Privacy Policy.
The short version. We collect what we need to run the show and get you in the door. In the app, we ask a few questions so we can match buyers and exhibitors usefully, and we only share your profile with exhibitors if you tell us to. You can decline and still use everything else. We do not sell personal information.
Who We Are.
Koelnmesse Inc., a Delaware corporation, 8770 West Bryn Mawr Avenue, Suite 1300, Chicago, IL 60631, is the controller of the personal data described here. Email [email protected] or call +1 773 326 9920.
What This Covers.
This policy applies to the h+h americas websites, the official h+h americas mobile app for iOS and Android, our registration process, and the exhibitor and attendee services we run around the show. Where the app does something different from the website, we say so.
Data We Collect.
When you use the website
- Name, contact details, company and job information you give us in forms
- Registration information, including pass type and any sessions you book
- Usage data: IP address, browser type, pages viewed and interaction patterns, collected through cookies and analytics. See our Cookie Notice.
- A recording of your visit, if you accept analytics cookies. This reconstructs how you moved through the page: mouse movement, clicks and taps, scrolling, and which pages you moved between. It is described in full under Website Analytics and Session Recording below.
When you use the app
- Your registration record, so the app knows who you are
- Your answers to the short set of onboarding questions. These cover your role, what you are sourcing or exhibiting, where you are in your buying cycle, and what a good show looks like for you
- Sessions and exhibitors you save, and meetings you request
- Device information: device and app identifiers, operating system, app version, and a push notification token if you allow notifications
- App usage and crash diagnostics, so we can fix what breaks
If you exhibit and use lead scanning
- Badge scans you capture, which record the attendee whose badge was scanned and the time and place of the scan
How We Use It.
- To run the event: registration, badges, session bookings, and getting you the information you need before and during the show
- To match buyers and exhibitors. Your answers to the onboarding questions are used to suggest exhibitors likely to carry what you are sourcing, and to suggest buyers likely to fit what an exhibitor sells
- To let you request and confirm meetings
- To send you service messages about the show, and marketing where you have opted in or where we are permitted to
- To understand how the site and app are used, and to improve them
- To protect the event and our systems from fraud and abuse
Automated Matching, and What It Does Not Do.
The app uses your answers to rank and suggest people and companies. That is the point of it. It is a suggestion engine, not a gatekeeper: it does not decide whether you can attend, what you pay, or whether you get a badge, and no decision with a legal or similarly significant effect on you is made automatically. You can ignore every suggestion it makes and use the directory directly.
Sharing Your Profile With Exhibitors.
This is the part worth reading twice.
- We ask you first. The app asks whether we may share your profile with relevant exhibitors so they can get in touch. You can say no.
- If you say no, you can still browse exhibitors, build a schedule, and use the rest of the app. Exhibitors can send you a connection request, which you are free to ignore.
- If you say yes, exhibitors matched to you may see your name, company, role, and the sourcing interests you described. They may contact you about the show and their products.
- You can change your mind. Contact us and we will update it.
Lead scanning is different and works the way you would expect at a trade show. If you let an exhibitor scan your badge, you are handing them your contact details, and they receive them. That is a deliberate act on your part each time.
Who Else Sees Your Data.
We use service providers who process personal data on our instructions and under contract. By category, they are:
- Our event app and matchmaking provider, which operates the app and its matching features
- Our registration platform, which handles sign-up, badges and session bookings
- Our customer relationship and email platforms, for exhibitor and attendee communication
- Google, which provides Google Analytics, and Microsoft, which provides Clarity, the tool that records visits to our website. See Website Analytics and Session Recording
- Our hosting and content delivery providers, which serve the website and app
- Our onsite services contractor, for badge printing and event logistics
We also share data with exhibitors as described above, and with authorities where we are legally required to. We do not sell personal information, and we do not share it for cross-context behavioural advertising. A current list of our processors is available on request from [email protected].
International Transfers.
h+h americas is run from the United States and our data is processed here. Koelnmesse Inc. is part of a German group, and some of our providers process data in the European Economic Area and in other countries outside it. Where personal data moves out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where applicable, and we require the same protections from any sub-processor.
Legal Bases.
For people in the EEA and UK, we rely on:
- Contract, to register you and deliver the event services you asked for
- Consent, for sharing your profile with exhibitors, for push notifications, for non-essential cookies, and for marketing where consent is required
- Legitimate interests, to run and improve the show, to communicate with our trade audience, and to keep our systems secure
- Legal obligation, where the law requires us to keep or disclose something
How Long We Keep It.
We keep personal data only for as long as we need it, then delete it or strip it of anything that identifies you. In practice that means:
| What | How long |
|---|---|
| Registration and attendance records, including pass type and sessions attended | 3 years after the last event you attended |
| Your app profile, your answers to the onboarding questions, and your matching history | 18 months after you last use the app, then deleted or anonymised |
| Our copy of badge scans captured by exhibitors | 12 months after the event |
| Device and app identifiers, and push notification tokens | Until you uninstall the app or turn notifications off. Invalid tokens are purged within 30 days |
| Crash reports and diagnostic data | 90 days |
| Website analytics | 14 months |
| Recordings of website visits | 30 days. A small sample, and any recording our team has flagged for follow-up, is kept for up to 13 months |
| Aggregated click and scroll data used to build heatmaps | 13 months |
| Your cookie consent choice | 12 months, after which we ask again |
| Marketing contact details | Removed from active marketing after 36 months with no engagement |
| Press and creator accreditation applications | 12 months after the edition they relate to |
| Payment and invoice records | For the period required by applicable tax and accounting law |
One deliberate exception. If you unsubscribe or ask us not to contact you, we keep a minimal record of that request, your email address and the date, indefinitely. We do this so that we can keep honouring it. If we deleted you completely, nothing would stop your details reaching us again from a badge scan or a registration next year and the emails starting over. That record is used for nothing else.
We may also keep data for longer where we are required to by law, or where we need it to establish or defend a legal claim. If you would like your data removed sooner than the periods above, ask us and we will do it unless one of those reasons applies.
Your Rights.
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to how we use it, receive a portable copy, withdraw consent, and not be discriminated against for exercising any of these. These rights are available under the GDPR and UK GDPR, and under US state privacy laws including those of California, Virginia, Colorado, Connecticut and Texas.
To exercise any of them, email [email protected]. We will verify who you are before we act, and we will respond within the time the applicable law allows. If you are in the EEA or UK and you are unhappy with our response, you can complain to your local supervisory authority.
Push Notifications and Marketing.
Push notifications are opt-in and can be switched off in your device settings at any time. Marketing emails carry an unsubscribe link in every message, in line with CAN-SPAM, and you can also unsubscribe by emailing or calling us. Service messages about a show you are registered for are not marketing and will still reach you.
Payments.
Card details are used only to take the payment you authorised and are handled by our payment processors. We do not store full card numbers. If you choose to save a card for future payments, it is stored by our payment processor, not by us.
Security.
We and our providers use industry-standard safeguards, including encryption in transit and at rest, access controls and multi-factor authentication on administrative systems. No system is completely secure, and we will not pretend otherwise. If a breach affects your personal data and the law requires us to tell you, we will.
Children.
h+h americas is a trade event for professionals and the app is not directed at children. We do not knowingly collect personal data from anyone under 18, and we delete it if we discover we have.
Website Analytics and Session Recording.
We want to say plainly what happens on our website, because one part of it is more intrusive than people usually expect from the word “analytics”.
Google Analytics tells us how many people visit, which pages they land on, roughly where in the world they are, and which links brought them to us. This is counting and aggregation.
Microsoft Clarity does something different. When you accept analytics cookies, Clarity records your visit. It is not a video of your screen or your camera; it is a reconstruction, built from the structure of the page plus a log of what you did on it, replayed afterwards as though it were a video. It captures where you moved your pointer, what you clicked or tapped, how far you scrolled, and how long you stayed. We use it to find out where our own pages confuse people, and it also feeds the heatmaps that show which parts of a page get attention.
What is kept out of a recording. We run Clarity in its strictest masking mode: all text on the page and all images are masked. Every piece of text, whether you typed it or the page displayed it, is replaced by placeholder characters on your own device before the recording is sent, and neither Microsoft nor we ever receive it. That covers your name, your email address, your company and anything else you enter, along with the content of the page itself. What a recording shows is the structure of the page and how you moved through it, not what it said. The masking happens in your browser, not after upload, so the unmasked values are never transmitted.
This only happens if you accept. Recording does not start until you choose “Accept All” on the cookie banner. If you decline, or if you simply do not respond to the banner, the recording tool is never loaded at all. You can change your mind at any time by clearing this site’s cookies and site data in your browser, which removes the stored choice and makes the banner appear again.
Where it goes. Recording and analytics data is processed by Microsoft and Google respectively, both United States companies, and is covered by the transfer safeguards described under International Transfers above. Neither tool is used to build an advertising profile of you, and we do not sell this data or share it for cross-context behavioural advertising.
Cookies.
Our websites use cookies for essential functions, analytics and personalisation. What each one does, and how to control them, is set out in our Cookie Notice.
Other Sites.
We link out to venues, hotels, exhibitors and partners. Once you leave our site or app, their privacy practices apply, not ours.
Changes.
We update this policy when what we do changes. The date at the top tells you when it last changed. If a change is significant, we will say so on the site and, where the law requires, ask for your consent again.
Contact Us.
Koelnmesse Inc.
8770 West Bryn Mawr Avenue, Suite 1300
Chicago, IL 60631, USA
Email: [email protected]
Phone: +1 773 326 9920