Privacy statement regarding protection of personal data in relation to the EGNOS and EDAS-Maritime User Support Websites, E-GNSS Call Centre, and EDAS-Martime and EGNOS Helpdesk.
EUSPA is committed to protect your personal data and to respect your privacy. All personal data are dealt with in compliance with Regulation (EU) No 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the European institutions, bodies, offices and agencies and on the free movement of such data (Regulation (EU) 2018/1725).
The following data protection information notice outlines the criteria by which the data is collected, managed and used in relation to the EGNOS and EDAS-Maritime User Support Websites, E-GNSS Call Centre, and EDAS-Maritime and EGNOS Helpdesk.
This privacy statement explains the reason for the processing of your personal data. It explains the way we collect, handle and ensure protection of all personal data provided, how that information is used and what rights you have in relation to your personal data. It also specifies the contact details of the responsible Data Controller with whom you may exercise your rights, the Data Protection Officer and the European Data Protection Supervisor.
Identity of the controller:
Controller: Head of EGNOS Exploitation, egnos-service-provision@euspa.europa.eu
European Union Agency for the Space Programme
Janovského 438/2
170 00 Prague 7 – Holesovice
Czech Republic
DPO: European Union Agency for the Space Programme (EUSPA), Data Protection Officer, dpo@euspa.europa.eu.
Identity of the Processor:
ESSP SAS (EUSPA contractor as EGNOS Service Provider - currently under contract GSA/CD/09/19)
3, rue Tarfaya - CS 84432 31405 Toulouse Cedex 4 – France
Delegated processor: Executive Director of EUROPEAN SATELLITE SERVICES PROVIDER SAS;
Purpose of processing:
- EGNOS and EDAS-Maritime User Support website registration
The purpose of the processing is the management and administration of the website, including the following activities:
- To enable access to specific contents and to the subscription to EGNOS related notifications/alerts.
- Dissemination of specific EGNOS User Support website related news and service information (e.g. outages).
- Dissemination of specific consultations and of the annual EGNOS User Satisfaction survey.
- EGNOS Documentation subscription
The purpose of the processing is the management of the EGNOS documentation subscriptions, including the following activities:
- Management of the EGNOS Documentation subscription function.
- Monitoring and reporting on the EGNOS documentation subscriptions use / activity.
- Dissemination of the annual EGNOS User Satisfaction survey.
- EDAS Users registration
The purpose of the processing is the management of the EDAS service, including the following activities:
- To enable access to the EDAS services (EUSPA authorisation required).
- Communications related to EDAS services status (new releases, planned/unplanned outages and interventions).
- Communications related to EDAS services documentation (EDAS Service Definition Document, Service Notices, Service Implementation Roadmaps).
- Monitoring and reporting on the EDAS use and EDAS-based applications implementation status.
- To implement specific consultations related to the EDAS use.
- Dissemination of the annual EGNOS User Satisfaction survey.
- EGNOS and EDAS-Maritime Helpdesk form / e-mail / phone calls (E-GNSS Call Centre)
The purpose of the processing is the management of the EGNOS Helpdesk, including the following activities:
- Management of the EGNOS and EDAS related questions / tickets.
- Monitoring and reporting on the EGNOS and EDAS Helpdesk use / activity.
- Dissemination of specific consultations and of the annual EGNOS User Satisfaction survey.
Data / categories of data concerned:
- EGNOS and EDAS-Maritime User Support website registration
Data necessary for the website related activities, administration and maintenance:
- obligatory data: e-mail address, first & second name, country, user category and service.
- optional data: phone, fax, name of organisation, position in the organisation, market segment and receiver.
- EGNOS Documentation subscription
Data necessary for the management of the EDAS documentation subscription function:
- obligatory data: e-mail address, subscription preferences.
- optional data: none.
- EDAS Users registration
Data necessary for the management of the EDAS services including the verification of the data consistency and EU origin:
- obligatory data: e-mail address, name of organisation, business area of activity, country, phone, IP address (for SL1 & SL2), purpose & description of the project, Internet Service Provider and Connection Point Address.
- optional data: type of organisation, fax and requested service level.
- EGNOS and EDAS Helpdesk form / e-mail / phone calls (E-GNSS Call Centre)
Data required for the EGNOS Helpdesk management:
- obligatory data: name, e-mail address, user category, EGNOS service and EGNOS domain.
- optional data: name of organisation.
When submitting a direct e-mail only the e-mail address is mandatory.
When contacting the EGNOS Helpdesk by phone only the telephone number and the e-mail address are mandatory.
Recipients of the data processed:
- EGNOS and EDAS-Maritime User Support website registration and EGNOS Documentation subscription
Persons which have access to the personal data on the basis of the ‘need to know’ principle:
- a limited number of persons managing the EGNOS website and EGNOS Documentation subscription activities among ESSP and EUSPA staff members and,
- a limited number of external contractors providing support to EUSPA and ESSP activities as regards the website management (e.g. GMV, Amazon) or companies providing IT support or hosting services to ESSP and EUSPA.
These recipients of the personal data concerned are bound by confidentiality clauses regarding the use, disclosure and protection of the personal data.
- EDAS Users Registration
Person which have access to the personal data on the basis of the ‘need to know’ principle:
- a limited number of persons managing the EDAS activities among ESSP and EUSPA staff members and,
- a limited number of external contractors providing support to EUSPA and ESSP activities as regards the EDAS management (e.g. ENAIRE, GMV).
These recipients of the personal data concerned are bound by confidentiality clauses regarding the use, disclosure and protection of the personal data.
- EGNOS and EDAS-Maritime Helpdesk form / e-mail / phone call (E-GNSS Call Centre)
Persons which have access to the personal data on the basis of the ‘need to know’ principle:
- a limited number of persons managing the EGNOS Helpdesk activities among ESSP, EUSPA staff members and,
- a limited number of external contractors providing support to ESSP activities and EUSPA activities as regards the EGNOS Helpdesk management (e.g. GMV, Amazon). These recipients of the personal data concerned are bound by confidentiality clauses regarding the use, disclosure and protection of the personal data.
Lawfulness of processing:
The lawfulness of the processing is based on Article 5(d) of Regulation (EU) No 2018/1725.
Data subjects unambiguously give their consent when submitting (a) the registration form in the case of the EGNOS User Support website and EDAS-Maritime, (b) the EGNOS Documentation Subscription request and / or (c) the request form in the case of the EGNOS Helpdesk.
Information on the retention period of personal data:
Data shall be stored as long as required by Regulation (EU, Euratom) 2018/1046 (Financial Regulation) for audit and discharge purposes: N+5 years from the end of the year of payment of the balance of the contract GSA/CD/09/19 plus an additional 2 years for discharge procedure of EU budget (= N+5+2), unless the users unregisters earlier. In accordance with Article 75, paragraph 3 of the Financial Regulation, personal data contained in supporting documents shall, where possible, be deleted when those data are not necessary for budgetary discharge, control and audit purposes.
Helpdesk users phone calls are recorded and stored for a period of 48 days.
Users can unregister from the EGNOS and EDAS-Maritime databases by sending an email to personaldata.essp@essp-sas.eu. Personal data will be deleted once a user is no longer registered at the EGNOS and EDAS-Maritime databases.
Users can unregister from the EGNOS and EDAS-Maritime User Support websites databases by editing their profiles in the “My Account” section of the website after logging in. Personal data will be deleted once a user is no longer registered in the website.
Users can unregister from the EGNOS Documentation Subscription database in the website by unselecting the required check-boxes from the subscriptions sections in the website and pressing the “unsubscribe” button. Personal data will be deleted once a user is no longer subscribed to any item.
Once the retention period is over, personal data are destroyed.
Information on storage of the personal data and possible transfer of data
Personal data are electronically stored in:
- EGNOS and EDAS-Maritime User Support website registration and EGNOS Documentation subscription request:
- EGNOS User Support website database: hosting services sub-contracted to GMV which uses Amazon Web Services servers located in Europe.
- Specific website activity databases: ESSP servers (Spain and France)
- Servers of EUSPA contractors mentioned above (under the section on “recipients of the data”), which are located in the EU and abiding by the necessary security provisions;
- EDAS Users registration
- EGNOS User Support website database: hosting services sub-contracted to GMV which uses Amazon servers located in Europe.
- EGNOS Helpdesk mailbox (helpdesk@egnos.gsc-europa.eu): ESSP servers (France)
- Specific EDAS registered uses database ESSP servers (Spain and France) - EUSPA EDAS mailbox (EDAS@euspa.europa.eu): EUSPA servers
- Servers of EUSPA contractors mentioned above (under the section on “recipients of the data”), which are located in the EU and abiding by the necessary security provisions;
- EGNOS and EDAS-Maritime Helpdesk form / e-mail / phone call (E-GNSS Call Centre)
- EGNOS User Support website database: hosting services sub-contracted to GMV which uses Amazon servers located in Europe.
- EGNOS Helpdesk mailbox (helpdesk@egnos.gsc-europa.eu): hosting services sub-contracted to Novenci which uses local servers located in Europe.
- Specific EGNOS Helpdesk database: ESSP servers (Spain and France) - EUSPA EDAS mailbox (EDAS@euspa.europa.eu): EUSPA servers
- Personal data may be stored on the servers of EUSPA contractors mentioned above (under the section on “recipients of the data”), which are located in the EU and abiding by the necessary security provisions.
It is underlined that Amazon Web Services (AWS) are provided by Amazon.com Inc, a US incorporated/based company. According to AWS, a small number of AWS services might involve the transfer of data to the US, for example, to develop and improve those services or because transfer is an essential part of the service (such as a content delivery service). In order to allow you to make an informed decision, please note that personal data that may be transferred to the United States of America may be subject to (a) disclosure to governmental authorities and/or (b) further transfer to other economic operators established in third countries; the EUSPA has no visibility on such processing operations.
Such transfer can occur on the basis of your consent to the proposed transfer (Art. 50(1)(a) of Regulation (EU) 2018/1725).
Automated decision-making
Your data will not be used for an automated decision-making, including profiling.
The data subject’s rights:
You have specific rights as a “data subject” under Chapter III (Articles 14-25) of Regulation (EU) 2018/1725, in particular the right:
- To obtain confirmation as to whether or not your personal data are being processed;
- To access your personal data and obtain detailed information on the processing;
- Of rectification of inaccurate personal data;
- Of erasure of personal data if the statutory provisions are met;
- Of restriction of processing if the statutory provisions are met;
- To data portability, where applicable;
- To withdraw the consent, without affecting the lawfulness of the processing carried out before you have withdrawn the consent.
Any request for the exercise of any of the abovementioned rights shall be addressed to egnos-service-provision@euspa.europa.eu or in case of conflict the Data Protection Officer at dpo@euspa.europa.eu. Data subjects are kindly requested to describe their requests explicitly.
You also have the right to lodge a complaint to the European Data Protection Supervisor at EDPS@edps.europa.eu should they consider that the processing operations do not comply with Regulation (EU) No 2018/1725.
Contact information:
- Regarding the processing of your personal data: egnos-service-provision@euspa.europa.eu;
- Regarding the interpretation, application or breach of Regulation (EU) 2018/1725, please contact the EUSPA Data Protection Officer (DPO) at dpo@euspa.europa.eu.