Privacy Policy
This notice describes how we process the personal data collected through the website and services of The Injection Show 2027, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Italian law.
Data controller
The data controller is STUDIO M.E.V. SRL (organiser of The Injection Show 2027), with registered office at Via Servi di Maria 3, 96100 Siracusa (SR), Italy, tax code and VAT no. 01911780896. For any request regarding the processing of your data, you may write to info@injectionshow.com.
Data we collect
We process the data you provide and the data generated by your use of our services:
- Identity and contact data (first name, last name, email, phone) provided at registration, purchase or through the contact form.
- Billing data (company name, address, tax code/VAT number, recipient code) required to issue tax documents.
- Order and ticket data (tier, add-ons, amounts).
- Payment data handled by the payment providers: we do not store full card details.
- Data provided as part of the Awards applications (clinical cases, images), processed as special categories of data under Article 9 GDPR, only on the basis of your explicit consent and for the purpose stated in the form (see the dedicated section).
- The speaker whose QR code you arrived from. On the first scan the reference sits in your browser session; when you first sign in it is written to your account, and from then on it does not expire. The first attribution wins: if you later scan another speaker's QR the link does not change, and the one on record also governs the purchases you make in future. Speakers are only told how many registrations they generated, never your data.
- The newsletter campaign you arrived from: if you open the site from a link in one of our emails and then buy, the reference to that campaign stays on the order. Here too the first one wins: if you open two newsletters before buying, the order is credited to the first (see the dedicated section).
- The dietary needs you state for yourself or for the people you are registering for the Gala Dinner. It is a free-text, optional field, but what you write may reveal a health condition (an allergy, coeliac disease): that is why we treat it as a special category of data under Article 9 GDPR. It is saved on the ticket and goes into the guest list we hand to the caterer.
- Data of the order in progress, temporarily saved in your browser's local storage (name, email and any dietary needs of the participants you are registering), so you do not lose it when reloading the page: it stays on your device while you fill it in, then it is sent to our server together with the order and cleared from the browser (see Cookie Policy).
- The email address you leave on the waiting list when a ticket or a Gala Dinner seat is sold out, together with your name if you give it and the site language. It is used only to tell you if a seat frees up (legitimate interest in answering a request you made to us, art. 6.1.f GDPR): it is not a newsletter sign-up, we do not use it to write to you about anything else, and we delete it after the event.
- If you are subscribed to the newsletter, whether you opened a message and which links you clicked (see the dedicated section).
- The content of your conversations with the virtual assistant, linked to a technical session identifier and not to your name (see the dedicated section).
- Aggregated traffic statistics: for each day we count how many visits each page received and which site or campaign they came from, and nothing else. We do not record your IP address, we use no analytics cookies and we send nothing to external services: these are sums, not individual visits, and no person can be identified from those rows. If you then buy, the order keeps a note of where you first came from, as already happens for speaker QR codes and newsletter campaigns: it tells us which initiatives actually produce sign-ups (legitimate interest, art. 6.1.f GDPR).
- Technical browsing data (e.g. IP address, browser type) processed by the server for website security and operation. The website uses only technical cookies (see Cookie Policy).
Purposes and legal bases
We process data for the following purposes:
- Managing ticket sales, event access and related services (performance of the contract).
- Issuing invoices and fulfilling accounting and tax obligations (legal obligation).
- Sending transactional emails about your order, check-in and the event (performance of the contract).
- Responding to enquiries sent through the contact form (legitimate interest).
- Sending the newsletter and promotional communications, subject to consent, which can be withdrawn at any time.
- Measuring newsletter opens and clicks, to understand which content is of interest and to stop writing to people who no longer open them (legitimate interest; see the dedicated section).
- Managing Awards applications, including the special categories of data, subject to explicit consent (Article 9 GDPR).
- Serving you a dish at the Gala Dinner that matches the dietary needs you told us about: performance of the contract for the ordinary part (a vegetarian preference says nothing about your health) and, for the part that reveals a health condition, your explicit consent (Article 9.2.a GDPR), given by choosing to fill in that field.
- Crediting to speakers the registrations that came from their referral QR, in order to measure how effective their promotion is (legitimate interest).
- Knowing which newsletter a purchase came from, to measure which campaigns actually produce registrations and stop sending the ones that do not (legitimate interest).
- Ensuring the security and correct operation of the website through technical cookies (legitimate interest).
- Translating the lectures from the stage in real time, on the main screen and in the webapp (performance of the contract). Your device's microphone is used only if you turn on that feature yourself and grant permission in your browser.
- Operating the virtual assistant and checking the quality of its answers (legitimate interest).
Payments
Payments are handled through Stripe and PayPal. These providers act as independent controllers or processors for payment data and apply their own privacy notices. We neither access nor store full payment instrument details.
Simultaneous translation and microphone
During the event the lectures are translated in real time, with subtitles on the main screen and in the webapp. In normal operation the voice being transcribed is that of the person speaking on stage, taken from a dedicated output of the room mixer: no audio leaves your device. The stage audio is sent to AssemblyAI, Inc. (United States), which transcribes it; the transcribed text is then translated by DeepL SE (Germany). Both act as data processors. A backup audio recording is kept on the production computer, used only to redo the transcription should the service fail in the middle of a lecture: it is deleted within 30 days of the end of the event. Alternatively, in the webapp you can turn on the "Translate from microphone" feature yourself: in that case, and only after you have granted permission in your browser, your device's microphone is used and transcription happens in the browser itself, which to do so may send the audio to the servers of the operating system or browser vendor (e.g. Apple or Google), under their own privacy notices; only the text reaches us, for as long as it takes to translate it. You can switch the microphone off at any time, and while it is on it may also pick up the voices of people near you. Translated sentences are kept in a temporary technical cache, not linked to you, so the same sentence is not translated again for every device in the room. If you listen to the translation through headphones, the voice is generated by your own device: nothing is sent to us or to third parties to produce it.
Virtual assistant
An assistant answering questions about the event is available on the website and in the webapp. Conversations are kept for a maximum of 30 days, to check the quality of the answers and correct mistakes, and are linked to a technical session identifier, not to your name: we do not use them to profile you or to send you communications. The language model that generates the answers runs on infrastructure belonging to the organiser, not on third-party services: what you type into the chat is not sent to external artificial intelligence providers. We nevertheless ask you not to enter health data or other personal data into the chat that is not necessary for your question.
Newsletter: opens, clicks and the purchases that follow
If you are subscribed to the newsletter, we record whether and when you open our messages and which links you click. This tells us which content is genuinely of interest and lets us stop writing to people who no longer open them: we do not build commercial profiles and we do not pass this data to anyone. There is one point, though, where the newsletter and your purchases do touch, and it should be said: the links in our campaigns carry a code identifying the campaign, and if you follow one and then complete an order, that code stays written on the order. It is the only way we have of knowing whether a newsletter actually produced registrations rather than merely being opened. The first campaign you followed counts, not the last. It is a link between a campaign and an order, not a profile of what you buy: we do not infer from it what you might be interested in purchasing, and we do not disclose it to third parties. The legal basis is our legitimate interest in measuring how effective our communications are (Art. 6.1.f GDPR); the reference stays on the order for as long as the order must be retained, and if you would rather it did not, you can ask us to remove it by writing to info@injectionshow.com. Opens and clicks are measured by Mailgun, which places an invisible image in the message and routes links through its own tracking domain before taking you to the destination page. If you would rather avoid it, most email programs let you block images from loading (the open is then not recorded), and you can in any case unsubscribe at any time using the link at the foot of every message: from that point we record nothing further. This data is kept alongside your subscription: when you unsubscribe, when you ask for erasure or when we delete your subscription, the rows that link it to you lose your address and the link to your subscription, and remain only as anonymous counts of a mailing that already went out (how many people opened that campaign), which can no longer be traced back to you. Inside those rows your address is never stored in the clear: in its place there is an irreversible code derived from the address, whose only job is to match the open notifications coming back from Mailgun to the right message.
Addresses you did not give us yourself
Some of the addresses on our newsletter list did not come from a form on this website, and Article 14 GDPR requires us to tell you where they did come from. There are two sources. The first is the MailPoet list of educational.studiomaiolino.net, which addresses the same professional audience: from there we import only those recorded as subscribed and confirmed, carrying over the original consent date — not the date of the import — and the legal basis remains that consent. The second is a list of professional contacts supplied by a third party: there, consent towards us never existed, and we process the address on the basis of our legitimate interest in making a sector congress known to the professionals who work in that sector (Art. 6.1.f GDPR). The categories of data are the same in both cases: email address, the name where the source provides one, the language and a label recording the origin. Every imported address carries its own source, and the first message you receive tells you what it is, together with a one-click unsubscribe link: from that moment we write to you no more. You can object at any time, even before receiving anything, by writing to info@injectionshow.com. Imported addresses are never passed on to anyone, for any reason.
Injection Awards: the clinical cases
An Injection Awards submission contains clinical photographs and the description of a case: this is health data, and it is not yours but your patient's. That is why the rules require you to have obtained the patient's consent and to have removed anything that could identify them before uploading the images. The files stay on a private disk on our server: they are not sent out as email attachments and cannot be reached from a guessable address. They are opened from the account area by the secretariat and the review committee, and by Prof. Douglas A. Terry for the final choice. If your case wins, it is projected and discussed on stage: the projection in the hall is part of the submission and of the licence you grant by submitting, and does not depend on a separate tick — it is the prize itself, and it is what you are competing for. The separate tick concerns something else: the gallery reserved to attendees. Without that consent the case does not appear in the gallery, and you can withdraw the consent whenever you like by writing to info@injectionshow.com: withdrawal removes the case from the gallery, it does not remove it from the competition. The materials are deleted automatically 24 months after the end of the edition you submitted them to, sooner if you ask us.
Who we disclose data to
Data may be disclosed to suppliers acting as data processors: the hosting provider; Mailgun for email delivery and the measurement of opens and clicks; MailPoet for managing the list we import subscribers from; Stripe and PayPal for payments; Google for the reCAPTCHA that protects the contact form; AssemblyAI and DeepL for the simultaneous translation of the lectures (see the dedicated section); Hetzner Online GmbH, which holds the nightly backup copy away from our server (see "Backup copies"); the catering supplier for the Gala Dinner, to whom we hand a guest list with the table, the name and only the dietary needs stated; tax advisors and, where necessary, lawyers. Speakers are told only how many registrations their QR generated, never who made them. We do not sell your data and we do not disclose it for third-party marketing.
Transfers outside Europe
Some suppliers are based, or have a parent company, outside the European Economic Area. Here is where they actually are. Stripe: the contract is with Stripe Payments Europe, Ltd. (Ireland), part of a United States group. PayPal: the contract is with PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg), also part of a United States group. Google reCAPTCHA is provided by Google Ireland Limited, but data may reach Google LLC in the United States. Mailgun is based in the United States and works for us on its European infrastructure: messages and statistics stay on servers in the European Union, but the supplier accesses them from the United States. AssemblyAI, Inc. is in the United States. DeepL SE and Hetzner Online GmbH are in Germany and the data they process does not leave the European Economic Area. When you search for an address or type a postcode during a purchase, the request leaves from our server and not from your browser: the geocoding service (OpenStreetMap, United Kingdom, a country the European Commission has recognised as providing an adequate level of protection) and the postcode service (United States) receive only the text you typed, without your IP address and without your browser cookies. All transfers to the United States take place on the basis of the standard contractual clauses approved by the European Commission and, for the suppliers that have joined it, of the EU-US Data Privacy Framework certification.
Data retention
We retain data for as long as necessary for the purposes described: order and billing data for the period required by tax obligations (typically 10 years); newsletter subscription data until consent is withdrawn; clinical materials submitted to the Injection Awards for up to 24 months after the end of the edition, after which an automatic routine deletes them without anyone having to remember, unless you ask us to remove them sooner; dietary needs on the ticket alongside the order, while the list handed to the caterer does not survive the Gala Dinner service; conversations with the virtual assistant for a maximum of 30 days; the backup audio recording of the lectures for up to 30 days after the end of the event; technical data for the periods indicated in the Cookie Policy. Backup copies follow their own timings, described below.
Backup copies
Every night an encrypted copy of the database and of the photographs submitted to the Awards is written to a Storage Box at Hetzner Online GmbH, in Germany: it is there to bring the service back up if the server fails or if something is deleted by mistake. The copies rotate: we keep those of the last seven days, then one a week for a month, one a month for four months and one a year for two years. That means something you are entitled to know: after a piece of data has been deleted from the system, it can still survive inside the older copies — at most two years — until the rotation removes those too. The copies are never used to put deleted data back into circulation: they are opened only for an emergency restore and, should that happen, the erasures requested in the meantime are carried out again.
Deleting your account
If you have an account in the web app you can delete it yourself, from «Profile → Delete my account»: there is no need to write to us. What happens depends on one thing only, and the system decides it. If there is no payment on record in your name, your account is deleted outright. If instead you have purchased — even if you were later refunded — the invoices, receipts and related records stay for ten years, as required by art. 2220 of the Italian Civil Code: this is the case where the GDPR expressly excludes the right to erasure (art. 17.3.b). In that case your profile is emptied anyway (name, email, phone, practice, photo, profile billing details) and access is closed: what remains on the accounting documents is only what an invoice must carry by law. In both cases we delete your name and email from the tickets issued to you, your Awards submissions with every photo uploaded, your preferences and notifications, any sign-in links already sent, and the messages you sent us through the contact form; your newsletter subscription is switched off and stripped of your name, and the address stays on record for the sole purpose of never mailing you again; the open and click statistics of the newsletters that had been sent to you lose every reference to you and remain only as figures for the campaign. We do not touch other people's data: if you bought tickets for colleagues, their data stays, because only the data subject can request erasure.We also delete the link to the speaker whose QR code you had arrived from: it existed to credit them with your future purchases, and a closed account makes no future purchases. Orders you had already placed stay credited to that speaker — that actually happened, and their count does not change. The operation is permanent and cannot be reversed on the live system; in the nightly backup copies your data may survive for a while longer, following the rotation described in the "Backup copies" section, and if a copy ever had to be restored the erasure would be carried out again. The account cannot be deleted while you have an order still to pay, a refund request in progress, or a valid ticket for an edition that has not yet taken place: in those cases the page tells you so and explains how to proceed.
Your rights
At any time you can exercise the rights provided by Articles 15-22 of the GDPR:
- Access to your personal data.
- Rectification of inaccurate or incomplete data.
- Erasure of data (right to be forgotten). If you have an account in the web app you can delete it yourself from «Profile → Delete my account»: see the dedicated section.
- Restriction of and objection to processing.
- Data portability in a structured format.
- Withdrawal of consent at any time, without affecting the lawfulness of processing already carried out: this also covers your consent to publishing your clinical case in the Awards gallery, which we can remove at your request.
- Lodging a complaint with the Data Protection Authority.
Contact
To exercise your rights or for any question about data processing, write to info@injectionshow.com or to Via Servi di Maria 3, 96100 Siracusa (SR), Italy.