Privacy Policy | Adria Security Summit

Last Updated: 11 August 2026

This Privacy Policy explains how Global Security d.o.o. Sarajevo (“we,” “us,” or “our”) collects, uses and protects your personal data when you visit adriasecuritysummit.com, contact us, subscribe to our newsletter, or register for and attend the Adria Security Summit.

1. Data Controller and Processors

  • Controller: GLOBAL SECURITY d.o.o. Sarajevo, Hasiba Brankovića 3, 71000 Sarajevo, Bosnia and Herzegovina. Contact: summit@asadria.com, +387 33 788 985.
  • Registration and ticketing: run.events GmbH — event registration, badge issuing, agenda, networking and mobile app.
  • Payments: Stripe — processing card payments through the run.events financial infrastructure.
  • Email and newsletter: Brevo (Sendinblue) — sending event updates and our newsletter.
  • Website analytics: Google Ireland Limited — Google Analytics 4, used only with your consent.
  • Website security and delivery: Cloudflare — protection against attacks and content delivery.
  • Website hosting: our hosting provider, which stores the website and its database.
  • Matchmaking: Configurence — optional tool that suggests relevant exhibitors and sessions.

2. Information We Collect

When you register for the Summit:

  • Registration data: name, email address, job title, company and country.
  • Payment information: payment is handled by Stripe. We do not store card numbers or CVC codes on our servers. Stripe collects this data directly to process the transaction securely.
  • Attendance data: session and workshop selections, check-in records, and badge scans at the venue.

When you use this website:

  • Contact form: name, company, phone number, email address and the content of your message.
  • Newsletter: your email address and any other details you choose to provide when subscribing.
  • Analytics: if you consent to statistics cookies, we collect anonymised information about how the site is used — pages viewed, approximate location, device type and referral source.
  • Technical data: our security and delivery provider processes IP addresses and request data to protect the site against attacks. This happens automatically and is necessary for the site to operate safely.
  • Matchmaking tool: if you use the “Should I attend” tool, the company website and role you enter are processed to generate your recommendation.

3. Legal Basis for Processing

We process personal data on the following legal bases under the GDPR and the BiH Law on the Protection of Personal Data:

  • Performance of a contract — processing your registration, issuing your ticket and badge, sending confirmations and invoices, and delivering the event you booked.
  • Consent — newsletter and marketing emails, statistics and marketing cookies, and sharing your details with an exhibitor when you allow them to scan your badge. You may withdraw consent at any time.
  • Legitimate interest — responding to enquiries you send us, protecting the website against attacks and abuse, and improving our services.
  • Legal obligation — meeting accounting and tax requirements in Bosnia and Herzegovina.

4. How Your Data is Used

  • To provide the service: processing your ticket, sending confirmation emails, and issuing invoices through the run.events system.
  • Event communication: sending essential updates about the Summit schedule, venue and access.
  • Responding to enquiries: answering questions you send through our contact form or by email.
  • Newsletter: sending news, speaker announcements and event updates, where you have subscribed.
  • Improving the website: understanding which pages are useful and where visitors have difficulty, based on consented analytics.
  • Financial compliance: meeting BiH tax and accounting requirements as the event organiser.

We do not sell your personal data, and we do not use automated decision-making or profiling that produces legal effects for you.

5. Cookies and Similar Technologies

This website uses cookies. Cookies that are strictly necessary for the site to function are always active. Statistics and marketing cookies are only placed after you give consent through our cookie banner.

You can change or withdraw your cookie consent at any time using the “Manage consent” option at the bottom of any page. A full list of the cookies we use, what each one does and how long it lasts is available in our Cookie Policy.

6. Third-Party Sharing (Exhibitors and Sponsors)

The Adria Security Summit features third-party exhibitors. Your data is shared with them only in the following cases:

  • Badge scanning: if you allow an exhibitor to scan your badge at their stand, you are giving explicit consent to share your contact details with that specific company.
  • Sponsored sessions: if you register for a session explicitly marked as “Sponsored,” your basic registration data may be shared with the sponsor of that session.

Exhibitors and sponsors act as independent controllers for any data they receive in this way, and their own privacy notices apply to how they use it.

7. International Data Transfers

Some of the providers listed in section 1 — including run.events, Stripe, Brevo, Google and Cloudflare — are international platforms, and your data may be processed in the European Union or in the United States. We rely on Standard Contractual Clauses (SCCs) or equivalent safeguards for these transfers, as required by the GDPR and by the BiH Law on the Protection of Personal Data (Official Gazette 12/2025).

8. How Long We Keep Your Data

  • Registration and attendance data: kept for the duration of the event and afterwards for as long as needed to support future editions, and for the period required by BiH accounting law.
  • Contact form enquiries: kept for as long as needed to handle your enquiry and for a reasonable period afterwards for reference.
  • Newsletter subscriptions: kept until you unsubscribe.
  • Analytics data: retained according to the retention period configured in Google Analytics.
  • Cookie consent records: your consent choice is stored for 365 days, after which you will be asked again.

9. Your Rights

Under the GDPR and BiH law, you have the right to:

  • Access the personal data we hold about you.
  • Have inaccurate data corrected.
  • Request deletion of your data, where no legal obligation requires us to keep it.
  • Restrict or object to certain processing.
  • Receive a copy of your data in a structured, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us at summit@asadria.com. We will respond within one month.

If you believe your rights have been infringed, you may lodge a complaint with the Personal Data Protection Agency in Bosnia and Herzegovina (www.azlp.ba). If you are located in the European Union, you may also lodge a complaint with the supervisory authority in your country of residence.

10. Data Security

All data submitted through this website is encrypted in transit using HTTPS/TLS. Payment data is handled in compliance with PCI-DSS standards by Stripe through the run.events integration. Access to registration data within our organisation is limited to staff who need it to deliver the event.

11. Changes to This Policy

We may update this Privacy Policy from time to time — for example, if we introduce a new service or if legal requirements change. The current version is always available on this page, and the “Last Updated” date at the top shows when it was last revised.