Description of the Service

The EGI Accounting service (hereinafter referred to as: "the service" or "Accounting") stores user accounting records from various services offered by EGI, such as Cloud, High Throughput Compute and storage usage. Accounting data is sent, using the Messaging service, to the central Accounting Repository and can be consulted online through the EGI Accounting Portal.

This privacy notice describes how we, the EGI Foundation (hereinafter referred to as "we" or "the Data Controller"), collect and process data by which you can be personally identified ("Personal Data") when you use the service.

Data controller

  EGI Foundation
  Science Park 140
  1098 XG Amsterdam
  Netherlands

Data protection officer

  EGI Foundation
  Data Protection Officer
  Science Park 140
  1098 XG Amsterdam
  Netherlands

E-mail: dpo@egi.eu

Jurisdiction and supervisory authority

Jurisdiction: NL, Netherlands
EGI Foundation's lead supervisory authority is the Dutch Data Protection Authority. They can be contacted at https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-us .

Personal data processed

The service may process the following personal data:

Purpose of the processing of personal data

The purpose of the collection, processing and use of the personal data mentioned above is:

Legal basis

The legal basis for processing personal data is: Legitimate interests pursued by the controller or by a third party according to Art. 6 (1) (f) GDPR.

Third parties to whom personal data is disclosed

Personal data will not be used beyond the original purpose of their acquisition. In particular, the data you provide to us will not be used for marketing.

For the purposes given in this privacy policy, personal data are passed to the following third parties:

Within the EU / EEA:

The records of your use and technical log files produced by the Service components may be shared, via secured mechanisms, for security incident response purposes with other authorised participants in the academic and research distributed digital infrastructures authorised by EGI Foundation governance, only for the same purposes and only as far as necessary to provide the incident response capability where doing so is likely to assist in the investigation of suspected misuse of Infrastructure resources.

Outside the EU / EEA:

Any data transfer to a third country outside the EU or the EEA only takes place under the conditions contained in Chapter V of the GDPR and in compliance with the provisions of this privacy policy and any related policies adopted by the EGI Federation.

Your rights

You can exercise the following rights at any time by contacting our data protection officer using the contact details provided in the Data Protection Officer section:

Data retention and deletion

The records of your use and technical log files produced by the service components will be deleted or anonymised after, at most, 18 months.

Security

We take appropriate technical and organisational measures to ensure data security and the protection against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access. A comprehensive overview of the technical and organisational measures taken by EGI Foundation can be found at the EGI Documentation Database.

Data Protection Code of Conduct

EGI Foundation is conforming to GEANT Code of Conduct and your personal data will be processed in accordance with the REFEDS Code of Conduct for Service Providers and the EGI-doc-2732-v3: Policy on the Processing of Personal Data.

Based on AARC Policy development kit (licenced under CC BY-NC-SA 4.0)