1. Purpose of this Policy
2. Who are we and what do we do
The Vistage EMEA Summit website is being managed by Vistage Malta. Vistage Malta is the data controller responsible for your personal information processed via the Site.
3. How to contact us
sending an email to firstname.lastname@example.org
calling us on +356 [insert contact number]
4. What personal information do we collect ?
We may collect personal information from you in the course of our business, including through your use of our Site, when you contact or request information from us, when you engage our booking forms or as a result of your relationship with one or more of our staff counterparts in your country.
Our primary goal in collecting personal information from you is to help us:
· verify your identity
· deliver our Services
· improve, develop and market new Services
· carry out requests made by you on the Site or in relation to our Services
· investigate or settle inquiries or disputes
· comply with any applicable law, court order, other judicial process, or the requirements of a regulator
· enforce our agreements with you
· protect the rights, property or safety of us or third parties, including our other clients and users of the Site or our Services
· use as otherwise required or permitted by law.
To undertake these goals we may process the following personal information:
If you are a visitor to the Site:
· Name and Surname
· Contact information including the company you work for, email address and social media account where appropriate
· Demographic information such as your address, preferences and interests.
· Other information relevant to the provision of Services.
5. How do we use your personal information ?
We may use your personal information for the following purposes:
Fulfilment of Services
We collect and maintain personal information that you voluntarily submit to us during your use of the Site and/or our Services to enable us to perform the Services.
What is our legal basis?
It is necessary for us to process your information to perform our obligations in accordance with any booking order or contract that we may have with you . It is in our legitimate interest or a third party’s legitimate interest to use your personal information in such a way to ensure that we provide the very best client service we can to you or others.
Our Site uses various user interfaces to allow you to request information about our Services including electronic enquiry forms and a telephone enquiry service. Contact information may be requested in each case, together with details of other personal information that is relevant to your Service enquiry. This information is used in order to enable us to respond to your requests.
What is our legal basis?
It is in our legitimate interest or a third party’s legitimate interest to use your personal information in such a way to ensure that we provide the very best client service we can to you or others.
Business administration and legal compliance
We use your personal information for the following business administration and legal compliance purposes:
to comply with our legal obligations;
to enforce our legal rights;
to protect the rights of legitimate third parties; and
in connection with a business transaction such as a payment.
What is our legal basis?
Where we use your personal information in connection with a business transition, to enforce our legal rights, or to protect the rights of third parties it is in our or a third party’s legitimate interest to do so. For all other purposes described in this section, it is our legal obligation to use your personal information to comply with any legal obligations imposed upon us.
We use information that we observe about you from your interactions with our Site, our email communications to you and/or with Services (see the Client Insight and Analysis section below for more details of the information collected and how it is collected) to send you marketing communications.
What is our legal basis?
It is in our legitimate interest to use your personal information for marketing purposes. We will only send you marketing communications where you have consented to receive such marketing communications, or where we have a lawful right to do so.
Client insight and analysis
We analyse your contact details with other personal information that we observe about you from your interactions with our Site, our email communications to you and/or with our Services such as the Services you have viewed.
an IP address to monitor Site traffic and volume;
a session ID to track usage statistics on our Site;
any information regarding your experiences and contact preferences.
By using this information, we are able to measure the effectiveness of our content and how visitors use our Site and our Services. This allows us to learn what pages of our Site are most attractive to our visitors, which parts of our Site are the most interesting and what kind of offers our registered users like to see. We also use this information for marketing purposes (see the marketing section above for further details).
What is our legal basis?
Where your personal information is not in an anonymous form, it is in our legitimate interest to use your personal information in such a way to ensure that we provide the very best products and services to you and our other clients. Any other purposes for which we wish to use your personal information that are not listed above, or any other changes we propose to make to the existing purposes will be notified to you using your contact details, where available.
6. What is our legal basis to use or process your personal information?
It is necessary for us to use your personal information:
· To perform our obligations in accordance with any booking order or contract that we may have with you.
· It is in our legitimate interest or a third party’s legitimate interest to use personal information in such a way to ensure that we provide the Services in the best way that we can.
· It is our legal obligation to use your personal information to comply with any legal obligations imposed upon us.
7. Who do we share your personal information with ?
Vistage Malta may share any information that we collect or that you provide to us with some third party entities’ employees, to the extent covered by the agreement between us and them.
We may share personal information with a variety of the following categories of third parties as necessary:
· Our professional advisers such as lawyers and accountants.
· Government or regulatory authorities.
· Third parties to whom we outsource certain services such as, without limitation, printing and processing, IT systems or software providers, IT Support service providers, document and information storage providers.
· Third parties engaged in the course of the services we provide to clients.
· Third party service providers to assist us with client insight analytics, such as Google Analytics.
· Third party e-mail providers who assist us in delivering our e-mail marketing campaigns to you, or delivering documents relate d to a matter.
· Please note this list is non-exhaustive and there may be other examples where we need to share with other parties in order to provide the Services as effectively as we can.
8. Third party contractors and other controllers
As mentioned above, we may appoint sub-contractor data processors as required to deliver the Services, such as, without limitation, document processing and, IT systems or software providers, IT Support service providers, document and information storage providers, who will process personal information on our behalf and at our direction. We conduct an appropriate level of due diligence and put in place contractual documentation in relation to any sub-contractor to ensure that they process personal information appropriately and according to our legal and regulatory obligations.
What is the legal basis?
It is necessary for us to perform our obligations in accordance with any contract that we may have with you. It is in our legitimate interest or a third party’s legitimate interest to use personal information in such a way to ensure that we provide the Services in the best way that we can.
9. Where do we transfer your data?
In order to provide the Services we may need to transfer your personal information to locations outside the jurisdiction in which you provide it. If you are based within the European Economic Area (EEA), please note that where necessary to deliver the Services we will transfer personal information to countries only within the EEA.
10. How long do we keep your personal information for?
For visitors to the Site, we will retain relevant personal information for at least one year1 from the date of our last interaction with you and in compliance with our obligations under the EU General Data Protection Regulation or similar legislation around the world, or for longer if we are required to do so according to our regulatory obligations or professional indemnity obligations.
For Service provision to any client, we will retain relevant personal information for at least six years from the date of our last interaction with that client and in compliance with our obligations under the EU General Data Protection Regulation or similar legislation around the world, or for longer as we are required to do so according to our regulatory obligations or professional indemnity obligations. We may then destroy such files without further notice or liability.
If personal information is only useful for a short period e.g. for specific marketing campaigns we may delete it.
11. Confidentiality and security of your personal information
We are committed to keeping the personal information provided to us secure and we have implemented appropriate information security policies, rules and technical measures to protect the personal information that we have under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss.
All of our partners, employees, consultants, workers and data processors (i.e. those who process your personal information on our behalf, for the purposes listed above), who have access to, and are associated with the processing of personal information, are obliged to respect the confidentiality of such personal information.
12. How to access your information and your other rights ?
You have the following rights in relation to the personal information we hold about you:
· Your right of access
If you ask us, we’ll confirm whether we’re processing your personal information and, if necessary, provide you with a copy of that personal information (along with certain other details). If you require additional copies, we may need to charge a reasonable fee.
· Your right to rectification
If the personal information we hold about you is inaccurate or incomplete, you are entitled to request to have it rectified. If you are entitled to rectification and if we’ve shared your personal information with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we’ll also tell you who we’ve shared your personal information with so that you can contact them directly.
· Your right to erasure
You can ask us to delete or remove your personal information in some circumstances such as where we no longer need it or if you withdraw your consent (where applicable). If you are entitled to erasure and if we’ve shared your personal information with others, we’ll let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal information with so that you can contact them directly.
· Your right to restrict processing
You can ask us to ‘block’ or suppress the processing of your personal information in certain circumstances, such as where you contest the accuracy of that personal information or you object to us. If you are entitled to restriction and if we’ve shared your personal information with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal information with so that you can contact them directly.
· Your right to data portability
You have the right, in certain circumstances, to obtain personal information you’ve provided us with (in a structured, commonly used and machine readable format) and to reuse it elsewhere or to ask us to transfer this to a third party of your choice.
· Your right to object
You can ask us to stop processing your personal information, and we will do so, if we are:
o relying on our own or someone else’s legitimate interests to process your personal information, except if we can demonstrate compelling legal grounds for the processing; or
o processing your personal information for direct marketing purposes.
· Your right to withdraw consent
If we rely on your consent (or explicit consent) as our legal basis for processing your personal information, you have the right to withdraw that consent at any time.
· Your right to lodge a complaint with the supervisory authority
If you have a concern about any aspect of our privacy practices, including the way we’ve handled your personal information, you can report it to the relevant Supervisory Authority.
Please note that some of these rights may be limited where we have an overriding interest or legal obligation to continue to process the data or where data may be exempt from disclosure due to reasons of legal professional privilege or professional secrecy obligations.
13. Collection of information by third-party sites and sponsors
The Site contains links to other sites whose information practices may be different than ours. Visitors should consult the other sites’ privacy notices as Vistage Malta has no control over information that is submitted to, or collected by, these third parties.
© Vistage Malta, July 2022.