Privacy Policy
1. Introduction
Your privacy matters to us. This privacy policy explains how Interplas Events Limited collects, uses, shares and protects your personal data, and the rights you have in relation to it.
It applies to personal data we process when you use our websites, subscribe to our publications and newsletters, register for or attend our events, purchase our products or services, contribute content, respond to surveys, or otherwise interact with us (together, our "Services").
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), together referred to in this policy as "Data Protection Laws".
2. Who we are and how to contact us
Interplas Events Limited (company number 09153942), with its registered office at Dodleston House, Bell Meadow Business Park, Park Lane, Pulford, Chester CH4 9EP, is the controller of your personal data. This means we decide how and why your personal data is processed.
We have appointed a data privacy manager who is responsible for overseeing questions in relation to this policy and requests to exercise your legal rights. You can contact them at:
- Email: dataprivacy@rapidnews.com
- Post: Data Privacy Manager, Interplas Events Limited, Dodleston House, Bell Meadow Business Park, Park Lane, Pulford, Chester CH4 9EP
- Telephone: +44 (0) 1244 680222
3. The personal data we collect
3.1 Data you give to us
We collect personal data when you register for an account or event, apply for or book exhibition space, subscribe to a publication or newsletter, download content, submit an enquiry, take part in a survey, poll or competition, contribute editorial content, provide feedback, or otherwise contact us. Depending on the interaction, this may include:
- Identity and Contact Data — your name, job title, employer, business address, email address, telephone and mobile numbers, and social media handles;
- Profile Data — your job function, business interests, areas of expertise and other business demographics you choose to share;
- Transaction Data — details of purchases you make from us and the payment details needed to process them (payment card details are processed by our payment service providers and are not stored by us);
- Attendee Data — the information you provide when registering for our events, including badge details;
- Publication Data — content you submit for publication on our websites or in our publications;
- Marketing and Communications Data — your marketing and communication preferences, including consent records.
Where information is mandatory for us to fulfil your request (for example, to complete an event registration), we will make this clear at the point of collection. If you do not provide it, we may be unable to provide the relevant product or service.
3.2 Data we collect automatically
When you use our websites we automatically collect Technical and Usage Data, such as your IP address, approximate location, browser type and version, operating system, pages viewed, time spent, navigation paths and referral sources. This is collected through cookies and similar technologies, which are only set with your consent where required by law. For full details, including how to manage your preferences, please see our Cookie Policy.
3.3 Data we receive from third parties
We may receive personal data about you from:
- analytics and advertising providers (such as Google) and search information providers;
- providers of technical, payment and delivery services;
- publicly available sources such as Companies House, and information you have made public on business websites or professional social media platforms;
- selected third-party business data providers.
Where we obtain your personal data from a third-party source rather than from you directly, we will provide you with the information required by Article 14 UK GDPR — including where your data came from — within one month of obtaining it, or in our first communication with you, whichever is sooner, unless an exemption applies.
3.4 Special category data
Where necessary to enable you to participate fully in our events, we may process dietary or accessibility requirements that you expressly choose to provide. We process this data only with your explicit consent, use it solely for the purpose for which it was provided, and delete it when no longer needed. We do not otherwise knowingly collect special category data, and we ask that you do not send it to us. If we receive special category data we have not requested, we will delete it.
3.5 Children
Our Services are directed at business professionals. We do not knowingly collect personal data from anyone under the age of 18, and we ask that you do not provide personal data to us unless you are at least 18 years old. If we become aware that we hold personal data of a person under 18, we will delete it.
3.6 Aggregated data
We may create and use aggregated statistical or demographic data for any purpose. Aggregated data may be derived from your personal data but does not directly or indirectly identify you and is not personal data in law. If we ever combine aggregated data with your personal data in a way that can identify you, we will treat the combined data in accordance with this policy.
3.7 Event Photography, Filming and Recording
We may photograph and record our events for promotional, editorial, security and archival purposes. Images or recordings may include attendees, exhibitors, speakers and visitors. Where practical, we will make attendees aware that photography or filming is taking place. If you do not wish to appear in close-up photography or recordings, please speak to event staff and we will make reasonable efforts to accommodate your request, although this may not always be possible in crowded public areas. Where CCTV is operated by a venue, that venue acts as the controller for those recordings under its own privacy information. We rely on our legitimate interests (promoting, documenting and securing our events) as the lawful basis for this processing.
4. How and why we use your personal data
We only use your personal data where the law allows us to. The table below sets out the purposes for which we process your personal data and the lawful bases we rely on. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you can request details of these assessments by contacting us.
| Purpose | Type of data | Lawful basis |
|---|---|---|
| Registering you as a customer, subscriber, website user or event attendee, and providing the products, services, subscriptions and events you have requested | Identity and Contact; Profile; Transaction; Attendee | Performance of a contract with you |
| Processing payments, managing subscriptions and collecting money owed to us | Identity and Contact; Transaction | Performance of a contract with you; Legitimate interests (recovering debts due to us) |
| Running our events, including registration, badging, entry management, safety and security, and post-event follow-up | Identity and Contact; Attendee; Special category (with explicit consent) | Performance of a contract with you; Legitimate interests (running safe, well-organised events); Explicit consent (dietary and accessibility data) |
| Managing our relationship with you, including notifying you of changes to our terms or this policy, and inviting you to leave reviews or complete surveys | Identity and Contact; Profile; Marketing and Communications | Performance of a contract with you; Legal obligation; Legitimate interests (keeping records updated; understanding how customers use our Services) |
| Enabling you to enter prize draws or competitions | Identity and Contact; Profile | Performance of a contract with you; Legitimate interests (growing our business) |
| Sending you direct marketing about our publications, events, products and services (see section 5) | Identity and Contact; Profile; Marketing and Communications | Consent, or the "soft opt-in" under PECR (email/SMS); Legitimate interests (postal and business-to-business telephone marketing, promoting our Services) |
| Administering and protecting our business and websites, including troubleshooting, testing, system maintenance, security, back-ups and fraud prevention | Identity and Contact; Technical; Usage | Legitimate interests (running our business; network and information security; fraud prevention); Legal obligation |
| Delivering relevant website content and online advertising, and measuring its effectiveness | Identity and Contact; Profile; Technical; Usage; Marketing and Communications | Consent (cookie-based advertising and measurement require your consent under PECR) |
| Using analytics to improve our websites, publications, events, products and services | Technical; Usage | Legitimate interests (keeping our Services updated and relevant; informing our strategy); Consent, where analytics cookies are used |
| Photographing, filming and recording our events for promotional, editorial, security and archival purposes (see section 3.7) | Images and audio-visual recordings of attendees, exhibitors, speakers and visitors | Legitimate interests (promoting, documenting and securing our events) |
| Establishing, exercising or defending legal claims; obtaining insurance and professional advice; managing risk | Any of the categories described in this policy, as relevant | Legitimate interests (protecting our business and legal rights) |
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the lawful basis for doing so.
Automated decision-making: we do not use your personal data to make automated decisions that have legal or similarly significant effects on you.
5. Direct marketing
5.1 Marketing from us
We may use your Identity, Contact, Profile, Technical and Usage Data to understand which of our publications, events, products and services may interest you.
For marketing by email or SMS, we will only contact you where you have consented, or where the PECR "soft opt-in" applies — that is, where you have purchased (or negotiated to purchase) products or services from us, we are marketing our own similar products and services, and you were given a clear opportunity to opt out when we collected your details and in every message since. Corporate subscribers may also receive business-to-business email marketing relevant to their role, always with a clear means of opting out.
For marketing by post, or by telephone to business numbers, we rely on our legitimate interest in promoting our Services, and we screen calls against the Telephone Preference Service and Corporate Telephone Preference Service.
5.2 Third-party marketing
We will obtain your express opt-in consent before sharing your personal data with any other company for their own marketing purposes.
We may send you communications on behalf of selected third parties within our industry sectors (for example, exhibitors and sponsors). In these cases your personal data remains under our control at all times: the third party provides us with the content and we send it to you; they never see or handle your data unless you respond to them directly.
5.3 Opting out
You can opt out of marketing at any time by using the unsubscribe or preference links in any message we send, by telling us during a telephone call, or by contacting us using the details in section 2. It may take a few days for our records to update. If you opt out, we will keep a minimal suppression record (such as your email address) to make sure we respect your choice. Opting out of marketing does not affect messages we need to send you to deliver a product or service you have purchased.
6. Who we share your personal data with
6.1 Service providers
We use third-party service providers who process personal data on our behalf, under written contracts that require them to protect it, use it only on our instructions, and delete or anonymise it when no longer needed. These include providers of:
- customer relationship management, marketing automation and analytics — HubSpot;
- email marketing — Campaign Monitor;
- subscription management and data hosting — Abacus Media Ltd (data hosted in the UK);
- event registration, networking and event technology — ExpoPlatform;
- website publishing and hosting — Metro Publisher (a service of Vanguardistas LLC) and Ghost;
- workplace productivity and email — Microsoft 365;
- website analytics — Google Analytics (data shared with Google in aggregated form; see our Cookie Policy);
- payment processing — our payment service providers, who process payment data under their own privacy policies (details available on request);
- event delivery services, such as registration and badging, stand design, show guide production and logistics.
6.2 At our events
If you attend one of our events, your personal data may be shared with:
- exhibitors — when you allow your visitor badge to be scanned at their stand, the exhibitor receives your contact and profile details and becomes an independent controller of that data;
- sponsors — when you register for or attend a session or feature that is sponsored, and this was made clear at the point of registration;
- other attendees and participants — where you choose to use a networking or meeting service we provide.
We will always make it clear at the point of collection when your data will be shared in these ways.
6.3 Other disclosures
We may also share your personal data with:
- our insurers and professional advisers, where reasonably necessary to obtain or maintain insurance, manage risk, take advice, or establish, exercise or defend legal claims;
- a purchaser or prospective purchaser, if we sell, merge or reorganise our business or assets, in which case the new owner may use your personal data in the same way as set out in this policy;
- law enforcement, regulators, courts and other authorities, where we are under a legal duty to do so, or to enforce our terms or protect the rights, property or safety of our business, our customers or others.
7. International transfers
Some of our service providers are based outside the UK, or store data outside the UK, so using them can involve transferring your personal data internationally — including to the United States.
Whenever we transfer your personal data outside the UK, we ensure it receives an equivalent level of protection by making sure at least one of the following safeguards applies:
- the destination country is covered by UK adequacy regulations (which include the EEA and, for certified organisations, the UK Extension to the EU-US Data Privacy Framework — the "UK-US Data Bridge");
- we have entered into the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, with the recipient;
- another valid transfer mechanism or exemption under UK GDPR applies.
Please contact us if you would like further information on the specific mechanism used for any particular transfer.
8. Security
We have put in place appropriate technical and organisational measures to protect your personal data from being accidentally lost, or used, accessed, altered or disclosed in an unauthorised way. We limit access to your personal data to those employees, agents, contractors and service providers who have a genuine business need to know it; they process it only on our instructions and are subject to a duty of confidentiality.
We have procedures in place to deal with any suspected personal data breach, and we will notify you and the ICO of a breach where we are legally required to do so.
Please note that no transmission of information over the internet can be guaranteed to be completely secure, so any transmission to our websites is at your own risk. Once we have received your information, we apply the measures described above to protect it.
9. How long we keep your personal data
We keep your personal data for no longer than necessary for the purposes for which it was collected, taking into account our legal, accounting, tax and reporting obligations, the nature and sensitivity of the data, and the risk of harm from unauthorised use or disclosure. In summary:
- Contractual and transaction records are kept for six years after the end of the contractual relationship, for tax and legal purposes;
- Marketing data is kept while you remain subscribed. If you have not engaged with any of our communications, events or content for three years, we will remove you from our marketing lists and suppress or anonymise your record;
- Event attendee data is kept for five years to administer the event cycle and, where permitted, invite you to future editions;
- Special category data (dietary and accessibility requirements) is deleted after the relevant event;
- Suppression records (minimal data used to honour opt-outs) are kept indefinitely, as this is necessary to respect your marketing preferences.
Data that has been fully anonymised is no longer personal data and may be retained and used indefinitely.
10. Your rights
Under UK GDPR you have the following rights in relation to your personal data:
- Access — to request a copy of the personal data we hold about you (a "subject access request");
- Rectification — to have inaccurate or incomplete data corrected;
- Erasure — to ask us to delete your personal data where there is no good reason for us to continue processing it. We may not always be able to comply for specific legal reasons, which we will explain to you at the time;
- Objection — to object to processing based on legitimate interests, where your particular situation gives you grounds to do so, and to object at any time and without giving reasons to processing for direct marketing, which we will always honour;
- Restriction — to ask us to suspend processing while a dispute about accuracy, lawfulness or grounds is resolved;
- Portability — to receive the personal data you provided to us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
- Withdrawal of consent — to withdraw consent at any time where consent is our lawful basis, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us using the details in section 2. You will not normally have to pay a fee, though we may charge a reasonable fee, or refuse a request, if it is manifestly unfounded, repetitive or excessive. We may need to verify your identity before acting on a request — this is a security measure to make sure personal data is not disclosed to someone who has no right to receive it. We respond to all legitimate requests within one month; if your request is particularly complex or you have made several requests, we will let you know if we need longer and keep you updated.
Right to complain: you have the right to lodge a complaint at any time with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection (ico.org.uk / 0303 123 1113). We would appreciate the chance to address your concerns before you approach the ICO, so please consider contacting us first.
11. Cookies
Our websites use cookies and similar technologies. Strictly necessary cookies are set automatically because the sites cannot function without them. All other cookies — including analytics and advertising cookies — are set only if you consent through the cookie banner displayed when you first visit, and you can change your preferences at any time through the cookie settings on the site.
Full details of the cookies we use, what they do, how long they last and how to manage them are set out in our Cookie Policy.
12. Changes to this policy
We keep this policy under regular review and will publish any updated version on this page, with the "last updated" date revised accordingly. If we make material changes to how we use your personal data, we will take additional steps to bring them to your attention, for example by emailing you or displaying a prominent notice on our websites.
13. Questions and comments
If you have any questions about this policy, the personal data we hold about you, or how we use it, or if you wish to exercise any of your rights, please contact our data privacy manager using the details in section 2. We are happy to help.
