Privacy Policy

1. Overview of Data Protection

This Privacy Policy explains how personal data are processed when you visit and use the QuantumPUF project website.

Personal data are any information relating to an identified or identifiable individual.

We take the protection of personal data seriously and process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Croatian data-protection legislation.

2. Data Controller and Contact

The controller responsible for the processing of personal data described in this Privacy Policy is:

Research and Innovation Services d.o.o. (RISE)
Ulica Republike Austrije 33
10000 Zagreb
Croatia

E-mail: contact-us@rise-innovation.eu
Data protection contact: dataprotection@rise-innovation.eu

RISE d.o.o. is beneficiary in the Horizon Europe project QuantumPUF – PORTABLE READOUT QUANTUM PHYSICAL UNCLONABLE FUNCTIONS USING LUMINESCENT MATERIALS FOR AUTHENTICATION, Grant Agreement No. 101258015.

RISE d.o.o. is a member of the EURICE Group and may use shared EURICE Group IT infrastructure and support services. Where another Group entity or service provider processes personal data on behalf of RISE d.o.o., appropriate data-processing arrangements pursuant to Article 28 GDPR apply.

3. Data Processing on this Website

When you visit this website, certain technical information may be processed automatically to ensure the proper and secure operation of the website.

This may include:

  • IP address;
  • browser type and version;
  • operating system;
  • date and time of access;
  • pages or files accessed;
  • referring website; and
  • technical server log information.

The processing of these data is based on Article 6(1)(f) GDPR, reflecting our legitimate interest in providing, maintaining and securing the project website.

Technical data are retained only for as long as necessary for website operation, security and troubleshooting.

SSL/TLS Encryption

This website uses SSL/TLS encryption to protect data transmitted between your browser and the website.

You can recognise an encrypted connection by the https:// address and the lock symbol displayed by your browser.

Please note that no method of transmission over the internet can guarantee absolute security.

4. Cookies and Website Analytics

This website may use cookies and basic website analytics to understand how the website is used and to improve its content and performance.

Technically necessary cookies may be used where required for the operation, functionality and security of the website.

Where optional analytics or other non-essential technologies require consent, they will only be activated after consent has been provided through the website's cookie settings. You can change or withdraw your cookie choices at any time through the available cookie settings.

5. Project Communication and Website Content

This website provides information about QuantumPUF, including its objectives, consortium, activities, events, progress and results.

Project communication may include names, professional roles, photographs, videos, quotations or other information relating to project participants, speakers and stakeholders.

Where consent is required for the publication of identifiable photographs, videos or similar communication content, RISE obtains consent separately in accordance with Article 6(1)(a) GDPR.

Where processing is based on consent, you may withdraw your consent at any time with effect for the future by contacting:

dataprotection@rise-innovation.eu

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

6. Contact and Event Registration

If you contact the QuantumPUF project through the website or register for a project event, we may process personal data such as your:

  • name and surname;
  • organisation and professional position;
  • e-mail address;
  • event registration or participation information; and
  • information contained in your enquiry.

These data are processed only to respond to your enquiry or to organise and administer the relevant project activity or event.

Depending on the activity, processing may be based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.

Event registration may be managed using Microsoft Forms / Microsoft 365. Where additional processing requires consent, for example the use of identifiable photographs or videos for communication purposes, consent will be requested separately.

7. LinkedIn and Social Media

QuantumPUF uses LinkedIn and may use other project social-media channels to communicate about project activities, events, progress and results.

When you visit or interact with a project social-media page, the relevant platform provider processes personal data according to its own privacy policy.

RISE may receive information about interactions with project content, such as comments, messages, reactions, follower information and aggregated statistics. We use this information to communicate with stakeholders and understand the reach and engagement of project communication.

For certain LinkedIn Page Insights, RISE and LinkedIn Ireland Unlimited Company may act as joint controllers in accordance with LinkedIn's applicable Page Insights arrangements.

Further information about the processing of personal data by LinkedIn is available in the LinkedIn Privacy Policy.

8. Recipients and Service Providers

Where necessary, personal data may be accessible to:

  • authorised RISE staff;
  • relevant QuantumPUF project partners;
  • IT, website and hosting service providers;
  • shared EURICE Group IT infrastructure and support services;
  • Microsoft and other approved service providers used for project activities and communication; and
  • funding bodies, auditors or public authorities where required by applicable legal or contractual obligations.

Where service providers process personal data on behalf of RISE, appropriate data-processing arrangements pursuant to Article 28 GDPR apply.

9. Transfers Outside the European Economic Area

Some online, IT or social-media service providers may process personal data outside the European Economic Area.

Where such transfers take place under RISE's responsibility, an appropriate transfer mechanism under Chapter V GDPR is used, such as an adequacy decision or appropriate safeguards, including Standard Contractual Clauses where applicable.

Please note that information published on publicly accessible websites or social-media platforms may be accessible worldwide.

10. Retention

Personal data are retained only for as long as necessary for the purposes for which they were processed.

Certain records may be retained for longer where required by applicable legal, contractual or Horizon Europe project obligations.

Personal data that are not required for such purposes will not be retained solely because of the project record-keeping period.

Where consent is withdrawn, RISE will stop future processing based on that consent and, where reasonably possible, remove the relevant content from channels under its control. Copies already shared, indexed or retained by third parties or platform providers may remain outside RISE's control.

11. Your Data Protection Rights

Subject to the conditions set out in the GDPR, you may have the right to:

  • access your personal data (Article 15 GDPR);
  • rectify inaccurate personal data (Article 16 GDPR);
  • request erasure (Article 17 GDPR);
  • restrict processing (Article 18 GDPR);
  • receive your data in a portable format where applicable (Article 20 GDPR);
  • object to processing where applicable (Article 21 GDPR); and
  • withdraw consent at any time where processing is based on consent (Article 7(3) GDPR).

To exercise your rights or ask a question about the processing of your personal data, please contact:

dataprotection@rise-innovation.eu

12. Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data-protection supervisory authority.

For RISE, the competent supervisory authority is:

Croatian Personal Data Protection Agency
Agencija za zaštitu osobnih podataka – AZOP
Ulica Metela Ožegovića 16
10000 Zagreb
Croatia

E-mail: azop@azop.hr
Website: www.azop.hr

13. Updates to this Privacy Policy

This Privacy Policy may be updated where necessary to reflect changes in the project website, communication activities, service providers or applicable legal requirements.

Last updated: October 2026