Privacy Policy
The Future of Anaesthesia and Critical Care in Africa
Last updated 7 August 2026. This policy explains how the Society of Anaesthesiologists of Tanzania (SATA), as organiser of the 10th All Africa Anaesthesia Congress (AAAC 2027), handles personal data. It is written to meet Tanzania's Personal Data Protection Act, 2022 and the GDPR-style expectations of delegates travelling from more than 25 countries.
1. Who we are
Data controller: Society of Anaesthesiologists of Tanzania (SATA), organiser of AAAC 2027, Julius Nyerere International Convention Centre, Dar es Salaam, Tanzania.
Data protection contact: privacy@aaac2027.com.
2. What we collect and why
- Identity & contact data (salutation, full name, gender, email, phone, country) — to create your delegate account, confirm registration and contact you about the congress.
- Professional data (institution, institution type, professional category, professional/registration number) — to verify eligibility for the correct registration category and to award CPD credits.
- Passport number — used only to produce your official invitation and visa support letters. Providing it is optional; you can register without it.
- Photograph (optional) — for badge production and delegate identification at the venue.
- Payment records (amount, method, reference, uploaded proof-of-payment receipt) — to verify and reconcile registration fees.
- Abstracts and submissions — for scientific review and, if accepted, publication in the congress programme and abstract book.
- Networking data — only where you explicitly opt in to appear in the delegate directory or send connection requests.
- Technical data (IP address, device/browser information, session cookies) — to keep the platform secure and functioning.
We do not sell personal data, and we do not use it for advertising or profiling.
3. Legal basis
We process your data on the basis of (a) performance of a contract — delivering the congress registration you requested; (b) your consent — optional items such as the delegate directory, photograph, newsletter and passport number; (c) legitimate interests — platform security, fraud prevention and congress administration; and (d) legal obligation — financial and tax records.
4. How your data is protected
- All traffic is served over HTTPS with HSTS enforced.
- Passwords are never stored by us in readable form — authentication is handled by our identity provider, which stores only a salted bcrypt hash. Nobody, including congress staff, can read your password.
- Passport numbers and phone numbers are stored encrypted at rest and are only decrypted through access-controlled functions for you or authorised congress staff.
- Payment receipts and photographs are stored in private buckets that are not publicly accessible; uploads are validated server-side for real file type and size.
- Database access is governed by row-level security so delegates can only read their own records.
5. Who we share it with
Data is shared only with parties needed to run the congress: our cloud hosting and database provider, our transactional email provider (for confirmations and notices sent from notify.aaac2027.com), the banking partner processing your registration fee, and the venue for access/badging. Where accepted, abstracts and presenter names are published in the programme. Some providers operate outside Tanzania; transfers are limited to what is necessary to deliver the service and are protected by contract.
6. How long we keep it
- Delegate account and registration records: up to 24 months after the congress closes.
- Passport numbers: deleted within 90 days of the congress closing, once visa and travel needs have passed.
- Payment and financial records: 7 years, as required by Tanzanian financial and tax law.
- Abstracts and CPD certificates: retained as part of the permanent scientific and accreditation record.
- Photographs: deleted within 12 months of the congress closing.
7. Your rights
You may request access to your data, correction of inaccurate data, deletion ("right to be forgotten"), a portable copy, restriction of processing, or withdrawal of any consent you gave. You can also object to processing based on legitimate interests.
Email privacy@aaac2027.com from your registered address and we will respond within 30 days. Deleting your account removes your profile, directory listing and optional data; financial records are retained where the law requires. You may also complain to Tanzania's Personal Data Protection Commission.
8. Cookies
We use only strictly necessary cookies and local storage — for your login session, language preference and security. We do not use advertising or cross-site tracking cookies.
9. Children
The platform is intended for healthcare professionals and students aged 18 and over.
10. Changes
Material changes to this policy will be announced by email to registered delegates and reflected in the "last updated" date above.
See also our Terms of Service.
