TRUST Website
  • Project
  • Use Cases
  • Partners
  • Results & Resources
  • Blog
  • Events
  • Contact
  • Project
  • Use Cases
  • Partners
  • Results & Resources
  • Blog
  • Events
  • Contact
Home > Privacy & Cookies Policy

Privacy & Cookies Policy

On this page

  • Privacy Policy
  • Data Controller
  • EU Representative
  • What Personal Data Is Collected
  • Legal Grounds for Data Processing Activities
  • Purpose and Use of Collected Information
  • How Data Can Be Collected
  • Principles when Processing Personal Data
  • Policy Towards Children
  • Data Storage and Retention Period
  • Recipients, Sharing and Transfer of Information
  • Security
  • Data Subject Rights
  • Information on Data Processing
  • Changes to this Policy
  • Cookies Policy
  • What Are Cookies?
  • What Cookies Do We Use and For What Purpose?
  • International Data Transfers
  • Social Media

Privacy Policy

This Privacy and Data Protection Policy describes how Mandat International, the Data Controller of this website, collects and processes personal data, for what purposes and, if applicable, to whom it discloses it. Furthermore, this Policy provides information which rights the data subjects are entitled to in order to provide and enforce personal data protection.

By operating this website https://thetrustproject.eu (hereinafter referred to as “website”), Mandat International (hereinafter “Mandat International”, “we”, “us”, “our”) processes personal data. Our services include, inter alia, website, online and onsite services, and other communication activities, as well as events and activities related to its aims. Mandat International treats personal data confidentially and processes it in accordance with the applicable laws, in particular the European General Data Protection Regulation (GDPR).

Data Controller

Mandat International
15 avenue de Sécheron
1202 Geneva
Switzerland

EU Representative

European Centre for Certification and Privacy (ECCP)

22 Boulevard des Scillas

L-2529 Howald – Luxembourg

Contact Details: If you have any questions about this policy or your privacy on the Services, you can contact our Data Protection Officer either through our contact form or via sending an email to trust@mandint.org

Effective date: This policy takes effect on 03.08.2026.

What Personal Data Is Collected

Personal data means any information relating to an identified or identifiable person (data subject), Article 4(1) GDPR. Information about an identified person can be, for example, name or email address. Personal data is also such data that allows a conclusion to be drawn about a person and thus finding out who they are, for example, by providing their address or bank details, date of birth or username, IP addresses and/or location data. This does not include data where the identity has been removed (anonymised data).

In order to provide its services, Mandat International collects general personal data such as:

  • Name;
  • Email address;
  • Other Personal Data that the user voluntarily shares with the Controller through established means of communication (emails, Contact Forms, Telephone etc.)
  • Technical Data, which includes Internet Protocol (IP), browser type and version, time zone settings and location, browser plug-in types and versions, operating system and platform, and other technology on users’ terminal devices to access the website. These queries to the website are recorded in the web server logs.
    Our website uses the log analyser AWStats to evaluate the log files. The IP addresses of website visitors are pseudonymised in our logfiles. AWStats does not use HTTP cookies or JavaScript code from the visitors’ browsers. These data (log files) cannot be assigned to specific persons and these data will not be combined with other data sources. The program is installed on the own hosting package and does not transmit data to foreign servers.

We use AWStats to compare website visits to expected Key Performance Indicator (KPI) in terms of dissemination. This helps us to compile reports on website activity in order to improve our website functionalities and services.

Please find more information about AWStats on their website: https://awstats.sourceforge.io.

Legal Grounds for Data Processing Activities

Our Data Processing Activities are based upon the following legal bases:

  1. Consent (Article 6.1 (a) GDPR): When the user shares personal data through the contact form or any other communication means.
  2. Legitimate Interest (Article 6.1 (f) GDPR): We are using technical data- that might capture personal data such as IP addresses to secure our website, prevent fraud, and improve user experience.

Purpose and Use of Collected Information

Mandat International processes personal data for the purposes of its aims, activities, and services, including:

  • Facilitating access to information, resources, tools, events and service providers;
  • Communication with users via Contact Form;
  • Improving users’ experience and the quality of delivered services;
  • Authenticating, securing, and collecting statistics on remote connections;
  • Marketing and Direct Communication, such as Sending newsletters, project updates, and informational material;
  • Managing registrations and logistics for project-related events and webinars.

How Data Can Be Collected

Mandat International can receive information and personal data through its websites, email notifications and other interactions means, and may include:

  • Information provided by the users when using our services;
  • Information provided by users’ devices for connectivity, such as IP address, etc. Such data may be logged for security and statistical reasons;
  • Cookies and similar technologies, whose use is voluntarily limited and minimised on our website.

Principles when Processing Personal Data

When Processing Personal Data, the Controller ensures that these principles are implemented in order to be compliant by design:

  • The Controller avoids collecting unnecessary personal data and if such data end up in its possession, the Controller takes adequate measures to delete, anonymize or remove them (Data Minimization Principle).
  • The Controller takes reasonable steps to ensure that the information collected or provided by the data subjects is accurate and up to date (Data Accuracy Principle).
  • The Controller ensures that each data processing activity is grounded upon a valid legal basis. In the event of absence of such grounds, the Controller will not perform the relevant processing activities (Lawfulness Principle).
  • Each Data Processing activity is strictly performed in accordance with a specified, explicit, and legitimate purpose, and no further processing in a manner that is incompatible with this purpose occurs (Purpose Limitation Principle).

Policy Towards Children

Our Services are strictly designed for professionals and are not directed at or intended for individuals under the age of 16. We do not knowingly collect or solicit personal data from anyone under 16. If we become aware that we have collected personal data from a child under the age of 16, we will take immediate steps to delete that information from our servers. If you believe that we might have any information from or about a child under 16, please contact us immediately at trust@mandint.org

Data Storage and Retention Period

Our Servers are located in Europe. Each personal data transfer from the European Servers to the Controller (established in Switzerland) is covered by Commission’s adequacy Decision 2000/518/EC as updated with the 15.01.2024 report.

The data retention period is minimised and combatible with the purposes under which the personal data were initially collected. Data that are no longer useful anymore are deleted or anonymised. The data retention period differs per data category and is established by taking into account legal, security, management, and other legitimate service requirements. Where data subject withdraws consent or request the deletion of their data, Mandat International will proceed accordingly. Nevertheless, where applicable, some personal data may be kept by us even after consent has been withdrawn if required by a legitimate purpose such as:

  • Legal and administrative obligations;
  • Documenting and archiving delivered services;
  • Potential legal claims.

Recipients, Sharing and Transfer of Information

Personal data are processed with care, and strict rules are applied to avoid any unnecessary data transfers to third parties or countries that may expose data at risk. The Controller may share personal data in the following cases:

  1. With Its Partners and Deployed Data Processors: The list of Partners are available in the partners section. The list of data processors is available upon simple request to the data protection officer. The Controller ensures that every processor and partner abides by the same legal obligations as the obligations included in this Privacy Notice.

In order to provide our services and secure our website, we may occasionally use trusted third-party service providers located outside the EEA and Switzerland, specifically in the United States (e.g., for website security or media hosting). When your personal data (such as technical data or IP addresses) is transferred to such third countries, we ensure that appropriate legal safeguards are in place. We strictly rely on:

  • Adequacy Decisions: We transfer data to US companies that are certified under the EU-US Data Privacy Framework (DPF) and the Swiss-US Data Privacy Framework, which guarantees a level of protection equivalent to European standards.
  • Standard Contractual Clauses (SCCs): In cases where a provider is not certified under the DPF, we rely on the Standard Contractual Clauses approved by the European Commission, along with any necessary supplementary measures, to ensure your data remains secure.

More information can be found in the Cookies Policy.

  1. When required by law or for legitimate purposes, such as protecting the legal rights and safety of the Controller, its partners, and the users of its services.

Security

Mandat International uses physical, technical, and administrative measures to safeguard information in its possession against loss, theft and unauthorised use, disclosure, or modification. Please note, however, that no data transmission or storage can be guaranteed to be 100% secure. As a result, while Mandat International strives to protect the information it processes, this should not be taken as a warranty. If you identify any weakness in our security, please inform us immediately.

Data Subject Rights

The Controller commits itself to respect the Users’ (Data Subjects) rights to the highest possible degree. Data Subjects have the following rights:

  • The right to access their data.
  • The right to rectify (correct) inaccurate data.
  • The right to erasure (the “right to be forgotten”).
  • The right to restrict processing.
  • The right to data portability.
  • The right to object to processing.
  • The right to withdraw consent at any time.
  • The right to lodge a complaint with a supervisory authority. As the Controller is based in Switzerland, our lead supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), available at https://www.edoeb.admin.ch/en. Data subjects have the right to lodge a complaint with their local Data Protection Authority (DPA) in their country of residence.

Data Subjects seeking to exercise their privacy rights, or requiring guidance regarding these procedures, are encouraged to direct their inquiries to our designated Data Protection Officer at the email provided in the contact information section.

Information on Data Processing

Mandat International does not use the personal data collected on this website to perform automated decision making (as defined in Art. 22 of the GDPR) or to profile the data subjects.

Changes to this Policy

Mandat International may revise this Privacy Policy from time to time and make changes at its sole discretion. The most current version of the policy will govern our use of processed information and will be available on the TRUST website: https://thetrustproject.eu By continuing to access or use the Services after those changes become effective, you agree to be bound by the revised Privacy Policy.

Cookies Policy

What Are Cookies?

Cookies are small data files that are stored on the user’s terminal device when visiting a website. These text files can be set either by the website they are currently visiting (“first-party cookies”) or by a different website (“third-party cookies”). Cookies enable the recognition of a terminal device and possibly certain functions of a website.

What Cookies Do We Use and For What Purpose?

This website minimises the use of cookies. We only use cookies that are required for a smooth user experience and for securing navigation within the website. For the most part, we only use so-called “session cookies”. These are automatically deleted when you end your internet session and close the browser. Other cookies remain stored on your end device for a longer period of time. We use following technically necessary cookies on our website:

“Cloudflare Turnstile”:

  • Cookie/Storage Name: cf.turnstile.u (local storage entry)
  • Purpose: This technology is used exclusively on our Contact page to verify that the visitor is human and to protect our contact form against spam and automated abuse (bot detection). It runs invisible, non-interactive checks (browser signals, environment integrity) and does not display a traditional CAPTCHA puzzle.
  • Provider: Cloudflare, Inc. (widget served from challenges.cloudflare.com)
  • Type: Local storage (not a traditional HTTP cookie),
  • Storage period: Cleared automatically once the security check is completed; no persistent tracking or user profiling takes place.
  • This processing is necessary to protect the legitimate interest of the controller in securing the website against automated abuse (Art. 6(1)(f) GDPR). Because this local storage is strictly necessary for the security of the website, it is exempt from the consent requirements of Article 5 of the Directive 2002/58 EC. Cloudflare Turnstile does not set advertising cookies, does not track browsing behaviour across sites, and does not build visitor profiles.
  • More information: Cloudflare Turnstile Privacy Addendum.

Vimeo Cookie:

  • Cookie Name: __cf_bm
  • Purpose: This cookie is set only when a visitor actively clicks to play the embedded Vimeo video on our homepage (lazy-loading: no cookie before that action). It distinguishes legitimate human traffic from automated bots to protect the security of the video player. Our video embed uses Vimeo’s “Do Not Track” parameter (dnt=1), which prevents any tracking, analytics, or advertising cookie from being set.
  • Provider: Cloudflare (on behalf of Vimeo, player.vimeo.com)
  • Type: HTTP cookie
  • Storage period: Approximately 24 hours
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the controller in ensuring the secure and reliable functioning of the video player. Because this local storage is strictly necessary for the security of the website, it is exempt from the consent requirements of Article 5 of the Directive 2002/58 EC.

Users have full control over the use of cookies, as they are stored on the user’s terminal devices. Users can instruct their internet browser to deactivate or restrict the transfer of cookies by changing their browser settings (see below). If cookies are deactivated for our website, individual functions of our website cannot be used or can only be used to a limited extent. If we obtain consent for the use of cookies via a cookie banner or a cookie consent tool, you can revoke this consent at any time within the settings of the cookie banner or cookie consent tool with effect for the future.

Please find below links to instructions on how to change cookie settings in some of the commonly used browsers:

  • Microsoft Edge:https://support.microsoft.com/en-us/microsoft-edge/delete-cookies-in-microsoft-edge-63947406-40ac-c3b8-57b9-2a946a29ae09
  • Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox
  • Chrome: https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en-GB
  • Safari: https://support.apple.com/en-euro/guide/safari/sfri11471/mac/
  • Opera: https://help.opera.com/en/latest/web-preferences/

International Data Transfers

In order to provide our services and secure our website, we may occasionally use trusted third-party service providers located outside the EEA and Switzerland, specifically in the United States (e.g., for website security or media hosting). When your personal data (such as technical data or IP addresses) is transferred to such third countries, we ensure that appropriate legal safeguards are in place. We strictly rely on:

  • Adequacy Decisions: We transfer data to US companies that are certified under the EU-US Data Privacy Framework (DPF) and the Swiss-US Data Privacy Framework, which guarantees a level of protection equivalent to European standards.
  • Standard Contractual Clauses (SCCs): In cases where a provider is not certified under the DPF, we rely on the Standard Contractual Clauses approved by the European Commission, along with any necessary supplementary measures, to ensure your data remains secure.

Social Media

Our website does not use any social media plug-ins. The logos of the social networks displayed on our website are merely linked to the corresponding profiles of our company. If you click on one of the logos, you will be redirected to the external website of the respective social network. Please note that our profiles within the social networks also constitute data processing. If a user is logged in to the respective social network when clicking on those links, the information will be assigned to the user’s account there. If a user interacts with our profile, i.e. by sharing, liking or retweeting content, the information will be stored in the user’s account. Social networks store user’s data using pseudonyms for advertising purposes and market research. For example, users may be shown advertisements within the social network and on other third-party websites that match their presumed interests. Cookies are usually used for this purpose, which the social network stores on users end device. Users have the right to object to the creation of these user profiles; To exercise this right, users must contact the social networks directly.

TRUST Website
Project Use Cases Consortium Results & Resources
News Events Contact Privacy & Cookie Policy

Funded by
the European Union

Funded by the European Union under Grant Agreement No. 101299091.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Commission. Neither the European Union nor the granting authority can be held responsible for them.


© 2026 TRUST. All rights reserved.