Privacy Policy
Last updated: 21 July 2026
Who we are
This site is operated by Bindi to Brera, organizer of the Bindi to Brera trade event taking place 19–21 February 2027 at Superstudio Maxi, Milan, Italy (“we”, “us”). For the purposes of the EU General Data Protection Regulation (GDPR) and the Italian Data Protection Code, we are the data controller for the personal data described below.
[CONFIRM before publishing]: registered legal entity name, registered address, and VAT number to appear here once the organizing entity is formally registered. Contact us at privacy@binditobrera.it with any privacy question in the meantime.
What data we collect
We collect different data depending on how you use the site:
- Account & profile data: name, email address, company, country, and role (visitor, buyer, exhibitor, sponsor, partner, or media) when you sign up.
- Exhibitor & buyer applications: company details, product categories, materials, certifications, and region for exhibitor profiles; sourcing interests for buyer profiles.
- Uploaded documents: certification documents, product images, and spec sheets you upload as part of an exhibitor profile or product listing.
- Ticket & visitor registration data: name and email address for free timed-entry tickets, and a unique QR code used for on-site check-in.
- Meeting requests: messages and scheduling data exchanged between buyers and exhibitors through the matchmaking system.
- Sponsorship & partnership inquiries: company and contact details you submit through the Sponsors or Partners inquiry forms.
- Technical data: IP address and basic request metadata, used only to enforce rate limits against automated abuse (see “Security” below), not for tracking or profiling.
- Analytics data (only with your consent): if you accept the cookie banner and Google Analytics (GA4) is active, anonymized usage statistics. If you decline, no analytics script loads at all. See our Cookie Policy.
We do not collect payment card data: Bindi to Brera tickets are free of charge.
Why we process your data, and the legal basis
- To perform our contract with you: creating your account, processing an exhibitor/buyer/sponsor/partner application, booking a free ticket, arranging a meeting, or checking you in at the event (Art. 6(1)(b) GDPR).
- Legitimate interest: preventing fraud and automated abuse of the free-ticket system (rate limiting), maintaining the security of the platform, and improving the site based on aggregated, non-identifying usage patterns (Art. 6(1)(f) GDPR).
- Consent: optional analytics cookies (Art. 6(1)(a) GDPR). You can withdraw this consent at any time; see the Cookie Policy.
- Legal obligation: where we must retain or disclose data to comply with Italian or EU law (e.g. venue safety/occupancy records).
Who we share data with
We use a small number of processors to run the platform. We do not sell your data.
- Supabase (database, authentication, and file storage): hosted in the EU (eu-west-1, Ireland).
- SendGrid (Twilio Inc.): sends transactional email only: ticket QR codes, meeting-request notifications, and application confirmations. SendGrid is not used for marketing email. As a US-based processor, transfers are safeguarded under Standard Contractual Clauses.
- Google Analytics (GA4): only loaded after you explicitly accept analytics cookies; see the Cookie Policy for details and how to opt out.
Exhibitor and buyer profile information marked as public (e.g. an approved exhibitor’s company name, category, and description) is visible to other registered buyers inside the platform’s directory, as part of the matchmaking service you signed up for.
International transfers
Our primary database, authentication, and file storage run in the EU (Ireland). Where a processor is based outside the EEA (currently: SendGrid, once configured), we rely on the EU Standard Contractual Clauses or an equivalent adequacy mechanism to safeguard the transfer.
How long we keep your data
- Account and profile data: for as long as your account is active, plus a reasonable period afterward for legal and accounting purposes.
- Ticket/visitor registration data: retained through the event and for a limited period afterward for reporting and safety-record purposes, then deleted or anonymized.
- Sponsorship/partnership inquiries that do not proceed: deleted after a reasonable follow-up period if no relationship is established.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request erasure of your data (“right to be forgotten”)
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) or your local EU supervisory authority
To exercise any of these rights, email privacy@binditobrera.it. We aim to respond within one month.
Children
This platform is intended for business and adult event use. We do not knowingly collect data from children under 16.
Changes to this policy
We may update this policy as the platform evolves. Material changes will be reflected by updating the “Last updated” date above.