This Privacy Policy explains how the Erasmus Student Network AISBL (“we”, “us”, or “the Company”) collects, uses, shares, and protects personal data when you use ErasmusCareers (the “Platform”), a platform connecting Candidates with Erasmus+ internships, traineeships, and international job opportunities.
It applies to personal data processed through the Platform's website, mobile applications (if any), and related communications, including data provided by Candidates, Host Organisations, and visitors. It should be read together with our Terms and Conditions.
This Policy may be updated from time to time (see Section 13). It does not cover the practices of third-party websites, Host Organisations, sending institutions, or National Agencies, which have their own privacy notices and act as independent controllers for their own processing activities.
This document is provided for information purposes and does not constitute legal advice. Nothing in this Policy limits the rights granted to you under the GDPR or applicable Belgian law.
The data controller responsible for the processing of your personal data described in this Policy is:
Erasmus Student Network AISBL
Rue Joseph II/Jozef II-straat 120, 1000, Brussels, Belgium
Company number (BCE/KBO): BE0876728263
Email: [email protected]
Data Protection Officer (if appointed): [email protected]
Where a Host Organisation makes its own recruitment decisions based on the information you submit, it acts as an independent data controller for that processing, and its own privacy notice applies to that part of the process.
We process your personal data for the following purposes:
- To create and manage your Account;
- To match Candidates with Listings and transmit applications to Host Organisations;
- To communicate with you about your account, applications, or support requests;
- To send you newsletters or marketing communications, where you have agreed to receive them;
- To maintain the security of the Platform and prevent fraud;
- To analyse and improve the Platform, including through usage analytics;
- To comply with legal, accounting, and tax obligations, and to respond to lawful requests from Belgian or EU authorities;
- Where relevant, to consider accessibility, health, or dietary needs in connection with an Erasmus+ mobility.
The legal basis for each of these purposes is set out in Section 10.
4.1 Data you provide directly:
- Identification data (eg: email, name, surname, date of birth, nationality, gender, photograph, …);
- Contact data (eg: email, postal code, LinkedIn url, city and country of residence, ...);
- Professional experience data: (eg: position, dates, if the activity took place under a mobility programme, Company/Institution name, country, ..);
- Academic, volunteering, and training data (eg: title/position, dates, if the activity took place under a mobility programme, provider name, country, …);
- Rest of the student data (eg: title of an activity, description, date, link to reference, names, providers, …);
- Application data, (eg: offer applied to, application status, messages exchanged with Host Organisations);
- Account data (eg: username, password (stored encrypted/hashed), preferences);
- For Host Organisations (eg: company name, country, address, description, logo, banner, website, LinkedIn url, sector, type of company, size of company, VAT number, …);
- Any other information you choose to include in your profile or communications with us.
4.2 Data collected automatically:
- Technical data: IP address, browser type, device identifiers, operating system.
- Usage data: pages viewed, searches performed, listings clicked, time spent on the Platform, referral source.
- Cookies and similar technologies, as described in Section 14.
4.3 Special category data: In limited circumstances (for example, information relevant to disability-related support during an Erasmus+ mobility), we may process special categories of personal data within the meaning of Article 9 GDPR. We only do so with your explicit consent or another applicable legal basis under Article 9(2) GDPR, and only to the extent necessary.
Internally, access is limited to staff who need it to perform their role (e.g. customer support, IT, or operations), on a need-to-know basis and subject to confidentiality obligations.
Externally, we may disclose your personal data to:
- Host Organisations, to the extent necessary to process an application you submit (e.g. your CV, cover letter, and profile information). Host Organisations act as independent controllers for their own recruitment decisions.
- Your sending institution and/or National Agency, where required to confirm Erasmus+ eligibility, funding, or reporting obligations.
- Service providers/processors acting on our behalf, such as hosting providers, email delivery services, analytics providers, and payment processors (Google Analytics, Cloudflare), under data processing agreements compliant with Article 28 GDPR.
- Professional advisors and authorities, where necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.
- A buyer or successor, in the event of a merger, acquisition, or sale of assets, subject to appropriate safeguards.
We do not sell your personal data.
International transfers: Some of our service providers may be located outside the European Economic Area (EEA). Where this is the case, we ensure an adequate level of protection through European Commission adequacy decisions, Standard Contractual Clauses (SCCs), or other safeguards recognised under Chapter V GDPR. You may request a copy of the relevant safeguard by contacting us at [email protected].
6.1 Retention period:
- Account and profile data: for as long as your Account is active, and for 2 years after your account has been marked as inactive.
- Application data: for 2 years after the relevant application process ends, for evidentiary and reporting purposes.
- Billing and accounting records: for the statutory period required under Belgian accounting and tax law (generally 7 years).
- Marketing consent: until you withdraw your consent or unsubscribe.
Retention periods may be extended where necessary to comply with a legal obligation or to establish, exercise, or defend legal claims. At the end of the applicable retention period, we securely delete or anonymise your data.
6.2 Account deletion. Any user can delete their account by themselves by going to their profile (as soon as the feature is enabled) or by requesting it to [email protected] (while the user cannot do it by themselves).
The deletion of the account is considered final, and no data can be retrieved after.
For students registering through the SSO (single sign-on) of Erasmus Generation Accounts (the system managing the accounts of the Erasmus Generation), deletion of data only happens on Erasmus Careers. Account deletion on the Erasmus Generation Accounts is regulated by its own Privacy Policy.
For legacy student accounts (those created within the former ErasmusJobs platform) and recruiter accounts, the deletion is executed as expected.
7.1 How we collect your data:
- Directly from you, when you create an account, complete your profile, upload a CV, or apply to a Listing.
- Automatically, through cookies and similar technologies when you use the Platform.
- From third parties, such as your sending institution, a National Agency, or a Host Organisation, where relevant to processing your application or mobility.
7.2 How we handle your data. Your data is processed using a combination of automated systems (e.g. account management, search, and matching tools) and manual review by authorised staff, hosted on secure servers operated by us or by our processors, and protected by the measures described in Section 7.
7.3 Automated decision-making and profiling. We do not use fully automated decision-making that produces legal or similarly significant effects on you without human involvement, within the meaning of Article 22 GDPR.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration, including encryption in transit, access controls, staff confidentiality obligations, and regular security reviews. No system is completely secure, and we cannot guarantee absolute security.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority within 72 hours where required, and inform affected individuals without undue delay where the breach is likely to result in a high risk, in accordance with Articles 33 and 34 GDPR.
9.1 Users’ rights. Under the GDPR and the Belgian Act of 30 July 2018, you have the right to:
- Access the personal data we hold about you (Art. 15 GDPR);
- Rectify inaccurate or incomplete data (Art. 16 GDPR);
- Erasure (“right to be forgotten”), subject to certain exceptions (Art. 17 GDPR);
- Restrict the processing of your data in certain circumstances (Art. 18 GDPR);
- Data portability, to receive your data in a structured, commonly used, machine-readable format (Art. 20 GDPR);
- Object to processing based on legitimate interest, including profiling, and to direct marketing at any time (Art. 21 GDPR);
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR);
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us using the details in Section 9. We will respond within one month, as required by Article 12(3) GDPR (extendable by two further months for complex requests). We may ask you to verify your identity before processing your request.
9.2 Complaints to the supervisory authority. If you believe your data protection rights have been infringed, you may lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, Belgium — https://www.autoriteprotectiondonnees.be — [email protected]. You may also lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement, if different from Belgium.
For any questions about this Privacy Policy or how we handle your personal data, or to exercise any of your rights, please contact:
Erasmus Student Network AISBL
Rue Joseph II/ Jozef II-straat 120, 1000, Brussels, Belgium
Email: [email protected]
Data Protection Officer: [email protected]
We rely on the following legal bases under Article 6 GDPR, depending on the purpose of processing:
- Performance of a contract (Art. 6(1)(b)) — to create and manage your Account, to match you with Listings, to transmit applications, and to communicate with you about your account or applications.
- Consent (Art. 6(1)(a)) — to send you newsletters or marketing communications, and for non-essential cookies. You may withdraw your consent at any time.
- Legitimate interest (Art. 6(1)(f)) — to maintain the security of the Platform, prevent fraud, and analyse and improve our Services. We have assessed that our interest is not overridden by your rights and freedoms; you may request further details or object at any time.
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax, and other statutory obligations, and to respond to lawful requests from Belgian or EU authorities.
- Explicit consent for special category data (Art. 9(2)(a)) — where we process accessibility, health, or dietary information in connection with an Erasmus+ mobility, or another applicable basis under Art. 9(2) where relevant.
The Platform is intended for individuals who meet the minimum age requirement set out in our Terms and Conditions.
We do not knowingly collect personal data from children below this threshold without appropriate consent, and we will delete such data if we become aware of it. Parents or guardians who believe their child has provided personal data to us without appropriate consent should contact us using the details in Section 9 so that we can take appropriate action.
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. We will post the updated version on the Platform with a revised “Last updated” date, and, where changes are material, notify you by email and a notice on the Platform before they take effect.
We use cookies and similar technologies to operate the Platform, remember your preferences, measure usage, and (with your consent) for analytics and marketing purposes. Non-essential cookies are only placed with your prior consent, in accordance with Belgian ePrivacy rules and Article 129 of the Belgian Act of 13 June 2005 on electronic communications. You can manage or withdraw your cookie preferences at any time via your browser settings.
We use cookies and similar technologies to operate the Platform, remember your preferences, measure usage, and (with your consent) for analytics and marketing purposes. Non-essential cookies are only placed with your prior consent, in accordance with Belgian ePrivacy rules and Article 129 of the Belgian Act of 13 June 2005 on electronic communications.
14.1 What is a cookie?
A cookie is a small text file that a website places on your computer, tablet, or mobile device when you visit it. Cookies are widely used to make websites work, work more efficiently, remember your preferences, and provide information to the owners of the site. Similar technologies (such as web beacons, pixel tags, and local storage) that serve a comparable function are also covered by this Section and referred to collectively as “cookies”.
14.2 Who places cookies on the Platform?
- First-party cookies are set directly by us.
- Third-party cookies are set by service providers acting on our behalf or embedded on our pages (e.g. analytics or social media providers). We do not control these cookies directly; they are governed by the relevant third party's own privacy and cookie policies, which we encourage you to review.
14.3 Categories of cookies we use
- Strictly necessary cookies: required for the Platform to function (e.g. keeping you logged in, remembering items in an application form, load balancing, security). These cannot be switched off and do not require your consent, as they are necessary to provide the service you requested (Art. 129, §1(2) of the Belgian Act of 13 June 2005).
- Functional cookies: remember your preferences (e.g. language, saved searches, display settings) to provide a more personalised experience.
- Analytics/performance cookies: help us understand how visitors use the Platform (e.g. pages visited, time on page, error messages) so we can improve it. Where these tools identify you individually, they are only used with your consent.
- Marketing/advertising cookies: used to deliver relevant content or measure the effectiveness of communications about internship and job opportunities. These are only placed with your consent and may be set by third parties.
14.4 Cookies used on this Platform
- Name: [SSESSxxxxxx] — Category: [Strictly necessary] — Purpose: [keeps you logged in during your visit] — Provider: [first-party] — Duration: [session]
- Name: [klaro] — Category: [Strictly necessary] — Purpose: [stores your cookie preferences] — Provider: [first-party] — Duration: [1 month]
- Name:[ cf_clearance] — Category: [Strictly necessary] — Purpose: [anti-bot feature] — Provider: [Cloudflare - third party] — Duration: [12 months]
- Name: [_ga_xxxx] — Category: [Analytics] — Purpose: [distinguishes users for usage statistics] — Provider: [Google Analytics – third party] — Duration: [13 months]
14.5 Duration of cookies
Session cookies are temporary and are deleted from your device when you close your browser. Persistent cookies remain on your device for a set period (or until you delete them) and are used, for example, to remember your preferences between visits.
14.7 Changes to our use of cookies
We may update the cookies we use as the Platform evolves. Where this involves a material change to the categories of cookies used - or their purposes -, we will update this Section and, where required, ask for your renewed consent.
14.6 Your consent and how to manage cookies
When you first visit the Platform, a cookie banner lets you accept or reject non-essential cookies, and to choose which categories you consent to. You can change your preferences at any time via [the cookie settings link in the footer of the Platform].
You can also manage or delete cookies directly through your browser settings. Please note that blocking or deleting strictly necessary cookies may affect the functioning of the Platform. Guidance for common browsers:
- Google Chrome: Settings > Privacy and security > Cookies and other site data
- Mozilla Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Microsoft Edge: Settings > Cookies and site permissions
You can also opt out of certain third-party advertising cookies via industry tools such as [www.youronlinechoices.eu].
- Consent: a freely given, specific, informed, and unambiguous indication of a data subject's wishes, by which they agree to the processing of their personal data (Art. 4(11) GDPR).
- Data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Art. 4(12) GDPR).
- Data controller: the entity that determines the purposes and means of processing personal data (Art. 4(7) GDPR).
- Data processor: an entity that processes personal data on behalf of, and under the instructions of, a data controller (Art. 4(8) GDPR).
- Data subject: the natural person to whom personal data relates (e.g. a Candidate or a contact person at a Host Organisation).
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
- Legitimate interest: a legal basis allowing processing where necessary for the controller's or a third party's legitimate interests, provided these are not overridden by the data subject's rights (Art. 6(1)(f) GDPR).
- Personal data: any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
- Processing: any operation performed on personal data, such as collection, storage, use, disclosure, or deletion (Art. 4(2) GDPR).
- Profiling: any automated processing of personal data to evaluate certain personal aspects of a natural person, such as performance, preferences, or behaviour (Art. 4(4) GDPR).
- Special category data: personal data revealing racial or ethnic origin, health, religious beliefs, or similar sensitive information, subject to stricter conditions under Art. 9 GDPR.
- Supervisory authority: the independent public authority responsible for monitoring GDPR compliance in a Member State — in Belgium, the Autorité de protection des données / Gegevensbeschermingsautoriteit.