Privacy notice
What iglc.net keeps about you, why, who else handles it, for how long, and what you can ask for.
Last updated 2 October 2026.
Who is responsible
The International Group for Lean Construction (IGLC) is an informal international network of researchers and practitioners. It is not a legal entity. The General Secretary and the Moderator, elected under the Charter and Operating Procedures, act for the IGLC in matters of personal data; the webmaster runs the site for them. Their names are on Committees and officers.
Write to secretary@iglc.net (the General Secretary) or moderator@iglc.net (the Moderator) about anything in this notice.
What we keep, and why
The site keeps one record per person, whichever way they came: as a conference attendee, an author, a committee member, a working group member or someone with an account. We keep only what the IGLC's work needs. We never ask for your date of birth, gender, nationality or phone number, and we never sell or share your details for marketing.
Visiting the site
You can read the site without an account. There is no analytics, advertising or tracking: no third-party scripts, and the fonts are served from iglc.net. Microsoft Azure, which hosts the site, records technical logs (your IP address, the page asked for and the time) to run and protect the service.
Your account
- Your email address, your name if you give it, and a password only if you set one (stored as a one-way hash, never readable). You can also log in with a code sent by email.
- If you choose to log in with ORCID: your ORCID iD, which ORCID confirms. ORCID's own privacy policy applies to what you do there.
- Two-factor login, if you set it up (required for some roles): the authenticator app's secret, your security keys or passkeys, and recovery codes.
- Your login sessions: when each started, and the IP address and browser, so that you can see them and log out of any of them under Login and security.
- Your time zone, if you choose one, so times are shown in it.
Why: to give you access to what is yours to see or do on the site, and to keep accounts safe.
Your record
Your name, email addresses, affiliation, country, the page about you at your institution, your ORCID iD, and, if you tell us, whether and when you took a PhD. If you have published in the IGLC proceedings, your record is linked to your author page in the archive. You can see and correct these under Your details.
IGLC membership
- Your attendance at IGLC conferences (which conference, in person or online), from the attendee lists the organisers send us or from your own claim, and the membership that follows from it under the Charter.
- The member register is never shared. Only the General Secretary and the Moderator can see it, and every time they look at it or export it is logged. Conference organisers can send us their attendee list but cannot see the register. Committees see only what they need, such as whether a candidate is eligible.
- Organisers pass your name, email address, affiliation, country and attendance to the IGLC to record your membership; their registration terms tell you so.
Why: the Charter makes attendance the basis of membership, and membership the basis of the right to vote and to stand for election. Keeping the register is how the IGLC runs itself.
Committees, officers and working groups
- Public: the names, roles, affiliation, country and years of service of the officers and committee members, on Committees and officers; the members of working groups listed publicly; the committee's published agendas, the public summary of its meetings, and its decisions with the vote counts.
- For the committee or group only: its items, documents, comments, meeting attendance, detailed notes and actions, and who voted what. A working group's space is seen by its members and the committee it works for.
- If you are invited to a working group from outside the committee: your name, email address and affiliation, when you joined and left, and what you add to the group's space.
Why: the Charter has the Standardisation Committee publish its agendas and a summary of its meetings (§9.2.5), and the IGLC keeps a record of the decisions it takes; the rest is the committee's or group's own working material.
Bids to host the conference
Bidders need an account, not a membership. A bid keeps what the form asks for, including the names and email addresses of the proposed chairs and deans, and every submitted version. The General Secretary sees a bid when it comes in; the Standardisation Committee after the deadline; the members once the bids are released with the Annual Business Meeting's agenda, and they stay with the members afterwards as part of the IGLC's record of how its conferences were chosen. The committee sees whether the named chairs meet the Charter's rules (§6.4.1, §6.5.1.1), from the member register; the bidder does not.
Requests to the Standardisation Committee
A request keeps what you send (your name and address, the request, any documents), the committee's questions and your replies, and the answer or decision. The committee sees it; you see it under Your requests. For a membership extension, your reasons stay with the committee: the register records only the extension and the decision that granted it. If you propose PhD summer school deans, the committee sees whether each holds a PhD, from their own record.
Imported proposals and connected assistants
A proposal you import (a file, or one an assistant sends) is kept as your draft, seen only by you until you put it out; the file itself is kept with the item's history, with who imported it and when. If you allow an AI assistant to connect to the site (the MCP server), the site keeps which assistant it is, when you allowed it, and a record of each call it makes (what it read or which draft it wrote), so that you and the General Secretary can check what it did. The assistant can read only your own drafts and what is public anyway; never the member register. What you send to the assistant itself is governed by its provider's terms, not by this notice. You can disconnect an assistant at any time under Login and security.
Papers and proceedings
The names, affiliations and ORCID iDs of the authors of published papers are part of the papers and are public. They are sent to Crossref with each paper's metadata so that it gets a DOI, and they stay in the scholarly record for good.
- The site sends its own mail (login codes, notices to members, committee mail) through Microsoft Azure Communication Services, with the mail data kept in Europe and no open or click tracking.
- We keep a copy of each mail the site sends, with its delivery report, for one year, so that we can see whether it arrived. Addresses that bounce, or whose owners ask us to stop, go on a list so the site does not write to them again.
- Committee and working group members get notices of what happens there, at once or in a daily digest as they choose under Notifications. The links in these mails open the page after one click on Continue, and log you in once, within 14 days, unless your account uses two-factor login.
- Mail to addresses such as secretary@iglc.net is forwarded by Forward Email to the person who holds the role.
The mailing list
The IGLC's mailing list (news, calls for papers) is separate from the member register and runs on Sender.net, whose privacy policy also applies; Sender can record whether a mailing was opened and which links were followed. You join it only by saying yes: on the sign-up form (then you confirm through a link we mail you), when you create an account, or on your account page. We keep a record of when and where you said yes and the wording you agreed to, and pass your address and name to Sender. You can leave from any mailing or from your account page. Leaving the list does not remove you from the member register. Under the current Charter (§5.2.1.2), members who leave the list lose the right to vote online; an amendment to change that is being prepared.
In your browser
The site sets only the cookies it needs: one that keeps you logged in (for up to 30 days, or until you log out) and one that protects forms against misuse. No consent banner is needed because there is nothing else. The conference programme's "my programme" stars are kept in your browser only and are never sent to us.
Who else handles the data
| Who | What for |
|---|---|
| Microsoft Azure | Hosting the site, its database and files, and sending its mail |
| Forward Email | Forwarding mail sent to @iglc.net addresses |
| Sender.net | The mailing list |
| ORCID | Logging in with ORCID, if you choose to |
| Crossref | DOIs for published papers (public metadata only) |
| Conference organisers | They send us attendee lists; they never see the register |
They handle the data only to provide their service.
How long we keep it
| Data | Kept |
|---|---|
| Your account | Until you ask us to delete it |
| Login sessions | Until you log out, or 30 days |
| Contact details in the member register | While your membership is valid and 5 years after it ends, so we can recognise you if you come back; then deleted. Deleted at once if you ask |
| Attendance at IGLC conferences | For good, without contact details once those are deleted: it is part of each conference's record and counts for membership |
| Copies of mail the site sent | One year |
| Mailing list: your address and the record of your consent | While you are on the list. After you leave, the address and the date you left, so you are not added again by mistake |
| A request to join the mailing list that was not confirmed | 14 days; then deleted |
| Your requests to have something sent to the mailing list, and the Moderator's answers | For good, as the record of what the list carried and why |
| Notices on My IGLC (what happened in your committees and groups) | One year |
| One-click links in the site's emails | Work once, for 14 days; then deleted |
| Committee and working group records (items, documents, notes, decisions, votes) | For good, as the IGLC's record of how it governs itself |
| A connected assistant's access | Until you disconnect it, or 30 days after it was last renewed |
| The record of an assistant's calls | One year |
| Imported proposal files | With the item, for good; drafts never put out until you delete them |
| Requests to the Standardisation Committee, and the answers | For good, as part of the committee's record |
| Bids to host the conference, and the committee's assessment | For good, as the record of how each conference was chosen |
| Published papers and their authors | For good, as part of the scholarly record |
| The log of who looked at the register | For good, so access can always be checked |
What you can ask for
You can ask to see what we keep about you, to have it corrected, to have it deleted, to have its use restricted, to object to its use, and to get a copy in a common format. Most of your details you can correct yourself under Your details; for anything else, write to secretary@iglc.net. We answer within a month.
Some things cannot be deleted: published papers stay in the proceedings, and committee decisions stay in the record.
If you think we have handled your data wrongly, tell us first, so we can put it right. You can also complain to the data protection authority where you live or work; in Norway, where the site is run, that is Datatilsynet.
Changes to this notice
When this notice changes, the date at the top changes. Important changes are also announced to the people they affect.