Draft for review – text in development
This Privacy Policy and Data Protection Notice is currently being reviewed and may be updated before final approval. It should not yet be treated as the final approved policy.
Privacy Policy and Data Protection Notice
Organisation: Society for Magnetic Resonance Angiography (SMRA)
Contact: contact@society4mra.org
Draft version: 2026-08-24-draft
Last updated: 24 August 2026
1. About this Privacy Notice
The Society for Magnetic Resonance Angiography (“SMRA”, “we”, “us” or “our”) is committed to protecting personal information and handling it fairly, transparently and securely.
This notice explains:
- what personal information we collect;
- where the information comes from;
- why and how we use it;
- who may process or receive it;
- how long we retain it;
- how we protect it; and
- the rights available to individuals under applicable data-protection law.
This notice is intended to support compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, the EU General Data Protection Regulation where applicable, and other relevant privacy and electronic-communications requirements.
2. Who Is Responsible for Your Personal Information?
2.1 Data Controller
The Society for Magnetic Resonance Angiography (SMRA) is the Data Controller.
This means that SMRA decides why personal information is collected, how it is used, which information is required for membership and Society activities, who may receive it, and how long it should be retained.
Questions about this notice or the use of personal information should be sent to:
2.2 Data Processor
Empirical Cultures Ltd acts as a Data Processor for the SMRA website and member-management system.
Empirical Cultures Ltd provides website development, technical administration, member-system support, data-import functionality and related maintenance services on behalf of SMRA.
Empirical Cultures Ltd processes SMRA personal information only for the purposes of providing these services, on SMRA’s instructions and subject to appropriate confidentiality, security and data-processing requirements. SMRA remains responsible for deciding how and why member information is used.
3. Who This Notice Applies To
This notice may apply to:
- current, former and prospective SMRA members;
- conference and event participants;
- Board members, candidates and nominees;
- people submitting nominations;
- eligible voters;
- speakers, sponsors, volunteers and collaborators;
- website visitors;
- newsletter subscribers;
- people who contact SMRA; and
- other individuals whose information is processed in connection with SMRA activities.
4. Personal Information We May Collect
4.1 Identity and Contact Information
- full name;
- first name and last name;
- email address;
- username or member identifier;
- postal address, where required;
- country and city;
- telephone number, where provided; and
- preferred method of communication.
4.2 Membership Information
- SMRA or membership-system identification number;
- membership category or type;
- membership status;
- membership start, renewal or expiry information;
- registered institution or organisation;
- registered country;
- payment status or balance;
- payment type and payment date; and
- information required to determine access to member services.
Full payment-card information is normally processed by the relevant registration or payment provider. The SMRA website may receive information such as payment status, balance, payment method and payment date, rather than full card details.
4.3 Member Profile and Directory Information
- professional position or job title;
- institution or organisation;
- department;
- professional biography;
- research and professional interests;
- profile photograph and cover image;
- website and professional social-media links;
- country and city for profile-display purposes; and
- the member’s choice about appearing in the Member Directory.
4.4 Conference and Event Information
- conference and event registrations;
- attendance and participation details;
- speaker or presenter information;
- programme contributions;
- professional affiliations; and
- communications relating to events.
4.5 Nominations, Elections and Governance Information
- the name and email address of the person submitting a nomination;
- the nominee’s name and email address;
- the position for which a person is nominated;
- confirmation that the nominee has agreed to be considered;
- biographical documents and candidate statements;
- eligibility and membership-status information;
- Board and governance records;
- voting eligibility information; and
- limited technical information needed to prevent duplicate voting and protect election integrity.
4.6 Communications
- emails and messages sent to or from SMRA;
- support requests;
- newsletter subscriptions and preferences;
- responses to forms, surveys and polls; and
- records of important account or membership communications.
4.7 Website and Technical Information
- IP address;
- browser and device information;
- login and account-security information;
- website usage and diagnostic information;
- security and audit logs;
- cookie preferences; and
- information needed to operate, secure and maintain the website.
4.8 Sensitive or Special-Category Information
SMRA does not normally require sensitive or special-category personal information for standard website membership.
Where a specific SMRA activity requires such information, SMRA will identify an appropriate legal basis and provide any additional information required. Individuals should avoid including unnecessary sensitive information in biographies, uploaded documents, free-text fields or correspondence.
5. Where Personal Information Comes From
Personal information may be collected:
- directly from you when you register, complete a form, create a profile, contact SMRA or participate in an activity;
- from SMRA’s membership and registration provider, currently Dekon, or any successor provider;
- from an authorised SMRA administrator;
- from another person when they nominate you, provided they confirm that they have contacted you and that you have agreed to be considered;
- from conference or event-registration systems;
- from publicly available professional or institutional sources, where appropriate; and
- automatically through website logs, cookies and security systems.
6. Why We Use Personal Information
6.1 Membership Administration
We use personal information to:
- create and maintain membership records;
- confirm membership eligibility and status;
- create and manage website accounts;
- provide access to member-only services;
- process renewals and membership changes;
- suspend or restore website access when membership status changes;
- communicate with members about their accounts; and
- provide membership benefits and resources.
The principal lawful bases may include performance of a contract or steps connected with membership, SMRA’s legitimate interests in operating the Society, and compliance with legal obligations.
6.2 Member Profiles and Directory
We use member-provided profile information to support professional networking and communication within the SMRA community.
Inclusion in the Member Directory is optional. A member must actively choose to be included, and the directory preference defaults to “No”. Members may change or withdraw this choice through their account where available or by contacting SMRA.
The Member Directory is intended to be accessible only to authorised, logged-in SMRA members unless SMRA clearly communicates a different arrangement.
6.3 Conferences, Events and Society Activities
We use information to administer conferences, meetings, educational activities, resources, programmes, speaker arrangements and other Society activities.
6.4 Nominations, Elections and Governance
We use information to:
- receive and review nominations;
- contact nominees and proposers;
- confirm candidate and voter eligibility;
- administer elections;
- prevent duplicate voting;
- communicate election information;
- support Board appointments; and
- maintain appropriate governance records.
Access to nomination and election information is limited to authorised administrators and reviewers where reasonably necessary. Confidentiality arrangements may be specified separately for each nomination or election process.
When online voting is used, SMRA seeks to separate voter eligibility from individual vote choices. Election results may be reported in aggregate. Limited technical records may be processed to confirm eligibility, protect the integrity of the vote and prevent duplicate submissions.
6.5 Service and Administrative Communications
We may send essential communications concerning:
- account creation and password setup;
- membership status;
- security matters;
- privacy or terms updates;
- conference or event participation;
- nominations and elections; and
- other services requested by the individual.
These essential service messages are separate from optional marketing or newsletter communications.
6.6 Newsletters and Optional Communications
Where required, we will request consent before sending optional promotional or newsletter communications. Individuals can unsubscribe using the link provided in the email or by contacting SMRA.
Unsubscribing from optional communications does not prevent SMRA from sending essential account, membership, security, governance or service-related messages.
6.7 Website Operation, Security and Improvement
We use technical information to:
- operate and maintain the website;
- authenticate users;
- protect accounts and data;
- investigate errors, misuse or security incidents;
- maintain backups and audit records;
- prevent spam, fraud and unauthorised access; and
- understand and improve website performance where permitted.
6.8 Legal and Regulatory Requirements
We may use or retain personal information where necessary to:
- comply with applicable law;
- maintain financial and accounting records;
- respond to lawful requests;
- establish, exercise or defend legal claims;
- investigate complaints or disputes; and
- protect the rights, safety and security of SMRA, its members and others.
7. Lawful Bases for Processing
Depending on the activity, SMRA may rely on one or more of the following lawful bases:
7.1 Contractual Necessity
Processing may be necessary to provide membership, website accounts, events, resources or other services requested by an individual.
7.2 Legitimate Interests
Processing may be necessary for SMRA’s legitimate interests in administering the Society, supporting members, maintaining governance, protecting the website, communicating relevant information and improving services.
Where legitimate interests are used, SMRA will consider the effect on the individual’s rights and reasonable expectations.
7.3 Legal Obligation
Processing may be necessary to comply with financial, tax, regulatory, legal or other applicable obligations.
7.4 Consent
We may rely on consent for optional activities such as:
- inclusion in the Member Directory;
- certain newsletter or promotional communications;
- non-essential cookies; and
- other clearly identified optional uses.
Where consent is used, it will be requested separately and through a clear affirmative choice. Consent may be withdrawn at any time without affecting processing that took place lawfully before withdrawal.
8. Membership Synchronisation and Account Access
SMRA may receive updated membership lists from its membership provider and use them to synchronise the website member database.
Membership access may be enabled, suspended or restored based on official membership information received from the membership provider, including whether the applicable membership balance has been settled.
This process applies SMRA’s membership rules; it does not independently decide whether someone should be a member. If you believe that your membership or website-access status is incorrect, please contact contact@society4mra.org.
When access is suspended, SMRA may retain the account and profile for a limited period so that records can be corrected or access can be restored without requiring the member to repeat the entire onboarding process.
9. Who We Share Personal Information With
Personal information may be disclosed to or processed by:
- authorised SMRA Board members, administrators and staff;
- Empirical Cultures Ltd, as the website and member-system Data Processor;
- Dekon or another membership and registration provider;
- website-hosting, cloud, backup and security providers;
- transactional-email and newsletter providers, including services such as Brevo and Mailchimp where used;
- conference, event and registration providers;
- payment providers and financial institutions;
- professional advisers, auditors, insurers or legal representatives;
- regulators, authorities or law-enforcement bodies where legally required; and
- other registered members through the Member Directory, but only where the member has chosen to be included.
Service providers acting as processors are expected to use personal information only for the authorised service, follow appropriate instructions, maintain confidentiality and apply suitable security measures.
SMRA does not make private membership data publicly available unless this is necessary, lawful and clearly explained, or the individual has actively chosen to publish the relevant profile information.
10. International Data Transfers
SMRA is an international Society, and some service providers, members, conference partners or recipients may be located outside the United Kingdom or European Economic Area.
Where personal information is transferred internationally, SMRA will seek to ensure that an appropriate legal mechanism is available, such as:
- an adequacy decision or adequacy regulation;
- appropriate contractual safeguards;
- an approved international data-transfer agreement;
- another legally recognised safeguard; or
- a permitted exception where applicable.
Further information about safeguards used for a particular transfer may be requested by contacting contact@society4mra.org.
11. How Long We Keep Personal Information
SMRA retains personal information only for as long as it is reasonably needed for the purposes described in this notice, or as required by law.
Retention periods depend on:
- whether the individual remains an active member;
- the nature of the information;
- the purpose for which it was collected;
- legal, financial or accounting obligations;
- the need to respond to disputes or complaints;
- security and backup requirements; and
- whether the information can be anonymised instead of retained in identifiable form.
11.1 Membership Records
Active membership and account information may be retained while membership remains active and for a limited period afterwards where required for administration, renewal, reactivation, financial records, dispute resolution or legal compliance.
11.2 Member Profiles
Profile information is generally retained while the account remains active. Members may update their profile and directory preference through the website where available.
11.3 Nomination and Election Records
Nomination, candidate and voting-administration information will be retained only for the period reasonably required to complete the relevant process, confirm the result, resolve questions or challenges, maintain necessary governance records and meet legal obligations.
Information that is no longer required will be deleted, securely destroyed or anonymised where reasonably possible.
11.4 Consent and Preference Records
Records of privacy acknowledgements, consent and withdrawal may be retained for as long as reasonably necessary to demonstrate and respect the individual’s choices.
11.5 Technical Logs and Backups
Security logs, technical records and backups are retained for limited operational periods and are deleted, overwritten or anonymised in accordance with technical and security requirements.
12. How We Protect Personal Information
SMRA and its authorised processors use appropriate technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, misuse, alteration or disclosure.
Measures may include:
- encrypted website connections;
- secure password-setting and reset processes;
- role-based access controls;
- restricted administrator access;
- security monitoring and logging;
- firewall and anti-malware controls;
- software maintenance and vulnerability management;
- backups and recovery procedures;
- confidentiality requirements;
- data minimisation; and
- access limited to people who reasonably need the information.
No website or electronic system can be guaranteed to be completely secure. If SMRA becomes aware of a personal-data breach, it will investigate and take the steps required by applicable law, including notifying affected individuals or regulators where necessary.
13. Your Data-Protection Rights
Depending on the circumstances and the applicable lawful basis, you may have the following rights:
13.1 Right to Be Informed
You have the right to receive clear information about how your personal information is collected and used.
13.2 Right of Access
You may request confirmation that SMRA processes your personal information and request a copy of that information.
Members may also use available account tools to view or update certain profile information. Where appropriate, information may be supplied in a commonly used electronic format.
13.3 Right to Rectification
You may ask SMRA to correct inaccurate personal information or complete information that is incomplete.
13.4 Right to Erasure
You may request deletion of personal information where the applicable legal conditions are met. This right is not absolute, and SMRA may need to retain certain information for legal, accounting, governance, security or legitimate administrative reasons.
13.5 Right to Restrict Processing
You may ask SMRA to limit the use of your personal information in certain circumstances.
13.6 Right to Data Portability
Where this right applies, you may request certain personal information in a structured, commonly used and machine-readable format, or request its transfer to another organisation where technically feasible.
13.7 Right to Object
You may object to processing based on legitimate interests in certain circumstances. You may also object at any time to the use of personal information for direct marketing.
13.8 Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
For example, a member may withdraw permission to appear in the Member Directory. The profile will then be removed from the directory, subject to the website processing the updated preference.
13.9 Rights Relating to Automated Decision-Making
SMRA does not intend to make solely automated decisions that produce legal or similarly significant effects without appropriate safeguards.
The website may automatically apply SMRA’s existing membership rules to enable or suspend access based on official membership-status information. Individuals may contact SMRA to request review or correction of the underlying information.
13.10 Exercising Your Rights
To exercise a data-protection right, contact:
Please describe your request clearly. SMRA may need to verify your identity before releasing or changing personal information. Requests will be handled within the period required by applicable data-protection law.
14. Cookies and Similar Technologies
The SMRA website uses cookies and similar technologies where necessary for:
- website operation;
- account login and authentication;
- security;
- session management;
- user preferences; and
- website performance and analytics where enabled.
Strictly necessary cookies may be used without optional consent where permitted by law. Non-essential cookies will be described and, where required, used only after the visitor has made an appropriate choice.
Further information is available in the SMRA Cookie Policy.
15. External Links and Third-Party Services
The SMRA website may contain links to external websites, registration platforms, conference services, social-media services or other third-party resources.
Those third parties may operate under their own privacy policies and terms. SMRA is not responsible for the privacy practices of an external service that acts independently as a separate Data Controller.
16. Children’s Information
The SMRA website and membership services are primarily intended for adults and professionals in medical imaging, research, clinical practice and related fields.
SMRA does not knowingly seek to collect unnecessary personal information from children. Anyone under the age required to provide valid consent in their jurisdiction should contact SMRA before creating an account or submitting personal information.
17. Complaints
If you have a concern about how SMRA uses your personal information, please contact us first so that we have an opportunity to investigate:
You may also have the right to complain to the Information Commissioner’s Office in the United Kingdom or to the relevant data-protection supervisory authority in your country.
Information about making a UK data-protection complaint is available from the Information Commissioner’s Office:
ICO – Make a Complaint.
18. Changes to This Notice
SMRA may update this Privacy Policy and Data Protection Notice when:
- website or membership services change;
- new systems or providers are introduced;
- data-protection requirements change;
- SMRA changes how personal information is used; or
- clarification is required.
The current version and last-updated date will be displayed at the top of this page. Where a change is material, SMRA may also notify affected members through the website, their account or email.
19. Related Documents
20. Contact Us
Questions, requests or concerns about this notice or the use of personal information should be sent to:
Society for Magnetic Resonance Angiography (SMRA)
Email: contact@society4mra.org
Document status: Draft for review
This text is in development and is being reviewed. The final approved version may include additional details or amendments.