Privacy Policy

MASTER PRIVACY & DATA PROTECTION POLICY

HEALTHEDIA GLOBAL HEALTH & PERFORMANCE ARCHIVE

Effective Date: August 8, 2026
Last Updated: August 8, 2026
Website: https://healthedia.org/


1. LEGAL FRAMEWORK & GLOBAL COMPLIANCE DECLARATION

This Master Privacy Policy governs the data collection, processing, and archiving practices of HEALTHEDIA (the “Platform,” “we,” “our,” or “us”). As the leading open-access indexing database for medical, rehabilitation, sports physiology, biomechanics, and human performance studies, we operate under strict global data protection frameworks.

This policy is explicitly designed to comply with:

  • The European Union General Data Protection Regulation (EU GDPR) 2016/679
  • The United Kingdom General Data Protection Regulation (UK GDPR) & Data Protection Act 2018
  • The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable U.S. state privacy laws (e.g., VCDPA, CPA, CTDPA, UCPA)
  • The Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada

2. DATA CONTROLLER IDENTIFICATION

For the purposes of the GDPR, UK GDPR, and equivalent data protection laws, HEALTHEDIA acts as the Data Controller for the personal data collected through our platform. In instances where we process research data on behalf of academic institutions, we may act as a Data Processor.

3. CATEGORIES OF PERSONAL DATA COLLECTED

We collect, use, store, and transfer different kinds of personal data, grouped as follows:

  • A. Identity Data: First name, maiden name, last name, username or similar identifier, academic titles, ORCID iD, and institutional affiliations.
  • B. Contact Data: Institutional and personal email addresses, telephone numbers, and professional geographic locations.
  • C. Professional & Academic Data: Publication history, peer-review records, citation metrics, academic credentials, and metadata associated with submitted research (including funding sources and conflicts of interest).
  • D. Technical Data: Internet Protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, and platform technologies used to access Healthedia.
  • E. Usage Data: Information about how you use our website, search queries, download history, API requests, and indexing interactions.
  • F. Communications Data: Preferences in receiving academic alerts, newsletters, and communications from us, as well as correspondence logs.

Note on Sensitive Data: As a repository for human performance and medical studies, any sensitive biometric or health data included in published research is processed under the exemption for archiving purposes in the public interest, scientific or historical research purposes pursuant to Article 89(1) of the GDPR.

4. LAWFUL BASIS FOR PROCESSING (GDPR & UK GDPR)

We will only use your personal data when the law allows us to. Our lawful bases for processing include:

  1. Contractual Necessity: Processing is necessary for the performance of a contract to which you are a party (e.g., our Terms of Service when submitting an article for indexing).
  2. Legitimate Interests: Necessary for our legitimate interests to run an open-access scientific archive, ensure network security, prevent fraud, and improve academic search functionalities.
  3. Public Interest / Scientific Archiving: Processing Identity and Academic Data is necessary for archiving purposes in the public interest and scientific research purposes.
  4. Consent: Where required by law (e.g., for non-essential cookies or specific marketing communications), we process data based on your explicit, revocable consent.

5. HOW WE COLLECT YOUR DATA

  • Direct Interactions: You may give us your Identity, Contact, and Academic Data by filling in forms, registering for an account, submitting manuscripts/data for indexing, or corresponding with us by post, phone, email, or otherwise.
  • Automated Technologies: As you interact with our website, we automatically collect Technical and Usage Data using cookies, server logs, API tracking, and similar technologies.
  • Third-Party Sources: We may receive personal data about you from academic cross-referencing services (e.g., Crossref, PubMed, DataCite), institutional repositories, and analytics providers.

6. PURPOSES OF DATA PROCESSING

We utilize your data to:

  • Index, archive, preserve, and publicly distribute medical, biomechanics, and sports physiology research.
  • Assign and manage Digital Object Identifiers (DOIs).
  • Maintain accurate academic records and attribution for authors and researchers.
  • Administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data).
  • Deliver relevant website content and measure the effectiveness of our indexing algorithms.
  • Comply with legal, regulatory, and ethical obligations in scientific publishing.

7. DATA SHARING AND GLOBAL DISCLOSURES

Given the nature of an open-access global database, certain data is inherently public:

  • Public Open-Access Disclosure: Authors’ names, institutional affiliations, ORCID iDs, and email addresses associated with published research are made globally accessible to ensure scientific transparency and academic communication.
  • Service Providers: We share restricted data with trusted third-party processors providing IT and system administration, cloud hosting, and database distribution services. All processors are bound by strict Data Processing Agreements (DPAs).
  • Legal & Regulatory Authorities: We may disclose data to third parties to whom we may choose to sell, transfer, or merge parts of our business, or to legal authorities to comply with anti-fraud, copyright, and international security laws.

8. INTERNATIONAL DATA TRANSFERS

Healthedia operates globally. Personal data collected within the European Economic Area (EEA) or the UK may be transferred to, and processed in, countries outside of these jurisdictions. Whenever we transfer your personal data out of the EEA or UK, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • Transferring data to countries deemed to provide an Adequate Level of Protection by the European Commission or the UK Information Commissioner’s Office (ICO).
  • Utilizing Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) for transfers to jurisdictions without adequacy decisions.

9. DATA RETENTION POLICY

  • Academic Record Data: Identity and Professional Data associated with indexed research papers, datasets, and scientific contributions are retained indefinitely to preserve the historical scientific record and academic integrity, in accordance with global archiving standards.
  • User Account & Technical Data: Account information is retained for as long as your account is active. Technical and Usage Data is strictly retained for the period necessary to fulfill the purposes outlined in this policy (typically up to 36 months), after which it is anonymized or securely deleted.

10. YOUR STATUTORY PRIVACY RIGHTS

Depending on your legal jurisdiction, you possess robust rights regarding your personal data:

For EU/UK Residents (GDPR & UK GDPR):

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of incomplete or inaccurate data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your data. (Note: This right is heavily restricted regarding published academic records, as deletion would severely compromise scientific integrity and the public interest).
  • Right to Restrict Processing: Suspend the processing of your data under certain scenarios.
  • Right to Data Portability: Request the transfer of your data to you or a third party in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or for direct marketing.

For U.S. Residents (CCPA/CPRA & State Laws):

  • Right to Know/Access: Request disclosure of the specific pieces and categories of personal information collected, sources, and commercial purposes.
  • Right to Delete: Request deletion of personal information, subject to exceptions (such as scientific research exemptions).
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: Healthedia DOES NOT SELL your personal data. You have the right to opt-out of the “sharing” of personal data for cross-context behavioral advertising.
  • Right to Non-Discrimination: You will not be denied services or access for exercising your privacy rights.

11. COOKIES AND TRACKING TECHNOLOGIES

Healthedia utilizes robust tracking technologies to ensure platform functionality.

  • Strictly Necessary Cookies: Required for the operation of the indexing platform, load balancing, and security protocols.
  • Performance & Analytics Cookies: Utilized to map academic traffic, track DOI resolution rates, and analyze user navigation flow.

You may configure your browser to refuse all or some cookies, or to alert you when websites set or access cookies. A dedicated Cookie Consent Banner governs our specific localized deployments.

12. DATA SECURITY PROTOCOLS

We have implemented enterprise-grade security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed.

  • Data at rest and in transit is secured utilizing AES-256 encryption and TLS 1.3/SSL protocols.
  • Access to administrative databases is strictly limited on a principle of least privilege (PoLP) and secured via Multi-Factor Authentication (MFA).
  • We maintain strict Incident Response Plans (IRP) and will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so within 72 hours.

13. CHILDREN’S PRIVACY

The Healthedia platform is strictly designed for academic professionals, researchers, and university-level students. We do not knowingly collect personal data from children under the age of 16 (or 13 in certain U.S. jurisdictions). If we discover that we have collected personal data from a child, we will promptly delete that data.

14. MODIFICATIONS TO THIS POLICY

We reserve the right to modify this Master Privacy Policy at any time to reflect technological advancements, legal shifts, or changes to our academic indexing protocols. Substantive updates will be communicated via email to registered users and indicated by an updated “Effective Date” at the top of this document.

15. CONTACT INFORMATION & DATA PROTECTION OFFICER (DPO)

If you have any questions about this Privacy Policy, our data processing practices, or wish to exercise your legal rights, please contact our Data Protection Officer at:

HEALTHEDIA GLOBAL HEALTH & PERFORMANCE ARCHIVE
Data Protection Officer (DPO)
Email: legal@healthedia.org / dpo@healthedia.org
Website: https://healthedia.org/
Data Subject Requests: privacy@healthedia.org