PRIVACY POLICY
AI Summit Barcelona | aisummitbarcelona.com
Last updated: 6 July 2026
1. Data Controller
AI SUMMIT ALLIANCE, S.L. (NIF: ESB88892443) is the data controller for the personal data collected through the website aisummitbarcelona.com and its associated apps and in connection with the AI Summit Barcelona event (hereinafter referred to as the "Organization", "we", "us", or "our").
- Legal form: Sociedad Limitada (S.L.)
- Registered office: C/ Casp, 54, 1º, Puerta 2B, 08010 Barcelona, Spain
- Email:
The Organization operates in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and Spain's Ley Orgánica 3/2018, de Protección de Datos Personales y garantía de los derechos digitales ("LOPDGDD").
2. Scope of This Policy
This Privacy Policy applies to all personal data collected through:
- The website aisummitbarcelona.com and any associated subdomains
- The ticket purchase, registration, and order confirmation process for AI Summit Barcelona 2026
- The official event application ("Event App"), including attendee profiles and in-app interactions
- Speaker, sponsor, and exhibitor application or onboarding processes
- Communications sent via email, contact forms, or social media channels operated by the Organization
- On-site data collection during the event (badge scanning, photo/video recording, Wi-Fi access)
- Satellite and side events organized under the AI Week Barcelona programme (16–23 September 2026)
3. Personal Data We Collect
3.1 Data you provide directly
- Identity data: first name, last name, job title, company name
- Contact data: email address, phone number, postal address
- Professional data: industry, role, areas of interest, LinkedIn profile URL
- Transaction data: ticket type and tier, purchase amount, payment method, invoicing details (CIF/NIF, company name). Full credit card numbers are processed by third-party payment providers and are not stored by us.
- Content data: speaker bios, presentation abstracts, session preferences, dietary requirements
- Communication data: messages sent via contact forms, email correspondence, support requests
3.2 Data collected automatically
- Technical data: IP address, browser type and version, device type, operating system, screen resolution
- Usage data: pages visited, time spent on pages, referral source, click patterns
- Location data: approximate geographic location derived from IP address
3.3 Data collected via the Event App
If you create an account on the official Event App, you will be discoverable and visible to other event attendees within the app. By default, your contact details (email, phone number) will not be shared with other attendees. We collect information about your app usage, including profile views, connections made, and session check-ins.
3.4 Data collected at the event
- Badge scan data: session attendance, exhibitor booth visits, networking interactions (where applicable)
- Photo and video recordings: the event will be photographed and recorded for promotional and archival purposes
- Wi-Fi usage data: if you connect to event-provided Wi-Fi, basic connection logs may be collected
4. Purposes and Legal Basis for Processing
We process your personal data for the following purposes and on the following legal bases under Article 6 GDPR:
a) Performance of a contract (Art. 6(1)(b) GDPR):
- Processing your ticket purchase and issuing order confirmation
- Delivering your official event ticket
- Communicating event logistics, schedule changes, and essential information
- Managing speaker agreements and sponsor deliverables
- Providing access to the Event App and enabling in-app features
b) Legitimate interest (Art. 6(1)(f) GDPR):
- Improving our website, event experience, and services using operational and security-relevant data, and (where you allow optional analytics storage) aggregated measurement configured through our tag manager
- Ensuring the safety and security of attendees, staff, and premises
- Fraud prevention, promo code abuse detection, and enforcement of our terms
- Producing anonymized and aggregated statistics about attendee demographics and interests
c) Consent (Art. 6(1)(a) GDPR):
- Sending marketing communications about future editions, partner events, or related offerings
- Setting Google Consent Mode v2 signals for analytics storage and for advertising-related storage (including ad storage, ad user data, and ad personalization) when you use our cookie banner or Privacy Settings; these choices are separate from accepting this Privacy Policy or the Terms of Service during ticket checkout
- Placing other non-essential cookies or similar technologies on your device where we use them and obtain your consent
- Sharing your contact information with event sponsors or exhibitors (only where you have explicitly opted in, for example by having your badge scanned at a sponsor booth or by ticking a consent box during registration)
d) Legal obligation (Art. 6(1)(c) GDPR):
- Retaining transaction records for tax and accounting purposes as required by Spanish law
5. Data Sharing and Recipients
We take your privacy seriously. We will never sell your personal data to third parties for their own marketing purposes without your prior, explicit consent.
We may share your personal data with the following categories of recipients:
- Service providers: payment processors, email service providers, CRM platforms, analytics providers, event management and ticketing platforms, Event App provider, AV production companies, and venue operators acting as data processors on our behalf
- Event sponsors and exhibitors: only where you have given explicit, affirmative consent (e.g., by having your badge scanned at a sponsor booth, or by actively opting in during registration). You may withdraw this consent at any time by contacting us.
- Co-organizers: where satellite events are co-organized with third parties, your registration data for that specific event may be shared with the co-organizer
- Legal and regulatory authorities: where required by applicable law, regulation, or legal process
- Professional advisors: lawyers, accountants, and auditors where necessary for the operation of our business
6. International Data Transfers
Some of our service providers may be located outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place, including:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Other lawful transfer mechanisms as permitted under GDPR
You may request a copy of the relevant safeguards by contacting us at .
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Account and registration data (including attendee profiles): retained for up to 2 years after your last interaction with us, unless required by law to be kept longer or you request earlier deletion
- Transaction and billing records (including invoices): retained for 5 years from the date of the transaction, in accordance with Spanish tax and commercial obligations
- Marketing contacts: retained until you withdraw consent or unsubscribe, plus up to 3 months to process the opt-out
- Website analytics and technical usage data: retained in anonymized form for up to 12 months from collection (where such data is collected only after you grant optional analytics storage, or from sources that do not rely on that consent)
- Consent Mode / cookie preferences: stored in a first-party consent cookie set on our parent domain (shared across our website and related sub-domains) until it expires (about 13 months), or you clear it, reset it via Privacy Settings, or clear site data in your browser
- Optional copy for signed-in users: if you are logged in when you save choices, we may store your analytics and ads-related Consent Mode selections, the consent version, and a timestamp on your user profile in our database (PostgreSQL) so your preferences can be restored across sessions; this is independent of ticket checkout legal acceptance below
- Ticket checkout acceptance: when you buy tickets, we record that you accepted this Privacy Policy and our Terms of Service as timestamps on the applicable ticket order record, for audit and compliance; those timestamps are not the same data as your Consent Mode selections
- Speaker and sponsor records: retained for the duration of the business relationship plus 3 years
When we no longer need your personal data, we will delete it or anonymize it. Where data is stored in backup archives, we will securely isolate it from further processing until deletion is possible.
8. Your Rights
Under the GDPR and LOPDGDD, you have the following rights:
- Right of access: to obtain confirmation of whether we process your data and to receive a copy
- Right to rectification: to have inaccurate or incomplete data corrected
- Right to erasure: to request deletion of your data where there is no compelling reason for continued processing
- Right to restriction of processing: to request that we limit how we use your data in certain circumstances
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format
- Right to object: to object to processing based on legitimate interest or for direct marketing purposes. For direct marketing, we will stop processing immediately upon your objection.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal
- Right not to be subject to automated decision-making: you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects concerning you
To exercise any of these rights, please contact us at . We will respond within one month. If your request is complex, we may extend this by an additional two months, and we will inform you.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at . We would, however, appreciate the chance to address your concerns before you approach the AEPD, so please contact us in the first instance.
9. Cookies, Tag Management, and Consent Mode
Our website uses cookies and similar technologies (including pixels, tags, and scripts loaded through our tag manager) to operate the site and, where you allow it, to measure use and support relevant advertising. We load Google Tag Manager (GTM) and use Google Consent Mode version 2 ("GCM v2") so that Google tags respect your choices: we set default consent to denied for analytics storage and for advertising-related storage categories (including ad storage, ad user data, and ad personalization) until you opt in, with a brief wait so your choice can apply before measurement runs. This approach is our first-party consent tooling alongside GCM; we do not operate an IAB TCF consent string or CMP on the site.
9.1 What we distinguish
- Strictly necessary technologies: required for core site operation, security, load balancing, and similar purposes. These are not gated by the analytics/ads toggles.
- Analytics storage (Consent Mode): when enabled, allows tags (for example analytics tools we configure in GTM) to use storage for measurement in line with your choice. When disabled, consent signals remain denied for that category.
- Advertising-related storage (Consent Mode): when enabled, allows GCM categories tied to ads and personalization (ad storage, ad user data, ad personalization) to be granted together for Google tags; when disabled, those signals stay denied. This is separate from analytics storage so you can allow one without the other where the product permits it.
9.2 How you set and change preferences
On your first visit, a cookie consent banner lets you accept all optional categories, reject all non-essential categories, or open granular controls for analytics and advertising-related storage; optional categories are off by default. After your choice, we store your selection in a first-party consent cookie set on our parent domain (so the same choice applies across our website and the related sub-domain, such as our attendee platform) and update GCM accordingly. You can reopen and change preferences at any time through "Cookie settings" / "Privacy Settings" in the site footer; clearing or resetting there may show the banner again. If you are signed in when you save, we may also send your choices to our API so a copy is stored with your user profile in our database (version, both category flags, and a recorded time); when you return signed in, the site may apply that server record to keep your consent state aligned across devices.
Accepting this Privacy Policy or the Terms of Service in the ticket checkout flow records separate timestamps on your ticket order for legal and contractual purposes. Those checkout acceptances are not the same fields as your Consent Mode / GCM preferences managed in the banner and Privacy Settings.
9.3 Browser controls
You can also block or delete cookies and site storage through your browser settings. Note that doing so may affect how preferences are remembered. For general information about cookies, visit .
9.4 Purchase conversion measurement (server-side)
When you complete a paid ticket purchase, we may also send a purchase/conversion event directly from our servers to our measurement partners (for example Google Analytics 4 via the Measurement Protocol and Meta via the Conversions API). These server events are used to measure sales accurately and are matched to any corresponding browser event using a shared event identifier so they are de-duplicated. Where these events include contact details (such as your email or phone number), they are transmitted in hashed form. This server-to-server measurement relates to first-party purchase records; we configure it consistently with applicable law and the choices you make in the banner and Privacy Settings.
10. Event App and Attendee Discoverability
By attending the event, you may create an account on the official Event App. By doing so, you will be discoverable and visible to other event attendees within the app. By default, none of your contact details (email, phone) will be accessible to other attendees. If you wish to share this information, you must actively enable the relevant option in the app. The Organization is not responsible for any information you voluntarily choose to share with other attendees through the app.
11. Children's Privacy
Our website and event are not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child has provided us with personal data, please contact us immediately at .
12. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (SSL/TLS), access controls, regular security assessments, and contractual obligations on our data processors. However, no method of transmission over the Internet is completely secure, and we cannot guarantee absolute security.
13. Third-Party Links
Our website may contain links to third-party websites, including those of sponsors, partners, and social media platforms. This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party website you visit.
14. Photography and Video at the Event
By attending AI Summit Barcelona, you acknowledge and agree that the event may be photographed, filmed, and recorded by the Organization or authorized third parties. These recordings may be used for promotional, marketing, and educational purposes, including on our website, social media channels, press materials, and future event communications, for a period of thirty-six (36) months after the closing date of the Event.
This includes the right to edit, use (alone or with other material), and license such media. If you do not wish to be photographed or filmed, please notify our staff on-site. Speakers and panelists will be recorded as part of the event programme; specific terms are set out in the speaker agreement.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The updated version will be posted on this page with a revised "Last updated" date. The version in force at the date of your registration or purchase applies to your data, unless a new version is required by law. Where changes are material, we will notify registered users by email.
16. Contact
For any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data:
AI SUMMIT ALLIANCE, S.L. NIF: ESB88892443 C/ Casp, 54, 1º, Puerta 2B 08010 Barcelona, Spain
Email: Website: aisummitbarcelona.com
For data protection complaints, you may also contact the Agencia Española de Protección de Datos (AEPD):
- Website:
- Address: C/ Jorge Juan 6, 28001 Madrid, Spain