Compliance
Privacy Policy
IEG Group Privacy Policy
In joint controllership with Meneghini & Associati SRL — SSEC Event | Version 11.03.2026
Table of Contents
- Introduction
- Categories of Data Subjects and Data
- General Principles of Processing
- Purposes of Processing
- Legal Basis, Mandatory and Optional Nature
- Data Controllership
- Data Protection Officer
- EU Representative of Non-EU Companies
- Non-EU Representative of EU Companies
- Communication and Disclosure of Data
- International Data Transfers
- Data Retention Period
- Processing Methods
- Security Measures
- Data Subject Rights
- Changes to this Policy
Introduction
This Privacy Policy is provided in accordance with the applicable personal data protection regulations, in relation to the personal data processed:
- a) as independent Data Controllers, by ITALIAN EXHIBITION GROUP S.p.A. ("IEG") and/or its subsidiary companies (the "Subsidiaries"), which organize and host exhibitions, fairs, events, conferences/congresses, workshops, webinars and/or physical and/or virtual business meetings (the "Events"), or provide services and products such as catering, set-up, cleaning, training, publishing, etc. (the "Services"); and
- b) as Joint Controllers, by IEG and MENEGHINI & ASSOCIATI SRL (also "MA") — with registered office in Vicenza, Viale Trento 56, Tax Code/VAT No. 00892530247 — exclusively in connection with the "SSEC – Storage and Solar Expo Conference" Event.
Personal data refers to information related to natural persons, sole proprietorships and/or partnerships ("data subjects") pursuant to EU Regulation 679/2016 ("GDPR").
Processing includes operations such as recording, organizing, storing, processing, modifying, selecting, extracting, comparing, using, communicating, deleting and destroying data, in accordance with the purposes described below.
Categories of Data Subjects and Data Collection
The data processed relates to the following categories of data subjects:
- Customers: exhibitors, visitors/consumers, buyers, conference attendees, congress participants, event speakers, workshop participants, webinar and business meeting attendees, purchasers of Services and Products.
- Prospects: individuals who have expressed interest in Events, Services and/or Products through contact requests, information or quote requests, including subscription to IEG Group or MA newsletters.
- Other categories: recipients of Event invitations (guests, journalists, media contacts); minors over the age of 14; website and/or app users.
Data is collected:
- directly from the data subject;
- from public and/or private databases (identification, contact, corporate, tax, financial, and creditworthiness data);
- from Subsidiaries (identification, contact, corporate, tax, and financial data);
- from social network platforms (e.g. LinkedIn, Facebook): identification data, contact details, economic and product sector.
General Principles of Processing
Data is processed in compliance with the principles of lawfulness, fairness, accuracy, transparency, proportionality, necessity, completeness and security, as well as all other obligations set forth by applicable data protection regulations.
Purposes of Processing
1. Protection of information assets, business continuity and IT security
Carried out by IEG and/or Subsidiaries (for events other than SSEC) and by Joint Controllers IEG and MA (exclusively for jointly controlled data of the SSEC Event).
2a. Newsletter service subscription
Of IEG and/or Subsidiaries (for events other than SSEC) and of Joint Controllers IEG and MA (for the SSEC Event).
2b. Fulfillment of pre-contractual requirements and/or compliance with contractual or legal obligations
Including the planning and technical-organizational management of Events and/or Services and Products of IEG and/or Subsidiaries (e.g. accounting, tax, administrative obligations, preparation of the consolidated Group financial statements).
2c. Joint Controllers IEG and MA – SSEC Event
Fulfillment of pre-contractual requirements and/or compliance with contractual obligations related to the SSEC Event, including the planning and technical-organizational management of the Event and/or obligations required by law or regulation.
3. Market research through nominative surveys
Conducted exclusively by IEG, aimed at measuring perceived performance levels and satisfaction in relation to Events, Services and Products.
4. Basic profiling
Carried out by IEG and/or Subsidiaries and, solely in the case of the SSEC Event, also by Joint Controller MA. Uses limited data sets to establish a minimal commercial profile of the data subject. The main data processed by category:
- Exhibitors: name and surname, company name, contact details, registered office, country, website, sector, brand, service/product types, promotional budget, distribution channels, markets of interest.
- Buyers/Visitors: name and surname, company name, job position, turnover, number of employees, sector, geographic areas of interest, purpose of the Event visit.
- Journalists: name and surname, contact details, media outlet, country, language.
- Speakers/Congress participants: name and surname, contact details, sector, topics covered, language.
- Other customer categories: name and surname, contact details, sector, turnover, number of employees.
5. Advanced profiling
This purpose requires the specific consent of the data subject.
Carried out exclusively by IEG and, solely in the case of the SSEC Event, by Joint Controllers IEG and MA. Analyzes the overall interactions of the data subject with the various IEG Group entities (customer centricity) by integrating:
- product/economic sector of activity;
- categories of Events, Services and/or Products requested or offered;
- transaction history;
- perceived satisfaction levels (from nominative surveys and statistical reports);
- commercial margins at Group level;
- website browsing behavior, interactions with communication channels and commercial e-mail services.
6. Commercial and advertising communications (soft spam)
Sent by IEG and/or Subsidiaries, and by Joint Controller MA solely for the SSEC Event, via e-mail, SMS, WhatsApp, Telegram, telephone calls, social networks and ordinary mail, regarding:
- Events/Services/Products similar to those already purchased (customer);
- Events/Services/Products that were the subject of pre-contractual inquiries or expressions of interest (prospect), including implicit expressions (e.g. spontaneous delivery of a business card).
Note: for Subsidiaries based in Brazil, China and Singapore, processing for this purpose requires prior specific consent (exclusively for B2C visitors).
7. Direct marketing activities
This purpose requires the specific consent of the data subject.
Exclusively by IEG (and, solely for the SSEC Event, by Joint Controllers IEG and MA) towards leads, customers and prospects, for communications relating to Events/Services/Products of a non-similar nature to those already purchased or of interest.
8. Data sharing
Each sub-purpose requires the specific consent of the data subject.
- 8a — From IEG to third-party partner companies or entities for their own direct marketing activities.
- 8b — From IEG to social network platforms for lookalike services.
- 8c — From Joint Controllers IEG and MA to third-party partner companies or entities of the Joint Controllers for their own direct marketing activities.
9. Online and physical security management
To protect IEG and Subsidiaries, Event participants, Group websites and apps from fraud, theft, misappropriation, damage or other violations of law.
10. Management of other organizational and operational activities
- Quality management system;
- Management control;
- Website access and content management;
- VIP contact database management;
- Production, printing and distribution of editorial materials;
- Media accreditation management;
- Extra-contractual management of thematic side initiatives at Events;
- Video surveillance management at Event venues.
11. Credit data management – IEG Events Arabia LLC
This purpose requires the specific consent of the data subject.
Processing of data relating to the financial situation, repayment capacity, past transactions and payment and debt behavior.
Legal Basis for Processing
| Purpose | Legal Basis | Notes |
|---|---|---|
| 1 – Protection of information assets | Legitimate interest | — |
| 2a – Newsletter | Legitimate interest | No consent required |
| 2b / 2c – Pre/contractual and legal obligations | Contractual necessity / legal obligation | Failure to provide data = inability to process requests |
| 3 – Nominative surveys | Legitimate interest | — |
| 4 – Basic profiling | Legitimate interest | — |
| 5 – Advanced profiling | Specific consent | Withdrawal possible without affecting ongoing contracts |
| 6 – Soft spam | Legitimate interest | Right to object at any time |
| 7 – Direct marketing | Specific consent | — |
| 8a / 8b / 8c – Data sharing | Specific consent | — |
| 9 – Security | Legitimate interest | — |
| 10 – Organizational activities | Legitimate interest | — |
| 11 – Credit data (Arabia) | Specific consent | IEG Events Arabia LLC only |
Consent provided by the legal representative of a company is deemed to extend to other data subjects within the same organization whose data is provided.
Data Controllership and Joint Controllership
Data Controllers
- IEG: for all purposes, in relation to data processed by IEG and/or Subsidiaries based in the EEA, and by non-EEA Subsidiaries within the limits of the extraterritorial application of local regulations.
- Each Subsidiary: for purposes 1, 2, 4, 6 only.
- IEG Events Arabia LLC: for purpose 11 only.
Joint Controllers
IEG and MA are Joint Controllers for purposes 1, 2a, 2c, 4, 5, 6, 7, 8c — exclusively for jointly controlled data of the SSEC Event.
Data Protection Officer
- DPO – Italian Exhibition Group S.p.A.: Avv. Luca De Muri, domiciled at IEG's registered office.
- DPO – IEG Asia Pte Ltd (Singapore): Avv. Ilaria Cicero, 1 Maritime Square #09-57, Harbourfront Centre, Singapore 099253.
- DPO – Meneghini & Associati SRL: Nicolò Muraro, domiciled at MA's registered office.
EU Representative of Non-EU Companies
The companies IEG China Co. Ltd, IEG Asia Pte. Limited, IEG Events Middle East LLC, IEG Events Arabia LLC, Italian Exhibition Group USA Inc. and Italian Exhibition Group Brasil Eventos Ltda have designated Italian Exhibition Group S.p.A. as their representative in the EU pursuant to Article 27 of the GDPR, for all matters concerning processing activities involving data subjects based or resident in the EU.
Non-EU Representative of EU Companies
Italian Exhibition Group S.p.A. has designated IEG China Co. Ltd as its representative in China pursuant to Article 53 of the Chinese Personal Information Protection Law (PIPL), for all matters concerning processing activities involving data subjects based or resident in China.
Communication and Disclosure of Data
Data is shared with authorized personnel of IEG and/or Subsidiaries (Financial, Communications, Travel, Sales, Marketing, Legal departments, etc.) and may be communicated to:
- Hosting, development, management, maintenance, disaster recovery and cybersecurity providers;
- Providers for Event organization and management (ticketing, logistics, security, first aid, electronic payment, hospitality, catering, translation, CRM, direct e-mail marketing, web marketing, etc.);
- Third-party partners for Event co-marketing;
- Journalists and media organizations;
- Agents and regional advisors;
- Law firms and notaries;
- Control and supervisory bodies (auditors, DPO, supervisory bodies, statutory auditors);
- Debt collection agencies;
- Computer forensics companies;
- Public authorities (Police, Prefecture, Tax Agency, Financial Police, etc.);
- IEG (from Subsidiaries) and Subsidiaries (from IEG).
Identification data of visitors/buyers may be communicated to exhibitors and vice versa through digital platforms, QR Codes or Event catalogs.
Exhibitor data is disclosed, only upon their request, through the event catalog (print and online). IEG and the other Group companies refrain from any other disclosure of data.
International Data Transfers
Data is transferred by IEG and/or EU-based Subsidiaries to non-EU recipients, including Subsidiaries and providers based in China, Singapore, USA, United Arab Emirates and Brazil, as well as online service providers (landing pages, social platforms, web traffic analysis, CRM, payment services).
The safeguards adopted for transfers are:
- USA: EU Commission Adequacy Decision of 10 July 2023 (Trans Atlantic Data Protection Framework).
- Canada: Adequacy Decision of 15 January 2024 (PIPEDA).
- Other non-EU countries: Standard Contractual Clauses (SCCs) in accordance with the text approved by the EU Commission.
In the case of data processed for the SSEC Event, the Joint Controllers IEG and MA do not transfer data abroad.
Data Retention Period
| Purpose / Data Category | Retention Period |
|---|---|
| Protection of information assets (purpose 1) | Indefinite; security logs: 1 year |
| Pre-contractual requirements – leads (purpose 2) | 2 years from collection |
| Pre-contractual requirements – prospects (purpose 2) | 10 years from collection |
| Contract performance – customers (purpose 2) | Duration of the commercial relationship + 10 years from termination |
| Invitation letters for consular visas | 6 months from the end of the Event |
| Assistance requests during Events | 60 days from the end of the Event |
| Event promotional catalog | 2 catalog editions |
| Business Matching service | 3 months from the end of the individual Event |
| Editorial products | 5 years from publication |
| Compliance with legal obligations (purpose 2) | 10 years from contract execution or data collection |
| Nominative surveys (purpose 3) | 2 years from collection |
| Basic profiling (purpose 4) | 2 years from collection |
| Advanced profiling (purpose 5) | 2 years from collection |
| Soft spam (purpose 6) | Until objection by the data subject |
| Direct marketing (purpose 7) | 10 years from collection or until consent withdrawal |
| Credit data – IEG Events Arabia LLC (purpose 11) | 2 years from collection |
| In case of litigation | Until the 6th calendar year following full execution of the judgment or settlement |
Processing Methods
IEG collects data through:
- IEG Group websites;
- Online or paper forms / pre-registration or participation apps;
- QR Codes or Bar Codes at Event entrances;
- Business cards spontaneously provided by the data subject;
- Applications to participate in Events, Services and/or Products;
- Contracts entered into with the data subject;
- Quote and/or information requests (e.g. via online forms);
- Online platforms for business meetings and information exchange between exhibitors, visitors and/or buyers;
- Intra-group information exchange from Subsidiaries.
Data is processed by authorized and trained personnel of IEG and/or Subsidiaries, using electronic and paper-based tools, with logic strictly related to the individual purposes.
Security Measures
Appropriate technical and organizational security measures are applied to the processing of personal data to ensure data integrity, security and availability. The main measures adopted include:
- Firewall, Antivirus, Antispam, DMZ;
- Redundant storage and daily back-up;
- Unique authentication credentials; 2FA and VPN for remote access;
- Authorization profiles via Active Directory / Azure Directory (Entra ID);
- Written confidentiality obligations and staff training;
- VLAN, Disaster Recovery, Patch Management;
- IDS, IPS, EDR, DLP systems;
- SIEM and SOC (Security Operation Center);
- HTTPS connections with 2048-bit encryption and TLS v1.x (PCI DSS Compliance);
- Periodic Vulnerability Assessment and Penetration Testing;
- Periodic audits.
The use of bot software programs violates the Terms of Use of IEG websites. IEG reserves the right to claim damages and to suspend access to services.
Data Subject Rights
Data subjects may exercise the following rights by contacting the Data Controllers/Joint Controllers:
- Access to their personal data processed by the Controller.
- Rectification or supplementation of inaccurate or incomplete data.
- Erasure of obsolete data, in the cases provided for by applicable regulations.
- Restriction of processing in the cases provided for by applicable regulations.
- Data portability within the limits set by applicable regulations.
- Objection to processing carried out on the basis of the Controller's legitimate interest.
- Not to be subject to automated decisions producing significant legal effects. (The Controllers do not use automated decision-making processes.)
- Withdrawal of consent where consent is the legal basis for processing.
- Lodging a complaint with the competent supervisory authority.
Supervisory Authority – Italy
Garante per la protezione dei dati personali
Piazza Venezia 11 – IT-00187 – Roma
Tel.: (+39) 06.69677.1 — E-mail: rpd@gpdp.it
Joint Controllers Contact Details
- Italian Exhibition Group S.p.A. — Via Emilia, 155 – 47921 Rimini (Italy) — privacy@iegexpo.it
- Meneghini & Associati SRL — Viale Trento 56/F – 36100 Vicenza (Italy) — nmuraro@meneghinieassociati.it
Changes to this Policy
This Privacy Policy may be updated over time to reflect changes in data processing practices or to comply with new regulatory requirements. Any update will be communicated through appropriate means (publication on IEG and/or Joint Controllers' websites, e-mail, restricted online areas).
IEG Group Privacy Policy in joint controllership with Meneghini & Associati — Version 11.03.2026