SINFT - Social Impact NFTs

Skip to main content
This website uses essential cookies required for its operation. Course content and all third-party embedded materials are accessible only to registered users. To manage your consent preferences, please register and log in.
x

Privacy Policy


SINFT Privacy Policy

SINFT Project

Privacy Policy

Last Updated: August 2026  |  Version 1.1  |  sinft.net

 

Data Controllers and Contact

This platform is operated under joint controllership by two consortium partners, each determining aspects of how your personal data is processed. Their respective responsibilities are allocated in a Joint Controllership Agreement pursuant to GDPR Art. 26.

 

Joint Controller 1 — Lead Partner

Poraka Nova Organisation

Project lead and primary public contact for data subjects

Contact: contact@porakanova.org

Web: www.sinft.net/contact

Joint Controller 2 — Technical Administrator

Angor AG

Technical platform operator; manages all data processing infrastructure

Operational contact via Poraka Nova

Data Protection Contact:  Aleksandar Karadimche — UIST (University of Information Science and Technology)

Role: Data Protection Contact for the SINFT Consortium | Contact via: contact@porakanova.org

Single public contact point: Poraka Nova Organisation — contact@porakanova.org

 

In accordance with GDPR Art. 26(1), Poraka Nova Organisation is designated as the single public-facing contact point for data subjects. You may exercise all rights described in this Privacy Policy by contacting Poraka Nova at contact@porakanova.org. Your request will be processed operationally by Angor AG within five working days, with a response to you within one calendar month.

A copy of the Joint Controllership Agreement is available on request from contact@porakanova.org.

 

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalised have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

 

Joint Controllers (referred to as "we", "us", or "our" in this Policy) refers to Poraka Nova Organisation and Angor AG, acting as joint data controllers of the personal data processed on this platform pursuant to GDPR Art. 26. See the Data Controllers and Contact section above for full details.

 

Data Protection Contact means the person designated by the Joint Controllers to advise on data protection compliance and act as operational contact for data subject matters. The designated Data Protection Contact is Aleksandar Karadimche, UIST (University of Information Science and Technology), reachable via contact@porakanova.org.

 

Cookies are small files that are placed on your computer, mobile device or any other device by a website, containing the details of your browsing history on that website among its many uses.

 

Device means any device that can access the Website such as a computer, a cell phone or a digital tablet.

 

Newsletter is a communication distributed by SINFT to its subscribers, providing updates, news, and information related to SINFT's activities, projects, and events.

 

Personal Data is any information that relates to an identified or identifiable individual.

 

Service refers to the Website and the e-learning platform accessible through it.

 

Service Provider means any natural or legal person who processes data on behalf of the Joint Controllers. It refers to third-party companies or individuals employed to facilitate or provide the Service or to assist in analysing how the Service is used.

 

Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit, IP address, browser type).

 

Website refers to SINFT: Social Impact NFT, accessible through https://sinft.net/

 

You means the individual accessing or using the Website, or the company or other legal entity on behalf of which such individual is accessing or using the Website.

 

Types of Data Collected

Data Provided Voluntarily

The optional, explicit and voluntary sending of emails to the email addresses indicated on this site, or completion of forms on the site (contacts, newsletters, registration), entails the subsequent acquisition of the sender's email address, name and surname, which are necessary in order to reply to requests and for the further purposes specified below, as well as other personal data included in the message or form. For registered platform users, additional profile data (username, country, organisation affiliation, age bracket) is collected at registration.

Usage Data

Usage Data is collected automatically when using the Service. This includes your device's Internet Protocol address (IP address), browser type and version, the specific pages of our Service that you access, the date and timestamp of your visit, the duration of your engagement, and unique device identifiers. When accessing via a mobile device, we may also collect the category of mobile device, its unique identifier, IP address, operating system, and mobile browser type.

 

Purpose and Legal Basis of Processing

Data Provided Voluntarily

Personal data are collected directly from data subjects who freely and voluntarily provided them. Personal data contained in requests for information are processed to respond to those requests. Data may also be used, with the express and specific consent of the person concerned, to send communications, without prejudice to the right to object at any time.

The legal basis for processing is — depending on the case — GDPR Art. 6(1)(a) (consent), Art. 6(1)(b) (performance of a contract or pre-contractual measures), and/or Art. 6(1)(f) (legitimate interest of the data controller in managing business relations and operating the platform).

Usage Data

Usage data is used for the sole purpose of obtaining anonymous statistical information on the use of the site, checking its correct operation, and protecting our rights in the event of security incidents. The legal basis is GDPR Art. 6(1)(f) — legitimate interest of the data controller to maintain site functionality and security.

Educational Platform Data

For registered users of the SINFT e-learning platform, personal data including enrolment records, course activity, assessment results, and completion data is processed for the purpose of delivering the educational service under the Erasmus+ project. The legal basis is GDPR Art. 6(1)(b) — performance of a contract to which the data subject is party (participation in the SINFT educational programme).

 

Retention of Your Personal Data

We retain your personal data for the duration necessary to fulfil the objectives outlined in this Privacy Policy. For registered platform users, account and activity data is retained for the duration of the SINFT Erasmus+ project plus a post-project period as required by the grant agreement and applicable law (typically 24 months for operational data and up to 5 years for certificate and reporting data).

We will retain and use your personal data to the extent required to meet our legal obligations, resolve disputes, and enforce our legal agreements and policies. Usage Data is generally preserved for a shorter duration (90 days for server access logs), with exceptions when this data is pivotal for security or when legal obligations mandate extended retention.

 

Security of Your Personal Data

Ensuring the security of your personal data is a paramount concern. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include HTTPS/TLS encryption for all data in transit, password hashing (bcrypt), server access restricted via SSH key authentication, and regular security monitoring.

However, no method of data transmission over the Internet or electronic data storage can be deemed entirely infallible. Despite our conscientious efforts to employ accepted security measures, we are unable to provide a definitive guarantee of absolute security.

 

Transfer of Your Personal Data

Overview

This section explains how and where your personal data is transferred outside the European Economic Area (EEA), under what legal mechanism, and what protections apply. As a general principle, we seek to keep your data within the EEA wherever possible. In all cases, transfers take place only where an appropriate legal safeguard under GDPR Chapter V is in place.

1. Hosting Infrastructure — Namecheap, Inc. (USA)

The sinft.net platform is hosted on a Virtual Private Server (VPS) operated by Namecheap, Inc., located at 4600 East Washington Street, Suite 305, Phoenix, Arizona 85034, USA. Personal data stored on this platform — including user account data, course activity records, and access logs — is physically stored on servers located in the United States of America, which does not hold a general EU adequacy decision under GDPR Art. 45.

Legal basis for the transfer

This transfer is governed by Standard Contractual Clauses (SCCs) — Module Two: Controller to Processor — as adopted by the European Commission in Decision 2021/914 of 4 June 2021, pursuant to GDPR Art. 46(2)(c). Namecheap, Inc. has incorporated these clauses in full in their published Data Processing Addendum (DPA), available at: https://www.namecheap.com/legal/universal/data-processing-addendum/

Role of Namecheap

Namecheap acts exclusively as an infrastructure-level Data Processor. Their role is limited to providing and maintaining the physical and virtual server infrastructure, network routing, and infrastructure-level security monitoring. Namecheap does not access, analyse, or use the personal data of platform users for any purpose of their own.

Transfer Impact Assessment

The SINFT Consortium has conducted a Transfer Impact Assessment (TIA) for this transfer, evaluating US law and practice in light of the Schrems II ruling (CJEU C-311/18). The TIA concluded that the combination of the SCCs, Namecheap's contractual commitments, the infrastructure-only nature of their role, the non-sensitive nature of the data, and the technical safeguards in place collectively provides a level of protection essentially equivalent to that afforded within the EEA. A copy of the TIA is available to supervisory authorities upon request.

2. Embedded Content — Google LLC (YouTube and Google Docs)

Certain course materials include videos embedded from YouTube and documents embedded from Google Docs, both operated by Google LLC (USA). When you access a page containing embedded content, your browser establishes a direct connection to Google's servers, involving transmission of your IP address and browser information to Google. This content is accessible only to authenticated, enrolled users. The transfer of data to Google LLC is lawful under the EU-US Data Privacy Framework adequacy decision (European Commission, 10 July 2023), under which Google LLC is certified. Google's privacy policy is available at: https://policies.google.com/privacy

3. Your Rights in Relation to International Transfers

You have the right to obtain a copy of the safeguards under which your personal data is transferred outside the EEA. To request this, contact: contact@porakanova.org. You also have the right to lodge a complaint with the supervisory data protection authority in your country of residence. All other data subject rights described in this Privacy Policy apply equally to personal data held in third-country infrastructure.

4. No Other International Transfers

Beyond Namecheap (infrastructure hosting) and Google LLC (embedded educational content), no other international transfer of personal data outside the EEA takes place in connection with this platform. The platform does not use third-party analytics, advertising networks, or social media integrations.

 

Automated Decision-Making

No automated decision-making processes are implemented on this platform that produce legal effects or similarly significantly affect the persons concerned (GDPR Art. 22).

 

Rights of the Data Subject

Under GDPR, you have the following rights in relation to your personal data:

•  Right of access (Art. 15) — request a copy of the personal data we hold about you

•  Right to rectification (Art. 16) — request correction of inaccurate data

•  Right to erasure (Art. 17) — request deletion of your personal data, subject to legal retention obligations

•  Right to restriction of processing (Art. 18) — request that processing be limited in certain circumstances

•  Right to data portability (Art. 20) — receive your data in a structured, machine-readable format

•  Right to object (Art. 21) — object to processing based on legitimate interest

•  Right to withdraw consent (Art. 7(3)) — withdraw consent at any time for consent-based processing, without affecting prior lawful processing

•  Right to lodge a complaint — with the supervisory authority in your country of residence

 

Requests to exercise any of these rights may be sent to: contact@porakanova.org, specifying the right you wish to exercise and a valid email address for the reply. You may also submit a data request directly from your Moodle profile page under Privacy and Policies → Data Requests.

 

Deleting Your Personal Data

You may request deletion of the personal data we have collected about you by contacting contact@porakanova.org or by submitting a data erasure request through your Moodle profile. We will process your request within one calendar month. In some instances, we may be required to retain certain information due to legal obligations, legitimate grounds, or Erasmus+ project reporting requirements.

 

Links to Other Websites

Our Service may incorporate links to external websites not under our operation or control. We strongly recommend that you review the Privacy Policy of every website you visit. We have no authority over, and cannot assume responsibility for, the content, privacy policies, or practices of any third-party websites or services.

 

Cookies

This platform uses cookies and similar tracking technologies. A full description of all cookies set by this platform, including third-party cookies set by embedded YouTube and Google Docs content, is provided in the Cookie Policy, which is presented separately as part of the mandatory consent process upon registration. The Cookie Policy is available at any time from the platform footer.

 

Changes to This Privacy Policy

This Privacy Policy may undergo periodic updates. Material changes will be communicated through the Moodle policy consent system — all users will be required to re-accept the updated policy before continuing to access the platform. The "Last Updated" date at the top of this document will be updated accordingly. We recommend that you routinely review this Privacy Policy to stay informed of any modifications.

 

Contact Us

If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:

 

•  By email: contact@porakanova.org

•  By visiting this page on our website: www.sinft.net/contact

•  Data Protection Contact: Aleksandar Karadimche (UIST) — reachable via contact@porakanova.org

 

SINFT Project — Privacy Policy v1.1 — August 2026  |  sinft.net


Credits
NFT ❯