est. 2026 · a division of the journal
Legal · Privacy

Privacy Notice

Version 1.0 · in force from 24 September 2026

In short

  • Browsing the museum sets no cookies and runs no analytics, trackers or advertising. The fonts and images come from our own server.
  • Our server keeps short technical logs to keep the site secure.
  • If you submit to the open call, we keep what you send only to review it and to work with you.
  • Payments go through PayPal. We see your PayPal name, e-mail and the transaction, never your card or bank details.
  • You can ask to see, correct or delete your data at any time.

1.Who is responsible

The controller of your personal data is Viacheslav Munister, director of EPRIS Journal and EPRIS Museum, [registered address, Milan, Italy], operating EPRIS Museum as a division of EPRIS Journal. For anything about your data write to munister@outlook.com. This notice follows Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR).

2.What we collect, why, and for how long

WhenWhatWhy, and legal basisKept for
You visit any pageIP address, date and time, page requested, referring page, browser type, response code, in the web server’s logTo deliver pages, prevent abuse and fix faults. Legitimate interest, Art. 6(1)(f)[14 days — confirm the server’s log rotation]
You send an open call submissionName, e-mail, discipline, Instagram handle, portfolio link, your statement, and the dateTo review your work and reply. Steps at your request before a contract, Art. 6(1)(b)If not accepted: 12 months after our decision, then deleted
Your work is acceptedThe above, plus the credit line and details you give for publicationTo publish and credit the work and manage our agreement. Contract, Art. 6(1)(b)While the work is displayed, and 12 months after it is taken down
You pay by PayPalYour PayPal name and e-mail, amount, date, transaction ID and noteTo match payments to invoices and keep accounts. Contract and legal obligation, Art. 6(1)(b) and (c)10 years, as Italian law requires for accounting records (Art. 2220 Civil Code)
You write to usYour e-mail address and what you writeTo answer you. Legitimate interest or contract, Art. 6(1)(f) or (b)24 months after the last message

The name and credit line printed beside an accepted work are public by design, at your request, and are removed when the work is taken down.

3.What we do not do

  • no cookies, analytics, fingerprinting, tracking pixels or advertising;
  • no third-party fonts, scripts or embeds while you browse: everything is served from our own server;
  • no selling, renting or sharing of your data for anyone else’s marketing;
  • no automated decisions about you: every submission is read by a person.

4.Who else handles your data

  • Our hosting provider, Hosting Ukraine LTD, Kyiv, Ukraine, runs the server that stores the site, the logs and open call submissions, as our processor under a data processing agreement.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg, processes your payment as an independent controller under its own privacy statement at paypal.com.
  • Our e-mail provider, Microsoft (Outlook.com), carries our correspondence with you, under Microsoft’s privacy statement; Microsoft may process e-mail outside the EU under its own safeguards.
  • Authorities, only where the law obliges us.

5.Data outside the EU

Our server is in Ukraine, which is not covered by an adequacy decision of the European Commission. We transfer data there under [the European Commission’s Standard Contractual Clauses — confirm these are signed with the host], and you can ask us for a copy. PayPal may transfer data under its own safeguards, described in its privacy statement.

6.Your rights

You have the right to ask for access to your data, to have it corrected or erased, to restrict or object to its use, and to receive it in a portable format (Articles 15 to 21 GDPR). Where we rely on legitimate interest you may object at any time. Write to munister@outlook.com; we answer within one month. We may ask you to confirm your identity first.

You also have the right to complain to a supervisory authority. In Italy that is the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, garanteprivacy.it. You may also complain in the EU country where you live or work.

7.Age

The open call is for people aged 18 or over. We do not knowingly collect data from children.

8.Security

The site is served only over HTTPS. Submissions are stored on our server and can be read only by the museum’s editorial team, whose access is password-protected. If a breach puts your data at risk, we will tell you and the Garante as the GDPR requires.

9.Changes

We update the date at the top when this notice changes, and announce significant changes on the home page.