Effective date: 23 June 2026
Last updated: 23 June 2026
1. About this Privacy Policy
This Privacy Policy explains how MEGACAMPUS EVENTS L.L.C (the “Company”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data, and how individuals may exercise their rights in relation to such data.
This Policy applies to any website, subdomain, landing page, registration form, online platform, mobile application, personal account, event page, online broadcast, ticketing or payment interface, communication channel or other digital service that links to this Policy and identifies the Company as the controller (collectively, the “Services”). It also applies to related customer communications and participation in events organised or administered by the Company.
This Policy is intended to be a general policy for the Company’s Services and is not tied to any specific event, broadcast or landing page. A service-specific privacy notice, consent form or jurisdiction-specific supplement may provide additional information for a particular processing activity. If such specific notice conflicts with this Policy, the specific notice will apply to that activity to the extent of the conflict.
This Policy does not apply where another legal entity is expressly identified as the controller, or to employment-related processing governed by a separate internal notice.
2. Data Controller and Contact Details
The controller responsible for the processing covered by this Policy is:
Company: MEGACAMPUS EVENTS L.L.C
Trade licence: License No. 1444340
Registered address: Office SM1-268, ARAB BANK Building, Port Saeed, Plot 184-0, Dubai, United Arab Emirates
Makani: 32005 94654
Email: sales@megacampus.com
Role: Controller of personal data processed through the Services, unless otherwise stated
Questions, requests and complaints concerning personal data may be sent to the email address above. We may ask for information reasonably necessary to verify the requester’s identity and protect personal data from unauthorised disclosure.
3. Legal Framework and Processing Principles
We process personal data in accordance with applicable data protection laws, including Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data of the United Arab Emirates (the “UAE PDPL”) and, where applicable to a particular individual or processing activity, other relevant laws such as the EU General Data Protection Regulation (“GDPR”) or the UK GDPR.
We seek to process personal data lawfully, fairly and transparently; collect it for specific and clear purposes; limit collection to what is necessary; keep it accurate; protect it using appropriate technical and organisational measures; and retain it no longer than necessary for the relevant purposes and legal requirements.
Where consent is required, it will be requested through a clear affirmative action. Merely visiting a Service does not by itself constitute consent to processing that legally requires consent. Consent may be withdrawn as described in this Policy, without affecting processing carried out before withdrawal.
4. Personal Data We May Collect
Depending on how an individual uses the Services, we may collect the following categories of personal data:
- Identification and contact data: name, surname, email address, telephone number, country, city, postal or billing address, company, position and preferred language.
- Account and profile data: login credentials, user or membership ID, profile details, settings, preferences, subscription status and account activity.
- Order, contract and transaction data: selected products or packages, ticket and registration details, order history, payment status, transaction identifiers, invoices, refunds and related correspondence. Full payment card details are generally processed directly by authorised payment service providers and are not stored by the Company unless expressly stated.
- Event and participation data: event registrations, attendance, ticket category, seating, accreditation or badge information, participation in online broadcasts, questions submitted to speakers, networking preferences and other information needed to organise or deliver an event.
- Communications and support data: messages, requests, complaints, call or chat records, survey responses, feedback and information provided during customer support interactions.
- Technical and usage data: IP address, device and browser information, operating system, language and time zone, identifiers, log data, referral source, pages viewed, clicks, session data and other information generated through the use of the Services.
- Cookie and similar technology data: information collected through cookies, pixels, tags, local storage, software development kits and comparable technologies, subject to the choices available in the relevant cookie banner and Cookie Policy.
- Marketing and preference data: marketing consent status, communication preferences, campaign source, engagement with emails and advertisements, and inferred interests used for audience segmentation where legally permitted.
- Content and media data: content submitted through the Services, testimonials, photographs, audio or video recordings, and event media in which an individual may appear, where collection and use are permitted and appropriately notified.
- Business contact data: professional contact information of representatives, agents, contractors, suppliers, sponsors, speakers, partners and other business counterparties.
- Compliance and security data: records needed for identity checks, fraud prevention, access control, incident investigation, sanctions or regulatory screening, and the establishment, exercise or defence of legal claims.
We do not intentionally request sensitive personal data unless it is genuinely necessary for a specific purpose and permitted by law. For example, accessibility, health or dietary information may be collected for an event only where needed and with an appropriate legal basis. Individuals should not provide sensitive data unless specifically requested.
5. Sources of Personal Data
We may obtain personal data:
- directly from the individual, including through forms, registrations, purchases, accounts, surveys, messages and event participation;
- automatically when the individual uses the Services, including through server logs, cookies and similar technologies;
- from authorised representatives, agents, employers or other persons acting on behalf of the individual;
- from ticketing platforms, payment providers, event venues, organisers, sponsors, speakers, partners and service providers involved in delivering the relevant product, service or event;
- from affiliates within the Megacampus group where sharing is lawful and necessary for a stated purpose;
- from social media platforms and other third-party services when the individual interacts with our pages, advertisements or integrations, subject to the settings and policies of those services; and
- from publicly available sources or lawful business databases where permitted.
6. Purposes and Legal Bases for Processing
The legal basis used for a particular activity depends on the applicable law and the context. We will not rely on a legal basis that is unavailable under the law governing that processing. The main purposes and bases are described below.
Purpose:Operating the Services; creating and administering accounts; registering users for events, broadcasts and programmes; providing tickets, access, memberships, digital content and customer support.
Typical legal basis:Performance of a contract; steps requested before entering into a contract; consent where required.
Purpose:Processing orders, payments, invoices, refunds and related records.
Typical legal basis:Performance of a contract; compliance with legal, tax, accounting and financial obligations.
Purpose:Sending service, transactional and organisational communications, including confirmations, access links, schedule changes, reminders, security notices and responses to requests.
Typical legal basis:Performance of a contract; steps requested by the individual; compliance with legal obligations; legitimate interests where permitted.
Purpose:Organising and administering online and in-person events, including access control, seating, accreditation, networking and safety.
Typical legal basis:Performance of a contract; consent where required; protection of individuals and property; compliance with legal obligations.
Purpose:Improving the Services, understanding usage, troubleshooting, testing, research, statistics and product development.
Typical legal basis:Consent for non-essential cookies or tracking where required; legitimate interests where permitted; anonymised or aggregated analysis.
Purpose:Personalising content, recommendations and user experience.
Typical legal basis:Consent where required; performance of requested services; legitimate interests where permitted.
Purpose:Sending marketing communications about products, events, services and special offers.
Typical legal basis:Prior consent where required. In limited cases, another basis may be used only where expressly permitted by applicable law and with a clear right to opt out.
Purpose:Protecting accounts, systems, users and the Company; preventing fraud, abuse, cyber incidents and unauthorised access; enforcing terms and policies.
Typical legal basis:Compliance with legal obligations; establishment, exercise or defence of legal claims; protection of rights and interests; legitimate interests where permitted.
Purpose:Complying with legal and regulatory requirements and responding to lawful requests from courts, regulators and authorities.
Typical legal basis:Compliance with legal obligations; public interest or lawful authority requirements; legal claims.
Purpose:Managing corporate operations, audits, restructuring, financing, merger, acquisition or transfer of business assets.
Typical legal basis:Compliance with legal obligations; legitimate interests where permitted; contractual necessity; appropriate confidentiality and transfer safeguards.
7. Marketing Communications
Service or transactional messages are different from marketing communications. We may send messages necessary to complete a registration or purchase, provide access, notify users of material service or event changes, respond to requests, protect accounts or comply with legal obligations even where the individual has opted out of marketing.
Marketing emails, messages or calls will be sent only where permitted by applicable law. Where consent is required, marketing consent will be requested separately and will not be a condition of registering for a free event or receiving a service that does not require such marketing.
An individual may stop marketing communications at any time by using the unsubscribe link or other opt-out mechanism in the message, changing available account preferences, or contacting us at sales@megacampus.com. We may retain limited information on a suppression list to ensure that the opt-out is respected.
8. Cookies and Similar Technologies
The Services may use cookies and similar technologies for strictly necessary functions, security, preferences, analytics, performance, personalisation and advertising. Non-essential technologies will be used only in accordance with applicable law and the choices presented through the relevant consent mechanism.
More detailed information, including available categories, providers, purposes and storage periods, should be provided in the Cookie Policy and cookie settings available on the relevant Service. Users may change their choices through those settings, although disabling strictly necessary technologies may prevent parts of the Services from functioning.
9. How We Share Personal Data
We do not sell personal data. We may disclose personal data only where necessary for the purposes described in this Policy and subject to applicable law, including to:
- hosting, cloud, cybersecurity, CRM, customer support, email, communications, analytics, advertising, software and IT service providers;
- payment service providers, banks, accounting platforms and fraud-prevention providers;
- ticketing platforms, event venues, co-organisers, production teams, access-control providers, travel or logistics providers, and other parties needed to deliver an event or service;
- affiliates within the Megacampus group for centralised administration, technology, customer support, marketing, finance, compliance and delivery of products or events, where lawful and necessary;
- professional advisers, auditors, insurers, banks and financing counterparties;
- courts, regulators, law-enforcement bodies, tax authorities and other public authorities where disclosure is required or lawfully requested;
- parties to an actual or proposed corporate transaction, reorganisation, financing, merger, acquisition or sale of assets, subject to appropriate confidentiality measures; and
- other recipients where the individual has requested or expressly consented to the disclosure.
Service providers acting as processors are expected to process personal data only on documented instructions, apply appropriate security measures and comply with applicable contractual and legal requirements. Some recipients, such as payment providers, ticketing platforms, social networks, venues or co-organisers, may act as independent controllers for their own processing. Their privacy notices may also apply.
10. International Transfers
The Company is established in the United Arab Emirates, and the Services may use providers, partners and infrastructure located in other countries. Personal data may therefore be transferred to, accessed from or stored in jurisdictions whose data protection laws differ from those of the individual’s country.
Where required, we use one or more lawful transfer mechanisms and safeguards, such as transfers to jurisdictions recognised as providing an adequate level of protection, contractual clauses and data protection agreements, explicit consent, or transfers necessary for the performance of a contract, legal claims or other grounds permitted by applicable law. Where the GDPR or UK GDPR applies, appropriate transfer safeguards may include the relevant standard contractual clauses and, where required, supplementary measures.
Information about applicable safeguards for a particular transfer may be requested by contacting us, subject to confidentiality, security and legal restrictions.
11. Retention of Personal Data
We retain personal data only for as long as reasonably necessary for the relevant purposes, taking into account the nature of the data, the relationship with the individual, legal and contractual requirements, limitation periods, security needs and the establishment, exercise or defence of claims. Typical retention criteria are set out below; a longer or shorter period may apply where required or permitted by law.
Category:Accounts and profiles
Typical retention period or criterion:For the life of the account and normally up to 3 years after closure or the last meaningful interaction, except that transaction and compliance records may be kept longer.
Category:Event registrations, free broadcasts and general enquiries not resulting in a purchase
Typical retention period or criterion:Normally up to 3 years after the event or last interaction, unless a shorter period is appropriate or a longer period is needed for a claim, complaint or legal requirement.
Category:Contracts, purchases, invoices, refunds and accounting records
Typical retention period or criterion:For the contract term and the legally required commercial, tax and accounting period, normally up to 7 years after the relevant transaction or termination, or longer where required.
Category:Customer support, complaints and legal claims
Typical retention period or criterion:Until resolution and normally up to 3 years thereafter, or for the duration of any applicable claim, investigation or proceeding.
Category:Marketing data and consent records
Typical retention period or criterion:Until consent is withdrawn, the individual opts out, or the data is no longer needed. Evidence of consent and a minimal suppression record may be retained for the period needed to demonstrate compliance and respect the opt-out.
Category:Technical logs and security data
Typical retention period or criterion:Normally up to 12 months, unless longer retention is needed to investigate an incident, prevent fraud, protect the Services or comply with law.
Category:Cookies and similar technologies
Typical retention period or criterion:For the period stated in the relevant Cookie Policy or cookie settings, subject to user choices and applicable law.
When retention is no longer justified, personal data will be securely deleted or anonymised, unless continued storage is required by law or necessary for legal claims. Backup copies may remain for a limited period until securely overwritten in accordance with standard backup cycles.
12. Security and Personal Data Breaches
We use technical and organisational measures appropriate to the nature, scope and risks of the processing. These may include access controls, authentication, role-based permissions, encryption or pseudonymisation where appropriate, logging, backups, security monitoring, vendor assessment, confidentiality obligations, staff awareness measures and incident-response procedures.
No transmission or storage method is completely secure. Individuals are responsible for keeping account credentials confidential and should notify us promptly if they suspect unauthorised access. Where a personal data breach creates a risk requiring notification, we will notify the relevant authority and affected individuals in accordance with applicable law.
13. Individual Rights
Subject to applicable law, identity verification and lawful exceptions, an individual may have the right to:
- receive information about the categories of personal data processed, the purposes, recipients, retention criteria and international transfer safeguards;
- request access to and a copy of personal data;
- request correction or completion of inaccurate or incomplete data;
- request deletion of personal data where the relevant legal conditions are met;
- request restriction or suspension of processing;
- object to or stop processing, particularly processing for direct marketing;
- withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal;
- receive certain data in a structured, commonly used and machine-readable format and request its transfer where legally and technically applicable;
- object to a decision based solely on automated processing that produces legal or similarly significant effects, and request human review where applicable; and
- submit a complaint to the competent data protection authority.
Requests may be sent to sales@megacampus.com. We will respond within the period required by applicable law. Where the GDPR or UK GDPR applies, this is normally within one month, subject to lawful extension for complex or numerous requests. Rights may be limited where necessary to protect the rights of others, information security, legal privilege, confidential business information, investigations, legal claims or compliance with other laws.
14. Automated Processing and Profiling
We may use automated tools for functions such as fraud detection, security monitoring, audience segmentation, content recommendations and service analytics. We do not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. If such processing is introduced, we will provide any additional notice, obtain consent where required, and implement safeguards including the opportunity for human review where applicable.
15. Children and Minors
The Services are generally intended for adults and are not directed to persons under 18, unless a particular Service expressly allows participation by minors and provides appropriate conditions. We do not knowingly collect personal data from a minor without the involvement or consent of a parent or legal guardian where required. If we learn that personal data has been collected from a minor in circumstances not permitted by law, we will take reasonable steps to delete or otherwise lawfully address it.
16. Third-Party Services and Links
The Services may contain links to or integrations with third-party websites, payment pages, ticketing services, social networks, applications or platforms. We do not control the independent privacy practices of those third parties. Individuals should review the privacy notices and settings of the third-party service before providing personal data or using an integration.
17. Changes to this Policy
We may update this Policy to reflect changes in the Services, processing activities, providers, legal requirements or business practices. The current version will be published through the relevant Services with an updated “Last updated” date. Where required by law or where a change materially affects individuals, we will provide an additional notice and obtain renewed consent if necessary.
18. Contact and Complaints
For privacy questions, requests to exercise rights, withdrawal of consent or complaints, please contact:
MEGACAMPUS EVENTS L.L.COffice SM1-268, ARAB BANK Building, Port Saeed, Plot 184-0, Dubai, United Arab Emirates
Makani: 32005 94654
Email:
sales@megacampus.comWe encourage individuals to contact us first so that we can review and address the issue. An individual may also complain to the competent data protection authority in the relevant jurisdiction, including the competent authority in the United Arab Emirates or, where applicable, the supervisory authority in the individual’s country of residence, work or the alleged infringement.