Version 2.0 Effective date: 3 August 2026
1. Introduction
This privacy notice provides you with details of how we collect and process your personal data through your use of our site.
GrowWell is an international project co-funded by the Erasmus+ Programme of the European Union. Dječji vrtić Čigra, established in Croatia, acts as the primary Data Controller and is responsible for your personal data (referred to as “we”, “us” or “our” in this privacy notice).
We have appointed a Data Protection Officer who is in charge of privacy-related matters for us. If you have any questions about this privacy notice, please contact the Data Protection Officer using the details set out below.
Contact Details
Our full details are:
- Full name of legal entity: Dječji vrtić Čigra
- Contact Name: GrowWell Project DPO Officer
- Email address: projekt.erasmus@cigravrtic.hr
- Postal address: Radnička cesta 50, 10 000 Zagreb, Croatia
- Associated Website: https://www.cigravrtic.hr/
2. What Data We Collect About You, for What Purpose, and Our Legal Basis
Personal data means any information capable of identifying an individual. It does not include anonymised data.
As the GrowWell website does not sell products or offer paid commercial services, we explicitly do not collect transactional customer data, billing addresses, or payment information.
We process the following specific categories of personal data:
- Communication Data: This includes any communication that you send to us through email, contact forms, text, social media messaging, or social media postings. We process this data to respond to your requests, maintain communication records, and establish, pursue, or defend legal claims where necessary. Our lawful basis for this processing is our legitimate interest (Art. 6(1)(f) GDPR), specifically to manage communications, provide appropriate responses, maintain project administration records, and address potential legal matters. Where processing is based on legitimate interests, you have the right to object to such processing in accordance with Article 21 GDPR by contacting us at projekt.erasmus@cigravrtic.hr.
- Expression of Interest Data: This includes personal data collected through the Expression of Interest forms, such as first and surname, e-mail address, country of residence, status as educator or parent/guardian, preferred language for training, and optional information such as organisation and organisation’s email address. We process this data for the purpose of organising, planning, and delivering free online socio-emotional learning (SEL) training sessions, providing related educational materials, sending notifications of training dates, and managing participation within the Erasmus+ GrowWell project (Project No. 2025-1-HR01-KA220-SCH-000360813). The lawful basis for this processing is your freely given and explicit consent (Art. 6(1)(a) GDPR), provided through the registration checkbox. You may withdraw your consent at any time by contacting us at projekt.erasmus@cigravrtic.hr. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Where you have actually participated in a GrowWell training session, a minimum record of your participation (your name, e-mail address and the session attended) is additionally processed on the basis of our legal obligation and our legitimate interest in demonstrating the proper use of Erasmus+ funding (Art. 6(1)(c) and Art. 6(1)(f) GDPR). That record is retained as set out in Section 8 even if you withdraw your consent; following withdrawal we will, however, cease all further communication with you.
- User Data: This includes data about how you use our website and any online services, together with any data you post for publication on our website. We process this data to operate our website, ensure relevant content is provided to you, maintain the security and back-ups of our website/databases, and properly administer our project platforms. Our lawful ground for this processing is our legitimate interests (Art. 6(1)(f) GDPR) to enable us to properly administer our website and our project operations. Where processing is based on legitimate interests, you have the right to object at any time pursuant to Article 21 GDPR by contacting us at projekt.erasmus@cigravrtic.hr.
- Technical Data (Analytics): This includes data about your use of our website and online services, such as your IP address, browser details, length of visit to pages, page views, and navigation paths. The source of this data is our analytical tracking systems (such as Google Analytics). We process this data to analyse website usage, optimise our platform, and measure the reach of our educational project. Our lawful ground for processing this data is your explicit, prior consent (Art. 6(1)(a) GDPR) granted via our cookie banner.
- Marketing & Project Communications Data: This includes data about your preferences in receiving project updates, educational resources, newsletters, and training notifications from us and our consortium partners. Our lawful ground for sending these communications is your explicit, freely given consent (Art. 6(1)(a) GDPR).
We do not process personal data of persons under 18 years of age through this website.
Sensitive Data
We do not collect any Sensitive Data about you. Sensitive data refers to data that includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data. We do not collect any information about criminal convictions and offences.
Purpose Limitations
We will only use your personal data for the purpose it was collected for, or a reasonably compatible purpose if necessary (such as tracking attendance for Erasmus+ funding compliance verification). If we need to use your details for an unrelated new purpose, we will let you know and explain the legal grounds for processing.
We do not carry out automated decision-making or any type of automated profiling.
3. How We Collect Your Personal Data
We collect data about you through two primary methods:
- Direct Interaction: You provide data directly to us by filling out forms on our site (such as the Expression of Interest form) or by corresponding with us via email.
- Automated Technologies: As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies and other similar technologies. Please see Section 11 (Cookies) for more details.
What Happens if You Do Not Provide the Data
Providing your personal data is voluntary. However, if you do not provide the required data, we will not be able to inform you regarding GrowWell training sessions, and provide you with related educational materials and notifications.
4. Marketing and Project Communications
Our lawful ground for processing your personal data to send you newsletters, workshop availability, or educational resources is strictly your explicit consent.
In compliance with the GDPR and national legislation implementing the EU ePrivacy Directive, you will only receive marketing and project communication if you have explicitly opted in via our submission forms or subscription checkboxes.
You can ask us to stop sending you project updates at any time by clicking the unsubscribe links found at the bottom of any email message sent to you, or by contacting us directly at projekt.erasmus@cigravrtic.hr.
5. Disclosures of Your Personal Data
For transparency, we do not share your data with generic third parties. We may share your personal data exclusively with the following specified categories of recipients for the purposes outlined below:
- Erasmus+ Project Consortium Partners: GrowWell is implemented by an international consortium of partner organisations consisting of Dječji vrtić Čigra, Profil Klett d.o.o., Otvoreno učilište Littera, National College of Ireland, Matrix Internet, European Parents’ Association and Pomoć deci – udruženje građana. Dječji vrtić Čigra is the sole controller of the personal data collected through this website and determines the purposes and the means of its processing. The consortium partners listed above process participant data as our processors: they act only on our documented instructions and under written agreements concluded pursuant to Article 28 GDPR. Participant data collected through the Expression of Interest form is shared securely among them solely to organise, evaluate, and deliver localised training sessions in their respective countries and languages. This includes contacting participants with information about training sessions, providing registration links for online or in-person activities, sending training-related information and coordinating participation. Matrix Internet operates the GrowWell website and the Expression of Interest form and collects participant data on our behalf. The collected data is made available to the consortium partners responsible for delivering the training activities. Dječji vrtić Čigra remains responsible for that data and is the contact point for all requests concerning it.
Core Service Processors:
- Website hosting and server infrastructure providers (located within the EEA).
- Web development and IT maintenance administration providers.
- Secure cloud storage and newsletter distribution platforms.
- Professional Advisers: Including lawyers, auditors, and insurers where necessary for compliance.
- Governmental & EU Funding Bodies: National agencies and European Commission auditors who require processing activity reports to verify Erasmus+ project compliance and funding eligibility.
We require all recipients to respect the security of your personal data and to process it in accordance with applicable data protection laws. Our processors process personal data only on our documented instructions, under written agreements concluded pursuant to Article 28 GDPR. National agencies, European Commission auditors and professional advisers are an exception: they act as independent controllers under their own legal obligations and are not bound by our instructions.
6. International Data Transfers
Your personal data is transferred outside the EEA in two situations. First, our consortium partner Pomoć deci – udruženje građana is established in Serbia, which is not covered by a European Commission adequacy decision. Where registration data of participants is transferred to that partner, the transfer is made on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. Second, some of our third-party service providers are established outside the EEA, as set out below.
Some of our third-party service providers (such as Google Analytics and Meta/Facebook plug-ins) are located outside the European Economic Area (EEA), primarily in the United States.
Whenever your personal data is transferred outside the EEA through these tools, we ensure a similar degree of protection is afforded to it by verifying that at least one of the following safeguards is implemented:
- The country has been deemed to provide an adequate level of protection for personal data by the European Commission.
- The provider participates in the EU-U.S. Data Privacy Framework, which binds them to strict data-sharing standards.
- We utilise specific Standard Contractual Clauses (SCCs) approved by the European Commission, which give personal data the same protection it has in Europe. Information regarding the European Commission’s Standard Contractual Clauses is available through the European Commission’s official website: https://commission.europa.eu/…. You may request further information about the safeguards applied to a specific transfer, or a copy of the clauses we have concluded (with commercially confidential information redacted), by writing to projekt.erasmus@cigravrtic.hr.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, altered, disclosed, or accessed without authorisation. We also limit access to your personal data only to those project employees and consortium partners who have a strict operational need to know. Recipients acting as our processors process your personal data solely on our documented instructions, under a written agreement concluded pursuant to Article 28 GDPR; joint controllers process it under their own responsibility as described in Section 5. All recipients are bound by confidentiality obligations.
We have established procedures to deal with any suspected personal data breach and will notify you and the competent regulator of a breach where we are legally required to do so.
8. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including the fulfilment of legal, accounting, and EU funding reporting requirements.
- Contact & General Inquiries: Retained for up to 1 year following the final resolution of your inquiry.
- Newsletter & Marketing Subscriptions: Retained until you withdraw your consent (unsubscribe).
- Workshop Registrations & Expressions of Interest: Because this project is funded through the EU Erasmus+ program, basic participant data and project documentation must be retained to satisfy strict financial auditing criteria. This data is kept for the operational duration of the GrowWell project plus the mandatory post-project audit retention window (5 years following official project closure).
- Technical Data and Analytics Data: Technical information collected through cookies and analytics tools (such as IP address, browser and device information, website usage statistics, page views and navigation data) is retained for the lifetime of the individual cookie, as set out in our Cookie Policy. Analytics records are retained for 14 months, in accordance with the retention period configured in our analytics tool, after which they are automatically deleted by the provider. Server and security logs are retained for 6 months. Back-up copies are overwritten in rotation; where data has been erased from our live systems, the corresponding back-up copies are overwritten within 30 days at the latest, and during that interval the data is not used for any other purpose.
9. Your Legal Rights
Under European data protection laws (GDPR), you have rights in relation to your personal data. These include the right to request access, correction, erasure, restriction of processing, data portability, object to processing, and—where the lawful ground of processing is consent—the right to withdraw your consent at any time.
You can read comprehensive details about these rights on the official Croatian AZOP platform: https://azop.hr/rights-of-individuals/
If you wish to exercise any of the rights set out above, please email us at projekt.erasmus@cigravrtic.hr. You will not have to pay a fee to access your data or exercise your rights unless the request is clearly unfounded, repetitive, or excessive.
Competent Supervisory Authority
If you are not happy with how we collect and use your data, you have the right to lodge an official complaint with the competent supervisory authority. For the Data Controller (Dječji vrtić Čigra), this is the Croatian Personal Data Protection Agency (AZOP):
- Name of Entity: Agencija za zaštitu osobnih podataka (AZOP)
- Postal Address: Selska cesta 136, 10000 Zagreb, Croatia
- Website: www.azop.hr
We would, however, appreciate the opportunity to resolve your concerns directly before you approach the authority, so please contact us first.
10. Third-Party Links
This website may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.
11. Cookies and Consent
Our website distinguishes between types of cookies to ensure your choice is fully compliant with the ePrivacy framework:
- Strictly Necessary Cookies: Placed automatically to ensure fundamental website operations and security features. These do not require consent.
- Performance Cookies: Used to see how visitors use the website, for example analytics cookies. These are blocked by default and are set only if you consent to them via our cookie banner.
- Targeting Cookies: Used to identify visitors across different websites and to build a profile of visitor interests. These are blocked by default and are set only if you consent to them. We do not currently use any targeting cookies on this website; if that changes, this notice and our Cookie Policy will be updated before any such cookie is set.
- Functionality Cookies: Used to remember the choices you make on the website, such as your preferred language. These are blocked by default and are set only if you consent to them.
You can manually configure your web browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or fail to function properly. For the full list of the cookies used on our website, their duration and their providers, please see our Cookie Policy, available at https://growwellproject.eu/cookie-policy/.