1. Purpose and controller
This Privacy Notice explains how MSK Regen uses personal data through IAMRegen. It applies to applicants, members, fellows, students, speakers, faculty, authors, reviewers, committee members, event attendees, website visitors, Case MDT users, contacts, suppliers, sponsors and other participants.
The controller is MSK REGEN, a charitable incorporated organisation registered in England and Wales under charity number 1211400.
Contact details:
- Privacy contact: [email protected]
- Address: MSK House, London Road, Silk Willoughby, Sleaford, Lincolnshire NG34 8NY, United Kingdom
- Telephone: 0330 001 0048
We use IAMRegen and I AM Regen as programme names. MSK Doctors Ltd, Professor Paul Lee's clinical practices and other separate organisations are not automatically joint controllers of IAMRegen data. We share data with a separate organisation only where a lawful, disclosed arrangement exists.
2. Laws and international scope
We apply the UK GDPR and Data Protection Act 2018 as amended, including by the Data (Use and Access) Act 2025. The EU GDPR may also apply where we offer Services to people in the European Economic Area or monitor their behaviour. Other local privacy laws may provide additional rights.
Where a non-UK law applies, we will provide any required local information, representative or supplement. Mandatory local rights are preserved.
3. Personal data we collect
Depending on the relationship, we may collect:
- identity and contact data, including name, title, date of birth where necessary, email, telephone, address, country and preferred language;
- Account and authentication data, including username, password hash, Google sign-in identifier, access records and acceptance history;
- professional and academic data, including role, speciality, employer, institution, biography, qualifications, registration number, ORCID, publications, affiliations, insurance or credential-verification material;
- application and membership data, including statements, category, decisions, status, benefits, participation, renewals and conduct records;
- transaction data, including Fees, invoices, refunds, currency, billing address, payment status and limited card metadata supplied by the payment provider;
- event data, including registration, attendance, accessibility and dietary requirements, badge information, travel or visa-letter details, images, audio, video and participation;
- publishing and scientific data, including Submissions, peer review, authorship, affiliations, conflicts, funding, Delphi responses, contribution records and correspondence;
- profile and User Content, including photographs, directory choices, comments, messages, uploads and communications;
- Case MDT administrative data and genuinely anonymised case material. Identifiable or pseudonymised patient information is prohibited under the standard Service;
- technical and usage data, including IP address, device, browser, approximate location, log-in activity, security logs, cookie choices, page interactions and diagnostic records;
- communications, enquiries, complaints, moderation reports, reviews and support records;
- safeguarding, fraud and compliance information where necessary and lawful; and
- information from public professional registers, institutional websites, referees, co-authors, event partners and other authorised sources.
We do not intentionally collect patient-identifiable data through the standard Case MDT. We do not seek criminal-offence data unless a specific lawful process requires it.
4. Special-category data
Special-category data may include health information in accessibility or dietary requests, diversity information, or information incidentally included in submitted material.
We process special-category data only where an Article 9 condition and an Article 6 lawful basis apply. Depending on context, this may include explicit consent, substantial public interest with required safeguards, legal claims, research with safeguards or another condition provided by law.
Accessibility and dietary health information should be limited to what the event team needs and will be shared only with relevant staff or providers. Consent can be withdrawn, although this may affect our ability to provide the requested adjustment.
Patient health data must not be submitted under the general Case MDT. An exceptional approved pathway requires a separate data assessment and agreement.
5. How we use data and our lawful bases
| Purpose | Typical data | Main UK/EU GDPR lawful basis |
|---|---|---|
| Create and secure Accounts | Identity, contact, authentication, logs | Contract; legitimate interests in secure administration |
| Assess eligibility and verify credentials | Application, professional and academic data | Steps towards/performing a contract; legitimate interests in integrity and safety |
| Administer membership and benefits | Membership, participation, status, communications | Contract; legitimate interests in programme administration |
| Process Fees, refunds and accounting | Transaction, identity and billing data | Contract; legal obligation; legitimate interests in fraud prevention |
| Operate events and provide adjustments | Registration, attendance and necessary accessibility data | Contract; legitimate interests; explicit consent or another Article 9 condition where required |
| Run consensus and Delphi activities | Responses, identity, conflicts, contribution records | Contract; legitimate interests in scientific collaboration; consent where a research protocol requires it |
| Assess and publish Submissions | Manuscripts, authors, reviewers, affiliations and disclosures | Contract; legitimate interests in scholarly publishing; consent where specifically required |
| Operate public profiles and directories | Selected profile fields and photograph | Consent or another clearly stated lawful basis; legitimate interests for limited professional listings where lawful |
| Provide Case MDT professional discussion and administration | Clinician identity, booking, communication and effectively anonymised case material | Contract; legitimate interests in administering a secure professional service. Patient personal data are prohibited under the standard Service |
| Moderate Content and protect users | User Content, reports, logs, conduct and security data | Legitimate interests; legal obligation; legal claims |
| Respond to enquiries, rights and complaints | Contact, correspondence and verification data | Legitimate interests; legal obligation; contract |
| Send core service communications | Contact, membership, event and transaction data | Contract; legitimate interests; legal obligation |
| Send optional news and marketing | Contact and preference data | Consent where required; legitimate interests where law permits and rights are respected |
| Improve and evaluate Services | Usage, feedback, aggregated and anonymised data | Legitimate interests; consent for optional analytics cookies |
| Prevent fraud and comply with law | Identity, payment, logs, sanctions and relevant compliance data | Legal obligation; legitimate interests; legal claims |
Where we rely on legitimate interests, we consider necessity, reasonable expectations and impact. Individuals may object where the law provides that right.
6. Sources of data
We obtain data directly from individuals and from organisations acting for them. We may also receive data from:
- professional and academic registers;
- institutions, employers, referees and sponsors;
- co-authors, corresponding authors and project leads;
- payment, authentication, event and communications providers;
- publicly available institutional or publication sources; and
- security, fraud-prevention and legal sources.
Where Article 14 UK/EU GDPR applies, we will provide the required information within the applicable period unless a lawful exception applies.
7. Required and optional information
Fields will indicate where information is required. Without essential identity, eligibility, payment or contact data, we may be unable to enter or perform the contract. Public profile, marketing, testimonial and optional demographic information is voluntary unless a separate programme lawfully requires it.
8. Public profiles, authorship and recordings
Public directory information is controlled through clear visibility choices. Users should publish only professional information they are comfortable making globally accessible. Public information may be indexed, copied or cached by third parties beyond our control.
Names, affiliations, contributor roles and disclosures associated with formal publications or consensus outputs form part of the scientific record and may be retained indefinitely.
Events may be recorded as explained in the Terms and event notice. We distinguish general audience recording from featured promotional use and obtain separate permission where required.
9. Marketing and sponsor communications
Operational messages about an Account, payment, safety, event or membership are not optional marketing where they are necessary to provide the Service.
Optional newsletters, offers and sponsor marketing will be sent only where permitted. Every electronic marketing message will provide a straightforward opt-out. Marketing consent can be withdrawn at any time without affecting core membership.
We do not sell personal data or give member contact lists to sponsors for their independent marketing without a valid, separately explained permission.
10. Sharing personal data
We may share the minimum necessary data with:
- authorised trustees, staff, volunteers, committee members, editors, reviewers and faculty who need it for their role;
- hosting, software, security, authentication, email, customer-support, video and infrastructure providers;
- Stripe or another payment provider and professional advisers, accountants and auditors;
- venues, event, badge, accessibility, catering and travel-letter providers;
- publishers, repositories, indexing services and research collaborators under appropriate arrangements;
- regulators, courts, law enforcement, safeguarding bodies and authorities where required or lawful;
- insurers and legal advisers in relation to claims; and
- a successor organisation receiving IAMRegen activities, subject to charity law, confidentiality and data-protection safeguards.
We use processor contracts where required. Access is role-based and recipients may use data only for the authorised purpose unless they are an independent controller whose role has been disclosed.
11. International transfers
Our international programme and providers may involve access or transfers outside the United Kingdom or EEA. Where transfer restrictions apply, we use an approved mechanism, such as:
- a UK or EU adequacy regulation or decision;
- the UK International Data Transfer Agreement or UK Addendum;
- EU Standard Contractual Clauses;
- another legally permitted safeguard or derogation; and
- supplementary technical and organisational measures where appropriate.
Individuals may request information about the relevant safeguard, subject to protection of security and commercial information.
12. Retention
We retain data only for as long as reasonably needed for the purpose, legal obligations, disputes, safeguarding, scientific integrity and the charitable record. Our operating schedule is:
| Record | Standard retention approach |
|---|---|
| Active Account and membership record | For the relationship, then normally 6 years |
| Contract, acceptance, invoice, payment and refund record | Normally 6 years after the relevant financial or contractual period |
| Unsuccessful or abandoned application | Normally 12 months, unless a dispute, safeguarding reason or shorter request applies |
| Credential source document | Delete or securely restrict normally within 90 days after verification; retain the verification outcome and audit record up to 6 years |
| Event registration and attendance | Normally 6 years; accessibility health details removed sooner when no longer needed |
| General event footage | Normally up to 5 years unless selected for the permanent charitable or scientific archive; featured promotional material follows its licence and privacy basis |
| Formal publication, authorship, conflicts and scientific record | Indefinitely where needed to preserve the scholarly record |
| Delphi response data | According to the protocol and publication record, ordinarily at least 10 years after publication where research governance supports it |
| Support and complaint record | Normally 3 years; up to 6 years for contractual, conduct or legal matters |
| Security and access logs | Normally 12 months, longer where needed for an incident or legal claim |
| Marketing record | Until opt-out or inactivity review; a minimal suppression record may be kept to honour the opt-out |
| Case MDT acknowledgement, administrative record, Opinion and Discussion Summary | Normally 6 years; genuinely anonymised learning material may be retained longer |
| Accidental patient-identifiable upload | Quarantine only as long as needed to secure, investigate, notify and delete; incident records retained as legally appropriate |
We may vary a period where law, grant, insurer, research protocol, litigation hold, safeguarding or archival duty requires. Backups are overwritten on controlled cycles.
13. Security
We use proportionate technical and organisational measures, including access controls, authentication, encryption where appropriate, backups, logging, processor diligence, confidentiality duties, incident response and staff training.
No system is completely secure. Users must protect credentials, use approved channels and avoid uploading information not required for the Service.
If a personal-data breach creates a legally reportable risk, we will notify the appropriate authority and affected individuals within the required timeframe.
14. Artificial intelligence, analytics and automated decisions
We may use automated tools for security, fraud detection, spam, search, transcription, accessibility, duplicate detection, analytics or administrative assistance. Human review remains available for decisions materially affecting membership, scientific merit, professional status or Content sanctions, unless a separate notice lawfully explains otherwise.
We do not make a solely automated decision producing legal or similarly significant effects without a lawful basis, required information and safeguards.
We may use genuinely anonymised and aggregated data to evaluate and develop services, including artificial-intelligence-assisted systems. We will not use identifiable patient data or confidential unpublished material to train a general-purpose model without a separate lawful basis, contractual authority, security review and appropriate notice.
15. Individual rights
Subject to applicable law and exemptions, individuals may have rights to:
- be informed;
- access personal data;
- correct inaccurate data;
- erase data;
- restrict processing;
- object, including an absolute right to object to direct marketing;
- receive or transfer certain data;
- withdraw consent without affecting earlier lawful processing;
- obtain safeguards relating to significant automated decisions; and
- complain to a supervisory authority.
Requests should be sent to [email protected]. We may verify identity and clarify a request. We normally respond within one month under UK/EU GDPR, subject to lawful extensions.
Rights are not absolute. For example, we may retain information needed for legal obligations, claims, safety, freedom of expression, research safeguards or the integrity of a published scientific record.
16. Data-protection complaints, regulators and representatives
A data-protection complaint may be sent to [email protected] with the subject line Data protection complaint, or by post to the address in section 1. Please describe the processing complained of, relevant dates, the outcome sought and enough information for us to identify the relevant records. We may ask for proportionate identity verification.
We will acknowledge a data-protection complaint within 30 days, investigate it without undue delay, keep the complainant appropriately informed and communicate the outcome. We will keep an internal record of the complaint, relevant investigation, decision and communications. These steps do not require a person to complain to us before approaching a regulator where the law permits a direct complaint.
In the United Kingdom, individuals may complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or telephone 0303 123 1113. We ask individuals to contact us first where comfortable so that we can try to resolve the matter.
People in the EEA may complain to the supervisory authority in their country. Because IAMRegen actively offers Services to people in the EEA, MSK Regen must appoint and publish an EU GDPR Article 27 representative unless a documented legal assessment confirms an exemption. The appointed representative's details must be inserted on the live Privacy Notice before processing for which appointment is required.
If the EU Digital Services Act applies to the Platform as an intermediary service, the separately appointed Article 13 DSA legal representative and regulatory point of contact must also be published.
17. Children
The Services are not directed to children and Accounts are restricted to people aged 18 or over. This contractual restriction is not treated as a substitute for any child-access assessment or age-assurance measure required by online-safety law. If we learn that a child supplied data in breach of this restriction, we will take appropriate steps to close the Account and delete or lawfully retain the data.
18. Changes and contact
We may update this Notice to reflect changes in law or practice. Material changes will be brought to affected individuals' attention where appropriate. The version and date will be shown.
Questions, objections and rights requests should be sent to [email protected].
MSK REGEN — registered charity 1211400. MSK House, London Road, Silk Willoughby, Sleaford, Lincolnshire NG34 8NY, United Kingdom. Questions: [email protected].
