Privacy Policy
HSCC+ICCPS 2027 PC Invitation Service Privacy Policy
Effective September 7, 2026. This policy explains how the HSCC+ICCPS 2027 PC Invitation Service collects, uses, stores, shares, protects, retains, and deletes invitation and response information.
Scope and controller
The HSCC+ICCPS 2027 program chairs control the HSCC+ICCPS 2027 PC Invitation Service. Taylor T. Johnson is the primary privacy contact, with the other program chairs providing continuity. This policy covers invitation and response information processed by the organizer-operated service. HotCRP separately governs account, profile, submission, and review data it processes.
Information the service collects
Before an invitation, the service may hold an invitee's professional name, affiliation, invitation address, suggested reviewing areas, public homepage, Google Scholar and ORCID links, a proposed public headshot source or standard-avatar fallback, and the invitation's deadline and delivery state. These professional details are collected from chair records, recommendations, and independently reviewed public sources.
A submitted response records the invitee's accept, decline, or contact choice and the minimum information needed for that choice. An acceptance may include corrected professional details, a preferred HotCRP address, selected reviewing areas, maximum review load, policy acknowledgments, independently editable public-profile links, and a portrait choice. A contact response includes the invitee's question. A decline does not request a reason or retain corrected profile fields.
How information is used
Invitation and response information is used only to prepare and deliver chair-approved invitations and follow-ups, record deliberate responses, prevent duplicates, provide support, maintain security and audit evidence, and prepare accepted members for separate chair-reviewed onboarding and roster publication.
Opening the response page does not record an accept, decline, or contact choice. An accepted response authorizes only the choices stated on the form; HotCRP onboarding and website publication remain separate reviewed steps. A discovered professional link or image is never treated as consent to publish it.
Processors, transfers, and human access
Service providers acting on the program chairs' behalf may process bounded information for message delivery, secure hosting, storage, and recovery. Authorized program chairs and operators may access only the invitation, response, delivery, and integrity evidence needed to operate, support, secure, audit, and close out the service.
After chair review, accepted contact-profile, review-capacity, and reviewing-area information may be transferred to HotCRP for Program Committee onboarding. Headshots and public profile-link choices are website-only and are not transferred to HotCRP.
The service does not sell invitation or response information, use it for advertising or retargeting, disclose it to data brokers, use it for lending or credit decisions or surveillance, or use it to train generalized artificial-intelligence or machine-learning models. Transfers required for legal compliance or a security investigation are limited to what is necessary.
Invitation and response data
The service processes an invitee's professional name, affiliation, invitation address, proposed homepage, independently verified Google Scholar and ORCID links when available, a proposed headshot-source URL or standard-avatar fallback, suggested reviewing areas, invitation and delivery identifiers, deadline, and response state. If an invitee chooses public-roster listing on the current response form, the form immediately displays the proposed external headshot and its source URL. The browser loads that image directly from the public HTTPS source with no referrer; the source website may still receive ordinary connection metadata such as the invitee's IP address, browser information, and cookies. Merely opening the form does not cause the conference service to copy or store the external image.
An acceptance may include corrected professional details, a preferred HotCRP email, independently editable Homepage, Google Scholar, and ORCID links, and one of three portrait choices: use the shown photo, use an alternate photo, or use no photo. Acceptance also records one to three reviewing areas, a maximum of three through ten papers, and policy acknowledgments. Contact includes the question submitted by the invitee but records no public-profile confirmation. Decline does not request a reason or retain corrected profile fields.
If an invitee accepts and chooses public listing, the invitee may confirm, correct, or omit each proposed Homepage, Google Scholar, and ORCID link independently. The invitee must separately choose the shown photo, an alternate photo supplied by public HTTPS URL or local upload, or no photo. The browser converts a selected JPEG, PNG, or WebP upload to a non-animated JPEG no larger than 512 pixels per side and 96 KiB; only that normalized copy is submitted with the restricted response evidence, and the original local file is not uploaded. The service does not automatically fetch a corrected or alternate URL.
Selecting a shown or alternate photo authorizes the conference to download or retain the selected image, copy it, crop or pad and resize it, locally host it, and display it with the person's accepted PC listing; it does not transfer copyright ownership. Selecting no photo authorizes no portrait publication, and the conference may display its common non-personal placeholder instead. A discovered image or public URL is never treated as confirmation. Corrected links, alternate photos, uploads, and every accepted profile still require chair, security, media, and separate website-publication review before publication. Photos are not used to infer demographics or other sensitive attributes.
After chair review, accepted contact-profile, review-capacity, and reviewing-area data may be transferred to HotCRP for Program Committee onboarding. Headshots and public profile-link choices are website-only and are not transferred to HotCRP. The service does not request invitee passwords, paper submissions, reviews, scores, conflicts, demographics, health data, or accommodation details, and it does not intentionally store IP addresses or user-agent strings at the application layer.
Security
The service uses HTTPS, role-limited access, protected credentials kept outside public source code and response records, one-recipient delivery controls, bounded rate limits, non-reversible digests instead of stored raw response links, integrity checks, and restricted recovery copies. Operational access is limited and reviewed. No Internet service is risk-free; this policy does not promise end-to-end encryption, a fixed data-residency location, or deletion of infrastructure security logs outside the chairs' control.
Retention and deletion
The first formal review of response information, delivery and reconciliation records, recovery copies, and restricted exports is June 30, 2027, or earlier after the last required reconciliation. That date begins a documented review; it is not a promise of automatic same-day deletion. Operational records and recovery copies are destroyed or retired after all delivery, response, Contact, incident, and HotCRP handoffs are reconciled, unless a narrower legal, security, audit, or future-contact suppression record receives an explicit dated extension.
Proposed headshot copies and provenance remain in restricted conference records while invitations and roster publication are active; unapproved candidate images never enter the public website bundle. A verified withdrawal removes the image from the next generated release, although repository history, already distributed artifacts, browser caches, or service-provider backups may persist under their separate retention controls. Narrow private audit identifiers may be retained only for reconciliation, security, or legal needs.
Your controls and deletion requests
To request access, correction, deletion, restriction, replacement of a profile image or link, or withdrawal of an optional roster or future-contact choice, email the monitored privacy contact shown in the footer with a clear description of the request. Invitees may also reply to their invitation. The chairs document and act on verified requests subject to necessary security, legal, audit, and suppression obligations; a request does not authorize the service to retain information for a new purpose.
Policy changes
The program chairs will update the effective date and this public page before materially changing what invitation or response information the service collects or how it is used or shared. A new use that requires consent will not begin until affected individuals receive clear notice and provide the required authorization.
