Last updated: 30th March 2021
MCI Group Holding SA, 9, Rue du Pré-Bouvier, 1242 Satigny, Geneva, Switzerland or relevant MCI entity (“MCI”) is an event and association management company with operations and subsidiaries in many countries around the world which provides association, congress management, meetings and event services to its corporate or association clients (the “Client”).
According to the article 27 of the GDPR, MCI Benelux, 280 Boulevard du Souverain 1160 Brussels, Belgium, has been appointed by MCI Group as representative within the European Union.
It is MCI’s utmost concern to constantly improve its services in order to best meet the needs of its Clients. To this end, MCI may collect and store certain information, including personal data of people like you. MCI takes the protection of your personal data very seriously in all of its business processes. This Data Protection Statement is meant to help you understand how data are collected, processed and stored to meet legal requirements and MCI’s data protection standards.
1. Scope of this Data Protection Statement
This Data Protection Statement applies to all services offered by MCI.
This Data Protection Statement does not apply to services offered by other companies or individuals. This Data Protection Statement does not cover the information practices of other companies and organizations who advertise MCI services or any third party operating any website to which the MCI website or other digital asset may contain a link.
2. Data collected and method of collection
MCI collects general and personal data concerning you from:
- you when you provide your details to MCI;
- its Clients (in such cases, Client must ensure that it is entitled to disclose such data and that you are aware of the various matters detailed in this Data Protection Statement);
- participants at Client’s meetings and events organized by MCI;
- users of MCI’s or Client’s websites; and third parties (such as online service provider or single sign on authority).
Following the reception of the data, an electronic profile is created in MCI tools for each person or entity (the “Contact Profile”).
The Contact Profile may contain but is not limited to:
- date of birth;
- phone numbers;
- email addresses;
- physical location data during an event
- ADA (American Disability Act) information
- food or allergies preferences
- emergency contact information
- organization or company of employment and/or job title;
- field of activity and/or interest;
- credit card references/numbers;
- travel destinations;
- travel schedules;
- travel preferences;
- accommodation preferences;
- other communicated preferences;
- passport; and
- visa details.
- additional information as requested by Clients on events
MCI may process sensitive personal data based on a specific and explicit additional consent of data subjects.
By attending an event, individual authorizes, free of charge and without consideration of any kind whatsoever, that any image and sound recording made in connection with the event, by video and/or audio recording, and/or photograph on which it appears, may be used, reproduced, modified and broadcast on any medium known or unknown to date and in particular on social networks or its Sites, by Dorier or by any MCI Group company within the meaning of the regulations in force, or their partners, for the duration of exploitation of the video and/or audio recordings, and/or photographs.
3. Purpose of data collection
MCI uses the data collected to provide, maintain, protect and improve the overall quality of its services. Data collection is also meant to protect MCI and its users. MCI does not collect more data than is necessary to fulfil such purposes.
In addition to creating Contact Profiles, MCI uses your data for the following purposes and for which you give your consent:
a) Bookings: The Contact Profiles are stored in a database as a reference document to be consulted each time a booking is to be made. When a booking is made, MCI creates a booking code that contains all of the personal data along with the booking information that is needed to fulfil your request and to fulfil regulatory requirements for certain destinations. To make bookings, MCI might need to transfer personal data to various third-party travel suppliers (such as airlines, hotels, car rental companies, online booking tool companies, safety and security tracking providers and computer booking systems) within your home country or in another country where you may be traveling and often also to government bodies for certain destinations. Legal basis: Contract;
b) Travel reports consolidation: At the request of a Client, MCI or a third party may prepare information reports that summarize and analyse the expenditures per destination, per travel supplier, etc. Such reports which may include certain personal data from your Contact Profile are then submitted to the requesting Client. Legal basis: Contract;
c) Compliance with travel policy: At the request of a Client, MCI may report on your compliance with the event compliance policy, budget compliance policy or travel policy of such Client and identify any exceptions to the compliance. Legal basis: Contract;
d) New products and services: With the goal of improving services and based on the data given to MCI, MCI may send you additional information related to your current or future event(s) and/or trip(s). An example might be a list of restaurants near a specific hotel in the destination city or parking facilities at the departure airport. Legal basis: Legitimate interest – improve MCI business activities and services;
e) Promotion and marketing: MCI may use your data to personalize your experience on the MCI website by presenting advertisements that are more relevant to you, to send you marketing communications that we believe may be of interest to you, including information about our services, case studies, thought leadership or whitepapers, blog updates, etc. For example, MCI uses third party service providers to present services and offers tailored to the preferences and interests demonstrated by your online activity over time. MCI may use your data for promotion and marketing purposes for MCI’s current or prospective Clients and/or third parties in MCI’s industry. MCI may use your data to personalize your experience on the event website by presenting advertisements that are more relevant to you, and to send you marketing communications as chosen by you in the registration process. MCI may use the data to analyse trends in order to propose other services to its Clients, such as new events or other services.
Legal basis: Consent;
f) Statistical analysis related to websites: MCI, or third parties instructed by MCI, evaluate this data purely for statistical purposes and only in an anonymised form, in order to optimize MCI’s website and increase user-friendliness, efficiency and safety. MCI may in particular use technical data to measure the success of MCI marketing campaigns, compile statistics about MCI website usage and response rates, and use aggregated personal data calculate the percentage of MCI users who have a particular telephone area code. Legal basis: Consent;
g) Job opportunities management:
Legal basis: Pre-Contractual conditions
h) Creation of a resume library:
Legal basis: Legitimate interest – reinforce MCI recruiting process
MCI may disclose your Data to third parties where such disclosure is permitted and required by law or court order, or where such disclosure is necessary for the protection and defence of its rights.
Other than in these cases, your Data will not be transferred or made available to any third party without your prior consent.
4. Duration of storage
General and personal data will be kept by MCI no longer than necessary for the execution of the purposes aforementioned. MCI will retain general and personal data during a maximum period of five years if no specific legal requirement. For applicants, the data will be retained for a maximum period of two years.
You may cancel/delete your MCI account by sending an email to our Data Protection Officer: email@example.com.
5. Location of storage and controller of data base
The Contact Profiles that MCI maintains are stored in cloud-based central databases at third-party providers’ location in Europe, United States and Asia. Third-party providers have signed our dedicated data protection clauses.
Any transfer of your Data outside the European Economic Area shall only take place with appropriate safeguards in place, such as contractual terms in compliance with applicable data protection laws and regulations.
You may have further information on the above by sending an email to our Data Protection Officer: firstname.lastname@example.org.
6. Your duties
You must ensure that the data you provide us with are:
- truthful; and
- compliant with any applicable laws.
In particular, since MCI will mainly use email communications with you, you are required to notify us of any modification of your email address. Alternatively, you can directly update your Contact Profile.
MCI is committed to protecting the privacy needs of children and we encourage parents and guardians to take an active role in their children’s online activities. MCI does not target the digital asset to children less than fourteen (14) years of age or knowingly collect information from children for the purpose of selling products or services.
7. Transfer and communication of data
7.1 In general
MCI is a worldwide company with offices in over 31 countries across Europe, the Americas, Asia and the Middle East. Your personal data may therefore be transferred to and outside of Switzerland, including in countries whose data protection laws may be different from, and less stringent than, those in your country of residence.
a) Transfers within the MCI group: Transfers are made throughout MCI and its subsidiaries to support its activities and/or services.
As part of its activities, MCI works with a certain number of recurring partners who process personal data on our behalf for specific purposes:
- Badge provider
- Benchmarking tool
- Event management platforms
- Mobile event application
This list is not exhaustive and can be updated from time to time. We invite you to regularly consult this list to keep up to date with any changes.
c) Regulatory transfers: MCI may be required by law to transfer data to governments and regulatory and/or supervisory authorities.
8. Security and organizational measures
To ensure the safety of your data on MCI’s website and systems, MCI has implemented appropriate technical, contractual, administrative, physical and organizational measures to protect your personal data from loss, destruction, unauthorized access, accidental or unlawful disclosure and manipulation. These measures are subject to continuous development in accordance with technological progress and are periodically reviewed to comply with all applicable privacy laws.
Only authorized MCI staff, third party companies’ (i.e. service providers) staff or our Clients' authorized staff (who have contractually agreed to keep all information secure) have access to your personal data. All MCI staff who have access to your personal data are required to adhere to the staff confidentiality regulations and all third-party employees who have access to your personal data have signed non-disclosure agreements. In addition, data transfer
agreements are in place with third-party companies that have access to your personal data to make sure these data remain secure.
In accordance with applicable data protection laws and regulations, you have a right to request access to, rectification of your Data, or restriction of processing, and to object to said processing, as well as the right to data portability to the extent applicable. Moreover, you have a right to lodge a complaint with a supervisory authority.
Under certain conditions you also have the right to have your personal data that is stored by MCI blocked and deleted, unless MCI has to keep these data for legitimate business or legal purposes. For more information, you should contact the Data Protection Officer at the above-mentioned e-mail address
To contact MCI with questions or issues about MCI’s data processing, you should contact the Data Protection Officer at the following e-mail address: email@example.com.
As per GDPR requirements, MCI gives you many choices regarding MCI’s use and disclosure of your personal data for marketing purposes (right to be forgotten, to modification, to limitation…). By contacting the Data Protection Officer at the above-mentioned e-mail address, you may opt-out from receiving future electronic marketing messages from MCI and request that we not share your personal data with unaffiliated third parties for their marketing purposes. MCI will try to comply with your request(s) as soon as reasonably practicable.
Please note that if you opt-out as described above, MCI will not be able to remove your personal data from the databases of unaffiliated third parties with which MCI has already shared your personal data (i.e., to which we have already provided your personal data as of the date that we implement your opt-out request).
Please also note that if you do opt-out of receiving marketing-related messages from MCI, we may still send you important administrative messages, and you cannot opt-out from receiving administrative messages.
This Statement may be revised and updated by MCI from time to time to comply with statutory data protection and privacy laws. MCI will post any statement changes on its website and, if the changes are significant, MCI will send a notice to the e-mail address provided in your Contact Profile.
If you need further assistance, please contact our Data Protection Officer via: E-mail address: firstname.lastname@example.org
Address: MCI Group Holding SA, Data Protection Officer, rue du Pré-Bouvier 9, 1242 Satigny, Switzerland.
For US residents and requests under CCPA (California Consumer Privacy Act): +18337910490