Privacy Policy
This policy describes how IPTICAR collects, uses, retains and protects your personal data when you use the ipticar.dz portal. It is established in accordance with Regulation (EU) 2016/679 (GDPR), Algerian Law No. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, and implementing texts of the National Authority for the Protection of Personal Data (ANPDP).
Last updated: 9 July 2026
1. Data controller
The data controller for personal data collected via the IPTICAR Platform is the Ministry of Higher Education and Scientific Research (MESRS) of the People's Democratic Republic of Algeria, acting within the IPTICAR project.
Contact for data protection requests: contact@ipticar.dz. A Data Protection Officer (DPO) may be appointed; where applicable, their contact details will be published on this page.
2. Scope
This policy applies to processing carried out via the ipticar.dz website, the api.ipticar.dz API, registration and contact forms, authenticated spaces (dashboards) and communications related to the project.
It does not cover third-party websites accessible via external links (MESRS, Expertise France, EU programmes, social networks), which are subject to their own policies.
3. Legal bases for processing
In accordance with the GDPR and Law 18-07, your data is processed on the following bases:
- Performance of a contract or pre-contractual measures: creating and managing your Account, authentication, providing Platform services.
- Consent: newsletter subscription, marketing communications, and processing of academic profile data declared at registration (mandatory checkbox). You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legitimate interest: Platform security, fraud prevention, service improvement, aggregated and anonymised statistics, handling support requests.
- Legal obligation: retention of certain data to meet accounting, administrative or judicial requirements applicable to the EU-funded project.
4. Data collected
Depending on your use of the Platform, we may process the following categories of data:
- Identification data: surname, first name, email address, phone number (optional), LinkedIn URL (optional).
- Institutional data: country, university, faculty, academic or professional roles.
- Academic profile data: scientific domains, expertise (tags), European themes, participation in EU projects, programmes mobilised, experience level, registration reasons, priority needs.
- Connection and technical data: session identifiers (httpOnly cookies), last login date, server logs (IP address, timestamp, user-agent), error data if Sentry monitoring is enabled.
- Communication data: support request messages (tickets) and any attachments; contact form content when operational.
- Preferences: GDPR consent (gdpr_consent), newsletter subscription (is_subscribed), favourite opportunities.
5. Purposes of processing
Your data is processed for the following purposes:
- Enabling registration, authentication and Account management;
- Personalising your experience and facilitating networking within the academic community;
- Disseminating relevant opportunities, events, resources and news;
- Managing editorial contributions and content moderation;
- Handling your support requests and providing user assistance;
- Sending communications about the IPTICAR project, subject to your consent for the newsletter;
- Ensuring security, maintenance and technical improvement of the Platform;
- Producing aggregated reports for reporting obligations of the EU-funded twinning project.
6. Cookies and similar technologies
The Platform uses cookies and local storage strictly necessary for the Service to function:
- ipticar_access, ipticar_refresh, ipticar_session: authentication cookies (httpOnly, SameSite=Lax), limited duration (30 minutes for access, 30 days for refresh).
- sidebar_state: dashboard sidebar display preference (7 days), stored in the browser.
- Form drafts (localStorage): reserved for dashboard users for content drafting, on the local device only.
- Sentry (where enabled): technical error monitoring in production with limited sampling; no advertising cookies are placed.
7. Processors and recipients
Your data may be disclosed to the following categories of recipients, to the extent necessary for their missions:
- Authorised IPTICAR and MESRS project teams (administration, moderation, support);
- Consortium partners (Expertise France, Fondazione PIN, Spider) for twinning project activities;
- Hosting and technical infrastructure provider for the Platform (servers, databases);
- Backend API service (api.ipticar.dz) handling storage and processing of user accounts;
- Sentry (Functional Software, Inc.) — only if enabled in production for technical error monitoring (limited sampling);
- Public authorities when required by law.
8. International transfers
Within the twinning project, certain data may be accessible to partners located in the European Union (France, Italy, Sweden). These transfers are governed by safeguards under Law 18-07 and, where applicable, the European Commission's standard contractual clauses or other mechanisms recognised by the GDPR.
Any transfer of personal data outside Algeria to a country not offering an adequate level of protection is subject to ANPDP requirements, including obtaining authorisation where required by Algerian regulation.
9. Retention periods
Data is retained for periods proportionate to the purposes:
- Active Account data: for the duration of use of the Service, then deletion or anonymisation within 3 years of last activity, unless otherwise required.
- Consent data (GDPR, newsletter): proof of consent retained for the duration of processing and up to 5 years after withdrawal, in line with evidence recommendations.
- Technical and security logs: up to 12 months, unless an incident requires longer retention.
- EU project reporting data: duration required by EU funding contractual obligations, then archiving or deletion.
- Rights requests: retention of the request and response for the applicable limitation period.
10. Security
IPTICAR implements appropriate technical and organisational measures: encrypted communications (HTTPS/TLS), httpOnly authentication cookies, content security policy (CSP), role-based access control, server-side hashed passwords, backups and infrastructure monitoring.
No method of transmission or storage is completely infallible; in the event of a data breach likely to pose a risk to your rights, we will notify the competent authorities and, where required, affected individuals within legal time limits.
11. Your rights
Under the GDPR and Algerian Law 18-07, you have the following rights, subject to conditions and limits provided by law:
- Right of access: obtain confirmation that your data is processed and receive a copy;
- Right to rectification: have inaccurate or incomplete data corrected;
- Right to erasure (“right to be forgotten”): request deletion of your data, subject to legal retention obligations;
- Right to restriction of processing;
- Right to object to processing based on legitimate interest or for direct marketing;
- Right to data portability for data you have provided, where processing is automated and based on consent or contract;
- Right to withdraw consent at any time for processing that relies on it.
12. Exercising rights and complaints
To exercise your rights, send a request to contact@ipticar.dz stating the subject of your request and, if necessary, a copy of proof of identity. We will respond within one month, extendable by two months in complex cases.
If you believe your rights are not respected, you may lodge a complaint with the National Authority for the Protection of Personal Data (ANPDP) in Algeria, or with the supervisory authority in your country of residence in the European Union if the GDPR applies to your situation.
13. Marketing communications
Newsletter subscription is optional. You may unsubscribe at any time via the link provided in emails or by contacting contact@ipticar.dz.
Withdrawing consent to the newsletter does not affect emails strictly necessary for Account management.
14. Minors
The Platform is not intended for children under 16. If you become aware that a minor has provided personal data without parental authorisation, please contact us so that we can take appropriate measures.
15. Changes
This policy may be updated to reflect changes in the Service, regulation or project practices. The last updated date appears at the top of the page. We encourage you to review it regularly.
In the event of a substantial change affecting your rights, we may inform you by email or via a notice on the Platform.
