Privacy & GDPR

Privacy policy

How ATTIMAR S.A. OÜ collects, uses and protects your personal data under the EU General Data Protection Regulation.

Last updated 13 August 2026 · ATTIMAR S.A. OÜ, registry code 16584720

1. Who we are

ATTIMAR S.A. OÜ (registry code 16584720, registered in Harju maakond, Tallinn, Estonia) is the data controller for personal data processed through this website and the student portal.

You can contact our data protection contact at privacy@attimar.eu. Because we are established in Estonia, our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

The scientific patronage of IUL — Università Telematica degli Studi does not make the university a controller or processor of your data. No student personal data is transferred to IUL except aggregated, non-identifying programme statistics for annual patronage review.

2. What we collect

Data you provide

  • Identity and contact data: name, email address, country, organisation
  • Application data: qualifications, motivation statement, cohort preference, bursary requests
  • Payment data: billing details and VAT identifiers (card data is handled by our payment processor and never reaches our servers)
  • Assessment data: quiz responses, capstone submissions, examination answers and results
  • Correspondence: messages you send to any of our published addresses

Data collected automatically

  • Portal usage: lessons opened, completion markers, resource downloads
  • Technical data: IP address, browser type, device category and preferred language
  • Examination integrity data: webcam and screen recording during supervised examinations only

3. Why we process it, and on what basis

We process your data on four legal bases under Article 6 GDPR.

  • Contract — to deliver the programme you enrolled in, assess your work, and issue your certificate
  • Legal obligation — to retain invoices and accounting records as required by Estonian and EU tax law
  • Legitimate interests — to secure our systems, prevent examination fraud, and improve course content using aggregated analytics
  • Consent — for optional marketing emails and for alumni directory inclusion, both withdrawable at any time

4. How long we keep it

  • Application data from unsuccessful or withdrawn applications: 12 months
  • Enrolment, assessment and certification records: 10 years, so that certificates remain verifiable
  • Examination recordings: 90 days after the result is confirmed, then permanently deleted
  • Invoices and accounting records: 7 years, as required by Estonian law
  • Marketing consent records: until withdrawal, plus 24 months to evidence the withdrawal

5. Who we share it with

We do not sell personal data, and we do not share it with advertisers or data brokers. We use a small number of processors, each bound by a data processing agreement under Article 28 GDPR:

  • EU-based cloud hosting for the website, portal and video delivery
  • An EU payment services provider for card and SEPA transactions
  • An EU transactional email provider for portal notifications
  • An examination proctoring provider processing data exclusively within the EEA

All processing takes place within the European Economic Area. Where a processor requires any transfer outside the EEA, it occurs only under Standard Contractual Clauses with a documented transfer impact assessment.

6. Your rights

Under GDPR you have the right to access your data, correct inaccuracies, request erasure, restrict or object to processing, receive your data in a portable format, and withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, email privacy@attimar.eu. We respond within one month, and we do not charge a fee unless a request is manifestly excessive.

Note that erasure of assessment records will invalidate your certificate, since verification depends on those records. We will tell you clearly before acting on such a request.

7. Cookies

This site uses strictly necessary cookies only: a session cookie for portal authentication and a preference cookie storing your cookie choices. We do not use advertising, profiling or cross-site tracking cookies, and therefore we do not show a consent banner for them.

Aggregate traffic statistics are collected in a cookieless, IP-anonymised manner that cannot identify individual visitors.

8. Security

Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to student records is limited to staff who need it, and every access is logged. We test our systems annually and maintain a documented breach response procedure.

In the event of a personal data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected individuals without undue delay.

Questions about this document? Write to legal@attimar.eu and we will respond within five working days.