Privacy notice
Who we are
IIoET is the trading name of IIOET Limited, a private company limited by guarantee registered in England and Wales(company number 17500376), registered office DOCK 3, Pioneer Science & Technology Park, Leicester, LE4 5JU, United Kingdom. We are the controller of the personal data described here.
Our privacy contact is James Martin, reachable at contact@iioet.org(choose "Privacy" as the subject). This contact also acts as our Data Protection Officer for Singapore and our person in charge of the protection of personal information for Quebec.
If you are in the European Union, you can contact us directly at the same address about any matter under the EU GDPR.
One standard for everyone
We apply the same privacy standard to every visitor and member, wherever they are. The annexes below add the rights, regulators and contacts specific to each market we serve.
What we collect and why
| When | What | Why and lawful basis | How long |
|---|---|---|---|
| You browse the site | IP address and request details in security and server logs. No tracking cookies; analytics are cookieless and aggregate. | To keep the site secure and working (legitimate interests) | 30 days for logs |
| You use a form | Your name, email, the details you give us, and any file you upload | To respond to you (legitimate interests, or steps before a contract) | Two years after our last contact |
| You submit a paper | Author details and manuscript | To review and, if accepted, publish your work (contract) | Rejected: two years. Published: permanently, as part of the published record |
| You ask for news | Your email and consent record | To send news you asked for (consent, which you can withdraw at any time) | Until you unsubscribe |
| You become a member | Profile, grade, membership, CPD and payment records | To provide your membership (contract) and meet our legal obligations | Membership plus six years |
| You publish with us | Name, post-nominals, affiliation, biography | To credit your work (contract) | As long as the work is published |
Who we share it with
We use a small number of service providers to run IIoET. Every one is listed on ourdata processors page with what it does, where it processes data and the safeguards in place. We never sell personal data.
International transfers
Some providers process data outside the UK and the EU, mainly in the United States. Each transfer relies on the UK International Data Transfer Addendum or the UK-US data bridge, and on the EU Standard Contractual Clauses or the EU-US Data Privacy Framework, as recorded on the data processors page.
Payments
Card payments are taken by Stripe, and Direct Debits by GoCardless, on their own hosted pages. We never see or store your full card or bank details.
Your rights
You can ask to see, correct, delete or move your data, object to or restrict how we use it, and withdraw consent at any time. Send requests to contact@iioet.org or use thecontact form. We answer every request within 30 days. We honour Global Privacy Control signals.
Security and breaches
We protect data with access control, multi-factor authentication and encryption in transit. If a breach puts your data at risk, we will notify the relevant regulators within their deadlines (the shortest being 72 hours) and tell you where required.
Age
Membership is open to people aged 18 and over. We do not knowingly collect data from children.
Complaints
Please contact us first. You can also complain to the regulator in your market, listed below.
Annex: United Kingdom
UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Regulator: the Information Commissioner's Office, ico.org.uk.
Annex: Spain and the European Union
EU GDPR and the Ley Orgánica 3/2018 (LOPDGDD). Regulator: the Agencia Española de Protección de Datos, aepd.es, or the authority in your EU country.
Annex: United States
Where a state privacy law applies to us, you have the rights it gives, including to know, delete, correct and opt out. We do not sell or share personal data for targeted advertising, and we honour Global Privacy Control.
Annex: Singapore
Personal Data Protection Act 2012. Our Data Protection Officer is James Martin,contact@iioet.org. Regulator: the Personal Data Protection Commission, pdpc.gov.sg.
Annex: Australia
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 and the Notifiable Data Breaches scheme. Regulator: the Office of the Australian Information Commissioner, oaic.gov.au.
Annex: Canada
PIPEDA and, for Quebec residents, Law 25. Our privacy officer is James Martin,contact@iioet.org. We assess transfers of Quebec residents' data outside Quebec. Regulators: the Office of the Privacy Commissioner of Canada, priv.gc.ca, and the Commission d'accès à l'information du Québec, cai.gouv.qc.ca.