NazivIER
Privacy policy
Last updated: 5. 10. 2026
1. Who is responsible
NazivIER, the internal tool for elections to research titles at naziv.ier.si, is run by the Institute for Economic Research (IER), a public research institute, Kardeljeva ploščad 17, 1000 Ljubljana (registration no. 5051690000, tax no. 81438818). The responsible person is the director, dr. Damjan Kavaš.
Send questions and requests about personal data to ier@ier.si; requests concerning data protection are passed on to IER’s data protection officer.
2. What the data is for, and the legal basis
- Running elections to research titles and keeping the titles register under IER’s rulebook on research titles (22 June 2026) and the law on research: calculating the conditions, applications, commissions, opinions, Scientific Council votes, decisions and deadline notices. Basis: legal obligation and a task in the public interest (GDPR Art. 6(1)(c) and (e)).
- Sign-in and security: who signed in and who did what in a procedure (the log), so the procedure can be checked. Basis: as above.
- HR’s to-do list: tasks HR staff keep for themselves (possibly naming the person or application concerned). If the Microsoft 365 link is switched on, the list is synced with their Microsoft To Do, messages they flag in Outlook become tasks, and details of the latest messages in their own work inbox are shown (see point 3), for that to-do list only. Basis: a task in the public interest and work duties (Art. 6(1)(e)).
- Usage analytics (which pages and buttons are used), only if you allow it in the cookie notice. Basis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
3. Which data, and where it comes from
- Name, work e-mail address, gender (for the right form of a title), SICRIS ID, level of education, role at IER – from HR’s records and, at sign-in, from your Microsoft 365 account.
- Titles with dates of election and validity (the register under Art. 30 of the rulebook).
- Bibliography, citations, the A3 score and projects – from the public COBISS and SICRIS (IZUM), OpenAlex and ier.si.
- What you enter yourself: years in research, projects led (without the clients of confidential projects), awards, authorship roles, summaries and attachments to an application.
- The procedure: HR’s decisions, the commission proposal and members, the commission report, Scientific Council votes and decision, e-mails the app sends.
- For HR’s to-do list only, and only from the own inbox of the HR staff member who switched the link on: subject, sender name and address, time received, up to the first 200 characters of the text and the link to the message in Outlook. The content of messages and attachments is not stored; the app reads no other mailbox.
- Technical data: when you signed in and acted; with your consent also page use (without the text on the pages, names or e-mail addresses).
4. Who sees what
- You see your own data, your applications and how the procedure goes. You receive the signed commission report with the Scientific Council decision.
- HR runs the procedures and the register; it sees the progress of a commission report, not its content.
- The director sees applications in procedure, to propose the commission, and the commission’s opinion once submitted.
- Commission members see an application only once appointed and after confirming they take part.
- Scientific Council votes are secret: nobody, HR included, sees how anyone voted.
- Nobody handles their own application.
- Own tasks and details from one’s own inbox are seen only by the HR staff member they belong to; HR’s shared tasks by everyone in HR.
The calculation of the conditions is an aid. The commission and the Scientific Council decide on an election; there is no automated decision-making.
5. Where the data is, and who processes it for us
- The app, database and attachments are on a server in the EU (Hetzner Online GmbH, Germany), run by IER.
- Sign-in uses IER’s Microsoft 365 accounts (Microsoft Entra ID) and IER’s sign-in server (auth.ier.si); e-mail is sent from an IER work mailbox in Microsoft 365.
- The link of HR’s to-do list with Microsoft 365 (if switched on): the tasks are also in that person’s Microsoft To Do, and message details are read from their mailbox in Microsoft 365 (Microsoft Graph), both within IER’s Microsoft 365.
- Analytics, only with your consent: PostHog (EU servers), through our own address naziv.ier.si.
- Until the previous version (4.x) is retired, your entries in it are copied into NazivIER.
We do not sell data or use it for advertising.
6. How long we keep it
The titles register is kept permanently, as its purpose requires. Applications and their history are kept; HR may delete an application’s attachments once you are elected to a higher title (the record of what was submitted remains). The log is kept as long as the procedure it belongs to. A sign-in session ends after 10 hours. Details of messages for HR’s to-do list are deleted after 30 days, and within 15 minutes when the link is switched off; a task stays until it is deleted.
7. Cookies and browser storage
| Name | Purpose | Duration | Kind |
|---|---|---|---|
| nz_session | sign-in | 10 hours | necessary cookie |
| nz_login | completing sign-in safely | 10 minutes | necessary cookie |
| nz.consent | your cookie choice | until deleted | necessary storage |
| naziv-theme | light or dark theme | until deleted | preference |
| ph_* | PostHog analytics (random ID) | until withdrawn | consent only |
You can change your choice any time with »Cookie settings« in the page footer. When you withdraw, analytics stops and its data is removed from your browser.
8. Security
Connections are encrypted (HTTPS), access requires an IER work account, rights are limited to one’s role in the procedure, every action is logged, files carry a checksum, and the database is backed up nightly.
9. Your rights
You have the right to access your data, to have it corrected, to restrict processing and to object; for analytics also to withdraw consent and have it erased. Data we must keep by law or under the rulebook (e.g. the titles register) cannot be erased. Send requests to ier@ier.si; we answer within one month.
If you think your rights have been breached, you can complain to the Information Commissioner, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si, www.ip-rs.si.
10. Changes
We tell you about significant changes to this policy in the app. The date of the last update is at the top of the page.

