Privacy Policy
Last updated: 24 September 2026
Who handles your information
WELLNESSINDUSTRY.IO is operated and generally hosted in Estonia by HOLOLIFE Summit OÜ, registry code 14867044, Tööstuse 43-100, 10411 Tallinn, Estonia. Contact us at [email protected] or through .
We are the controller for platform accounts, security, our communications and events we organise. When another organiser uses the platform, that organiser controls its event applications, registrations and event operations; we process those records on its behalf. The event page identifies its organiser. We can help direct a privacy request to the right team.
What we collect
- Accounts: name, email, profile details, account roles, password hash, authentication information and preferences.
- Tickets and registrations: buyer and attendee contact details, organisation, job title, registration answers, ticket assignments, attendance, billing address, VAT details, orders and payment status. Card details go directly to the payment provider.
- Applications and company registrations: contact and company details, descriptions, products, websites, social accounts, logos, photos, submitted files, selected packages and billing details. This includes exhibitor, sponsor, partner, food vendor, speaker, volunteer, press and other open-call applications.
- Application handling: verification and consent records, submitted updates, correspondence, decisions, reviewer notes and activity history. We may consult relevant public websites and professional profiles supplied with an application.
- Event logistics: speaker travel details such as date of birth, flights, hotel arrangements and emergency contacts, and information needed to organise volunteer assignments or other participation.
- Photos and content: uploaded portraits, event photographs, tags, recordings, transcripts, public profiles, articles and marketing assets, including AI-assisted versions. Managers and attendees may add photo tags. You can ask us to correct a tag or remove an image of you.
- Support and AI tools: messages, prompts, relevant event context, attachments, responses and saved conversation history when these features are used.
- Technical and marketing information: IP address, device and request information, security logs, newsletter subscription status and, with advertising consent, browser identifiers, click IDs and measurement events.
Information can come from you, an organiser, a company representative or someone booking a ticket for you. Public-source research is limited to material relevant to the application or content being prepared. Providing details marked as required is necessary to complete the relevant service; photo and marketing choices are separate.
Why we use it
- Providing the service and taking steps you request: managing accounts, applications, tickets, registrations, participation, invoicing and support. We rely on a contract or steps before a contract where you are the contracting person.
- Running and protecting the platform: working with company contacts, reviewing applications, coordinating events, preventing misuse, maintaining security and resolving disputes. We rely on our or the organiser's legitimate interests and consider the impact on your rights. You can object to this processing.
- Legal obligations: accounting, tax, responding to lawful requests and retaining records required by law.
- Your consent: newsletter marketing, analytics and advertising measurement, and the photography and AI-editing uses you separately choose. You can withdraw consent without affecting processing that was lawful before withdrawal.
Agreeing to the Terms of Service and acknowledging this policy does not give blanket consent to marketing, photography or AI portrait editing.
Applications, publication and AI assistance
A company application starts a review. Acceptance may invite you to complete a separate registration, select a package and provide billing details. Previously submitted information can be reused or prefilled so you can check and update it. Review, completed registration and payment are recorded as separate steps.
Authorised organisers and reviewers can access submissions and internal notes for their work. Contact information, billing details and private application answers are not automatically published. Approved profile content, programme information, articles and published event assets may be publicly viewable, downloadable and shared without an account.
We use Microsoft Azure OpenAI with GPT models for application-review assistance, summaries, writing and the AI assistant. Research articles based on session transcripts use Google Gemini Deep Research, which receives condensed transcripts and relevant speaker and event context. Requests may include relevant submitted information, public-source material, event context and attachments. Separate image, speech, search and translation providers are listed below. AI review suggestions support a human reviewer; the application-review tool does not itself decide whether to accept or reject an applicant.
If you connect an external AI client or another authorised tool, it receives the information and permissions you grant it. Its provider handles information under its own terms. You can revoke a connection; this stops future access but does not automatically delete copies already received by that provider.
Photographs, AI editing and your choices
At platform signup you can allow authorised teams to edit your portrait with AI. Without that permission, only you can use the platform's AI tools on your own portrait. Allowing editing does not make a private application photo public.
Event forms offer separate choices for being photographed and using those images to promote the event, future events in the same series and Wellnessindustry.io; and for AI editing or turning those images into motion graphics for those purposes. Declining either choice does not prevent registration or participation.
For a company application or registration, the choices relate to the submitted person or company and the material you are authorised to provide. They do not change your personal account-wide permissions or give permission on behalf of unrelated people. A company representative must have authority for the permissions they give.
You may withdraw permission or request removal of any image of you, including a group photo or AI-edited version, whether or not you previously consented. Use Photo permissions, available with an account or a verified email link, or contact us. We stop further consent-dependent use and review identified images and derivatives for removal or replacement with a version excluding you. Copies published by others require follow-up with those publishers.
We keep the wording, scope, version, source and date of permission changes and the records needed to handle withdrawals and removal requests. Historical permission records remain distinguishable from new explicit choices. General scenes and group photos remain subject to applicable privacy requirements and the same removal-request process.
Email and cookie choices
Account creation or a newsletter request may send your name and email to Klaviyo for a subscription-confirmation message. Our newsletter lists use double opt-in: you must confirm before joining the list and receiving its marketing. You can unsubscribe through newsletter links. Necessary messages about your account, application, order or event arrangements are separate.
Analytics and advertising tools, including Google and Meta tags and the first-party Google click-ID cookie, require your cookie consent. With consent, purchase matching can also use hashed buyer details, browser information and order values. Hashing does not make this information anonymous. We do not send ticket questionnaire answers for advertising measurement.
Use Cookie settings to allow or turn off these tools. Rejecting them does not prevent browsing, applications or purchases. See the Cookie Policy for identifiers and durations.
Who receives information
We share information needed by the relevant organiser, authorised staff and service providers for the purposes above. When you present your badge or ticket for an exhibitor to scan, the exhibitor receives your name, email, organisation and job title as a contact lead, not your billing or payment details. Exhibitors are responsible for their subsequent use and any separate marketing permissions required. We may also disclose information when required by law or to establish or defend legal claims.
The following providers support the features indicated when those services are used. Their linked terms explain their processing responsibilities; payment and advertising providers may also act as controllers for some purposes.
Microsoft Azure OpenAI (GPT models)
- Purpose
- AI assistant, application-review assistance, research, writing, summaries, embeddings and content analysis
- Information
- Prompts, relevant application or event details, public-source material, conversation content, files and generated responses
- Location
- Azure processing locations depend on the deployment; international processing may apply
- Role
- Processor under Microsoft's Products and Services Data Protection Addendum
Google Gemini (Deep Research)
- Purpose
- Web research and research articles based on session transcripts
- Information
- Condensed transcripts, speaker and event context, research prompts and generated articles
- Location
- International processing where Google or its service providers maintain facilities
- Role
- Research-service provider under Gemini API terms and applicable data-processing terms
OpenAI (image tools)
- Purpose
- Image generation, portrait editing and photo relighting
- Information
- Reference photographs and editing instructions
- Location
- International processing under the provider's data-processing terms
- Role
- Processor for image inputs and outputs
Stripe
- Purpose
- Payments and hosted checkout
- Information
- Buyer and billing details, purchase amounts and payment information; card details go directly to Stripe
- Location
- EEA and international processing, including the US
- Role
- Processor and independent controller, depending on the payment service
Tito
- Purpose
- Event ticket checkout and registration, where offered
- Information
- Buyer and attendee details, ticket orders, registration answers and consented attribution metadata
- Location
- Ireland and the locations of Tito's service providers
- Role
- Processor for organiser ticketing data under its service terms
Brevo (Sendinblue)
- Purpose
- Transactional email, invitations and event communications
- Information
- Recipient name and email, message content, delivery information and attachments
- Location
- EU and locations of the service providers identified in Brevo's terms
- Role
- Processor under the data-processing agreement in its service terms
Klaviyo
- Purpose
- Newsletter confirmation, subscriptions and email marketing
- Information
- Email, name, signup source, consent and subscription records, email interactions
- Location
- US and the locations of Klaviyo's service providers
- Role
- Processor under its customer data-processing agreement
Cloudflare
- Purpose
- Website delivery, traffic routing and security
- Information
- IP address, request and connection information, and content passing through the service
- Location
- Global network, including the EEA and US
- Role
- Processor for website traffic under its customer data-processing addendum
Google Tag Manager, Analytics and Ads
- Purpose
- Consent-based site analytics, advertising attribution and purchase matching
- Information
- Page and interaction events, browser identifiers, click IDs, hashed buyer details and purchase value
- Location
- International processing, including the EEA and US
- Role
- Processor or controller according to the Google service and applicable data terms
Meta Pixel and Conversions API
- Purpose
- Consent-based advertising measurement and purchase matching
- Information
- Browser events and identifiers, hashed buyer details and purchase value
- Location
- International processing, including the EEA and US
- Role
- Roles depend on the processing under Meta's Business Tools Terms
AssemblyAI
- Purpose
- Audio and session transcription
- Information
- Audio recordings and transcripts
- Location
- EU or US processing according to the selected service and endpoint
- Role
- Processor under its data-processing addendum
ElevenLabs
- Purpose
- Spoken playback of assistant responses
- Information
- Text submitted for speech synthesis and generated audio
- Location
- International processing under the provider's data-processing terms
- Role
- Processor for customer content under its data-processing addendum
DeepL
- Purpose
- Translation of session content
- Information
- Transcript text and translation requests
- Location
- Processing locations depend on the service and data-residency arrangement
- Role
- Processor for customer content under its business data-processing terms
Tavily
- Purpose
- Web and image search supporting research and content creation
- Information
- Search queries, which may include public speaker or company names, and retrieved results
- Location
- International processing, including the US
- Role
- Search-service provider under its service and privacy terms
| Provider and role | Purpose and information | Location |
|---|---|---|
| Microsoft Azure OpenAI (GPT models) Processor under Microsoft's Products and Services Data Protection Addendum Provider data terms | AI assistant, application-review assistance, research, writing, summaries, embeddings and content analysis Prompts, relevant application or event details, public-source material, conversation content, files and generated responses | Azure processing locations depend on the deployment; international processing may apply |
| Google Gemini (Deep Research) Research-service provider under Gemini API terms and applicable data-processing terms Provider data terms | Web research and research articles based on session transcripts Condensed transcripts, speaker and event context, research prompts and generated articles | International processing where Google or its service providers maintain facilities |
| OpenAI (image tools) Processor for image inputs and outputs Provider data terms | Image generation, portrait editing and photo relighting Reference photographs and editing instructions | International processing under the provider's data-processing terms |
| Stripe Processor and independent controller, depending on the payment service Provider data terms | Payments and hosted checkout Buyer and billing details, purchase amounts and payment information; card details go directly to Stripe | EEA and international processing, including the US |
| Tito Processor for organiser ticketing data under its service terms Provider data terms | Event ticket checkout and registration, where offered Buyer and attendee details, ticket orders, registration answers and consented attribution metadata | Ireland and the locations of Tito's service providers |
| Brevo (Sendinblue) Processor under the data-processing agreement in its service terms Provider data terms | Transactional email, invitations and event communications Recipient name and email, message content, delivery information and attachments | EU and locations of the service providers identified in Brevo's terms |
| Klaviyo Processor under its customer data-processing agreement Provider data terms | Newsletter confirmation, subscriptions and email marketing Email, name, signup source, consent and subscription records, email interactions | US and the locations of Klaviyo's service providers |
| Cloudflare Processor for website traffic under its customer data-processing addendum Provider data terms | Website delivery, traffic routing and security IP address, request and connection information, and content passing through the service | Global network, including the EEA and US |
| Google Tag Manager, Analytics and Ads Processor or controller according to the Google service and applicable data terms Provider data terms | Consent-based site analytics, advertising attribution and purchase matching Page and interaction events, browser identifiers, click IDs, hashed buyer details and purchase value | International processing, including the EEA and US |
| Meta Pixel and Conversions API Roles depend on the processing under Meta's Business Tools Terms Provider data terms | Consent-based advertising measurement and purchase matching Browser events and identifiers, hashed buyer details and purchase value | International processing, including the EEA and US |
| AssemblyAI Processor under its data-processing addendum Provider data terms | Audio and session transcription Audio recordings and transcripts | EU or US processing according to the selected service and endpoint |
| ElevenLabs Processor for customer content under its data-processing addendum Provider data terms | Spoken playback of assistant responses Text submitted for speech synthesis and generated audio | International processing under the provider's data-processing terms |
| DeepL Processor for customer content under its business data-processing terms Provider data terms | Translation of session content Transcript text and translation requests | Processing locations depend on the service and data-residency arrangement |
| Tavily Search-service provider under its service and privacy terms Provider data terms | Web and image search supporting research and content creation Search queries, which may include public speaker or company names, and retrieved results | International processing, including the US |
Our core databases, file storage and self-hosted processing services are operated by us in Estonia. External checkout destinations, such as a linked Shopify store, also provide their own privacy information at checkout.
International processing and security
External providers may process information outside the European Economic Area. Applicable data-processing terms provide safeguards such as European Commission Standard Contractual Clauses, or transfers rely on an applicable adequacy decision, including the EU–US Data Privacy Framework for covered certified providers. You can ask us for information about the safeguards relevant to your data.
We use access controls, authenticated connections and security monitoring to protect information. Access to private application, billing and logistics records is limited according to the user's role and event responsibilities.
How long we keep information
- Accounts and participation: for the active relationship and as needed to provide your records, resolve disputes or meet legal duties. Applications and correspondence are kept for review, follow-up and related event administration; retention depends on the application outcome and any ongoing relationship.
- Accounting: accounting source documents are normally kept for seven years after the relevant financial year ends under Estonian law. Other applicable legal obligations or claims can require a different period.
- Travel profiles: event travel logistics are scheduled for deletion 30 days after the event ends.
- Public content: published profiles, programmes, recordings and event archives remain available while relevant to the event or platform, subject to applicable permissions and removal requests.
- Consent and marketing: subscription data is used while the subscription continues. Limited consent, withdrawal and suppression records may be kept to demonstrate and respect your choices.
- Other records: support conversations, AI interactions and security records are retained for their operational purpose and any necessary dispute or legal retention period, then deleted or anonymised. Restricted backups are retired through their backup lifecycle rather than immediately when a live record changes.
Your rights and how to use them
You can request access, correction, deletion, restriction or portability where applicable, object to processing based on legitimate interests, and withdraw consent. You can object to direct marketing at any time. Contact [email protected]; you do not need an account. We may ask for proportionate information to verify your identity.
Signed-in users can download the account data available through our export tool and manage their account in Account settings. The export does not replace your right to request other personal data we hold. Account deletion, permission withdrawal and removal of publicly shared images are different actions; contact us for a wider erasure request. Legal retention duties and other people's rights may limit what can be erased.
We normally respond within one month. If a request is complex or you have made several requests, we may take up to two additional months and will explain this within the first month. You can complain to the Estonian Data Protection Inspectorate or your local supervisory authority.
We update this policy as the service changes. The date above identifies this version. Material changes will be brought to your attention where required, and new consent will be requested when needed.