Privacy policy
We take your privacy seriously. This page tells you exactly what data this conference app collects, why we need it, how long we keep it and what rights you have.
Because the conference takes place in the European Union and the app is aimed at attendees there, the EU General Data Protection Regulation (GDPR) applies to this processing under its Art 3(2), even though the controller is established in Canada.
1. Data controller
LabMed Alliance Inc., 373, Jean-Baptiste-Laperche, L'Assomption, Québec J5W 0J5, Canada (corporation number 1491582-8) — see the imprint for full details.
For data-protection questions, please contact:
- E-Mail:
experts@labmedalliance.com
Enquiries from within the EU can also be addressed to our Chief Information Officer, Prof. Dr. Janne Cadamuro, who is based in Salzburg, Austria, at the same e-mail address. We have not appointed a data protection officer — the conditions of Art 37 GDPR that would require one are not met by this processing.
2. What this app is — and what it is not
This app is the companion to the conference: programme, speakers, abstracts, sponsors, Q&A, live polls, session ratings and a small leaderboard.
It is not the registration system. Registration, invoicing and badge production are handled by the conference secretariat, MZ Events srl (Milan), on the conference website. This app receives no registration data from them — no names, no e-mail addresses, no invoices. Your access token is a random code printed on your badge. Inside the app it is linked to your nickname, your participant group (delegate, speaker, industry) and the time of its first and last use — not to your name; only the secretariat, which prints the badges, could tell which badge carries which code (see section 5).
3. What data we collect and why
| Data | When | Purpose | Legal basis |
|---|---|---|---|
| Nickname (chosen by you on first token sign-in) | When you redeem a QR token | Display your name on questions, ratings, leaderboard | Art 6(1)(b) — performance of the event |
| Username + password (if you have an account — speakers, chairs, organisers) | When you sign in via /accounts/login/ | Authentication | Art 6(1)(b) |
| Affiliation (department, institution, city, country) | Optional, in your profile | Show context next to your questions and on the speakers list | Art 6(1)(f) — you decide whether to fill it in; leaving it empty costs you nothing |
| Questions you post in Q&A | Each time you submit | Display to other attendees, chair, speaker | Art 6(1)(b) |
| Up-votes on questions | Each tap | Sort questions by popularity | Art 6(1)(b) |
| Poll answers | When you vote in a live poll | Multiple-choice votes: aggregate result chart shown to the room. Open-text answers: your answer is shown to the room word for word or as a word cloud, always without your nickname; if the chair releases the results, other attendees see the same in the app | Art 6(1)(b) |
| Session ratings (4 dimensions + optional comment) | When you rate | Quality feedback to the organisers; shared with speakers only in aggregate | Art 6(1)(f) — our interest in the scientific quality of the programme |
| Survey answers | When you submit a survey | Feedback for organisers (programme, venue, etc.). Some surveys can be answered without signing in; for those we keep a counter per IP address for one hour to block repeat submissions | Art 6(1)(f) — same |
| E-mail address in a survey (optional) | Only if you say you would come back and choose to enter it | One message to let you know about the next event — nothing else, no newsletter | Art 6(1)(a) — consent; you can withdraw it any time by e-mail |
| QR check-ins at sponsor booths and posters, poster votes | When you scan a booth or poster code | Activity points and the audience poster award; which booth or poster you scanned and when is visible only to you and the organiser, never to the sponsor | Art 6(1)(f) — legitimate interest |
| Activity score, badges (gamification) | Derived automatically | Make participation a bit more fun; show your own progress on /me/ and on the leaderboard | Art 6(1)(f) — legitimate interest |
| Server log files (IP, user agent, URL, timestamp, status) | On every HTTP request | IT security, debugging, abuse defence | Art 6(1)(f) — legitimate interest |
| Sign-in records (username, IP, user agent, timestamp) | On every sign-in attempt, successful or failed | Brute-force protection (account lockout after 10 wrong tries) and IT security | Art 6(1)(f) |
We do not use any analytics, advertising, A/B-testing or social tracking tools. There are no third-party cookies. The only cookies set by this app are technical: the session cookie (valid for 14 days, so you do not have to scan your token again every morning), the CSRF token and, if you switch the language, a language preference. If you dismiss an announcement in the banner, your browser remembers that locally (localStorage): only the announcement's identifier and timestamp, nothing is sent to us. So that a page stays where you left it when you go back, your browser remembers the scroll position per page (sessionStorage) — only until you close the tab, and nothing is sent to us.
Everything the app loads — stylesheets, fonts, scripts, images — comes from our own server. There are no content delivery networks, no web fonts fetched from elsewhere, no embedded maps or videos. Your browser never contacts a third party while you use this app.
The one exception is workshops with limited seats: for those, the programme links to an external registration form. The link opens only when you click it and leaves the app. The form is covered by its operator's own privacy notice; we do not learn whether you signed up there.
4. Speakers, chairs and committee members
If you appear in the programme, the app shows a profile of you: name, academic title, affiliation, position, country, a short biography, a photo, your pronouns if you provided them, and — where you gave them to us — links to your LinkedIn profile, ORCID record or website. This is the information you or your institution provided to the organisers when your contribution was accepted, as published on the conference website https://d42026.com. A CV you sent us is not published: only the organising team and the chairs of your session can open it, to prepare your introduction. Where a biography was missing, the organising team compiled a short one from your publicly available professional profiles (institution website, publication record); such biographies are published only after you have approved them, and are replaced by your own text as soon as you send us one.
The legal basis is Art 6(1)(b) GDPR for speakers and chairs (presenting your contribution is what you agreed to do) and Art 6(1)(f) for committee members (the attendees' interest in knowing who put the programme together). Your profile, like the programme, is visible to anyone who opens the app — no sign-in is required for it — and only once it has been released by you. If you want anything corrected, removed or your profile hidden altogether, one e-mail to the address above is enough — we will do it the same day during the conference.
The same applies to authors named on abstracts and posters shown in the app.
5. Recipients of your data
Your data is processed by:
- LabMed Alliance Inc. as the organiser and the conference committee members listed in the app.
- Uberspace (Jonas Pasche, Mainz, Germany) as our hosting provider and data processor under Art 28 GDPR. A data processing agreement was concluded on 20 May 2026. Uberspace processes data only on our documented instructions.
- MZ Events srl (Milan, Italy), the conference secretariat, which has an organiser login to this app for one task: generating the access tokens and printing them on the badges. It acts on our instructions; the written data processing agreement required by Art 28 GDPR is being concluded. It does not receive your nickname, questions, votes or ratings for its own purposes.
There are no other recipients. In particular, we use no content delivery network, no advertising network and no analytics provider.
Your nickname and your questions are visible to other attendees of the event; the programme, speaker profiles and the leaderboard can be opened without signing in. Session ratings are shown to other attendees only as averages. Individual ratings, free-text comments on ratings and survey answers are visible only to the organiser — who can see which nickname gave which rating. Answers to open-text live polls are the exception: they are meant for the room and appear there without your nickname (see the table above), so do not write anything into them you would not say aloud.
6. Transfers to third countries
The app, its database and its automated backups are stored on servers in Germany; the offline backup copy is held by the organising team in Salzburg, Austria. Your data is not sold, rented or passed on to third parties.
Because LabMed Alliance Inc. is established in Canada, members of its board may access this data from Canada in order to run the conference. LabMed Alliance Inc. is subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) as an organisation processing personal information in the course of commercial activities. For such organisations the European Commission has determined an adequate level of protection — adequacy decision 2002/2/EC of 20 December 2001, confirmed in the Commission's review of January 2024 — which is the legal basis for these accesses under Art 45 GDPR.
Apart from this, no data is transferred to a third country.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data, nickname, affiliation | Deleted as part of the post-conference wrap-up, at the latest 6 months after the event ends (i.e. by 12 March 2027) — earlier if you ask us to |
| Questions, up-votes, polls, ratings, surveys (linked to your nickname) | Same point in time — afterwards anonymised and kept only in aggregate form for the conference report |
| E-mail address entered in a survey | Stored only in this app, visible to the organising team; deleted as soon as the message about the next event has been sent, at the latest when the app is taken offline; earlier on request |
| Speaker, chair and committee profiles | Remain visible as the programme archive until the app is taken offline, at the latest 6 months after the event; removed earlier on request |
| Server log files (web server access log) | Rotated automatically by the hosting platform; we do not evaluate them beyond IT security and do not archive them |
| Application log (systemd journal of the app service) | Deleted automatically after 7 days |
| Sign-in records (username, IP, user agent, timestamp) | Deleted automatically after 7 days by a nightly job; a lockout itself expires after 1 hour |
| Token-redeem failure counters (rate limiting) | Held in volatile memory only, expire after 15 minutes |
| Database backups | 48 hourly plus 30 daily snapshots, then deleted automatically |
| Media backups (images uploaded by the organiser) | 8 weekly snapshots, then deleted automatically |
| Hosting provider's own backups of the server account | Kept by Uberspace for technical reasons and deleted with a delay of 7 weeks after we delete data (clause 2.3 of the data processing agreement) |
The 6-month deletion is a documented step in our conference wrap-up, carried out by hand — not an automated job. If you want your data removed before then, one e-mail is enough.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art 15),
- have inaccurate data corrected (Art 16),
- have your data deleted (Art 17),
- have processing restricted (Art 18),
- receive your data in a portable format (Art 20),
- object to processing based on legitimate interest (Art 21),
- withdraw consent at any time, without affecting the lawfulness of prior processing (Art 7(3)),
- lodge a complaint with a supervisory authority — normally the one of your country of residence or workplace. For attendees in Austria that is the Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, https://www.dsb.gv.at.
To exercise any of these rights, contact us at the address above. We will respond within one month.
9. Do you have to provide any of this?
No. Only a nickname is required to use the interactive features, and you are free to invent one. Everything else — affiliation, questions, ratings, survey answers — is voluntary, and leaving it out costs you nothing: the programme, the speaker list and all conference information stay fully readable either way.
10. Automated decision-making
We do not use automated decision-making that produces legal effects or similarly significantly affects you within the meaning of Art 22 GDPR. Your activity score and badges are calculated automatically from what you do in the app, but they influence nothing beyond your own progress display and your position on the leaderboard. If you would rather not appear on the leaderboard, tell us and we will take you off it.
11. Security
This app is served exclusively over HTTPS with HSTS, uses a restrictive Content Security Policy that permits no external sources at all, brute-force protection on sign-in and token redemption, and is built on Django's security middleware. We do not store passwords in plaintext — they are hashed with Django's PBKDF2 default.
The database is backed up automatically several times a day. Backups are stored on the same hosting infrastructure as the app itself, inside a private area readable only by the operating account, plus one offline copy held by the organising team in Salzburg, Austria. Old snapshots are pruned automatically on the schedule shown in section 7.
12. Changes
We may update this policy when functionality changes or new legal requirements apply. The "last updated" date below tells you when it was last revised.
Last updated: 9 September 2026.