GDPR & Data Processing
These terms describe how MobilityCloud is provided and how project, billing, participant, document and mobility evidence workflows are handled. MobilityCloud is powered by Xeotype.
1. Scope of this Data Processing Summary
This page explains the intended GDPR and data-processing position for MobilityCloud. It is designed to help users, partners, participants and automated agents understand the main roles, data flows and responsibilities around the platform.
2. Controller and processor roles
XEOTYPE SRL operates MobilityCloud and generally acts as controller for account administration, billing, security, product operations, platform support, audit logs and legal compliance.
For project content, participant records, uploaded evidence, dissemination materials, partner data and documents entered by a user, the project owner is usually the organisation deciding why and how that data is processed. In those cases, XEOTYPE SRL may act as a platform provider and processor, processing the data according to the project owner’s instructions and the functional choices made inside MobilityCloud.
Some situations may involve independent controller responsibilities, joint responsibilities or processor relationships depending on the customer type, contract, grant agreement, participant context and applicable law. Users remain responsible for obtaining their own advice where necessary.
3. Processing instructions
MobilityCloud processes project and participant content only to provide the platform, including authentication, project access, collaboration, participant intake links, document handling, mobility evidence, budgets, exports, final archive preparation, support, backup, security and administrative functionality.
- Project owners decide what project data is entered, which collaborators are invited and which participant fields are collected.
- Collaborators should only access projects and modules for which they have a legitimate project role.
- MobilityCloud may process logs, metadata and support context to keep the service secure and reliable.
- MobilityCloud may refuse instructions that appear unlawful, unsafe, technically impossible or incompatible with platform security.
4. Data categories and data subjects
Depending on how a project is configured, MobilityCloud may process:
- user and collaborator data, including names, emails, roles, verification status, session activity and administrative notes;
- billing data, including legal entity details, tax identifiers, invoice status, approved grant values and payment state;
- project data, including application text, language settings, budgets, tasks, activities, documents, generated files and final reporting materials;
- participant data, including complete name, organisation, email, phone, mobility details, optional identification files, notes and participant intake submissions;
- evidence data, including photos, links, videos, materials, outputs, dissemination records, receipts and supporting files;
- technical data, including IP addresses, audit trails, device/browser metadata, error logs and security events.
Data subjects may include account users, project owners, collaborators, participants, facilitators, partner organisation representatives, suppliers, trainers, volunteers, support contacts and invoice contacts.
5. Subprocessors and service providers
MobilityCloud may use carefully selected providers for hosting, server infrastructure, email delivery, storage, backups, security monitoring, error logging, support communication and professional services. These providers are used only to the extent necessary to operate, secure, support and improve the platform.
A current subprocessor list or provider summary can be requested from contact@xeotype.com. Where legally required, MobilityCloud will take reasonable steps to ensure appropriate contractual protections with subprocessors.
MobilityCloud does not sell project data, participant data or account data.
6. Security measures
MobilityCloud applies technical and organisational measures appropriate for a hosted project platform, including individual accounts, email verification, role-based project access, controlled file delivery, HTTPS, server firewalling, backup practices, administrative separation, audit logs, password hashing and operational monitoring.
Users must also maintain security on their side: strong passwords, secure devices, careful sharing of participant intake links, removal of old collaborators and avoidance of unnecessary sensitive uploads.
7. Assistance with data subject rights
Where MobilityCloud acts as processor for project data, it will reasonably assist the relevant project owner with access, rectification, deletion, restriction, portability, objection or consent-withdrawal requests, taking account of the nature of the processing and the information available to MobilityCloud.
Requests about account, billing or platform-administration data can be sent directly to contact@xeotype.com. Requests about participant or project content may need to be handled by the project owner as the primary organisation responsible for that data.
8. International transfers
MobilityCloud aims to use European infrastructure where practicable. If a provider processes personal data outside the European Economic Area, appropriate safeguards should be used where required by GDPR or other applicable law, such as contractual protections, transfer mechanisms, risk assessment and supplementary measures where necessary.
9. Retention, return and deletion
- Project data is retained while the project is active or until deletion is requested and permitted.
- Billing and invoice records may be retained for statutory tax and accounting periods.
- Security, audit and system logs may be retained for abuse prevention, troubleshooting, incident investigation and legal proof.
- Backups may contain deleted data for a limited period until normal backup rotation removes it.
- Where feasible, project owners can export or download relevant project files before deletion.
10. Personal data breach assistance
If MobilityCloud becomes aware of a suspected personal data breach affecting project data, it will assess the situation, take reasonable containment steps, preserve relevant information and notify affected project owners or users where legally required or operationally appropriate.
Project owners are responsible for assessing their own notification obligations toward participants, partners, funders, National Agencies or supervisory authorities where they act as controller.
11. Project owner responsibilities
Project owners must ensure that their use of MobilityCloud is lawful. This includes providing privacy notices, choosing appropriate participant fields, avoiding unnecessary sensitive data, obtaining consent where required, respecting image rights and copyright, controlling collaborator access, and complying with Erasmus+, employment, child protection, accounting and data-protection obligations that apply to their organisation.
Company details
Legal review note
These documents are prepared as launch-ready platform policies. Because legal requirements can depend on the exact customer type, data flows, payment model, processors and jurisdictions involved, XEOTYPE SRL should periodically review them with qualified legal counsel.