Data protection & your rights
Privacy
What the AM26 website collects, why, and how you can control it: under the EU General Data Protection Regulation (GDPR). Last updated July 3, 2026.
Who we are
This website is operated by IFMSA: the International Federation of Medical Students' Associations, a non-profit association registered with the Netherlands Chamber of Commerce, Amsterdam: for the AM26 General Assembly. IFMSA is the data controller for the personal data described on this page. For any question about this policy or your data, write to the address at the bottom of this page.
GA registration
This website does not handle GA registration and stores no registration data. Registration runs through your NMO and official IFMSA channels.
The contact form
If you write to us through the enquiry form, your name, email, and message are relayed to the relevant team's mailbox by email (via our provider, Resend) and answered there. They are not stored in any database, and we use them only to reply to you.
The Wall (photo wall)
If you sign in to post on the Wall, we store a handle, display name, your self-selected NMO (delegation), and: if you choose one: your avatar settings. Photos you submit are stored together with any caption and your consent record, and are published only after review. You can request removal of your photo or profile at any time.
Push notifications
If you opt in to push notifications, your browser creates a subscription (a technical endpoint and encryption keys) that we use to send you updates, plus your language preference so alerts arrive in the right language. You can withdraw this at any time from your browser or device settings.
The scavenger hunt
If you play the AM26 Hunt, your claims are linked to your Wall profile, and we record a salted, non-reversible hash of your IP address to detect abuse: for example, one device claiming a station under many identities. No real name is required to play.
The admin console
IFMSA staff and organizers who manage this website sign in through a separate admin console. We keep a username, a securely hashed password, and an audit log of admin actions (including a salted hash of the IP address involved) for accountability and security. This does not apply to general website visitors.
Cookies and similar technologies
We use a small number of cookies to keep you signed in and remember your preferences, plus optional analytics cookies you can accept or decline. See our Cookie Policy for the full list, and use the cookie-settings link in the footer to change your choice at any time.
Why we're allowed to process this data
We rely on your consent for optional features (Wall photos, push notifications, analytics cookies); on our legitimate interest in keeping the site secure and free of abuse (hashed IP addresses, admin audit logs); and on the steps necessary to provide a service you've asked for (keeping you signed in while you use the Wall or Hunt).
Who we share data with
We use a small number of processors to run this site: Resend (email relay), Supabase (sign-in and database), Cloudflare (photo storage), Vercel (hosting and analytics), Umami Cloud and Sentry (analytics and error monitoring), and MapTiler (map tiles). Some of these providers may process data outside the European Economic Area, notably in the United States; where that happens, we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard. We never sell your data or use it for advertising.
How long we keep it
Wall photos, profiles, and Hunt data are deleted within 90 days after the General Assembly ends. Push subscriptions are deleted when you unsubscribe or when the site is archived after the GA. Contact-form messages are not stored at all: they exist only as an email in our mailbox. Admin audit logs are kept for as long as needed for security accountability.
Your rights
Under the GDPR, you can ask us to access, correct, delete, or restrict the personal data we hold about you, object to our processing, and receive your data in a portable format. Where we rely on your consent, you can withdraw it at any time without affecting anything we did beforehand. Photo takedown requests made during the GA are handled within 24 hours. To exercise any of these rights, email us at the address below. If you believe we haven't handled your data properly, you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Children
This website is built for medical students and delegates attending an international General Assembly, and is not directed at children. We do not knowingly collect data from children.
Changes to this policy
We'll update this page if what we collect changes: for example, when a new GA-week feature launches. The date at the top always reflects the latest version.
