ECCO IT HUB (= ECCO DATABASE) –  PRIVACY POLICY ACCORDING TO GDPR

ECCO IT HUB consists of the following organisational entities with their registered seat in 1030 Wien, Ungargasse 6/13, and is based on a joint controllership agreement according to Article 26 General Data Protection Regulation (“GDPR”):

(together hereafter referred to as “ECCO IT HUB” or “we”).

1. Purpose

ECCO IT HUB solely processes your personal data for the purpose of:

2. Legal basis of data collection

ECCO IT Hub only processes your personal data as follows:

 

 

 

Should you have a strong objection about a specific item, you can still address ECCO Office as outlined in point 7 below.

These photos and film footage are intended for reporting about the event on the ECCO Website, in the ECCO eNewsletters, in promotional material (such as Congress break slide) and in printing material (such as the ECCO Anniversary Book series). 

3. Data categories: What kind of data?

Your personal data will not be subject to further processing in a way and manner that are incompatible with the intended purposes listed above.

ECCO Website

ECCO IT Hub processes the IP address of ECCO Website visitors and cookie information chosen by you and as explained in the cookies setting banner:

 

 

 

ECCO Portal Account Holders in ECCO IT Hub

ECCO IT Hub processes the following personal data as provided by you in setting up an ECCO Portal Account and choosing to participate in further interactions:

If you participate in the ECCO App and/or an ECCO virtual event, you can choose to share your personal information as well as your opinion in public debates with the other participants.

You may withdraw your consent regarding consent based data at any time. The withdrawal of your consent shall not affect the lawfulness of processing based on consent before its withdrawal.

4. Data received from third parties (Article 14 of the GDPR)

Please note that in the context of the following group registration, nomination and submission processes, ECCO IT HUB received your personal data via the contact person of the respective group registration:

 

 

 

 

Please note that data subjects of such group registrations are contacted by ECCO Office within the first month with full transparency about this general ECCO Privacy Policy outlined here. 

As a data subject, you can address the contact point and data protection officers indicated above as well as the data protection authority indicated below.

5. Data recipients and sub-processors:

In order to adequately fulfil the intended purposes listed above, ECCO IT Hub contracts primarily data processors based in the European Union – including but not limited to:

 

In the group registration processes, group leaders have a restricted duplicate-check option via entering the correct email address and name.

 

 

 

 

 

In case you explicitly consent to badge scanning in the ECCO Congress exhibition or satellite symposia, we transfer your personal data (Name; Contact details) to the exhibition or sponsor companies of the congress, some of which do have their head-quarters in the USA.  The current list of exhibitors can be found on the annual Congress Website (accessible via https://www.ecco-ibd.eu/congresses-and-events.html )  in the exhibitor section. You may withdraw your consent at any time. The withdrawal of your consent shall not affect the lawfulness of processing based on consent before its withdrawal.

6. Data storage time-frame:

ECCO IT Hub of course also observes the principle of storage limitation for personal data.

Personal (non-scientific) supporting documents (such as letters of intent, CVs, publication lists), submitted in the context of applications to open calls, event and project participation(s)are stored not longer than 3 years.

7. Your rights as data subject:

Should you be affected by our processing of personal data, you have the right at any time to request access to, rectification, or erasure of personal data, or restriction of the processing concerning your personal data or to object to processing as well as the right to data portability.

As data subject, you may withdraw your consent for

from ECCO IT HUB to process your personal data at any time under This email address is being protected from spambots. You need JavaScript enabled to view it. or This email address is being protected from spambots. You need JavaScript enabled to view it. or by postal mail to ECCO Office, Ungargasse 6/13, A-1030 Vienna, Austria.

Please note that the withdrawal of your consent shall not affect the lawfulness of processing based on consent before its withdrawal, and that in certain circumstances ECCO IT Hub is entitled or else required to process certain forms of personal data for a period extending beyond the withdrawal of consent, either due to our contractual relationship with you, or else due to legal requirements.

According to Art. 13 (2) e GDPR, you are not obliged to agree to the processing of your data. However, please also note

You directly access and modify your information via your personal log-in under the following link: https://cm.ecco-ibd.eu/cmgateway/member/NW/index.html?module=relationmanager&config=normal#manageprofiles.

In case you believe that the processing of your personal data does not comply with the provisions of data protection, you can – other legal remedies in law courts or under administrative law notwithstanding – make a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Austria, the supervisory authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde).

According to Art. 13 (2) f GDPR, ECCO IT HUB does not generate automatic decisions including data profiling.

8. Nature of joint data processing by ECCO and OCEAiN:

The essence of the ECCO IT Hub arrangement according to Article 26 GDPR:

(Updated with JCA revised text per March 15, 2020)

DESCRIPTION OF JOINT DATA PROCESSING OPERATIONS:

The ECCO Database constitutes the core for all projects on the side of ECCO Association as well the side of OCEAiN GmbH, who is in charge of organising the annual ECCO Congress, the e-Learning platform and publishing the ECCO News magazine.

As the ECCO Congress constitutes the annual meeting of the ECCO Members and other stakeholders in the field of inflammatory bowel diseases, the ECCO Database has a significant intersection set of data subjects as the same data subjects can be ECCO Members and Congress Delegates. 

The data subjects in the ECCO Database are health care professionals, pharma industry representatives, patient representatives and students in the field of inflammatory bowel diseases with an interest in both ECCO Association activities and ECCO Congress and e-Learning activities. In addition, the ECCO Database captures press contacts, as well as employees and contact persons of tour operator agencies booking group registrations and of supplier companies, which are contracted to implement projects of ECCO and OCEAiN. 

MEANS OF JOINT DATA PROCESSING OPERATIONS: 

With the increasingly enhanced digitalisation of the joint data processing operations over the past years, the ECCO Website with a Login-Area called the ECCO Portal constitutes the main entrance door to all activities of ECCO and OCEAiN.

The ECCO Portal Account is the “front” side entrance door to and, after personal Login-In, the front side display of the respective personal data-set captured in the ECCO Database.

As soon as an ECCO Portal Account holder applies for ECCO Membership or engages in another activity, joint processing takes place in the ECCO Database: the use of synergy effects in data harmonization also aims to facilitate access of  data subjects to activities within the larger framework of ECCO IT Hub (e.g. distribution of our newsletters, promotion of our Congress and educational/scientific activities, access facilitation via the publisher/distributor of our publications). 

Depending on the status of the data subject (e.g.: Membership status, Congress Registration statutes, Scientific Reviewer Status), the data subject can access various online tools (e.g.: online application process per open call, registration process for workshops or ECCO Congress, industry webshop)  and various levels of online content (e.g.: applications received for internal or scientific review, e-Learning material, meeting documents).

Most of the functionalities are directly provided by the ECCO Database suppliers and do not need data transfers to other suppliers.

The ECCO Website and the ECCO Database are hosted on a rented ECCO Server space in Austria.

Additional Platforms and technology needed are solved with a single-sign on technology with the ECCO Database, which are in particular

 

In addition, two further joint data processing platforms are used to facilitate project management and communication:

PURPOSE OF JOINT DATA PROCESSING OPERATIONS: please refer to point 1 above.

CATEGORIES OF DATA PROCESSED UNDER THIS AGREEMENT: please refer to point 3 above.

DATA STORAGE LIMITATION: please refer to point 6 above.

ALLOCATION OF DATA PROTECTION TASKS/DUTIES (under Art. 26 GDPR)

The data protection tasks done jointly are

 

The data protection tasks done separately are:

 

CONTACT POINT ACCORDING TO ARTICLE 13, 14 and 26 GDPR:

ECCO Office
Ungargasse 6/13, A-1030 Vienna, Austria.
Tel: +43-(0)1-710 2242-0
Fax: +43-(0)1-710 2242-001

E-Mail: This email address is being protected from spambots. You need JavaScript enabled to view it. or This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Data ProTection Officer ACCORDING TO ARTICLE 37 GDPR:

Knyrim Trieb Rechtsanwälte OG

Mariahilfer Straße 89a, A-1060 Wien

T: +43 1 909 30 70, F: +43 1 9093639

E: This email address is being protected from spambots. You need JavaScript enabled to view it., W: www.kt.at

FN 462250f, HG Wien