Privacy Policy
Last updated: 25 July 2026
1. General information
This Privacy Policy explains how personal data is processed in connection with the activities carried out under the Eventguru brand, in particular when:
- using the following websites:
- https://www.eventguru.pl;
- https://www.eventgurub2b.com;
- contacting us by means of online forms, email, telephone, social media or other communication channels;
- taking part in a free initial consultation;
- requesting, negotiating or entering into a B2B proposal or agreement;
- using our event-related services or event consulting services;
- participating in events organised or co-organised by Eventguru;
- downloading materials made available by Eventguru;
- subscribing to our newsletter or receiving commercial communications;
- engaging in business, marketing or sales-related communications with us.
The Eventguru websites are intended primarily to present our B2B event organisation, event production and event consulting services.
Submitting an online form, sending an enquiry or taking part in a free initial consultation does not automatically result in the conclusion of a paid agreement.
2. Data Controller
The controller of personal data is:
PEPERONCINO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
with its registered office in Warsaw, Poland, operating under the Eventguru brand
Registered address:
ul. Mroczna 5A, unit 007A
01-456 Warsaw
Poland
National Court Register number, KRS: 0000679998
Tax identification number, NIP: 5272809907
Statistical number, REGON: 367344399
referred to in this Policy as the “Controller”, “Eventguru”, “we”, “us” or “our”.
For any questions concerning the processing of personal data, you may contact us:
- by email at kontakt@eventguru.pl;
- by post at the registered address stated above.
3. Categories of personal data we may process
Depending on the nature of your interaction with Eventguru, we may process the following categories of personal data:
- identification data, including your first name and surname;
- contact details, including your email address, telephone number and correspondence address;
- professional and business information, including:
- job title;
- position or role within an organisation;
- name of your employer or the organisation you represent;
- industry;
- business profile;
- professional contact details;
- information concerning an enquiry or planned project, including:
- type and purpose of the event;
- proposed date and location;
- anticipated number of attendees;
- budget or budget range;
- requested scope of services;
- organisational, technical, marketing or consulting requirements;
- information shared during consultations, meetings or correspondence;
- information relating to our business relationship, including:
- proposals;
- agreed arrangements;
- communication history;
- accepted quotations or budgets;
- purchase orders;
- agreements;
- acceptance records;
- settlements;
- complaints;
- project progress information;
- billing and accounting data, including:
- company name;
- business address;
- tax identification number;
- contact person details;
- information included in invoices and accounting documents;
- payment-related information;
- event attendee data, where required for the organisation or delivery of a particular event, including:
- first name and surname;
- professional contact details;
- company and job title;
- registration details;
- organisational preferences;
- information necessary for accommodation, transport or access to the event;
- newsletter and downloadable content data, including:
- first name;
- email address;
- company name;
- subscription date;
- source of the subscription;
- records of consent and withdrawal of consent;
- information concerning delivery, opening or link clicks where such tracking features are enabled;
- technical and online usage data, including:
- IP address;
- device type;
- browser type and version;
- operating system;
- approximate location derived from the IP address;
- date and time of access;
- pages visited;
- referral source;
- online identifiers;
- information collected through cookies and similar technologies;
- information obtained from publicly available sources, including company websites, public registers, business directories, professional platforms and professional social media profiles.
As a general rule, we do not ask you to provide special categories of personal data, such as information concerning health, political opinions, religious beliefs or sexual orientation.
Where certain information, such as accessibility, dietary or special assistance requirements, is necessary for the proper organisation of an event, we process it only to the extent required and on the basis of an appropriate legal ground.
4. Enquiries, contact forms and communications
When you contact us through an online form, by email, telephone, social media or another communication channel, we may process your personal data in order to:
- receive and handle your enquiry;
- respond to your message;
- understand your needs or the needs of the organisation you represent;
- assess whether we are able to provide the requested services;
- arrange a meeting or consultation;
- prepare a proposal;
- conduct further business discussions.
The legal basis for this processing is:
- Article 6(1)(b) GDPR, where processing is necessary to take steps at your request prior to entering into a contract and you are acting in your own name as a sole trader or other individual business operator;
- Article 6(1)(f) GDPR, where you act on behalf of a company, employer or other organisation. Our legitimate interests include conducting business communications, handling enquiries, identifying authorised contact persons, assessing potential cooperation and preparing proposals.
Providing personal data is voluntary. However, failure to provide the information necessary to respond or assess the enquiry may prevent us from replying or preparing a proposal.
5. Free initial consultations
Where you take part in a free initial consultation, we may process your personal data in order to:
- arrange and conduct the consultation;
- obtain a preliminary understanding of your needs;
- discuss the proposed event or organisational issue;
- assess the feasibility and potential scope of cooperation;
- outline possible directions or solutions;
- prepare a proposal or recommend further consulting services.
The legal basis for processing is:
- Article 6(1)(b) GDPR, where you act in your own name as an individual business operator and the consultation forms part of steps taken prior to entering into a contract;
- Article 6(1)(f) GDPR, where you represent another organisation. Our legitimate interests include conducting business discussions, assessing the needs of a potential client and preparing possible cooperation.
Participation in a free initial consultation does not create an obligation to enter into an agreement, either for you or for Eventguru.
6. Preparing and negotiating proposals
We process the personal data of persons involved in a proposal or negotiation process in order to:
- prepare a proposal, budget or quotation;
- determine the scope of services;
- conduct negotiations;
- verify the authority of representatives and contact persons;
- document agreed arrangements;
- preserve evidence concerning the negotiation process.
The legal basis for processing is:
- Article 6(1)(b) GDPR, where the prospective contracting party is an individual;
- Article 6(1)(f) GDPR, where the individual acts on behalf of an organisation. Our legitimate interests include preparing and negotiating an agreement with that organisation and documenting the arrangements made.
7. Entering into and performing agreements
We process the personal data of clients, representatives, employees, contractors and contact persons in order to:
- enter into and perform an agreement;
- manage the project;
- deliver event-related or consulting services;
- maintain operational communications;
- obtain approvals and confirmations;
- coordinate suppliers and subcontractors;
- settle and invoice the project;
- deal with changes, complaints and other requests;
- establish, pursue or defend legal claims.
The legal basis for processing is:
- Article 6(1)(b) GDPR, where the individual is a party to the agreement;
- Article 6(1)(f) GDPR, where the individual acts on behalf of a company or other organisation. Our legitimate interests include entering into and performing an agreement with that organisation, maintaining operational contact, documenting arrangements and protecting ourselves against claims;
- Article 6(1)(c) GDPR, where processing is necessary to comply with legal obligations, including accounting, tax and record-keeping obligations.
Providing data required for entering into and performing an agreement is voluntary, but failure to provide such data may prevent us from entering into or performing the agreement.
8. Event consulting services
When you use our paid or unpaid event consulting services, we may process information concerning:
- the organisation you represent;
- its business and event plans;
- the objectives of the proposed event;
- attendee requirements;
- the budget;
- the timeline;
- sales, marketing or international expansion plans;
- previous event experience;
- persons involved in the decision-making and delivery process.
We process this information in order to:
- carry out an analysis;
- prepare recommendations;
- develop a concept or action plan;
- assess suppliers, events, trade shows, venues or technical solutions;
- perform other agreed consulting services.
The legal basis is Article 6(1)(b) or Article 6(1)(f) GDPR, depending on whether the data subject is personally a party to the agreement or acts on behalf of another organisation.
9. Event organisation and attendee data
In connection with the organisation of events, we may process personal data relating to attendees, speakers, guests, representatives of partners, suppliers and event personnel.
The scope of data depends on the nature of the specific event and may include information necessary to:
- register and confirm attendance;
- provide access to the event;
- prepare name badges;
- provide organisational communications;
- prepare attendee lists;
- arrange accommodation or transport;
- provide catering;
- ensure technical support and security;
- prepare event materials;
- document the event, where an appropriate legal basis exists.
Depending on the structure of the project, Eventguru may act:
- as an independent controller;
- as a joint controller together with a client or partner;
- as a processor acting on behalf of a client.
The respective roles and responsibilities are determined for each event or set out in the relevant agreement.
Where Eventguru processes personal data solely on documented instructions from a client, the processing is governed by a data processing agreement.
10. Photography and video recordings at events
Photographs or video recordings may be taken during certain events.
Information about photography or recording, the intended use of the materials and the relevant legal basis should be provided before the event or, at the latest, upon entry to the event.
Images and recordings may be processed on the basis of:
- the consent of the person concerned, pursuant to Article 6(1)(a) GDPR;
- the legitimate interests of the controller, pursuant to Article 6(1)(f) GDPR, where the use is lawful, proportionate and does not override the rights and freedoms of the individual;
- other legal provisions permitting the use or publication of an image without consent, where applicable.
More detailed rules may be provided separately for a particular event by its organiser.
11. Accounting, payments and legal obligations
We process personal data included in invoices, accounting records, agreements and other settlement documents in order to:
- issue and receive invoices and other accounting documents;
- maintain accounting and tax records;
- settle payments;
- comply with legal obligations towards public authorities;
- recover outstanding amounts.
The legal basis is:
- Article 6(1)(c) GDPR, where processing is required by law;
- Article 6(1)(f) GDPR, where processing is necessary for our legitimate interests in managing payments and recovering debts.
12. Newsletter
If you subscribe to our newsletter, we process your email address and any other information you provide voluntarily in order to:
- send the newsletter;
- provide information about our publications, services, materials, events and business activities;
- manage your subscription and document your consent;
- analyse the effectiveness of messages where the system used enables us to measure delivery, message opening or link clicks.
The legal basis for processing is your consent pursuant to Article 6(1)(a) GDPR.
Commercial communications sent by electronic means are also subject to the requirements of the applicable Polish Electronic Communications Law.
You may withdraw your consent at any time:
- by using the unsubscribe link included in the message;
- by contacting us at kontakt@eventguru.pl.
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
Following an unsubscribe request, we may retain limited information on a suppression list in order to ensure that no further messages are sent to that address and to demonstrate that the request has been respected.
13. Downloadable materials
Where we provide a checklist, guide, report or other material in exchange for contact details, we process the data in order to:
- provide or deliver the requested material;
- support the technical delivery process;
- prevent abuse;
- send further communications only where the relevant consent has been obtained.
Downloading a material does not, by itself, constitute consent to receive a newsletter unless that purpose is presented clearly and the user provides a separate and voluntary consent.
The legal basis for processing information necessary to provide the material is Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the nature of the arrangement.
14. Business contacts and B2B marketing
We may process professional contact details of persons acting on behalf of businesses and organisations in order to:
- introduce Eventguru and the scope of our services;
- establish a business relationship;
- assess potential interest in cooperation;
- conduct individual B2B communications;
- continue previously initiated discussions;
- manage relationships with prospective and existing clients.
Such data may be obtained:
- directly from the individual;
- from the organisation the individual represents;
- from a publicly accessible company website;
- from public registers;
- from professional social media platforms;
- at conferences, trade shows and business meetings;
- from business partners, where the disclosure is lawful.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests include developing our B2B activities, establishing and maintaining business relationships and presenting our services to persons who may reasonably be professionally interested in them.
Reliance on legitimate interests under the GDPR does not remove the obligation to comply with separate rules governing direct marketing and commercial communications through particular channels.
You have the right to object at any time to the processing of your personal data for direct marketing purposes.
Once an objection has been received, we will stop using the data for direct marketing. We may retain limited information on a suppression list in order to respect the objection.
15. Customer relationship management system
We may use a customer relationship management system, including solutions provided by HubSpot, to manage business contacts, enquiries, proposals, communications and client relationships.
The CRM system may contain:
- contact details;
- company name and job title;
- source of the contact;
- communication and meeting history;
- enquiry details;
- meeting notes;
- status of potential cooperation;
- proposals and agreed arrangements;
- records of consent, unsubscribe requests and objections.
Depending on the purpose, the legal basis may be:
- Article 6(1)(b) GDPR;
- Article 6(1)(c) GDPR;
- Article 6(1)(f) GDPR;
- Article 6(1)(a) GDPR, where the relevant activity is based on consent.
The use of a CRM system does not mean that decisions producing legal or similarly significant effects are made solely by automated means.
16. Website analytics
Subject to the user’s consent, we may use analytics tools, including Google Analytics 4, in order to:
- measure website traffic and how users interact with the websites;
- identify the most frequently visited pages and content;
- analyse traffic sources;
- identify errors and usability issues;
- develop and improve the websites;
- assess the effectiveness of informational and marketing activities.
Optional analytics cookies and similar technologies are used after obtaining the relevant consent, unless a specific solution operates in a manner that does not require consent under applicable law.
The legal basis for processing personal data in connection with optional analytics is generally Article 6(1)(a) GDPR.
Further information about cookies, providers, purposes and storage periods is available in our Cookie Policy and in the consent management panel.
17. Cookies and consent management
The websites use cookies and similar technologies.
We may use Cookiebot to manage user choices and consents.
Cookies may be divided into the following categories:
- strictly necessary cookies;
- preference cookies;
- statistics or analytics cookies;
- marketing cookies.
Strictly necessary cookies may be used without consent to the extent permitted by applicable law.
Other categories are activated in accordance with the choices made by the user in the consent management panel.
Users may:
- accept all optional cookies;
- reject optional cookies;
- select individual categories;
- later change or withdraw their consent.
Detailed information about the use of cookies is provided in a separate Cookie Policy.
18. Server logs and website security
When you use the websites, the server may automatically record technical information such as:
- IP address;
- date and time of access;
- requested resource;
- browser type;
- operating system;
- server response code;
- error-related information.
This data is processed in order to:
- ensure the proper operation of the websites;
- diagnose errors;
- maintain security;
- prevent misuse and cyberattacks;
- investigate security incidents.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests include maintaining the security, availability and continuity of our websites and IT systems.
19. Social media
If you contact Eventguru through social media or interact with our profiles, we may process:
- information available on your profile;
- username;
- profile image;
- messages, comments and reactions;
- information concerning your interaction with our profile.
We process this data in order to:
- operate our profiles;
- respond to messages and comments;
- develop business relationships;
- present Eventguru’s activities;
- moderate content;
- protect against misuse;
- carry out lawful marketing activities.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests include communication, brand development, business relationship management and protection of our rights.
The operator of the relevant platform also processes personal data under its own terms and privacy policy as an independent controller.
In certain cases, Eventguru and the platform operator may act as joint controllers to the extent resulting from the functions provided by that platform.
20. Establishing, pursuing and defending legal claims
We may retain and use personal data where necessary to:
- establish the existence of a claim;
- recover outstanding amounts;
- handle a complaint;
- defend against a claim;
- preserve evidence concerning the conclusion and performance of an agreement;
- demonstrate compliance with legal obligations.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests include protecting Eventguru’s legal and financial position.
21. Recipients of personal data
We may disclose personal data to third parties supporting our business operations where this is necessary and lawful.
Recipients may include:
- hosting and IT infrastructure providers;
- website administrators and technical service providers;
- email and communication service providers;
- CRM providers, including HubSpot;
- analytics service providers, including Google;
- consent management platform providers, including Cookiebot;
- newsletter and marketing automation providers;
- online meeting, project management and document storage providers;
- accountants, accounting firms, tax advisers and auditors;
- law firms, professional advisers and insurers;
- banks and payment service providers;
- debt collection service providers;
- courier, postal and transport service providers;
- event venues, hotels, airlines and transport organisers;
- providers of technical equipment, catering, exhibition stands, scenography, event materials, staffing and other event-related services;
- photographers, videographers, graphic designers, speakers, hosts and other subcontractors involved in the project;
- business partners and co-organisers of a specific event;
- public authorities, courts and other authorised bodies where disclosure is required by law.
Processors acting on our behalf are required to protect personal data and process it in accordance with the applicable agreement and our documented instructions.
Additional recipients relevant to a specific event may be identified in a separate privacy notice.
22. Transfers of personal data outside the European Economic Area
Some technology providers used by us may have their registered offices, affiliated entities, servers or personnel outside the European Economic Area, including in the United States.
Where personal data is transferred outside the EEA, the transfer may take place only on the basis of a mechanism permitted by the GDPR, including:
- an adequacy decision adopted by the European Commission;
- participation by the recipient in the EU–US Data Privacy Framework, provided that the certification covers the relevant entity and category of data;
- standard contractual clauses approved by the European Commission;
- binding corporate rules;
- another lawful mechanism provided for in Chapter V of the GDPR.
Where required, additional safeguards appropriate to the nature of the transfer are applied.
Information concerning the applicable transfer mechanism or a copy of the relevant safeguards may be requested by contacting us at kontakt@eventguru.pl.
Documents may be redacted or limited where necessary to protect confidential business information and security.
23. Data retention periods
We retain personal data only for as long as necessary for the purpose for which it was collected.
As a general rule:
- enquiries and online forms that do not result in cooperation are retained for up to 24 months from the last meaningful interaction;
- free initial consultations that do not result in cooperation are retained for up to 24 months from the consultation or the last meaningful interaction;
- negotiations and proposals that do not result in an agreement are retained for as long as necessary to conduct the discussions and, as a rule, for up to 24 months after they end, unless a longer period is justified by the need to establish, pursue or defend claims;
- data connected with the performance of an agreement is retained for the duration of the agreement and subsequently until the expiry of the applicable limitation periods;
- accounting and tax records are retained for the period required by applicable law;
- event attendee data is retained for the period necessary to prepare, deliver and settle the event and to deal with potential claims, unless a client acting as controller specifies another retention period;
- data processed on the basis of consent is retained until the consent is withdrawn or the purpose ceases to exist, whichever occurs first;
- newsletter data is retained until consent is withdrawn or the newsletter service is discontinued;
- data used for direct marketing on the basis of legitimate interests is retained until a valid objection is raised or the purpose ceases to exist;
- records of withdrawn consent, unsubscribe requests or objections may be retained for as long as necessary to demonstrate compliance, protect against claims and prevent renewed use of the data for the challenged purpose;
- claim and dispute-related data is retained until the matter is finally resolved and the relevant limitation periods expire;
- server logs and security-related data are retained for the period resulting from system configuration, security requirements and the need to investigate incidents;
- cookie-related data is retained for the periods specified in the consent management panel and the Cookie Policy.
After the relevant retention period expires, data is deleted, anonymised or retained only where another valid legal basis applies.
24. Our legitimate interests
Where we rely on Article 6(1)(f) GDPR, our legitimate interests may include:
- conducting business communications;
- handling enquiries;
- establishing and maintaining relationships with clients, partners and suppliers;
- preparing and negotiating proposals;
- performing agreements entered into with organisations represented by the data subject;
- managing projects and contacts through a CRM system;
- conducting lawful B2B direct marketing;
- developing and promoting Eventguru’s business;
- managing social media profiles;
- maintaining the security of websites and systems;
- detecting and preventing misuse;
- conducting statistical analysis that does not require consent;
- establishing, pursuing and defending legal claims;
- documenting consents, objections, unsubscribe requests and business arrangements.
Before relying on a legitimate interest, we assess whether that interest is overridden by the rights and freedoms of the individual concerned.
25. Your rights
Depending on the legal basis and circumstances of the processing, you may have the following rights:
- the right of access, including the right to obtain confirmation as to whether we process your data and to receive a copy;
- the right to rectification, including correction of inaccurate data and completion of incomplete data;
- the right to erasure, in the circumstances specified in Article 17 GDPR;
- the right to restriction of processing, in the circumstances specified in Article 18 GDPR;
- the right to data portability, where processing is based on consent or a contract and is carried out by automated means;
- the right to object, where processing is based on Article 6(1)(e) or Article 6(1)(f) GDPR;
- the right to withdraw consent, where processing is based on consent;
- the right to lodge a complaint with a supervisory authority;
- the right to obtain information about safeguards used for transfers outside the EEA.
These rights are not absolute. In certain circumstances, applicable law may permit or require us to continue processing, for example in order to comply with a legal obligation or protect against claims.
To exercise your rights, please contact us at:
kontakt@eventguru.pl
We may request additional information where necessary to verify the identity of the person making the request. We will not request information that is excessive in relation to the verification purpose.
As a general rule, we respond within one month. Where a request is complex or we receive a high number of requests, the response period may be extended in accordance with the GDPR. We will inform you of the extension and the reasons for it.
26. Right to object
Objection to direct marketing
Where personal data is processed for direct marketing purposes, you may object to such processing at any time.
Once an objection has been received, we will no longer process the data for direct marketing purposes.
Objection based on your particular situation
Where we process personal data on the basis of legitimate interests for purposes other than direct marketing, you may object on grounds relating to your particular situation.
Following such an objection, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for the establishment, exercise or defence of legal claims.
27. Withdrawal of consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal of consent:
- does not affect the lawfulness of processing carried out before withdrawal;
- does not affect processing carried out on another valid legal basis;
- should be as easy as giving consent.
You may withdraw consent through the mechanism provided in connection with the relevant service or by contacting us at kontakt@eventguru.pl.
28. Complaints to the supervisory authority
If you believe that your personal data is being processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.
In Poland, the competent authority is:
President of the Personal Data Protection Office
Prezes Urzędu Ochrony Danych Osobowych
You may contact Eventguru first to give us an opportunity to explain or resolve the matter, but doing so is not a condition for lodging a complaint.
29. Automated decision-making and profiling
We may organise and segment business contacts on the basis of information such as:
- industry;
- company type;
- job title;
- area of interest;
- proposed event type;
- geographic market;
- stage of potential cooperation;
- previous contact with Eventguru.
This may be used to tailor communications, prioritise the handling of enquiries and manage business relationships.
We do not make decisions concerning individuals that are based solely on automated processing, including profiling, and that produce legal effects or similarly significantly affect them within the meaning of Article 22 GDPR.
30. Data security
We apply appropriate technical and organisational measures taking into account the nature of the data, the scope of our activities and the risks identified.
These measures are intended to protect personal data against:
- unauthorised access;
- accidental loss;
- unauthorised alteration;
- disclosure;
- destruction;
- use inconsistent with the purpose of processing.
Access to personal data is limited to persons who require it in order to perform their duties.
For security reasons, we do not publish detailed information about the safeguards used.
31. External links and third-party services
The websites may contain links to third-party websites, social media platforms, registration systems, maps, video content or other external services.
When you access such a service, your personal data may be processed by its operator in accordance with its own privacy policy.
Eventguru is not responsible for the privacy practices of independent third-party service providers.
32. Data relating to minors
Eventguru’s services are directed primarily at businesses, organisations and persons acting in a professional capacity.
We do not direct our websites or commercial communications to children.
Where personal data relating to a minor is required in connection with a specific event, the applicable processing arrangements, including any requirement to obtain consent from a parent or legal guardian, should be determined according to the nature of the event.
33. Changes to this Privacy Policy
We may update this Privacy Policy, in particular where:
- applicable law changes;
- the operation of the websites changes;
- new functions or technologies are introduced;
- service providers change;
- the scope of Eventguru’s business changes;
- further clarification is necessary.
The current version will be published on the websites together with the date of the latest update.
Material changes may also be communicated through the websites or another appropriate channel.
34. Contact details
For questions concerning this Privacy Policy, personal data processing or the exercise of your rights, please contact:
PEPERONCINO SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
ul. Mroczna 5A, unit 007A
01-456 Warsaw
Poland
Email: hello@eventgurub2b.com
KRS: 0000679998
NIP: 5272809907
REGON: 367344399