Legal

Privacy notice

Last updated: 7 October 2026

Who we are

IIoET is the trading name of IIOET Limited, a private company limited by guarantee registered in England and Wales(company number 17500376), registered office DOCK 3, Pioneer Science & Technology Park, Leicester, LE4 5JU, United Kingdom. We are the controller of the personal data described here.

Our privacy contact is James Martin, reachable at contact@iioet.org(choose "Privacy" as the subject). This contact also acts as our Data Protection Officer for Singapore and our person in charge of the protection of personal information for Quebec.

If you are in the European Union, you can contact us directly at the same address about any matter under the EU GDPR.

One standard for everyone

We apply the same privacy standard to every visitor and member, wherever they are. The annexes below add the rights, regulators and contacts specific to each market we serve.

What we collect and why

WhenWhatWhy and lawful basisHow long
You browse the siteIP address and request details in security and server logs. No tracking cookies; analytics are cookieless and aggregate.To keep the site secure and working (legitimate interests)30 days for logs
You use a formYour name, email, the details you give us, and any file you uploadTo respond to you (legitimate interests, or steps before a contract)Two years after our last contact
You submit a paperAuthor details and manuscriptTo review and, if accepted, publish your work (contract)Rejected: two years. Published: permanently, as part of the published record
You ask for newsYour email and consent recordTo send news you asked for (consent, which you can withdraw at any time)Until you unsubscribe
You become a memberProfile, grade, membership, CPD and payment recordsTo provide your membership (contract) and meet our legal obligationsMembership plus six years
You publish with usName, post-nominals, affiliation, biographyTo credit your work (contract)As long as the work is published

Who we share it with

We use a small number of service providers to run IIoET. Every one is listed on ourdata processors page with what it does, where it processes data and the safeguards in place. We never sell personal data.

International transfers

Some providers process data outside the UK and the EU, mainly in the United States. Each transfer relies on the UK International Data Transfer Addendum or the UK-US data bridge, and on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as recorded on the data processors page.

Payments

Card payments are taken by Stripe, and Direct Debits by GoCardless, on their own hosted pages. We never see or store your full card or bank details.

Your rights

You can ask to see, correct, delete or move your data, object to or restrict how we use it, and withdraw consent at any time. Send requests to contact@iioet.org or use thecontact form. We answer every request within 30 days. We honour Global Privacy Control signals.

Security and breaches

We protect data with access control, multi-factor authentication and encryption in transit. If a breach puts your data at risk, we will notify the relevant regulators within their deadlines (the shortest being 72 hours) and tell you where required.

Age

Membership is open to people aged 18 and over. We do not knowingly collect data from children.

Complaints

Please contact us first. You can also complain to the regulator in your market, listed below.

Annex: United Kingdom

UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Regulator: the Information Commissioner's Office, ico.org.uk.

Annex: Spain and the European Union

EU GDPR and the Ley Orgánica 3/2018 (LOPDGDD). Regulator: the Agencia Española de Protección de Datos, aepd.es, or the authority in your EU country.

Annex: United States

Where a state privacy law applies to us, you have the rights it gives, including to know, delete, correct and opt out. We do not sell or share personal data for targeted advertising, and we honour Global Privacy Control.

Annex: Singapore

Personal Data Protection Act 2012. Our Data Protection Officer is James Martin,contact@iioet.org. Regulator: the Personal Data Protection Commission, pdpc.gov.sg.

Annex: Australia

We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 and the Notifiable Data Breaches scheme. Regulator: the Office of the Australian Information Commissioner, oaic.gov.au.

Annex: Canada

PIPEDA and, for Quebec residents, Law 25. Our privacy officer is James Martin,contact@iioet.org. We assess transfers of Quebec residents' data outside Quebec. Regulators: the Office of the Privacy Commissioner of Canada, priv.gc.ca, and the Commission d'accès à l'information du Québec, cai.gouv.qc.ca.