Data Processing Policy

Policy Overview

Data collected by the American Association for Anatomy (AAA) are used to provide better service to AAA’s members and other users of the AAA’s website. It is AAA’s policy to collect and store only information that users voluntarily provide.

Personal Data

Personal Data is defined in this policy and in the General Data Protection Regulation (GDPR) as any information related to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier.

Data Controller

The AAA is the data controller of your Personal Data, but AAA also acts as a data processor on behalf of members for Personal Data that is processed through the websites.

Data Processing

Information submitted on the AAA’s websites is collected, stored, and processed in the United States. If you are outside the U.S., your Personal Data and other information will be transferred to the U.S. The data privacy and data protection laws outside your country may offer less protection than the laws in your country. By using our website and services, you agree to the transfer of your Personal Data as described in this policy. If you do not agree to such cross-border transfers of your Personal Data, please do not submit it through our website.

Notice for Website Visitors

The AAA may collect certain personal data when a user visits the website. Aggregate data, such as IP addresses and the number of hits per page, may be collected. We may use information about your IP address to help diagnose problems, perform administrative tasks, analyze trends, track page usage statistics, and gather information that assists us in identifying visitor preferences. We may also use aggregate data for our business purposes such as disclosing such data to our partners and service providers; however, this aggregate data does not identify you. Notwithstanding anything herein to the contrary, the AAA may share personal data disclosed with consultants and staff for internal business purposes and as required by law if such data are subpoenaed.

Additionally, web browsing data is stored in and analyzed by Google Analytics and is set to expire after 26 months of no visits to our site. Upon a visit to our site your aggregate data is considered a new session and the expiration period begins again.

Cookies

A cookie is a file that stores data on a user’s computer or returns it to the web server. The data in the file is information a user has entered using an online form, or generic information about the visiting user, such as IP address or browser type. A cookie can either be temporary or persistent, but ultimately the user is in control of if and how any cookie is stored through their web browser.

AAA requires cookies to provide functionality on certain areas of the website such as the member portal. If cookies are not enabled, those areas will not function as intended and the AAA will be unable to provide the full range of services the user might be expecting. AAA does not store any financial information in cookies.

Online Forms

Several areas of the AAA website (such as membership forms, meeting registration forms, abstract submission forms, award submission forms) request users to provide various types of information: contact information (e.g., names and email addresses), financial information (like credit card information), and demographic information (like address and ZIP Code). Each type of information serves a different purpose, depending on where it is requested. The types of personal data we collect are based on the services being requested by the user. This data is stored in our membership database and may be shared with third-party vendors for the business of AAA programs and communication. The third-party vendors we share membership data with are for the purposes of AAA-related business and relate to marketing and running programs of interest to members such as printed mailings, Experimental Biology, AAA journals, our website and membership database vendor, and other association business purposes.

Contact information obtained from online forms may be used to provide information about educational programs or other AAA program and events. Financial information that is collected is used solely to bill the user for products and/or services ordered. Financial information will in no way be used for marketing purposes, nor will it be shared with any third parties unless the third party manages the billing for the AAA.

Emails

The AAA uses email as a method to communicate with members and colleagues. Users may withdraw consent to receive marketing and promotional emails at any time using the unsubscribe link at the bottom of a marketing email, but note that this may also unsubscribe you from pertinent member email communications. AAA staff may still communicate with you directly via their personal email accounts, and using the email address you provided in your membership application, to discuss AAA business. If you wish to no longer have emails sent to you from AAA regarding any issue, please contact the office at the contact method of your choice provided at the end of this document.

Security Capabilities and Financial Information

Financial information may be collected online when individuals register for meetings, submit abstracts, order publications, or make payment for membership. The online forms are secured using SSL protocols.  This encrypts the entered information during the transaction in order to protect the information from unauthorized access. The SSL certifications are provided by trusted and established certificate vendors. No credit card data is stored in electronic or paper format after charges have been processed by the AAA.

External Links

This site contains links to other sites. AAA is not responsible for the privacy practices or the content of external websites. Websites maintained by third parties may collect information and use it in a way inconsistent with this policy. We encourage users to be aware when leaving the AAA’s websites, and to read the privacy statements of each website they visit. Websites maintained by third parties may also refer to AAA products, processes, or services; unless AAA has provided explicit authority, such references in no way indicate our endorsement, recommendation, or preference.

Feedback

We may request information regarding various aspects of our services and programs from users through surveys. Survey participation is completely voluntary and the user has a choice whether or not to disclose any information. Information requested may include contact information and demographic information. Feedback received is used to improve our websites and programs. Personal information submitted by the user in response to surveys may be used to provide information on opportunities for participation in educational activities and leadership in AAA, as indicated in survey forms.

Electronic comments submitted in connection with or in response to a request for input will only be published if permission is provided by the user. Participation is completely voluntary and the user has a choice whether or not to disclose any information.

Anatomy Connected Community and Public Areas

Data from membership profiles is shared with our online community, Anatomy Connected. Some information posted to this forum may be available for viewing by the general public. Use of such interactive web pages is voluntary and information posted on these forums may be deleted at any time. If you do not wish to share your data with Anatomy Connected, it can be removed. We expect communications on such pages to be respectful of others and of the AAA’s mission. We do not actively monitor the discussion forum. Please use caution when posting information. The AAA does not control the sending or receiving of email messages as a result of postings to our websites. Anatomy Connected posts are always viewable by other AAA members and a Directory of Members is available for members only to search. Personal data that is part of your membership profile with AAA is also part of your Anatomy Connected profile through data sharing between AAA and our third-party host of Anatomy Connected (Higher Logic).

Ways of Obtaining Personal Data

The ways by which AAA obtains Personal Data are defined hereby:

AAA does not obtain any personal information about users unless they have voluntarily provided that information to AAA via means including but not limited to membership forms, surveys, award applications, association voting, data provided in Anatomy Connected, registering for our events including the Annual Meeting at  Experimental Biology, or other online or hard-copy forms. Members and users may choose to submit personal information by mail, phone, email, or other means as deemed appropriate at that time.

The types of personal data that we collect vary based on the services offered but generally include name, address, telephone number, company name, job title, email address, curriculum vitae (CV) or resume, credit card information, and other information voluntarily submitted.

While on the AAA website, information may be collected about your device and activity on the website. Some of the information collected may consist of, but is not limited to, search terms, browser information, computer or device type, operating system, website usage, referring/exit pages, and date/time stamp.

Use of the Information this Site Gathers and Tracks

The AAA uses voluntarily-submitted contact information to send members and prospects information about meetings and membership benefits and discounts, such as voting privileges, award opportunities, leadership opportunities, etc., as well as the AAA e-newsletter.  Contact information is also used when necessary for contractual and legitimate business purposes. The online Membership Directory is provided for informational purposes, and members may elect to be excluded from the directory at any time by hiding themselves from the directory, which can be done in the user account privacy settings. (The Directory is only accessible to current members and requires a login through Anatomy Connected.)

AAA does not rent or sell its membership and meeting registration mailing lists for use by third parties. We  may share members’ or prospects’ contact information for legitimate business purposes with third-party vendors, such as mailing address for use by a printing company to mail printed membership, renewal, or marketing material.

We also compile, anonymize, and/or aggregate personal data and other information collected about websites visitors as described in this policy and use such anonymized and/or aggregated data for our business purposes internally. This data is shared with Google Analytics to understand web visitor traffic. This aggregate information does not identify you. This use of your AAA website browsing data does not identify you, and is necessary for our legitimate interests in understanding how the websites and our products and services are being used by you and to improve your experience on it.

We may also disclose personal data to third parties in the following circumstances:

  • If you request or authorize (when required by the law, we will inform you in advance of the third parties to which we may provide your data and the purpose for doing so, and we will obtain your prior consent for such use);
  • The information is provided, to comply with the law (for example, to comply with a search warrant,  subpoena or other legal process), to protect our rights, property or safety, or the rights, property or safety of our employees or others, or to investigate fraud,
  • To address emergencies;
  • To address disputes, claims, or to persons holding a legal or beneficial interest;
  • If we are involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, in which case your personal data and other information may be transferred to a successor or affiliate as part of that transaction along with other assets.

Data Storage

Personal membership data collected from our members at the time they joined the association or when they voluntarily update their membership profiles is stored electronically in our membership database. Data may be pulled from this database for legitimate use by AAA staff. Membership data are kept as long as members are active, dues-paying members. Once a member stops paying dues, they are considered a prospect. Prospect data is kept for twenty-four (24) months and used for business practices related to marketing events and programs of interest to prospects. This marketing and promotion will come through email and/or postal mail. AAA regularly performs data deletion of prospect data after the 24-month period has passed.

Data Subject Rights

Subject to applicable law, you have the following rights in relation to your personal data:

Right of access: If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may need to charge a reasonable fee.

Right to rectification: If your personal data is inaccurate or incomplete, you are entitled to have it rectified or completed. If we have shared your personal data with others, we will tell them about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you with whom we shared your personal data so that you can contact them directly.

Right to erasure: You may ask us to delete or remove your personal data and we will do so in some circumstances, such as where we no longer need it (we may not delete your data when other interests outweigh your right to deletion). If we have shared your data with others, we will tell them about the erasure where possible. If you ask us, where possible and lawful to do so, we will also tell you with whom we shared your personal data so that you can contact them directly.

Right to restrict processing: You may ask us to restrict or ‘block’ the processing of your personal data in certain circumstances, such as where you contest the accuracy of that personal data or object to us processing it. We will tell you before we lift any restriction on processing. If we have shared your personal data with others, we will tell them about the restriction where possible. If you ask us, where possible and lawful to do so, we will also tell you with whom we shared your personal data so that you can contact them directly.

Right to data portability: Effective 25 May 2018, you have the right to obtain your personal data from us that you consented to give us or that is necessary to perform a contract with you. We will give you your personal data in a structured, commonly-used, and machine-readable format. You may reuse it elsewhere.

Right to object: You may ask us at any time to stop processing your personal data and we will do so:

  • If we are relying on a legitimate interest to process your personal data – unless we demonstrate compelling legitimate grounds for the processing; or
  • If we are processing your personal data for direct marketing.

Rights in relation to automated decision-making and profiling: You have the right to be free from decisions based solely on automated processing of your personal data, including profiling, that affect you, unless such processing is necessary for entering into, or the performance of, a contract between you and us or you provide your explicit consent to such processing.

Right to withdraw consent: If we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on your prior consent.

Right to lodge a complaint with the data protection authority: If you have a concern about our privacy practices, including the way we have handled your personal data, you can report it to the data protection authority that is authorized to hear those concerns.

You may exercise your rights by contacting us as indicated under the “Communication Preferences” section below.

Please note: In some instances, if you withdraw your consent for AAA to hold and process your personal information, this may cause ineligibility for membership. Without personal data we would be unable to create a membership for you, thus voiding your eligibility. If you wish to continue to be a member, but would like to change how your personal data are processed by AAA, we will work with you to our best ability to make this happen, if possible.

Changes to This Statement

The AAA reserves the right to change this policy at any time. We will use data in accordance with the privacy statement under which any data have been collected. Questions should be sent to info@anatomy.org.

Communication Preferences

If you wish to change your consent to this policy – including consenting to, or removing consent from, all of our communication areas – contact the AAA office by mail, phone, or email as shown below.