[[LEGAL: privacy-notice]]
DRAFT FOR CLAY / COUNSEL REVIEW — NOT FINAL — NOT LEGAL ADVICE
Prepared by CureRays Data Sharing Counsel for Website Division paste into curerays.org membership slots.
Institute (curerays.org / 501(c)(3)) only — never clinic / curerays.com / PHI / EMR.
Do not treat as final until Clay clears.
CureRays Innovation & Education Institute — Membership Privacy / Data-Use Notice
DRAFT FOR REVIEW — Version 2026-09-24
Effective date (when finalized): [PLACEHOLDER: date Clay clears]
Operator: CureRays Innovation & Education Institute (“Institute,” “we,” “us”), curerays.org (501(c)(3)).
This Notice describes how we collect, use, store, and share professional membership data when you use /membership/, /membership/signup/, and related Institute membership features. It applies to Institute systems only. It does not cover clinic care, clinic EMR, or curerays.com.
1. Critical boundary — no patient data
1.1 Do not submit PHI or patient information on membership forms, uploads, or Institute membership channels. That includes names of patients, charts, MRNs, images, clinical notes, identifiers, and any row-level clinical records (including “de-identified” patient-level rows).
1.2 Membership signup is for your professional affiliation (and, if applicable, your organization’s seat interest). If you accidentally submit patient data, contact contact@curerays.org immediately. We will quarantine and delete such material where feasible and will not use it for membership administration.
1.3 The Institute is not your clinic’s EMR, patient portal, or HIPAA business associate for membership signup. Clinic patient data stays with clinics under their own privacy programs.
2. Data we collect on signup and membership administration
2.1 Information you provide
Typical fields (as shown on the signup form; required fields marked on the form):
| Category | Examples | Purpose |
| Identity | Full name; email | Roster; communications; matching to Institute Identity |
| Professional profile | Role; specialty; institution; city / region / country | Program fit; cohorts; events; institutional seats |
| Interests | DSOP / education; research protocols; IJRM-SSS; SIRiiM awareness; philanthropy updates | Entitlements routing; optional communications |
| Optional academic IDs | ORCID; NPI (optional) | Cross-check professional identity — not patient data |
| Consents | Terms; privacy; affirmation of no PHI submitted | Legal / compliance records |
| Attribution | How you heard about us | Program improvement |
2.2 Information generated by Institute systems
Stored in an Institute-owned member database (and related Institute tools such as Netlify Forms / Identity / future Institute billing), which may include:
- Roster records and membership tier / status;
- Balances and entitlement credits (when paid offerings exist);
- Lecture / course purchases and access rights;
- Training status and education progress (e.g., DSOP-related learner progress where offered);
- Society status flags (e.g., SIRiiM-related awareness or separately verified society status — SIRiiM remains a separate program);
- Journal readership indicators for IJRM-SSS pathways where offered;
- Technical logs needed for security and abuse prevention (e.g., submission time, source form name).
2.3 Payment data
If Institute-paid offerings are enabled later, payment card data is handled by the Institute’s payment processor (not clinic Stripe). We receive limited billing metadata (e.g., success/failure, last4, entitlement SKU) — not full card numbers on Institute forms. [PLACEHOLDER: name processor when wired.]
3. How we use membership data
We use membership data to:
1. Provide access — administer membership, authenticate eligible users, unlock education / hub features per tier;
2. Billing and entitlements — track purchases, seats, balances, and access rights for Institute offerings;
3. Communications — send transactional messages (receipts, access, security) and, only if you opt in, education / research / philanthropy updates;
4. Program operations — improve Institute education and research-awareness programs; aggregate nonsensitive metrics;
5. Safety and compliance — prevent abuse, enforce Terms, respond to legal process, and maintain audit trails.
We do not sell membership personal information. We do not use membership signup to build patient dossiers.
4. Where data is stored; who processes it
4.1 Controller: CureRays Innovation & Education Institute (curerays.org).
4.2 Institute-owned member database holds roster, balances, purchases, training status, society-status flags, and journal-readership indicators as described above. Operational intake may use Netlify Forms / Functions / Identity on the Institute site, and may later sync to a private Institute members repository or equivalent Institute-controlled store.
4.3 Processors may include website hosting, forms, identity, email, and (if enabled) Institute payment providers — under contracts appropriate to professional contact data. [PLACEHOLDER: maintain a short subprocessors list for Clay.]
4.4 Separation from clinic: Membership data is not stored in clinic EMR and is not part of curerays.com clinical systems. Do not assume clinic staff can see Institute membership records unless separately authorized inside Institute ops.
5. Sharing
We may share membership data only:
- With Institute service providers acting on our instructions (hosting, email, payments, identity);
- With you or contacts you designate for institutional seats;
- When required by law, legal process, or to protect rights, safety, and security;
- In a successor transaction limited to Institute nonprofit operations (with notice where required);
- As aggregated / de-identified statistics that do not identify you.
We do not share membership data with clinic systems for treatment purposes via this Notice. Research collaborations that involve clinic-derived aggregate statistics (never patient rows at the Institute) are governed by separate Data Sharing / Research DUA papers — not by this membership form.
6. Retention
6.1 We retain roster and entitlement records for as long as your membership is active and for a reasonable period afterward for audit, finance, dispute, and legal obligations — proposed default: [PLACEHOLDER: e.g., 7 years for financial/entitlement records; sooner deletion of marketing preferences on request].
6.2 Training progress and purchase history may be retained to preserve your access rights and certificates.
6.3 You may request access, correction, or deletion of membership personal data by emailing contact@curerays.org. We may retain limited records where required by law or for legitimate Institute interests (e.g., proof of consent, fraud prevention).
7. Communications choices
Transactional messages (security, access, purchases) are part of membership. Marketing / newsletter-style Institute updates require opt-in (including interest checkboxes on signup). You may unsubscribe from optional communications via the email footer or by contacting us; roster-essential notices may continue.
8. Security
We apply administrative, technical, and physical safeguards appropriate to professional contact and entitlement data (not a clinical PHI repository). No method of transmission or storage is 100% secure. Report suspected incidents to contact@curerays.org.
9. Children
Membership is directed to professionals and organizational representatives. It is not directed to children under 16 (or under 13 where that standard applies). We do not knowingly collect membership data from children.
10. International visitors
curerays.org may be accessed from outside the United States. If you submit membership data from abroad, you understand it may be processed in the United States. [PLACEHOLDER: add GDPR/UK addendum only if Clay expects EU/UK targeting.]
11. Changes
We may update this Notice by posting a revised version on curerays.org and adjusting the effective date. Material changes affecting ongoing use will be communicated to the email on your roster record where practicable.
12. Contact / requests
CureRays Innovation & Education Institute
https://www.curerays.org
contact@curerays.org
Subject line suggestions: “Membership privacy request” / “Membership data deletion”
For clinic privacy or patient records, contact your clinic (curerays.com / treating facility) — not the Institute membership channel.