This notice explains what happens to personal data on remedies5point0.eu, the website of the Future of Plastic (R)evolution conference (Center Rog, Ljubljana, 7 October 2026), organised under the REMEDIES and REMEDIES 5.0 projects.
The short version: this site is run entirely on infrastructure operated by the project’s technical partner in Trieste, Italy. Nothing you do here is sent to Google, to an analytics company, to an advertising network or to any other third party, and no personal data leaves the European Union. Nothing at all is stored on your device except one cookie used by the site’s own administrators. That is why you are not asked to accept cookies.
Who is responsible for your data
Controller — the body that decides why and how personal data is processed:
Kemijski inštitut (National Institute of Chemistry)
Hajdrihova ulica 19, 1000 Ljubljana, Slovenia
Registration number 5051592000 · Tax number SI 33840890
Telephone +386 1 476 02 00 · glavna.pisarna@ki.si
Represented by Prof. Dr. Gregor Anderluh, Director
The National Institute of Chemistry is the coordinator of the REMEDIES and REMEDIES 5.0 projects and the organiser of the conference.
Data Protection Officer of the controller:
Aljaž Kotar Mlakar
aljaz.kotar.mlakar@ki.si · pooblascenecop@ki.si
Telephone +386 1 476 05 60
Processor — the body that operates this website and the systems behind it, on the controller’s documented instructions and under a data processing agreement pursuant to Art. 28 GDPR:
Infordata Sistemi S.r.l. Società Benefit
Strada per Vienna 55/1, 34151 Trieste (TS), Italy
VAT number IT00933570327
Telephone +39 040 367189 · info@infordata.it · PEC info@pec.infordata.it
Data Protection Officer: Cyber365 S.r.l.s., dpo@cyber365.it
Infordata Sistemi designed, built and maintains this website, hosts it on its own servers in Trieste, operates the visitor statistics, the assistant REMI, the contact form, the mail server that carries your messages and the EventMatic platform used for conference registration. Its information security management system is certified to ISO/IEC 27001, and it is registered with the Italian National Cybersecurity Agency (ACN) as a qualified cloud service provider.
Infordata Sistemi processes personal data only on the instructions of the controller. It does not use it for its own purposes, does not sell it, and does not disclose it to anyone except as instructed or as required by law.
Where to write. For anything concerning this notice or your rights, contact the controller’s Data Protection Officer at the addresses above. You may also write to Infordata Sistemi’s DPO at dpo@cyber365.it; requests received there are forwarded to the controller without delay.
At a glance
| What | Data | Legal basis | Kept for |
|---|---|---|---|
| Web-server logs | IP address, timestamp, page, referrer, user-agent | Legitimate interests, Art. 6(1)(f) | 10 days |
| Visitor statistics | Page, time, referrer, approximate location (country, region, city), browser, operating system, device type, screen size, browser language — no identifier stored on your device | Legitimate interests, Art. 6(1)(f) | 14 months |
| Assistant REMI | The text of your messages; IP address for rate limiting | Legitimate interests, Art. 6(1)(f) | Not retained |
| Contact form / e-mail | Name, e-mail, subject, message | Legitimate interests, Art. 6(1)(f) | Until resolved, then archived for the project’s audit period |
| Conference registration | Registration and attendance details | Contract / legitimate interests; audit records under legal obligation | Audit period of the grant agreements |
What is collected, and why
Web-server logs
Like every web server, ours records each request it receives: your IP address, the date and time, the address of the page requested, the page that referred you and your browser’s user-agent string.
- Purpose — keeping the site running, diagnosing faults, and detecting abuse or attacks.
- Legal basis — legitimate interests, Art. 6(1)(f) GDPR: operating a secure and available website.
- Retention — logs are rotated daily and kept for 10 days, after which they are deleted. Where a log entry forms part of a security incident investigation, it is preserved until that investigation is closed.
Visitor statistics
We count visits so that we know which parts of the conference site are useful, and so that the project can report how widely its results were disseminated — a reporting obligation towards the European Commission that both grant agreements impose.
This is done with Umami, an open-source analytics tool running on our own server in Trieste. The figures are not sent to Google Analytics or to any other analytics company, and they are not combined with data from any other website.
- What is recorded — the page you viewed, the time, the website that referred you (if any), your approximate location derived from your IP address (country, region and city), and your browser, operating system, device type, screen size and preferred browser language.
- What is not recorded — nothing is written to your device: no cookie, no local-storage entry, no advertising identifier, no browser fingerprint. The counting script reads a single local-storage key,
umami.disabled, to check whether you have switched the counting off; it never writes that key, so unless you have deliberately set it yourself it is simply not there. To recognise that several page views belong to one visit, your IP address and browser string are converted into a short code using a secret that changes every day; the IP address itself is not kept, and once the secret changes, yesterday’s visits can no longer be linked to today’s. - Purpose — understanding how the site is used, and reporting dissemination figures for an EU-funded project.
- Legal basis — legitimate interests, Art. 6(1)(f) GDPR: measuring the reach of our own website in a way that neither identifies you nor follows you elsewhere. We consider your interests are not overridden because the measurement is limited to this one site, stores nothing on your device, and produces statistics rather than profiles.
- Retention — 14 months, after which the underlying records are deleted. Aggregate totals that contain no individual visit records may be kept for project reporting.
Because this measurement stores nothing at all on your device, it does not require consent — see Cookies below.
Assistant REMI
REMI is the assistant available on every page. It answers only from this site’s published conference information.
REMI runs on the project’s own infrastructure. The language model behind it is an open-weights model installed on Infordata Sistemi’s servers in Trieste. What you type is processed inside that perimeter and is not sent to Google, OpenAI, Anthropic or any other external AI provider. It is not used to train, fine-tune or otherwise improve any model, and no human reads it.
When you send REMI a message:
- the text of your message, and the earlier messages in that same conversation, are held in the server’s working memory for as long as it takes to produce an answer;
- your IP address is used solely to enforce a short rate limit. It is held in the server’s working memory, is never written to disk, and is discarded when the service restarts;
- your conversations are not stored. REMI has no account, no login and builds no profile of you. Closing the window ends the conversation on our side.
- Purpose — answering visitors’ questions about the conference.
- Legal basis — legitimate interests, Art. 6(1)(f) GDPR: providing information to people interested in the event. Using the assistant is entirely optional; every piece of information REMI gives is also available in the ordinary pages of this site.
- Retention — nothing is retained.
Even so, please do not type personal details into REMI — your name, contact details, accessibility needs, or information about anyone else. REMI cannot act on them, and they will simply be discarded. If you need to tell the organisers something personal, use the contact form or the e-mail addresses below, where your message reaches a person.
Conference registration
Registration is handled through EventMatic, an event management platform operated by Infordata Sistemi S.r.l. Società Benefit — the same technical partner that runs this website — and hosted on the same infrastructure in Italy.
EventMatic acts as a processor for this conference: the National Institute of Chemistry, as organiser, decides what is collected and why, and Infordata Sistemi processes it on that instruction under the Art. 28 agreement described above. EventMatic does not use your registration data for its own purposes and does not share it with other customers of the platform.
- What is collected — the details shown on the registration form at the moment you fill it in, typically your name, e-mail address, organisation and role, together with any practical choices you make (sessions, catering or accessibility requirements).
- Purpose — registering you for the conference, sending you practical information about it, managing access on the day, and evidencing participation to the funding authority.
- Legal basis — Art. 6(1)(b) GDPR for the steps needed to register you and admit you to the event; Art. 6(1)(f) for keeping and reporting attendance figures; Art. 6(1)(c) where the grant agreements require records to be retained for audit.
- Retention — registration and attendance records are kept for the record-keeping period the Horizon Europe grant agreements impose, which runs until five years after payment of the balance of the project. They are then deleted.
If you tell us about a dietary requirement or an accessibility need, that information is used only to make the arrangement you asked for, is seen only by the organising team members who need it, and is deleted after the event.
Contacting the organisers
You can reach us by writing to the e-mail addresses published on this site, or by using the contact form. Either way, your message and your contact details are processed so that we can reply to you.
When you use the contact form, the name, e-mail address, subject and message you type are sent to our server and forwarded as an e-mail to the organising team’s mailbox. The form does not store your message in a database on this website, and it does not set any cookie. Your IP address is held in the server’s memory for a few minutes only, to stop the form being abused to send bulk mail; it is not written into the message and is not kept afterwards.
- What is collected — your name, e-mail address, the subject line and the text of your message.
- Purpose — reading and answering your enquiry.
- Legal basis — legitimate interests, Art. 6(1)(f) GDPR: responding to enquiries addressed to us.
- Who it reaches — the conference organising team. The message is carried by a mail server operated by Infordata Sistemi in Italy. No external mail provider — Google, Microsoft or otherwise — is involved in delivering it.
- Retention — until your enquiry has been dealt with; correspondence that documents a project activity is then archived for the audit period of the grant agreements and deleted afterwards.
What is not collected
This site carries no tracking pixels, no advertising and no social-media trackers. It does not profile you and makes no automated decisions about you. Fonts are served from our own server rather than from a font network, and there are no embedded maps, videos or social widgets, so reading these pages does not report your visit to any advertising or social network. The visitor counting described above runs on our own server and never follows you to another website.
We do not ask for, and have no use for, any special category of personal data (Art. 9 GDPR). Please do not send us any.
Cookies
This website sets one cookie, and only for the site’s administrators:
remedies_preview— set only when an administrator opens the site with a preview key, so that the team can review finished pages while the site is still behind its “under construction” screen. It lasts 30 days, cannot be read by JavaScript, and is not used to identify or track anyone.
Because that cookie is strictly necessary to provide a service the user has expressly requested, it is exempt from the consent requirement in Art. 5(3) of the ePrivacy Directive 2002/58/EC, as transposed in Slovenia by Art. 225 of the Electronic Communications Act (ZEKom-2).
Why there is no cookie banner. Consent is required for storing information on your device or reading information already stored there. Our visitor counting writes nothing to your device — no cookie, no local-storage entry, no fingerprint — and the one local-storage key it reads (umami.disabled) is an opt-out switch that is only ever there because you put it there, which is strictly necessary on exactly the same ground as the cookie above. There are no advertising, marketing or profiling cookies of any kind. With nothing to consent to, a banner would ask you to agree to something that is not happening, while putting an obstacle in the way of people using a keyboard or a screen reader. If that ever changes, this notice will be updated and consent will be asked for properly, before anything is set.
Who your data is shared with
Your data is handled by the controller and by its processor, and by nobody else:
- Infordata Sistemi S.r.l. Società Benefit (Trieste, Italy) — website development and maintenance, hosting, visitor statistics, the assistant REMI, the mail server, and the EventMatic registration platform. Acts only on the controller’s instructions under an Art. 28 GDPR data processing agreement.
There is no analytics company on this list, no advertising network, no AI provider and no external mail provider — because none of them receives your data.
Your data is not sold, rented, or used for advertising. It is not shared with anyone else except where we are legally required to disclose it, or where a national or European audit body exercises its right to inspect project records.
Transfers outside the EU/EEA
There are none. All the processing described in this notice takes place on servers located in Italy, within the European Union. No personal data collected through this website is transferred to a country outside the EU/EEA or to an international organisation.
Should that ever change — for example if a service hosted outside the EEA were added — this notice will be updated before the change goes live, and the transfer safeguard relied on (adequacy decision, standard contractual clauses, or another Chapter V instrument) will be named here.
Your rights
Under Articles 15 to 22 GDPR you have the right to ask for access to your personal data, its correction or erasure, the restriction of its processing, and its portability; and, because most of the processing described here rests on legitimate interests, you have the right to object to it at any time.
Where we rely on legitimate interests, an objection means we stop the processing unless we can demonstrate compelling legitimate grounds that override your interests. In practice, for the statistics and the assistant there is nothing to weigh: the processing simply stops.
In practice, because this site stores almost nothing — no accounts, no conversation history, no tracking — there is usually very little data to give you. Server-log entries can normally only be located if you can tell us your IP address and roughly when you visited.
To exercise any of these rights, write to the controller’s Data Protection Officer at the address at the top of this notice. Exercising them costs you nothing, and we will answer within one month, extendable by two further months for complex requests, in which case we will tell you why.
Complaints
If you believe your data has been handled unlawfully you may lodge a complaint with a supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si — or with the supervisory authority of the EU country where you live or work.
Changes to this notice
If the way this site handles data changes — for example if an embedded map, a newsletter or an externally hosted service were added — this notice will be updated before the change goes live.
Version 1.0 · Last updated: 2 September 2026