Last updated: June 25, 2026
The data controller within the meaning of the EU General Data Protection Regulation (GDPR – Regulation 2016/679) is:
Nucleomatica di Cecilia Marino
Via F. Carabellese 10/C
70056 Molfetta BA
Italy,
partita IVA 07804710726 (IT)
Privacy contact / Data Protection Officer: Cecilia Marino
E-mail: info@inmr.net
This privacy policy describes how personal data collected in the context of the initiative Nation of the Month ("the Initiative") is processed. It applies exclusively to data collected through the form present at https://www.inmr.net/gratis.php .
Processing is carried out on the basis of the data subject's freely given, specific, and informed consent (Art. 6(1)(a) GDPR), provided at the time of participation in the Initiative. Where processing is necessary for compliance with a legal obligation applicable to the controller, Art. 6(1)(c) GDPR serves as the additional legal basis.
We collect the following categories of personal data: name, professional affiliation, town, country, IP address.
Personal data are processed exclusively for the purposes of the Initiative and for producing aggregated, anonymised statistical analyses. Individual-level data are never published or otherwise disclosed. Once data have been aggregated and anonymised they no longer constitute personal data and fall outside the scope of the GDPR.
We do not use your data for profiling, automated decision-making, direct marketing, or any purpose other than those stated above.
Your personal data are not shared with any third party, whether within or outside the European Economic Area (EEA). No data are sold, licensed, or otherwise disclosed to external organisations, public authorities, or individuals, except where we are required to do so by applicable EU or Member State law.
No transfers of personal data to third countries (outside the EEA) take place. Personal data are hosted within the EEA. Should any technical service provider involve data processing outside the EEA, we ensure that such transfers are governed by appropriate safeguards.
Personal data are retained for no longer than is necessary to fulfil the purposes described in Section 4. Specifically, identifiable data will be deleted no later than 12 months after the close of the Initiative. IP addresses are processed temporarily for the sole purpose of verifying the legitimacy of requests and are discarded/anonymised immediately after the monthly validation process. Aggregated, anonymised results may be retained indefinitely for scientific or historical reference.
As a data subject you have the following rights:
Right of access (Art. 15) – You may request confirmation of whether we
process your personal data and, if so, obtain a copy.
Right to rectification (Art. 16) – You may request correction of inaccurate
or incomplete data.
Right to erasure ("right to be forgotten") (Art. 17) – You may request
deletion of your personal data at any time, without prejudice to processing already
completed on the basis of your consent.
Right to restriction of processing (Art. 18) – You may request that
processing be limited in certain circumstances.
Right to data portability (Art. 20) – You may request your data in a
structured, commonly used, machine-readable format.
Right to withdraw consent (Art. 7(3)) – You may withdraw your consent at
any time; withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right to lodge a complaint (Art. 77) – You have the right to lodge a
complaint with the supervisory authority of your Member State of habitual residence.
In Italy, the competent authority is the Garante per la protezione dei dati personali
(www.garanteprivacy.it).
To exercise any of the rights listed above, including requesting the deletion of your personal data, please send an e-mail to:
info@inmr.net
Please include sufficient information to identify yourself and specify the right you wish to exercise. We will respond within 30 days of receipt of your request, as required by Art. 12 GDPR. In complex cases this period may be extended by a further 60 days; you will be informed of any such extension and the reasons for it. o ensure your privacy and security, we may take reasonable steps to verify your identity before granting access or making corrections.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Art. 32 GDPR. Access to identifiable data is restricted to the principal investigator and authorised team members who are bound by confidentiality obligations. Technical measures include, but are not limited to, storing data files in a non-publicly accessible directory, outside the server's web root, to prevent unauthorized access.
We may update this policy from time to time to reflect changes in the Initiative or in applicable law. The date at the top of this page indicates when the policy was last revised. Where changes are material, we will notify participants through a notice on the website.