Terms of Use

Effective Date: October 1, 2025

This extensive Terms of Use and Data Governance Policy (the “Terms”) governs your access to and use of the website and services (collectively, the “Site”) provided by the Paediatric Society of Papua New Guinea (the “Society,” “we,” “us,” or “our”). By accessing or using the Site, you agree to be bound by these Terms and our Privacy Policy. If you do not agree to all of these Terms, you may not access or use the Site.


1. Acceptance of Terms and Amendments

1.1. Agreement: These Terms constitute a legally binding agreement between you and the Society. 

1.2. Amendments: The Society reserves the right to modify or replace these Terms at any time. We will provide notice of significant changes by posting the new Terms on the Site with a revised effective date. Your continued use of the Site after any such changes constitutes your acceptance of the new Terms.


2. User Accounts, Bio Data, and Confidential Information

2.1. User Accounts: To access certain features, such as membership services, event registration, or restricted professional resources, you may be required to register for an account. You are responsible for maintaining the confidentiality of your account login information (username and password) and for all activities that occur under your account.

2.2. Submission of Bio Data (Professional and Personal Information): a. Accuracy: You agree to provide current, complete, and accurate professional and personal biodata, including but not limited to: name, qualifications, professional registration number, place of employment, contact information (email, phone, address), and membership status. b. Professional Records: This data is critical for verifying membership eligibility, maintaining a professional register, accreditation, and for communication of vital public health and professional information.

2.3. Critical Information on the Site: The following data elements are considered “Critical Information” and are subject to the highest standards of data governance and security: a. User Account Credentials: Encrypted passwords and security questions/answers. b. Professional Bio Data: Name, Professional Registration/Licence Numbers, Qualifications, and Employment Details. c. Payment Transaction Records: History of membership fee and event payments (excluding full payment card data, which is handled externally as per Section 4). d. Any Public Health or Patient-Related Aggregated Data: Non-identifiable statistical data related to child health reports, morbidity, and mortality uploaded by members or authorized bodies.


3. Data Governance Policy and Use of Data

The Society is committed to a robust Data Governance Framework consistent with modern medical data governance principles and the spirit of the PNG National Data Governance and Protection Policy.

3.1. Data Governance Principles: a. Transparency: Users will be informed about the data collected, the purpose of collection, and how it is used. b. Accountability: The Society’s designated Data Governance Officer (or equivalent) is responsible for ensuring compliance with this policy. c. Purpose Limitation: Data will only be collected and used for specified, explicit, and legitimate purposes (e.g., membership verification, professional communication, service delivery, statistical reporting) and will not be further processed in a manner that is incompatible with those purposes. d. Data Minimization: Only data that is adequate, relevant, and limited to what is necessary for the stated purpose will be collected. e. Accuracy: We will take reasonable steps to ensure Critical Information is accurate and, where necessary, kept up to date. Users are responsible for updating their own Bio Data. f. Storage Limitation: Data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed. g. Integrity and Confidentiality (Security): Data will be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage.

3.2. Use of Critical Information: a. Membership Management: Processing applications, renewals, and verifying professional standing. b. Communication: Sending essential professional updates, event invitations, and public health advisories to members. c. Service Delivery: Providing access to member-only resources, journals, and educational materials. d. Statistical Reporting: Aggregating and anonymising health data (if submitted) for research, publication, and advocacy purposes, strictly prohibiting the use of identifiable patient data. e. Legal/Regulatory Compliance: Disclosing information as required by PNG law, professional licensing bodies, or court order.

3.3. Data Sharing and Disclosure: a. Non-Disclosure: The Society will not sell, rent, or lease your Critical Information to third parties for marketing purposes. b. Third-Party Service Providers: Information may be shared with trusted third-party providers (e.g., website hosting, email services, payment gateways) only to the extent necessary to perform services on our behalf and under strict confidentiality agreements. c. Anonymised Data: We may share aggregated, anonymised, and de-identified data for research, public health reporting, and advocacy, which cannot be used to identify any individual user or patient.

3.4. Data Subject Rights (User Rights): a. Access: Users have the right to request access to their own Critical Information held by the Society. b. Correction: Users must be able to update and correct inaccuracies in their Bio Data via their account profile. c. Deletion/De-registration: Members can request the deletion of their account and associated Bio Data, subject to the Society’s legal and professional obligations to retain certain records for a specified period (e.g., financial or professional standing records).


4. Payment Data Security (Bank of South Pacific (BSP) Standards)

4.1. Payment Processing: All electronic payment transactions (e.g., for membership fees, event registration) on the Site will be processed through a secure, certified Payment Gateway Service Provider.

4.2. Compliance with BSP Standards: The Society and its chosen Payment Gateway Service Provider will adhere to the highest applicable security standards, specifically referencing the security principles espoused by the Bank of South Pacific (BSP) for the protection of cardholder data in Papua New Guinea (e.g., adherence to general security principles like 128-bit encryption, commitment to international standards like PCI DSS if applicable, and emphasis on confidentiality).

4.3. Cardholder Data Storage: The Society’s Site will NOT store, process, or transmit full cardholder data (Primary Account Number – PAN, CVC, Expiration Date). All such data will be handled directly by the secure Payment Gateway in an encrypted environment, minimizing the Society’s security risk and compliance burden.

4.4. Transaction Records: While the full card data is not stored, the Society will retain transaction records (e.g., date, amount, last four digits of the card, name of cardholder) for financial reconciliation and legal purposes, secured within its Critical Information database as outlined in Section 5.


5. Data Security and Safeguards

5.1. Technical Measures: The Society employs reasonable technical and organisational security measures to protect the integrity, confidentiality, and availability of Critical Information, including: a. Encryption: Use of Secure Socket Layer (SSL) technology for all data transmission to and from the Site. User credentials and other sensitive data stored in the database are encrypted. b. Access Control: Strict control measures to ensure that access to Critical Information is restricted to authorised Society personnel on a “need-to-know” basis. c. Regular Audits: Periodic security assessments and vulnerability scanning of the Site infrastructure.

5.2. Breach Notification: In the event of a data security incident or breach that affects the Critical Information of users, the Society will: a. Promptly assess the breach and its severity. b. Take immediate steps to contain and mitigate the breach. c. Notify affected users and relevant authorities in Papua New Guinea as required by law or professional standards.


6. Site Content and Intellectual Property

6.1. Society Content: All content on the Site, including text, graphics, logos, professional guidelines, and reports (excluding User Submissions), is the exclusive property of the Society or its licensors and is protected by copyright and intellectual property laws.

6.2. Limited License: Users are granted a limited, non-exclusive, non-transferable license to access and use the Site Content solely for personal, non-commercial professional development, and advocacy purposes, provided all copyright and proprietary notices are maintained.

6.3. Prohibited Use: Reproduction, modification, distribution, or public display of any Site Content without the express written permission of the Society is strictly prohibited.


7. User Obligations and Prohibited Conduct

7.1. Lawful Use: You agree to use the Site only for lawful purposes and in a manner that does not infringe the rights of, or restrict or inhibit the use and enjoyment of the Site by, any third party.

7.2. No Misrepresentation: You shall not impersonate any person or entity, or falsely state or otherwise misrepresent your affiliation with a person or entity, particularly in relation to your professional standing or qualifications.

7.3. Harmful Content: You shall not submit or upload any content that is false, defamatory, obscene, harassing, or that violates any applicable law.


8. Disclaimer of Warranties and Limitation of Liability

8.1. Professional Information: The information, content, and professional guidelines provided on the Site are for informational and educational purposes only and are not intended as a substitute for professional medical advice, diagnosis, or treatment.

8.2. “As Is” Basis: The Site is provided on an “as is” and “as available” basis. The Society expressly disclaims all warranties of any kind, whether express or implied, including, but not limited to, the implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

8.3. Limitation of Liability: The Society shall not be liable for any direct, indirect, incidental, special, consequential, or exemplary damages, including but not limited to, damages for loss of profits, goodwill, data, or other intangible losses resulting from the use or inability to use the Site.


9. Governing Law and Jurisdiction

These Terms shall be governed by and construed in accordance with the laws of Papua New Guinea. Any dispute arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of Papua New Guinea.


10. Contact Information

If you have any questions or concerns about these Terms, the Data Governance Policy, or your Critical Information, please contact the Society at:

Paediatric Society of Papua New Guinea [Insert relevant Contact Email]