Privacy Statement

Privacy Statement

CitiObs Application — Registered with AUTHENIX
Effective Date: [DATE]
This Privacy Statement explains how the CitiObs Application (the "App") collects, uses, stores, and protects your Personal Data, in compliance with Regulation (EU) 2016/679 (GDPR) and the AUTHENIX Privacy Statement.

1. Name of the Service

CitiObs Application (the "App"), a Citizen Observatory application registered as an Operator with the AUTHENIX Authorization Server, developed within the CitiObs project (EU Horizon Europe Grant Agreement No. 101086421).

2. Data Controller

[Operator Organisation Name]

[Operator Address]

[Operator Country]

Contact: [Contact Person Name]

Email: [Contact Email]

Phone: [Contact Phone]

Data Protection Officer (if applicable): [DPO Name and Contact Details]

3. Jurisdiction

[Operator Country – Region] (e.g., Germany – Bavaria)

4. Description of the Service

The App enables citizens to contribute environmental observations (primarily air quality data) using low-cost sensors and wearable devices, and to access aggregated environmental information from multiple Citizen Observatories. The App connects to the following components:

5. Legal Basis for Processing

The processing of Personal Data is based on the following legal grounds under the GDPR:

6. Categories of Personal Data Collected

6.1 Data Received from AUTHENIX

The App receives Personal Data brokered by AUTHENIX from your Identity Provider, limited to the OpenID Connect scopes authorised during registration:

ScopeData Provided
openid A user cryptonym (pseudonymous identifier), generated only if a subject identifier was received from the Identity Provider.
profile Name, family name, given name, middle name, nickname, preferred username, profile URL, picture, website, gender, birthdate, timezone, locale, and update timestamp.
email Email address and email verification status.
idp Identity Provider origin, identifier, name, and country.

6.2 Data Collected Directly by the App

7. Purpose of Processing

Your Personal Data is processed for the following purposes:

8. Data Sharing and Recipients

Your data may be shared with the following categories of recipients:

Important: Only anonymised data will be shared publicly. Sensitive or identifiable Personal Data will not be disclosed outside the Consortium Agreement without your explicit consent.

9. Transfer of Data Outside the EU/EEA

The App is primarily operated within the European Union. Should any transfer of Personal Data outside the EU or EEA become necessary, such transfers will only take place in compliance with Chapter V of the GDPR, using appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.

In line with AUTHENIX policy, all Operators (including this App) are contractually bound to comply with GDPR standards or higher, even if located outside the EU or EEA.

10. Data Retention

Data will only be retained for as long as necessary for the stated purposes, in accordance with the data minimisation principle.

11. Your Rights

Under the GDPR, you have the following rights:

Right to be Informed

Clear information about how your data is processed (this Privacy Statement).

Right of Access

Obtain a copy of the Personal Data held about you.

Right to Rectification

Correct inaccurate Personal Data. For data from your Identity Provider, contact them directly.

Right to Erasure

Request deletion of your data. Use the "Forget Me" option at authenix.eu.

Right to Restrict Processing

Request limitation of processing in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing of your data, including for direct marketing purposes.

Automated Decision-Making

Not to be subject to decisions based solely on automated processing that produce legal effects.

To exercise any of these rights, contact the Data Controller above. You may also manage active sessions and revoke App authorizations at authenix.eu/authorizedapps.

12. Security Measures

Appropriate technical and organisational measures are in place to protect your Personal Data:

13. Data Protection Code of Conduct

The Personal Data processed by this service is protected in accordance with the GÉANT Code of Conduct for Service Providers, a common standard for the research and higher education sector.

14. Minors

The CitiObs project may engage participants under the age of 18. In such cases, consent for the processing of Personal Data will be obtained from the minor's legal guardian, in compliance with Article 8 of the GDPR and applicable national legislation. Particular care is taken to ensure that minors and their guardians understand the nature and extent of data collection.

15. Right to Lodge a Complaint

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with a supervisory authority in your country of residence, your place of work, or the country where the alleged infringement occurred.

16. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect changes in our practices or applicable legislation. Material changes will be communicated through the App or via email. The effective date will be updated accordingly.

17. Contact

For any questions or concerns regarding this Privacy Statement:

[Operator Organisation Name]

[Operator Address]

Email: [Contact Email]

Phone: [Contact Phone]