Privacy Policy

Last updated 20 July 2026. Applies to the IAITI website and Member Portal.

1. Who we are

The International Association of Immersive Technology Innovation ("IAITI", "we", "us") is the data controller for personal data collected through this website and the Member Portal. For any question about this policy or to exercise your rights below, contact us at privacy@iaiti.org.

2. What we collect

When you register for a member account, we collect:

  • Your name and email address (required)
  • A securely hashed password — we never store or can see your actual password
  • Institution, country, Special Interest Group, and a short bio (optional, provided by you)
  • Account activity we need for security — sign-in timestamps, IP address on sign-in/registration, and similar technical logs

We don't collect payment details, government IDs, or any special category data.

3. Why we process it, and on what legal basis

  • To create and run your member account — necessary to perform our membership agreement with you (Art. 6(1)(b) GDPR).
  • To keep the portal secure (login attempt tracking, lockouts, audit logs) — our legitimate interest in preventing abuse (Art. 6(1)(f)).
  • To show your profile in the member directory — only with your explicit, opt-in consent (Art. 6(1)(a)), which you can withdraw at any time from Account Settings.

4. Who we share it with

We don't sell or share your data with advertisers. Verification and password-reset emails are sent through IAITI's own email provider acting purely as a message carrier (a data processor) — it does not use your data for its own purposes. If you opt in to the member directory, your name, institution, country, SIG, and bio (never your email or password) are visible to other signed-in members only.

5. How long we keep it

We retain your account data for as long as your membership is active. If you delete your account, your personal data is removed immediately, except for minimal security log entries (which are stripped of your name/email but keep an anonymous record that an event occurred, for fraud and abuse prevention).

6. Your rights

Under the GDPR, you have the right to:

  • Access the data we hold about you — download it anytime from Account Settings.
  • Rectify inaccurate data — edit your profile anytime.
  • Erase your data — delete your account anytime from Account Settings.
  • Port your data to another service — the export is a plain, structured JSON file.
  • Withdraw consent for directory visibility at any time, without affecting your membership.
  • Object to processing based on our legitimate interest.
  • Lodge a complaint with your national data protection supervisory authority if you believe your data has been mishandled.

7. Security

Passwords are hashed with bcrypt and never stored in plain text. Sessions use signed, HTTP-only cookies. Repeated failed sign-in attempts temporarily lock an account. Password-reset and email-verification links are single-use, expire quickly, and are stored as one-way hashes, not as plain, reusable links.

8. Cookies

We use a single essential session cookie to keep you signed in. It is not used for advertising or cross-site tracking, and no consent banner is required for it under EU cookie rules because it's strictly necessary for the service you've requested.

9. Changes to this policy

If we make material changes, we'll update the date at the top of this page. Your continued use of the Member Portal after a change constitutes acceptance of the updated policy.