Privacy Policy
v2 · Effective June 21, 2026
PRIVACY POLICY
Inedsys.com
Effective Date: June 21, 2026
Inedsys ("we," "us," or "our") operates the website and SaaS platform available at Inedsys.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our Service — including our webinar and content platform, InedAI assistant, newsletter, and email communications — and the choices you have regarding that information.
By accessing or using our Service, you agree to this Privacy Policy. If you do not agree, please immediately discontinue use of the Service.
PART I — GENERAL PRIVACY PRACTICES
1. Information We Collect
We collect the following categories of information:
1.1 Information You Provide Directly
- Account registration data: name, email address, username, and password.
- Billing and payment information: billing name, address, and payment method details (processed by Stripe; we do not store full card numbers).
- Profile information: job title, company name, and other optional fields you choose to complete.
- Newsletter and email preferences: your subscription status and communication preferences.
- Communications: messages, support tickets, and feedback you send to us.
1.2 Information Collected Automatically
- Log and usage data: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps.
- Device information: hardware model, device identifiers, and network information.
- Cookies and tracking technologies: see Section 5 for details.
- Email engagement data: whether you open, click, or unsubscribe from our emails (collected via standard email tracking pixels).
- Performance and diagnostic data: crash reports and error logs to improve platform stability.
1.3 InedAI Query Data
When you use the InedAI assistant, Inedsys stores the text of the questions you submit. We collect and retain this data using reasonable best efforts to ensure no patient information is included in your search. Furthermore, we never link these stored questions to your user account, name, email address, or any other personally identifiable information. This data is used solely to improve the quality and accuracy of InedAI's responses over time.
Because InedAI questions are stored anonymously, we are unable to retrieve, identify, or delete a specific question on your behalf after submission. You should not include your name, contact information, personal health details, or other sensitive personal information in questions submitted to InedAI*.*
1.4 Information from Third-Parties
- Single sign-on (SSO): if you log in using Google, Microsoft, or another SSO provider, we receive profile data (name, email, profile picture) as permitted by that provider.
- Integration partners: data from third-party tools you connect to our Service, limited to what is necessary to provide the integration.
- Payment processor: Stripe provides us with transaction confirmations, last four digits of payment method, and billing details necessary to manage your subscription.
1.5 Webinar and Live Event Participation Data
When you join a live webinar, panel discussion, or other event hosted on the Inedsys platform, we may collect the following information in connection with your participation:
- Your registered name and account information, which may be displayed to other attendees and visible in the recording;
- Audio of your spoken contributions, including questions and comments made during the session, if you use your microphone;
- Video of your appearance if you enable your camera during the session;
- Text-based questions or comments submitted through the Q&A or chat features;
- Attendance metadata, such as the time you joined and left the session, to support session management and technical troubleshooting.
By creating an account and joining any live event on our platform, you consent to this data collection and to the recording, editing, and publication of session content as described in Section 2.4 below.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Providing and Improving the Service
- Create and manage your account.
- Deliver the features and functionality you request, including Premium content access.
- Process transactions and send related notifications.
- Monitor and analyze usage to improve performance and user experience.
- Develop new features and services, including improvements to InedAI.
2.2 Email Communications and Newsletter
- Send transactional emails: account confirmation, password resets, billing receipts, and security alerts.
- Send our newsletter with platform updates, featured physician content, and community news.
- Send webinar reminders for upcoming live events and notifications about newly published content.
- Send promotional emails about membership plans, special offers, and platform updates, where you have opted in.
You may opt out of marketing and newsletter emails at any time using the unsubscribe link in any email or by contacting us at contact@inedsys.com. You cannot opt out of transactional emails necessary to administer your account.
2.3 InedAI Improvement
Anonymized InedAI query data is used to train, fine-tune, and improve the accuracy and relevance of AI-generated responses. This data is used only for this purpose and is not associated with your identity.
2.4 Webinar Recordings, Live Events, and InedCast
Inedsys records live webinars, panel discussions, and Q&A sessions for educational publication. We use participation data collected under Section 1.5 for the following purposes:
- Publishing long-form session recordings on the Inedsys website and YouTube channel for registered and public viewers;
- Producing InedCast, our podcast and audio series, which may feature excerpts from webinar sessions, including audience questions, panelist responses, and Q&A discussions;
- Distributing InedCast episodes on major podcast platforms (e.g., Apple Podcasts, Spotify, Google Podcasts, Amazon Music);
- Creating promotional short-form clips for distribution on social media and other channels.
Questions submitted during sessions may be included in published recordings and InedCast episodes. If you submit a text question and indicate “anonymous,” Inedsys will make reasonable efforts to omit your name from the published version; however, we cannot guarantee anonymity for audio or video contributions. If you do not wish to appear in published content, you should not enable your microphone or camera during live sessions.
2.5 Security and Fraud Prevention
- Detect, investigate, and prevent fraudulent transactions and other illegal activities.
- Protect the security and integrity of our Service.
- Enforce our Terms of Service.
2.6 Legal and Compliance
- Comply with applicable laws and regulations.
- Respond to lawful requests from public authorities.
- Establish, exercise, or defend legal claims.
2.7 Aggregate and De-identified Data
We may aggregate or de-identify personal information so that it can no longer reasonably identify you. We may use and share such data for any lawful business purpose without restriction.
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
3.1 Service Providers
We share information with vendors and third-party service providers who perform services on our behalf, such as:
- Cloud hosting and infrastructure providers.
- Stripe (payment processing).
- Email service providers and newsletter platforms.
- Analytics and monitoring services.
- Customer support software.
- AI model and infrastructure providers supporting InedAI.
- Social media platforms (LinkedIn, YouTube, X (formerly Twitter), Instagram, TikTok) on which we distribute content and promotional Clips. Your interactions with content on those platforms are subject to their own privacy policies.
These providers are contractually obligated to use information only as directed by us and in accordance with this Privacy Policy.
3.2 Business Transfers
If we are involved in a merger, acquisition, reorganization, asset sale, or similar transaction, your information may be transferred as part of that transaction. We will notify you of any such change via email or prominent notice on our Service.
3.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect the rights, property, or safety of Inedsys, our users, or the public.
3.4 With Your Consent
We may share information for other purposes with your prior consent or at your direction.
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.
When you close your account, we will delete or anonymize your personal information within 120 days, except where retention is required by law or for legitimate business purposes such as fraud prevention.
Anonymized InedAI query data does not contain personally identifiable information and is retained indefinitely for AI model improvement purposes. Because this data is not linked to your identity, account closure does not affect the retention of anonymized query data.
Email engagement data (open rates, click data) is retained for as long as your email subscription is active and for a reasonable period thereafter for analytics purposes.
4.1 Feature-Specific Retention
The following feature-specific categories are retained as follows. Chat messages and attached photographs are retained until deleted by the user, by a moderator, or by deletion of the surrounding room or account; no automatic time-based expiry currently applies. Invitation records for non-users are retained until the invitee accepts or declines, until thirty (30) days after the invitation expires, or until the prospective invitee requests deletion, whichever is sooner. Host applications, custom-symposium inquiries, and sponsorship records are retained for the period reasonably necessary to evaluate the application and operate the resulting event, after which they will be deleted or de-identified on reasonable request. AI interaction logs (questions, answers, and feedback) are retained on a user-scoped basis to support quality improvement; users may request deletion of their AI interaction history by contacting us.
5. Cookies and Tracking Technologies
We use cookies, pixel tags, and similar technologies to collect information automatically as you interact with our Service, including standard email tracking pixels used in our newsletter and email communications.
5.1 Types of Cookies We Use
Essential cookies: Required for the Service to function (e.g., session management, authentication). These cannot be disabled.
Performance cookies: Help us understand how users interact with our Service (e.g., pages visited, errors encountered).
Functionality cookies: Remember your preferences and settings to provide a personalized experience.
Analytics cookies: Used to analyze aggregated usage patterns to improve our Service.
5.2 Email Tracking
Our newsletter and marketing emails may include a tracking pixel — a small invisible image — that allows us to detect whether an email was opened and whether links were clicked. This helps us understand engagement and improve our communications. You can disable email tracking by setting your email client to block remote images.
5.3 Your Choices
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies; however, doing so may affect the functionality of our Service.
6. Data Security
We implement industry-standard technical, administrative, and physical safeguards designed to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit (TLS) and at rest (AES-256).
- Role-based access controls and least-privilege principles.
- Regular security assessments and vulnerability testing.
- Incident response procedures.
No method of data transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at contact@inedsys.com.
7. Your Privacy Rights
Depending on where you reside, you may have the following rights regarding your personal information:
7.1 General Rights (All Users)
- Access: Request a copy of the personal information we hold about you.
- Correction: Request that we correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to legal limitations.
- Portability: Request your information in a structured, machine-readable format.
- Opt-out of marketing: Unsubscribe from marketing and newsletter emails at any time.
7.2 California Residents — CCPA / CPRA Rights
If you are a California resident, you have additional rights under the CCPA and CPRA:
- Right to Know: Know the categories and specific pieces of personal information we collect, the sources, the business purposes, and the third parties with whom we share it.
- Right to Delete: Request deletion of personal information we collected from you, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights.
How to Submit a Request: Email us at contact@inedsys.com with the subject line "California Privacy Rights Request." We will respond within 45 days. We may need to verify your identity before processing your request.
Note: InedAI query data is stored in an anonymized format that is not linked to your identity. Because we cannot identify which stored questions are yours, we are unable to retrieve or delete specific InedAI queries on a per-user basis.
8. Children’s Privacy
Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have inadvertently collected such information, please contact us at contact@inedsys.com and we will promptly delete it.
9. Links to Third-Party Sites
Our Service contains links to, and integrates with, social media and third-party platforms including YouTube, LinkedIn, X (formerly Twitter), Instagram, TikTok, and major podcast platforms (e.g., Apple Podcasts, Spotify, Google Podcasts, Amazon Music). We post content, promotional clips, and InedCast episodes on these platforms. This Privacy Policy does not apply to those third-parties. We have no control over and assume no responsibility for the content, privacy policies, or data practices of any third-party platform. We encourage you to review the privacy policies of each platform independently.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address associated with your account) or by posting a prominent notice on our Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the changes.
PART II — FEATURE-SPECIFIC DATA PRACTICES
The following sections describe data practices specific to individual features of the Service.
11. Chat and Messaging Data
11.1 What We Collect
We operate an in-platform messaging feature that supports real-time conversations attached to SIGs, Events, and user-created groups. For each message we store the text of the message, the sender’s user identifier, timestamps of creation and any edits, soft-delete flags identifying who deleted the message, threaded-reply to relationships, and per-user read state.
Users may attach one photograph per message (JPEG, PNG, or WebP). Photographs are compressed in the user’s browser to a maximum of 1,600 pixels and uploaded to our object-storage processor. The system is set such that each stored object is deleted when the message is deleted by the sender or by a moderator.
Users may pin links to external Google Drive resources (e.g., Docs, Sheets, Slides, or Forms) to a chat room. We store the link and basic metadata returned by the link; we do not store the linked file itself.
We also store emoji reactions to messages, user-submitted reports of other messages, moderation warnings issued to users, and per-user chat-ban flags.
11.2 Who Can See Messages
Four chat room types exist: (a) SIG rooms (visible to SIG members), (b) Grand Rounds rooms (visible to the event team, with attendees excluded by default), (c) Symposium rooms (same visibility model as Grand Rounds), and (d) user-created groups. User-created groups require administrator approval before any member other than the creator can view or post in them. Rejected groups are invisible to other users. Invited users cannot read or post in a room until they accept the invitation from their dashboard. The platform also offers Clubs, which function as open-forum communities available to all users on a self-join basis and covering a wide range of topics. Club chats are moderated by an AI agent that monitors activity in real time, and the Company takes enforcement action against any user who violates the Terms of Service, including by posting spam, illegal content, or prohibited materials.
11.3 Encryption and Operator Access
Chat messages are NOT end-to-end encrypted. While data in transit may be protected by HTTPS/TLS and data at rest is protected by the standard storage protections of our database and object-storage processors, message text and photographs are stored in a form readable by us. Inedsys administrators and platform moderators are able to read message content for moderation, abuse-prevention, safety, security, and legal-compliance purposes. You should not transmit information through the chat feature that you would not be willing to share with Inedsys.
11.4 Moderation Actions and Account Suspension
When a message is reported, an administrator may review the reported message and the surrounding context. We may, in our sole and unquestionable discretion, delete messages, issue formal warnings, ban a user from all chat features, remove a user from a specific group, reject or remove a user-created group, or suspend an entire user account through our authentication provider. All moderation actions are logged with the acting administrator’s identifier and a timestamp. All moderation actions are made in our complete and unquestionable discretion.
11.5 Retention and Deletion
We do not currently operate an automatic message-expiry policy. When you delete one of your messages, the message content is blanked and the attached photograph object is deleted from object storage. When a chat room is deleted, all of its messages, members, reports, reactions, and pinned external links are deleted. When you delete your account, messages you authored are removed under the cascade rules described in Section 4 (Data Retention). Messages remain available to room members until they are explicitly deleted or until the room itself is deleted.
12. Push Notifications
Where you have enabled push notifications on a device or in a supported browser, we send notifications through Apple Push Notification service (APNs) on iOS, Firebase Cloud Messaging (FCM) on Android, and Web Push on supported browsers. Each notification may include the relevant room or event name, the sender’s name, a short snippet of the message (no more than 120 characters), and a link to open the relevant feature. We store the device or browser token associated with your account for the sole purpose of delivering these notifications. You may turn notifications off at the device, operating-system, or account level at any time. You are responsible for the costs, if any, of these notifications.
13. Special Interest Group (SIG) Participation Data
13.1 What We Collect
Special Interest Groups are clinician communities organized around a clinical specialty. For each SIG we store its name, description, clinical specialty, logo, public “about” content, and lifecycle status (draft, live, or archived). For each SIG member, we store the member’s role within the SIG (chair, vice-chair, secretary, or member), the date they joined, and information they have already provided to Inedsys under Section 1.1 (name, professional credentials, specialty, and profile photograph), which is displayed to other SIG members.
If you apply to join a SIG that requires approval, we collect your institution, specialty focus, and any free-text personal statement you submit. If you are invited to a SIG by email, we generate a single-use tokenized invitation link that expires after thirty (30) days.
For each topic published within a SIG we store the topic’s title and description, speaker names and credentials, learning objectives, scheduled webinar information, recording URL (if recorded), an AI-generated summary, and continuing-medical-education metadata where applicable (credits, type, joint provider, and activity identifier).
13.2 User-Generated Content within SIGs
SIGs include three forms of user-generated content. Internal SIG discussion threads are visible only to SIG members. The SIG member forum is open to all authenticated SIG members for both reading and posting. Access to the forum is NOT restricted to paid Premium accounts. SIG members may also upload presentation materials (in PDF, PPT, or PPTX format), which are stored in our object-storage processor.
13.3 Visibility of SIG Content
Draft SIGs are visible only to their members and to Inedsys administrators. Live SIGs are discoverable by all authenticated users of the platform, while their discussion threads, forum content, and uploaded materials remain restricted to SIG members unless explicitly marked otherwise. Archived SIGs are hidden from listings. No SIG content is intentionally exposed to the unauthenticated public.
13.4 SIG-related Third-Parties
SIG slide uploads are stored with Cloudflare R2. SIG topic webinars may reference Zoom meetings, but Zoom integration for SIGs is currently limited to manual URL entry by the SIG organizer (no Zoom API integration or on-demand). Where the SIG schema supports email invitations, those invitations are transmitted by our transactional email processor (Resend).
14. Events — Grand Rounds and Symposiums
14.1 Event records and team data
For Grand Rounds or Symposium events we store the event’s title, topic and description, the presenter’s name, professional credentials, biographical statement, and photograph, the host and any co-hosting institutions, the schedule and time zone, Zoom webinar URLs and identifiers, recording URLs (if applicable), and sponsor information including name, logo, website, and description. We also store agenda items, and for symposiums we store each section’s chairs, speakers, and moderators. Personal data shown publicly on event pages includes the names, credentials, specialties, photographs, and biographical statements of event team members.
14.2 Invitations to Non-users
We may store the email address of a prospective invitee before that person is a registered user of the platform, together with the invitee’s role designation and a single-use tokenized invitation link that expires after thirty (30) days. We process these email addresses solely to extend the invitation and to manage the resulting attendance or response. Where required by law, we will honor requests from prospective invitees to delete their email address from our invitation records.
14.3 Host Applications and Sponsorship Data
Where you apply to host a Grand Round or related event through our “apply to host” workflow, we collect a set of professional and institutional information, which may include your: name, work email, telephone number, professional credentials, specialty and sub-specialty, institution, department, region, time zone, LinkedIn profile URL, the source through which you learned of Inedsys, your proposed event concept, funding-path details including any pharmaceutical-industry-facilitated funding and the pharmaceutical-industry contacts involved, your proposed budget, pricing tier, institutional sponsors, regulatory considerations, and consent flags regarding pharmaceutical outreach and recording rights. We process this information to evaluate the application, to plan the event, and (where you have consented) to coordinate sponsorship and outreach activity. A separate custom-symposium inquiry form may also collect your name, email address, institution, and our internal administrative notes.
Host-application data is treated as sensitive sales-lead and commercial information. We retain it for the period reasonably necessary to evaluate the application and to administer the resulting event, after which we will delete or de-identify it on reasonable request and in any event in accordance with the retention rules described in Section 4.
14.4 Zoom Integration and Panelist Data Transmission
Events are delivered through Zoom under an API-integrated workflow. The platform is set to create, update, and delete Zoom webinars and manages the panelist list on the host’s behalf. Panelist names and email addresses are transmitted to Zoom as a sub-processor. Zoom processes that data under its own terms and privacy notice and we disclose Zoom as a sub-processor in Section 3 of this Policy. Consult Zoom’s terms and privacy notice for additional information.
14.5 Recording and Consent
Event sessions may be recorded. When sessions are recorded, the recording URL is stored on the event record. By participating as a presenter, panelist, co-host, moderator, or attendee, you acknowledge that the session may be recorded and that the recording may include your name, voice, image, and any contributions you make during the session, and you grant Inedsys the rights to use the recording for the purposes described in this Policy and in our Terms of Service. If you do not wish to be recorded, you must not enable your microphone or camera during the session or decline to attend.
15. Expanded AI Features
15.1 Features
We provide three AI-assisted study tools. InedAI is a retrieval-augmented question-and-answer feature.
15.2 AI Sub-processors
Our primary large-language-model provider is Anthropic. If Anthropic is temporarily unavailable, our system automatically, and without further user action, fails over to OpenAI (GPT-4 Turbo family). OpenAI also provides the embedding model that powers semantic search across the Inedsys library; embedding vectors are stored in our database. Both Anthropic and OpenAI act as sub-processors and are disclosed in Section 3 of this Policy.
15.3 What Data is Sent to the AI Sub-processors
We either: (a) transmit your question, up to approximately five turns of recent conversational history with excerpts of matched library content (including extracted text from library PDFs); or (b) transmit your selected answers, the case content involved, and per-clinical-domain accuracy statistics. We do not place your name, email address, or other identity attributes into the prompt payload. A client-side filter screens for common patterns of patient-identifying information (Social Security Number, date of birth, medical record number, email address, telephone number, and personal names) and a server-side guard refuses to forward questions that appear to contain patient identifiers.
You must not enter any patient-identifiable information, protected health information, or any information from which an individual patient could reasonably be re-identified, into any AI feature.
15.4 What We Store
For each AI interaction we store: the question or prompt submitted; the full answer returned; the citation sources referenced; the identifier of the model and provider that answered; and a timestamp. We also store thumbs-up or thumbs-down feedback you provide. We additionally store each case attempt (including the case JSON and AI feedback), per-domain scores, satisfaction (NPS) feedback, flagged cases, and module or drill session progress. All such data is scoped to the originating user under Postgres Row-Level Security.
15.5 No Medical Advice; Educational Use Only
The AI features are provided for the continuing education of licensed physicians and other licensed clinicians. They are not a medical device, do not provide medical advice or diagnosis, and must not be used to make patient-care decisions. AI outputs may be inaccurate, incomplete, or out of date and must be independently verified against authoritative sources by the user. Your use of the AI features is at your own professional discretion and risk.
16. Continuing Medical Education (CME) Credit and Data Sharing
16.1 Variability of CME availability and provider
Inedsys may offer Continuing Medical Education (CME) credit for some webinars, SIG topics, Grand Rounds, Symposiums, or other educational sessions on the Service. Whether CME credit is available for any particular session, the number of credits offered, the type of credit, the eligibility criteria, and the accredited CME provider issuing the credit may vary on a session-by-session basis and are subject to change. Inedsys does not guarantee that CME credit will be available for any specific session, and CME availability may be added, modified, or withdrawn at any time without notice to you.
16.2 Accredited CME Providers
CME credit, where offered, is issued through one or more accredited CME providers with whom Inedsys partners. We may engage one or more accredited joint providers from time to time, and we may add or remove provider relationships at our discretion. The current list of accredited CME providers with whom Inedsys partners will be disclosed at the time of CME enrollment for each applicable session and is available on request made to contact@inedsys.com.
16.3 Personal Data Shared with Accredited CME Providers
Where you elect to claim CME credit for a session, we share with the relevant accredited CME provider the personal data that the provider reasonably requires or requests in order to issue, document, and report CME credit. This may include: your full name; your professional credentials and specialty; your professional licensure information (including, where applicable, NPI number, state medical license number, or other identifier required by the accreditation body); your email address; attendance metadata for the session (date and duration of your participation); your responses to any post-session evaluation, post-test, or required attestation; and any disclosure acknowledgements required by the accreditation body.
16.4 Role of the Accredited CME Provider
The accredited CME provider acts as a separate data controller (or, where the engagement so provides, an independent processor) for the purpose of issuing and reporting CME credit, and processes the shared data under its own terms and privacy notice and under the rules of the relevant accreditation body (including, in the United States, the Accreditation Council for Continuing Medical Education). Accredited CME providers are typically required by those rules to retain learner records for a defined period; that retention is governed by the CME provider’s own retention policy and the applicable accreditation rules.
16.5 Consent and Accuracy
By electing to claim CME credit for any session, you consent to the data sharing described in this Section 16 and you confirm that any licensure or professional-credential information you submit for CME purposes is accurate and complete. Inedsys is not responsible for CME credit being denied, delayed, modified, or revoked by an accredited CME provider, including where such action results from inaccurate or incomplete information you have provided. If you do not wish to share the information described above, you should not elect to claim CME credit; you may still participate in the underlying session subject to the rest of these Terms and Privacy Policy.
17. Society Participation Data
17.1 What We Collect about Societies and Officers
The Service supports professional medical and scientific societies (each, a “Society”) in hosting their public presence, membership, and content on Inedsys. For each Society we store the Society’s record, which may include: the Society’s legal name and any short or trading name; its mission and public “about” content; its logo; its headquarters address and country; contact information designated for public display; references to its bylaws or governing documents to the extent the Society shares them; and its lifecycle status (draft, live, or archived).
For each Society officer or team member (each, a “Society Officer”), we store the personal data the Society chooses to display on its public team page, which may include the Officer’s full name, professional credentials, role or title within the Society (such as President, President-Elect, Past President, Joint Secretary, Treasurer, Editor, Academic Co-ordinator, Research Co-ordinator, Council Member, or any other role configured by the Society), professional photograph, biographical statement, and any external links the Society chooses to publish. The Society warrants that it has obtained consent from each named Officer to the public display of that personal data on the Service.
For each Society member, we store the member’s user identifier, the member’s role within the Society, and the date the member joined the Society. Where a Society operates an application-to-join workflow, we may also store the data submitted on the application form (which may include the applicant’s institution, professional credentials, specialty focus, country of practice, free-text personal statement, and any custom fields configured by the Society Admin) and the disposition of the application (pending, approved, or rejected).
We also store content the Society contributes to the Service, including posts and comments in the Society’s public discussion forum, topic and event records the Society publishes, uploaded presentation materials, and any other content the Society creates on the Service.
17.2 Public Visibility of Society Pages
Each Society has a public-facing landing page that is visible to all visitors to the Service, including visitors who are not registered Inedsys users. This page may display the Society’s mission, its team (including the personal data described in Section 20.1 for each Society Officer), its activities, and its public discussion forum. The page may be indexed by external search engines. Personal data displayed on a Society’s public page is therefore likely to be discoverable outside the Service.
Posting to a Society’s public discussion forum is restricted to authenticated Inedsys users. Reading the forum may, where the Society configures it that way, be open to all visitors including unauthenticated visitors and search-engine crawlers.
17.3 Society Admin Moderation
Each Society designates one or more authorized representatives (each, a “Society Admin”) with delegated moderation authority within the Society’s space on the Service. A Society Admin may, in their discretion: read forum posts and applications submitted to the Society; approve or reject membership applications; remove forum posts and comments; warn, mute, or remove Society members from the Society; and modify the Society’s public-facing content. Society Admins act on behalf of the Society and not on behalf of Inedsys. Inedsys retains overarching moderation authority over Society content and may take any of the moderation actions described in Section 11.4 at any time in its sole discretion.
17.4 Society-Contributed Content and Promotional Uses
Where a Society publishes a topic, event, presentation, or other content to the Service, such content may be included in the Inedsys library and may be referenced or featured in other parts of the Service. Inedsys may also use such content (including, but not limited to, images, presenter photographs, and short excerpts) for promotional purposes on the Service, on Inedsys-operated social-media channels, and in newsletter communications, on the same terms that apply to other presenter-contributed content as set out in the Terms of Service.
17.5 International Data Flows
Societies and their Officers and members may be based outside the United States. Where a Society or its Officers are located outside the jurisdiction in which Inedsys is incorporated, the personal data of those Officers and members may be processed in jurisdictions other than their own and may flow into and out of the United States in connection with the operation of the Service. We rely on appropriate transfer mechanisms (such as standard contractual clauses) where required by applicable law.
17.6 Retention and Removal of Officer Data
Society records are retained while the Society is active on the Service. If a Society is archived or terminated, its public page is hidden from listings; Society-contributed content already published to the Inedsys library may remain available subject to the content license described in the Terms of Service. We will remove an Officer’s personal data from a Society’s public page on reasonable and timely request from the relevant individual or from the Society, subject to applicable record-keeping requirements and to the rights granted in respect of content already published to the Inedsys library.
PART III — REFERENCE
18. Sub-Processor List
The following sub-processors are added to, or expanded within, the list disclosed in Section 3: Cloudflare R2 (object storage for chat photographs and uploaded slide and PDF materials); Resend (transactional email, including chat-invitation emails, moderation-warning emails, event-invitation emails, Zoom-link emails, application confirmations, and administrative alerts); Apple Push Notification service, Firebase Cloud Messaging, and Web Push (delivery of push notifications and corresponding device or browser tokens); Zoom Video Communications (creation and operation of event webinars, including transmission of panelist names and email addresses, and storage of session recordings); Anthropic (primary large-language-model provider for the AI features); and OpenAI (failover large-language-model provider and embedding-model provider for the AI features).
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Company: NEDSYS INC.
Email (all privacy inquiries): contact@inedsys.com
Mailing Address: Diversified Corporate Services Int'l, Inc., 508 Main Street, Wilmington, Delaware 19804
Website: Inedsys.com
We aim to respond to all privacy-related inquiries within 30 days.