Privacy Policy
Last updated:
Last updated: 16 July 2026
Introduction
Human Driven AI Summit ("Site") is operated by WitUp Ltd, a company registered in England and Wales with registered office at 71-75 Shelton Street Covent Garden London WC2H 9JQ, London, United Kingdom ("Controller", "we"). This Privacy Policy describes how we process personal data collected through humandriven-ai.com and related services, in compliance with Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018.
By accessing the Site or using our services you accept the practices described below. If you disagree, please do not use the Site.
1. Data controller
| Item | Detail |
|---|---|
| Legal entity | WitUp Ltd |
| Registered office | 71-75 Shelton Street Covent Garden London WC2H 9JQ, London, United Kingdom |
| Registration | 16572774 — Companies House (England & Wales) |
| Privacy email | segreteria@humandriven-ai.com |
| General email | summit@humandriven-ai.com |
To exercise your GDPR rights write to segreteria@humandriven-ai.com. Response within 30 days (extendable to 60 in complex cases, with prior notice).
2. Categories of data collected
2.1 Data provided directly by the user
- Identification data: first name, surname, professional role
- Contact data: email address, phone number (if provided), company
- Message contents: texts submitted via Contact forms, speaker applications, sponsor/partner enquiries, newsletter subscriptions
- Ticket purchase data: attendee names, billing data (payment data is processed directly by Stripe and never stored on our systems)
- Press/media-partner accreditation and partnership requests: outlet/organisation, role, contacts, request content
- Named badges and check-in: name, company/outlet, access category, entry time (QR scan)
- HDAI Network app (opt-in): professional profile, interests, 1:1 messages, meeting requests
- Resource / media-kit downloads: email, name, organisation, role
2.2 Automatically collected data
- Technical navigation data: IP address (anonymised where possible), browser type, OS, language, timezone, pages visited, session duration, referrer
- Interaction data: CTA clicks, scroll depth, site path (via Google Analytics 4 with anonymised IP)
- Technical and analytics cookies: see Cookie Policy
2.3 Data received from third parties
In specific cases we may receive data from:
- Stripe (payment outcomes: confirmation, refunds, disputes — never full card data)
3. Purposes of processing and legal basis
| Purpose | GDPR legal basis | Retention |
|---|---|---|
| Respond to form enquiries | Art. 6(1)(b) — pre-contractual measures | 24 months from last contact |
| Newsletter subscription | Art. 6(1)(a) — consent | Until consent withdrawal |
| Speaker / sponsor application | Art. 6(1)(b) — application handling | 36 months after event |
| Aggregate statistics (GA4) | Art. 6(1)(f) — legitimate interest | 14 months (GA4 default) |
| Security and fraud prevention | Art. 6(1)(f) — legitimate interest | 12 months access logs |
| Ticket sales, badges and event check-in | Art. 6(1)(b) — contract performance | 24 months after event (invoicing: 10 years) |
| Press / media-partner accreditation | Art. 6(1)(b) — pre-contractual measures | 36 months after event |
| Partnership and convention requests | Art. 6(1)(b) — pre-contractual measures | 36 months after event |
| HDAI Network app (profile, chat, meetings) | Art. 6(1)(a) — consent (opt-in) | Until profile deletion or 12 months after event |
| Promotional communications (mailing) | Art. 6(1)(a) — consent | Until withdrawal (unsubscribe link in every email) |
| Form protection (Google reCAPTCHA) | Art. 6(1)(f) — legitimate interest | Per Google policy |
| Tax and accounting compliance | Art. 6(1)(c) — legal obligation | 10 years (UK tax law) |
Newsletter sign-up requires express consent via a dedicated checkbox; for evidentiary purposes we record the date, IP address and user-agent of the consent.
We do not use your data for automated profiling. We do not make solely automated decisions producing legal effects on the data subject (Art. 22 GDPR).
4. Processing methods
Data is processed with manual and electronic tools following principles of:
- Lawfulness, fairness, transparency towards the data subject
- Purpose limitation (collection only for specified purposes)
- Data minimisation (only necessary data)
- Accuracy (kept up-to-date and correct)
- Storage limitation (kept for the minimum time necessary)
- Integrity and confidentiality (technical and organisational protection)
4.1 Security measures in place
- TLS 1.3 encryption in transit across the site (valid HTTPS certificate)
- At-rest encryption on database and storage (AES-256 via Supabase + Vercel)
- Multi-factor authentication (MFA) for administrative access
- Row Level Security on database tables
- Daily automated backups with 30-day retention
- Access logs and audit trail for administrative operations
- Periodic penetration testing and dependency updates
5. Data recipients and external processors
Your data may be processed by:
- Employees and collaborators of WitUp Ltd, authorised and trained
- Technical service providers (external processors under Art. 28 GDPR):
- Vercel Inc. (hosting, USA — Standard Contractual Clauses 2021/914 in force)
- Supabase Inc. (database and storage, EU region Frankfurt)
- Resend (transactional email, USA — SCC)
- Google LLC (Analytics 4 + reCAPTCHA, USA — SCC + Privacy Shield successor)
- Stripe Payments Europe Ltd (ticket payments, IE/USA — SCC; PCI-DSS certified)
- Google Workspace (@humandriven-ai.com mailboxes, EU/USA — SCC)
- Meta Platforms / TikTok (campaign measurement pixels, active ONLY with cookie-banner consent)
- Competent authorities (only on legal request or court order)
- Professional advisors (accountants, lawyers) bound by professional secrecy
We do not sell your data to third parties. We do not share data with advertising brokers.
6. Transfers outside the EEA
Some providers (Vercel, Resend, Google) may transfer data outside the European Economic Area. In such cases we apply:
- Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914)
- Transfer Impact Assessments (TIA) where required
- Supplementary measures (end-to-end encryption, pseudonymisation)
7. Data subject rights (Art. 15–22 GDPR)
You have the right to:
- Access (Art. 15) — obtain confirmation of processing and a copy of the data
- Rectification (Art. 16) — correct inaccurate or incomplete data
- Erasure / "right to be forgotten" (Art. 17) — request data deletion (subject to legal retention obligations)
- Restriction (Art. 18) — restrict processing in specific cases
- Portability (Art. 20) — receive your data in a structured, readable format
- Objection (Art. 21) — object to processing based on legitimate interest or marketing
- Withdraw consent (Art. 7.3) — at any time, without affecting the lawfulness of prior processing
- Lodge a complaint with the supervisory authority:
How to exercise: send a written request to segreteria@humandriven-ai.com indicating the right you intend to exercise. Response within 30 days.
8. Data retention
Retention periods are listed in the table at §3. At expiry, data is deleted or irreversibly anonymised, except where law requires longer retention (e.g. tax).
9. Minors
The Site is not intended for minors under 16. We do not knowingly collect data from minors without the consent of the parental responsibility holder. If you become aware that a minor has provided us data without consent, write to segreteria@humandriven-ai.com for immediate removal.
10. AI-generated content
Some editorial content on this site — notably the "AI & News" articles and their cover images — is produced with the assistance of generative artificial intelligence systems, in accordance with Article 50 of Regulation (EU) 2024/1689 (AI Act). Each article carries a label indicating its nature: "AI-assisted · human editorial review" where the content has been verified by an editor (of which we keep a record), or "AI-generated content" where it was published through an automated pipeline without individual review. AI-generated images are labelled accordingly. Editorial responsibility lies with The Patent ® Magazine (WitUp Ltd, London). AI systems are not used to make decisions with legal effects on users nor for automated profiling (Art. 22 GDPR). Content reports: segreteria@humandriven-ai.com.
11. Changes to this Policy
We reserve the right to update this Policy at any time. Changes take effect from the date of publication on this page. For substantial changes (new purposes, new recipients, different legal bases) we will notify you via email if you are subscribed to the newsletter, or via prominent notice on the Site.
12. Privacy contacts
| Channel | Contact |
|---|---|
| Dedicated privacy email | segreteria@humandriven-ai.com |
| General email | summit@humandriven-ai.com |
| Postal address | WitUp Ltd — 71-75 Shelton Street Covent Garden London WC2H 9JQ, London, UK |
| Contact page | /en/contatti |
