Privacy Policy
IIHSR Medical Research Center
Medical Research Division of IIHSR European University
Effective Date: 12/10/2025
The IIHSR Medical Research Center ("IIHSR Medical Research Center", "IIHSR-MRC", "we", "us", or "our") is the dedicated medical research division of IIHSR European University.
We respect the privacy of applicants, students, researchers, healthcare professionals, academic partners, website visitors, and other individuals who interact with us. This Privacy Policy explains how we collect, use, store, protect, disclose, and otherwise manage personal information in connection with our websites, academic programmes, research activities, applications, communications, and related services.
We are committed to handling personal information responsibly, transparently, and in accordance with applicable privacy and data-protection laws.
Where applicable, our handling of personal information is intended to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), as well as other applicable privacy and data-protection requirements relevant to our operations and the individuals with whom we interact.
1. About IIHSR Medical Research Center
IIHSR Medical Research Center operates as the medical research division of IIHSR European University and supports activities including:
- Medical and clinical research
- Postgraduate medical education
- Research supervision
- Academic programmes
- Research projects and dissertations
- Academic assessment
- Professional development
- Research publications
- Academic communication
- International research collaboration
- Healthcare and medical innovation
This Privacy Policy applies to personal information collected through our websites, online application systems, academic platforms, research activities, email communications, forms, and other interactions with the Center.
2. Information We Collect
Depending on the nature of your interaction with us, we may collect different categories of personal information.
Personal and Contact Information
This may include:
- Full name
- Date of birth
- Gender, where required
- Residential or mailing address
- Country of residence
- Email address
- Telephone or mobile number
- Identification details where required
- Communication preferences
Academic Information
For applicants, students, researchers, and academic participants, we may collect:
- Academic qualifications
- Degrees and diplomas
- Academic transcripts
- Professional qualifications
- Training records
- Professional experience
- Research experience
- Curriculum vitae
- Publications
- Research interests
- Academic references
- Professional registrations where relevant
Application and Programme Information
We may collect information relating to:
- Programme applications
- Admission assessments
- Academic evaluations
- Research proposals
- Thesis or dissertation submissions
- Clinical practice documentation
- Professional experience
- Academic correspondence
- Programme progression
- Assessment results
- Graduation and certification records
Research Information
Where relevant to research activities, we may collect information associated with:
- Research projects
- Research participation
- Research proposals
- Research data
- Academic publications
- Research correspondence
- Research supervision
- Research ethics documentation
Where research involves identifiable individuals or sensitive information, additional privacy, consent, confidentiality, ethics, and data-management requirements may apply.
Payment and Transaction Information
Where fees or other payments are processed, we may collect information necessary to administer the transaction.
Payment card information may be processed directly by third-party payment providers. We do not generally require or store complete payment-card details on our own systems where the payment provider processes those details directly.
Technical and Website Information
When you use our website, we may collect technical information such as:
- IP address
- Browser type
- Device information
- Operating system
- Website pages accessed
- Date and time of access
- Referring website
- General website usage information
- Cookies and similar technologies
3. Sensitive Information
Some information may constitute sensitive information or a special category of personal data under applicable law.
Depending on the circumstances, this may include:
- Health information
- Medical information
- Disability information
- Biometric information
- Information concerning professional or clinical practice
- Information relating to research participation
- Other information classified as sensitive under applicable law
We will only collect and use sensitive information where permitted or required by applicable law and, where required, with appropriate consent or another valid legal basis.
Under Australian privacy law, sensitive information receives additional protection, and its collection is generally subject to stricter requirements than ordinary personal information.
4. How We Collect Personal Information
We may collect personal information:
- Directly from you
- Through online application forms
- Through registration forms
- Through academic submissions
- Through research applications
- Through email correspondence
- Through telephone or other communications
- Through academic institutions or professional organizations
- From referees or supervisors where authorized
- From approved representatives
- Through our website and online platforms
- From third-party service providers
- From publicly available professional or academic sources where appropriate and lawful
Where practicable, we will explain the purpose for which personal information is collected at or before the time of collection, or as soon as reasonably practicable afterwards. Australian privacy guidance specifically requires appropriate notification of matters such as the entity's identity, purposes of collection, usual disclosures, and overseas disclosures where applicable.
5. Why We Collect Personal Information
We may collect, hold, use, and disclose personal information for purposes including:
- Processing applications
- Conducting academic assessments
- Providing academic services
- Administering programmes
- Managing student and researcher records
- Providing research supervision
- Evaluating research work
- Administering examinations and assessments
- Maintaining academic records
- Issuing academic documents
- Verifying qualifications and academic records
- Managing payments and fees
- Communicating with applicants and students
- Providing student support
- Managing research projects
- Supporting academic publications
- Conducting quality assurance
- Maintaining institutional records
- Preventing fraud or misuse
- Meeting legal and regulatory obligations
- Responding to enquiries and complaints
- Improving our services and website
- Maintaining information security
- Conducting legitimate institutional research and analysis where permitted
We will seek to ensure that personal information is used only for purposes that are reasonably necessary, directly related, authorized, or otherwise permitted under applicable law.
6. Academic and Research Use
IIHSR Medical Research Center may process personal information in connection with academic and medical research.
Where research involves identifiable personal information, the Center will apply appropriate safeguards and follow applicable legal, ethical, and institutional requirements.
Where appropriate, research information may be:
- De-identified
- Anonymised
- Aggregated
- Coded or pseudonymised
- Restricted to authorized researchers
- Stored in controlled research environments
Research participants may receive additional information about the specific collection and use of their information through a research consent form, participant information sheet, research protocol, or other applicable documentation.
This Privacy Policy does not replace specific research consent documentation where such documentation is required.
7. Disclosure of Personal Information
We may disclose personal information where reasonably necessary for our academic, administrative, research, legal, or operational functions.
Depending on the circumstances, information may be disclosed to:
- IIHSR European University
- Academic advisers
- Research supervisors
- Academic Council members
- Assessment personnel
- Authorized administrative personnel
- Approved academic partners
- Research collaborators
- Professional or academic referees
- Technology and hosting providers
- Payment service providers
- Email and communication service providers
- Document verification service providers
- Professional advisers
- Auditors
- Government or regulatory authorities where required
- Legal authorities where required or permitted by law
We do not sell personal information as a commercial commodity.
8. International and Overseas Disclosure
Because IIHSR European University and IIHSR Medical Research Center operate in an international academic environment, personal information may be processed or accessed across national borders.
For example, information may be processed by:
- International technology providers
- Cloud-storage providers
- Academic service providers
- Research collaborators
- Payment providers
- Communication platforms
- Administrative service providers
Where applicable, we will take reasonable steps to ensure that overseas disclosures are handled in accordance with applicable privacy requirements.
Where Australian privacy law applies, our privacy policy will identify overseas disclosure practices and, where practicable, the countries in which overseas recipients are likely to be located.
9. Data Security
We take reasonable technical and organizational measures to protect personal information against:
- Unauthorized access
- Unauthorized disclosure
- Misuse
- Loss
- Destruction
- Alteration
- Interference
Security measures may include:
- Access controls
- Password protection
- Secure systems
- Encryption where appropriate
- Restricted administrative access
- Secure document management
- Backup procedures
- Staff confidentiality obligations
- Monitoring and security controls
No electronic transmission or storage system can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of information transmitted over the internet.
Australian Privacy Principle 11 requires applicable entities to take reasonable steps to protect personal information and, when it is no longer needed and no retention requirement applies, to destroy or de-identify it.
10. Retention of Personal Information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, or as required by applicable:
- Academic requirements
- Legal obligations
- Regulatory requirements
- Research requirements
- Institutional recordkeeping requirements
- Financial and accounting requirements
- Dispute-resolution requirements
Academic records, qualification records, research records, and verification records may need to be retained for longer periods because of their academic and institutional importance.
When personal information is no longer required, we will take reasonable steps to securely delete, destroy, or de-identify it, subject to applicable retention obligations.
11. Cookies and Website Technologies
Our website may use cookies and similar technologies to:
- Operate website functions
- Remember preferences
- Improve website performance
- Understand website usage
- Maintain security
- Analyze website traffic
- Improve user experience
You may be able to control cookies through your browser settings.
Disabling certain cookies may affect some website functionality.
12. Third-Party Websites and Services
Our website may contain links to third-party websites, platforms, payment services, academic resources, or other external services.
Once you leave our website, the privacy practices of the third party may apply.
We are not responsible for the privacy practices, security, content, or policies of independent third-party websites.
We encourage users to review the privacy policies of third-party services before providing personal information.
13. Access to Personal Information
You may request access to personal information we hold about you, subject to applicable law.
Your request should generally include sufficient information for us to identify you and locate the relevant records.
We may need to verify your identity before providing access.
In some circumstances, access may be refused or limited where permitted or required by law.
14. Correction of Personal Information
We seek to maintain accurate, complete, and up-to-date personal information.
If you believe that information we hold about you is inaccurate, incomplete, outdated, or misleading, you may request correction.
We will consider correction requests in accordance with applicable privacy laws and institutional requirements.
Australian Privacy Principles 10 and 13 address the quality and correction of personal information.
15. Privacy Enquiries and Complaints
If you have a question, concern, or complaint regarding the handling of your personal information, please contact us first.
We will:
- Receive and acknowledge your complaint.
- Review the relevant circumstances.
- Investigate where appropriate.
- Communicate with you regarding the outcome.
- Take corrective action where appropriate.
- Maintain appropriate records of privacy complaints.
We aim to resolve privacy concerns fairly, efficiently, and within a reasonable period.
16. Contact Us
For privacy enquiries, access requests, correction requests, or privacy complaints, please contact:
Privacy Officer
IIHSR Medical Research Center
Medical Research Division of IIHSR European University
Email: [Insert Privacy Email]
Website: [Insert Website]
Postal Address: [Insert Official Address]
Please include "Privacy Enquiry" or "Privacy Complaint" in the subject line where appropriate.
17. External Privacy Regulator
Where applicable, individuals may have the right to lodge a complaint with the relevant privacy or data-protection regulator if they are not satisfied with the response to their privacy concern.
For matters governed by Australian privacy law, individuals may contact the Office of the Australian Information Commissioner (OAIC) after raising the matter with the organization concerned.
The Australian Privacy Principles establish rights and obligations concerning collection, use, disclosure, security, access, correction, and other aspects of personal information management.
18. Children's Privacy
Our academic and research services are primarily intended for adults and qualified applicants.
Where information relating to a child or young person is collected for an authorized academic, research, healthcare, or administrative purpose, appropriate safeguards will be applied in accordance with applicable law and ethical requirements.
Where consent from a parent, guardian, or authorized representative is required, we will seek such consent before collecting or using the relevant information.
19. Research Ethics and Confidentiality
Medical and health research may involve information requiring a higher level of confidentiality.
Where applicable, research activities will follow relevant:
- Research ethics requirements
- Participant consent requirements
- Confidentiality obligations
- Data-management requirements
- Institutional research procedures
- Applicable privacy legislation
Researchers and authorized personnel may only access research information to the extent necessary for their approved responsibilities.
20. Professional Confidentiality
Individuals involved in academic, research, clinical, or administrative activities may be required to maintain confidentiality regarding information obtained through their work.
Confidential information must not be improperly disclosed, copied, transferred, or used for unauthorized purposes.
21. Data Breach Management
If we become aware of a data security incident involving personal information, we will assess the incident and take appropriate action in accordance with applicable law.
Where notification is legally required, affected individuals and relevant authorities will be notified in accordance with the applicable requirements.
Our response may include:
- Containing the incident
- Assessing affected information
- Investigating the cause
- Taking corrective measures
- Strengthening security controls
- Notifying affected individuals where required
- Notifying relevant authorities where required
22. Automated Decision-Making
We may use technology and automated systems for administrative, technical, analytical, or operational purposes.
Where applicable law provides individuals with specific rights concerning automated decision-making, we will comply with those requirements.
For Australian organizations subject to the relevant amendments to the Privacy Act, additional APP privacy-policy requirements concerning certain automated decisions are scheduled to commence on 10 December 2026.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our services
- Changes in technology
- Changes in research activities
- Changes in academic operations
- Changes in privacy practices
- Changes in applicable legislation or regulations
The updated version will be published on our website with the revised "Last Updated" date.
We recommend reviewing this Privacy Policy periodically.
24. Transparency and Accountability
IIHSR Medical Research Center is committed to managing personal information in an open and transparent manner.
Our privacy practices are intended to support:
Transparency → Security → Confidentiality → Responsible Research → Academic Integrity
We recognize that privacy is particularly important in medical and health research, where information may be sensitive and may have significant implications for individuals.
We therefore seek to apply responsible information-management practices throughout the research and academic lifecycle.
25. Governing Principles
This Privacy Policy is guided by the following principles:
Transparency
We explain how personal information is collected and used.
Necessity
We seek to collect information that is reasonably necessary for legitimate academic, research, administrative, or legal purposes.
Confidentiality
We restrict access to personal information to authorized persons and purposes.
Security
We implement reasonable technical and organizational safeguards.
Accuracy
We seek to maintain accurate and up-to-date information.
Accountability
We maintain processes for handling privacy enquiries and complaints.
Research Responsibility
Medical research involving personal information is conducted with appropriate ethical and privacy safeguards.
Respect for Individuals
We respect individuals' privacy rights and applicable legal protections.
26. Final Statement
IIHSR Medical Research Center recognizes privacy as an essential component of responsible medical research, academic administration, professional education, and international collaboration.
We are committed to protecting personal information while enabling legitimate academic, research, and institutional activities.
By interacting with IIHSR Medical Research Center, applicants, students, researchers, professionals, and website users can expect their personal information to be handled responsibly, securely, and transparently in accordance with applicable privacy and data-protection requirements.
IIHSR Medical Research Center
Medical Research Division of IIHSR European University
Advancing Medical Knowledge. Supporting Research. Improving Healthcare.