Privacy notice pursuant to Article 13 of Regulation (EU) 2016/679 (“GDPR”)
Dear user, this document contains information regarding the processing of your personal data collected and processed during your browsing of the website https://www.cosmos2026.org/. This notice does not apply to other information collected through different channels or by other websites that may be consulted by the user through any links available on the website https://www.cosmos2026.org/.
Who processes the data?
The Data Controller is MEC & Partners S.r.l., with registered office at Piazza della Mercanzia, 2 – 40125 Bologna, telephone +39 051 4070658, PEC: mec-partners@pec.it, VAT No. 03177151200, in the person of its legal representative pro tempore. For matters relating to the processing of your personal data, you may write to privacy@mec-partners.it.
What data will be processed?
Browsing data
The IT systems and software used to operate the Website collect, during their normal operation, certain data the transmission of which is standard and always required by the most common Internet communication protocols. This information is not collected in order to be associated with specific data subjects, but by its very nature could, through processing and association with data held by third parties, allow users to be identified. This category of data includes IP addresses or domain names of the computers used by users connecting to the website, URI (Uniform Resource Identifier) addresses, the time of the request, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.) and other parameters relating to the user’s operating system and IT environment. These data are used solely to obtain statistical information on use of the website and to check its proper functioning, and are deleted after processing. The data may be used to ascertain liability in the event of hypothetical cybercrimes against the Website or third parties: except for this possibility, web contact data are not currently stored on a permanent basis.
Cookies
At present, this website may use only cookies that are strictly necessary for its operation, whether first-party or third-party, to enable the user to browse the site and use its essential functions. Where applicable, first-party anonymised analytical cookies may also be used to analyse access to and visits to the website on a statistical basis, collecting information in aggregated form with no possibility of identifying the individual user (therefore without any profiling or marketing purpose).
Data provided voluntarily by the user: this website does not collect personal data through generic contact forms or newsletters. The collection of personal data is limited exclusively to the registration form for the COSMOS 2026 conference. To find out how the data entered in that form are processed, please refer to the specific Event Privacy Notice.
For what purposes will the data be processed?
The categories of data listed above will be processed for the following purposes:
To facilitate browsing, carry out maintenance and perform statistical analysis of the website on the basis of statistical and anonymous data, as provided for by Directive 2002/58/EC (the so-called ePrivacy Directive);
To reply to emails sent by the data subject to the addresses indicated on this website and to respond to contact requests submitted through the relevant form (on the basis of pre-contractual measures taken at the request of the data subject: Article 6(1)(b) GDPR);
To allow registration for the “MEC&Partners Updates and Info” service (newsletter) for the periodic sending of promotional communications and updates on the Controller’s initiatives (on the basis of the consent freely given by the data subject by ticking the relevant box at the bottom of the “Contact us” form: Article 6(1)(a) GDPR); consent so given may always be withdrawn via the unsubscribe link included in the newsletter.
To protect, where necessary, the Controller’s rights of defence and credit and to prevent possible fraud or cybercrime (on the basis of the Controller’s legitimate interest: Article 6(1)(f) GDPR).
Except as specified for Browsing Data, for any strictly necessary technical Cookies and for first-party anonymised analytical Cookies, the user is free to provide personal data whenever requested in specific sections of the website. Failure to provide such data, however, may make it impossible to obtain what has been requested or sought.
How will the data be processed?
The processing will be carried out by means of IT and digital tools using logic strictly related to the purposes for which the data were collected, in compliance with the principle of purpose limitation as well as all the other principles of lawfulness, fairness and transparency set out in Article 5 GDPR. In particular, in observance of the principles of integrity, availability and confidentiality, specific security measures are adopted to prevent data loss, unlawful or improper use and unauthorised access. The Data may be processed by means of comparison, classification and calculation, as well as by the creation of lists or registers.
To whom will the data be disclosed?
The Data, or some of them, may be disclosed to the following subjects and/or entities which, for certain purposes, may carry out processing operations on behalf of MEC & Partners, including, in particular, the internal administrative office and our network of collaborators and employees, business information companies, external professionals and consultants, providers of software solutions or SaaS services, and ICT service providers.
Such subjects have been duly appointed, as applicable, as data processors or authorised persons pursuant to Articles 28 and 29 GDPR, or they receive and process personal data as independent controllers depending on the services provided and the agreements entered into with them from time to time by the Controller. In the latter case, they themselves will provide their own privacy notice to data subjects and collect consent where necessary. The list of suppliers to whom your personal data may be disclosed is available upon request.
Will the data be transferred outside the European Union?
No, the data will be processed mainly at the Controller’s operational office, located at Piazza della Mercanzia, 2, 40125 Bologna (BO), or alternatively at the premises of the suppliers appointed as data processors by the Controller, who have contractually undertaken to process the data only at their establishments located within the European Economic Area.
How long will the data be retained?
User data are retained by the Controller for the period strictly necessary to achieve the purposes for which they were collected and, once such purposes have ended, for any further period established by the applicable law. As regards Cookies, their retention depends on whether they are session Cookies or persistent Cookies.
What are the data subject’s rights?
At any time, data subjects have a series of rights provided by the GDPR, including:
- Access to their data (once confirmation has been obtained that they are being processed)
- Rectification and completion of their personal data
- Erasure of their data
- Restriction of the processing of their data, in the presence of certain conditions
- Portability, namely the possibility of receiving the personal data provided to the controller in a structured and commonly used format, and transmitting them to another controller
- Objection to the processing of data, in the presence of certain conditions
- The possibility of NOT being subject to automated decision-making
- Receiving communications relating to serious data breaches
- The possibility of withdrawing any consent given to the processing
Such requests may be addressed to the Controller, also through an authorised representative, at the following email address: privacy@mec-partners.it. The Controller shall provide an appropriate response to such request without undue delay.
If they are not satisfied with the Controller’s response, data subjects may always lodge a complaint with the Supervisory Authority which, in Italy, is the Garante per la Protezione dei Dati Personali, which may be contacted at the following details: (address) Piazza Venezia 11, 00187 Rome, (telephone) +39 06 696771, (email) protocollo@gpdp.it, (PEC) protocollo@pec.gpdp.it.
Date of last update of this notice: 02/04/2026.
