AXIS2027
Legal

Privacy notice

How we collect, use and protect your personal data when you create an account, submit work, register or partner with AXIS 2027. In short, we collect only what we need to run the conference, we never sell your data, and we share it with partners only if you opt in.

Draft — subject to legal review

At a glance

Four commitments.

No card numbers

Payments go through Stripe. We never see or store your full card details.

No tracking cookies

We use only the essential session cookie that keeps you signed in.

Opt-in sharing

Partners receive your details only if you explicitly opt in.

UK & EU hosting

Your account and submission data are stored in a UK or EU region.

1. Who we are

AXIS 2027 (Aberdeen eXchange for Industry & Science, the International Conference on Energy Transition & Mechanics) is organised by Bon Accord Symposia Ltd, Aberdeen, Scotland, United Kingdom. Company status: In formation — company registered in Scotland. Bon Accord Symposia Ltd is the data controller for the personal data described in this notice. Company and ICO registration numbers will be added here once issued.

For any question about your data, or to exercise your rights, contact us at hello@axis2027.example with "Privacy" in the subject line.

2. What we collect

Account data

Your name, email address, password (held only as a secure hash by our authentication provider), affiliation, country, job title or career stage, and your communication preferences.

Submissions and peer review

Abstracts, full and extended papers, author and co-author names and affiliations, track and format choices, image competition entries, and reviewers' scores and comments. If you review for us, we also keep your areas of expertise and any conflicts of interest you declare.

Registration and payments

Your fee category, any discount you claim with its supporting evidence (for example proof of student status), extras such as gala tickets, and the names of accompanying persons. Card payments are processed by Stripe. We never receive or store your card number. We receive only a payment reference, the amount, the date and limited card details such as the brand and last four digits.

Invoices and purchase orders

Billing name and address, the purchase order number, the finance contact and their email, and VAT details where relevant.

Attendance and support needs

Dietary requirements, access needs, emergency contact details if you give them, your photography preference, and records of check-in and session attendance used for CPD certificates. Dietary and access information can reveal health or religious information. We use it only to arrange catering and support, with your explicit consent.

Partners and exhibitors

Contact details of the people who arrange a partnership, and the logos and materials you send us.

Website and security data

Technical data such as IP address, browser type and request logs, which our hosting provider processes to deliver the site and protect it from abuse, including bot checks on forms.

3. Why we use it, and our lawful bases

  • Contract: to run your account, handle submissions, register you, take payment, issue invoices, visa invitation letters and certificates, and deliver the conference in person and online.
  • Legitimate interests: to run fair peer review, keep the site and conference secure, handle code of conduct reports, publish the programme and proposed proceedings, and send essential service messages about the conference you are involved in. We weigh these interests against your rights.
  • Legal obligation: to keep financial and VAT records and to respond to lawful requests.
  • Consent: for news about future events, for sharing your details with partners, and for processing dietary or access information that reveals health or religious information. You can withdraw consent at any time without affecting the conference services you have paid for.

4. Who processes your data for us

We use a small number of service providers (processors), each bound by a data processing agreement and permitted to act only on our instructions.

  • Cloudflare: website hosting, content delivery, security and bot protection.
  • Supabase: database, file storage and account authentication, hosted in an EU or UK region.
  • Stripe: card payment processing. Stripe is also an independent controller for some data it needs for fraud prevention and its own legal duties.
  • Our email provider: transactional emails such as confirmations, decisions and invoices. The provider will be named here once confirmed.

Some providers may process data outside the UK. Where they do, we rely on UK adequacy regulations or on the UK International Data Transfer Agreement or Addendum to protect it.

5. Who else sees your data

  • Programme and proceedings: author names, affiliations and abstracts of accepted work appear in the programme, the abstract book and, for full papers, the proposed proceedings volume or journal special issue.
  • Reviewers and committee members: see the submissions they are assigned. Review is single-blind, so reviewers see authors' names but authors do not see reviewers' names.
  • Partners and exhibitors: receive your name, affiliation and contact details only if you explicitly opt in at registration or in your account. The opt-in is off by default and you can withdraw it at any time. Withdrawal applies to future sharing.
  • Venue and caterers: receive names for badges and access, and dietary information without contact details.
  • Professional advisers and authorities: where we are required to by law.

We never sell your personal data.

6. How long we keep it

  • Accounts: until you delete your account, or three years after the last conference you took part in, whichever comes first.
  • Accepted submissions: abstracts and papers published in the programme or proceedings form part of the permanent scholarly record.
  • Unsuccessful submissions and reviews: deleted within twelve months after the conference.
  • Financial records: invoices, payment references and VAT records are kept for six years after the end of the financial year, as UK law requires.
  • Dietary, access and emergency contact details: deleted within three months after the conference.
  • Code of conduct reports: kept securely for as long as needed to deal with the report and any later events.

7. Cookies

We use only strictly necessary storage: a session token, held as a cookie or in your browser's local storage, that keeps you signed in to your account. Our hosting provider may also set a short-lived security cookie to protect forms from bots. We do not use advertising, analytics or tracking cookies, so we do not ask for cookie consent.

8. Your rights

Under UK data protection law you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, subject to our legal and publication obligations;
  • restrict or object to our processing, including objecting to processing based on legitimate interests;
  • receive your data in a portable format;
  • withdraw consent at any time, where we rely on consent.

You can update most details yourself in your account. For anything else, email hello@axis2027.example. We will respond within one month.

9. Security

We use encrypted connections (HTTPS), strict security headers, role-based access so that reviewers and committee members see only what they need, and providers with recognised security certifications. Only authorised members of the organising team can access registration and payment records.

10. Complaints

If you are unhappy with how we have handled your data, please contact us first so we can try to put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk/make-a-complaint or on 0303 123 1113.

11. Changes to this notice

This notice is a draft and is subject to legal review. We will update it as arrangements are confirmed, and if we make a significant change we will tell registered users by email.

Your data, your choice

Questions about your personal data?

Ask us what we hold, correct it, or withdraw consent for partner sharing at any time.