Privacy Policy

Version 2026-09.3. Last updated: 26 September 2026.

This notice explains how ARSID handles personal data on this website and in the management of its membership, in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Danish Data Protection Act.

Who is responsible for your data

The data controller is ARSID – Association of Italian Researchers and Scientists in Denmark (Associazione Ricercatori e Scienziati Italiani in Danimarca), CVR 42601047, c/o Istituto Italiano di Cultura, Gjørlingsvej 11, 2900 Hellerup, Denmark. For any question about your data, write to info@arsid.org.

Visiting the website

This website does not use cookies for statistics, marketing or profiling, and it does not use analytics tools, advertising networks or social media trackers. Fonts and images are served from our own server, so your browser does not contact third-party services when you read our pages. For this reason there is no cookie banner.

Like any website, our hosting provider records technical data in server logs when a page is requested (IP address, date and time, page requested, browser type). These logs are used only to keep the website secure and working, on the basis of our legitimate interest (Art. 6(1)(f) GDPR), and are deleted automatically by the provider after a short period. Technical cookies are set only for the volunteers who log in to manage the website.

To protect the website against attacks, we use a security plugin (Wordfence). It checks requests to the website and login attempts, blocks those that look malicious, and records the IP address, date and time and the page requested for suspicious requests and failed logins. These records are kept on our own server, are used only for security on the basis of our legitimate interest (Art. 6(1)(f) GDPR), and are deleted automatically after 14 days. The plugin is supplied by Defiant Inc. (United States), which may receive technical data about suspicious requests in order to keep its security rules up to date. Depending on the features enabled, these data may include the IP address of the visitor or proxy, the URL requested, the HTTP headers and request body of suspicious requests, and the email address of the website administrator. Participation in the Wordfence Security Network is switched off. The transfer is covered by the Standard Contractual Clauses incorporated in Defiant’s Data Processing Addendum. The plugin sets no cookies for visitors.

Becoming and remaining a member

When you apply through the Join form we process: name and surname, email address, affiliation, role, ERC research domain, city in Denmark, an optional short biography and optional links to your institutional or LinkedIn profile, together with the member number we assign when you join (it identifies your record even if your email address changes), the date of your application, your choice about the Find a Member directory, the date of your last confirmation and the dates of the renewal messages we send you. Membership is free, so we never process payment data.

Your name and email address are necessary to register you and to contact you. We ask for your affiliation, role and city to check that you meet the membership requirements described on the Join page, and for your research area (ERC domain) to classify the membership by field, which we use to plan events and, if you agree, in the Find a Member directory. All other fields are optional.

We use these data to manage your membership: confirming your application, keeping the register of members required by our statutes, sending the annual renewal request, inviting you to assemblies and events, and informing you about the activities of the association. The legal basis is your membership relationship with the association (Art. 6(1)(b) GDPR): we need these data to register you as a member, to keep the register of members provided for by our statutes and to manage your membership. Invitations to assemblies and events and information about the activities of the association are also based on our legitimate interest in keeping members informed (Art. 6(1)(f) GDPR); you can object to them at any time.

Registering for an event

When you register for an event on the website, we collect the event you choose, your name, your email address, your affiliation (optional) and whether you are a member of ARSID. The form tool also records the type of browser and device used; it does not record your IP address. We use these data only to organise the event: to know who is coming, for the practical organisation of the event, and to send you the confirmation and any practical change to the programme. The legal basis is our legitimate interest in organising our events (Art. 6(1)(f) GDPR). Registering for an event does not make you a member and does not add you to our newsletter.

Emails and newsletter

We send members the association’s emails and newsletter (news about events, assemblies, calls and activities) from info@arsid.org. The mailing tool is installed on our own website, so your name, email address and list membership are not passed to an external newsletter service. We do not record whether you open our emails or click on their links, and we do not build profiles. Every newsletter contains a link to unsubscribe at once; unsubscribing from the newsletter does not end your membership, and messages about your membership itself (confirmation, renewal) will still reach you. The legal basis is your membership relationship (Art. 6(1)(b) GDPR) and our legitimate interest in keeping members informed about the association (Art. 6(1)(f) GDPR).

In autumn 2026 the association is moving to a new membership system. People registered in our previous list receive one email inviting them to register again, on the basis of our legitimate interest in informing former members (Art. 6(1)(f) GDPR). If you do not register, your address is deleted from the invitation list within 60 days of the invitation and is not used for any other purpose.

Find a Member directory (optional)

If you agree, your name, role, affiliation, city, ERC research domain, short biography and, if you provided them, your institutional website and LinkedIn profile appear in the public directory on this website, so that other researchers and partners can find you. The directory is publicly accessible and may be indexed by search engines. Your email address is never published. This use is based on your consent (Art. 6(1)(a) GDPR): it is optional, you can become a member without it, and you can withdraw it at any time from your personal member area or by writing to us, without affecting any publication made before the withdrawal.

Photos and videos from events

Photos and videos are taken at ARSID events and may be published on this website, on the association’s social media pages and in its printed materials, to document and present its activities. Because it is not practical to separate members who appear in group pictures, this use is based on the association’s legitimate interest in presenting its activities (Art. 6(1)(f) GDPR), and members acknowledge it when they join. You have the right to object at any time (Art. 21 GDPR): write to info@arsid.org or tell the photographer at the event, and we will avoid publishing pictures in which you can be recognised and remove those already published on the channels we manage.

How long we keep your data

  • Applications that are not confirmed through the link sent by email are deleted when the link expires, 24 hours after it is sent. If an application is still unconfirmed after 12 hours, we send one reminder with the same link.
  • The copy of your application kept by the form tool, including the technical data it records (IP address and browser), is deleted after 30 days; from then on your data exist only in the member record.
  • Event registrations are deleted within three months after the event.
  • Your membership lasts one year from the date you confirm it. At the end of that year we email you a personal renewal link, valid for 30 days, and, if you have not confirmed, one reminder with a further 30 days. If you do not confirm within that time, your record is deleted and you leave the public directory.
  • If you cancel your membership, you leave the public directory immediately and your record is deleted within 30 days.
  • We keep an anonymous log of deletions (date, reason, membership year) that contains no personal data.

Who receives your data

Your data are handled only by the volunteers who run the association, within the limits of their tasks. The website and the association’s mailbox are hosted by Aruba S.p.A. in the European Union, which acts as our data processor. We do not sell your data, we do not share them with sponsors or other third parties, and we do not transfer membership data outside the European Economic Area. The only data that may leave the European Economic Area are the limited security records described in the section on visiting the website.

Your rights

You have the right to access your data, to correct them, to have them deleted, to restrict or object to their processing, to receive them in a portable format and to withdraw your consents. Most of these actions are available directly in your personal member area, which you can reach through the link we send to your registered email address; for everything else, write to info@arsid.org. We reply within one month.

Where we process your data on the basis of our legitimate interest, you have the right to object at any time on grounds relating to your particular situation (Art. 21 GDPR); we will then stop the processing unless we can demonstrate compelling legitimate grounds.

If you believe that your data are not handled correctly, you can lodge a complaint with the Danish Data Protection Agency (Datatilsynet, www.datatilsynet.dk) or with the supervisory authority of the country where you live or work.

Changes to this notice

If we change the way we process personal data, we will update this page and its version number. Members will be informed of significant changes by email.

Scroll to Top