How we handle your details
Version 2026-01-v1. Last updated 23 August 2026.
Who is responsible
TLV Lifesciences Network 2026 is organised by Dot Compliance Ltd. For anything in this notice, write to privacy@tlvlifesciences.org.
What we collect, and why
If you register to attend
Your name, work email address, organisation, job title, LinkedIn profile URL, country, optionally your mobile number, and your professional domain and preferred track. We use these to decide whether to offer you a place, to contact you about the event, and to admit you on the day. The LinkedIn URL is used to confirm that applicants hold the industry roles the programme is intended for.
We also record which version of this notice you agreed to, when, and the network your submission came from — reduced to a network prefix rather than your full address — so that we can evidence consent and investigate abuse of the form.
If you apply to speak or enquire about partnership
The same contact details, plus what you tell us about your proposal, your company, the passes you need, and any logo file you upload. Uploaded files are stored privately and are only ever downloaded by our staff.
The attendee directory
The directory is opt-in and off by default. If you turn it on, other approved attendees can see your name, job title, organisation, country and professional domain. Your email address and phone number are never shown — attendees contact one another by requesting a meeting, which we relay. You can turn the listing off at any moment in your participant area, and you disappear from the directory immediately.
Meetings
When you book a meeting, we tell the other person who you are, your role, the slot and any note you wrote. That is the point of the booking, and it is the only circumstance in which we pass your details to another attendee.
Our legal basis
Your consent, given when you submitted the form, for handling your application and contacting you about this event. Our legitimate interest in running a secure event for the operational records — access logs, the audit trail of who inside the organisation looked at what, and the security measures below. Consent can be withdrawn at any time; see your rights.
Who else sees it
Nobody buys this list, and we do not sell, rent or share it for marketing. It is handled by:
- the event team at Dot Compliance, who review applications and run the day;
- Amazon Web Services, which hosts the site and the database in Frankfurt, Germany (EU);
- Amazon Simple Email Service, which delivers our email, also in the EU.
Your data is stored in the European Union and is not transferred outside it. Sponsors receive no attendee list: if you want a sponsor to have your details, you give them to the sponsor yourself.
How long we keep it
- Declined or waitlisted applications — 180 days from the decision, then deleted automatically.
- Attendee records — one year after the event.
- The internal audit trail of staff access — two years.
- Sign-in links — 15 minutes, and they work once.
- Server access logs — 400 days.
Deletion is scheduled by the database itself rather than depending on somebody remembering.
How it is protected
- Encrypted in transit (HTTPS everywhere) and at rest with a dedicated encryption key that only this application's components can use.
- Staff accounts require a second factor. Every time a staff member opens a record, exports a list, sends a mailing or erases anything, it is recorded with their name and the time.
- You sign in with a single-use emailed link. There is no password to reuse or leak, and no shared access code.
- No advertising trackers, no third-party analytics, no third-party fonts. The pages load nothing from anyone else's servers. If you reached us from a campaign link, the source, medium and campaign name in that link are stored with your registration so we know which announcement brought you — nothing is written to your device to do it, and it is read only at the moment you submit the form. We also add 1 to a running count of arrivals for that campaign, so we can compare how many people a link brought with how many registered. That count is a single number per campaign: it holds no identifier, no address and no record of you, and it cannot be traced back to any individual.
Cookies
Only two, and only once you sign in: one holds your session, one protects forms against cross-site request forgery. Both are strictly necessary, so there is no cookie banner to dismiss. We set nothing on the public pages.
Your rights
You can ask for a copy of everything we hold about you, ask us to correct it, ask us to delete it, withdraw your consent, or object to how we are using it. Write to privacy@tlvlifesciences.org and we will respond within 30 days. We may ask you to confirm your identity first — otherwise anyone could ask us to delete your registration.
If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority. In Israel, that is the Privacy Protection Authority.