Privacy statement 果冻传媒

Privacy

Eindhoven University of Technology (hereinafter referred to as 果冻传媒) handles personal data responsibly and in compliance with the General Data Protection Regulation (GDPR) and other applicable laws and regulations (such as the Telecommunications Act, Civil Code and Higher 果冻传媒 and Research Act). This Privacy statement provides information about the personal data the 果冻传媒 has collected regarding your relation with us, the purposes for which it is collected, and how your personal data is stored and processed. It also explains how you can use your privacy rights and provides additional relevant information.

This Privacy statement applies to personal data that is processed within 果冻传媒, excluding our websites. For details on how we handle website visitor data and use cookies, please refer to 果冻传媒鈥檚 cookie statement.

We have tried to present all information in a clear and readable way. However, if you still have questions after reading this, you can always contact us via the contact details at the end of this Privacy statement.

Responsibility for your personal data鈥

The Executive Board of 果冻传媒 is responsible for processing your data as defined by the GDPR (in the GDPR this is called the 鈥渃ontroller鈥). This means that the 果冻传媒鈥檚 Executive Board is responsible for carefully processing your personal data. 

Personal data we process and its purposes

果冻传媒 processes personal data from various individuals for different purposes, depending on the relationship they, and therefore you, have with 果冻传媒. We receive most of this personal data directly from you, but we may also receive personal data from other organizations who are authorized or required to share this with us.

Below you will find detailed information on the types of personal data processed and the purposes for each type of relationship. These overviews are based on the most common processes within 果冻传媒. Information on incidental or very specific processing of personal data will be provided in separate supplementary privacy statements.

  • Applicants & employees

  • (Prospective) students

  • Alumni

  • Campus visitors

  • Visitors to the 果冻传媒 network

  • Research participants

Legal basis for processing your personal data

To process your personal data, 果冻传媒 must have a valid reason. The GDPR specifies several legal bases for data processing, and all data processing at 果冻传媒 is based on one of these legal bases.

  • Performance of a contract

  • Legal obligation

  • Public task

  • Legitimate interest

  • Consent

  • Vital interest

Sharing of your personal data

The basic principle is that only 果冻传媒 will use your personal data, and access is restricted to employees who need your personal data to perform their work. Your personal data will never be rented or sold. However, there are certain situations where we share your personal data with other parties. When we do, we ensure that only the minimum necessary data is provided, and that these parties are obligated to handle your personal data with care through contractual agreements.

These other parties fall into the following categories:

Government agencies and supervisory authorities
In some cases we are legally required to share your personal data with third parties such as government agencies or supervisory authorities. These could be for example:

  • Government agencies such as the Tax and Customs Administration, the Immigration and Naturalisation Service (IND, in case of an employee or student from outside the EU), Employee Insurance Agency (UWV), 果冻传媒 Executive Agency (DUO)
  • The Occupational Health and Safety Service
  • Law enforcement agencies (e.g. the police) and other supervisory authorities
  • External accountant (e.g. audits by the European Commission for research subsidies)
  • Pension fund ABP

Additionally, when you have given permission for this yourself, we may share your data with a trade union or interest group.

Other education and research institutions 
果冻传媒 may share your personal data with other educational and research institutions if this is necessary for providing education or conducting scientific research. This may include collaborative programs (such as a joint degree), exchange programs and collaborative research projects. We ensure that these parties handle your data confidentially and carefully by establishing written agreements.

Additionally, 果冻传媒 may share personal data of employees with research funding organizations, such as the Dutch Research Council NWO, the European Union (Horizon Europe) to secure research grants and subsidies.

Data processors
果冻传媒 may engage other organizations to manage or organize certain aspects of our activities on our behalf. When these organizations handle personal data in this context, they are referred to as data processors. 果冻传媒 has agreements in place with these data processors to ensure confidential and careful handling of personal data. Examples of such processors are our student registration system Osiris, safe exam workspace Schoolyear, PhD registration system HoraFinita, campus card supplier ID-Ware, applicant tracking system Varbi, service management system TOPdesk, HR and payroll system AFAS, financial systems ProActis and Unit4, and learning management system Canvas.

University Fund (specifically for alumni)
Alumni data is shared with Stichting Universiteitsfonds Eindhoven (hereinafter referred to as UFe), to promote 果冻传媒鈥檚 mission by offering expertise in fundraising and alumni relations. The sharing of data with UFe is regulated in a Covenant on data protection in accordance with the GDPR, to ensure that alumni data is handled confidentially and carefully. Additionally, we may share alumni data with affiliated organizations that support alumni, such as alumni associations and alumni circles.

Processing personal data outside the European Economic Area (EEA)

果冻传媒 strives to process your data only within the European Economic Area ("EEA") by storing your data on a server in the EEA whenever possible. However, there may be exceptions, such as transferring data to a university outside the EEA in the context of an exchange program.

When engaging processors, we require them to store personal data on servers in the EEA. When this is not possible, we implement necessary measures to ensure adequate protection of your personal data.

Each transfer of personal data is carefully assessed through a standardized process to ensure adequate protection, both within and outside the EEA. This process is regularly updated to comply with the latest legal and regulatory developments.

Retention period

果冻传媒 retains your personal data in compliance with the GDPR, ensuring that data is not kept longer than necessary to achieve its intended purposes. The exact retention period depends on the type of personal data and the purpose for which it is processed. We adhere to statutory retention periods where applicable, such as those specified in the Selection List for Universities and University Medical Centres 2020, the Public Records Act, and other laws (such as tax and labor laws).

Job application
If you are not hired, 果冻传媒 will keep your data for a period of 4 weeks after the application procedure ends. If you have given permission to process your data with a view to being informed about other vacancies, we keep your data in accordance with the consent you have given, for 1 year after the end of the application process.

Scientific research
You can find the retention period for your personal data in the information letter, introductory materials, or privacy statement accompanying your research. Generally, for research conducted in the public interest, we will retain your data for at least 10 years after publication of the research results. This is necessary to verify the research results and ensure the research is repeatable. We never retain more data than necessary for this purpose and anonymize or pseudonymize it as soon as possible. Contact information, for example, is often deleted soon after the conclusion of the research project.

Camera surveillance
Surveillance footage from security cameras is retained for a maximum of 1 week. If an incident such as a theft or accident has occurred on campus, the images may be retained for a longer period to analyze what exactly happened or to share the images with the police. If this is the case, images will be deleted after the incident has been fully dealt with.

Security

果冻传媒 makes sure that personal data is treated confidentially. We take appropriate technical and organizational measures in order to protect data against loss or any form of unlawful processing. Our security policy and standards are regularly brought in line with new regulations, best practices and developments.

Technical measures
To optimally protect your personal data against unauthorized access or use, 果冻传媒 has appropriate security technology in use. For example, many of our systems work with two-factor authentication and we have implemented email scanning to detect spam and malware. For research data, we use well鈥憇ecured storage infrastructure. Data communication takes place via secure connections.

Organizational measures
果冻传媒 has taken a large number of measures to ensure that your data is not only technically secured, but that the chance of human error and misuse is also kept to a minimum. Your personal data can only be accessed by employees who need your data to properly carry out their duties. Additionally, employees are to be screened if necessary and have a duty of confidentiality. When we engage a third party in order to process personal data, we always check that this third party has an adequate level of security.
 

If despite this strict security, an incident occurs, we will resolve the incident as soon as possible and take measures to ensure it cannot happen again. We report data breaches that pose a risk to the rights and freedoms of data subjects to the Dutch Data Protection Authority.

Your rights

The GDPR provides you with a large number of rights with regard to your personal data. You have the right to view your data and to have it corrected or deleted. In certain cases, you have the right to have the processing of your data temporarily frozen ('restricted') and the right to object to the processing of your data. And finally, in some cases you have the right to have a whole set of data that we have about you transferred to another organization. This is called the right to data portability.

If you wish to exercise these rights, please contact us at privacy@tue.nl or the (postal) address at the bottom of this webpage. Please note that we may ask for additional information to verify your identity when exercising these rights, if we are unsure about the requester鈥檚 identity. 

If you have given consent to process your personal data for a certain purpose, you may always withdraw this consent. Note however that withdrawal of your consent is not retroactive. Instructions on how to withdraw consent will be provided when you first give your consent. If you no longer have this information, you can also contact us via the contact details at the end of this Privacy statement. 

Questions or complaints

If you have questions about how we process your personal data, please contact us via privacy@tue.nl or the (postal) address at the bottom of this webpage. We will be happy to assist you.

If you believe that your personal data is being processed in breach of the GDPR or you are unhappy about how a request related to your rights has been handled, you may submit a complaint to our Data Protection Officer (DPO) via dataprotectionofficer@tue.nl. The DPO is the link between 果冻传媒 and the Dutch Data Protection Authority. The DPO acts independently and can discuss your complaint with or ask for advice from the . If you disagree with the outcome of the DPO鈥檚 handling of your complaint, you can submit a complaint directly to the .

For IT security incidents and emergencies, you can contact CERT@tue.nl. For any related questions, you can reach out to the security team at security.operations@tue.nl.

 

This privacy statement was last amended in March 2025 and is subject to change. Please check to make sure you are consulting the most recent version.