Privacy Policy & Legal Information
Last Updated: July 2026 | Effective From: June 2026
📋 Quick Navigation
1. Data Controller Information
The Gallagher Research Group operates this website as part of the Department of Radiology at the University of Cambridge.
📍 Contact Details
Organization: University of Cambridge, Department of Radiology
Lab Lead: Prof. Ferdia Gallagher
Address: Addenbrooke's Hospital, Cambridge CB2 0XZ, United Kingdom
Email: contact@ferdiagallagher.com
University Website: www.medschl.cam.ac.uk
Data Protection Officer: For data protection queries, contact the University of Cambridge Data Protection Office at dpo@admin.cam.ac.uk
2. What Data We Collect
2.1 Contact Form Data
When you submit our contact form, we collect:
- Name — Your full name (required)
- Email Address — Your email address (required)
- Message Content — Any text information you provide in the message field (required)
Anti-spam check: The form includes a simple arithmetic question to deter automated spam. Your answer is verified on our server and is not stored; it is not sent to any third-party service (we do not use Google reCAPTCHA or similar external verification).
2.2 Automatically Collected Data
Our website may automatically collect limited technical information:
- Browser Type & Version — Information about your web browser
- Operating System — Your device's operating system
- Pages Visited — Which pages you access on our site
- Time & Date — When you access the website
- Referrer Information — How you found our website
Note: We currently do not use cookies or tracking pixels. This information is only collected through standard web server logs.
2.3 What We DO NOT Collect
- We do not use analytics trackers (Google Analytics, etc.)
- We do not use advertising cookies or retargeting pixels
- We do not collect location data
- We do not collect sensitive personal data (race, religion, health data, etc.)
- We do not store passwords or authentication credentials
3. How We Use Your Data
3.1 Contact Form Submissions
When you submit the contact form, we use your information to:
- Respond to your inquiry, question, or request
- Process your application (if applying for a position)
- Facilitate collaboration discussions
- Contact you about relevant research opportunities
3.2 Data Handling
- Your message is sent directly to the lab administrator's email inbox
- We do not store submissions in a database on this website
- Storage is handled by your email provider (governed by their privacy policy)
- Data is not sold, rented, or shared with third parties for marketing
- Data is not used for automated decision-making or profiling
3.3 Legitimate Uses
We may use technical data (browser info, pages visited) to:
- Improve website functionality and user experience
- Diagnose technical issues
- Monitor for security threats
- Comply with legal obligations
4. Legal Basis for Processing (UK GDPR)
Under UK GDPR and the Data Protection Act 2018, we must have a lawful basis to process your data. Here's ours:
| Data Type | Legal Basis | Justification |
|---|---|---|
| Contact form (name, email, message) | Consent | By submitting the form, you consent to us processing your data to respond |
| Technical web logs | Legitimate Interest | We have a legitimate interest in maintaining website functionality and security |
| Data retention for communication | Contractual/Pre-contractual | Necessary to fulfill your request or establish a working relationship |
5. Data Retention — How Long We Keep Your Information
5.1 Contact Form Data
- If we respond: Your data is retained in email archives for 3 years in case of follow-up inquiries
- If you don't respond: Your data may be archived after 6 months of inactivity
- If you request deletion: We will remove your data within 30 days
5.2 Web Server Logs
- Technical logs are retained for 90 days for security and troubleshooting purposes
- After 90 days, logs are automatically deleted
5.3 Legal Obligations
We may retain data longer if required by law or for legitimate research purposes (with appropriate safeguards).
6. Your Rights Under UK Data Protection Law
Under the UK Data Protection Act 2018 and UK GDPR, you have the following rights:
6.1 Right of Access
You have the right to request a copy of the personal information we hold about you. We will provide this within 30 days of your request.
6.2 Right to Rectification
You can request that we correct any inaccurate or incomplete information we hold about you.
6.3 Right to Erasure ("Right to be Forgotten")
You can request deletion of your data in most circumstances. We will erase it within 30 days. Note: We may retain data if legally required or if there's an active research collaboration.
6.4 Right to Restrict Processing
You can ask us to limit how we use your data while you dispute its accuracy or we verify our legal basis.
6.5 Right to Data Portability
You can request your data in a structured, machine-readable format (e.g., CSV) so you can transfer it elsewhere.
6.6 Right to Object
You can object to us processing your data for direct marketing, research, or statistical purposes.
6.7 Right to Withdraw Consent
If we process data based on your consent (e.g., contact form), you can withdraw it at any time. This doesn't affect data processing before withdrawal.
6.8 Rights Related to Automated Decision-Making
We do not use automated decision-making or profiling. All decisions about your inquiry are made by humans.
How to Exercise Your Rights
To exercise any of these rights, contact us:
Email: contact@ferdiagallagher.com
Subject Line: "Data Subject Access Request" (or specify your request type)
We will respond within 30 days (extendable by 60 days for complex requests).
6.9 Right to Lodge a Complaint
If you're unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Email: casework@ico.org.uk
Phone: 0303 123 1113
Website: www.ico.org.uk
7. Cookies & Tracking Technologies
7.1 Current Cookie Usage
Our website does NOT currently use cookies or tracking pixels.
However, if we do implement cookies in the future, we will:
- Update this policy to describe what cookies we use
- Obtain your explicit consent before placing non-essential cookies
- Provide clear information about how to manage or delete cookies
7.2 Third-Party Websites
Our website links to external sites (Google Scholar, ORCID, LinkedIn, PubMed, etc.). Those sites may use their own cookies. Please review their privacy policies for details.
7.3 How to Manage Cookies (if implemented)
You can manage cookies through your browser settings:
- Chrome: Settings → Privacy and security → Cookies
- Firefox: Preferences → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Cookies and website data
- Edge: Settings → Privacy and security → Cookies
8. Data Security & Protection
8.1 Security Measures
We implement the following security measures:
- HTTPS Encryption: All data in transit is encrypted using SSL/TLS
- Security Headers: We implement Content Security Policy (CSP) and other security headers
- Access Controls: Only authorized lab personnel can access contact form submissions
- Server Security: Our server is hosted on secure, professionally-managed infrastructure
- No Sensitive Data: We do not store passwords, payment information, or health data
8.2 Limitations
While we implement industry-standard security, no system is 100% secure. We cannot guarantee absolute security against hacking or data breaches. If a breach occurs, we will:
- Notify affected individuals without undue delay (typically within 72 hours)
- Notify the ICO if required by law
- Provide guidance on protective measures
9. How to Contact Us
For questions about this privacy policy or your data:
📧 General Inquiries & Data Requests
Email: contact@ferdiagallagher.com
Subject Line Examples:
- "Data Subject Access Request"
- "Erasure Request"
- "Privacy Policy Question"
🏢 University Data Protection
For complaints or escalation:
University of Cambridge Data Protection Office
Email: dpo@admin.cam.ac.uk
9a. Website Disclaimer & University Links
This website is maintained by the Gallagher Research Group. While hosted independently, the group is part of the University of Cambridge, and the following official University policies may also be relevant:
- University of Cambridge — Terms and Conditions
- University of Cambridge — Privacy Policy
- University of Cambridge — Data Protection
Content on this site is provided for general information about the group's research and does not constitute medical advice. Views expressed here are those of the Gallagher Research Group and do not necessarily represent the official position of the University of Cambridge.
10. Changes to This Privacy Policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. When we do:
- The "Last Updated" date at the top will change
- For material changes, we will notify users via email (if we have contact information)
- Your continued use of the website after changes means you accept the updated policy
We recommend reviewing this policy periodically (at least annually).
11. Quick Reference Table
| Your Question | Our Answer |
|---|---|
| Do you use cookies? | Not currently, but we'll ask if we do in future |
| Do you sell my data? | No. Ever. |
| How long do you keep my data? | 3 years (email) or 90 days (server logs). Less if you request deletion. |
| Can I get a copy of my data? | Yes, within 30 days of requesting it |
| Can I delete my data? | Yes, unless there's a legal reason to keep it |
| Who can I complain to? | Us first, then the ICO if unsatisfied |
| Is my data secure? | Yes, we use industry-standard encryption and security measures |
| Do you profile me? | No, we never use automated profiling or decision-making |
Version 2.0 | Last updated July 2026
This policy is compliant with UK Data Protection Act 2018 and UK GDPR (effective date: June 2024)