Privacy Notice

How we collect, use and protect personal data.

Last updated: [DATE OF LEGAL APPROVAL]

Draft for legal review

This page is a comprehensive working draft. Replace all bracketed fields, confirm the operating entity and jurisdictions, and obtain professional legal review before publication.

1. Who we are

This Privacy Notice applies to the websites, applications, forms, events, communications and services operated under the UNBOUNDED™ Global Ecosystem, including Annual Standing, the Leaders Concierge, the Annual Programme, National Professional Delegations, Global Business Corridors and the Annual Global Assembly of Leaders.

The data controller is [FULL LEGAL ENTITY NAME], incorporated in [JURISDICTION] under registration number [NUMBER], with its registered office at [REGISTERED ADDRESS] (“UNBOUNDED”, “we”, “us” or “our”). Contact: [PRIVACY EMAIL]. Data Protection Officer or privacy lead: [NAME/CONTACT, IF APPLICABLE].

2. Scope

This Notice applies when you visit our website; apply for or hold Annual Standing; register for or attend an event; participate in a delegation, corridor, programme, working group or publication; contact the Leaders Concierge; create or use a profile or dashboard; subscribe to communications; or otherwise interact with us in a professional capacity.

3. Personal data we may collect

3.1 Identity and professional data

Name, title, role, organisation, professional biography, photograph, jurisdiction, qualifications, languages, areas of practice, professional memberships, website and publicly available professional information.

3.2 Contact data

Business email, telephone number, postal address, assistant or representative details and communication preferences.

3.3 Application and assessment data

Information submitted in applications or expressions of interest, professional objectives, corridor and delegation preferences, references, due-diligence information, reputational checks and internal assessment notes.

3.4 Transaction and payment data

Billing name and address, payment status, invoice records, tax information and limited payment-related information received from payment processors. We should not store complete payment-card credentials unless expressly stated and securely implemented.

3.5 Service and participation data

Concierge requests, Cross-Border Action Notes, onboarding notes, programme registrations, attendance, Assembly interests, meeting requests, privileges used, contribution submissions, participation history and Standing Record information.

3.6 Event, image and media data

Photographs, audio, video, livestream recordings, quotations, presentation materials and related metadata captured or supplied in connection with events and programmes, subject to the applicable notice, consent or legitimate-interest assessment.

3.7 Technical and usage data

IP address, device identifiers, browser type, operating system, referral source, pages viewed, dates and times, clickstream, security logs, cookie identifiers and analytics information.

3.8 Communications

Emails, contact-form submissions, meeting records, support requests, preferences and other correspondence.

3.9 Sensitive or special-category data

We do not normally seek special-category data. Where event accessibility, dietary, health, religious or other sensitive information is voluntarily provided, we process it only where necessary and with an appropriate lawful basis and safeguards.

4. How we obtain personal data

We collect data directly from you; from your organisation or authorised representative; from constituent institutions and programme partners; from event-registration and payment providers; from professional directories and public sources; through cookies and similar technologies; and from people who nominate, refer or invite you.

5. Purposes and lawful bases

Depending on the context and applicable law, we process data to:

  • receive and assess applications, perform due diligence and decide whether to offer Annual Standing or participation - legitimate interests, pre-contractual steps and, where necessary, legal obligations;
  • enter into and administer Annual Standing, event registration, payments and related services - performance of a contract;
  • operate profiles, dashboards, Concierge requests, directories, delegations, corridors and programme participation - contract and legitimate interests;
  • organise Barcelona 2026 and other events, including security, access, hospitality, communications and participant support - contract, legitimate interests and legal obligations;
  • facilitate consent-based professional engagement and relevant opportunities - contract, legitimate interests and consent where required;
  • publish professional profiles, contributions, photographs or recordings - legitimate interests, contractual permissions or consent, depending on the context;
  • send service messages and institutional updates - contract and legitimate interests;
  • send marketing communications - consent where required, or legitimate interests where permitted, with an opt-out;
  • protect participants, systems, rights and reputation; prevent misuse, fraud and security incidents - legitimate interests and legal obligations;
  • meet accounting, tax, compliance, legal and regulatory obligations - legal obligation;
  • analyse and improve the website, programme and services - consent for non-essential analytics where required and legitimate interests for aggregated operational analysis.

6. Professional profiles and ecosystem visibility

Accepted Standing Holders may have a profile visible to authorised participants and, where expressly agreed or otherwise lawfully permitted, on public pages such as “Who Holds Standing”. The profile settings and participation terms should explain which information is public, restricted or private. We do not promise that every profile will be publicly displayed.

7. Leaders Concierge and introductions

Concierge requests may contain commercially sensitive or confidential professional information. You should avoid submitting privileged, client-identifying or highly confidential information unless specifically requested through an approved secure process. Information may be shared with internal teams, relevant constituent institutions or proposed professional contacts only to the extent necessary, appropriate and permitted. Engagement requests remain subject to relevance, availability, consent and professional obligations.

8. Events, photography and recordings

Events may be photographed, filmed, recorded or livestreamed. Event notices, registration terms and on-site signage should explain the intended uses. We may use event imagery and recordings for institutional reporting, archives, proceedings, editorial content and promotion, subject to applicable law and participant rights. Participants requiring special arrangements should contact [EVENT PRIVACY CONTACT] before the event.

9. Sharing personal data

We may share data with:

  • our employees, consultants and authorised service teams;
  • constituent institutions and programme partners where necessary for the relevant service or opportunity;
  • technology, hosting, CRM, communications, analytics, payment, accounting, security and support providers;
  • event venues, accommodation or logistics providers where necessary and disclosed;
  • professional advisers, auditors, insurers and financiers;
  • governmental, judicial or regulatory authorities where legally required;
  • a buyer, successor or restructuring party in connection with a genuine corporate transaction.

We do not sell personal data. Advertisers do not receive private participant communications merely because they advertise or sponsor an activity.

10. International transfers

UNBOUNDED is a global ecosystem. Personal data may be accessed or processed outside your country, including outside the European Economic Area or United Kingdom. Where required, we use recognised safeguards such as adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, contractual and organisational safeguards, or another lawful transfer mechanism.

11. Retention

We retain data only for as long as reasonably necessary for the relevant purpose, including:

  • unsuccessful or incomplete applications: ordinarily [12-24 MONTHS], unless a longer period is justified or consented to;
  • Annual Standing and participant records: for the relationship and ordinarily [6-7 YEARS] thereafter for legal, tax and contractual records;
  • Concierge and engagement records: ordinarily [3-6 YEARS], subject to sensitivity and legitimate operational needs;
  • marketing preferences and suppression records: for as long as necessary to respect preferences;
  • event photographs, proceedings and institutional archives: potentially long-term where there is continuing historical, editorial or institutional value, subject to rights and applicable law;
  • security logs and cookies: according to the relevant security or Cookie Notice periods.

12. Security

We use proportionate technical and organisational measures, including access controls, authentication, encryption where appropriate, secure providers, staff confidentiality, backups, monitoring and incident procedures. No internet system is completely secure, and you should protect your credentials and notify us promptly of suspected misuse.

13. Your rights

Subject to applicable law, you may have rights to access, correct, erase or restrict personal data; object to processing based on legitimate interests or direct marketing; receive portable data; withdraw consent; and complain to a supervisory authority. Automated decision-making producing legal or similarly significant effects will not be used unless lawfully implemented and disclosed.

Requests may be sent to [PRIVACY EMAIL]. We may need to verify identity. Under the GDPR, a response is generally due within one month, subject to lawful extensions.

14. Marketing preferences

You may unsubscribe using the link in an email or by contacting us. Service, contractual and safety communications may still be sent where necessary. We may retain minimal suppression information to ensure an opt-out remains effective.

15. Children

Our professional services are not directed to children. We do not knowingly collect personal data from children through Annual Standing or professional applications.

16. Third-party links and services

Our website may link to constituent institutions, venues, payment providers, social networks and other third parties. Their privacy practices are governed by their own notices.

17. Changes

We may update this Notice. Material changes will be highlighted through the website or direct communication where appropriate. The “last updated” date will identify the current version.

18. Complaints and contact

Contact: [PRIVACY EMAIL]; postal address: [REGISTERED ADDRESS]. You may also complain to the data-protection authority in your habitual residence, place of work or the place of an alleged infringement. For Spanish event-related processing, the competent authority may include the Agencia Española de Protección de Datos, subject to the final controller structure and legal advice.