Privacy Policy
Effective Date: 01.08.2025
Table of Contents
1. Who We Are
AI in Healthcare Community (AIiHC) is a nonprofit community portal built on WordPress, powered by community portal, serving health professionals and researchers interested in AI applications in healthcare. We are based in Norway and committed to data protection under both the Norwegian Personal Data Act (aligning with GDPR) and GDPR itself when handling personal data of EU/EEA residents.
2. What Personal Data We Collect & Why
We collect only what’s necessary, per GDPR principles of data minimization,
purpose limitation, and storage limitation.
a) Account Data (for registered members): Name, email, professional affiliation, institution, consent for membership.
Purpose: community access, identity, and communications.
b) Usage Data: Interaction logs, posts, profile updates, and preferences captured within BuddyBoss or WordPress.
Purpose: platform functionality and site improvement.
c) Technical Data: IP address, device type, browser, referral source, usage patterns through analytics tools.
Purpose: site performance, analytics, security.
d) Communication Data: Newsletter subscriptions or contact form submissions.
Purpose: communications and administration.
e) Cookies & Tracking: Managed via CookieYes (essential, functional, analytics, social media); users must give active consent.
3. Legal Basis for Processing
Under GDPR Article 6:
– Consent: for cookies, newsletters, optional data collection.
– Contractual necessity: for membership operations.
– Legitimate interests: for platform functionality and analytics, unless overridden by user rights.
4. Who Has Access
We only share data with:
– Admins and moderators with a legitimate role in community operations.
– Third-party service providers and hosting under Data Processing Agreements.
If data is transferred outside the EEA, it will only be to providers with EU-approved protection mechanisms (e.g., SCCs).
5. Data Retention
We retain data only as long as necessary:
– Membership data persists while the user is active plus a reasonable period after.
– Content (e.g., forum posts) remains unless deleted by users or admins.
– Technical logs and analytics are purged periodically per internal retention policy.
6. Your Rights
As a data subject, you have the right to:
– Access, correct, or update your data.
– Request erasure (“right to be forgotten”).
– Withdraw consent at any time.
– Request portability of your data.
– Object to processing based on legitimate interest.
– Lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet).
7. Security
We implement technical and organizational measures including encryption, access control, and regular reviews to protect data.
8. Children
Minimum age for consent to digital services in Norway is 13.
We do not knowingly collect data from under-13 users and will delete such data if identified.
9. Updates to This Policy
We may update this policy. Changes will be communicated via site notices or email.
The “Effective Date” will always reflect the latest revision.
10. Contact Us
For privacy-related questions or to exercise your rights, contact us at:
Email: privacy@aiihc.org