Governance & privacy

Privacy Policy

Last updated: 21 August 2026

1. Who we are

This website is operated by Foundation "European Risk Policy Institute" (European Risk Policy Institute, ERPI), UIC 176961675, VAT No. BG176961675, with registered office and address of management at 1 Gusla St., Ovcha Kupel 1, Sofia 1618, Bulgaria.

Privacy and data-protection enquiries: info@risk-policy.eu

2. Scope of this notice

This notice explains how personal data may be processed when you visit risk-policy.eu or contact ERPI by email. The launch configuration is deliberately low-tracking and does not use a public web contact form, public user registration, comments, analytics, advertising pixels, newsletter registration, payment services, chat services, third-party fonts or third-party embedded content.

3. Personal data we may process

Email correspondence: your name, email address, message content and any information or attachments you choose to send to ERPI.

Technical request and security data: IP address, date and time, requested URL or path, browser/user-agent information, referrer where supplied, and technical or error information recorded by the hosting or security infrastructure.

Site-search data: search terms submitted to the website may be included in ordinary server request logs.

Administrative authentication data is processed for authorised ERPI website administrators and is not part of ordinary public visitor registration.

4. Why we process personal data

To respond to enquiries and manage professional communications. Depending on the context, the legal basis is ERPI's legitimate interests in conducting its institutional activities (Article 6(1)(f) GDPR) or steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).

To operate, secure, diagnose and protect the website and its infrastructure. The legal basis is ERPI's legitimate interests in maintaining the security, integrity and availability of its services (Article 6(1)(f) GDPR), together with any applicable legal obligations.

To establish, exercise or defend legal claims where necessary.

5. Cookies, tracking and local storage

ERPI does not use analytics or marketing cookies in the controlled launch configuration. WordPress authentication cookies are used only for authorised administrators. The hosting or security layer may use strictly necessary technical security mechanisms, including cookies or equivalent storage where required to protect or deliver the site. These are not used by ERPI for advertising or behavioural analytics.

6. Recipients and service providers

Personal data may be processed by service providers that support the operation of the website and ERPI communications, including hosting, infrastructure, security and email providers, acting under applicable contractual and data-protection requirements. Personal data may also be disclosed where required by law or to competent public authorities.

7. International transfers

The controlled website does not intentionally use third-party analytics, advertising, external fonts or embedded platforms that require routine visitor-data transfers outside the European Economic Area. If a service provider processes personal data outside the EEA, ERPI will rely on an applicable safeguard under Chapter V of the GDPR.

8. Retention

Email correspondence is retained only for as long as necessary to handle the enquiry and any relevant follow-up, or longer where required for contractual, legal, accountability or legal-claims purposes. Technical and security logs are retained according to operational and security needs and the applicable hosting/security configuration. ERPI applies the principle that personal data should not be kept longer than necessary for the purpose for which it is processed.

9. Your rights

Subject to the conditions of the GDPR, you may request access to your personal data, rectification, erasure, restriction of processing, data portability, or object to processing based on legitimate interests. You may also lodge a complaint with a supervisory authority. To exercise your rights with ERPI, contact info@risk-policy.eu.

10. Supervisory authority

In Bulgaria, the competent supervisory authority is the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria; email: kzld@cpdp.bg; website: www.cpdp.bg.

11. Automated decision-making

ERPI does not use the website to make automated decisions about visitors that produce legal or similarly significant effects.

12. Changes to this policy

ERPI may update this notice when the website, its service providers or applicable legal requirements change. The current version and update date will be published on this page.