Oulu ICT Study Paths Logo
Oulu ICT Study PathsITEE Faculty
Sign Up
GDPR Compliant Notice
Privacy & Data Protection

Privacy Policy

Learn how Oulu ICT Study Paths protects your privacy, manages internal authentication, and upholds European GDPR standards.

Internal System Notice:This portal is strictly designed for internal collaboration. General users and attendees are not recommended to log in. Event browsing is open to everyone without an account.

1. Internal Use Advisory

The Oulu ICT Study Paths portal is engineered primarily for internal administrative, research partnership, and organizational coordination between the Faculty of ITEE at the University of Oulu and academic institutions in Vietnam.

Recommendation on Account Creation:

External visitors, students, and event attendees are not recommended to log in. You do not need to register or provide personal credentials to view event schedules, access venue details, or browse official merchandise.

2. Information We Collect Upon Authentication

If an authorized internal user chooses to create an account or sign in (via direct email/password or Google / GitHub OAuth), the platform collects and processes the following categories of data:

Email Address

Captured from user input or your OAuth provider to uniquely identify your administrative account, deliver verification tokens, and dispatch security notices.

Full Name

Used to attribute event creation records, update logs, and display administrative authorship across the collaborative management portal.

IP Address (Internet Protocol)

Logged during active sessions to detect anomalous access patterns, enforce geographic and network rate-limits, and mitigate automated attacks.

Access Logs & Telemetry

Timestamps of authentication attempts, browser user-agent headers, and mutation audit logs recorded by Supabase and Next.js middleware for system accountability.

Strict Data Minimization: We do NOT collect credit card numbers, payment accounts, tracking cookies for marketing, or sensitive personal data.

3. Supabase Cloud Hosting & Technical Safeguards

All account profiles and event metadata are securely hosted on Supabase Cloud, which operates on enterprise-grade cloud facilities located within European Union compliance parameters.

  • GDPR Compliance: Supabase maintains ISO/IEC 27001 certifications, SOC 2 Type II audits, and comprehensive Data Processing Agreements (DPA) adhering strictly to GDPR.
  • Transport Security: All client-server traffic is forced over HTTPS using modern TLS 1.3 cryptographic suites.
  • Storage Encryption: Database tables, backups, and user avatars in Supabase Storage are encrypted at rest with AES-256.
  • Row Level Security: PostgreSQL Row Level Security (RLS) is applied across every table to guarantee that only authenticated administrators with verified roles can alter content.

4. Your Rights Under the GDPR

Under Regulation (EU) 2016/679 (GDPR), every individual whose personal data is processed by the platform is entitled to exercise the following statutory rights:

Right of AccessArt. 15 GDPR

You have the right to request confirmation of whether your personal data is being processed and receive a full copy of your data records.

Right to RectificationArt. 16 GDPR

You can request the immediate correction or completion of inaccurate or outdated personal details stored in your profile.

Right to Erasure ("To Be Forgotten")Art. 17 GDPR

You have the right to demand the permanent deletion of your account credentials, profile, and associated personal records from our databases.

Right to Restriction of ProcessingArt. 18 GDPR

Under specific legal criteria, you may request that we temporarily freeze or restrict the active processing of your personal information.

Right to Data PortabilityArt. 20 GDPR

You are entitled to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV export).

Right to ObjectArt. 21 GDPR

You retain the continuous right to object to any automated processing of your information on grounds relating to your particular circumstances.

To exercise any of these rights, contact our Data Protection Liaison at the email provided below. Requests are evaluated and addressed within thirty (30) days without undue delay.

5. Data Retention & Non-Disclosure

No Commercial Sharing: We do not sell, license, rent, or trade your personal information with third-party advertisers, data aggregators, or marketing firms under any circumstances.

Retention Period: Personal identifiers associated with internal accounts are stored only for the duration of active institutional involvement in the Oulu ICT Study Paths collaboration or until account deletion is requested.

6. Data Controller & Inquiries

The designated Data Controller responsible for personal data processing on this platform is:

Faculty of Information Technology and Electrical Engineering (ITEE)

University of Oulu, Pentti Kaiteran katu 1, 90570 Oulu, Finland

General Cooperation: itee.cooperation@oulu.fi

If you believe your data has been handled inconsistently with European data protection regulations, you also have the statutory right to lodge a formal complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) in Finland.