YOUR DATA
Privacy Policy
How we collect, use, retain, and protect personal data when you visit the website, register, or take part in the Symposium.
Last updated: 19 August 2026
This policy applies to solsymposium.org, event registration, abstract submission, and our administration of the International Science of Learning Symposium 2027.
1. Data controller
The data controller is the Science of Learning Academy, based in Finland, as organizer of the International Science of Learning Symposium (“we” or “us”).
Privacy contact: office@solsymposium.org
Website: https://solsymposium.org
2. Personal data we collect
Depending on how you use the website and event services, we may collect:
- Identity and contact data: name, email address, phone number, organization, role, country, billing address, and account details.
- Order and payment data: ticket or product purchased, price, tax, order history and status, payment method and transaction reference. Payment providers process complete card or bank credentials; we do not receive your complete card number.
- Registration data: attendee details, presenter category and registration code, invitation-letter request, and event communications.
- Assistance and dietary data: information you voluntarily provide about accessibility or airport assistance, food allergies, intolerances, or special diets. This may reveal health information and is treated as sensitive data.
- Abstract data: title, abstract, presentation format, names, affiliations and contact details of contributors, supporting information, review outcome, and technical or accessibility requirements.
- Communications: messages, enquiries, feedback, consent records, and information needed to resolve support or refund requests.
- Technical and usage data: IP address, browser and device information, timestamps, referring pages, security logs, and cookie or session identifiers needed to operate the site, cart, checkout, and account.
We normally receive data directly from you. We may also receive transaction status or fraud-prevention information from a payment provider, attendee details from the person or organization making a group booking, and contributor information from the person submitting an abstract. If you provide another person’s information, you must be entitled to do so and should direct them to this policy.
3. Why we use personal data and our legal bases
| Purpose | Legal basis |
|---|---|
| Take payment, fulfil orders, issue tickets and confirmations, administer attendance, and provide requested event services | Performance of a contract or steps requested before entering a contract |
| Review abstracts, build and publish the programme, communicate with presenters, and run sessions | Performance of a contract and our legitimate interests in organizing the event |
| Maintain invoices, transaction records, and other legally required records | Compliance with legal obligations |
| Answer enquiries, manage complaints, prevent fraud, secure the website, diagnose faults, and establish or defend legal claims | Our legitimate interests in operating secure, reliable services and protecting our rights and users |
| Use voluntarily provided health-related information to arrange suitable accessibility support or catering | Your explicit consent; where applicable, performance of the service you requested |
| Use non-essential analytics or marketing cookies, or send optional electronic marketing | Your consent, where these activities are used |
You may withhold optional assistance or dietary information. You may withdraw consent to our use of that sensitive information at any time by emailing us, without affecting processing already carried out. Withdrawal may mean we cannot arrange the requested accommodation or catering. Information needed to complete an order is marked as required; without it, we may be unable to register you.
5. International transfers
Some service providers may process data outside Finland or the European Economic Area. When required, we use a lawful transfer mechanism, such as an adequacy decision or the European Commission’s standard contractual clauses, together with appropriate safeguards. You may contact us for more information about safeguards relevant to your data.
6. How long we retain data
- Orders, invoices, and accounting records: for at least the period required by Finnish accounting and tax law, generally six years from the beginning of the calendar year following the relevant financial period or transaction period.
- Registration and operational event data: until the event and essential follow-up are complete, then normally no longer than 12 months, unless the information is also needed in an accounting record, dispute, or other legal record.
- Assistance and dietary data: deleted or anonymized as soon as it is no longer needed after the event, normally within 30 days, unless an incident or legal claim requires longer retention.
- Abstracts and programme records: unsuccessful submissions and review working data are normally deleted or anonymized within 12 months after the event. Published programme information and accepted abstracts may be retained as a lasting public event archive.
- Support and complaint records: for as long as needed to resolve the matter and for the applicable limitation period.
- Technical and security logs: only as long as reasonably needed for security, troubleshooting, and fraud prevention, unless an incident requires longer retention.
We may anonymize information so it no longer identifies anyone and retain the anonymous information for statistics and event planning.
8. Security
We use appropriate technical and organizational measures intended to protect personal data, including access controls, encrypted web connections, updates, backups, and limiting access to people who need the data. No online service is completely risk-free, so please use a strong, unique password if you create an account and contact us if you suspect misuse.
9. Your data-protection rights
Subject to the conditions in data-protection law, you may ask us to:
- confirm whether we process your data and provide a copy;
- correct inaccurate or incomplete data;
- delete data or restrict its use;
- provide data you supplied in a portable format;
- stop processing based on our legitimate interests, including direct marketing; and
- withdraw consent at any time.
These rights are not absolute. For example, we may retain information required for accounting, legal claims, security, or other legal obligations. To make a request, email office@solsymposium.org. We may need to verify your identity and will respond within the period required by law.
You also have the right to complain to a data-protection authority. Our lead supervisory authority is the Office of the Data Protection Ombudsman of Finland. If you live elsewhere in the EU or EEA, you may also contact the authority where you live or work.
10. Automated decisions and children
We do not make decisions producing legal or similarly significant effects solely by automated means. Payment providers may use automated fraud checks under their own notices. The website and event registration are intended for adults and professional participants; a person under 18 should register only with the involvement of a parent or guardian.
11. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. We will post the revised version here and change the “Last updated” date. We will give additional notice if a change materially affects how we use data already collected.
12. Contact
For questions or requests concerning privacy, email office@solsymposium.org.