIC Agencia Estatal Consejo Superior de Investigaciones Científicas Spain BEN
- ETH Zürich Eidgenössische Technische Hochschule Zürich Switzerland BEN
- CERN Organisation Européenne pour la Recherche Nucléaire Switzerland BEN (IO)
- Trust-IT Trust-IT Services srl Italy BEN – Data Controller (Website, FSTPs)
- COMMpla COMMpla Srl Italy AE (of Trust-IT) – FSTP platform co-operator