Privacy Policy
Projects with External Collaborator of Meridional Events S.L.
1. Introduction
This Privacy Policy applies specifically to projects, events and services contracted with Meridional Events S.L. whose operational management is carried out wholly or partly with the involvement of an independent external collaborator.
In these projects, the client contracts with Meridional Events S.L., while the external collaborator may undertake the day-to-day operational management, act as a point of contact and communicate with clients, participants and suppliers in order to perform the service.
Meridional Events S.L. retains oversight of the project and may keep copies of emails, messages, documents and other communications handled by the collaborator in its corporate systems.
Personal data shall be processed solely to manage and perform the project, comply with the applicable legal and contractual obligations, resolve incidents and address potential liabilities arising from the service.
This policy contains all the information applicable to these projects and is aligned with the data protection principles and measures applied by Meridional Events S.L. across its other activities.
2. Applicable legislation
The processing of personal data is governed by Regulation (EU) 2016/679 (GDPR), Ley Orgánica 3/2018 (LOPDGDD), and all other applicable legislation.
3. Data Controller
Meridional Events S.L.
NIF: B75679035
Address: Calle Pelayo, Málaga, Spain
Email: ![]()
Website: www.meridionalevents.com
4. How we process data
Depending on the context of the project, Meridional Events S.L. shall normally act as Controller where it organises, coordinates and executes the event.
In certain cases, where the client provides participant data for the provision of the service, Meridional shall process such data within the framework of the mandate received and in the role which legally corresponds according to the nature of the specific processing.
In all cases, the data are used exclusively for the execution of the project.
5. Role of the external collaborator
In the projects covered by this policy, the external collaborator accesses data solely in order to manage the project, acts within Meridional’s organisational framework, may not use the data for its own purposes, may not create independent databases, may not reuse contacts or information outside the project, must comply with the applicable security and confidentiality measures, and must erase or cease using the data once its involvement has ended.
The collaborator’s access is carried out through corporate accounts or project operational channels, and the collaborator may intervene in communications with clients and suppliers where necessary for the execution of the event.
6. What data we process
Depending on the project, we may process the following categories of data:
- Identification and contact data: first name and surname, email, telephone number, company and position.
- Event logistics data: travel, accommodation, schedules, rooming lists, transfers and planning.
- Data required for accommodation, documentary registration and nominative access: first name and surname, sex, nationality, date of birth, type and number of identification document (DNI, NIE, TIE or passport, as applicable), habitual place of residence (full address, locality and country) where required, email address and telephone number where required or necessary for service management, together with arrival, departure, booking, contract or payment details where required by the applicable legislation or by the provider subject to the registration obligation.
- Administrative data: billing, tax details, and payment or refund information.
- Communications and project records: emails, messages, attachments, instructions, notes and other operational information relating to the project, including communications handled by the external collaborator and retained in the systems of Meridional Events S.L.
- Health data, only where necessary: allergies, intolerances, reduced mobility and special requirements.
Such data are requested only where they are indispensable for the proper provision of the service.
7. Where the data come from
The data may come from the data subject itself, from the client company, from project forms, from communications by email, WhatsApp or other operational channels, from lists or documents provided by the client, and from the external collaborator within the project.
8. What we use the data for
The data are processed in order to organise and execute the event, manage accommodation, activities and logistics, coordinate participants and suppliers, manage billing and legal obligations, resolve incidents, and guarantee the safety of the event.
We do not use the data for commercial purposes or marketing in this specific context.
8.1 Use of automation and artificial intelligence
Meridional Events S.L. and, where necessary for the management of the project, the external collaborator may use authorised services provided by OpenAI — including ChatGPT and its API — Google — including Gemini — Anthropic — including Claude — and other technology providers to classify, summarise or translate communications, extract operational information, identify outstanding tasks and prepare drafts.
These tools may process information contained in emails, messages, documents and enquiries relating to the project. Their use supports the purposes described in the preceding section and relies on the legal basis applicable to the relevant processing.
We apply data minimisation measures and, where supported by the service used, available privacy settings intended to restrict retention and the use of information for model training. The external collaborator may only use tools authorised by Meridional Events S.L. and in accordance with its instructions.
As a general rule, we avoid entering health data, identification documents or complete banking details into external artificial intelligence tools, unless this is strictly necessary and an authorised environment offering appropriate safeguards is used.
We do not make decisions producing legal or similarly significant effects based exclusively on these systems. Relevant decisions remain subject to human review.
9. Communication of data
The data may be disclosed, where necessary, to hotels and accommodation providers, museums, monuments or nominative access points, logistics providers, restaurants in the event of dietary requirements, technology providers supplying email, storage, automation and artificial intelligence services, and public authorities where there is a legal obligation to do so.
We always apply the principle of minimum necessary access.
10. Processing of health data
Health data are processed under enhanced protection, are collected only where necessary, are limited to what is strictly indispensable, and are communicated solely where necessary for the provision of the service.
As a general rule, they shall be shared on a non-nominative basis whenever possible, and shall only be associated with a specific person where strictly indispensable in order to guarantee that person’s safety or the proper execution of the service.
They are never used for purposes other than the event.
11. International transfers
Some technology providers may process personal data outside the European Economic Area.
Where an international transfer takes place, we shall apply an adequacy decision, Standard Contractual Clauses or another valid safeguard under the GDPR, depending on the provider and service used.
Such transfers may involve, among others, services provided by Google, Microsoft, OpenAI or Anthropic.
You may request further information about these transfers and the safeguards applied by writing to the email stated at clause 3.
12. Data retention
The data shall be retained only for so long as is necessary for each purpose and, thereafter, for the periods required by the applicable legislation or necessary for the bringing, exercise or defence of claims.
- Project and participant operational data: for the time necessary for the preparation, execution, close-out of the project and handling of subsequent incidents and, as a general criterion, for a maximum period of 12 months from the end of the event, unless they must be retained for longer due to a legal obligation or pending claim.
- Data communicated for accommodation, documentary registration and nominative access: for the time strictly necessary for service management and for such periods as may be required pursuant to the applicable legislation and to the documentary registration obligations of the relevant provider or responsible party.
- Health data and special requirements: until they cease to be necessary and, as a general rule, within a maximum period of 90 days from the end of the event, unless there is a legal obligation or an open incident.
- Tax, accounting and contractual data: for the applicable statutory periods.
- Project communications: emails, messages, attachments and operational records, including communications handled by the external collaborator and copies retained in the systems of Meridional Events S.L., shall be retained during the management of the project and, as a general rule, for up to 24 months from the last relevant interaction, unless longer retention is required by law or for the defence of claims.
- Project communications: emails, messages, attachments and operational records, including communications handled by the external collaborator and copies retained in the systems of Meridional Events S.L., shall be retained during the management of the project and, as a general rule, for up to 24 months from the last relevant interaction, unless longer retention is required by law or for the defence of claims.
- External collaborator access credentials and project-related permissions: only for so long as necessary for the operational needs of the project or of the collaboration, and they must be revoked or restricted when no longer necessary.
13. Rights of data subjects
The data subject may exercise the rights of access, rectification, erasure, objection, restriction and portability by sending a request to
.
The data subject may also lodge a complaint with the Agencia Española de Protección de Datos.
14. Security
We apply appropriate technical and organisational measures, including access control, project-based organisation, use of corporate channels, and restriction of access to sensitive data.
The external collaborator is under an obligation to comply with such measures.
15. Security incidents
Any incident affecting personal data must be notified to Meridional without delay for evaluation and management in accordance with the applicable legislation.
16. Minors
The services are directed at companies.
We do not intentionally process data relating to minors. In exceptional cases, such processing shall be limited to what is strictly necessary.
17. Images and videos
As a general rule, images shall not be captured or used for promotional purposes in these projects.
Capturing may only take place where expressly requested by the client or where it forms part of the contracted service.
Under no circumstances may the collaborator use images for its own purposes.
18. Updates
This policy may be updated in order to adapt to legal or operational changes.
19. Contact
Meridional Events S.L.
Calle Pelayo, Málaga, Spain
Email: ![]()
Website: www.meridionalevents.com