Skip to content
EXHIBITIONDNA

Privacy & GDPR

Understand how information is used.

1. Who is responsible?

ExhibitionDNA is operated by We are the Medium, Noida, India. Contact support@exhibitiondna.com for privacy questions. We determine how website enquiries, account administration and service-security information are used.

When an exhibiting company collects visitor details in its workspace, that company generally acts as the controller. ExhibitionDNA processes those records on its instructions. That company must provide its own visitor notice and determine a lawful basis. The applicable service agreement and data processing agreement must define the parties’ responsibilities.

2. Information processed

  • Enquiries: name, email, optional phone number, company, selected plan and message.
  • Accounts and staff profiles: sign-in email, role, company membership and profile information supplied by administrators.
  • Visitor records: contact details, company, designation, product interests, notes, exhibition source and recorded channel permissions.
  • Files and activity: uploaded images, catalogues, ticket details, QR activity, audit events and delivery status where enabled.
  • Security data: sign-in records and request-limit identifiers used to protect the service.

Do not submit sensitive personal information or information about children through enquiry or lead forms. Camera and image-recognition behaviour depends on the capture feature and any configured provider; review the collection notice before supplying an image.

3. Why information is used

We use enquiry details to respond to requests; account information to provide and administer workspace access; and security records to protect the service. Where GDPR applies, the relevant basis may be steps requested before a contract, performance of a contract, a legal obligation, or a legitimate interest balanced against the individual’s rights. Marketing based on consent requires a separate, valid choice. Each exhibiting company must establish and explain the basis for its own lead processing.

4. Marketing choices

Submitting an enquiry, sharing a business card or downloading a catalogue does not by itself grant marketing permission. Where consent is relied on, it must be freely given, specific, informed and affirmative. Keep separate choices for email, SMS and WhatsApp, record the notice version and choice, and make withdrawal as easy as giving consent. Withdrawing consent does not invalidate earlier lawful processing.

5. Access, providers and transfers

Authorised company users may access their workspace according to their roles. Hosting, storage and email providers may process information to deliver the service. Company-configured messaging or CRM services receive data when those features are used. Confirm the actual production provider list and processing locations with support; no EU-only hosting promise is made here.

Where GDPR restricts an international transfer, an appropriate legal mechanism and any necessary supplementary safeguards must be established before the transfer. Provider contracts and a data processing agreement must be reviewed for the live deployment.

6. Retention and deletion

Information should be kept only for the purpose for which it is needed and any applicable legal obligations. Tenant lead retention can be configured; scheduled cleanup depends on that setting and the maintenance service being enabled. This does not establish a universal deletion deadline for enquiries, files, audit records or backups. Ask support or the collecting company for the applicable retention period. The production retention and backup-deletion schedule must be confirmed before launch.

7. Your rights

Where GDPR applies, you may request access, correction, deletion, restriction or portability when the relevant conditions are met, and object to processing. You can object to direct marketing and withdraw consent. Rights are subject to applicable exceptions.

Email support with “Privacy request”, the company or event involved and enough information to locate your record. Do not send identity documents unless a secure verification step is requested. For company-controlled lead data, we will direct the request to the responsible company and assist as appropriate. GDPR requests generally require a response within one month; permitted extensions must be explained. You may complain to the relevant data-protection supervisory authority.

8. Security and incidents

The application uses role-based access, tenant-scoped data access and audit records. Operational protection also depends on hosting, configuration, monitoring and staff practices. No system is risk-free. Report suspected exposure promptly to support without including passwords or sign-in tokens. Breaches must be assessed and notified where applicable law requires.

9. Cookies and changes

Read the cookie notice for essential sign-in storage. Material changes to this policy should be published with an updated date and communicated where required.

GDPR guidance for exhibiting companies

  • Show your collection notice before visitors submit information.
  • Collect only fields needed for the stated purpose.
  • Separate optional marketing permissions from catalogue or contact access.
  • Restrict access, review exports and honour objections and withdrawals.
  • Set retention periods and test the deletion process.
  • Confirm processor contracts, transfer safeguards and incident procedures.

Guidance: European Commission: individual rights · EDPB: lawful processing and consent.