Policies
Privacy notice
How the Association of Surgeons in Technology and Innovation collects, uses and protects personal data under UK GDPR.
Who we are
ASTI is a professional association for surgeons, trainees, students, researchers and engineers working with surgical technology. For the purposes of UK data protection law, the Association is the data controller for the personal data described in this notice.
What we collect
Account and membership details (name, title, email address, institution, role, career stage, specialty, country), optional professional information (biography, interests, expertise, links), membership and payment records, event bookings and attendance, education progress and certificates, competition submissions, directory preferences, newsletter preferences, and enquiry messages. Card details are handled by our payment provider and are never stored by the Society.
Why we use it
To administer membership and renewals, run events and education, issue certificates, operate competitions, publish the opt-in members directory, send service messages, and — where you have consented — send the newsletter. Our lawful bases are contract (membership services), legitimate interests (running the Society and its education), consent (marketing, directory listing, optional data) and legal obligation (financial records).
GMC numbers and professional details
A GMC or professional registration number is optional. Where provided it is used only to verify eligibility for a membership category. It is never displayed in the directory, shared with third parties or used for any other purpose.
Directory visibility
Inclusion in the members directory is opt-in and can be switched off at any time from your dashboard. Only the fields you choose are shown to other signed-in members. Email addresses are not published; contact is made through the Society's messaging feature.
Sharing
We use service providers for hosting, database services, email delivery and payment processing. They act on our instructions under contract. We do not sell personal data. Aggregate, non-identifying statistics may be published in annual reports.
Retention
Membership and financial records are kept for as long as required for accounting and audit purposes. Account data is kept while your account is open and for a limited period afterwards. Enquiry messages are kept only for as long as needed to answer them.
Your rights
You have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent at any time. You can export your profile data from your dashboard and contact the Society to request deletion. You may also complain to the Information Commissioner's Office.
Security
Access to member data is restricted by role, protected by database-level access rules, and logged for audit purposes. Passwords are stored by our authentication provider using industry-standard hashing.
This page was last reviewed when the website was first published.