GETC2027
  • About
    • Tickets
    • Schedule
    • FAQ
    • Awards
    • Apply for GETC Awards
    • Visit / Practical
    • Exhibition
    • Become an Exhibitor
    • Become a Speaker
    • Apply to Speak
    • Partners
    • Become a Partner
    • Media Accreditation
    • Apply for Media Accreditation
    • Investor Access
    • Apply for Investor Access
    • Government & Institutional
    • Government & Institutional Contact
  • Contacts
Get your ticket
  • About
  • Attend
    • Tickets
    • Schedule
    • FAQ
    • Awards
    • Apply for GETC Awards
    • Visit / Practical
  • Exhibit
    • Exhibition
    • Become an Exhibitor
  • Speak
    • Become a Speaker
    • Apply to Speak
  • Partners
    • Partners
    • Become a Partner
    • Media Accreditation
    • Apply for Media Accreditation
  • Access
    • Investor Access
    • Apply for Investor Access
    • Government & Institutional
    • Government & Institutional Contact
  • Contacts
Get your ticket
LEGAL

Privacy & Cookie Policy

GETC 2027 — PRIVACY & COOKIE POLICY

Working draft for external legal review — not for publication in this form Applies to: GETC 2027 website (getc2027.eu) and the GETC 2027 participant app Version 0.3 (working draft) This document has three parts: Part I is the Privacy Policy, covering personal-data processing generally; Part II is the Cookie Policy, covering website cookies and the app's comparable local-storage/SDK technologies; Part III is the Media, Photography & Recording Notice, covering image and video use.

GDPR & DATA PROTECTION AT A GLANCE

This is the main data-protection document for the whole GETC 2027 ecosystem (website and app together) and is drafted with reference to Regulation (EU) 2016/679 (the "GDPR") and Spanish Organic Law 3/2018 (LOPDGDD). Cookie consent on the website is additionally governed by Spanish Law 34/2002 (LSSI-CE), Art. 22.2, which implements the EU ePrivacy rules (see Part II). A photograph, audio recording, or video that identifies a person is also personal data under the GDPR, and separately engages Spanish Organic Law 1/1982 on the right to one's own image (see Part III). Shorter, layered notices appear at the point of collection (e.g. the Application & Accreditation Notice in Article 10 and the checkout notice referenced in the Terms & Conditions); this Policy is the full reference document those notices point back to, in line with the transparency obligations of Articles 13 and 14 GDPR.

PART I — PRIVACY POLICY

ARTICLE 1 — WHO THIS POLICY APPLIES TO AND HOW IT IS STRUCTURED

This Policy applies to any individual whose personal data is processed through the GETC 2027 website, the GETC 2027 participant app, an application/accreditation form, or in connection with attendance at the Congress. Part I is organised as follows: Articles 2–7 describe what data is processed, why, and on what basis; Articles 8–9 address special categories of data and layered/point-of-collection notices; Article 10 addresses your rights; Articles 11–15 address specific topics (profile visibility, minors, security, retention, international transfers); Articles 16–18 contain general provisions. Part II (cookies) and Part III (media/photography) follow with their own numbered articles.

ARTICLE 2 — DATA CONTROLLER AND CONTACT DETAILS

[LEGAL ENTITY] · [registered address] · [privacy e-mail] · [Data Protection Officer contact, if one is appointed under Art. 37 GDPR, or a statement that no DPO is required and who to contact instead] is the controller for personal data collected through the website and the participant app, acting as a single controller across both surfaces.

ARTICLE 3 — CATEGORIES OF PERSONAL DATA

3.1 Identification and contact data: name, e-mail address, phone number, country, postal address where relevant. 3.2 Professional and organisation data: job title, employer, sector, area of expertise. 3.3 Ticket and payment-related records: order details, invoice data; payment-card data itself is processed by the payment provider and is not stored by GETC (see Article 6). 3.4 Account, QR-badge and check-in/scan data: account credentials, the Credential itself, and logs of when and where it was scanned at the venue. 3.5 Networking, meeting-request and messaging activity: data generated through the app's matchmaking, meeting-request, and Deal Room features. 3.6 Agenda selections and session bookmarks: data reflecting a Participant's chosen or bookmarked sessions. 3.7 Application / accreditation data: data submitted through the Speaker, Media, Exhibitor, Partner, Investor, Government, or Group forms. 3.8 Technical and device data: IP address, browser/device type, app diagnostics and crash logs, and push-notification tokens. 3.9 Consent records: records of cookie consent, marketing consent, and accreditation-related consent, with timestamp and version of the relevant notice. 3.10 Event attendance data: session check-ins, exhibition-area visits, and similar attendance analytics. 3.11 Photography / video: images and recordings in which a Participant may appear, as described in Part III (Media, Photography & Recording Notice) below. 3.12 Support communications: records of correspondence with GETC's support channels. 3.13 Special category data: where relevant to an accessibility request, data revealing health or disability status — see Article 9.

ARTICLE 4 — PURPOSES OF PROCESSING

Personal data is processed for: event registration and delivery; ticket fulfilment; access control at the venue via the app Credential; participant support; networking and matchmaking; speaker, exhibitor, partner, media, investor, government and university workflows; security and fraud prevention; legal and accounting obligations; event communications by e-mail or in-app notification; analytics on website and app usage, including to improve the Congress and future editions; and optional marketing where permitted (see Article 11).

ARTICLE 5 — LAWFUL BASES FOR PROCESSING (ARTICLE 6 GDPR)

5.1 Contract performance (Art. 6(1)(b)) — where processing is necessary to provide purchased or requested event services, including the app account and Credential, ticket fulfilment, and accreditation review. 5.2 Legal obligation (Art. 6(1)(c)) — for example, accounting, tax, and other statutory record-keeping. 5.3 Legitimate interests (Art. 6(1)(f)) — where appropriate and balanced against the individual's rights and reasonable expectations, for example venue security, fraud prevention, and general event analytics. Where GETC relies on this basis, it will be able to explain the balancing test applied on request. 5.4 Consent (Art. 6(1)(a)) — where required, including certain marketing communications, non-essential cookies and app tracking technologies (see Part II — Cookie Policy below), push notifications, optional profile-visibility features, and processing of special category data under Article 9. Consent can be withdrawn at any time, free of charge, without affecting the lawfulness of processing carried out before withdrawal.

ARTICLE 6 — RECIPIENTS AND PROCESSORS

Personal data may be shared, under a written data-processing agreement consistent with Article 28 GDPR, with categories of recipients including: event-tech providers (including the app and matchmaking platform); payment providers; CRM and e-mail platforms; venue, security, and check-in providers; badge and registration vendors; hosting and IT suppliers; and professional advisers, in each case only to the extent required for the relevant service. GETC will maintain a record of its processors and will make the categories of processor, though not necessarily every individual sub-processor, available on request.

ARTICLE 7 — INTERNATIONAL TRANSFERS

Where personal data is transferred outside the European Economic Area — including through the app's hosting or analytics providers — the transfer will rely on an adequacy decision under Art. 45 GDPR, Standard Contractual Clauses adopted by the European Commission under Art. 46 GDPR, or another transfer mechanism recognised under Chapter V GDPR. The final Policy will name the specific mechanism used per relevant recipient, and a copy of the relevant safeguard can be requested from [privacy e-mail].

ARTICLE 8 — RETENTION

8.1 Personal data is kept only for as long as necessary for the purpose for which it was collected, or as required by applicable law. Indicative retention periods, to be finalised before launch, are: (a) Account and app-Credential data: for the duration of the account, plus a limited post-event period to handle queries and disputes, after which it is deleted or anonymised unless a longer period is required by law. (b) Ticket and payment records: for the statutory accounting/tax retention period applicable in Spain. (c) Application/accreditation records: for the duration of the review process, plus a limited operational retention period to support future editions of the Congress, unless the applicant requests earlier deletion and no legal ground requires retention. (d) Marketing consents and related records: until consent is withdrawn, plus a limited period to evidence the withdrawal. (e) Security and access-scan records: for a limited, defined period after the Congress, proportionate to security and incident- investigation needs. (f) Special category data collected for an accessibility request: only for as long as necessary to arrange the accommodation, after which it is deleted. 8.2 The final Policy will publish these periods as concrete durations (for example, "24 months from the end of the Congress"), not as vague placeholders, once Legal and the relevant operational teams confirm them.

ARTICLE 9 — SPECIAL CATEGORY DATA (ARTICLE 9 GDPR)

Where a Participant discloses data revealing health or disability status in connection with an accessibility request, that data is processed only for the purpose of accommodating the request, on the basis of explicit consent (Art. 9(2)(a)) or another applicable Art. 9(2) condition, is accessible only to the personnel who need it to arrange the accommodation, and is retained only as long as necessary for that purpose (see Article 8.1(f)). See also the Accessibility / Code of Conduct document.

ARTICLE 10 — APPLICATION & ACCREDITATION NOTICE, AND MARKETING CONSENT

10.1 Layered notice. Speaker, Media, Exhibitor, Partner, Investor, Government, and Group forms display a short notice at submission covering: the controller; the purpose (reviewing and managing the application and related communications); the lawful basis (steps taken at the applicant's request, legitimate interests, or consent, depending on the workflow); recipients; retention; applicable rights; and a link back to this Policy, consistent with Article 13 GDPR. 10.2 Marketing consent. Transactional e-mails (ticket confirmation, accreditation updates, operational and security notices) are sent as part of service delivery and are not "marketing." Optional marketing communications rely on consent or, where legally permitted under Spanish LSSI-CE rules for an existing customer relationship, a "soft opt-in" limited to similar products/services with a clear opt-out offered at collection and in every message. Marketing consent is never enabled by a pre-ticked box, and every marketing e-mail carries a simple, free unsubscribe mechanism. Proof of consent (or of the soft-opt-in conditions being met) is retained where relied upon.

ARTICLE 11 — YOUR RIGHTS

Subject to the conditions set out in the GDPR, you may exercise the following rights by contacting [privacy e-mail]; GETC will respond within one month of a verified request, extendable by two further months for complex requests, as permitted under Art. 12(3) GDPR: 11.1 Right of access (Art. 15) — obtain confirmation of, and access to, your personal data and the information listed in Art. 15(1). 11.2 Right to rectification (Art. 16) — correct inaccurate or incomplete data. 11.3 Right to erasure (Art. 17) — request deletion, subject to legal retention obligations and the other grounds in Art. 17(3). 11.4 Right to restriction of processing (Art. 18), in the circumstances listed in that Article. 11.5 Right to data portability (Art. 20), where processing is based on consent or contract and carried out by automated means. 11.6 Right to object (Art. 21), in particular to processing based on legitimate interests or to direct marketing, in which case marketing processing will stop. 11.7 Rights related to automated decision-making (Art. 22) — GETC does not currently use automated decision-making producing legal or similarly significant effects on individuals; if this changes, this Policy will be updated accordingly. 11.8 Right to withdraw consent at any time, where consent is the legal basis, without affecting the lawfulness of processing before withdrawal. 11.9 Right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD), C/ Jorge Juan, 6, 28001 Madrid, www.aepd.es, or with the supervisory authority of your habitual residence or place of the alleged infringement. 11.10 Identity verification. GETC may request reasonable additional information to verify the identity of a person exercising a right under this Article, to protect against fraudulent requests.

ARTICLE 12 — PROFILE VISIBILITY AND NETWORKING

Participant-directory visibility and networking functions in the app use privacy settings and role-based permissions. Protected profiles (e.g. investor, government) can control contact availability where the platform supports it. The final Terms will define whether Participants may export or download other Participants' data, and will restrict that ability to prevent unauthorised scraping, consistent with Article 12.2 of the Terms & Conditions of Attendance.

ARTICLE 13 — CHILDREN / MINORS

GETC is primarily a professional event and is not designed for minors. If minors are permitted to register or participate in any specific programme, on the website or in the app, a separate legal and operational review will define consent (including, where relevant, verifiable parental consent consistent with Art. 8 GDPR and Spanish LOPDGDD requirements), safeguarding, and data-processing rules before that programme opens.

ARTICLE 14 — SECURITY MEASURES AND BREACH NOTIFICATION

14.1 GETC applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or destruction, proportionate to the risk, including access controls, encryption in transit for the website and app, and contractual security obligations on processors. 14.2 In the event of a personal-data breach likely to result in a risk to individuals, GETC will notify the AEPD within 72 hours of becoming aware of it, as required by Art. 33 GDPR, and will communicate the breach to affected individuals without undue delay where it is likely to result in a high risk to their rights and freedoms, as required by Art. 34 GDPR.

ARTICLE 15 — RECORDS OF PROCESSING AND ACCOUNTABILITY

Consistent with the accountability principle in Art. 5(2) GDPR, GETC will maintain a record of processing activities under Art. 30 GDPR covering the processing described in this Policy, and will carry out a Data Protection Impact Assessment under Art. 35 GDPR for any processing identified as high-risk (for example, large-scale processing of special category data, or systematic monitoring of the venue).

ARTICLE 16 — RELATIONSHIP TO OTHER DOCUMENTS

This Policy is structured in three parts: Part I (this Privacy Policy), Part II (Cookie Policy, governing website cookies and the app's comparable local-storage/SDK technologies) and Part III (Media, Photography & Recording Notice, governing image and video use). It should also be read together with the Accessibility / Code of Conduct document (which governs special category data collected for accessibility requests).

ARTICLE 17 — CHANGES TO THIS POLICY

GETC may update this Policy to reflect changes in its processing activities or in applicable law. The version in force at the time of processing, identified by version number and date, applies, and material changes will be highlighted at the top of this document and, where required by law, separately notified.

ARTICLE 18 — GENERAL PROVISIONS

18.1 Severability. If a provision of this Policy is held invalid or unenforceable, that provision is severed and the remainder continues in full force and effect. 18.2 Language. This Policy is drafted in English; a Spanish version will be published and, in the event of a discrepancy, the version more favourable to the data subject under applicable law prevails. 18.3 Governing law. This Policy, and GETC's processing of personal data, is governed by the GDPR and by Spanish data-protection law (LOPDGDD), without prejudice to the competence of the AEPD and the Spanish courts, and to the equivalent competence of another Member State's authority or courts where applicable law so provides.

PART II — COOKIE POLICY

ARTICLE 19 — WHAT ARE COOKIES AND WHY THIS PART EXISTS

19.1 Cookies are small text files placed on a device when visiting a website, used to store or retrieve information about browsing behaviour, preferences, or identity for a defined period. 19.2 This Part explains what cookies and comparable technologies the GETC 2027 website and app use, why, on what legal basis, and how a User can control them, in compliance with LSSI-CE Art. 22.2 and the GDPR.

ARTICLE 20 — CATEGORIES OF WEBSITE COOKIES

20.1 Strictly necessary / technical cookies — required for the website to function (e.g. session management, load balancing, security, shopping-cart/checkout state, cookie-consent-choice storage itself). These may be set without consent where legally exempt under LSSI-CE Art. 22.2. 20.2 Preference cookies — remember non-essential choices such as language or display settings. 20.3 Analytics cookies — measure aggregated website usage to understand and improve the Congress website; used only with consent unless configured to operate in a fully anonymised, exempt mode. 20.4 Advertising / behavioural cookies — used, if at all, for retargeting or measuring the effectiveness of advertising campaigns; used only with consent. 20.5 Third-party embedded-content cookies — set by embedded content such as maps, videos, or social-media widgets, which may set their own cookies subject to the third party's own policy; used only with consent where non-essential.

ARTICLE 21 — PARTICIPANT APP EQUIVALENTS

21.1 The participant app does not use browser cookies. It may use comparable technologies instead: local device storage, device identifiers, push-notification tokens, and analytics or crash-reporting SDKs bundled into the app. 21.2 These technologies are disclosed here for transparency, and in more detail in the app's own in-app permissions and privacy-settings screen, and follow the same consent-before-tracking principle described in Article 22.1 for any technology that is not strictly necessary to run the app (e.g. analytics or push-notification SDKs, as opposed to the local storage needed to keep a User logged in).

ARTICLE 22 — CONSENT MANAGEMENT

22.1 Consent-first loading. Non-essential cookies and comparable app technologies — preference, analytics, and advertising/behavioural — are not loaded or activated before valid consent is given. 22.2 Equal prominence. The website's cookie banner presents "Accept" and "Reject" with equivalent visual prominence (same size, colour weight, and number of clicks), in line with AEPD guidance on cookie-consent interface design; a banner that makes rejection harder than acceptance does not constitute valid consent. 22.3 Granular control. Users can configure preferences by purpose and, where applicable, by individual vendor, through the consent-management platform ("CMP"), rather than being limited to an all-or-nothing choice. 22.4 Withdrawing consent. Consent can be withdrawn or changed at any time, as easily as it was given, via a persistent "Cookie Settings" control accessible from the website footer, without needing to contact GETC directly, and the app's equivalent settings screen for app-level technologies. 22.5 Consent expiry and re-prompting. Consent will be re-requested after a defined validity period (commonly no more than 12 months, to be confirmed) or when the set of cookies/technologies changes materially under Article 24. 22.6 Do-not-track and similar browser signals. The final Policy will state how, if at all, the website responds to a browser-level do-not-track or Global Privacy Control signal.

ARTICLE 23 — COOKIE TABLE

The final Policy will list, per cookie or comparable technology: name; category (per Article 20); purpose; provider (first-party or named third party); duration/retention period; and, for third-party cookies, a link to the provider's own policy — generated from an actual live cookie audit of the website and app, not from a generic template. A placeholder table structure is set out below for the audit to populate:

NameCategoryPurposeProviderDuration
[session cookie]Strictly necessaryMaintain login/checkout stateFirst-partySession
[consent cookie]Strictly necessaryStore cookie-consent choiceFirst-party12 months
[analytics cookie]AnalyticsAggregate usage statistics[Provider][Duration]
[advertising cookie, if used]Advertising[Purpose][Provider][Duration]

ARTICLE 24 — CHANGES TO COOKIES OR APP TRACKING TECHNOLOGIES

If the set of cookies or app tracking technologies changes materially (e.g. a new analytics or advertising vendor is added), this Part and the CMP configuration will be updated, and re-consent will be sought under Article 22.5, before the change takes effect; previously given consent is not assumed to cover the new use.

ARTICLE 25 — CONSENT RECORDS

Consent records — from the website's cookie banner and the app's permission prompts — are timestamped, linked to the version of this Part presented at the time, and stored in a way that allows GETC to demonstrate compliance with Articles 22 and 24 if requested by a supervisory authority.

ARTICLE 26 — GENERAL PROVISIONS

26.1 Severability. If a provision of this Part is held invalid or unenforceable, that provision is severed and the remainder continues in full force and effect. 26.2 Language. This Part is drafted in English; a Spanish version will be published and, for a Spanish User, the version more favourable to the User under applicable law prevails in the event of a discrepancy. 26.3 Governing law. This Part is governed by Spanish law, including LSSI-CE Art. 22.2, and by the GDPR to the extent cookies or app tracking technologies process personal data.

PART III — MEDIA, PHOTOGRAPHY & RECORDING NOTICE

ARTICLE 27 — PURPOSE AND SCOPE OF THIS NOTICE

27.1 This Part explains how photography, audio, and video recording are used at the Congress and through the Platform, and the rights an individual has in relation to their own image and voice. 27.2 It applies to all Participants, speakers, exhibitors, sponsors, accredited media, and other attendees at the Congress, and to any photography or recording carried out by or on behalf of GETC. 27.3 It does not apply to recordings made by a Participant on their own device for personal, non-commercial use, which are instead governed by Article 32 (participant-taken recordings) and by the venue's own house rules.

ARTICLE 28 — GENERAL EVENT RECORDING

Photography, audio and video recording may take place in public event areas throughout the Congress, for event coverage, documentation, communications and media purposes. Resulting material may be published on the website, on official social-media channels, and — where a session-recording or on-demand feature is offered — made available inside the app to registered Participants. This general coverage is carried out on the basis of GETC's legitimate interest in documenting and promoting a professional congress of this scale.

ARTICLE 29 — SIGNAGE AND ON-SITE NOTICE

Areas subject to general event recording will be marked with visible signage at venue entrances and within the relevant areas, informing attendees that recording is taking place, consistent with the transparency obligations of Art. 13 GDPR; the exact signage design and placement will be confirmed with the venue and with counsel before the Congress.

ARTICLE 30 — RESTRICTED AREAS

Closed meetings, protocol rooms, backstage areas and other restricted spaces may have separate rules and may prohibit recording entirely, regardless of the access role shown on a Participant's app Credential. Any recording permitted in such areas requires GETC's prior written authorisation.

ARTICLE 31 — CLOSE-UP, PROMOTIONAL AND INTERVIEW USE

Where an individual is filmed or photographed in a close-up, promotional, or interview format intended for dedicated use (rather than incidental inclusion in wide event-coverage shots), separate specific consent — distinct from the general legitimate-interest basis in Article 28 — will be sought before that specific material is used, ideally recorded through a simple release confirmation (in person, by e-mail, or in-app). That consent can be withdrawn for future use at any time by contacting [privacy e-mail], without affecting the lawfulness of use before withdrawal.

ARTICLE 32 — PARTICIPANT-TAKEN RECORDINGS

Participants may take photographs or videos on their own devices for personal use, subject to: (a) restricted-area rules under Article 30; (b) any specific "no recording" instruction given during a particular session (for example, at a speaker's request); and (c) the Code of Conduct's general prohibition on harassment, which includes non-consensual close-up filming of other attendees. Participant-taken recordings shared publicly remain the responsibility of the Participant who took them, and are not covered by this Notice as GETC content.

ARTICLE 33 — PARTICIPANT REQUESTS AND OBJECTIONS

Where operationally feasible and legally appropriate, Participants have a route — via the website contact page or the app's support/help section — to ask questions about photography/recording, to request that specific material not be used, or to exercise the right to object described above. GETC will acknowledge such a request within a reasonable time and will take reasonable steps to stop future use of the specific material identified, without an obligation to recall material already lawfully distributed to third parties before the request.

ARTICLE 34 — SPEAKER RECORDING PERMISSIONS

Speaker agreements separately address recording, streaming, reuse of presentations, on-demand availability in the app, and use of the speaker's name and image, and take precedence over this general Notice for speaker-specific content. Absent a broader grant in that agreement, GETC does not assume the right to distribute a speaker's slides or presentation materials beyond the recorded session itself.

ARTICLE 35 — ACCREDITED MEDIA

35.1 Accredited media remain subject to venue, security, privacy and restricted-area rules, whether operating on-site or coordinating through the app, and are separately bound by their own media accreditation terms. 35.2 Accredited media are responsible for their own compliance with applicable image-rights and data-protection law in respect of the footage and photographs they capture and publish independently of GETC's own official coverage.

ARTICLE 36 — MINORS

If a minor is present at the Congress (e.g. as part of an approved programme), additional safeguards apply to any recording involving that minor: the lawful basis will not rely on legitimate interest alone, and verifiable parental or guardian consent will be obtained before any dedicated (as opposed to incidental, wide-shot) use of the minor's image; see also Article 13 above.

ARTICLE 37 — RETENTION AND DISTRIBUTION

Event photography and video are retained for the period needed for event documentation, archival, and promotional reuse in future editions of GETC, to be defined as a concrete retention period before publication, and may be distributed internationally through the website and social channels; where this involves a transfer outside the EEA, the safeguards described in Article 7 above apply.

ARTICLE 38 — GENERAL PROVISIONS

38.1 Severability. If a provision of this Notice is held invalid or unenforceable, that provision is severed and the remainder continues in full force and effect. 38.2 Language. This Notice is drafted in English; a Spanish version will be published and, in the event of a discrepancy, the version more favourable to the data subject under applicable law prevails. 38.3 Governing law. This Notice is governed by Spanish law, including Organic Law 1/1982 on the right to one's own image, and by the GDPR to the extent it involves personal data.

LEGAL REVIEW NOTE

Insert the actual controller identity, DPO contact (or confirmation that no DPO is required under Art. 37 GDPR), and the specific international- transfer mechanism per recipient once Legal confirms them, and make sure the data map in Article 3 and the retention schedule in Article 8 match what the app and website actually collect and retain — not a generic template. The Records of Processing Activities and any required DPIA referenced in Article 15 should be commissioned in parallel with this Policy, not treated as a purely internal afterthought. The AEPD has expressly required that accepting and rejecting cookies be offered at the same level of prominence — the exact CMP configuration must be tested on the live website before launch, not merely described in Part II. The cookie table in Article 23 must be generated from a live cookie audit before publication, and the consent-expiry period in Article 22.5 and the do-not-track position in Article 22.6 need a final operational decision. The final lawful basis and notice design for event photography/video in Part III must be reviewed by counsel, especially for close-up/promotional use, interviews, any recordings involving minors, and any recordings surfaced back to attendees inside the app. The practical mechanism for Article 33 (an objection or opt-out route that actually reaches the photography/media team in time) and the exact signage design in Article 29 need to be operationally defined before publication.

Source: GETC 2027 Legal Pages Master v1, sections 7, 8, 9, 10 and 11. Part I expanded using standard GDPR Article 13/14 transparency-notice drafting practice: the full lawful-basis breakdown, the complete data-subject-rights list with response timeframes, breach-notification and accountability provisions (Art. 30/33/34/35 GDPR), and a full general-provisions block. Part II expanded using standard EU/Spanish cookie-compliance drafting practice: a full cookie-category breakdown, a placeholder cookie table structured for a live audit, consent-expiry and re-prompting rules, and a description of the app's non-cookie equivalents. Part III expanded using standard event-photography-notice drafting practice: the GDPR lawful-basis distinction between general coverage and close-up/promotional use, the separate Spanish image-rights framework (Organic Law 1/1982), signage and participant-taken-recording provisions, and a minors and retention/distribution statement. Wording continues to explicitly cover both the website and the participant app as one Platform. Final sign-off from Spanish counsel is still required before publication.

GETC2027

Global Energy Transition Congress
9-10 April 2027
Valencia, Spain

EXPLORE

  • About GETC

  • Programme

  • Exhibition

  • Awards

PARTICIPATE

  • Tickets

  • Become an Exhibitor

  • Become a Partner

  • Become a Speaker

  • Media Accreditation

  • Investor Access

  • Government & Institutional

GETC

  • FAQ

  • Contacts

  • Visit / Practical Information

LEGAL

  • Legal Notice

  • Terms & Conditions

  • Privacy & Cookie Policy

  • Accessibility / Code of Conduct

  • GETC Awards Rules & Eligibility