Privacy Policy
processing of personal data on the platform of the 25th Asian Oceanian Congress of Radiology (AOCR 2027)
- Revision of
- 20 August 2026
- Effective date
- 20 August 2026
- Revision identifier
- privacy-2026-08-20
1. General Provisions
1.1. This Privacy Policy (hereinafter, the "Policy") sets out the procedure for processing the personal data of users of the aocr2027.uz website (hereinafter, the "Platform") — the platform of the 25th Asian Oceanian Congress of Radiology (AOCR 2027), held from 29 April to 2 May 2027 in Tashkent, Republic of Uzbekistan.
1.2. The Policy applies to the processing of personal data carried out by the Operator when the Platform is used: when creating an account, registering for the Congress, placing and paying for orders, submitting abstracts, taking part in scientific review, maintaining information about speakers, and contacting support.
1.3. Personal data is processed in accordance with the legislation of the Republic of Uzbekistan, including the Law of the Republic of Uzbekistan "On Personal Data" No. ZRU-547 of 2 July 2019.
1.4. The conditions of participation in the Congress and the settlement procedure are set out in the Public Offer of the Platform. This Policy is a separate document and describes only the processing of personal data.
1.5. This Policy describes the processing actually carried out by the Platform as at the date of this revision. If the Operator connects a new service or introduces a new processing purpose, the Policy is updated before such processing begins.
2. The Operator of Personal Data
2.1. The operator of personal data is the legal entity providing services for participation in the Congress and acting as the Service Provider under the Public Offer of the Platform.
| Full name | OOO SCHOOL OF MEDICINE |
|---|---|
| TIN / STIR | 309573174 |
| Address | 100047, Uzbekistan, Tashkent, Yashnabad District, Makhtumkuli St., 103 |
| Phone | +998998773589 |
| medschool.uz@gmail.com | |
| Congress Platform | https://aocr2027.uz |
| Head | Каюмов Азиз Ильхамович |
2.2. AOCR 2027 is the name of the Congress and of the Platform. The operator of personal data is the legal entity named above.
3. Categories of Personal Data Processed
3.1. The Operator processes the following categories of personal data:
- account data: e-mail address, whether the address has been confirmed, and the user’s roles on the Platform;
- participant profile data: first name, last name, form of address or academic title, institution, department, city, country, telephone number, preferred language of communication;
- Congress registration data: the selected registration category, the name for the badge, invoicing details (payer type, name, country, address, tax identifier), and a record of acceptance of the Public Offer and of this Policy stating the revision identifier and the moment of agreement;
- order data: the composition of the order, the amount, the currency, the status and the time of each status change;
- abstract data: information about authors and co-authors — display name, affiliation, country, e-mail address, indications of the presenting and corresponding author — together with the content of the work and any attached file;
- scientific review data: information about reviewers, review assignments, scores, comments and conflict-of-interest declarations;
- speaker data: name, form of address, institution, department, country, ORCID, website link, portrait, participation status, and an internal contact e-mail address;
- enquiry data: the content of the enquiry and the contact details provided with it;
- technical data and security log records: IP address, browser information, request identifier, event type and the time of the event.
3.2. The Operator does not process biometric or genetic data, information about users’ state of health, patients’ medical data, or any other special categories of personal data on the Platform.
3.3. The Operator does not receive or store bank card details. The Platform’s information system contains no fields for storing them.
3.4. The user’s password is not transferred to the Operator as part of the Platform application: it is processed solely by the authentication service referred to in Section 7.
4. Sources of Personal Data
4.1. Personal data reaches the Operator from the following sources:
- directly from the user — when creating an account, completing a profile, registering for the Congress, submitting abstracts and contacting support;
- automatically when the Platform is used — technical data and security log records;
- from the corresponding author — in respect of the co-authors of an abstract, whose details they enter when preparing the work;
- from the organisers of the Congress — in respect of information about invited speakers, entered by authorised staff of the Operator.
4.2. The Operator does not purchase personal data from third parties and does not build user profiles from data obtained from external sources.
5. Purposes of Processing
5.1. Personal data is processed for the following purposes:
- creating and maintaining an account and enabling sign-in to the Platform;
- concluding and performing the agreement on participation in the Congress, including registration, order creation and payment confirmation;
- recording the fact and the moment of agreement with the Public Offer and with this Policy;
- organising the scientific programme: receiving abstracts, their consideration by the scientific committee, and composing the session schedule;
- maintaining information about invited speakers and publishing the agreed information in the public part of the Platform;
- sending service messages necessary for the performance of the agreement and for servicing the account;
- handling enquiries, claims and refund requests;
- ensuring the security of the Platform, preventing unauthorised access and investigating incidents;
- complying with obligations imposed by law, including record-keeping and document retention.
5.2. The Operator does not use personal data for advertising targeting, for profiling, or for taking decisions solely on the basis of automated processing.
6. Legal Bases for Processing
6.1. Personal data is processed on the following bases:
- performance of an agreement to which the data subject is a party, and steps necessary to conclude it — account, profile, registration and order data;
- consent of the data subject — information provided voluntarily, including optional profile fields and consent to receive mailings;
- compliance with obligations imposed on the Operator by law — accounting records and document retention;
- the Operator’s legitimate interest in the security of the Platform — security log records.
6.2. Agreement with the Public Offer and consent to receive advertising and informational mailings are recorded separately. Withdrawing consent to mailings does not affect the ability to participate in the Congress.
6.3. Withdrawal of consent does not terminate processing that is carried out on another legal basis, in particular data that must be retained by law.
7. Account and Authentication
7.1. User authentication is performed by a separate authentication service operated by the Operator on its own infrastructure. The user’s password is stored only in that service; the Platform application neither receives nor stores it.
7.2. A user profile is created on the Platform at first sign-in. It is created solely from verified account details — the identifier and the e-mail address. The e-mail address and the account identifier cannot be changed through the Platform’s forms.
7.3. The user’s session is maintained by service cookies that are not accessible to scripts in the browser. Access tokens are not stored in the browser and are not placed in browser local storage.
7.4. The authentication service sends service messages relating to the account: confirmation of the e-mail address and password recovery.
8. Congress Registration and Orders
8.1. When registering for the Congress, the selected registration category, the name for the badge and the details required for invoicing are processed, where the user provides them.
8.2. Agreement with the Public Offer and with this Policy is recorded as a separate entry containing the type of document, the identifier of its revision, the moment of agreement and the request identifier. No IP address and no browser information is recorded for this purpose.
8.3. An order contains the composition, amount and currency determined by the Platform on the basis of the selected registration category. Order records are not altered retroactively: a change of state is recorded as a new event.
8.4. Information about registrations and orders is available to authorised staff of the Operator in the administration area of the Platform, to the extent necessary to organise the Congress and to handle enquiries.
9. Payment
9.1. As at the date of this revision of the Policy, no payment provider is connected to the Platform and online payments are not accepted. Accordingly, no personal data is currently transferred to third parties for the purpose of processing online payments.
9.2. When a payment service is connected, bank card details are entered by the user on the payment service’s side. The Operator does not receive, process or store such details; only the information necessary to identify the order and to confirm the outcome of the payment is passed to the Platform.
9.3. Before the acceptance of online payments begins, this Policy will be supplemented with information about the payment service and about the scope of the data transferred to it.
9.4. Information about payment transactions is recorded in the Operator’s information system as immutable event records, necessary to confirm settlements and to handle enquiries.
10. Abstracts and Co-author Data
10.1. When an abstract is submitted, the content of the work, information about the authors and co-authors, and any attached file are processed.
10.2. Information about co-authors is entered by the corresponding author. By submitting the work, they confirm that the co-authors have been notified of the submission and of the transfer of their data to the Operator. A co-author is not required to have an account on the Platform, and holding information about them does not create an account for them.
10.3. Files attached to an abstract are held in closed storage. No public links to such files are produced: a file can be obtained only through an authorised request via the Platform.
10.4. After a work has been submitted, its content, the information about the authors, the attached file and the history of changes are retained, including where the work is withdrawn: this is necessary to confirm what was submitted for consideration, and when.
10.5. A co-author is entitled to contact the Operator in the manner set out in Section 19 of this Policy on matters concerning the processing of their data.
11. Scientific Review
11.1. To organise scientific review, information about reviewers, review assignments, the scores and comments filed, and conflict-of-interest declarations are processed.
11.2. The review procedure, including the applicable anonymity arrangement, is determined by the Organising Committee. Where an anonymous arrangement applies, information about the authors is not passed to the reviewer as part of the materials sent for review.
11.3. Information relating to review is confidential, is not published in the public part of the Platform, and is available only to authorised staff of the Operator and to assigned reviewers, to the extent necessary to perform their role.
11.4. Activity log records relating to review contain only information about the fact and the time of an event, and contain no scores, comments or conflict-of-interest explanations.
12. Speakers and Organisational Administration
12.1. Information about invited speakers is entered by authorised staff of the Operator and is used to compose the scientific programme of the Congress.
12.2. Only information about speakers whose publication has been confirmed is published in the public part of the Platform. The internal contact e-mail address and internal administrative notes are not published and are available only to authorised staff of the Operator.
12.3. An invitation to a speaker is sent as a service link. Such a link is time-limited and single-use; its value is held by the Operator only as an irreversible hash.
12.4. Information about a declined invitation, a revoked invitation and a change of participation status is retained: deleting such records would make it impossible to confirm the agreed composition of the programme.
13. Notifications and Service Messages
13.1. The authentication service sends messages relating to the account: confirmation of the e-mail address and password recovery.
13.2. Other notifications are currently recorded by the Platform as an intention to send a message, without the message actually being sent: no message-delivery infrastructure is connected as at the date of this revision. Such a record contains the type of notification, the recipient’s language and a reference to the related record, and contains no e-mail address, no name and no message text.
13.3. When message-delivery infrastructure is connected, this Policy will be supplemented with information about the service used and about the scope of the data transferred to it.
13.4. The Platform does not carry out advertising mailings. Consent to receive mailings is recorded separately from agreement with the Public Offer and may be withdrawn.
14. Cookies and Technical Data
14.1. The Platform uses only technically necessary cookies:
14.2. The cookies that are set:
- aocr_session — the encrypted session of a signed-in user;
- aocr_refresh — encrypted information required to extend the session;
- aocr_auth_flow — temporary information required to complete sign-in securely;
- aocr_locale — the interface language chosen by the user.
14.3. The Platform uses no web analytics systems, advertising networks, tracking pixels or other third-party scripts that collect data about visitors. No cookies are set for advertising or analytics purposes.
14.4. Security logs record the IP address, browser information, the request identifier, the event type and the time of the event. These records are used to secure the Platform and to investigate incidents.
14.5. Activity log records contain no passwords, tokens, bank card details or other secret information.
15. Transfer of Personal Data to Third Parties
15.1. The Operator does not sell personal data, does not pass it to advertising networks and does not provide it to third parties for their own purposes.
15.2. An infrastructure (hosting) provider is engaged in the processing, on whose equipment the Platform’s servers are located. Such a provider acts on the Operator’s instructions and is not entitled to use the data for its own purposes.
15.3. The authentication service and the file storage are operated by the Operator on its own infrastructure and are not third-party services.
15.4. As at the date of this revision of the Policy, the Operator engages no payment service, no e-mail delivery service, no web analytics system and no advertising platform in the processing. The engagement of any such service will be reflected in this Policy before processing begins.
15.5. Personal data may be provided to state authorities in the cases, to the extent and in the manner expressly provided for by the legislation of the Republic of Uzbekistan.
16. Place of Processing and Cross-Border Transfer
16.1. Personal data is processed on the server infrastructure used by the Operator to run the Platform.
16.2. The Operator does not carry out cross-border transfers of personal data for advertising, analytics or marketing purposes.
16.3. If the provision of services requires engaging a processor located outside the Republic of Uzbekistan, such a transfer will be carried out in the manner provided for by the legislation of the Republic of Uzbekistan and will be reflected in this Policy before the transfer begins.
17. Retention Periods
17.1. Personal data is retained for no longer than is necessary for the purposes set out in Section 5, or for the period established by law.
17.2. The following retention principles apply:
- account and profile data — for the lifetime of the account;
- registration, order and settlement data, and records of agreement with the documents — for the period established by law for the corresponding accounting records;
- abstracts, information about the authors, attached files and their change history — retained from the moment the work is submitted, including where it is withdrawn, as confirmation of the material submitted for consideration;
- information relating to scientific review — for the period necessary to organise the scientific programme of the Congress and to confirm the decisions taken;
- activity and security log records — for the period necessary to secure the Platform and to comply with the requirements of law.
17.3. Activity log records are not deleted when a user profile is deleted: they contain no reference to the profile and are retained as evidence of the actions performed in the system.
17.4. Once the retention period has expired, personal data is deleted or anonymised.
18. Personal Data Protection Measures
18.1. The Operator applies organisational and technical measures aimed at protecting personal data against unauthorised access, alteration, disclosure and destruction, including:
- role-based access control: access is granted to the extent necessary to perform a duty;
- transfer of data between the browser and the Platform over a secure connection;
- storage of session information in encrypted service cookies that are not accessible to scripts in the browser;
- storage of the password only in the authentication service;
- storage of uploaded files in closed storage with no public access;
- maintaining an immutable activity log for operations affecting user data;
- restricted access to the server infrastructure.
18.2. No protective measure provides absolute security. The user is obliged to keep their credentials confidential and to notify the Operator immediately of any sign of unauthorised access to the account.
19. Rights of the Data Subject and How to Exercise Them
19.1. The data subject is entitled:
- to obtain information about the processing of their personal data;
- to require their personal data to be clarified, corrected or supplemented;
- to require processing to cease and their personal data to be deleted, where there is no other legal basis for processing it;
- to withdraw consent previously given, including consent to receive mailings;
- to appeal against the Operator’s acts or omissions to the authorised state body or to a court.
19.2. Part of the profile information can be changed by the user in the Personal Account. The e-mail address and the account identifier are changed through the authentication service, not through the Platform’s forms.
19.3. To exercise the rights set out in clause 19.1, the data subject sends a request to medschool.uz@gmail.com stating their surname, first name, the e-mail address of the account and the substance of the request. The Operator is entitled to request additional information necessary to identify the applicant.
19.4. The time limit for considering a request is 10 working days from the date of its receipt, unless another time limit is established by law.
19.5. Deleting certain information may make it impossible to provide services for participation in the Congress. The Operator informs the applicant of such consequences before acting on the request.
20. Changes to the Policy and Contact Details
20.1. The Operator is entitled to amend this Policy by publishing a new revision on the Platform. Material changes are communicated to users by a reasonable means.
20.2. The effective date of this revision: 20 August 2026. The identifier of this revision: privacy-2026-08-20.
20.3. The current revision of the Policy is published at https://aocr2027.uz/en/privacy, and also at https://aocr2027.uz/ru/privacy and https://aocr2027.uz/uz/privacy. The Russian revision is the original; the English and Uzbek translations are provided for the user’s convenience, and in the event of a discrepancy in interpretation the Russian text prevails.
20.4. Contact details for questions relating to the processing of personal data:
E-mail: medschool.uz@gmail.com
Phone: +998998773589
Postal address: 100047, Uzbekistan, Tashkent, Yashnabad District, Makhtumkuli St., 103
