Privacy Policy — meetplace.pl
Last updated: 21 May 2026
1. Data Controller
- The controller of personal data processed in connection with the use of the meetplace.pl website (hereinafter: the "Website") is 7777 International Sp. z o.o. with its registered office in Warsaw (02-391), ul. Mikołaja Drygały 5, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw, 14th Commercial Division of the National Court Register, under KRS number: 0001091860, NIP (Tax ID): 7011194017, REGON (Statistical ID): 528047553 (hereinafter: the "Controller").
- For matters related to the protection of personal data, you may contact the Controller at the following e-mail address: [email protected].
2. Scope of Data Collected
- The Controller processes the following categories of personal data:
- Data from contact forms and enquiry forms: first and last name, e-mail address, phone number, company name, position, message content;
- Data from the Event Brief: first and last name, e-mail address, phone number, company name, details of the planned event (date, number of attendees, technical requirements, budget);
- User Account data (client panel): first and last name, e-mail address, password (stored in encrypted form — bcrypt), company name, contact details;
- Data from the Review form: name/nickname, e-mail address, review content, rating;
- Data from the venue submission form: venue details, contact details of the person submitting;
- Technical data collected automatically: IP address, browser type and version, operating system, screen resolution, referring pages, date and time of visit, pages visited, cookie identifiers.
- Providing personal data is voluntary but necessary to use certain features of the Website (submitting an enquiry, creating an Account, posting a Review).
3. Purposes and Legal Bases of Processing
- Personal data is processed for the following purposes and on the following legal bases:
Purpose of Processing Legal Basis (GDPR) Handling enquiry forms and Event Briefs — forwarding data to selected Venues/Suppliers Art. 6(1)(b) — performance of a contract / taking steps at the request of the data subject Operation and management of the User Account in the client panel Art. 6(1)(b) — performance of a contract Handling e-mail correspondence and contact forms Art. 6(1)(f) — legitimate interest (handling enquiries) Publishing Reviews of Venues and Suppliers Art. 6(1)(a) — consent of the data subject Statistical analysis and improvement of the Website Art. 6(1)(f) — legitimate interest (analytics) Ensuring the security of the Website, abuse detection, rate limiting Art. 6(1)(f) — legitimate interest (security) Fulfillment of legal obligations (e.g. accounting, archiving) Art. 6(1)(c) — legal obligation Pursuing or defending against claims Art. 6(1)(f) — legitimate interest
4. Data Recipients
- Personal data may be disclosed to the following categories of recipients:
- Conference venues and Service providers — to the extent necessary to process an enquiry or Event Brief (name, e-mail, phone number, enquiry content);
- IT service providers — hosting (OVH / nazwa.pl), CDN services (Cloudflare), e-mail services (SMTP);
- Analytics tools — Google Analytics 4 (with IP anonymisation), Cloudflare Web Analytics;
- Public authorities — only on the basis of applicable law, upon request from authorised bodies.
- The Controller does not sell personal data to third parties.
5. Transfers of Data Outside the EEA
- Due to the use of Google (Analytics) and Cloudflare services, data may be transferred to countries outside the European Economic Area (in particular the USA).
- Such transfers are carried out on the basis of:
- a European Commission adequacy decision (EU-US Data Privacy Framework) — with respect to certified entities;
- standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR).
6. Data Retention Period
- Personal data is stored for the period necessary to fulfil the purposes for which it was collected:
Data Category Retention Period Enquiry forms / Event Briefs 12 months from the date of submission or until consent is withdrawn User Account Until the Account is deleted at the user's request E-mail correspondence 12 months from the end of correspondence Reviews Until consent is withdrawn or deleted at the author's request Analytics data (cookies) According to the cookie expiry period (see: Section 9) Accounting / invoicing data 5 years from the end of the fiscal year (legal obligation) Data related to claims Until the statute of limitations expires (max. 6 years) - After the retention period expires, data is permanently deleted or anonymised.
7. Rights of Data Subjects
- Under the GDPR, you have the following rights:
- Right of access (Art. 15) — to obtain information about the data being processed and a copy of the data;
- Right to rectification (Art. 16) — to request the correction of inaccurate or completion of incomplete data;
- Right to erasure (Art. 17) — to request the deletion of data ("right to be forgotten") where there is no basis for further processing;
- Right to restriction of processing (Art. 18) — to request restriction of processing in certain circumstances;
- Right to data portability (Art. 20) — to receive data in a structured format (JSON/CSV);
- Right to object (Art. 21) — to object to processing based on legitimate interest;
- Right to withdraw consent (Art. 7(3)) — to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- To exercise any of the above rights, please send a message to: [email protected]. The Controller will respond to requests within 30 days.
- You also have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
8. Data Security
- The Controller implements appropriate technical and organisational measures to ensure the protection of personal data, including but not limited to:
- encryption of connections using the TLS/SSL protocol (HTTPS certificate);
- encryption of passwords using the bcrypt algorithm;
- protection of forms with CSRF tokens;
- rate limiting of requests to prevent abuse;
- HTTP security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options);
- regular updates of software and dependencies;
- restriction of data access to authorised persons only;
- encrypted backups.
9. Cookies and Tracking Technologies
- The Website uses cookies — small text files stored on the User's device.
- Types of cookies used:
Name / Category Purpose Expiry Period Type session / XSRF-TOKEN Session management and CSRF protection Session / 2 hours Strictly Necessary cookie_consent Storing the cookie consent decision 12 months Strictly Necessary locale Storing the selected language (PL/EN) 12 months Functional _ga, _ga_* Google Analytics 4 — traffic statistics Up to 14 months Analytical cf_clearance Cloudflare — security verification Up to 12 months Strictly Necessary - In addition, the Website uses browser localStorage to store:
- the cookie consent decision (
cookie_consent); - the list of favourite venues (
mp_favorites) — data stored exclusively on the User's device and is not transmitted to the server.
- the cookie consent decision (
- The User may manage cookies:
- using the cookie banner displayed on the first visit;
- through browser settings (blocking, deleting cookies);
- using the Google Analytics opt-out tool: tools.google.com/dlpage/gaoptout.
- Disabling strictly necessary cookies may limit the functionality of the Website.
10. Third-Party Services
- The Website uses the following third-party services that may process data:
- Google Analytics 4 (Google Ireland Ltd.) — web analytics. Privacy policy: policies.google.com/privacy;
- Cloudflare (Cloudflare, Inc.) — CDN, DDoS protection, DNS. Privacy policy: cloudflare.com/privacypolicy;
- OpenStreetMap (OpenStreetMap Foundation) — venue maps. Privacy policy: osmfoundation.org;
- Google Fonts — may be loaded from Google servers. Privacy policy: policies.google.com/privacy.
- The Controller is not responsible for the privacy policies of third parties.
11. Profiling and Automated Decision-Making
- The Website does not make decisions based solely on automated processing (including profiling) that would produce legal effects or similarly significantly affect the User.
- The Website may use artificial intelligence algorithms for the following purposes:
- intelligent search of venues and suppliers (matching results to queries);
- generating editorial content (blog articles) under editorial supervision.
- The above activities do not constitute profiling within the meaning of Art. 22 GDPR.
12. Children's Data
- The Website is not directed at persons under the age of 16.
- The Controller does not knowingly collect personal data from children. If the Controller becomes aware that data of a child has been processed, such data will be promptly deleted.
13. Changes to the Privacy Policy
- The Controller reserves the right to update this Privacy Policy to reflect changes in legislation or data processing practices.
- The Controller will notify Users of significant changes via the Website.
- The current version of the Privacy Policy is always available at meetplace.pl/en/privacy-policy.
14. Contact
- For matters relating to the protection of personal data, the exercise of your rights, or questions regarding this Policy, please contact:
- E-mail: [email protected]
- Address: 7777 International Sp. z o.o., ul. Mikołaja Drygały 5, 02-391 Warsaw, Poland
7777 International Sp. z o.o.
ul. Mikołaja Drygały 5, 02-391 Warsaw, Poland
KRS: 0001091860 | NIP: 7011194017 | REGON: 528047553
E-mail: [email protected]