Privacy policy
EuroExpo Desk is run by Packsy Global B.V. in The Hague. Below you can read which personal data we process when you use the website, why we do it, who receives it and how you can use your rights.
Who is responsible
Packsy Global B.V. is the controller for the processing described here. We decide why and how personal data is processed on EuroExpo Desk (euroexpodesk.com).
- Packsy Global B.V., KVK 99226057
- Athenesingel 100, 2548 TH Den Haag, Netherlands
- Email: [email protected]
Write to this address with any privacy question or request. Please do not send identity documents or other sensitive information through WeChat.
This policy covers the website, accounts, requests, service provider profiles, the trade fair emails and messages you send us. Organisers, venues and service providers whose websites we link to have their own privacy policies.
What we process and why
We process only what we need for the purposes below. The legal bases come from Article 6(1) of the General Data Protection Regulation (GDPR): (a) consent, (b) a contract with you or steps you ask for before one, (c) a legal obligation, and (f) our legitimate interests. You can object at any time to processing based on legitimate interests (see Your rights).
| Activity | Personal data | Purpose | Legal basis |
|---|---|---|---|
| Visiting the website | IP address, requested page, time, browser and device information, referring page | Delivering the website and protecting it against attacks and abuse | Legitimate interest (f): a working, secure website |
| Signing in with an email code | Email address, account ID, sign-up and sign-in times; security records kept by the sign-in service, such as IP address and browser information | Creating your account, signing you in and keeping the account secure | Contract (b); security records: legitimate interest (f) |
| Human check (Cloudflare Turnstile) | IP address, browser and connection characteristics | Telling people apart from automated sign-ups and spam on the sign-in and subscription forms | Legitimate interest (f): preventing abuse |
| Your platform profile | Role (exhibitor, service provider or both), company or name, country, description, service categories; review and verification status and our notes on them | Running the platform and reviewing service providers | Contract (b); review notes: legitimate interest (f) |
| Showing a provider profile | Company, country, service categories, description, approval and verification status, completed services and reviews | Letting signed-in exhibitors find service providers | Your consent (a), given with the display checkbox; reviews: legitimate interest (f) |
| Exhibitor requests | Exhibition or location, requirements, contact name, email address or phone number, company, budget, timing, requested services | Reviewing the request, following up with you and introducing suitable service providers | Contract (b): steps you ask us to take |
| Introductions, interest and reviews | The provider's expression of interest and note, our match and completion notes, the exhibitor's rating (1 to 5) and comment | Running introductions and showing a factual service record | Contract (b); published ratings: legitimate interest (f) |
| Earlier account tools | On the account, requests and planning tool pages: provider applications (company, country, website, VAT number or reason for having none, services, description, display choice), saved drafts and projects, and requests you share with a chosen provider together with the selected fields | Keeping the earlier tools available to existing users | Contract (b) |
| Trade fair emails | Email address, country interest, version of the consent text, sign-up and confirmation times, a hashed confirmation code | Sending the newsletter you asked for | Consent (a) |
| Messages to us | Your email address or WeChat ID and what you write to us | Answering you and handling privacy requests | Legitimate interest (f); records of privacy requests: legal obligation (c) |
We do not use your data for advertising, we do not sell it and we do not build profiles of you.
Our database rejects text that looks like an email address or phone number in public profile fields, published request texts and reviews, so contact details do not end up in public text by mistake.
Who can see what on the platform
- Public visitors see exhibition information only.
- Signed-in service providers see the request text after our review, without your contact details.
- Signed-in exhibitors see the company, country, service categories, description and service record of approved providers who agreed to be shown.
- Contact details and our internal notes are visible only to you and to us.
When we introduce an exhibitor and a service provider to each other, we pass on the contact details needed for the introduction, and only to the party we introduce. From then on, that party handles the data under its own responsibility. We cannot recall information it has already received.
The table Who sees what on the About and data page shows the same overview.
Service providers we use
These companies process data on our behalf as processors. They are bound by data processing terms and may not use the data for their own purposes, except where stated below.
| Processor | What for | Location and safeguards |
|---|---|---|
| Cloudflare, Inc. | Hosting and delivering the website, DNS, protection against attacks, human check (Turnstile) | Global network, company in the USA. EU-US Data Privacy Framework and EU standard contractual clauses |
| Supabase (contracting party Supabase Pte. Ltd., Singapore) | Database, sign-in service, subscription function | Our database project is located in the EU (Frankfurt). Support and maintenance may take place outside the EU under the EU standard contractual clauses |
| Resend (Plus Five Five, Inc., USA) | Sending sign-in codes, subscription confirmations and trade fair emails; managing the mailing list and unsubscribes | Processing mainly in the USA. EU-US Data Privacy Framework and EU standard contractual clauses |
Other recipients:
- Service providers or exhibitors we introduce you to (see above).
- Google: our mailbox runs on Gmail, and Google processes the emails you send us under its own terms and privacy policy.
- Tencent, if you contact us on WeChat. Tencent processes those messages under its own terms.
- Cloudflare uses part of the Turnstile data as an independent controller to improve its bot detection; see the Turnstile privacy addendum.
- Authorities, only where the law requires us to share data.
Transfers outside the European Economic Area
Cloudflare and Resend are US companies, and Supabase's contracting party is in Singapore. Where personal data leaves the European Economic Area (EEA), the transfer relies on the EU-US Data Privacy Framework, in which Cloudflare and Resend take part, or on the EU standard contractual clauses in the providers' data processing terms. You can ask us for a copy of these safeguards.
Google and Tencent may also process data outside the EEA.
How long we keep data
We keep personal data only as long as we need it for the purposes above. The table shows how long that is.
| Data | Period |
|---|---|
| Account and platform profile | While your account exists. If you ask us to delete your account, we delete it together with your requests, profile, interest records and reviews. If you have not signed in for 24 months, we email you first and then delete the account |
| Exhibitor requests, including contact details | 24 months after the introduction ends |
| Internal review notes and review logs | 24 months |
| Security records of the sign-in service | 90 days |
| Sign-in session on your device | Until you sign out |
| Trade fair email subscription | Until you unsubscribe. We then keep the record of your consent for 3 years, to show that you had agreed |
| Unconfirmed subscriptions | The confirmation link expires after 24 hours. We delete unconfirmed sign-ups after 30 days |
| Emails and messages to us | 24 months |
| Records of privacy requests | 3 years |
| Backups | Overwritten on a rolling basis, following the backup cycle of our hosting plan |
| Delivery logs at Resend | Resend's default retention period |
| Data stored only in your browser | Until you delete it or clear your browser storage |
Information already passed to a party we introduced you to stays with that party. Copies in backups are removed when the backups expire.
Cookies and local storage
EuroExpo Desk sets no advertising or tracking cookies. We use your browser's local storage only for what the website needs to work or what you choose to save. Under Dutch law (Article 11.7a of the Telecommunications Act) this needs no consent, so there is no cookie banner.
| Name | Type | Purpose | Kept until |
|---|---|---|---|
| euroexpo-language | Local storage | Remembers the language you chose | You clear your browser storage |
| sb-hszznjpwfjtmovqildph-auth-token | Local storage, written by the sign-in library | Keeps you signed in | You sign out |
| euroexpo-desk-draft-v1, euroexpo-projects-v1 | Local storage | Drafts and projects you save on this device. They reach us only if you save them to your account or submit them | You delete them on the account page or clear your browser storage |
| euroexpo-inquiry-draft | Session storage | Keeps the request form filled in while you sign in or switch language | Deleted when read back, no longer used after 30 minutes, removed when you close the tab |
| __cf_bm, cf_clearance and similar | Cookies set by Cloudflare | Security checks against bots and attacks, only when Cloudflare's protection is triggered | Set by Cloudflare; __cf_bm expires after 30 minutes of inactivity |
The human check (Cloudflare Turnstile) reads browser and connection characteristics to tell people apart from bots. More in the Turnstile privacy addendum.
We do not use visitor statistics at the moment. If that changes, we will update this section first.
Trade fair emails
You join the list only after you opt in on the subscription page and click the link in the confirmation email. Signing in, submitting a request or applying as a service provider does not subscribe you.
We store your email address, your country interest, the version of the consent text, and when you signed up and confirmed. Resend sends the emails, manages the list and unsubscribes, and records whether an email was delivered or bounced.
Every email has an unsubscribe link. Unsubscribing withdraws your consent; it does not affect emails already sent.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have incorrect data corrected;
- have your data deleted;
- restrict processing, for example while we check a correction;
- receive the data you gave us in a machine-readable format (data portability), where processing is based on consent or contract;
- object to processing based on our legitimate interests;
- withdraw your consent at any time, without affecting processing before the withdrawal.
Some things you can do yourself: withdraw your display consent in the service provider workspace, unsubscribe through the link in any trade fair email, and delete projects saved to your account or on your device on the Account & supplier application page.
For anything else, email [email protected] from the address you registered with. We treat a request from that address as coming from you, so you do not need to send an identity document. If you write from another address, we will ask you to confirm from your registered address. The Help & contact page has a ready-made email for this.
Sometimes the law requires us to keep certain data, so we cannot delete it straight away. If so, we will tell you what we keep and why.
Complaints
If you think we handle your data incorrectly, please tell us first so we can put it right. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in the EU country where you live or work.
Required data, automated decisions and age
You need an email address to create an account. We need the fields marked as required in the request and profile forms to carry out our review; without them we cannot handle your request. No information is required by law.
We make no decisions about you based solely on automated processing. A person reviews requests, approves service providers and makes introductions. Provider profiles are ordered by a fixed formula based on ratings and the number of reviews; this has no legal or similarly significant effect on you.
EuroExpo Desk is meant for businesses and is not aimed at children.
Security
The connection to the website is encrypted (HTTPS). Private data such as requests and contact details sits in a part of the database that browsers cannot read directly; access runs through checked functions that return only data you are allowed to see. Administrator rights are checked on the server. No system is completely secure. If a data breach is likely to affect you seriously, we will tell you.
Changes to this policy
We update this policy when our services or the providers we use change, and we change the date at the top. If a change affects processing you consented to, we will ask for your consent again.
See also the terms of use and Help & contact.