privacy policy

1.1. Introduction

1.1. Introduction
This Privacy Policy is aimed at illustrating the means and purposes of the processing of personal data carried out by FAV INNOVATION and Technologies COOP. v. (CIF F01612845), having its registered office in Spain, in its quality of data controller (hereinafter “FAV INNOVATION and Technologies COOP. v.” or the “Controller”), through the website https://www.athena-horizon.eu/ (hereinafter the “Website”).

Please note that this Privacy Policy applies to anyone who accesses and visits the ATHENA Project Website or otherwise interacts with the web services offered on the Website (the “User”).

Pursuant to Article 5 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Processing of the Personal Data carried out by FAV INNOVATION and Technologies COOP. v. for the development and management of the Website will be based on the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and accountability.

Any term indicated in capital letters shall have the meaning attributed to it within the GDPR, or otherwise provided hereto.

1.2. Data Controller

The data Controller is FAV INNOVATION and Technologies COOP. v. (CIF F01612845), Spain.
Privacy contact email: privacy@athena-horizon.eu.

1.3. Which kind of Personal Data are collected

1.3.1. Traffic and Internet data

The computer systems and software procedures used to operate the Website acquire, during their normal operation, certain technical data whose transmission is implicit in the use of Internet communication protocols (e.g., IP address, browser type, OS, referring URLs, pages visited, timestamps, time on page, internal path analysis and other parameters related to the User’s device and environment). These technical/IT data are collected and used only in an aggregated and not immediately identifiable manner. They could be used to ascertain responsibilities in case of crimes against the Website, or upon public authorities’ request.
In order to enable such collection, the Website uses cookies. Please read the Cookie Policy for further information.

1.3.2. Personal data provided by the User

When using the contact form, Users may provide personal data such as name, email, organisation, country, and the message content (including any information the User chooses to include).

1.4. Why Personal Data are processed and the Lawful basis

User’s Personal Data are processed exclusively for the following purposes and exclusively in the framework of the research Project’s activities (more information on the Project is available on the Website):

  • To fulfil requests submitted via the contact form. This processing is necessary to respond to the User’s enquiry and is based on the Controller’s legitimate interests (Art. 6.1.f GDPR) in handling and responding to such requests. Where the form includes a consent checkbox for follow-up, processing will rely on consent (Art. 6.1.a).

  • To comply with legal obligations and to ascertain responsibilities in case of any computer crimes against the Website (Art. 6.1.c GDPR).

The User’s Personal Data are not used for automated decision-making, including profiling, nor are they further processed for incompatible purposes.

1.5. Cookies

The Website uses cookies. Further information and choices are available at: https://www.athena-horizon.eu/cookies-policy.

1.6. For how long Personal Data are kept

The Controller keeps Personal Data only for the time necessary to fulfil the purposes for which the data were collected and to comply with legal obligations:

  • Contact enquiries: retained for up to 180 days after the request is closed.

  • Server/security logs: retained for up to 180 days for security and diagnostics.

After these periods, data are deleted or irreversibly anonymised.

1.7. How Personal Data are secured

Personal Data may be processed through information technology tools, manually or electronically, under appropriate technical and organisational measures to ensure security and confidentiality and to prevent risks arising from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Access is restricted to authorised personnel and processors on a “need-to-know” basis, subject to confidentiality obligations.

1.8. Who may access Personal Data

Personal Data collected by the Controller may be shared with:

  • Members of the ATHENA Consortium, only to fulfil User requests relating to project activities and objectives.

  • Service providers engaged by the Controller (e.g., hosting/infrastructure), acting as processors under written agreements and located within the European Economic Area (EEA), exclusively for IT/organisational/support needs.

The Controller may disclose User information to comply with the law, a judicial proceeding, court order or other legal process, or where necessary to investigate, prevent or take action regarding illegal activities, suspected fraud, threats to safety, or as evidence in litigation.

Except as above, and unless required by law or authorised by the User, Personal Data are not shared with other organisations. In particular, the Controller does not transfer Personal Data outside the EEA in connection with this Website. Should a transfer outside the EEA become necessary in the future, it will be carried out in accordance with the GDPR and the User will be duly informed.

1.9. Redirection to other websites

The Website may include links to third-party websites or platforms. The Controller assumes no responsibility for processing that may occur through such third-party sites. Users should review the privacy policies of those sites/platforms, which are provided and managed by autonomous controllers.

1.10. Users’ rights and how to exercise them

Under the GDPR, Users have the rights to be informed, access, rectification, erasure (“right to be forgotten”), restriction, portability, to lodge a complaint with a supervisory authority, to withdraw consent (where consent applies), and to object to certain processing.
Where Users wish to exercise their rights in the context of one or several specific processing operations, please describe them in the request. User requests will be handled within a maximum of 30 working days.

1.11. Contact information

To exercise GDPR rights or for any questions/concerns regarding this Privacy Policy, please contact: privacy@athena-horizon.eu.

1.12. Changes

Where appropriate, Users will be notified of material changes to this Privacy Policy (e.g., by email or on-site notice).

1.13. Entry into force

This Privacy Policy enters into force on the date of its publication on the Website, version 1.0.

© 2025 Athena – All rights reserved