Privacy Statement Effective from: 02/08/2019 Overview This website VitalityExpo.ie is operated by EventHaus Ltd At EventHaus we seek to maintain the privacy, accuracy, and confidentiality of all data (including your personal data) that we collect and use as part of our services. We will use your personal data only for the purposes described below and in full compliance with the GDPR Data Protection Legislation. This Privacy Statement applies to https://www.vitalityexpo.ie/ EventHaus and its associated companies are fully committed to protecting and respecting your privacy. It is the intention of this Privacy Statement to explain to you the information practices of EventHaus in relation to the information we collect about you and other users. Registration Certain services are only available to registered users. Examples of these are newsletters and competitions Sign up When you sign up with https://www.vitalityexpo.ie/ to avail of a service we collect only the information needed to provide that service. What we process:
Personal Identifier– we collect an identifier such as your email address or social login.
Why we process this data: The legal basis for processing this data is to enable us to deliver registration services that you have consented to. The personal identifier allows us to recognise you when you come to our site or service. This enables us to provide you with the service that you signed up for. For example, viewing your newsletter preferences etc. Details of these specific services are provided elsewhere on this page. Who has access: Customer registration identity information is only ever accessible to EventHaus employees though sometimes aggregated statistics about usage may be made available to others. For example, we might state to our exhibitors & sponsors that we have a certain number of registered users who access the https://www.vitalityexpo.ie/ newsletter. Access may be granted to our registration system provider in order to resolve problems but only under the strictest governance by EventHaus. EventHaus ensures that our registration provider adheres to the highest standards of data protection and privacy. Your data may also be shared with a 3rd party if you choose to avail of a service from that 3rd party but only with your consent. Delete My Account: If you wish to delete your https://www.vitalityexpo.ie/ account please email firstname.lastname@example.org request that your account is deleted. Newsletters One of the main services that we offer to our registered users is the ability to sign up to receive newsletters. When you sign up for newsletters we collect information to enable us to deliver the newsletter and to tell us what content you are interested in. What we process:
Identity data – your email address and name
Newsletter Interest - which newsletters you wish to receive.
Interaction data - newsletters that you open and the links you follow in the newsletter
Why we process this data: The legal basis for processing this data is to enable us to deliver the newsletters that you have consented to receive. This identity and interest data helps us deliver the newsletters that you have requested. The interaction data allows us to understand which parts of the newsletter and which content interests you to enable us to improve the service that we deliver to you. Who has access: Only EventHaus employees will have access to this data through our email and customer identity systems. Access may be granted to third parties such as our email campaign provider in order to resolve problems sending emails etc. but only under the strictest governance by EventHaus. EventHaus ensures that our email campaign provider adheres to the highest standards of data protection and privacy. This registration data allows us to provide you with access to newsletters with as little hassle as possible. Competitions When you enter a competition in association with EventHaus we may collect data about you or your entry in order to manage the competition and enable us to deliver the prize to you if you are lucky enough to win. Entering a competition When you enter a competition, we need to process your entry What we process:
Identity data- including name, address, phone number, email
Data about entry- including date of entry, device used etc.
Why we process this data: The legal basis for processing this data is legitimate interest. In order to decide the competition winner, it is necessary for us to process your entry This data is required to enable EventHaus to contact winners and manage the competition. Who has access: This data will only be processed by EventHaus employees and/or sub contracted service providers for the sole purpose of managing the competition. The only exception to this is where a 3rd party is sponsoring the competition and requests to get access to your information. Information will only be shared with this 3rd party with your consent and this will be made clear to you before submitting your competition entry to ensure that you have full control of who sees your data. Delete my competition entries: If you wish to delete any competition entries that you have made please email EventHaus at email@example.com and request that you wish to have your competition entries deleted. Winning a competition If you are lucky enough to win a competition, then we need to contact you to ensure delivery of your prize and know where to send it. What we process:
Identity data- including name, address, phone number, email
Data about entry- including date of entry, device used etc.
Why we process this data: The legal basis for processing this data is our contract with the winner to deliver the prize to them. This data is required to enable EventHaus to contact winners and deliver the prize to them Who has access: This data will only be processed by EventHaus and sub contracted service providers for the sole purpose of delivering the prize to the winner. When a 3rd party is sponsoring the competition and providing the prize it is necessary to provide them with the winner’s personal data in order to enable them to deliver the prize to the winner. The only exception to this is where a 3rd party is sponsoring the competition and requests to get access to your information. Information will only be shared with this 3rd party with your consent and this will be made clear to you before submitting your competition entry to ensure that you have full control of who sees your data. Delete my competition entries: If you wish to delete any competition that you have made, please email EventHaus at firstname.lastname@example.org request that you wish to have your competition entries deleted. Ticketing Occasionally, our employees receive payment information from customers over the phone. When this occurs, the payment information is entered as instructed into the relevant payment system and all other copies are deleted or destroyed immediately. We will use your Data only for the purposes and in the manner set forth below, which describes the steps we take to ensure the processing of your Data is in compliance with the Data Protection Acts 1988 and 2003 (as amended) and any subsequent data protection and privacy legislation, European Union Law including Regulation (EU) 2016/679, known as the General Data Protection Regulation or GDPR and any subsequent amendments (collectively referred to as “Data Protection Legislation”). Site Function We use analytics providers in order for us to understand our audience, the content that appeals to them and how well our site is working. We also provide tools from the major social networks (Twitter, Facebook etc.) to allow you to share content from our site. Analytics Analytics tools allow us to understand how our audience interacts with our site and our content and enables us to provide a better service to our site visitors. We do not collect or process any personal information in our analytics platform. What we process:
Your IP address- in order to track your activity on our site we process your IP address
Anonymous data about your device – your operating system (e.g. iOS11), device type (e.g. tablet)
Anonymous aggregated demographics- for example your current city and other anonymous data.
Anonymous data about your browsing- stories you read, types of content consumed and browsing patterns.
Right of Access: You are entitled to have access to your personal data which we hold (this is more commonly known as submitting a “data subject access request”). Typically, there is no fee for this, however, we have the right to apply a reasonable fee in exceptional circumstances.
Right of Portability: You can request a copy of the personal information we hold about you in a structured, commonly used and machine-readable format and if technically feasible, have your personal information transmitted to another data controller in a machine-readable format.
Right to rectify: If it is found that personal data is inaccurate, you are entitled to have the inaccurate data removed, corrected or completed, as appropriate.
Right to withdraw consent: You have the right to withdraw your consent to any future processing for which you have previously given that consent.
Right to Erasure: Subject to certain conditions, you are entitled, on certain grounds, to have your personal data erased (also known as the “right to be forgotten”).
Right to Restriction: Restrict processing of your personal information in certain circumstances
Right to object to processing: You are entitled to object to our use of your personal information for our legitimate interests, for profiling and for direct marketing purposes.
Rights relating to automated decision making including profiling: You are entitled to not be subject to a decision which is based solely on automated processing where that decision produces a legal effect on you or otherwise significantly affects you. We do not make automated decisions of this nature
Right to complain: You are entitled to lodge a complaint with the Data Protection Commissioner if you have concerns about how we process your personal data.
You can complain directly to the Office of the Data Protection Commissioner at Canal House, Station Road, Portarlington, Co. Laois by telephone at 1890 25 2231 and/or by email to email@example.com. You can also make a complaint directly to the relevant data protection authorities in the country where you are ordinarily resident. For example, in the UK you can also complain directly to the ICO at https://ico.org.uk/make-a-complaint/ or call their helpline on 0303 123 1113. How To Exercise Your Rights Requests for information or to exercise these rights should be made in writing to the EventHaus
by post to the EventHaus, Unit 3 Block A, Broomfield Business Park, Malahide, Co. Dublin, Ireland
If possible, you should specify the type of information you would like to see to ensure that we meet your expectations. We must be able to verify your identity in order to ensure the safety of your data. Your request may not affect the rights and freedoms of others, e.g. privacy and confidentiality rights of other individuals and/or businesses. Limitations To These Rights These rights are in some circumstances limited by data-protection legislation. You may have various rights under Data Protection Legislation. However, in certain circumstances, these rights may be restricted (Article 23 of the General Data Protection Regulation, which is transposed into Irish law by section 54 of the Data Protection Bill 2018, sets out the circumstances in which your rights may be restricted). In particular, your rights may be restricted where this is necessary:
for the prevention, detection, investigation and prosecution of criminal offences, and/or
in compliance with a legal obligation such as a court order and/or
in contemplation of or for the establishment, exercise or defence of a legal claim or legal proceedings (whether before a court, tribunal, statutory body or an administrative or out-of-court procedure).
Your Data The following sections describe how we manage, secure and control access to your data and under what circumstances we disclose data to others. Retention Of Your Data We keep your personal data for as long as it is necessary to do so to fulfil the purposes for which it was collected as described above. The criteria we use to determine data retention periods for personal data includes the following:
Retention in case of queries; we will retain it for a reasonable period after the relationship between us has ceased;
Retention in accordance with legal and regulatory requirements.
If you would like further information about our data retention practices, please contact EventHaus (see the “Contact Us” section below). As a matter of course, we will delete personal data associated with accounts that have been inactive for at least 6 years. Sharing Data with Third Parties We use third party service providers who work for us in the provision of our services. Your data may be processed by a third party if required to deliver a service you have requested. For example, our ticketing software and payments are processed by 3rd parties. We will check any third party that we use to ensure that they can provide sufficient guarantees regarding the confidentiality and security of your Data. We will have written contracts with them which provide assurances regarding the protections that they will give to your Data and their compliance with our data security standards and international transfer restrictions. How Is Your Data Secured EventHaus operate and use appropriate technical and physical security measures to protect your personal data. We have in particular taken appropriate security measures to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. In addition, our service providers are also selected carefully and required to use appropriate protective measures. Where Do We Store Your Data? In most cases, EventHaus stores your data securely within the European Economic Area (EEA) using GDPR compliant service providers. In some cases, EventHaus may have to transfer or store your data to countries outside the EEA, for example, when one of our service providers use employees or equipment based outside the EEA. For transfers of your personal data to third parties outside of the EEA, we take additional steps in line with Data Protection Legislation. We have put in place adequate safeguards with respect to the protection of your privacy, fundamental rights and freedoms, and the exercise of your rights, e.g. we establish an adequate level of data protection through EU Standard Contractual Clauses based on the EU commission’s model clauses. Disclosure Of Your Data Your Data is private and confidential. Your Personal data may only be shared within EventHaus, for any of the purposes set out in this Privacy Statement. From time to time, we may access and/or disclose your Data if required to do so by law or in good faith and belief that such action is necessary to:
conform with the law or comply with legal process served on us;
protect and defend our rights or property including, without limitation the security and integrity of our network and systems; or
act under exigent circumstances to protect the personal safety of users of our services or members of the public
CHANGES TO THIS INFORMATION This statement is effective from: 2nd August 2019 We may decide to make changes to this Privacy Notice. If it’s a fundamental change in how we deal with you, then the updated Privacy Notice will be provided to you well in advance of the change actually taking effect. We will post the changes on our website along with an explanation of what the likely impact of those changes will be to you, if any. In order to ensure fairness of the processing, we encourage you to review the content of this Privacy Notice regularly. ACCEPTANCE OF THIS PRIVACY STATEMENT By using this Site and by disclosing your Data to us, you consent to the collection, storage, processing, use and disclosure of your Data by us as described in this Privacy Statement. If you do not agree with or are not comfortable with any aspect of this Privacy Statement, your only remedy is to discontinue using our Site. We reserve the right to modify this Privacy Statement at any time. Your continued use of any part of our Site following notification or posting of such changes will constitute your acceptance of those changes. Contact the Data Protection Office EventHaus has a data protection function including a data protection officer. If you wish to invoke you rights or have any questions please contact firstname.lastname@example.org Updated 09.02.2020