ADRIONWIND Privacy Policy (Website & ICT Platform)
Project: ADRIONWIND – "Adriatic‑Ionian Offshore Wind Network of Excellence" (IPA‑ADRION00163)
Project duration: 36 months
Version/date: v1.1 – 29 July 2026
1. General information
ADRIONWIND is an Interreg VI‑B IPA Adriatic Ionian project (IPA‑ADRION00163) with a duration of 36 months.
The project establishes a collaboration network and a digital platform to support stakeholder engagement, knowledge exchange, and network activities.
This privacy policy explains how personal data is processed when you:
- visit the ADRIONWIND website (https://adrionwind.eu),
- use the ADRIONWIND ICT platform (including registration, profiles, thematic working groups, knowledge repositories, discussion channels and related content),
- join authorised video meetings for thematic working groups via the self‑hosted Jitsi service at https://meet.adrionwind.eu,
- subscribe to the ADRIONWIND Network Newsletter,
- register for or participate in ADRIONWIND events, workshops, consultations and focus groups (including those managed through the ICT platform).
Please note that data transmission over the internet may never be completely secure. We apply appropriate technical and organisational measures, but absolute security cannot be guaranteed.
2. Who is responsible for processing (controllers) and how to contact us
2.1 Platform/website operator (primary contact for the platform)
The Lead Partner is responsible for the purchase, application and testing of the ADRIONWIND ICT platform.
Lead Partner (LP1) / Platform operator (for the ADRIONWIND ICT platform and website):
University of Zagreb, Faculty of Mechanical Engineering and Naval Architecture (UNIZAG FSB)
Address: Ivana Lučića 5, 10002 Zagreb, Croatia
Project contact email: neven.duic@fsb.hr
General platform contact: info@adrionwind.eu
2.2 Consortium partners
ADRIONWIND is implemented by a consortium. Partners may process personal data in their own scope (e.g., when they invite you to an event they host, manage a focus group, or process attendance lists). The partnership includes: UNIZAG FSB (LP1), FENICE (PP2), KINNO (PP3), AKBN (PP4), AIH (PP5), FEAC (PP6), UDG (PP7), ARTI (PP8), EPBiH (PP9).
For ADRIONWIND-related data protection questions, you may contact the relevant partner:
If your organisation has an official DPO contact different from the project contact person, you may also contact your DPO.
3. What personal data we collect
3.1 Data you provide (typical categories)
Depending on what you do on the website/platform, we may process:
- identification and contact details (e.g., name, email, organisation, position, country),
- account data (profile data, institution type, permissions assigned by administrators),
- communications (messages, support requests, thematic‑group discussion posts),
- participation data (event registrations, attendance, feedback forms),
- content you submit to the platform (posts, uploaded materials in knowledge repositories, stakeholder/business datasets you are authorised to manage),
- consultation/focus group inputs (notes, questionnaires, chat messages, shared documents),
- newsletter subscription data (email address and related Mailchimp audience fields you provide),
- audio/video and images if an online session is recorded or photos are taken (only where clearly announced and a legal basis exists).
Member / stakeholder directory: organisational and contact information may be shown in stakeholder mapping and related directory features according to the visibility rules configured on the platform. We apply data minimisation to fields that are publicly or widely visible.
3.2 Data collected automatically (technical)
When you access the website/platform, we may process:
- IP address,
- date/time and pages accessed,
- device and browser information,
- referrer URL,
- error logs and security logs,
- authentication and session cookies necessary for login and CSRF protection.
3.3 Video meetings (Jitsi)
Authorised users of Thematic Working Groups may join video meetings embedded from the portal. For that purpose we may process:
- your portal user ID and display name (passed to the meeting service so other participants can identify you),
- technical connection data required to run the conference (e.g. IP address, device/browser information, meeting room identifier),
- audio and video streams while you participate (processed in real time to enable the call).
Access is restricted: the portal checks your login session and group authorisation before issuing a short‑lived access token for a fixed meeting room. Users without authorisation do not receive a token.
Recording: server‑side recording is not enabled by default for thematic‑group meetings. If a meeting is recorded (e.g. local browser recording by a participant, or a separately announced session recording), participants will be informed where practicable, and a lawful basis (typically consent) will be applied.
4. Why we process personal data and the legal bases (GDPR)
- Account creation and platform access – Purpose: create and manage user accounts, allow login, provide platform functions. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f)).
- Member networking and collaboration – Purpose: enable thematic working groups, knowledge repositories, discussions, networking and stakeholder engagement. Legal basis: legitimate interests (Art. 6(1)(f)) and/or contract (Art. 6(1)(b)).
- Video meetings for authorised group members – Purpose: enable remote collaboration within thematic working groups. Legal basis: legitimate interests (Art. 6(1)(f)) and/or contract (Art. 6(1)(b)); where recording is used, typically consent (Art. 6(1)(a)).
- Handling inquiries and support – Purpose: respond to messages sent to project/platform contacts. Legal basis: legitimate interests (Art. 6(1)(f)) and/or contract (Art. 6(1)(b)).
- Events, workshops, B2B and knowledge-sharing activities – Purpose: manage registrations, attendance, feedback and reporting; relevant parts of certain events may be recorded and published for network members where announced. Legal basis: legitimate interests (Art. 6(1)(f)) and/or contract (Art. 6(1)(b)); recordings: consent (Art. 6(1)(a)) unless another lawful basis applies and is documented.
- Stakeholder consultations and focus groups (Activity 2.4) – Purpose: organise discussions and related consultations through the ICT platform and partner activities. Legal basis: legitimate interests and/or contract depending on format; recordings: typically consent.
- Documentation of engagement (project reporting/deliverables) – Purpose: document stakeholder engagement for project deliverables and reporting. Legal basis: legitimate interests (Art. 6(1)(f)) and/or legal obligation where applicable (Art. 6(1)(c)).
- Security, abuse prevention and technical operation – Purpose: protect platform integrity, prevent fraud/spam, troubleshoot. Legal basis: legitimate interests (Art. 6(1)(f)).
- Newsletter (Mailchimp) – Purpose: send the ADRIONWIND Network Newsletter and related project updates. Legal basis: consent (Art. 6(1)(a)). You may withdraw consent at any time via the unsubscribe link in emails or by contacting us.
- Cookies and analytics – Purpose: ensure platform functionality and, with consent, measure usage. Legal basis: strictly necessary cookies: legitimate interests; analytics/non-essential cookies: consent (via cookie banner).
Special categories of data (GDPR Art. 9): ADRIONWIND does not intend to collect special category data via the platform. If such data is submitted, it will be processed only where a lawful basis applies and only to the extent necessary.
5. Who receives personal data (sharing and disclosures)
Within the consortium: data may be shared among ADRIONWIND partners only when needed to run project activities (e.g., registration lists for an event hosted by a partner, consultation participation management).
Platform / IT providers (processors or equivalent service providers), including:
- Web hosting for
adrionwind.eu (website and database hosting under the project hosting package),
- Email delivery for transactional project mail (e.g. account activation) via the project mail service for
adrionwind.eu,
- Jitsi Meet on
meet.adrionwind.eu for authorised thematic‑group video meetings (display name / user id and real‑time AV data as needed to run the call),
- Mailchimp (Intuit Mailchimp) for newsletter subscription and sending, when you subscribe via the website form,
- other support providers engaged under contract where necessary for security or maintenance.
These providers process data under contractual arrangements and instructions to the extent required to provide their services.
Publicly accessible vs restricted content: the website includes public content and restricted sections (e.g. thematic‑group workspaces, certain knowledge resources) available only to authenticated and authorised users.
Social media: links to ADRIONWIND pages on Facebook and LinkedIn may lead you to those platforms, which process data under their own policies.
6. International transfers
The consortium includes organisations in EU and non‑EU countries. Where personal data is transferred outside the EU/EEA and GDPR requires safeguards, appropriate measures will be applied (e.g., Standard Contractual Clauses), and details can be requested via the contact points in Section 2.
Newsletter data processed by Mailchimp may involve transfers outside the EU/EEA. Mailchimp provides information on its processing and transfer safeguards in its privacy notice; by subscribing you acknowledge that transfer as also stated next to the newsletter form.
7. Retention: how long we keep data
We keep personal data only as long as needed for the purposes above, applying data minimisation.
The project duration is 36 months. ADRIONWIND's network and ICT platform are planned for sustainability; stakeholders/organisations supported may commit to participate for the project duration and at least 2 years after project end (MoU concept) and the consortium commits to support the core output for at least 2 years post‑project.
Project documentation may also require retention for audits/controls and programme rules (the stricter retention requirement applies where relevant).
- Account/profile data: for the active use period, with periodic review; delete or anonymise after prolonged inactivity (e.g. 24 months) unless retention is required for project/network governance or the account remains active.
- Event registration lists: until deliverable/reporting completion plus the applicable audit window under programme rules.
- Video meeting tokens: short‑lived; not retained as meeting credentials beyond their expiry.
- Meeting AV streams: processed for the duration of the call; not stored by default on the meeting server when recording is disabled.
- Newsletter data: until you unsubscribe or we delete the subscription upon request.
- Recordings (if any): only as long as needed for the stated purpose; necessity is re‑validated periodically.
8. Your rights (GDPR)
You have the right to:
- access (Art. 15),
- rectification (Art. 16),
- erasure (Art. 17),
- restriction (Art. 18),
- portability (Art. 20, where applicable),
- objection (Art. 21, where applicable),
- withdraw consent at any time (where processing is based on consent).
To exercise your rights, contact info@adrionwind.eu or the relevant partner contact listed in Section 2.2.
If you believe your data protection rights have been violated, you may lodge a complaint with the competent supervisory authority. For the platform operator in Croatia, this is the Croatian Personal Data Protection Agency (AZOP).
9. Cookies
The website/platform uses cookies and similar technologies:
- Strictly necessary – login/session cookie, CSRF/security cookie (always active; required for the platform to work),
- Preference – language and similar settings where used,
- Analytics / non‑essential – only if enabled and after you consent via the cookie banner.
You can manage cookies via the cookie banner on the site and/or your browser settings. Disabling necessary cookies may prevent login and other core functions.
10. Third‑party links and embedded tools
The platform may link to or embed third‑party services (for example social media pages, or the Jitsi meeting interface loaded from meet.adrionwind.eu). Those services may process data under their own technical requirements and, where applicable, their own notices. ADRIONWIND controls access to thematic meetings via portal authentication and authorisation; it is not responsible for processing by unrelated third‑party sites you choose to visit via external links.
11. Changes to this policy
We may update this Privacy Policy to reflect platform changes and project needs. The latest version will be published on the platform at ?p=privacy. Material changes (for example new processors or new video features) will be reflected in the version/date above.