Privacy Policy
Last updated: September 18, 2026
Who we are
The Personal AI Health Alliance (“PAIHA”, “we”, “us”) operates the website https://paihealth.org. This policy explains what personal data this website collects, why it is collected, who it is shared with, and the rights you have over it. It covers the website only.
We do not use the data collected here for advertising, and we do not sell or rent it to anyone.
The contact form
When you use our contact form we collect your name, your email address, the topic of your request, an optional subject line, and your message. We also record that you ticked the consent box, together with the date and time of the submission.
This data is stored on the website and sent by email to the Alliance team members who handle enquiries. If you select “Join the Alliance” as the topic, your request is also sent to the team members responsible for membership. You receive an acknowledgement email confirming the topic and subject of your request.
Legal basis: your consent (Art. 6(1)(a) GDPR), given by ticking the box before sending the form, and our legitimate interest in answering enquiries addressed to us (Art. 6(1)(f) GDPR).
Retention: for as long as needed to handle your request, and at most 24 months after our last exchange, unless a longer period is required by law or by an ongoing relationship with the Alliance.
The contributor request form
If you ask for a contributor account through the “Become a Contributor” page, we collect your first name, last name, company or organisation, email address, and the description you write about yourself and what you intend to publish. We also record that you accepted the Publishing Charter and the privacy consent box, with the date and time.
This data is stored on the website and sent by email to the team members who review contributor requests. You receive an acknowledgement email.
Legal basis: your consent (Art. 6(1)(a) GDPR), and steps taken at your request before entering into a relationship with the Alliance (Art. 6(1)(b) GDPR).
Retention: for as long as needed to assess your request, and at most 24 months after our last exchange. If your request is accepted, the data becomes part of your contributor account.
Contributor accounts
Contributors have an account on this website. For each account we hold a username, an email address, a display name, the content that account has written, and any file it has uploaded to the media library. Contributors sign in without a password: you enter your email address or username, and we send a single-use code to your mailbox, valid for a few minutes. Your browser then holds a session cookie that keeps you signed in.
To protect accounts, the website temporarily records failed sign-in attempts together with the IP address they came from, and limits how many sign-in codes can be requested for one account within an hour. Two-factor authentication is required for administrator accounts, with a short enrolment period once the requirement applies to an account.
Legal basis: performance of our arrangement with the contributor (Art. 6(1)(b) GDPR) and our legitimate interest in keeping the website secure (Art. 6(1)(f) GDPR).
Retention: for as long as the account exists. Security records such as failed sign-in attempts are kept in a log that is trimmed once it grows beyond a set size, rather than on a fixed schedule, so an individual entry can remain for several weeks.
Anti-spam verification
Both forms and the contributor sign-in page are protected by Cloudflare Turnstile, a verification service that distinguishes people from automated scripts. To do this, Turnstile receives your IP address and technical signals from your browser. It does not ask you to solve a puzzle and, according to Cloudflare, it does not use this information to profile or track you across websites.
Legal basis: our legitimate interest in protecting the website against automated abuse (Art. 6(1)(f) GDPR).
Technical data and security
Like any website, this one is reached through servers that record technical information about each request: IP address, date and time, the page requested, the referring page, and your browser’s user agent. This website is served through Cloudflare, which processes that information to deliver pages quickly and to filter malicious traffic.
Legal basis: our legitimate interest in operating and securing the website (Art. 6(1)(f) GDPR).
Cookies and analytics
On your first visit you are asked to choose which categories of cookies you accept. No analytics or marketing cookie is set before your choice, and nothing beyond what is strictly necessary is stored on your device.
The Google tag that carries this measurement is loaded on every page, so your browser contacts a Google server whichever choice you make. Until you accept statistics cookies, that tag is instructed to store nothing on your device and to collect no analytics data about you.
If you accept statistics cookies, this website uses Google Analytics to understand how pages are used. The cookies set on the public pages, what each one does and how long it lasts, are listed in our Cookie Policy, where you can also change or withdraw your choice at any time. The session cookie described above, which only exists once a contributor is signed in, is not part of that list.
Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.
Fonts
The typefaces used on this website are loaded from Google Fonts. As a result, your browser contacts a Google server when a page loads, and your IP address is transmitted in the process.
Who your data is shared with
Your data is accessible to the Alliance team members who handle enquiries, membership requests and contributor requests. Those people work for member organisations of the Alliance, at present Global Health Connector and Qualcomm, so your message reaches the email systems of those organisations. Beyond that, we rely on the following service providers, who process data on our behalf or as part of delivering the website:
- Hostinger, which hosts the website and its database.
- Cloudflare, which delivers and protects the website and provides the Turnstile verification on our forms and sign-in page.
- Titan, which delivers the emails this website sends.
- Google, for Google Analytics if you have accepted statistics cookies, and for Google Fonts. nnnn
- The technical provider that maintains this website, which holds administrative access for that purpose.
Some of these providers process data outside the European Economic Area, including in the United States. Where that is the case, the transfer relies on the safeguards set out in that provider’s data processing terms.
Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable form, and to withdraw your consent at any time. Withdrawing consent does not affect processing that took place before you withdrew it.
To exercise any of these rights, write to us through our contact page, selecting “Other” as the topic. We answer within one month. To change or withdraw your cookie choices, use the consent panel on our Cookie Policy page.
You also have the right to lodge a complaint with the data protection supervisory authority of the country where you live or work.
Changes to this policy
If we change how this website handles personal data, we update this page and the date at the top. Significant changes affecting contributors are also communicated by email to the accounts concerned.