Last updated 31 March 2026

Privacy Policy

This policy explains what personal data BREATHE x JEPE 2026 collects, why we collect it, how long we keep it, and how you can exercise your rights under the GDPR.

Who controls your data

The data controller for this website and the event registration process is the BREATHExJEPE 2026 organising committee. The site operates at https://breatheconference.eu/.

If you have a privacy question, want a copy of your data, or want us to correct or delete information we hold, email contact@breatheconference.eu.

What we collect

Depending on how you use the site, we may collect:

  • Identity and contact details such as your name, email address, phone number, city, country, institution, and professional registration details.
  • Registration details such as attendance category, sponsor promo code, and any dietary, accessibility, or other special requirements you choose to provide.
  • Message content you send through the public contact form or by replying to conference emails.
  • Technical and security data such as server logs, IP-related request metadata, and form abuse-prevention signals needed to keep the site reliable and secure.
  • Optional first-party analytics data about page usage, scroll depth, and registration-flow interactions, but only after you opt in through the cookie banner.

Why we process your data

We process personal data for the following purposes and legal bases:

  • To manage registrations, reserve places, send event information, and run the attendee journey. Legal basis: taking steps at your request and performing a contract.
  • To respond to enquiries sent through the contact form or email inboxes. Legal basis: our legitimate interest in handling communications and event operations.
  • To keep the site secure, prevent abuse, and maintain service reliability. Legal basis: our legitimate interest in protecting the website and attendees.
  • To comply with legal, accounting, and record-keeping duties where they apply. Legal basis: legal obligation.
  • To measure how the site performs and where visitors drop off in the registration flow. Legal basis: consent, which you can withdraw at any time through Cookie Settings in the footer.

Cookies, local storage, and consent

This site uses a small number of technologies with different purposes:

  • Essential cookies or equivalent storage needed for basic site operation, including remembering your cookie choice.
  • WordPress cookies that may appear for logged-in users, editors, or standard platform functionality.
  • Optional first-party analytics that stores a pseudonymous session identifier in your browser and sends limited interaction events to our own WordPress endpoint only after you opt in.

We do not use advertising, remarketing, or third-party behavioural tracking cookies on the public site. If you choose Essential Only, analytics stays off.

Who we share data with

We only share personal data where it is necessary to run the event or operate the website. This may include:

  • Website hosting, email delivery, and technical service providers acting on our instructions.
  • Operational suppliers who need attendee data to deliver conference logistics, accessibility accommodations, badges, or other event services.
  • Professional advisers, regulators, or public authorities where disclosure is legally required or necessary to protect legal rights.

We do not sell attendee data. If any supplier processes data outside the EEA, we use appropriate safeguards such as contractual protections.

How long we keep data

  • Pre-registration and event-operation data is kept only for as long as needed to run the event and related follow-up, and is periodically reviewed after the event cycle.
  • Contact-form messages are retained only as long as needed to answer the enquiry and maintain an operational record.
  • Optional analytics events are automatically purged after 395 days.
  • Your cookie-consent preference is stored for up to 12 months unless you change it sooner.
  • Where law requires longer retention, such as accounting or dispute-related records, we keep the minimum necessary for that purpose.

Your GDPR rights

You may have the right to:

  • Ask for access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request deletion where there is no overriding reason for us to keep processing.
  • Request restriction of processing in certain circumstances.
  • Object to processing based on legitimate interests.
  • Withdraw consent for analytics at any time without affecting earlier lawful processing.
  • Receive a portable copy of data you provided to us where the law grants that right.
  • Lodge a complaint with your local supervisory authority, including the Romanian data protection authority if applicable.

How to contact us

Email contact@breatheconference.eu for privacy requests, or use the contact page for general enquiries. When contacting us, include enough detail for us to identify your record safely.

Email Privacy Team