Privacy Policy
Last updated 20 August 2026. Applies to the IAITI website and Member Portal.
1. Who we are
The International Association of Immersive Technology Innovation ("IAITI", "we", "us") is the data controller for personal data collected through this website and the Member Portal. For any question about this policy or to exercise your rights below, contact us at privacy@iaiti.org.
2. What we collect
When you register for a member account, we collect:
- Your name and email address (required)
- A securely hashed password — we never store or can see your actual password
- Institution, country, Special Interest Group, and a short bio (optional, provided by you)
- Account activity we need for security — sign-in timestamps, IP address on sign-in/registration, and similar technical logs
We don't collect payment details, government IDs, or any special category data.
3. Conference and event attendee records
Separately from account registration, IAITI sometimes imports attendee lists from conference registrations (name, email, institution, country) to invite past attendees to become members. If you attended an IAITI conference, a record with this information may exist in our system even if you never created an account — this is processed under our legitimate interest in inviting past participants to join the association (Art. 6(1)(f)).
These records are kept for at most 24 months from import if unclaimed (i.e. you never register), after which they are automatically deleted. Registering with the same email address links and supersedes the record, at which point it's treated as ordinary account data under this policy. You can ask us to delete an unclaimed record early at any time — contact us at privacy@iaiti.org.
4. Membership applications
Since IAITI membership is by referral, joining without an existing conference registration means submitting an application at iaiti.org/join. We collect your name, email, institution, country, the type of membership you're applying for, the name of the current member who referred you, and an optional message. Naming a referrer means we process a small amount of information about someone other than you (their name) — this is necessary to verify referral-based membership and is limited to what you provide.
Applications are reviewed by an admin or director of membership under our legitimate interest in vetting new members (Art. 6(1)(f)). If approved, the application becomes part of your account data under this policy. If rejected, or never reviewed, we keep the application for up to 12 months (to allow you to follow up on a decision) before it's automatically deleted.
5. Why we process it, and on what legal basis
- To create and run your member account — necessary to perform our membership agreement with you (Art. 6(1)(b) GDPR).
- To keep the portal secure (login attempt tracking, lockouts, audit logs) — our legitimate interest in preventing abuse (Art. 6(1)(f)).
- To show your profile in the member directory — only with your explicit, opt-in consent (Art. 6(1)(a)), which you can withdraw at any time from Account Settings.
6. Who we share it with
We don't sell or share your data with advertisers. Verification and password-reset emails are sent through IAITI's own email provider acting purely as a message carrier (a data processor) — it does not use your data for its own purposes. If you opt in to the member directory, your name, institution, country, SIG, and bio (never your email or password) are visible to other signed-in members only.
7. How long we keep it
We retain your account data for as long as your membership is active. If you delete your account, your personal data is removed immediately, except for minimal security log entries (which are stripped of your name/email but keep an anonymous record that an event occurred, for fraud and abuse prevention). Conference attendee records are covered separately in Section 3, and membership applications in Section 4.
8. Your rights
Under the GDPR, you have the right to:
- Access the data we hold about you — download it anytime from Account Settings.
- Rectify inaccurate data — edit your profile anytime.
- Erase your data — delete your account anytime from Account Settings.
- Port your data to another service — the export is a plain, structured JSON file.
- Withdraw consent for directory visibility at any time, without affecting your membership.
- Object to processing based on our legitimate interest.
- Lodge a complaint with your national data protection supervisory authority if you believe your data has been mishandled.
9. Security
Passwords are hashed with bcrypt and never stored in plain text. Sessions use signed, HTTP-only cookies. Repeated failed sign-in attempts temporarily lock an account, and public forms are rate-limited against automated abuse. Password-reset links are single-use, expire quickly, and are stored as one-way hashes, not as plain, reusable links.
10. Cookies
We use a single essential session cookie to keep you signed in. It is not used for advertising or cross-site tracking, and no consent banner is required for it under EU cookie rules because it's strictly necessary for the service you've requested.
11. Changes to this policy
If we make material changes, we'll update the date at the top of this page. Your continued use of the Member Portal after a change constitutes acceptance of the updated policy.
