Focused Research Organization
Get involved

Privacy

What we keep, and what we don't.

IIDA collects personal data in three places: the problem bank, the visitors' register, and the founding members' register. Nothing else on this site collects anything. There are no analytics, no advertising trackers, and no third-party scripts.

The registers

What we collect

Only what you type into a form: your name, and whichever of organisation, city, role, a short statement and a link you choose to provide. Visitors also tell us which member referred them. We store a salted hash of your IP address and your browser's user-agent string, solely to investigate abuse of the forms.

Photographs. Founding members may have a photograph on their entry. Some were uploaded by IIDA, on the same footing as the names and titles described below; others were chosen by the member from their invitation link, and a member's own choice always replaces ours. Either way it is shown only while the member wants it: unticking the box on your invitation removes the photograph and deletes the stored file, and withdrawing deletes it too. Photographs are never used for anything but your entry on this site — no facial recognition, no analysis, no sharing.

This site sends no email at all, and the visitors' form does not ask for an address. Two places we do hold one, both stated plainly because neither is obvious from the forms:

  • Founding members. If you were invited to the founding cohort, we hold your name and one contact detail someone at IIDA already had for you — usually a LinkedIn profile — because that is how your invitation reached you. We send invitations by hand; you did not type anything into this site to be invited. Neither is ever published, and you can ask us to delete both at any time, whether or not you accept.
  • An address you chose to publish. The invitation form offers an optional email field, off unless you tick it. If you tick it the address appears on your entry, so that people reading it can write to you — we still send you nothing. A published address will be harvested by scrapers sooner or later, which is why it is off by default and why we would rather say so than imply we can stop it. Untick it, or withdraw, and it is gone.
  • The problem bank. An organisation submitting a problem gives a contact address, because a problem cannot be scoped without reaching the people who have it. Never published, and nothing is ever sent to it automatically — a member writes by hand.

What we publish

Your name, and the specific fields you ticked to publish. Every optional field defaults to not published. Who referred you is shown to the reviewer and is never published. A problem bank contact address is never published, never sold, and never shared.

The legal basis

For the visitors' register and the problem bank: consent, recorded at the moment you give it, together with the exact version of the wording you agreed to. Nothing is published without that record, and a member reviews every entry before it appears.

The founding cohort is different, and we would rather say so than imply otherwise. Those entries were published by IIDA from public professional information — name, title, city, LinkedIn profile — before the people concerned had confirmed anything. They are marked listed on the register. Each has been invited to correct the entry, choose what it shows, and confirm it; until they do, it is our assertion about them rather than their own words, and we do not record it as consent. If you are one of them and would rather not be there, say so and it is gone the same day — no reason needed.

Because we do not verify an email address, the check that a submission is genuinely yours is a human one — a visitor names the member who referred them, and we ask that member before publishing anything. If you find an entry about you that you did not create, write to us and we will remove it immediately.

Withdrawing

When you submit or confirm an entry, we show you a permanent one-click removal link on screen and ask you to save it. It needs no login and no explanation, and it takes effect on the next site build — usually within minutes. That page is the only place the link ever appears: we store only a one-way hash of it, so we cannot resend it, look it up, or recover it for you.

If you lose it — or never had one — write to research@iidalabs.org and we will remove you by hand. That route always works and needs no proof of anything.

When you withdraw we delete your name, organisation, city, statement, links, referral, IP hash and user-agent, and any contact address held for a problem. We keep only a record identifier and, for founding members, the member number, so that a number is never reissued to someone else.

How long we keep it

  • Submissions awaiting review: deleted after 90 days if no decision is taken
  • Declined submissions: deleted after 90 days
  • Published entries: kept until you withdraw
  • Approval decisions: an audit record is kept indefinitely, holding the record identifier, the action, who took it and when — no personal data

Where it lives

In a Cloudflare D1 database, in Cloudflare's Asia-Pacific region. Nothing is sent to an email provider, because this site sends no email. We do not transfer personal data to anyone else.

Your rights

You can ask what we hold about you, ask us to correct it, or have it erased — the removal link does the last of these immediately. For anything else, write to research@iidalabs.org, and we will respond within 30 days.

Changes

If we change what we collect or publish, we bump the consent wording version and ask again. We do not retroactively apply new terms to consent already given.

Last updated 3 August 2026. IIDA is being established as a Section 8 non-profit; this notice will be reissued in the entity's name once that registration completes.