Document type: Internal act – Data Protection Policy

Project: Humans as Intelligent Shield against Cyber Threats (IQ Defence)

Grant Agreement No.: 101249724

Programme: Digital Europe Programme (DIGITAL)

Version: 1.0

Date: May 2026

Prepared by: Algebra Bernays University

1. Purpose and Scope of This Document

This Internal Privacy Policy is a binding internal act adopted by Algebra Bernays University (hereinafter: the University) in connection with the implementation of the IQ Defence project. It sets out the framework for the lawful, fair, and transparent processing of personal data within the project, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation – GDPR) and applicable national data protection legislation of the Republic of Croatia.

The purpose of this document is to:

  • Identify the University as the primary data controller for the IQ Defence project and specify its contact details;
  • Define the highest level of organisational responsibility for the protection of personal data and the rights of data subjects;
  • Define all relevant roles in the field of personal data protection within the project;
  • Provide a detailed description of each processing activity, including its name and purpose, legal basis, categories of data subjects, categories of personal data processed, and the applicable retention period;
  • Inform data subjects about their rights under the GDPR and the manner in which those rights may be exercised;
  • Provide data subjects with the contact details of the competent national supervisory authority.

This Policy applies to all personal data processing activities carried out in connection with the IQ Defence project by the University as controller, as well as to activities carried out jointly with the project partner Millenium Promocija d.o.o. where a joint controller relationship exists. Each project partner retains separate controllership over personal data processed exclusively within its own institutional operations (e.g. employment and contractual relationships with its own staff and collaborators).

This document is mandatory for all University employees, associates, contractors, and other persons involved in the implementation of the IQ Defence project who come into contact with personal data in the course of their duties.

2. Data Controller Identity and Contact Details

The primary data controller for personal data processed within the IQ Defence project is:

Algebra Bernays University, Gradišćanska 24, 10000 Zagreb, Republic of Croatia

For all matters relating to personal data protection within the IQ Defence project, data subjects may direct their enquiries and requests to the University’s Data Protection Officer:

Data Protection Officer – Algebra Bernays University

E-mail: dpo.algebra@algebra.hr

For certain processing activities carried out in connection with the organisation of project events (conferences, workshops, seminars), Algebra Bernays University and Millenium Promocija d.o.o. (hereinafter: Millenium Promocija) act as joint controllers. The contact details of Millenium Promocija as joint controller for event-related processing are:

Millenium Promocija d.o.o., Ulica grada Vukovara 23, 10000 Zagreb, Republic of Croatia

E-mail: privacy@mpr.hr

3. Highest Level of Organisational Responsibility

The highest level of organisational responsibility for the protection of personal data and the rights of data subjects within the University rests with the Rector of Algebra Bernays University. The Rector, in the exercise of general institutional governance, is responsible for ensuring that the University, as a data controller, maintains and implements policies, procedures, and technical and organisational measures adequate to fulfil its obligations under the GDPR and applicable national legislation.

At the level of the IQ Defence project, the Rector has delegated operational responsibility for data governance and GDPR compliance within the project to the Head of the University Department of Cybersecurity Security, who acts as the responsible person at senior management level for overseeing the implementation of this Policy in the context of the project.

The Data Protection Officer of Algebra Bernays University supports the Rector and the project management in the performance of their data protection obligations, provides guidance, monitors compliance, and serves as the primary point of contact for data subjects and for the national supervisory authority (AZOP).

4. Roles and Responsibilities in Personal Data Protection

The following roles are defined for the purpose of implementing data protection obligations within the IQ Defence project:

Data Controller

Algebra Bernays University acts as the primary data controller for personal data processing activities carried out within the project’s central infrastructure, including the Moodle-based e-learning platform, and for all project activities where the University determines the purposes and means of processing. As controller, the University is responsible for ensuring lawful processing, maintaining records of processing activities (RoPA), ensuring transparency toward data subjects, implementing technical and organisational security measures, and responding to requests for the exercise of data subject rights.

Joint Controllers

For personal data processing related to the organisation of project events (conferences, workshops, seminars), Algebra Bernays University and Millenium Promocija act as joint controllers pursuant to Article 26 GDPR. The University is responsible for defining the purposes and objectives of events and for ensuring that the joint controller arrangement is documented. Millenium Promocija is responsible for the operational management of event registration, participant communication, and event logistics. A joint controller agreement documents the allocation of responsibilities between the two partners.

Data Protection Officer (DPO)

The Data Protection Officer of Algebra Bernays University is the designated expert responsible for:

  • Informing and advising the University and its staff of their obligations under the GDPR;
  • Monitoring compliance with this Policy and with applicable data protection legislation;
  • Providing guidance on Data Protection Impact Assessments where required;
  • Acting as the point of contact for data subjects exercising their rights;
  • Cooperating with and acting as the contact point for the national supervisory authority (AZOP).

The DPO acts independently in the performance of these tasks and reports directly to the Rector.

Project Manager / Project Coordinator

The project management team of Algebra Bernays University is responsible for:

  • Ensuring that this Policy is implemented in all project activities;
  • Ensuring that staff and collaborators involved in the project are informed of their data protection obligations;
  • Ensuring that personal data are collected only to the extent necessary for project purposes;
  • Coordinating with the DPO on any new processing activities or changes to existing ones;
  • Ensuring that third-party suppliers and event organisers engaged in the project have appropriate data processing agreements in place where required.

Platform Administrator

The Moodle platform administrator, operating within the University’s IT infrastructure, is responsible for:

  • Managing user accounts and access rights on the Moodle e-learning platform in accordance with the role-based access model;
  • Ensuring system security, applying updates, and maintaining logs;
  • Implementing technical security measures (encryption, backup, access control, MFA);
  • Reporting potential security incidents to the DPO without undue delay.

Instructors, Trainers, and Course Managers

Project staff in instructional roles are responsible for:

  • Accessing only the personal data necessary for the delivery and evaluation of their assigned training activities;
  • Treating participant data with confidentiality;
  • Not sharing personal data of participants with unauthorised persons;
  • Notifying the platform administrator or DPO of any suspected data protection incidents.

Marketing and Communication Staff

Staff responsible for dissemination, communication, and event activities are responsible for:

  • Ensuring that dissemination materials published publicly do not contain personal data without appropriate legal basis;
  • Obtaining valid consent where required (e.g. for newsletter subscriptions, PDF download registration, close-up photographs used in promotional materials);
  • Maintaining records of consent and enabling easy withdrawal of consent (e.g. unsubscribe links in all newsletter communications);
  • Applying data minimisation principles when collecting contact details through website forms.

All Staff and Collaborators

Every person involved in the implementation of the IQ Defence project who processes or has access to personal data is obliged to:

  • Process personal data only for the purposes and in the manner described in this Policy;
  • Maintain the confidentiality of personal data accessed in the course of their duties;
  • Immediately notify the DPO of any actual or suspected personal data breach;
  • Comply with all applicable data protection requirements and institutional policies.

5. Processing Activities

The following sections describe in detail each personal data processing activity carried out in connection with the IQ Defence project. For each activity, the applicable legal basis under Article 6 GDPR is stated together with an explanation of its nature, the categories of data subjects, the specific personal data processed, and the applicable retention period.

Employees and External Collaborators

Management of employment and contractual relationships with employees and external collaborators (lecturers, experts, consultants, and other service providers) engaged for the purposes of the IQ Defence project. This includes entering into contracts, processing payments, maintaining statutory records, managing project roles and responsibilities, and fulfilling legal obligations as an employer.

This processing is a standard HR and contractual necessity. The University, as employer or contracting party, is legally required to process certain personal data of its employees and collaborators. There is no alternative basis that could substitute for the contractual and legal obligation grounds applicable here.

Controller model: Each project partner acts as a separate and independent data controller with respect to its own employees and collaborators. Algebra Bernays University processes personal data of its own staff; Millenium Promocija processes personal data of its own staff. No joint controller arrangement applies.

Categories of data subjects:

  • University employees assigned to the IQ Defence project;
  • External collaborators engaged under service contracts, author’s contracts, or similar contractual arrangements.

Categories of personal data:

  • Identity data: first name, surname, date of birth, personal identification number (OIB);
  • Contact data: residential or official address, e-mail address, phone number;
  • Contractual and professional data: role and responsibilities within the project, qualifications and professional background, contractual terms;
  • Financial data: bank account number, tax status, remuneration details;
  • Administrative data: copies of identification documents where required, nominations to project bodies, records of tasks performed.

Personal data are retained for the duration of the contractual relationship and, thereafter, for the period required by applicable statutory obligations (accounting records: 11 years; employment records: in accordance with Croatian Labour Act and pension insurance regulations). For EU-funded project purposes, documentation supporting proof of project activities must be retained for the period specified in the Grant Agreement (minimum 5 years from the final payment or, where applicable, the period required under audit provisions).

Advisory Board Members

Collection and management of personal data of members of the IQ Defence Advisory Board for the purposes of project governance, coordination of advisory activities, scheduling of meetings, and communication with Advisory Board members in connection with their advisory function.

The Advisory Board was established as part of the project governance structure. Processing of members’ contact and professional data is a necessary and proportionate measure for carrying out advisory coordination activities. Data subjects are professionals who voluntarily accept nomination to the Board and can reasonably anticipate such use of their professional contact information.

Categories of data subjects:

  • Members of the IQ Defence Advisory Board.

Categories of personal data:

  • Identity data: first name, surname, academic or professional title;
  • Contact data: professional e-mail address, institutional affiliation;
  • Professional data: area of expertise, professional biography provided for publication.

Personal data of Advisory Board members are retained for the duration of the project and for a limited period thereafter as required for project reporting and documentation purposes (aligned with EU Grant Agreement retention requirements, minimum 5 years from final payment).

Training Participants and E-Learning

Collection of registration data and management of participant accounts on the Moodle-based e-learning platform hosted by Algebra Bernays University, for the purpose of enabling access to online training courses, monitoring course progress and engagement, evaluating training effectiveness, and fulfilling project reporting obligations regarding training participation.

The training programme is a central project deliverable. The processing of participant registration and progress data is strictly necessary to fulfil contractual obligations toward the EU funding authority and to deliver the training service to participants. Participants register voluntarily; however, once registered, a service relationship is established that constitutes the contractual basis for processing.

Controller model: Algebra Bernays University acts as the sole data controller for this processing activity. Millenium Promocija does not have access to individual participant data from the Moodle platform. Reporting to the EU funding authority is made using aggregated and anonymised data.

Categories of data subjects:

  • Individuals registered as participants in IQ Defence online training courses.

Categories of personal data:

  • Identity data: first name, surname;
  • Contact data: e-mail address;
  • Institutional data: institutional affiliation or organisation, country of residence;
  • Platform account data: username, password (hashed), account creation date;
  • Learning data: course enrolment information, course progress and completion status, assessment results and scores, login records and session data;
  • Communication data: messages exchanged within the platform in connection with the training.

Participant account data and learning records are retained for the duration of the training activities and for the period required to fulfil reporting obligations under the Grant Agreement. Following the end of the retention period, user accounts are deactivated and identifiable personal data are deleted or anonymised. Aggregated and anonymised statistical data may be retained for long-term evaluation purposes.

Testing and Certification

Administration of competency assessments and issuance of certificates to participants who successfully complete IQ Defence training programmes. Processing includes recording assessment results and maintaining certification records.

The certification process is an integral part of the training service. Participants register for training with the understanding that successful completion leads to a certificate. Processing of assessment data to issue and maintain certification records is therefore directly linked to the contractual relationship with the participant and the project’s grant obligations.

Controller model: Algebra Bernays University acts as the sole data controller. Individual assessment results are not shared with Millenium Promocija.

Categories of data subjects:

  • Training participants who undertake competency assessments.

Categories of personal data:

  • Identity data: first name, surname;
  • Contact data: e-mail address;
  • Assessment data: test results, scores, pass or fail status;
  • Certification data: certificate identifier, issue date, validity period, completion status.

Certification records are retained for the duration of the project and for the period required by the Grant Agreement for audit and reporting purposes (minimum 5 years from final payment). Assessment results in individualised form are retained for the same period and subsequently anonymised or deleted.

Event Organisation and Participants

Organisation and management of project events, including conferences, workshops, seminars, and online events. Processing includes collection of participant registration data, management of attendance, communication with participants before and after events, and collection of event feedback for evaluation purposes. Results are used to demonstrate project activities in EU reporting.

Participants register voluntarily for project events. The registration process constitutes the formation of a service relationship that justifies processing of the personal data provided. The obligation to document event participation and report on it to the EU funding authority further supports this basis.

Controller model: Algebra Bernays University and Millenium Promocija act as joint controllers for event organisation and participant management. Millenium Promocija leads the operational organisation; Algebra Bernays University defines event objectives and content and participates in fulfilment of reporting obligations. The responsibilities of the joint controllers are documented in a joint controller agreement pursuant to Article 26 GDPR.

Categories of data subjects:

  • Participants in project events (conferences, workshops, seminars, online events);
  • External speakers and invited experts.

Categories of personal data:

  • Identity data: first name, surname, academic or professional title;
  • Contact data: e-mail address, phone number (where provided);
  • Institutional data: institutional affiliation or organisation, country;
  • Participation data: event registration records, attendance records, session participation data;
  • Feedback data: responses to voluntary post-event evaluation questionnaires.

Event registration and attendance records are retained for the duration of the project and for the period required by the Grant Agreement for reporting and audit purposes. Feedback questionnaire responses are retained in identifiable form only for as long as necessary for evaluation purposes, after which they are anonymised or deleted. Aggregated participation statistics may be retained for long-term reporting.

Photography and Video Recording at Events

Capture of photographs and video recordings at project events for the purpose of documenting project activities and for use in project communication and dissemination materials, including the project website, social media channels, and reports.

For general event documentation (wide-angle shots, audience photographs not featuring identifiable individuals in a prominent or targeted manner): Article 6(1)(f) GDPR – legitimate interest of the University and the consortium in documenting project activities and fulfilling EU-funded project communication obligations. The legitimate interest is balanced against the reasonable expectations of participants who attend a publicly announced project event and who are informed of photography in advance.

For close-up photographs and video recordings in which specific individuals are clearly identifiable and which are intended for prominent promotional use (e.g. feature images, speaker portraits used on the project website or in campaign materials): Article 6(1)(a) GDPR – consent of the data subject.

For professional speakers and presenters engaged under contract: processing of image and video data may be based on Article 6(1)(b) GDPR as part of the contractual engagement, where image rights are addressed in the relevant agreement.

Participants attending project events are informed in advance (via registration confirmation and visible notices at the event venue) that photography and video recording will take place. Consent is obtained separately for targeted promotional use.

Controller model: Joint controllers – Algebra Bernays University and Millenium Promocija, consistent with the joint controller arrangement for events.

Categories of data subjects:

  • Event participants, speakers, trainers, and other individuals present at project events.

Categories of personal data:

  • Photographic images and video recordings in which individuals are identifiable;
  • Name and image (for speaker profiles and promotional content, where separate consent is obtained).

General event photographs and videos are retained for the duration of the project and for a limited post-project period consistent with communication and reporting obligations. Promotional materials using individual images are retained only for as long as the promotional use continues or until withdrawal of consent. Upon withdrawal of consent, identifiable images are removed from public channels without undue delay.

Newsletter and Communication Subscriptions

Management of a subscription list for a project newsletter and other regular project communications, for the purpose of informing subscribers about project activities, outcomes, events, and cybersecurity awareness content.

Because the newsletter subscription goes beyond the immediate transaction or project participation relationship, and because subscribers include persons who have not otherwise entered into a direct contractual relationship with the University in connection with the project, consent is the appropriate and only lawful basis. Consent must be actively given.

Controller model: Each project partner manages its own subscriber lists as a separate and independent data controller. Where a joint newsletter is issued, the party that administers the technical sending infrastructure acts as the primary controller, with the other partner acting as joint controller. The applicable arrangement is documented accordingly.

Categories of data subjects:

  • Individuals who have voluntarily subscribed to the IQ Defence project newsletter or other project communication channels.

Categories of personal data:

  • Identity data: first name, surname (where provided);
  • Contact data: e-mail address;
  • Subscription management data: date and record of consent, unsubscribe requests and their date.

Personal data of newsletter subscribers are retained for as long as the subscription remains active (i.e. until the data subject unsubscribes or withdraws consent). Upon unsubscription, the e-mail address is removed from the active mailing list without undue delay. Consent records may be retained for a limited additional period for the purpose of demonstrating compliance.

Website Contact Forms and Document Downloads

Collection of personal data through the project website when users complete a form to download project publications or documents (e.g. guidelines, reports, awareness materials) or to register interest in the project. The data are used to provide the requested content and to send future notifications about project activities, new publications, and events.

At the point of submitting the website form, data subjects are informed that their e-mail address will be used to send the requested document and to keep them informed of future project activities. A clear and active opt-in mechanism is used. The form includes an unambiguous statement of purpose and a reference to the right to withdraw consent and to unsubscribe from future communications at any time via the unsubscribe link included in every communication.

Controller model: Algebra Bernays University acts as the primary data controller for the project website. Where Millenium Promocija participates in website management or dissemination activities connected to the website, the applicable controller arrangement is agreed and documented between the partners.

Categories of data subjects:

  • Website visitors who complete a contact or document download registration form.

Categories of personal data:

  • Identity data: first name, surname (where provided);
  • Contact data: e-mail address;
  • Subscription and consent data: date and record of consent, topic of interest, document downloaded.

Personal data collected through website forms are retained for as long as the data subject remains subscribed to project communications. Upon unsubscription or withdrawal of consent, personal data are deleted or anonymised without undue delay. Consent records may be retained for a limited additional period for compliance purposes.

Attendance Signature Lists

Collection of signed attendance lists at project training sessions and events for the purpose of documenting participant attendance, providing proof of participation to individual participants, and demonstrating project activity to the EU funding authority in the context of grant reporting obligations.

Signature lists serve a dual function: they document the individual’s participation and they serve as mandatory evidence of project activities required by the EU funding body. Both the contractual and legal obligation bases apply.

Categories of data subjects:

  • Participants in project training sessions and events who sign the attendance list.

Categories of personal data:

  • Identity data: first name, surname;
  • Participation data: name of event or training session, date and location, handwritten or electronic signature, organisation or affiliation.

Attendance signature lists are retained for the duration of the project and for the period required by the Grant Agreement for audit and verification purposes (minimum 5 years from final payment to the project). After the retention period, lists are securely destroyed or anonymised.

Working Groups, Interviews, and Focus Groups

Organisation of working group meetings, individual interviews, and focus group sessions with cybersecurity professionals, practitioners, and subject matter experts for the purpose of developing cybersecurity occupational standards and qualification frameworks as part of the IQ Defence project’s work packages.

Participants in working groups, interviews, and focus groups are professionals who voluntarily engage with the project in an expert capacity. Processing is necessary for the performance of the engagement or participation agreement with the working group member or interview/focus group participant, which constitutes the basis for their involvement in the standards development process. Legitimate interest of the University in conducting expert consultations necessary for the development of publicly available cybersecurity occupational standards and qualification frameworks, which directly serve the project’s European public interest objectives. The legitimate interest is proportionate to the public benefit of developing EU-aligned cybersecurity standards.

Controller model: Algebra Bernays University acts as data controller. Where Millenium Promocija is operationally involved in organising specific sessions, the applicable controller arrangement is agreed between the partners.

Categories of data subjects:

  • Members of working groups established within the IQ Defence project;
  • Participants in expert interviews and focus group sessions.

Categories of personal data:

  • Identity data: first name, surname, academic or professional title;
  • Contact data: professional e-mail address, phone number (where provided);
  • Professional data: institutional affiliation, area of expertise, professional background;
  • Contribution data: responses, opinions, and statements provided during interviews or focus group sessions (in notes, transcripts, or recordings where applicable); working group participation records.

Personal data of working group members and interview/focus group participants are retained for the duration of the project and for the period required by the Grant Agreement. Detailed interview or focus group records are retained in identifiable form only for as long as needed for analysis and documentation of outcomes, after which they are anonymised. Published outputs (occupational standards documents) do not contain identifiable personal data of individual contributors unless explicit consent has been obtained.

EU Project Reporting and Project Administration

Preparation and submission of periodic and final reports to the European Commission / EU executive agency (ECCC) in fulfilment of Grant Agreement obligations, including documentation of project activities, outputs, and outcomes. Also includes internal project administration and coordination documentation.

The submission of reports to the EU funding authority is a mandatory contractual and regulatory obligation. The University has no discretion to avoid processing personal data where such data form part of mandatory project documentation (e.g. names of key personnel, signatures on deliverables, lists of project activities). Individual participant data included in reports are, wherever possible, aggregated and anonymised.

Categories of data subjects:

  • Key project personnel named in project reports and deliverables;
  • Participants whose aggregated data are referenced in project reporting.

Categories of personal data:

  • Identity data of project personnel: first name, surname, institutional affiliation, role in the project;
  • Aggregated and anonymised participation statistics (not personal data in identifiable form, where properly anonymised).

Project reports and associated documentation are retained for the period required by the Grant Agreement and applicable EU financial regulation (minimum 5 years from final payment or as otherwise specified in the Grant Agreement).

6. Rights of Data Subjects and How to Exercise Them

All data subjects whose personal data are processed by Algebra Bernays University in connection with the IQ Defence project are entitled to exercise the following rights under the GDPR. Data subjects may exercise these rights at any time by submitting a written request to the Data Protection Officer of Algebra Bernays University. Requests will be responded to without undue delay and in any event within one month of receipt, which period may be extended by a further two months where necessary given the complexity or number of requests (in which case the data subject will be informed of the extension within one month of receipt of the request).

Right to be Informed (Article 13 and 14 GDPR)

Data subjects have the right to receive clear, transparent, and accessible information about the processing of their personal data at the time their data are collected (or, where data are not collected directly from the data subject, within a reasonable period). This information is provided through this Policy, the privacy notice on the project website, registration forms, event documentation, and platform user information notices.

Right of Access (Article 15 GDPR)

Data subjects have the right to obtain confirmation as to whether or not their personal data are being processed, and, where that is the case, to receive a copy of the personal data and supplementary information about the processing (purpose, categories of data, recipients, retention period, etc.).

Right to Rectification (Article 16 GDPR)

Data subjects have the right to obtain without undue delay the rectification of inaccurate personal data concerning them, and to have incomplete personal data completed.

Right to Erasure / Right to be Forgotten (Article 17 GDPR)

Data subjects have the right to obtain the erasure of their personal data without undue delay where one of the following grounds applies: the data are no longer necessary for the purposes for which they were collected; the data subject withdraws consent and there is no other legal basis for processing; the data subject objects to processing and there are no overriding legitimate grounds; the data have been unlawfully processed; erasure is required to comply with a legal obligation.

This right does not apply where processing is necessary for compliance with a legal obligation (e.g. mandatory retention under the Grant Agreement or applicable statutory law) or for the exercise or defence of legal claims.

Right to Restriction of Processing (Article 18 GDPR)

Data subjects have the right to obtain restriction of processing in certain circumstances: where the accuracy of the data is contested by the data subject (for the period necessary to verify accuracy); where the processing is unlawful and the data subject opposes erasure; where the controller no longer needs the data but the data subject requires them for legal claims; or where the data subject has objected to processing pending verification of grounds.

Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or on contract performance and is carried out by automated means, data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format, and to have those data transmitted to another controller where technically feasible.

Right to Object (Article 21 GDPR)

Data subjects have the right to object at any time to processing of their personal data that is based on the legitimate interests of the controller (Article 6(1)(f) GDPR). Upon receipt of an objection, the controller will no longer process the personal data unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defence of legal claims.

Data subjects also have the right to object at any time to processing of their personal data for direct marketing purposes, in which case the processing shall cease immediately.

Right to Withdraw Consent (Article 7(3) GDPR)

Where processing is based on the data subject’s consent, the data subject has the right to withdraw consent at any time without detriment. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

Right to Lodge a Complaint with the Supervisory Authority (Article 77 GDPR)

Without prejudice to any other administrative or judicial remedy, data subjects have the right to lodge a complaint with the competent national supervisory authority if they consider that the processing of their personal data infringes the GDPR. The University encourages data subjects to contact the DPO first in order to resolve any concerns quickly and informally; however, exercising this right does not require prior contact with the University.

The contact details of the competent supervisory authority are provided in the following section.

7. Contact Details of the National Supervisory Authority (AZOP)

The competent national supervisory authority responsible for monitoring compliance with data protection legislation in the Republic of Croatia is:

  • Agencija za zaštitu osobnih podataka (AZOP)
  • (Croatian Personal Data Protection Agency)
  • Postal address: Ulica Metela Ožegovića 16, 10000 Zagreb, Republic of Croatia
  • Telephone: +385 (0)1 4609-000
  • Fax: +385 (0)1 4609-099
  • E-mail: azop@azop.hr
  • Website: www.azop.hr

8. Final Provisions

This Internal Privacy Policy enters into force on the date of its adoption by the authorised representative of Algebra Bernays University and applies for the entire duration of the IQ Defence project and for the post-project retention period applicable to each category of personal data as described herein.

This Policy shall be reviewed and updated whenever significant changes occur in the processing activities of the project, in the applicable legal framework, or following any data protection incident that reveals a need for revision. Minor updates and corrections that do not materially affect the rights of data subjects may be made administratively; material updates are subject to re-adoption by the authorised representative.

All persons involved in the implementation of the IQ Defence project are required to familiarise themselves with this Policy and to comply with its provisions. Compliance with this Policy is monitored by the Data Protection Officer of Algebra Bernays University.

This Policy is made available to all project staff and collaborators through internal project channels and, in summary form, to data subjects through the project website and event documentation.

For any questions regarding the interpretation or application of this Policy, please contact:

  • Data Protection Officer – Algebra Bernays University
  • E-mail: dpo.algebra@algebra.hr
  • Postal address: Gradišćanska 24, 10000 Zagreb, Republic of Croatia

ALGEBRA BERNAYS UNIVERSITY

  • Name: Mislav Balković, PhD, Associate Professor
  • Title: Rector
  • Date: 1 January 2026

MILLENIUM PROMOCIJA D.O.O.

  • (as co-controller for joint processing activities only)
  • Name: Vladimir Preselj
  • Title: Director
  • Date: 1 January 2026

Privacy Policy