Privacy Policy

PondMapp Portal

In compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council, of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR), as well as with applicable data protection legislation, users of the PondMapp Portal are hereby informed of the following:


Data Controller

The controller of the personal data collected through the PondMapp Portal is the Spanish National Research Council (CSIC), a public research organisation belonging to the General State Administration of Spain.


Purpose of Processing

Personal data provided by users through the PondMapp Portal shall be processed by the CSIC and incorporated into the processing activity entitled “General Information Enquiries”, the purpose of which is to manage and respond to enquiries, communications or requests submitted by users, as well as to monitor and follow up on such enquiries.

This processing is carried out in the context of the exercise of the public powers and competences legally assigned to the CSIC.


Legal Basis for Processing

The legal basis for the processing of personal data is:

  • The consent of the data subject, expressed by submitting an enquiry or request through the Portal.

  • The necessity of the processing for the performance of a task carried out in the public interest or in the exercise of official authority vested in the CSIC.


Recipients of the Data

Personal data may be disclosed to other competent services of Public Administrations where such disclosure is necessary in order to properly address the enquiry or request submitted by the user.

No international transfers of personal data are envisaged.


Data Retention Period

Personal data shall be retained for the period necessary to fulfil the purpose for which they were collected, and subsequently for any additional periods required by applicable legal obligations, depending on the nature of the enquiry or service provided.


Data Protection Officer

In accordance with applicable data protection regulations, the CSIC has appointed a Data Protection Officer (DPO), whose designation has been duly notified to the Spanish Data Protection Authority (AEPD).

The Data Protection Officer of the CSIC is José López Calvo.

Users may contact the Data Protection Officer for any matters related to the processing of their personal data, as well as for the exercise of their rights, through the contact form provided for this purpose.


Rights of Data Subjects

Users may exercise the following rights at any time in relation to their personal data:

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to object

  • Right to restriction of processing

These rights may be exercised by submitting a request to the CSIC through the officially established channels or by contacting the Data Protection Officer.


Record of Processing Activities

Data protection regulations require that the Record of Processing Activities (RoPA) be made publicly available by electronic means.

The CSIC provides access to its Record of Processing Activities for both the central organisation of the CSIC and its Institutes and Research Centres, through its official channels. This record includes, for each processing activity:

  • The identity of the data controller

  • The legal basis for processing

  • The purposes of the processing

  • The categories of personal data processed

  • Data retention periods

  • A general description of the technical and organisational security measures applied


Security Measures

The CSIC has fulfilled the obligations established under data protection legislation, including, among others:

  • The establishment of internal procedures for the notification and management of personal data breaches.

  • The performance of risk analyses associated with data processing activities.

  • The implementation of appropriate technical and organisational security measures, based on the identified risks.

  • The conduct of Data Protection Impact Assessments (DPIAs) in cases where processing activities—particularly those linked to research projects—have been identified as presenting specific risks.

These measures are applied in order to ensure the confidentiality, integrity and availability of personal data processed through the PondMapp Portal.