MyUnipd app and processing of personal data
Art. 13 EU Regulation 2016/679 - General Data Protection Regulation
Pursuant to Art. 13 of EU Regulation 2016/679 – the so-called GDPR, the processing of the personal data of the data subjects (students, graduates and those enrolled in any course or training activity provided by the University) for the management of their academic career and any other service and further requirement that may prove necessary by virtue of the existence of that relationship will be based on the principles of fairness, lawfulness and transparency, and on the protection of their confidentiality and their rights.
MyUnipd is the official app of the University of Padua, available in Italian and English, which allows users to manage their university career easily and quickly via smartphone or tablet; it is intended as an alternative way to access services and content currently available on the web. These are the main features.
The Data Controller, that is, the body which determines how and why the data of data subjects are processed, is the University of Padua, with registered office at via VIII Febbraio n. 2, 35122, Padua (PEC address: amministrazione.centrale@pec.unipd.it).
At the University there is a Data Protection Officer, appointed pursuant to Art. 37 of the EU Regulation, who can be contacted at the email address: privacy@unipd.it.
The University processes the personal data provided by the data subject during registration, pre-enrolment, enrolment and registration on degree courses, PhD courses, specialisation courses, master's programmes and any other higher education or professional course activated at the University, including after the award of any final qualification.
The personal data that may be processed are:
- personal details (first name, surname, date of birth, sex), contact details, residence details, data relating to academic career, participation in teaching activities, qualifications held and income conditions;
- special category data, relating solely to the possibility of requesting compensatory tools during examinations (a function active only for students to whom they have been granted, on the basis of a declaration of temporary or permanent disability, without any further information on its nature being visible);
- browsing data (user ID and information relating to authentication, IP address).
MyUnipd does not process data relating to:
- actions and interactions carried out on the app via the personal smartphone (content and services consulted, actions and selections carried out);
- the smartphone model used, the operating system version and the version of the app used;
- any interruptions or slowdowns of the service or connection, malfunctions or crashes of the system or of some services.
In order to identify the causes of any malfunctions, inefficiencies or errors of the app itself, the user may provide personal and technical information for the resolution of the aforementioned problems.
The personal data of the data subjects are processed, on the basis of Article 6(1)(e) of the GDPR (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller), for the following purposes:
Management of the university career and provision of services. The MyUnipd app constitutes an access interface to the reserved area of Uniweb, the information system that allows all students enrolled at the University of Padua to access remotely information about their study path and to manage their university career directly. The MyUnipd app allows access to that information system after authentication, in order to consult the record book and study plan, exam registration, reject a mark, access the ESU canteen service, borrow books from libraries, receive notifications from Uniweb, check the payment status of their university fees, the university credits (ECTS credits) accumulated and the average of their marks. The user’s data are only displayed by the app through an interface suitable for the screen of the mobile device.
Management of access to the reserved Uniweb area. To access the reserved Uniweb area from MyUnipd it is necessary to authenticate using a university email address and password. To avoid requesting credentials at each login or upon expiry of their validity, the app stores the authentication information on the mobile device in a protected area. The session token is valid until the user logs out of the app or until its natural expiry (the session time to live is established by Uniweb). To delete the credentials stored on the smartphone, it is sufficient to uninstall the app.
Collection and management of browsing data. During its normal operation, the MyUnipd app acquires certain personal data whose transmission is implicit in the use of Internet communication protocols, such as IP addresses. Such data are processed for the purpose of checking the proper functioning of the systems and services offered, as well as for security reasons and for the protection of the rights of the Controller.
The personal data of the data subject are processed with the support of IT tools. The University adopts appropriate organisational and technical measures to protect and ensure the confidentiality of the personal data in its possession, in particular against the loss, theft, as well as the unauthorised use, disclosure or modification of personal data.
Access to the MyUnipd app takes place through the institutional credentials provided by the University and protected by the centralised access control system Single Sign On (SSO), which uses Shibboleth technology. Users’ credentials are not accessible, not even in encrypted form, to service providers and web and mobile applications, as the identification process always takes place within the University authentication system, based on the Security Assertion Markup Language (SAML) protocol.
The University does not use automated decision-making processes relating to the rights of the data subject on the basis of personal data, including profiling, in compliance with the safeguards provided for in Article 22 of the EU Regulation.
Any processing of special categories of data is carried out in compliance with the “Regulations for the processing of the University’s sensitive and judicial data”, available on the page Regulations of general interest.
The processing of personal data for the purposes of managing the university career and providing services is essential for the establishment and management of the relationship between the data subject and the University, for the provision of services and for compliance with the related legal obligations (performance of tasks carried out in the public interest with which the University is entrusted, as defined by law, by the University Statute and by internal regulations, pursuant to Article 6(1)(e) of the GDPR.
The processing of personal data for the purposes of collecting and managing browsing data is also essential for the provision of services and for compliance with the related legal obligations (performance of tasks carried out in the public interest with which the University is entrusted, as defined by law, by the University Statute and by internal regulations, pursuant to Article 6(1)(e) of the GDPR.
Failure to provide personal data relating to browsing makes it impossible to use the MyUnipd app.
Personal data will be processed by the staff of the University of Padua and by any collaborators appointed to assess the functioning of the application. They will not be disclosed to other third parties, nor transferred to countries outside the EU.
- data relating to the university career: personal data are stored for the entire period necessary to carry out this purpose, in accordance with the provisions of the legislation in force and the University Regulations on the Records Retention Schedule as regards the student file.
- data for access to the Uniweb reserved area from the App: the session token for access to Uniweb is valid until the student logs out of the app or until its natural expiry.
- browsing data: data relating to electronic traffic (IP addresses) are deleted or anonymised when they are no longer necessary for the transmission of the communication, unless otherwise provided by law
The data subject may exercise the rights provided for in Articles 15 et seq. of the EU Regulation, such as the right of access, the right to rectification or completion of their data, the right to erasure (right to be forgotten) and restriction of processing, and the right to data portability, under the conditions and within the limits indicated by the EU Regulation.
The request for erasure of personal data cannot be accepted insofar as the processing is necessary for compliance with a legal obligation, for the performance of institutional tasks, for the establishment, exercise or defence of a right before a court, and in any other case provided for by Article 17(3) of the EU Regulation.
The data subject has the right to object at any time to the processing of their personal data, in accordance with Article 21 of the EU Regulation. The data subject may lodge a complaint with the Garante per la protezione dei dati personali.
To exercise their rights, the data subject may contact the University by writing to the certified email address amministrazione.centrale@pec.unipd.it or to the email address urp@unipd.it. Alternatively, the data subject may write to: University of Padua, via VIII Febbraio n. 2, 35122 Padua.
The University is required to provide a response within one month of the request, which may be extended up to three months in cases of particular complexity of the request.
Any amendments and additions to this privacy notice are published in the privacy section of the institutional website at www.unipd.it/privacy.
In any case, the University undertakes to communicate directly to data subjects, through its institutional channels, any changes to the purposes of the processing, the identity of the data controller, and any other changes likely to have a significant impact on the rights of data subjects or on the exercise of those rights.
Last updated: 10 July 2024
Data Protection Officer DPO: Giorgio Valandro
email: privacy@unipd.it