Home / Privacy Policy

Privacy Policy

How I-STEP Network collects, uses, stores and protects personal data through its website and membership system.

1. WHO WE ARE

This website is operated by:

I-STEP Network

Legal form: NGO

Registration number: G27662303

Registered address: Escorpión 16, Alicante, Spain

Website: https://istep-network.org

General and data protection contact: office@istep-network.org

I-STEP Network determines the purposes and means of processing personal data collected through this website and acts as the data controller.

2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy explains how I-STEP Network processes personal data in connection with:

  • Visits to the website.
  • Membership applications.
  • Assessment and administration of membership.
  • Public profiles of approved member organisations.
  • Organisational capacity and reach statistics.
  • Communications addressed to I-STEP members.
  • Contact forms and enquiries.
  • Website accounts and administration.
  • Comments, where enabled.
  • Uploaded images, logos and documents.
  • Content embedded from third-party websites.

Information about cookies and similar technologies is provided separately in our Cookie Policy.

This policy applies to information relating to identified or identifiable natural persons.

Information relating exclusively to a legal entity may not constitute personal data. However, names, email addresses, telephone numbers, professional roles and other information concerning representatives, employees, volunteers and contact persons are personal data.

3. PERSONAL DATA WE PROCESS

3.1 Website and technical information

When a person visits the website, I-STEP Network and its technical service providers may process:

  • IP address.
  • Browser type and version.
  • Device and operating system.
  • Date and time of access.
  • Pages requested.
  • Referring page or website.
  • Server and security logs.
  • Error and diagnostic information.
  • Information used to detect spam, misuse or unauthorised access.

This information is used to operate and protect the website, maintain its availability, diagnose technical problems and prevent abuse.

3.2 Membership applications

When an organisation applies to join I-STEP Network, we may collect the following information.

Public organisational information:

  • Display name.
  • Acronym.
  • Organisation type.
  • City and country.
  • Website.
  • Social media links.
  • Short and extended organisational descriptions.
  • Areas of work.
  • I-STEP strategic groups.
  • Featured projects.
  • Organisation logo.
  • Organisational capacity and reach figures, where publication has been authorised.

Private administrative information:

  • Full registered legal name.
  • Erasmus+ Organisation ID, where applicable.
  • Registration number or other organisational identifier.
  • Main contact name.
  • Main contact role or position.
  • Email address.
  • Telephone number.
  • Information provided in declarations and acknowledgements.
  • Information required to assess and administer the application.

Private administrative information is not published in the public member directory, member map or individual member profile.

Technical and governance information:

  • Application date.
  • Application language.
  • Membership status.
  • Approval, rejection, suspension, withdrawal or reactivation dates.
  • Internal Board notes.
  • Requests for clarification.
  • Profile verification dates.
  • Metrics verification information.
  • Records of membership status changes.
  • Records showing which version of the membership conditions and privacy information was acknowledged.
  • Submission and security information where necessary to prevent misuse or retain evidence of the application.

3.3 Assessment of membership applications

Membership applications are assessed by authorised I-STEP Network administrators and members of its Board.

The assessment may consider whether the applicant organisation’s mission, activities, conduct and values are aligned with the mission, values and areas of activity of I-STEP Network.

Admission is not automatic.

Membership decisions are made or reviewed by authorised persons. I-STEP Network does not use solely automated decision-making to approve or reject membership applications.

Internal assessment information may include:

  • Comments made during the assessment.
  • Requests for additional information.
  • Reasons supporting the membership decision.
  • Internal governance notes.
  • Information relating to changes in membership status.

3.4 Public profiles of approved members

When an organisation is approved, the information identified as public in the application may be published in:

  • The I-STEP member directory.
  • The member map.
  • The organisation’s individual member page.
  • Related project pages.
  • Website search results.
  • Pages presenting the composition, expertise and activities of the network.
  • Aggregate information about I-STEP Network.

A public member profile may include:

  • Organisation name and acronym.
  • Organisation logo.
  • Organisation type.
  • City and country.
  • Website.
  • Public organisational descriptions.
  • Areas of work.
  • I-STEP strategic groups.
  • Social media links.
  • Featured projects.
  • Membership approval year.
  • Last profile verification date.
  • Organisational metrics where their public display has been authorised.

The member map displays an approximate city-level location. It is not intended to publish an exact office address or personal address.

Applicant organisations are responsible for ensuring that they are authorised to provide and publish any logos, images, project descriptions, links and other organisational content submitted through the application.

3.5 Organisational capacity and reach metrics

I-STEP Network may collect the following organisational information:

  • Number of paid staff.
  • Number of active volunteers.
  • Number of formal individual members.
  • Number of organisations represented by a network, federation, platform or umbrella organisation.
  • Annual direct reach.
  • Reference year.
  • Whether the figure is exact or estimated.
  • Whether the figure represents unique individuals, participations or a mixed measure.
  • Annual indirect or digital reach.
  • Information explaining how the figures were calculated.
  • Date on which the information was last updated.
  • Internal verification and quality-control information.

These figures may be used to:

  • Understand the scale and composition of the network.
  • Monitor the development of I-STEP Network.
  • Prepare internal reports.
  • Produce aggregated statistics.
  • Communicate the collective scale and reach of the network.
  • Prepare funding applications, reports, presentations and institutional communications.
  • Improve network planning and accountability.

Aggregate figures may contain overlaps. For example, the same person may participate in activities delivered by more than one member organisation.

Paid staff, volunteers, formal members, direct participants and indirect audiences are treated as separate indicators. They are not automatically added together or presented as a single total.

Organisation-specific figures are published on an individual member profile only where the organisation has authorised their public display.

I-STEP Network may exclude information from public aggregate calculations where it is outdated, incomplete, unreliable, duplicated or not sufficiently comparable.

3.6 I-STEP Members communications through Brevo

When an organisation is approved, its main contact may be added to the I-STEP Members communications list managed through Brevo.

The following information may be transferred to Brevo:

  • Email address.
  • First and last name.
  • Professional role.
  • Organisation name and acronym.
  • Organisation type.
  • City and country.
  • Preferred language.
  • Membership status.
  • Public member-profile URL.
  • Membership approval date.
  • Strategic groups.
  • Areas of work.

The list is used exclusively for communications relevant to I-STEP membership and participation in the network, including:

  • News about I-STEP Network.
  • Governance and network-development information.
  • Opportunities relevant to members.
  • Partnership and funding opportunities.
  • Events and meetings.
  • Projects.
  • Resources.
  • Publications.
  • Training.
  • Consultations and participation opportunities.
  • Information about the activities of member organisations.

The I-STEP Members list is not intended to be used as:

  • A public subscription list.
  • A commercial customer database.
  • A prospects database.
  • A list for unrelated third-party advertising.
  • A mailing list for unrelated BACKSLASH communications.
  • A database for selling consultancy or other commercial services.

Brevo acts as a service provider and data processor on behalf of I-STEP Network.

Recipients may unsubscribe from non-essential member bulletins.

Unsubscribing from non-essential member bulletins does not terminate the organisation’s membership.

I-STEP Network may continue sending essential administrative, legal or governance communications that are necessary to administer the membership relationship.

Where an organisation becomes inactive, withdraws or has its membership terminated, its contact may be removed from the active I-STEP Members list.

The server-to-server Brevo integration does not install Brevo Tracker, advertising pixels or Brevo tracking cookies on visitors’ devices.

3.7 Contact forms and enquiries

When a person contacts I-STEP Network, we may process:

  • Name.
  • Email address.
  • Organisation.
  • Professional role.
  • Telephone number, where provided.
  • Message content.
  • Documents or information voluntarily provided.
  • Technical information required to prevent spam or misuse.

This information is used to respond to the enquiry, maintain appropriate correspondence records and take any requested organisational or pre-contractual steps.

Users should not submit special-category personal data, confidential information or information about third parties unless it is necessary and I-STEP Network has specifically requested it.

3.8 Comments and Gravatar

Where comments are enabled, the website collects the information entered in the comment form, together with the visitor’s IP address and browser user-agent information for moderation, security and spam detection.

An anonymised value generated from the email address may be provided to the Gravatar service to determine whether the commenter uses that service.

After a comment is approved, the associated profile picture may appear publicly alongside the comment.

Comments should not contain sensitive personal data or unnecessary information about third parties.

This section does not apply where comments are disabled throughout the website.

3.9 Images, logos and other media

When an organisation uploads a logo, image or document, the file and its technical metadata are processed to manage the relevant membership profile or website content.

Publicly uploaded material may be downloaded by website visitors.

People uploading images should:

  • Remove unnecessary personal information from filenames.
  • Avoid files containing embedded GPS or location information.
  • Ensure that the organisation has the necessary intellectual-property and publication rights.
  • Avoid personal photographs unless the persons depicted have authorised their use.

Visitors may be able to inspect metadata that remains embedded in a publicly accessible file.

3.10 Website accounts

Where website accounts are provided, I-STEP Network may process:

  • Username.
  • Name.
  • Email address.
  • Role and permissions.
  • Password in encrypted or hashed form.
  • Login and security activity.
  • Account-management information.
  • Interface and profile preferences.

Users may update certain profile information through their account.

Some records, including usernames, security logs and administrative information, may be retained where necessary for security, governance, accountability or legal purposes.

3.11 Password resets

When a password reset is requested, the website may process:

  • User account.
  • Email address.
  • Time of request.
  • IP address.
  • Security verification information.

This information is used to authenticate and protect the password-reset process.

4. EMBEDDED CONTENT FROM OTHER WEBSITES

Pages and articles may contain embedded content such as:

  • Videos.
  • Images.
  • Maps.
  • Documents.
  • Social media content.
  • Articles hosted on third-party platforms.

Embedded content may behave as though the visitor had accessed the third-party website directly.

The third party may:

  • Receive the visitor’s IP address.
  • Use cookies or similar technologies.
  • Collect technical or usage information.
  • Monitor interactions with the embedded content.
  • Associate those interactions with a third-party account where the visitor is logged in.

The processing carried out by those third parties is governed by their own privacy policies.

5. PURPOSES AND LEGAL BASES

I-STEP Network processes personal data only where an appropriate legal basis exists.

5.1 Website operation and security

Purposes:

  • Operating, protecting and maintaining the website.
  • Preventing fraud, spam, misuse and unauthorised access.
  • Diagnosing technical faults.
  • Protecting I-STEP Network, its members and website users.

Legal bases:

  • Legitimate interests in maintaining a secure and functional website.
  • Compliance with applicable legal obligations where relevant.

5.2 Membership applications

Purposes:

  • Receiving and assessing applications.
  • Contacting applicant organisations.
  • Requesting clarification.
  • Making and communicating membership decisions.

Legal bases:

  • Steps taken at the applicant’s request before establishing the membership relationship.
  • Legitimate interests in managing the network and assessing alignment with its mission and values.

5.3 Membership administration

Purposes:

  • Maintaining membership records.
  • Managing membership status.
  • Facilitating participation in I-STEP Network.
  • Managing governance and network activities.
  • Maintaining accountability records.

Legal bases:

  • Performance and administration of the membership relationship.
  • Legitimate interests in the governance and proper functioning of the network.
  • Compliance with applicable legal obligations.

5.4 Public member profiles

Purposes:

  • Identifying approved member organisations.
  • Operating the member directory and map.
  • Presenting the composition and expertise of the network.
  • Facilitating cooperation between members and external stakeholders.

Legal bases:

  • The membership relationship and the organisation’s acceptance of the public-profile feature.
  • Legitimate interests in presenting the network and facilitating collaboration.
  • Separate permission for publication of organisation-specific metrics.

5.5 Organisational metrics

Purposes:

  • Measuring the scale, composition and reach of the network.
  • Preparing aggregated statistics.
  • Supporting planning, accountability and institutional communication.
  • Preparing reports, presentations and funding applications.

Legal bases:

  • The membership relationship.
  • Legitimate interests in measuring, managing and communicating the collective activities of I-STEP Network.
  • Separate permission for publishing organisation-specific figures.

5.6 Member communications

Purposes:

  • Sending information relevant to membership.
  • Communicating opportunities, events, projects and resources.
  • Supporting participation in network activities.
  • Communicating administrative and governance matters.

Legal bases:

  • Administration of the membership relationship.
  • Legitimate interests in informing members and facilitating participation in the network.

Recipients may object to or unsubscribe from non-essential member bulletins.

Where a future communication constitutes advertising or commercial promotion rather than genuine membership information, I-STEP Network will apply any additional consent or electronic-communications requirements that may be applicable.

5.7 Enquiries and contact forms

Purposes:

  • Responding to messages and requests.
  • Managing correspondence.
  • Taking requested organisational or pre-contractual steps.

Legal bases:

  • The requester’s initiative.
  • Legitimate interests in responding to correspondence.
  • Consent where expressly requested for an optional purpose.

6. WHO MAY ACCESS OR RECEIVE PERSONAL DATA

Personal data may be accessed or received by:

  • Authorised I-STEP Network administrators.
  • Authorised members of the I-STEP Board.
  • Website-hosting and technical-maintenance providers.
  • Backup, security and spam-prevention providers.
  • Email and communications providers, including Brevo.
  • Professional advisers where necessary.
  • Public authorities, courts or regulators where disclosure is legally required.
  • Other recipients expressly authorised by the person concerned.

Service providers may process data only for the services they provide and under applicable contractual, security and confidentiality obligations.

Information included in public member profiles may be accessed by any website visitor and may be indexed by search engines.

7. INTERNATIONAL DATA TRANSFERS

Some service providers or their subprocessors may process information outside the European Economic Area.

Where a transfer to a third country takes place, I-STEP Network will rely on an appropriate legal mechanism, such as:

  • A European Commission adequacy decision.
  • Standard contractual clauses.
  • Another safeguard permitted by applicable data-protection law.

Information about the relevant safeguards may be requested by contacting office@istep-network.org.

8. HOW LONG WE RETAIN PERSONAL DATA

Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected and for applicable security, governance, accountability and legal requirements.

8.1 Pending applications

Information is retained while the application is assessed and for an appropriate period afterwards to manage enquiries, reconsideration and accountability.

8.2 Rejected applications

Information may be retained for the period necessary to document the decision, respond to disputes and assess a subsequent application. It will then be deleted, anonymised or reduced to a minimal governance record.

8.3 Approved members

Information is retained for the duration of membership and while necessary to administer the relationship and maintain the public profile.

8.4 Inactive, withdrawn or terminated members

The public profile is removed.

A limited administrative record may be retained where necessary for governance, accountability, legal compliance or the management of potential claims.

8.5 Organisational metrics

Current and historical figures may be retained where relevant to reporting and accountability.

Outdated figures may be archived, anonymised or excluded from public statistics.

8.6 Member communications

Contact information is retained while the person remains an authorised contact of a member organisation or until the contact unsubscribes or is removed from the active list.

A minimal record of an opt-out may be retained to ensure that the address is not added again inadvertently.

8.7 Declarations and acknowledgements

Records of accepted membership conditions, privacy information and other declarations may be retained for as long as necessary to demonstrate the lawful and accountable administration of the membership relationship.

8.8 Comments

Comments and associated metadata may be retained while the comment remains published or while needed for moderation, security and accountability.

8.9 Security and technical logs

Logs are retained for a limited period proportionate to security, troubleshooting and legal requirements.

8.10 Website accounts

Account information is retained while the account remains active and afterwards for the time needed to close the account, protect the website and maintain necessary administrative records.

Retention criteria and periods are reviewed periodically.

9. AUTOMATED DECISION-MAKING

I-STEP Network does not use solely automated decision-making to approve or reject membership applications.

Membership decisions are made or reviewed by authorised persons.

Security and spam-prevention systems may automatically identify or restrict suspicious activity. They do not make final membership decisions.

10. YOUR DATA-PROTECTION RIGHTS

Subject to the conditions established by applicable law, individuals may exercise the following rights:

  • Access: obtain confirmation of whether their personal data is being processed and receive access to it.
  • Rectification: correct inaccurate or incomplete information.
  • Erasure: request deletion where there is no continuing lawful basis for retaining the data.
  • Restriction: request that processing be limited in certain circumstances.
  • Objection: object to processing based on legitimate interests, including non-essential member bulletins.
  • Portability: receive relevant data in a structured, commonly used and machine-readable format where applicable.
  • Withdrawal of consent or optional permission: withdraw consent or an optional permission at any time, without affecting processing lawfully carried out before withdrawal.
  • Complaint: lodge a complaint with the competent supervisory authority.

Requests may be sent to:

Email: office@istep-network.org

Postal address:

I-STEP Network

Escorpión 16

Alicante, Spain

I-STEP Network may request reasonable information to verify the identity of the requester. This information will be used only to process and secure the request.

Complaints may be submitted to the competent supervisory authority. Where I-STEP Network is established in Spain, the competent authority is the Spanish Data Protection Agency, AEPD.

11. ACCURACY AND UPDATING OF INFORMATION

Applicant and member organisations are responsible for providing accurate and current information.

Member organisations should inform I-STEP Network when:

  • Their main contact changes.
  • Their legal or public organisational information changes.
  • Their website or social media links change.
  • Their organisational-capacity information changes materially.
  • Their annual-reach information requires updating.
  • Their organisation no longer wishes organisation-specific metrics to be displayed publicly.
  • Their membership circumstances change.

I-STEP Network may request periodic verification of member profiles and organisational metrics.

12. DATA SECURITY

I-STEP Network applies technical and organisational measures intended to protect personal data from:

  • Unauthorised access.
  • Unlawful processing.
  • Accidental loss.
  • Unauthorised alteration.
  • Unlawful disclosure.
  • Destruction or damage.
  • Misuse.

Access to private membership information is restricted according to assigned roles and responsibilities.

No internet-based system can guarantee absolute security. Users should avoid submitting unnecessary sensitive or confidential information through website forms.

13. EXTERNAL LINKS

The website may contain links to websites operated by third parties.

I-STEP Network is not responsible for the privacy practices, content or security of those websites.

Visitors should consult the privacy information provided by each third party.

14. CHANGES TO THIS PRIVACY POLICY

I-STEP Network may update this Privacy Policy where:

  • Website functions change.
  • Service providers change.
  • Membership procedures change.
  • Legal requirements change.
  • New processing activities are introduced.

The current version will be published on this page together with its revision date.

Where a change materially affects member organisations or their contact persons, I-STEP Network may provide an additional notification.

15. CONTACT

Questions, requests or concerns concerning this Privacy Policy or the processing of personal data may be sent to:

I-STEP Network

NGO

Registration number: G27662303

Escorpión 16

Alicante, Spain

Email: office@istep-network.org

Website: https://istep-network.org