MyUnipd app and personal data processing
Art. 13 EU Regulation 2016/679 - General Data Protection Regulation
Pursuant to Art. 13 of EU Regulation 2016/679 – the so-called GDPR, the processing of the personal data of the data subjects (students, graduates and those enrolled in any course or training activity provided by the University) for the management of their academic career and of any other service and further requirement that may prove necessary by virtue of the existence of such relationship will be based on the principles of fairness, lawfulness and transparency, and on the protection of their privacy and their rights.
MyUnipd is the official app of the University of Padua, available in Italian and English, which makes it possible to manage your academic career simply and quickly via smartphone or tablet; it is intended as an alternative way to access services and content currently available on the web. These are its main features.
The Data Controller, namely the body that determines how and why the data of data subjects are processed, is the University of Padua, with registered office at via VIII Febbraio n. 2, 35122, Padua (PEC address: amministrazione.centrale@pec.unipd.it).
At the University there is a Data Protection Officer, appointed pursuant to Article 37 of the EU Regulation, who can be contacted at the following email address: privacy@unipd.it.
The University processes the personal data provided by the data subject during registration, pre-enrolment, enrolment and registration on degree programmes, PhD programmes, specialisation courses, master's programmes and any other advanced or professional training course offered by the University, including after the award of any final qualification.
The personal data that may be processed are:
- personal details (first name, surname, date of birth, sex), contact, residence, data relating to academic career, participation in teaching activities, qualifications held and income conditions;
- special category data, relating solely to the possibility of requesting compensatory tools during examinations (a function active only for students to whom these have been granted, on the basis of a declaration of temporary or permanent disability, without any further information on its nature being visible);
- browsing data (user ID and authentication-related information, IP address).
MyUnipd does not process data relating to:
- actions and interactions carried out on the app via the user's personal smartphone (content and services consulted, actions and selections made);
- the smartphone model used, the operating system version and the version of the app used;
- any interruptions or slowdowns of the service or connection, malfunctions or system crashes or crashes affecting some services.
In order to identify the causes of any malfunctions, inefficiencies or errors in the app itself, the user may provide personal and technical information for the resolution of the aforementioned issues.
The personal data of data subjects are processed, on the basis of Article 6(1)(e) of the GDPR (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller), for the following purposes:
Management of the university career and provision of services. The MyUnipd app provides an interface for accessing the reserved area of Uniweb, the information system that allows all students enrolled at the University of Padua to access information about their course of study remotely and to manage their university career directly. The MyUnipd app allows access to that information system after authentication, in order to consult the academic record book and study plan, register for exams, refuse a mark, access the ESU canteen, borrow books from libraries, receive notifications from Uniweb, check the payment status of their tuition fees, the university credits (ECTS credits) accumulated and the average of their marks. The user’s data are only displayed by the app through an interface suited to the screen of the mobile device.
Management of access to the reserved Uniweb area. To access the reserved area of Uniweb from MyUnipd it is necessary to authenticate using a university email address and password. To avoid requesting credentials at every login or upon expiry of their validity, the app stores the authentication information on the mobile device, in a protected area. The session token remains valid until the user logs out of the app or until its natural expiry (the session time to live is established by Uniweb). To delete the credentials stored on the smartphone, it is sufficient to uninstall the app.
Collection and management of browsing data. During its normal operation, the MyUnipd app acquires certain personal data whose transmission is implicit in the use of Internet communication protocols, such as IP addresses. Such data are processed for the purpose of checking the correct functioning of the systems and services offered, as well as for security reasons and to protect the rights of the Controller.
The personal data of the data subject are processed with the support of IT tools. The University adopts appropriate organisational and technical measures to protect and ensure the confidentiality of the personal data in its possession, in particular against the loss, theft, as well as the unauthorised use, disclosure or modification of personal data.
Access to the MyUnipd app takes place through the institutional credentials provided by the University and protected by the centralised access control system Single Sign On (SSO), which uses Shibboleth technology. Users' credentials are not accessible, not even in encrypted form, to service providers and web and mobile applications, since the identification process always takes place within the University's authentication system, based on the Security Assertion Markup Language (SAML) protocol.
The University does not use automated decision-making processes relating to the rights of the data subject on the basis of personal data, including profiling, in compliance with the safeguards provided for in Article 22 of the EU Regulation.
Any processing of special categories of data is carried out in compliance with the “Regulations for the processing of the University's sensitive and judicial data”, available on the page Regulations of general interest.
The processing of personal data for the purposes of managing the university career and providing services is essential for the establishment and management of the relationship between the data subject and the University, for the provision of services and for compliance with the related legal obligations (performance of tasks carried out in the public interest entrusted to the University, as defined by law, by the University Statute and by internal regulations, pursuant to Art. 6(1)(e) of the GDPR.
The processing of personal data for the purposes of collecting and managing browsing data is also essential for the provision of services and for compliance with the related legal obligations (performance of tasks carried out in the public interest entrusted to the University, as defined by law, by the University Statute and by internal regulations, pursuant to Art. 6(1)(e) of the GDPR.
Failure to provide personal data relating to browsing makes it impossible to use the MyUnipd app.
Personal data will be processed by staff of the University of Padua and by any collaborators appointed to assess the functioning of the application. They will not be disclosed to other third parties, nor transferred to countries outside the EU.
- data relating to the university career: personal data are retained for the entire period necessary to fulfil this purpose, in accordance with the provisions of the applicable legislation and the University Regulations on records retention and disposal with regard to the student file.
- data for access to the reserved Uniweb area from the App: the session token for access to Uniweb remains valid until the student logs out of the app or until its natural expiry.
- browsing data: data relating to electronic traffic (IP addresses) are deleted or anonymised when they are no longer necessary for the transmission of the communication, unless otherwise provided for by law
The data subject may exercise the rights provided for in Articles 15 et seq. of the EU Regulation, such as the right of access, the right to rectification or completion of their data, the right to erasure (right to be forgotten) and restriction of processing, and the right to data portability, under the conditions and within the limits indicated by the EU Regulation.
The request for erasure of personal data cannot be granted to the extent that the processing is necessary for compliance with a legal obligation, for the performance of institutional tasks, for the establishment, exercise or defence of a right in judicial proceedings, and in any other case provided for by Article 17(3) of the EU Regulation.
The data subject has the right to object at any time to the processing of their personal data, in accordance with Article 21 of the EU Regulation. The data subject may lodge a complaint with the Garante per la protezione dei dati personali.
To exercise their rights, the data subject may contact the University by writing to the certified email address amministrazione.centrale@pec.unipd.it or to the email address urp@unipd.it. Alternatively, the data subject may write to: University of Padua, via VIII Febbraio n. 2, 35122 Padua.
The University is required to provide a response within one month of the request, extendable up to three months in the event of particular complexity of the request.
Any amendments and additions to this privacy notice are published in the privacy section of the institutional website at www.unipd.it/privacy.
In any case, the University undertakes to communicate directly to data subjects, through its institutional channels, any changes to the purposes of the processing, the identity of the data controller and any other changes capable of significantly affecting the rights of data subjects or their exercise.
Last updated: 10 July 2024
Data Protection Officer DPO: Giorgio Valandro
email: privacy@unipd.it