Privacy Policy

Last updated: 24 September 2026

Who handles your information

WELLNESSINDUSTRY.IO is operated and generally hosted in Estonia by HOLOLIFE Summit OÜ, registry code 14867044, Tööstuse 43-100, 10411 Tallinn, Estonia. Contact us at [email protected] or through .

We are the controller for platform accounts, security, our communications and events we organise. When another organiser uses the platform, that organiser controls its event applications, registrations and event operations; we process those records on its behalf. The event page identifies its organiser. We can help direct a privacy request to the right team.

What we collect

  • Accounts: name, email, profile details, account roles, password hash, authentication information and preferences.
  • Tickets and registrations: buyer and attendee contact details, organisation, job title, registration answers, ticket assignments, attendance, billing address, VAT details, orders and payment status. Card details go directly to the payment provider.
  • Applications and company registrations: contact and company details, descriptions, products, websites, social accounts, logos, photos, submitted files, selected packages and billing details. This includes exhibitor, sponsor, partner, food vendor, speaker, volunteer, press and other open-call applications.
  • Application handling: verification and consent records, submitted updates, correspondence, decisions, reviewer notes and activity history. We may consult relevant public websites and professional profiles supplied with an application.
  • Event logistics: speaker travel details such as date of birth, flights, hotel arrangements and emergency contacts, and information needed to organise volunteer assignments or other participation.
  • Photos and content: uploaded portraits, event photographs, tags, recordings, transcripts, public profiles, articles and marketing assets, including AI-assisted versions. Managers and attendees may add photo tags. You can ask us to correct a tag or remove an image of you.
  • Support and AI tools: messages, prompts, relevant event context, attachments, responses and saved conversation history when these features are used.
  • Technical and marketing information: IP address, device and request information, security logs, newsletter subscription status and, with advertising consent, browser identifiers, click IDs and measurement events.

Information can come from you, an organiser, a company representative or someone booking a ticket for you. Public-source research is limited to material relevant to the application or content being prepared. Providing details marked as required is necessary to complete the relevant service; photo and marketing choices are separate.

Why we use it

  • Providing the service and taking steps you request: managing accounts, applications, tickets, registrations, participation, invoicing and support. We rely on a contract or steps before a contract where you are the contracting person.
  • Running and protecting the platform: working with company contacts, reviewing applications, coordinating events, preventing misuse, maintaining security and resolving disputes. We rely on our or the organiser's legitimate interests and consider the impact on your rights. You can object to this processing.
  • Legal obligations: accounting, tax, responding to lawful requests and retaining records required by law.
  • Your consent: newsletter marketing, analytics and advertising measurement, and the photography and AI-editing uses you separately choose. You can withdraw consent without affecting processing that was lawful before withdrawal.

Agreeing to the Terms of Service and acknowledging this policy does not give blanket consent to marketing, photography or AI portrait editing.

Applications, publication and AI assistance

A company application starts a review. Acceptance may invite you to complete a separate registration, select a package and provide billing details. Previously submitted information can be reused or prefilled so you can check and update it. Review, completed registration and payment are recorded as separate steps.

Authorised organisers and reviewers can access submissions and internal notes for their work. Contact information, billing details and private application answers are not automatically published. Approved profile content, programme information, articles and published event assets may be publicly viewable, downloadable and shared without an account.

We use Microsoft Azure OpenAI with GPT models for application-review assistance, summaries, writing and the AI assistant. Research articles based on session transcripts use Google Gemini Deep Research, which receives condensed transcripts and relevant speaker and event context. Requests may include relevant submitted information, public-source material, event context and attachments. Separate image, speech, search and translation providers are listed below. AI review suggestions support a human reviewer; the application-review tool does not itself decide whether to accept or reject an applicant.

If you connect an external AI client or another authorised tool, it receives the information and permissions you grant it. Its provider handles information under its own terms. You can revoke a connection; this stops future access but does not automatically delete copies already received by that provider.

Photographs, AI editing and your choices

At platform signup you can allow authorised teams to edit your portrait with AI. Without that permission, only you can use the platform's AI tools on your own portrait. Allowing editing does not make a private application photo public.

Event forms offer separate choices for being photographed and using those images to promote the event, future events in the same series and Wellnessindustry.io; and for AI editing or turning those images into motion graphics for those purposes. Declining either choice does not prevent registration or participation.

For a company application or registration, the choices relate to the submitted person or company and the material you are authorised to provide. They do not change your personal account-wide permissions or give permission on behalf of unrelated people. A company representative must have authority for the permissions they give.

You may withdraw permission or request removal of any image of you, including a group photo or AI-edited version, whether or not you previously consented. Use Photo permissions, available with an account or a verified email link, or contact us. We stop further consent-dependent use and review identified images and derivatives for removal or replacement with a version excluding you. Copies published by others require follow-up with those publishers.

We keep the wording, scope, version, source and date of permission changes and the records needed to handle withdrawals and removal requests. Historical permission records remain distinguishable from new explicit choices. General scenes and group photos remain subject to applicable privacy requirements and the same removal-request process.

Email and cookie choices

Account creation or a newsletter request may send your name and email to Klaviyo for a subscription-confirmation message. Our newsletter lists use double opt-in: you must confirm before joining the list and receiving its marketing. You can unsubscribe through newsletter links. Necessary messages about your account, application, order or event arrangements are separate.

Analytics and advertising tools, including Google and Meta tags and the first-party Google click-ID cookie, require your cookie consent. With consent, purchase matching can also use hashed buyer details, browser information and order values. Hashing does not make this information anonymous. We do not send ticket questionnaire answers for advertising measurement.

Use Cookie settings to allow or turn off these tools. Rejecting them does not prevent browsing, applications or purchases. See the Cookie Policy for identifiers and durations.

Who receives information

We share information needed by the relevant organiser, authorised staff and service providers for the purposes above. When you present your badge or ticket for an exhibitor to scan, the exhibitor receives your name, email, organisation and job title as a contact lead, not your billing or payment details. Exhibitors are responsible for their subsequent use and any separate marketing permissions required. We may also disclose information when required by law or to establish or defend legal claims.

The following providers support the features indicated when those services are used. Their linked terms explain their processing responsibilities; payment and advertising providers may also act as controllers for some purposes.

  • Microsoft Azure OpenAI (GPT models)

    Purpose
    AI assistant, application-review assistance, research, writing, summaries, embeddings and content analysis
    Information
    Prompts, relevant application or event details, public-source material, conversation content, files and generated responses
    Location
    Azure processing locations depend on the deployment; international processing may apply
    Role
    Processor under Microsoft's Products and Services Data Protection Addendum
    Provider data terms
  • Google Gemini (Deep Research)

    Purpose
    Web research and research articles based on session transcripts
    Information
    Condensed transcripts, speaker and event context, research prompts and generated articles
    Location
    International processing where Google or its service providers maintain facilities
    Role
    Research-service provider under Gemini API terms and applicable data-processing terms
    Provider data terms
  • OpenAI (image tools)

    Purpose
    Image generation, portrait editing and photo relighting
    Information
    Reference photographs and editing instructions
    Location
    International processing under the provider's data-processing terms
    Role
    Processor for image inputs and outputs
    Provider data terms
  • Stripe

    Purpose
    Payments and hosted checkout
    Information
    Buyer and billing details, purchase amounts and payment information; card details go directly to Stripe
    Location
    EEA and international processing, including the US
    Role
    Processor and independent controller, depending on the payment service
    Provider data terms
  • Tito

    Purpose
    Event ticket checkout and registration, where offered
    Information
    Buyer and attendee details, ticket orders, registration answers and consented attribution metadata
    Location
    Ireland and the locations of Tito's service providers
    Role
    Processor for organiser ticketing data under its service terms
    Provider data terms
  • Brevo (Sendinblue)

    Purpose
    Transactional email, invitations and event communications
    Information
    Recipient name and email, message content, delivery information and attachments
    Location
    EU and locations of the service providers identified in Brevo's terms
    Role
    Processor under the data-processing agreement in its service terms
    Provider data terms
  • Klaviyo

    Purpose
    Newsletter confirmation, subscriptions and email marketing
    Information
    Email, name, signup source, consent and subscription records, email interactions
    Location
    US and the locations of Klaviyo's service providers
    Role
    Processor under its customer data-processing agreement
    Provider data terms
  • Cloudflare

    Purpose
    Website delivery, traffic routing and security
    Information
    IP address, request and connection information, and content passing through the service
    Location
    Global network, including the EEA and US
    Role
    Processor for website traffic under its customer data-processing addendum
    Provider data terms
  • Google Tag Manager, Analytics and Ads

    Purpose
    Consent-based site analytics, advertising attribution and purchase matching
    Information
    Page and interaction events, browser identifiers, click IDs, hashed buyer details and purchase value
    Location
    International processing, including the EEA and US
    Role
    Processor or controller according to the Google service and applicable data terms
    Provider data terms
  • Meta Pixel and Conversions API

    Purpose
    Consent-based advertising measurement and purchase matching
    Information
    Browser events and identifiers, hashed buyer details and purchase value
    Location
    International processing, including the EEA and US
    Role
    Roles depend on the processing under Meta's Business Tools Terms
    Provider data terms
  • AssemblyAI

    Purpose
    Audio and session transcription
    Information
    Audio recordings and transcripts
    Location
    EU or US processing according to the selected service and endpoint
    Role
    Processor under its data-processing addendum
    Provider data terms
  • ElevenLabs

    Purpose
    Spoken playback of assistant responses
    Information
    Text submitted for speech synthesis and generated audio
    Location
    International processing under the provider's data-processing terms
    Role
    Processor for customer content under its data-processing addendum
    Provider data terms
  • DeepL

    Purpose
    Translation of session content
    Information
    Transcript text and translation requests
    Location
    Processing locations depend on the service and data-residency arrangement
    Role
    Processor for customer content under its business data-processing terms
    Provider data terms
  • Tavily

    Purpose
    Web and image search supporting research and content creation
    Information
    Search queries, which may include public speaker or company names, and retrieved results
    Location
    International processing, including the US
    Role
    Search-service provider under its service and privacy terms
    Provider data terms

Our core databases, file storage and self-hosted processing services are operated by us in Estonia. External checkout destinations, such as a linked Shopify store, also provide their own privacy information at checkout.

International processing and security

External providers may process information outside the European Economic Area. Applicable data-processing terms provide safeguards such as European Commission Standard Contractual Clauses, or transfers rely on an applicable adequacy decision, including the EU–US Data Privacy Framework for covered certified providers. You can ask us for information about the safeguards relevant to your data.

We use access controls, authenticated connections and security monitoring to protect information. Access to private application, billing and logistics records is limited according to the user's role and event responsibilities.

How long we keep information

  • Accounts and participation: for the active relationship and as needed to provide your records, resolve disputes or meet legal duties. Applications and correspondence are kept for review, follow-up and related event administration; retention depends on the application outcome and any ongoing relationship.
  • Accounting: accounting source documents are normally kept for seven years after the relevant financial year ends under Estonian law. Other applicable legal obligations or claims can require a different period.
  • Travel profiles: event travel logistics are scheduled for deletion 30 days after the event ends.
  • Public content: published profiles, programmes, recordings and event archives remain available while relevant to the event or platform, subject to applicable permissions and removal requests.
  • Consent and marketing: subscription data is used while the subscription continues. Limited consent, withdrawal and suppression records may be kept to demonstrate and respect your choices.
  • Other records: support conversations, AI interactions and security records are retained for their operational purpose and any necessary dispute or legal retention period, then deleted or anonymised. Restricted backups are retired through their backup lifecycle rather than immediately when a live record changes.

Your rights and how to use them

You can request access, correction, deletion, restriction or portability where applicable, object to processing based on legitimate interests, and withdraw consent. You can object to direct marketing at any time. Contact [email protected]; you do not need an account. We may ask for proportionate information to verify your identity.

Signed-in users can download the account data available through our export tool and manage their account in Account settings. The export does not replace your right to request other personal data we hold. Account deletion, permission withdrawal and removal of publicly shared images are different actions; contact us for a wider erasure request. Legal retention duties and other people's rights may limit what can be erased.

We normally respond within one month. If a request is complex or you have made several requests, we may take up to two additional months and will explain this within the first month. You can complain to the Estonian Data Protection Inspectorate or your local supervisory authority.

We update this policy as the service changes. The date above identifies this version. Material changes will be brought to your attention where required, and new consent will be requested when needed.