Symposia ("we," "us," or "our") operates the Symposia conference management platform (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Service you agree to this policy.
1. Information We Collect
1.1 Information you provide directly
- Account data ๐น name, email address, and profile photo when you register via Google or LinkedIn OAuth.
- Profile data ๐น job title, institution, bio, research interests, and any other information you add to your attendee or committee profile.
- Submission content ๐น abstract text, author lists, supplementary files, and review comments you submit through the platform.
- Communications ๐น messages you send within the platform and any email correspondence with our team.
1.2 Information collected automatically
- Usage data ๐น pages visited, features used, session durations, and clicks, collected through server logs and analytics.
- Device and connection data ๐น browser type, operating system, IP address, and referring URLs.
- Cookies and similar technologies ๐น we use session cookies for authentication and preference cookies to remember your settings (e.g., light/dark mode). We do not use third-party advertising cookies.
1.3 Information from third parties
When you sign in with Google or LinkedIn we receive your name, email, and profile photo from that provider. We do not access contacts, posts, or any data beyond what is necessary to create your account.
2. How We Use Your Information
- Provide, operate, and improve the Service.
- Authenticate your identity and maintain your session.
- Match attendees with shared research interests (only within events you have registered for).
- Send transactional emails ๐น submission confirmations, review assignments, agenda updates, and security alerts. You cannot opt out of transactional messages while your account is active.
- Send optional product announcements and feature updates (you may unsubscribe at any time).
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
3. Sharing Your Information
We share your data only in these circumstances:
- Within the platform ๐น your name and institution are visible to other participants of events you have joined. Abstract content is visible per the blind-review rules set by the organizing committee. You can review exactly what is visible in your profile settings.
- Service providers ๐น we use Supabase (database and authentication), Resend (transactional email), and Vercel (hosting). Each provider has a data processing agreement with us and may only process data to deliver the service.
- Organizing committees ๐น the committee that runs an event you registered for can see your registration details, check-in status, and submitted abstracts. They cannot export raw personal data in bulk without a separate data processing agreement.
- Legal requirements ๐น we may disclose information if required by law or to protect the rights, property, or safety of Symposia, our users, or the public.
- Business transfers ๐น if Symposia is acquired or merged, your information may be transferred as part of that transaction. We will notify users before data is transferred and becomes subject to a different privacy policy.
4. Data Retention
We retain your account data for as long as your account is active. Submitted abstracts and review records are retained for a minimum of 3 years to support academic integrity and audit needs of organizing institutions. You may request deletion of your account at any time (see Section 7); retention of abstract records may be required under our agreements with organizing institutions.
5. Security
We use industry-standard safeguards including TLS encryption in transit, AES-256 encryption at rest, role-based access control, and audit logging for sensitive operations. No method of transmission or storage is 100% secure; we cannot guarantee absolute security but we respond promptly to any suspected breach.
6. International Transfers
Symposia is operated from the United States. If you access the Service from outside the US, your data will be transferred to, processed, and stored in the US. We rely on Standard Contractual Clauses where required for transfers from the European Economic Area.
7. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access ๐น request a copy of the personal data we hold about you.
- Correction ๐น update inaccurate information (most fields are editable directly in your profile).
- Deletion ๐น request that we delete your account and personal data, subject to our retention obligations.
- Portability โ receive a machine-readable export of data you have provided to us.
- Objection / restriction โ object to or restrict certain processing activities.
- Withdraw consent โ where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at privacy@symposia.io. We will respond within 30 days. If you are in the EEA you have the right to lodge a complaint with your local supervisory authority.
8. Children
The Service is not directed to individuals under 16. We do not knowingly collect personal data from children under 16. If we learn we have done so, we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the effective date above and, for material changes, notify you by email or a prominent notice on the platform. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
10. Contact Us
Questions about this policy? Contact our privacy team at privacy@symposia.io or write to us at:
Symposia
Privacy Team
privacy@symposia.io