Privacy Policy

Last updated: May 25, 2026

This Privacy Policy explains how Exiwik (“Exiwik”, “we”, “us”) collects, uses, and protects personal data when you use our exhibition management platform (the “Service”). It applies to organisers, exhibitors, and visitors who use the Service.

1. Information we collect

  • Account information — name, email address, and profile details you provide when registering, and details such as company name and industry for organiser and exhibitor accounts.
  • Visitor registration data — when visitors register for an event, we process their name, email address, phone number, and any other details the organiser requests, on behalf of that organiser.
  • Payment information — when organisers purchase a subscription, payment is handled by our payment processors. We receive confirmation and limited transaction details, but we do not store full card numbers.
  • Usage data — technical information such as device, browser, IP address, and how you interact with the Service, used to operate and improve it.

2. How we use information

We use personal data to:

  • provide, maintain, and improve the Service;
  • create and manage accounts and authenticate users;
  • process event registrations and enable lead capture for exhibitors;
  • process payments and manage subscriptions;
  • send transactional communications such as confirmations and important notices;
  • protect the security and integrity of the Service and comply with legal obligations.

3. Legal bases

Where data protection law such as the UK or EU GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Service you request), legitimate interests (to operate, secure, and improve the Service), consent (where required, for example for certain communications), and compliance with legal obligations.

4. Roles and responsibilities

For account data, Exiwik acts as a data controller. For visitor registration data collected through an event, the organiser is the controller and Exiwik acts as a processor, handling that data on the organiser’s instructions. Organisers are responsible for having a lawful basis to collect visitor data and for providing their own privacy information to visitors.

5. Sharing and service providers

We share personal data with trusted service providers who help us run the Service, including providers for cloud hosting and database, transactional email delivery, and payment processing. These providers process data on our behalf under appropriate agreements. We do not sell personal data. We may disclose data where required by law or to protect our rights and the safety of users.

6. Cookies

We use cookies and similar technologies that are necessary to operate the Service, such as keeping you signed in, and to understand usage so we can improve it. You can control cookies through your browser settings, though disabling some may affect functionality.

7. Data retention

We retain personal data for as long as your account is active or as needed to provide the Service, and afterwards only as required to comply with legal obligations, resolve disputes, and enforce our agreements. Visitor data is retained according to the organiser’s instructions and event needs.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, or port your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at support@exiwik.com. If your data is held by an organiser as controller, we may direct your request to that organiser.

9. International transfers

The Service is operated with infrastructure that may be located in different countries, so your data may be transferred to and processed outside your country of residence. Where required, we use appropriate safeguards for such transfers.

10. Security

We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 18.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice through the Service or by email. The “last updated” date above indicates when this policy was last revised.

13. Contact

For privacy questions or to exercise your rights, contact us at support@exiwik.com.

See also our Terms of Service.