Privacy Policy
These terms describe how MobilityCloud is provided and how project, billing, participant, document and mobility evidence workflows are handled. MobilityCloud is powered by Xeotype.
1. Controller and contact
XEOTYPE SRL operates MobilityCloud and acts as data controller for account, billing, platform administration and support data. In some project contexts, the project owner may also act as an independent controller for participant and project data entered into the platform.
For privacy requests, contact contact@xeotype.com or contact@mobilitycloud.eu.
2. Categories of personal data
- Account data: name, email, password hash, verification status, role, language or interface preferences.
- Billing data: legal billing name, address, country, tax/VAT identifiers, invoice status and payment records.
- Project data: project names, application text, budgets, tasks, collaborators, partner organisations, project settings and activity logs.
- Participant data: complete name, organisation, email, phone, country, travel or mobility information, optional identification documents and related forms where uploaded.
- Files and evidence: documents, signed copies, receipts, photos, materials, dissemination evidence, links, comments and metadata.
- Technical data: IP address, device/browser information, login/session logs, audit logs, error logs, security events and email delivery events.
- Support data: messages, requests, administrative notes and communications needed to resolve issues.
3. Purposes and legal bases
MobilityCloud processes personal data only where there is a valid purpose and legal basis, including:
- contract performance: creating accounts, authenticating users, providing project management features, exports, files and collaboration;
- legitimate interests: platform security, fraud prevention, audit logs, product reliability, support, abuse prevention and service improvement;
- legal obligations: invoicing, tax, accounting, legal retention and compliance requests;
- consent, where required: optional communications, optional cookies, or specific participant data processing arranged by the project owner;
- public interest or contractual project obligations, where applicable to the project owner’s Erasmus+ or grant-management activity.
4. Participant data and partner organisations
Project owners are responsible for ensuring that participants and partner organisations receive appropriate privacy information before their data is entered into MobilityCloud. This includes data collected through participant registration links, manual entry, CSV import, uploaded files or mobility evidence.
Where participant data includes minors, sensitive details, identification documents, images or special categories of data, the project owner must ensure that the processing is lawful, proportionate, necessary and supported by the correct notices, consents or other legal basis.
6. Retention and deletion
- Account data is retained while the account is active and for a reasonable period after closure where needed for security, billing or legal reasons.
- Invoice and accounting records may be retained for statutory accounting and tax periods.
- Project files are retained while the project is active or until deletion is requested and permitted.
- Audit, security and access logs may be retained to investigate misuse, protect the service and prove administrative actions.
- Backups may retain deleted data temporarily until backup rotation removes it.
7. Data subject rights
Depending on applicable law and the context of processing, individuals may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority.
Requests can be sent to contact@xeotype.com. MobilityCloud may need to verify identity and may refer project-specific participant requests to the relevant project owner when that owner controls the data.
Individuals in Romania may also contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
8. Security, incidents and automated decisions
MobilityCloud uses technical and organisational measures such as authenticated access, role-based permissions, HTTPS, private file delivery, server firewalling, backups, audit trails and administrative access controls.
No system can be guaranteed perfectly secure. Suspected incidents should be reported immediately to contact@mobilitycloud.eu. Where legally required, MobilityCloud will assess and handle breach notification obligations.
MobilityCloud does not use personal data for decisions that produce legal or similarly significant effects solely by automated means.
Company details
Legal review note
These documents are prepared as launch-ready platform policies. Because legal requirements can depend on the exact customer type, data flows, payment model, processors and jurisdictions involved, XEOTYPE SRL should periodically review them with qualified legal counsel.