1. Privacy and Data Protection
Data protection is a matter of confidence and your trust is important to us. We respect Swiss data protection legislation when we collect or use any data relating to your personal information, as detailed below. Your personal details are treated confidentially, only shared with third parties where necessary, and never sold or exchanged.
“Personal Data” means any information relating to an identified or identifiable natural or legal person, according to the Swiss Federal Act on Data Protection (“FADP”).
Please read the following carefully to understand our views and practices regarding your Personal Data and how we will process it.
2. Responsibility for Your Personal Data
Data Protection Officer
Ecole Polytechnique Fédérale de Lausanne,
BS 248 / Station 4
Alternatively, the Data Protection Officer may be contacted by e-mail at email@example.com.
3. Collection of Personal Data
3.1 When You Visit Our Sites
When you visit our Sites, we may automatically collect the following Personal Data:
- information regarding the use of our Sites, including but not limited to the duration, language, date and time stamp of your visit, the browser used, the volume of data transmitted, and the URLs web pages on our Sites that were presented to you;
- technical information, including the IP (Internet Protocol) address used to connect your computer to the Internet, the type of device you use, and unique device identifier of that device;
- any information you may share with us, for example through the contact forms on our Sites;
- login information, where applicable.
This Personal Data is collected through cookies and similar technologies as described in art. 5.
3.2 When You Contact Us
When you contact us by mail, e-mail, phone, in person or through social networks, we may process Personal Data you share with us in order to answer your questions, provide you feedback and/or better understand your needs.
3.3 When You Use Social Media
When you allow a third-party social media platform (like Facebook or Twitter) to share your Personal Data with us, we are entitled to receive any Personal Data that is provided by that service (which may include your name, e-mail address, gender, profile picture, friend list or contact list, preferences, and other data collected by that third-party service).
We will also receive Personal Data related to your profile when you use functionalities of social media that are integrated into the Sites or when you interact with us through social media.
3.4 Opt-in Communications
When you sign up to any of our newsletters or opt-in to other communications, you need to provide Personal Data to us. We may ask you for your e-mail address, your first name, your family name and other additional information. We process this Personal Data in order to be able to keep you informed in a relevant and personalized way, with information that is tailored to your interests. This Personal Data is treated as confidential, subject to legal obligations, and may be shared with third parties who provide newsletter mailing and marketing services on our behalf. By submitting your data to us, you specifically authorize its use for marketing, communication, research and analytical purposes. You may unsubscribe from our newsletters or opt-out of receiving communications from us at any time.
When you opt to receive communications from us, you authorize us to process the above-mentioned Personal Data in order to send you relevant messages.
We may process this Personal Data in order to:
- Communicate information to you in connection with the Services;
- Provide feedback and support to you;
- Contact you by e-mail, mail, or phone about our products and services, conduct surveys and research studies, inform you of special events and/or to provide you with other information that we think may be of interest to you;
- Customize the content we provide through the Services;
- Help us better understand your interests and needs;
- Engage in analysis, research, and reports regarding use and improvement of the Services;
- Maintain the security and stability of the Services;
- Comply with any applicable procedures, laws, and regulations, where necessary for our legitimate interests or the legitimate interests of others;
- Establish, exercise, or defend our legal rights, where necessary for our legitimate interests or the legitimate interests of others.
4. Sharing Your Personal Data
4.1 With Data Processors
We may share your Personal Data with those who provide us with services as data processors, in particular:
- Amazon AWS: S3 asset hosting and Cloudfront content delivery - https://aws.amazon.com
- Campaign Monitor: newsletters and marketing – https://campaignmonitor.com
- Google: Tag Manager for marketing - https://marketingplatform.google.com/about/tag-manager
- Heroku: hosting provider - https://www.heroku.com
- New Relic: performance analytics - https://newrelic.com
- Papertrail: log management - https://www.papertrail.com
- Redis To Go: database hosting - http://redistogo.com
- Rollbar: error tracking - https://rollbar.com
- Zoho: marketing and transactional e-mails - https://www.zoho.com
Our data processors are bound by an obligation of confidentiality and are entitled to use your Personal Data only in accordance with our instructions and this Policy.
4.2 With Third Parties
We may share your Personal Data with third parties when allowed or required by law, when it is necessary to defend our interests, or with your consent, for example at the request of judicial authorities or to assert our rights in court.
5.1 Types of Cookies
Three kinds of cookies are used on the Sites:
Essential Cookies These are necessary for the operation of the Sites.
Functional Cookies These are used to remember you when you come to the Sites, and allow our Sites to remember choices you have made (such as your username and language).
Analytical cookies These allow us to understand use of the Sites by our visitors and users on an aggregate basis, including when and how people come to the Sites and how they move around and interact within it.
You can opt out of accepting functional and analytical cookies through your browser’s settings.
5.2 Third-party Cookies
Our Sites may include applications from third parties which allow you to share our Sites’ content with other people and let them know that you have engaged with or have an opinion about content on our Sites.
These cookies use is subject to third parties’ privacy policies over which we have no control. Please refer to their respective privacy policies in order to learn more about the way they use their cookies.
6. Transfer of Personal Data Outside of Switzerland
Your Personal Data may be processed in Switzerland and in other countries that ensure an adequate level of protection. If the relevant country provides a lower level of protection than Switzerland, standard contractual clauses, which may be obtained from our Data Protection Officer, shall be signed.
EPFL uses standard technology and security precautions, and organizational procedures to protect your Personal Data from unauthorized access, improper use, disclosure, loss or destruction.
8. Your Rights
You have the right to receive a copy of your Personal Data and you may request the correction of any Personal Data which is inaccurate or incomplete. You also have the right to object to the processing of your Personal Data for legitimate reasons as well as a right to object to the use of those data for prospecting in accordance with applicable laws. When the processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. The EPFL reserves the right to refuse any abusive request or one which is contrary to applicable laws. Finally, you have the right to lodge a complaint with the relevant supervisory authority.
9. Changes to This Policy