Symposed

Privacy Notice

Last updated 6 July 2026

1. Who we are

Symposed is a platform for discovering and advertising research and related project opportunities, finding collaborators and communicating with other users. Symposed is operated by Symposed ("Symposed", "we", "us" or "our").

For the personal information described in this notice, we are generally the data controller. You can contact us via our contact form.

This notice applies to symposed.org and any related web or mobile application that links to it (the "Service").

2. A very important restriction: no patient or confidential clinical data

Symposed is a collaboration and opportunity platform. It is not a clinical system, electronic health record, research database, data safe haven or approved route for transferring patient information.

You must not upload, paste, send or otherwise submit patient-identifiable information, confidential patient information, clinical records, patient images, NHS numbers, hospital numbers, identifiable case narratives, research datasets containing personal data, or confidential NHS, university or healthcare information to Symposed. This restriction applies to public posts and private messages.

If we become aware that prohibited sensitive or confidential information may have been submitted, we may restrict access to the content, preserve limited information where legally necessary, investigate, notify relevant persons or authorities where required, and delete or quarantine the content as appropriate.

3. Personal information we collect

  • Account and identity data: name, email address, account identifiers, password/authentication records handled by our authentication provider, and account status.

  • Profile and professional data: institution, university or employer, career stage, profession, specialty or interests, skills, research experience, availability, profile summary, optional profile image, LinkedIn or other professional-profile link, and similar information you choose to provide.

  • Verification data: institutional email domain, verification status and limited evidence or signals used to assess eligibility for platform verification or badges.

  • Project and application data: listings, project type, specialty/topic, experience level, location/remote status, role descriptions, authorship or contribution expectations, application statements, application status, project status and user actions.

  • Communications data: message requests, accepted or rejected messaging connections, private messages, public questions or discussion posts, support messages and service notifications.

  • Contact-sharing data: a phone number, email address or other contact detail that you voluntarily choose to share through a private message or a dedicated contact-sharing function.

  • Reviews and reputation data: reviews, ratings, reliability indicators, badges, project-completion information and information submitted by other users about a genuine collaboration.

  • Safety, complaint and moderation data: reports, supporting evidence, moderation decisions, account restrictions, appeals, legal notices and complaint correspondence.

  • Technical and security data: IP address, device/browser information, timestamps, authentication and access logs, security events, error logs and similar information needed to operate and protect the Service.

  • Usage and preference data: filters, settings, consent choices, marketing preferences and aggregate or event-level product usage information where collected lawfully.

  • Payment and transaction data if paid features are introduced: purchase, subscription and billing records. Payment-card details should normally be handled by the payment provider rather than stored directly by Symposed.

4. Where information comes from

We obtain information directly from you when you create an account, build a profile, post or apply to a project, send a message, share contact details, leave a review or contact us. We also receive information about you from other users when they review you, message you, include you in a genuine project interaction or submit a report. Technical information may be collected automatically from your device or generated by our service providers. Where you choose to provide a professional-profile link, we may use information you make available through that link for verification or moderation where this is appropriate and lawful.

5. What is public and what is private

  • Public or platform-visible content: information that the Service clearly identifies as public or visible to other users may include selected profile fields, project listings, public questions/discussions, reviews, badges and project-related status information.

  • Lister visibility: when you post a project, your profile or selected lister information may become visible through the project even if the Service does not otherwise offer a general profile-search feature.

  • Private messages: messages are not displayed publicly and are intended for the participants in that conversation. However, unless we expressly state otherwise, they are not an end-to-end encrypted clinical communications channel. Authorised personnel and service providers may access message content where reasonably necessary to operate the Service, investigate a report, protect users or the Service, comply with law, or establish, exercise or defend legal claims.

  • Contact details: where you deliberately share your own email address or phone number with another user, that recipient can view and may copy the information outside Symposed. We cannot technically control information after it has been voluntarily disclosed to another person.

  • Third-party information: you must not share another person's private contact details or personal information unless you have their permission or another lawful authority to do so.

6. Why we use personal information and our lawful bases

Purpose Examples Typical lawful basis ———————– ———————– ———————– Provide the Service Create accounts; Performance of our profiles; listings; contract with you. applications;
messaging; contact
sharing; project
status; reviews.

Verify users and Institutional-email Contract and our platform eligibility checks, verification legitimate interests in status and trust and platform anti-impersonation integrity. checks.

Operate fair-use and Application limits, Contract and our reputation features credits, badges, legitimate interests in reliability indicators, maintaining a useful anti-spam rules and and trustworthy misuse detection. marketplace.

Send service Account, security, Contract and, where communications application, message, appropriate, legitimate project and moderation interests. notifications.

Safety, moderation and Review reports, Legitimate interests complaint handling restrict content, and legal obligations investigate abuse, where applicable. handle appeals and
protect users.

Security and fraud Access logs, abuse Legitimate interests prevention prevention, account and legal obligations protection and incident where applicable. response.

Comply with law and Data rights, regulator Legal obligation and legal process requests, Online Safety legitimate interests in Act duties, court establishing, orders and legal exercising or defending claims. legal claims.

Improve and understand Aggregate usage, Legitimate interests, the Service diagnostics, testing or consent/another and product basis where required by improvement. PECR or data protection law.

Advertising Display, measure or Consent where required personalise advertising for non-essential where used. storage/access or tracking; otherwise a lawful basis permitted by applicable law.

Marketing News, launches or Consent where required promotional messages by PECR; otherwise that are not necessary another lawful basis to operate your only where permitted. account.

Paid features, if Billing, subscription Contract and legal introduced administration, refunds obligations. and accounting.

Where we rely on legitimate interests, we consider the purpose, necessity and impact on users. You may have a right to object. Where consent is our basis, you can withdraw it at any time without affecting earlier lawful processing.

7. Sensitive and special-category information

Symposed does not ask users to provide patient health information or research datasets and does not use health information for project matching or advertising. Please do not submit special-category information about another person. If you voluntarily disclose sensitive information about yourself in a profile or communication, you should understand that the visibility of that information depends on where you post it. We may remove unnecessary sensitive information and will assess any further processing under applicable law.

8. Ranking, badges, application limits and automated features

The Service may use rules, filters or scoring methods to organise projects, display beginner-friendly opportunities, apply fair-use limits, award badges, identify suspicious activity or generate reliability indicators. Criteria may change as the Service develops. At launch, Symposed does not intend to make solely automated decisions that produce legal or similarly significant effects on you. If that changes, we will update this notice and provide any information and safeguards required by law.

9. Who we share information with

  • Other users, according to the visibility of your profile, projects, applications, reviews, public posts and contact-sharing choices.

  • Technology providers that host, secure, authenticate, store or deliver the Service, such as database/authentication, hosting and email-delivery providers.

  • Analytics, advertising or consent-management providers, where enabled and lawfully configured.

  • Payment providers if paid features are introduced.

  • Professional advisers, insurers and auditors where reasonably necessary.

  • Regulators, law-enforcement bodies, courts, institutions or other recipients where disclosure is required by law or is otherwise lawful and necessary to protect rights, safety, security or the integrity of the Service.

  • A buyer, investor, successor or restructuring participant in connection with a genuine business sale, merger, financing or reorganisation, subject to appropriate confidentiality and data protection measures.

We do not sell your personal information. Some third-party providers may act as independent controllers for their own purposes, particularly advertising, payment or external services. Their own privacy information will apply to those activities.

10. Current service providers

The public Symposed site currently identifies Supabase, Vercel and Resend. Before publication, Symposed will verify the production configuration and maintain an up-to-date service-provider list. Providers may change as the Service develops.

[VERIFY AND INSERT CURRENT PROVIDER / PURPOSE / LOCATION OR LINK TO A LIVE SUBPROCESSOR LIST]

11. International transfers

Some service providers may process information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, we will use an applicable adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary measures where appropriate.

12. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including providing the Service, maintaining safety and trust, resolving disputes, responding to complaints, preventing repeat abuse, complying with legal obligations and establishing, exercising or defending legal claims.

  • Account and profile information is generally kept while your account is active and then deleted or anonymised in accordance with our internal retention schedule, subject to the exceptions below.

  • Project, application and message information may be retained for a limited period after a project, conversation or account closes where this is needed for user safety, report handling, dispute resolution or platform integrity.

  • Reports, moderation, fraud, legal and complaint records may be kept longer where necessary to document decisions, prevent repeat abuse, comply with law or manage legal claims.

  • Security and technical logs are kept for limited periods based on security and operational need.

  • Consent and preference records may be kept as evidence of the choices you made.

  • Financial or tax records for paid services may be retained for legally required periods.

  • Backups may retain deleted data temporarily until overwritten under the backup cycle.

When retention is no longer necessary, information is deleted or anonymised. Account deletion does not necessarily delete information that another user must retain in their own communications, information we must preserve by law, or content that has been lawfully anonymised so that it is no longer personal information.

13. Your data protection rights

Depending on the circumstances, you may have rights to be informed; access your personal information; correct inaccurate information; request erasure; request restriction; receive certain information in a portable format; object to certain processing; and withdraw consent where processing is based on consent. These rights are not absolute and legal exceptions may apply.

To exercise a right, via our contact form. We may need proportionate information to verify your identity. We normally respond within the time required by data protection law and may extend the response period for complex or multiple requests where the law permits and we notify you.

14. Data protection complaints

You can make a data protection complaint using [PRIVACY COMPLAINT FORM / PRIVACY EMAIL]. We will facilitate complaints, acknowledge receipt within 30 days, make appropriate enquiries, keep you informed where appropriate, and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK data protection regulator. We ask that you contact us first so we have an opportunity to investigate, but you are not required to do so.

15. Security

We use technical and organisational measures designed to protect personal information, including access controls and security measures appropriate to the nature of the Service. No internet service can guarantee absolute security. You must keep your account credentials confidential and tell us promptly if you believe your account or personal information has been compromised.

16. Children

Symposed is intended for people aged 18 and over. You must not create or use an account if you are under 18. If we reasonably believe an account belongs to a person under 18, we may restrict or close the account and take appropriate steps in relation to the information held.

17. Changes to this notice

We may update this notice when the Service, our providers or the law changes. We will update the effective date and, where a change is material, provide an appropriate notice through the Service or by email.

18. Contact

Privacy enquiries and data rights: our contact form

Operator: Symposed