Privacy Policy


YouTHink Moodle Privacy Policy

  • We collect only the information needed to create and manage your Moodle account, provide learning activities, keep the platform secure and, where applicable, evaluate the YouTHink pilot activities.
  • We may record your course participation, activity completion and feedback.
  • Your uploaded work, forum posts, screenshots, audio and video files are used for learning, assessment and, where necessary, project evaluation. They are not published by default.
  • Your name, image, voice or creative work will be published only if separate consent has been given and, where required, parental or guardian authorisation has been obtained.
  • Some minimum participation and completion records may need to be kept as Erasmus+ project evidence for audit and reporting purposes.
  • You can ask to see or correct your data and, where applicable, request its deletion.

You can also withdraw consent for optional activities or publication at any time. Please read the full Privacy Policy below for more information and contact asociacija@vipt.lt if you have questions.

YouTHink Moodle Privacy Policy

Effective date: 4 May 2026
Last updated: 18 September 2026

This Privacy Policy explains how personal data are processed when you use the YouTHink Moodle Virtual Learning Environment (the VLE) at https://moodle-youthink.eu/. The VLE supports the Erasmus+ project YouTHink – Responsible Youth through Media Literacy Education (Project No. 2024-1-LT02-KA220-YOU-000251256).

Participation in YouTHink project activities is voluntary. You may decide not to take part in optional activities and may withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing already carried out before withdrawal.

This notice is written for young people aged 14–19, mentors, trainers and other users of the VLE. Please read it with a parent or legal guardian if you are unsure about any part of it.


1. Data controller and project roles

The VLE is administered by Association Viešieji interneto prieigos taškai (VIPT), also operating internationally as the Rural Internet Access Points Association (RIAP), legal entity code 300618195, address S. Žukausko g. 18-30, Vilnius, email asociacija@vipt.lt. RIAP is the data controller for personal data processed through Moodle for account administration, access control, platform security, technical logs and the administration of learning activities.

Each YouTHink project partner acts as an independent data controller for the personal data it processes when recruiting participants, organising local pilot activities, managing parental or guardian authorisations and carrying out local communication activities.

Where two or more project partners jointly determine the purposes and essential means of a specific processing activity, they act as joint controllers. Their respective responsibilities are documented in a joint controller arrangement, and the essential information about that arrangement is made available to the affected participants.

RIAP is the main contact point for questions relating to personal data processed through Moodle.

The YouTHink project partners are:

2. Why we process your personal data

We process personal data only for the purposes below and on an appropriate legal basis.

  • User registration, account administration and access to learning activities. Processing is necessary to take steps requested by the user and to provide the requested VLE service (Article 6(1)(b) GDPR). This includes creating an account, confirming access, displaying course content and recording completion.
  • Certificates. We use the minimum account, enrolment, participation, completion and assessment records necessary to confirm successful completion of a learning activity and to issue a YouTHink certificate. Where applicable, the relevant national Project Partner may also use the minimum necessary records to issue or arrange the issue of a Youthpass certificate.

RIAP may provide Moodle completion information to the relevant national Partner only where this is necessary for certificate issuance under the Project arrangements. Where issuing a Youthpass certificate requires personal data to be entered into an external Youthpass service, the relevant national Partner will provide the participant, and where applicable the parent or guardian, with further information before that transfer takes place.

  • Platform security, prevention of unauthorised access, system maintenance and incident management. Processing is necessary for our legitimate interests in maintaining a secure and reliable learning environment (Article 6(1)(f) GDPR). This includes technical logs, security monitoring, access management and troubleshooting.
  • Project administration, pilot implementation, evaluation, statistical analysis, reporting and audit. Processing is necessary for the legitimate interests of the project partners in implementing, evaluating and verifying the Erasmus+ project (Article 6(1)(f) GDPR), and, where applicable, for compliance with a legal obligation (Article 6(1)(c) GDPR). This includes evidence of participation, aggregate results, required reports and responses to audit requests.
  • Optional survey questions, publication of a name, image, voice, quotation or identifiable creative work, and communication photographs or recordings. Processing is based on separate consent (Article 6(1)(a) GDPR). This includes optional feedback, social-media posts, exhibitions, websites and publications.

We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects.

3. What personal data we process

Depending on how you use the VLE, we may process:

  • account and contact data: name or chosen account name, email address, user role, organisation where relevant, country and age group;
  • platform and security data: IP address, login date and time, technical logs, session information and necessary cookie information;
  • learning and evaluation data: course enrolment, activity completion, responses to evaluation questions, feedback, participant role and results needed to evaluate the pilot activities;
  • user-generated content: files uploaded by users, creative works, screenshots, forum posts, text submissions, audio files and video files, where these are submitted as part of a learning activity;
  • consent and participation records: records showing the basis for participation, consent for optional activities and, where applicable, parent or guardian consent; and
  • publication data: only where separate consent has been given, a participant’s name or pseudonym, image, voice, quotation, creative work or other identifiable contribution.

We do not intentionally collect special categories of personal data, such as data concerning health, racial or ethnic origin, religious beliefs, political opinions or sexual orientation. Do not include such information in forum posts, uploads or survey responses unless the activity expressly requests it and you have been informed about the specific legal basis.

Surveys and project evaluation

The VLE may collect survey responses and learning activity results to evaluate pilot activities and the YouTHink project. Evaluation data may include age group, country, participant role, completion of learning activities, responses to evaluation questions and feedback on learning materials.

Where possible, evaluation data are analysed using a participant code, pseudonym or aggregated results rather than a participant’s full name. Questions not necessary for project evaluation will be clearly marked as optional.

User-generated content

Files, creative works, screenshots, forum posts and audio or video submissions are used only for learning, assessment, platform administration and evaluation of project results. They are not made public unless separate publication consent has been obtained. Access is limited to authorised RIAP administrators, relevant trainers and project staff who need access for these purposes.

4. Children and young people

The YouTHink VLE is intended for young people aged 14–19. Where a processing activity is based on consent and the VLE is offered directly to a child, the relevant national age threshold and consent requirements apply.

The local project partner organising the activity is responsible for applying the requirements in its country and for obtaining and retaining parental or guardian authorisation where this is required by law or by the partner’s safeguarding procedures. A Moodle confirmation does not replace the required parental or guardian consent procedure.

5. Publication and dissemination

Personal data are not published by default. A participant’s name, pseudonym, image, voice, quotation, creative work or other identifiable contribution may be used in project communication, exhibitions, websites, social media or publications only where separate consent has been provided by the participant and, where required, by a parent or legal guardian.

If publication consent is not given, only aggregated or appropriately anonymised results may be used for reporting and dissemination. A contribution is not considered anonymous merely because the participant’s name has been removed if the contribution could reasonably identify that person.

Where publication is approved, we will use the minimum necessary information, such as a pseudonym, country, age group and the submitted work.

6. Who may receive personal data

Personal data may be accessed only by authorised RIAP administrators, project coordinator, relevant project staff and trainers where access is necessary for the purposes described in this policy.

Data may be shared with the YouTHink project partners only where necessary for project implementation, evaluation, reporting, consent management, safeguarding or agreed dissemination activities.

Service providers acting on our behalf may process data, for example the Moodle hosting provider, technical maintenance providers, email service providers, backup providers and security service providers. They may process personal data only under documented instructions and appropriate data-processing arrangements.

Project evaluation and participant-record data may be provided to official bodies, including the National Agency / Youth Affairs Agency, authorised bodies of the European Commission, auditors, the European Anti-Fraud Office (OLAF), the European Public Prosecutor’s Office or the European Court of Auditors, where required for reporting, verification, audit, investigation or legal compliance and only on a lawful basis.

Project partners are established in Lithuania, Portugal, Slovenia, Italy and Switzerland. Where data are transferred outside the European Economic Area, including to Switzerland where applicable, the transfer will take place only where an adequate level of protection or appropriate safeguards under applicable data-protection law are ensured.

7. How long we keep data

We apply data minimisation and do not keep personal data longer than necessary.

  • User account data: retained while the account is active and for the period necessary to close the account, resolve technical matters or meet project obligations. When access is no longer needed, the account will be deactivated and the user will no longer be able to log in. Personal data that are no longer necessary will be deleted or anonymised. Any limited data that must be retained as project evidence will be stored separately, with restricted access, for the applicable retention period.
  • Technical logs and security data related to the pilot activities: retained until 31 December 2027, that is, for 12 months after the end of the project, and deleted or anonymised thereafter, unless a longer retention period is necessary to investigate a security incident, establish, exercise or defend legal claims, or preserve specific evidence required for an audit or verification.
  • Technical logs and security data generated through continued use of the platform after the end of the project: retained in accordance with the applicable Moodle log-retention settings and deleted or anonymised thereafter, unless a longer retention period is necessary for security, legal claims or incident investigation.
  • Pilot participation and completion records: retained for the period required under the Erasmus+ Grant Agreement and applicable law. These records may include the minimum data necessary to demonstrate that pilot activities were carried out and that participants completed the relevant learning activities. Relevant records and supporting documents are retained for five years after the final payment, or longer where a verification, audit, investigation, litigation or other claim is ongoing.
  • Availability of the platform and learning materials: the YouTHink platform and its openly licensed learning materials will remain available for at least three years after the end of the project. This does not require retention of inactive user accounts or personal data that are no longer necessary.
  • Project evaluation, participant-record, reporting and audit data: retained for the period required by the Erasmus+ Grant Agreement and applicable law. Under the current Grant Agreement, relevant records and supporting documents are retained for five years after the final payment, and longer where a verification, audit, investigation, litigation or other claim is ongoing.

When the applicable retention period expires, data will be securely deleted or irreversibly anonymised.

8. Your rights

Subject to the conditions set out in applicable data-protection law, you have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data where the conditions of Article 17 GDPR are met;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive personal data in a portable format where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with the competent data-protection supervisory authority.

Right to erasure and withdrawal of consent

You may request erasure where the conditions of Article 17 GDPR are met. This right may be limited only to the extent necessary where RIAP or the relevant project partner must retain specific records or supporting documents to comply with applicable legal requirements, respond to verification, audit or investigation requests under the Erasmus+ Grant Agreement, or establish, exercise or defend legal claims.

In these cases, only the minimum data necessary are retained, access is restricted to authorised persons, and the data are not used for unrelated learning, communication or publication purposes.

If consent is withdrawn, we will stop processing based solely on that consent, including public use of a participant’s name, image, voice, quotation, creative work or other optional content. Withdrawal does not affect processing carried out before it was withdrawn. Limited data that must be retained as project evidence may be kept only for the applicable retention period and with restricted access.

9. Cookies

The Platform uses strictly necessary cookies for session management and security, as well as preference cookies and third-party cookies associated with embedded content. Detailed information about these cookies, their purposes and duration is provided in the Platform’s Cookie Policy. These cookies are necessary for the VLE to function.

10. Contact and complaints

For questions, requests or complaints about data processed through Moodle, contact:

YouTHink Moodle administrator / Association “Viešieji interneto prieigos taškai” (VIPT), also operating internationally as the Rural Internet Access Points Association (RIAP) Legal entity code: 300618195 Registered address: S. Žukausko St. 18-30, LT-08234 Vilnius Country: Lithuania. Email: asociacija@vipt.lt. Privacy contact: asociacija@vipt.lt

You may also contact the relevant national project partner:

Country Partner Contact email
Lithuania Informaciniu technologiju institutas info@itinstitutas.lt
Portugal Instituto Politecnico de Tomar geral@ipt.pt
Slovenia Simbioza Genesis, socialno podjetje info@simbioza.eu
Italy CRHACK LAB FOLIGNO 4D ODV grafica@clf4d.eu
Switzerland Foundation Ynternet.org thanasis.priftis@ynternet.org

You have the right to lodge a complaint with the data-protection supervisory authority in the country of your habitual residence, place of work or the place of the alleged infringement. In Lithuania, the competent authority is the State Data Protection Inspectorate, L. Sapiegos St. 17, LT-10312 Vilnius, email: ada@ada.lt.

For Switzerland, complaints may also be directed to the Federal Data Protection and Information Commissioner: https://www.edoeb.admin.ch/.

11. Changes to this policy

We may update this policy where necessary to reflect changes in the VLE, project activities, legal requirements or data-processing practices. The current version and the date of the latest update will be published in Moodle.