Skip to main content
GAMA-RADS — Imaging Repository & Advanced Processing
Sign inRequest access

Privacy policy

How GAMA-RADS handles personal data — both the account data of the clinicians, residents and researchers who use the platform, and the imaging data that enters the repository.

Version 1.0 · reviewed and approved 13 August 2026

Scope

This policy covers the GAMA-RADS platform at gamarads.com: the case repository, the imaging processing pipeline, and the account and access-request flows attached to them.

It does not cover clinical systems operated by the hospital, the wider university web estate, or any third-party site reached by a link from this platform.

Who is responsible

The data controller is Departemen Radiologi, Fakultas Kedokteran, Kesehatan Masyarakat dan Keperawatan, Universitas Gadjah Mada.

Controller
Departemen Radiologi FK-KMK UGM
Postal address
Gedung Tahir Lt. 5 Sayap Utara, FK-KMK UGM, Jl. Farmako Sekip Utara, Yogyakarta 55281, Indonesia
Data protection officer
[email protected]
Ethics committee
Komisi Etik Penelitian Kedokteran dan Kesehatan (KEPK) FK-KMK UGM

What we process

Account data

When you request access or sign in we process your name, institutional email address, stated role, institution, and — where the department requires it — evidence of professional registration. We also keep a record of the access decision and who made it.

Usage data

Sign-in and sign-out events are recorded by the authentication service. Within the platform we record who created each case and each pipeline run, the progress events a run emits, and a view count against each teaching link. We do not currently keep a per-account record of which cases were opened or which files were downloaded — governed access is enforced at the point of access by the database’s own rules, but it is not, today, retrospectively attributable case by case. Closing that gap is on the roadmap and this page will say so when it is done. None of what is recorded is used to profile individuals or to measure productivity.

Technical data

Standard server logs record IP address, user agent, timestamp and requested path. Retention is short and stated below.

Patient imaging data

This is the part of the platform that carries the most risk, so it is worth stating plainly.

  • Imaging is de-identified before it enters the repository. Direct identifiers are removed from DICOM headers, burned-in pixel annotations are checked and cleared, and study dates are shifted per subject by a consistent offset so that intervals remain analysable while calendar dates do not identify an admission.
  • GAMA-RADS does not hold the re-identification key. The mapping between a repository subject and a hospital medical record number stays inside the clinical environment, under the department's control, and is not accessible from this platform.
  • Contribution requires ethics approval. No case enters the repository without a documented approval covering its collection and its intended secondary use.
  • Re-identification is prohibited. Attempting to re-identify a subject, or to link repository data against any other dataset for that purpose, is a breach of the terms of use and of the data use agreement.

Because de-identification reduces but never fully eliminates risk, de-identified imaging is still handled as sensitive data on this platform rather than treated as anonymous.

Lawful basis

Processing is intended to rest on the grounds set out in Undang-Undang No. 27 Tahun 2022 tentang Pelindungan Data Pribadi. The mapping below is the working assumption and is one of the items requiring legal review.

Account and access data
Necessary to provide a service you asked for, and the legitimate interest of the department in governing access
Audit and security logs
Legal obligation and legitimate interest in securing the platform
Imaging for teaching and research
Ethics-committee approval together with the basis recorded for each contributing study

Who we share data with

We do not sell personal data and we do not disclose it for advertising.

  • Data stays within infrastructure operated by or for Universitas Gadjah Mada. Hosting and object storage are provided by Biznet, on servers located in West Java, Indonesia.
  • Named collaborators on an approved research protocol may receive a defined cohort under a data use agreement. The agreement records the purpose, the retention period, and the prohibition on re-identification and onward transfer.
  • We may disclose data where required by Indonesian law or by a valid order from a competent authority.
  • Cross-border transfer is not part of the current design. If it becomes necessary it requires a separate assessment under UU PDP.

How long we keep data

Server logs
90 days
Audit trail of access decisions
1 year
Account records
For the life of the account, then archived with the audit trail
Repository imaging
Retained for the research and teaching value of the collection; reviewed under the governance framework rather than on a fixed clock

Server log and audit trail periods were set with the department on 13 August 2026. The two below them are governed by the retention review in the data governance framework rather than by a fixed clock.

Your rights

Under UU PDP you may ask us to give you access to your personal data, correct it, delete it, restrict or object to how it is processed, withdraw a consent you previously gave, and receive your data in a portable form. You may also complain to the supervisory authority.

To exercise any of these, contact the data protection officer using the details above. We will confirm receipt and respond within the statutory period. We may ask you to verify your identity first — that check protects your data, not ours.

A limit worth being honest about

Rights over repository imaging work differently from rights over your account. Because the re-identification key is held in the clinical environment and not here, a request about a specific patient study has to be raised with the department through the clinical route rather than through this platform.

Cookies

The platform sets two cookies, both strictly necessary. A session cookie keeps you signed in; it cannot be switched off without breaking authentication. Following a teaching link sets a second cookie that carries that link’s token, so the case and its images stay readable as you move between the page and the viewer; it lasts twelve hours, is not readable by scripts, and grants nothing beyond the single case the link was issued for. No advertising or cross-site tracking cookies are used. If analytics are added later, they will be listed here before they are switched on.

Security

Access is role-based and granted per account after institutional review, and every query is filtered by the database’s own row-level rules rather than by the application asking nicely. Transport is encrypted. An account can be suspended by an administrator at any time, which takes effect on the next request; there is no automatic expiry for dormant accounts, so dormancy is reviewed by hand.

If you believe data has been exposed, or you have found a vulnerability, please report it — see the contact page. Report it before testing anything further, and do not access data beyond what is needed to demonstrate the issue.

Changes to this policy

Material changes will be announced on the platform before they take effect, and the version and review date at the top of this page will be updated. Superseded versions are kept so it is possible to establish which policy applied at a given time.

Contact

Questions about this policy, or about how your data is handled, go to the data protection officer. General enquiries and access requests are handled through the contact page.