Privacy Policy
Last Updated: August 2026
1. Introduction & Data Controller
The National Institute for Pathology & Computational Research ("NIPCR", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. NIPCR acts as the Data Controller for the personal data collected through our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (nipcr.org) and use our credentialing and evaluation services.
2. Information We Collect
We only collect the information absolutely necessary to evaluate your academic research and maintain your registry profile. In the preceding 12 months, we have collected the following categories of information:
- Identifiers: Your name and email address.
- Professional or Employment-Related Information: Academic history, job titles, and titles of your submitted manuscripts.
- Commercial Information: Records of fellowship evaluation fees paid (processed securely via our merchant of record, Paddle).
- User-Generated Content: Profile information that you submit for public display on the NIPCR Registry.
What we DO NOT collect:
We do not collect biometrics, sensory data, student education records (FERPA), or demographic characteristics (such as age, gender, or race). We do not build consumer profiles based on psychological or behavioral inferences.
3. How We Use Your Information
We use the information we collect to:
- To perform methodological audits and evaluate your submitted manuscripts for the NIPCR Fellowship credential.
- To populate and maintain the public NIPCR Registry.
- Communicate with you regarding your application status, billing, and institutional updates.
- Prevent fraud and enforce our Terms of Service (e.g., maintaining a blacklist for fraudulent chargebacks).
Note on Artificial Intelligence: We do not offer AI-based services to consumers. We may utilize internal AI tools to assist our staff in reading and summarizing manuscripts submitted during the evaluation process, but your private personal information is not used to train AI models.
4. Tracking Technologies and Cookies
We value your privacy and do not use invasive marketing trackers, Google Analytics, social media pixels, or cross-site advertising cookies.
We only use essential session cookies. These are strictly necessary to authenticate your session, keep you securely logged in to your NIPCR dashboard, and prevent cross-site request forgery. Because we do not engage in non-essential tracking, our website does not actively respond to Global Privacy Control (GPC) or "Do Not Track" signals.
5. Data Retention
We retain your personal information for as long as you maintain an active account with us to keep your credential active on the public registry.
If you choose to delete your account, your personal data and registry profile will be purged from our active databases. However, please note that certain transactional and commercial data (such as records of payments made via Paddle) will be retained for a longer period strictly as necessary to comply with international tax, legal, and accounting obligations.
6. Security Measures
We implement enterprise-grade security measures to protect your data. Our backend infrastructure utilizes encrypted connections (HTTPS), secure password hashing, and Row Level Security (RLS) provided by our infrastructure partners (Vercel and Supabase) to prevent unauthorized access.
7. International Data Transfers
NIPCR is based in the United States, and our servers are located in the United States. If you are accessing our services from the European Economic Area (EEA), the United Kingdom, or other regions with laws governing data collection and use, please note that your personal information will be transferred to the United States.
We ensure an adequate level of protection for international transfers by adhering to the European Commission's Standard Contractual Clauses (SCCs) when transferring data to our US-based service providers.
8. Your Privacy Rights (CCPA, GDPR, and State Laws)
Depending on your jurisdiction (such as California, Texas, Florida, or the EEA), you may have the right to access, view, edit, or request the deletion of your personal information.
- No Sale of Data: We do not sell your personal information to third parties, nor do we share it with business partners for cross-context behavioral advertising.
- No Financial Incentives: We do not offer financial incentives in exchange for the retention or sale of your personal information.
- California "Shine the Light" Law: California residents may request a list of the categories of personal information disclosed to third parties for direct marketing purposes. (As noted, NIPCR makes no such disclosures).
9. Children's Privacy
Our services are intended for professional researchers and academics. Our website is not intended for use by children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to securely delete that information.
10. Contact Us
If you have any questions about this Privacy Policy, or if you wish to exercise your data rights, please contact us using one of the following methods:
- Email: privacy@nipcr.org
- Web: nipcr.org/contact