“Controller” means the entity which determines the purposes and means of the Processing of Personal Data. In this case,
ESTRO.
“Data Protection Laws and Regulations” means all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom, applicable to the Processing of Personal Data under the Agreement.
“Data Subject” means the identified or identifiable person to whom Personal Data relates.
“GDPR” means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
“Personal Data” means any information relating to an identified or identifiable natural person and, an identified or identifiable legal entity (where such information is protected similarly as personal data or personally identifiable information under applicable Data Protection Laws and Regulations).
“Processing” means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Processor” means the entity which Processes Personal Data on behalf of the Controller. These entities could be teachers, IT suppliers, exhibitors, medical companies, and congress organizers.
“Sub-processor” means any Processor engaged by a Processor to process the Controller’s data.
“Supervisory Authority” means an independent public authority which is established by an EU Member State pursuant to the GDPR.
“Third party processors” refers to companies delivering products and services to ESTRO for specific purposes. An example would be a company providing a software tool allowing persons to register for a workshop. These companies will not use contact details for their own commercial purposes but process the data on behalf of ESTRO. Another example would be a company processing payment on behalf of ESTRO, for example when registering to attend the ESTRO Congress. These entities could be teachers, IT suppliers, exhibitors, medical companies, and congress organizers.
“ESTRO contact” is a person in contact with ESTRO with an ESTRO account who is neither an ESTRO member nor participates to any ESTRO activities (such as courses and congress).
“ESTRO participant” is a person who participates to ESTRO activities (course, congress, live or online workshop).
“ESTRO member” is a person who is an ESTRO member and has therefore access to dedicated benefits, depending on his/her membership type.
“Sub-processor” means any Processor engaged by a Processor to process the Controller’s data.
“Supervisory Authority” means an independent public authority which is established by an EU Member State pursuant to the GDPR.
“Other data/not personal data” are collected for technical or internal purposes but are not mentioned in this document as those data are not covered either by GDPR or privacy regulation.