Privacy Policy

1. Who We Are

This website is operated by S.G. Worldwide Media Company Ltd, a company incorporated and registered in the Republic of Cyprus under registration number HE 415670 (hereinafter referred to as the “Company”, “Controller”, “we”, “our”, or “us”).

For the purposes of Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”) and any other applicable data protection legislation, the Company acts as the controller of the personal data collected through this website, our digital platforms, including SiGMA Match, and our products, services and events.

The Company has appointed a Data Protection Officer (“DPO”), who may be contacted regarding any questions concerning this Privacy Policy, our processing of personal data or the exercise of your rights.

Email: [email protected] 

We are committed to processing personal data lawfully, fairly and transparently, while ensuring that such processing complies with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability as required under Article 5 of the GDPR. 

2. Scope of This Policy

This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you interact with our website, register for events, use our networking platforms, purchase products or services, subscribe to communications or otherwise engage with us in a professional capacity.

This Privacy Policy applies to this website and, where expressly indicated, to affiliated websites, applications and digital platforms operated within the SiGMA Group that refer to or incorporate this Privacy Policy. 

3. Categories and Sources of Personal Data

The categories of personal data we process depend on the nature of your interaction with us. 

In the context of event registration, networking platforms, service provision or commercial engagement, we may process identification and professional information such as your name, job title, company affiliation and nationality, as well as contact details including business email address and telephone number. Where required for invoicing, ticketing, regulatory compliance or event administration, additional data such as VAT details, billing information or identification documentation may be processed where legally necessary. 

In certain instances, we may also request copies of passports. Such requests may be made where required by the authorities of the jurisdiction in which we are holding our event. Where applicable, such personal data is processed on the basis of our legitimate interests, including compliance with legal and regulatory requirements, event security, and the effective organisation and delivery of our events. 

When you use our websites, certain technical data may be processed automatically, including IP address, browser type, device information, operating system, access timestamps and referring URLs. Such processing supports the security, functionality and stability of our services. 

Where you attend our events, photographs and video recordings may be captured for documentation, promotional, security and archival purposes. Such processing is carried out on the basis of our legitimate interests, provided that these interests do not override the rights and freedoms of individuals. 

Personal data is generally collected directly from you. In certain circumstances, personal data may also be obtained from authorised business partners, event organisers, payment providers or publicly available professional sources where such collection is lawful and necessary. 

We process only personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. 

Information that you choose to include in your SiGMA Match profile may be visible to other authorised users of the platform for the purpose of facilitating professional networking before, during and after SiGMA events. 

Event Media 

When attending our events, photographs, audio recordings and video recordings may be captured for promotional, documentary, security, media, historical and archival purposes. 

Such content may be used on our websites, digital platforms, social media channels, printed publications, promotional materials and other media relating to the Company’s business and events. 

Information Obtained from Other Sources 

Although personal data is generally collected directly from you, we may also receive personal data from third parties where permitted by applicable law and where necessary for the provision of our services, the organisation of our events or the operation of our business. 

In all cases, we process only personal data that is adequate, relevant and limited to what is necessary for the purposes for which it is processed. 

4. How Personal Data Is Collected

Personal data is collected when you complete forms, register for events, create accounts, subscribe to communications, make purchases, contact us or otherwise communicate with us. 

Certain information is collected automatically through cookies and similar technologies when you browse our website. Further information regarding cookies is provided in our Cookie Policy. 

We process personal data only where a lawful basis exists under Article 6 of the GDPR. 

Depending on the circumstances, we process personal data for purposes including: 

Performance of a Contract 

We process personal data where necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract. 

This includes processing necessary to: 

Compliance with Legal Obligations 

We process personal data where necessary to comply with legal and regulatory obligations, including obligations relating to taxation, accounting, fraud prevention, health and safety, regulatory compliance, security requirements and requests from competent authorities. 

Legitimate Interests 

Where appropriate, we process personal data on the basis of our legitimate interests, provided such interests are not overridden by your rights and freedoms. 

Our legitimate interests include: 

Before relying on legitimate interests, we assess whether our interests are balanced against your rights and freedoms. 

Consent 

Where required by applicable law, we will rely on your consent to process personal data. 

Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out prior to its withdrawal. 

6. Marketing Communications 

We may send you communications relating to our events, products, services, industry news, promotional offers and other information that may be of interest to you. 

Where required by applicable law, such communications will be sent only where you have provided your consent. 

Where permitted by applicable law, we may also send marketing communications on the basis of our legitimate interests, particularly where you have an existing business relationship with us or have previously engaged with our products or services. 

You may withdraw your consent or object to receiving marketing communications at any time by: 

Unsubscribing from marketing communications will not affect the delivery of administrative, transactional or service-related communications that are necessary for the performance of our contractual obligations or the operation of our services. 

7. SiGMA Match 

SiGMA Match is the Company’s professional networking platform designed to facilitate business connections and enhance the experience of attendees participating in SiGMA events. 

Access to SiGMA Match is generally available to registered attendees of eligible SiGMA events. Users access the platform using the email address associated with their event registration and may create a professional profile to participate in networking activities. 

Through SiGMA Match, users may: 

The information you choose to include in your profile may be visible to other authorised users of SiGMA Match for the purpose of facilitating professional networking and business engagement. 

You are responsible for ensuring that the information you choose to include in your profile is accurate, appropriate and suitable for sharing with other authorised users of the platform. 

We encourage users not to include unnecessary personal information or any special categories of personal data within their profiles or communications unless strictly necessary. 

The Company is not responsible for the subsequent use of information that you voluntarily choose to share with other users through the networking platform. 

8. Cookies and Similar Technologies  

Our websites and digital platforms use cookies and similar technologies to ensure their proper operation, improve functionality, enhance user experience, analyse website usage and, where applicable, support marketing activities. 

Some cookies are strictly necessary for the operation of our websites and cannot be disabled. Other cookies are used only where permitted under applicable law and, where required, are placed only with your consent. 

Further information regarding the cookies we use, the purposes for which they are used and the choices available to you can be found in our Cookie Policy. 

9. Automated Decision-Making  

The Company does not carry out automated decision-making or profiling that produces legal effects or similarly significant effects concerning individuals within the meaning of Article 22 of the GDPR. 

10. Disclosure of Personal Data  

We may disclose personal data where necessary for the purposes described in this Privacy Policy. 

Personal data may be shared within the SiGMA Group where necessary for administrative, operational, commercial, customer support, event management or other legitimate business purposes. 

We may also disclose personal data to third parties that provide services on our behalf. Such parties process personal data only under our documented instructions and are required to implement appropriate technical and organisational measures to protect personal data and comply with applicable data protection legislation. 

Where you use SiGMA Match, certain profile information and networking information that you choose to make available may be visible to other authorised users of the platform for the purpose of facilitating professional networking during SiGMA events. 

Personal data may also be disclosed where required by law, regulation, court order or the request of a competent public authority. 

We may disclose personal data where necessary to establish, exercise or defend legal claims or otherwise protect our legal rights, property, employees, customers or business operations. 

Where all or part of our business is subject to a merger, acquisition, restructuring, investment, financing or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality obligations and applicable legal requirements. 

We do not sell personal data to third parties. 

11. International Transfers  

Given the international nature of our business and events, personal data may be transferred to, accessed from or processed in countries outside the European Union (“EU”) and European Economic Area (“EEA”). 

Where personal data is transferred outside the EU or/and the EEA, we ensure that such transfers are carried out in accordance with Chapter V of the GDPR. 

Where required, appropriate safeguards are implemented to ensure that personal data continues to receive an adequate level of protection. These safeguards may include adequacy decisions adopted by the European Commission or other legally recognised transfer mechanisms permitted under applicable data protection laws. 

Where appropriate, additional technical, contractual and organisational safeguards may also be implemented to protect personal data transferred internationally. 

12. Retention of Personal Data  

We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, including satisfying applicable legal, regulatory, contractual, accounting and reporting requirements. 

The period for which personal data is retained depends upon the nature of the information, the purpose for which it is processed and the legal obligations applicable to the Company. 

When personal data is no longer required, it will be securely deleted, destroyed or irreversibly anonymised using appropriate methods designed to prevent its reconstruction or recovery. 

Where retention is necessary for the establishment, exercise or defence of legal claims or to comply with legal obligations, personal data may be retained for a longer period as required or permitted by applicable law. 

13. Security of Personal Data  

We are committed to safeguarding the personal data entrusted to us and have implemented appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data, taking into account the nature, scope, context and purposes of the processing, as well as the likelihood and severity of risks to the rights and freedoms of individuals, in accordance with Article 32 of the GDPR. 

Our security measures are designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or any other form of unlawful processing. 

Access to personal data is limited to authorised personnel and service providers who require such access for legitimate business purposes and who are subject to appropriate confidentiality obligations. 

Although we take reasonable steps to protect personal data, no method of transmitting information over the internet or storing information electronically can be guaranteed to be completely secure. Accordingly, while we strive to protect personal data, we cannot guarantee its absolute security. 

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority and, where required by applicable law, the affected individuals within the applicable legal timeframes. 

14. Your Rights  

Subject to applicable data protection laws, you may exercise the following rights in relation to your personal data: 

The exercise of certain rights may be subject to legal limitations where processing is necessary to comply with legal obligations or for the establishment, exercise or defence of legal claims. 

To exercise any of your rights, please contact our Data Protection Officer using the contact details provided below. We may request additional information to verify your identity before responding to your request. 

We will respond to your request without undue delay and, in any event, within the time limits prescribed by applicable data protection legislation. 

15. Children’s Privacy  

Our websites, events and digital platforms are intended primarily for individuals acting in a professional or business capacity. 

We do not knowingly collect personal data from children where such collection is prohibited by applicable law. If we become aware that personal data relating to a child has been collected inadvertently, we will take appropriate steps to delete such information unless we are required to retain it under applicable law. 

16. Accountability and Governance  

The Company maintains internal policies, procedures and governance measures designed to ensure ongoing compliance with applicable data protection legislation and to demonstrate accountability in accordance with Article 24 of the GDPR. 

Our processing activities are subject to appropriate internal governance, periodic review and risk-based assessment to ensure that personal data continues to be processed lawfully, fairly and securely. 

Where required by applicable law, we implement data protection by design and by default when developing new services, technologies and business processes involving the processing of personal data. 

We also ensure that individuals authorised to process personal data are subject to appropriate confidentiality obligations and receive suitable guidance and training relating to data protection responsibilities. 

17. Third-Party Websites  

Our websites, digital platforms and communications may contain links to third-party websites, applications or services that are not operated or controlled by the Company. 

This Privacy Policy applies solely to the processing of personal data carried out by the Company. We are not responsible for the privacy practices, content or security of third-party websites or services. 

We encourage you to review the privacy policies of any third-party websites or services before providing them with your personal data. 

18. Changes to this Privacy Policy  

We may update this Privacy Policy from time to time to reflect changes in applicable laws, regulatory guidance, technology, our business operations or our personal data processing activities. 

Any changes will become effective upon publication of the updated Privacy Policy on our website unless otherwise required by applicable law. 

Where appropriate, we may also notify you of material changes through other communication channels. 

We encourage you to review this Privacy Policy periodically to remain informed about how we process and protect your personal data. 

19. Contact Us 

If you have any questions regarding this Privacy Policy, the processing of your personal data or if you wish to exercise your rights under applicable data protection legislation, you may contact our Data Protection Officer: 

Data Protection Officer 

Email: [email protected] 

If you are not satisfied with our response, you have the right to lodge a complaint with the competent supervisory authority in your jurisdiction.