Cyprus Private & Exclusive Investment Event
Privacy policy
Contents
1. Who is responsible for your data
The controller for expressions of interest, invitations, RSVPs, guest lists, website analytics, marketing and image use on the terms below is XPADIA LTD, a company incorporated under Cyprus law, registered on 6 March 2023 under HE 444439; registered office: Mykinon 12, Floor 6, 1065 Nicosia (Lefkosia), Cyprus; correspondence address: Labs Tower, 4 Fotie Pitta, 1065 Nicosia, Cyprus; EU VAT: CY60014811J. Contact for personal data and consent: info@xpadia.com.
AVATARLAND sp. z o.o., ul. Trybunalska 46, 60-325 Poznań, Poland, KRS 0000099765, NIP 7792167451, operates the website and registration on XPADIA's behalf and according to its instructions. Event contact and assistance forwarding requests to XPADIA: info@MocneStronyCypru.pl.
AVATARLAND is also the formal Event organiser. It acts as a separate controller only to the extent necessary to meet its own legal obligations, handle complaints and establish, pursue or defend its own claims. This does not permit its own marketing based on consents given to XPADIA.
2. What we receive and where it comes from
- From the person completing the form: the attendee's first and last name; company, position and reasons for attending in the application form; email, telephone number with country and calling code, preferred contact method and whether the form is completed by the attendee or an authorised representative.
- When contacting an office or assistant: that person's name and contact details instead of the attendee's contact details.
- RSVP declarations, including acceptance of the Terms, separate choices concerning image consent and marketing consent, the communication channels covered by any marketing consent, the date and time, the versions and wording of the declarations and the submission reference.
- During administration: correspondence, invitation, RSVP and attendance status, and information necessary to deal with a request or issue.
- Technical data: HTTP request data, including IP address, date and browser information as needed to operate and secure the server; session identifier and form security data. We do not use these for advertising tracking.
- For analytics: page, device and performance statistics described in section 8, without registration contents.
- With separate consent: an identifiable image recorded in Event photographs or videos. Publication of an interview or statement is agreed separately.
If someone other than the attendee supplies details, the source is the person making the registration or nominating the office contact. We ask them to pass this information to the person concerned; independently, the controller meets its own information obligations, no later than first contact and within the limits in Article 14 GDPR. Application statements should not include health information, identity document details or other particularly sensitive information.
3. Purposes and lawful bases
- Applications, guest selection, invitations, RSVPs, organisational communications and entry lists: Article 6(1)(f) GDPR, XPADIA's legitimate interest in organising a private business event, processing voluntary applications and keeping guests safe.
- Contacting a nominated office or assistant: Article 6(1)(f) GDPR, the legitimate interest in providing organisational communications according to the attendee's preference. This is not consent to marketing to that person.
- XPADIA marketing after the Event: Article 6(1)(a) GDPR and the Participant's consent. We use your data to present XPADIA's services, business cooperation opportunities, future events concerning investment and business activity in Cyprus. Where you have provided the required consent, we may contact you through any communication medium or channel permitted by applicable law, including telephone, email, SMS, MMS, WhatsApp and other electronic or messaging services.
- Recording and publishing an image in Event coverage as part of XPADIA's marketing communications: Article 6(1)(a) GDPR and separate permission to publish the image under § 6 of the Event Terms.
- Protecting the website and forms against abuse: Article 6(1)(f) GDPR, the legitimate interest in security and continuity of service.
- AVATARLAND's own attendance-related obligations and complaints: Article 6(1)(b) GDPR where the person is a contracting party, and Article 6(1)(f) GDPR as necessary to deal with other applicants or representatives. Its own statutory duties: Article 6(1)(c) GDPR only where a legal obligation actually applies.
- Evidence of consents and withdrawals and establishing, pursuing or defending claims: Article 6(1)(f) GDPR, the relevant controller's legitimate interest in demonstrating proper administration and protecting its rights. Such records are not used to continue marketing after consent is withdrawn.
- Website traffic and performance measurement: XPADIA's legitimate interest in understanding content popularity and improving the website (Article 6(1)(f) GDPR insofar as personal data are involved). We do not link statistics to registrations or use them for advertising profiling. Analytics is independent of Event consents.
Providing basic form information is voluntary but necessary to process an application or RSVP. Missing required details prevent the form from being processed. The expression-of-interest form does not require acceptance of the Terms or collect image or marketing consent. After receiving an invitation, the guest confirms attendance through RSVP, accepts the Terms and may select consents. Image consent and marketing consent are optional, not pre-selected and independent of each other. One marketing checkbox covers the purposes and communication channels described in § 7.1 of the Terms, subject to valid consent and applicable law. Refusing or withdrawing marketing consent does not affect applications, invitations or attendance. Earlier consents remain limited to their original scope under § 10.2 of the Terms. Acceptance of the Terms does not replace these consents.
4. Recipients
XPADIA can access the applications needed for guest selection and the complete list of confirmed attendees. AVATARLAND and authorised staff use data within their assigned responsibilities. Hosting and email are provided by dhosting. For analytics, Cloudflare, Inc., USA, provider of Cloudflare Web Analytics, also receives technical data. Other recipients may include technical providers, Skyfall Warsaw reception and security personnel, photographers, videographers and legal advisers, only as necessary for a specific service or obligation. Processors act on documented instructions under the arrangements required by law.
If WhatsApp is used within a valid consent, its provider also processes contact and communication data under its own privacy policy. Providers of telephone, email and messaging services receive data only as necessary for the selected communication. XPADIA must verify the provider’s terms, data protection role and appropriate transfer safeguards before use; consent alone does not replace these requirements.
We do not publish participant lists or application statements or provide them to other guests or partners for their own marketing. Competent authorities may receive data where required by applicable law.
5. Photographs, video and external services
Image consent covers Event coverage as part of XPADIA's marketing communications exclusively on www.xpadia.com and the official XPADIA LinkedIn profile, no later than the end of 6 October 2028. It excludes print, paid advertisements, other profiles or websites, and AVATARLAND's or other partners' own marketing. Detailed rules and early withdrawal are set out in § 6 of the Event Terms.
Public posts can be accessed worldwide. LinkedIn also processes data under its own privacy policy. Global providers of publication and messaging channels may process data outside the European Economic Area. The controller may use such services only with appropriate safeguards, such as an adequacy decision or standard contractual clauses and any additional measures required. Information about the mechanism used and how to obtain a copy of the safeguards is available from info@xpadia.com. Sending data from Poland to XPADIA in Cyprus is not itself a transfer outside the EEA.
The Event website does not embed social plugins or external videos. Social links do not load social plugins. Separate Cloudflare analytics rules are set out in section 8. Any venue security CCTV is covered by its controller's separate notice and not by marketing image consent.
6. Retention periods
- Applications, organisational contact details and guest lists: until Event administration is completed, normally by 6 November 2026. Only data necessary for ongoing matters, legal obligations or claims remain longer, limited to what is needed.
- Marketing data: until consent is withdrawn, the purpose ends earlier or 6 October 2028 at the latest. Marketing after that date requires a new lawful basis and appropriate consents.
- Marketing photographs and videos: until withdrawal or the end of 6 October 2028 at the latest. Materials, including source files, are then deleted or anonymised as regards identifiable images. Previous posts are not kept on controlled channels merely because they were published before that deadline.
- Consent evidence, complaints and claims records: as necessary to demonstrate proper conduct and no longer than the applicable limitation period, taking account of any legally effective suspension or interruption. Only necessary records are kept, not automatically all data.
- Temporary form data: for session handling and correction of errors. Security records and backups are subject to the provider's retention cycle and restricted access and are not used for marketing. Details of the period applicable to a particular category of logs or backups can be obtained from the controller. In an incident, records may be preserved only for the investigation and relevant proceedings.
- According to Cloudflare documentation, unsampled measurements are retained for 7 days and then sampled; reports cover the previous 6 months. Report availability is not a statement that all provider technical data are deleted at that point.
7. Your rights and withdrawing consent
Where provided by the GDPR, you have rights of access and a copy of your data, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests on grounds relating to your particular situation. You may object to direct marketing at any time, with effect for that purpose.
Each consent may be withdrawn separately, without charge or giving a reason, via info@xpadia.com, through info@MocneStronyCypru.pl, by replying to a marketing email or during a marketing call. You may also use an unsubscribe link where provided or withdraw through the relevant messaging service where available. Withdrawal may cover all marketing channels or specified ones. Withdrawal does not affect lawful processing before withdrawal or attendance at the Event. Organisational messages necessary to arrange attendance may still be sent.
Requests must be handled without undue delay, normally within one month. If an extension is permitted because of complexity or the number of requests, you will be told about it and the reasons. Identity is checked only as necessary; a copy of an identity document is not routinely required.
You may complain to a competent supervisory authority, particularly the Polish Personal Data Protection Office or the Cyprus data protection authority. Under the GDPR, you may choose the authority for your habitual residence, place of work or the alleged infringement.
8. Sessions, analytics and security
The website uses the necessary CYPRUSEVENT session cookie to secure forms and display errors or confirmation. It is a session cookie with HttpOnly, SameSite=Lax and Secure on HTTPS. Blocking cookies may prevent submissions. Fonts and images remain local; no advertising cookies or advertising profiling are used.
Cloudflare Web Analytics runs by default during visits, without a consent banner. Its script comes from static.cloudflareinsights.com and measurements go to cloudflareinsights.com. According to Cloudflare's description, measurement uses neither cookies nor browser storage. The provider receives the IP address during connection but states that it discards it at the data centre without keeping it in the service's core databases or logs.
Reports cover visited pages, referral sources, country, device type, browser, operating system, loading times and performance. We do not send form contents, names, phone numbers or emails, or link statistics to registrations. Cloudflare reporting dimensions.
We do not store analytics choices in cookies or localStorage. For data matters, including an objection to processing based on legitimate interests, contact info@xpadia.com. You can also block the measurement script in your browser without preventing use of the forms. Aggregate reports are not used to identify specific attendees.
Cloudflare operates globally; technical data may be processed outside the EEA, including in the USA. Cloudflare's data processing terms provide transfer mechanisms, including standard contractual clauses where safeguards are required. Information about the applicable mechanism and copies of safeguards are available via info@xpadia.com. See also Cloudflare's privacy policy.
Forms use transport encryption on HTTPS, protection against forged requests, validation and anti-spam limits. Submissions are sent to Event staff by email with a JSON attachment, not placed in a public file or directory. Access must be restricted to authorised people. Invitations are decided individually by people; the form does not make solely automated attendance decisions or use advertising profiling.
Questions or consent withdrawal: info@xpadia.com · info@MocneStronyCypru.pl