Privacy Statement
How Wiredin Events LLC collects, uses, and protects personal data in connection with this website and the Congress.
1. Introduction and Scope
Wiredin Events LLC (“Wiredin”, “we”, “us”, or “our”) is a healthcare engagement agency and professional conference organizer (PCO) established in Dubai, United Arab Emirates. In the course of our activities we collect and process personal data belonging to event attendees, healthcare professionals, speakers, faculty, scientific committee members, sponsors, exhibitors, suppliers, website visitors, and users of our digital platforms.
This Privacy Statement explains what personal data we collect, why we collect it, the legal bases on which we process it, with whom we share it, how long we keep it, how we protect it, and the rights available to you. It is the single authoritative reference for all Wiredin systems and services, including:
- the Wiredin corporate website and any microsites or event websites we operate, including this website;
- our event and congress registration systems, including online registration forms, on-site registration, badge issuance, and attendance tracking;
- Scholaris (scholaris.health), our continuing medical education (CME) platform for healthcare professionals; and
- our customer relationship management (CRM) and communications systems used to manage contacts and send communications.
This Statement applies to individuals whose personal data we process regardless of their location. Our delegates, faculty, sponsors, and platform users are based in the United Arab Emirates, across the Gulf Cooperation Council region, and internationally. Your personal data is processed and stored primarily in the United Arab Emirates, subject to the international transfer safeguards described in Section 10, irrespective of the country from which you register or access our platforms.
Not every system collects every category of data described in this Statement. Section 5 sets out which categories of personal data are collected by which system. Where a specific event, program, or platform requires additional or different processing, we will provide a supplementary notice at the point of collection.
By using our websites and platforms, and by completing registration for an event we organize or co-organize, you confirm that you have read and agree to this Privacy Statement and to the applicable event terms and conditions. That wording is shown at the point of registration. Where we contact you about our other events and educational activities, we do so on the basis described in Section 7, and you may object or unsubscribe at any time as described in Section 14.
2. Data Controller and Contact Details
The data controller responsible for the processing described in this Statement is:
Wiredin Events LLC
Concord Tower, Dubai Media City, Dubai, United Arab Emirates
Trade License No.: 952713 (Dubai Department of Economic Development)
Email for privacy matters: privacy@wiredin.ae
Data protection queries, requests, and complaints under this Statement should be directed to the contact details above.
For certain events, Wiredin acts as a processor on behalf of a client (for example, a pharmaceutical company, medical society, or government entity that commissions an event). Where that is the case, the client is the data controller, and this will be indicated in the event-specific registration notice. This Statement continues to describe our security and handling practices in those situations.
3. Legal Framework
This Statement is prepared in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“PDPL”) and its Executive Regulations, together with other applicable UAE legislation. Where we process personal data of individuals located in other jurisdictions (for example, international delegates or faculty), we take account of the data protection laws applicable to those individuals, including, where relevant, the EU/UK General Data Protection Regulation (“GDPR”) for delegates from those jurisdictions.
Nothing in this Statement limits any right you have under applicable law.
4. Key Definitions
- Personal data means any data relating to an identified natural person, or a natural person who can be identified directly or indirectly by way of linking data, including name, identification number, location data, online identifiers, or factors specific to physical, physiological, economic, cultural, or social identity.
- Sensitive personal data means data that directly or indirectly reveals racial or ethnic origin, religious or philosophical beliefs, political opinions, criminal records, biometric data, or data concerning health.
- Processing means any operation performed on personal data, including collection, storage, recording, organization, use, disclosure, transfer, or erasure.
- Controller means the party that determines the purposes and means of processing.
- Processor means the party that processes personal data on behalf of a controller.
5. Personal Data We Collect, by System
We apply the principle of data minimization: we collect only what is necessary for the stated purpose. Individual events may collect a subset of these categories; the registration form for each event shows exactly what is requested for that event.
5.1 Corporate Website and Event Websites
Contact and inquiry data (name, email, phone, organization, job title, message content); Newsletter and marketing data (email and preferences); Technical and usage data (IP address, browser/device info, pages visited, cookie identifiers, see Section 9).
5.2 Event and Congress Registration Systems
Identity data (full name, title, gender, nationality, date of birth); Contact data (email, phone, address, city, country); Professional data (employer, department, job title, specialty, license number and issuing authority e.g. DHA/DOH/MOHAP, years of experience); Registration and eligibility data (registration category, fee category, proof of eligibility such as student card, enrollment letter, employer letter, or where specifically required an identity document, see Section 6); Payment data (method, transaction reference, billing/invoicing; full card numbers processed by licensed payment providers, not stored by Wiredin); Event participation data (sessions attended, badge scans, check-in/out, workshop selections, dietary/accessibility requirements, travel/accommodation where arranged by us); Audio-visual data (photos/recordings, where notified); Communications data (correspondence with our registration team).
Note on dietary and accessibility requirements: these may indirectly reveal health or religious information, which is sensitive personal data. We collect them only where volunteered, use them solely to accommodate participation, restrict access to them, and delete them after the event.
5.3 Scholaris (CME Platform)
Scholaris collects a narrower set of data than event registration and does not collect identity documents, date of birth beyond accreditation needs, payment card details, or dietary/accessibility data. Account data (name, email, hashed password, country, professional role); Professional data (specialty, place of work, license number where required for CME/CPD credit); Learning data (courses, assessments, credits, certificates, activity for accreditation evidence); Technical data (login records, IP, device/browser, cookies).
5.4 CRM and Communications
Our CRM consolidates professional contact information (name, role, specialty, institution, email, phone, country) from event registrations, Scholaris accounts, business interactions, and public professional sources, plus a record of our communications and your stated preferences. We do not store identity documents, payment data, or sensitive personal data in the CRM.
6. Identity Documents (Emirates ID, Passport, and Similar)
For most events, no identity document is required. We may request a copy of, or the number from, an identity document only where: a government authority, regulator, or venue requires verified identification as a condition of the event permit or venue access; verification is required to confirm eligibility for a restricted or discounted registration category and no less intrusive proof is sufficient; or required by law.
Safeguards applied when identity documents are collected: the requirement and reason are stated at the point of collection; documents are stored in a segregated, access-restricted repository, separate from our general contact database, with access limited to named personnel who need it for the stated purpose; documents are encrypted in transit and at rest; documents are not used for any other purpose, not added to marketing or CRM records, and not shared with sponsors or exhibitors; documents are deleted once the verification or regulatory purpose is fulfilled, or at the end of any mandated retention period. Where a less intrusive document, such as a student card or employer letter, is sufficient to establish eligibility, we accept it instead.
Speakers and faculty are a separate case. Government event-licensing rules require individual speaker permits, and the documents required depend on nationality and residency status. For events licensed in Abu Dhabi, the Department of Culture and Tourism – Abu Dhabi requires a recent photograph for UAE citizens and residents, and a passport copy with a recent photograph for GCC and other foreign nationals, with a UAE visa copy in addition where the speaker enters on a mission or visit visa. Dubai events holding a DET or DTCM permit have equivalent requirements for speakers. We collect these documents only to obtain the permit that allows the speaker to present, and we apply the same safeguards set out above. A speaker cannot be confirmed without the permit, so this collection is a regulatory requirement rather than a matter of choice.
7. Purposes of Processing and Legal Bases
Under the PDPL, processing of personal data requires the consent of the data subject unless another lawful basis applies, including where processing is necessary for the performance of a contract to which the data subject is party, for compliance with a legal obligation, or in the other cases set out in the PDPL.
| Purpose | Legal basis |
|---|---|
| Event registration and delivery (badges, confirmations, attendance, delegate services) | Performance of a contract; consent for optional fields |
| CME/CPD accreditation (attendance, results, certificates, credit reporting) | Performance of a contract; compliance with accreditation requirements |
| Identity and eligibility verification (discounted categories; permit/venue security) | Compliance with a legal or regulatory obligation; performance of a contract; consent where neither applies |
| Payments and accounting (fees, invoices, VAT compliance) | Performance of a contract; compliance with legal obligations |
| Sponsor and exhibitor reporting (aggregate attendance statistics; attendee details only as described in Section 8) | Consent |
| Marketing and scientific communications (upcoming congresses, CME programs relevant to your specialty) | Legitimate interest, with the right to object at any time |
| Platform operation and security (accounts, authentication, fraud prevention, troubleshooting) | Legitimate operation of our services; compliance with legal obligations |
| Compliance and legal claims (lawful requests from authorities; legal claims) | Compliance with legal obligations; exercise of legal rights |
| Photography and recording at events (documentation, reporting, promotional material where notified) | Consent, provided at registration or venue, with the ability to object |
Where we rely on consent, you may withdraw it at any time as described in Section 13. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. Disclosure and Sharing of Personal Data
We do not sell personal data. We share personal data only as follows:
- Accrediting and regulatory authorities. For accredited CME/CPD activities, we report attendance and credit data to the relevant accrediting authority as required to issue and validate credits.
- Event clients. Where an event is commissioned by a client or organizing society and Wiredin acts as processor, data is shared with that entity as controller, as disclosed in the event-specific registration notice. Post-event reporting to a society or contracting entity is otherwise provided in aggregate form.
- Sponsors and exhibitors. Where a sponsor or partner arranges attendance for delegates, we receive those delegates’ registration details from that sponsor in order to register them. Reporting we provide to sponsors and exhibitors after an event describes the composition of the audience in aggregate and does not identify individual delegates. Badge scanning during an event records attendance. Where identifiable delegate details are to be shared with a sponsor or exhibitor for any event, the basis for that is stated at the point of collection for that event.
- Service providers. We use third-party providers for registration and event technology, CME platform hosting, email delivery, payment processing, cloud storage, badge printing, and audiovisual production. Providers act on our documented instructions under contracts imposing confidentiality and data protection obligations, and may not use your data for their own purposes.
- Venues and security. Where a venue or government authority requires attendee identification for access or permit purposes, we share the minimum required data with that party.
- Dubai government authorities (DET / DTCM). Where an event uses a Dubai Department of Economy and Tourism (DET) registration or promotional code, or requires a DET or Dubai Department of Tourism and Commerce Marketing (DTCM) permit, we share the delegate data required by that authority. DTCM operates under the DET umbrella. DET acts as data controller for the personal data it receives, under its own privacy notice at dubaidet.gov.ae, and can be contacted at privacy@dubaidet.ae. This is disclosed at the point of registration for the events concerned.
- Abu Dhabi government authorities (DCT Abu Dhabi). Where an event is held in Abu Dhabi, it is licensed by the Department of Culture and Tourism – Abu Dhabi (DCT Abu Dhabi) under the Abu Dhabi Events Licensing System (Decree No. 54 of 2016), applied for through the TAMM platform. We submit the event and participant details that system requires. Speakers and faculty must additionally be permitted individually, which requires identification documents as described in Section 6. Where tickets are issued, they are processed through the DCT Events Licensing E-Ticketing System. DCT Abu Dhabi acts as data controller for the data it receives, under its own privacy policy at dct.gov.ae.
- Professional advisers and authorities. We may disclose data to auditors, legal advisers, insurers, courts, or public authorities where required by law or necessary to protect our legal rights.
- Corporate transactions. If Wiredin is involved in a merger, acquisition, or asset transfer, personal data may be transferred as part of that transaction, subject to this Statement.
9. Cookies and Similar Technologies
Our websites and platforms use cookies and similar technologies, falling into strictly necessary, functional, analytics, and marketing categories. Non-essential cookies are set only with your consent, which you can give, refuse, or withdraw through the cookie banner or your browser settings. See our Cookie Notice for the full list of cookies used on this site.
10. International Transfers of Personal Data
Some of our service providers, faculty, accrediting bodies, and clients are located outside the United Arab Emirates, and some of our systems are hosted on cloud infrastructure located outside the UAE. Where personal data is transferred outside the UAE, we do so in accordance with the PDPL and its Executive Regulations, by transferring: to jurisdictions recognized as providing an adequate level of protection; or subject to appropriate safeguards, such as contractual clauses imposing data protection obligations equivalent to those of the PDPL; or where a specific derogation under the PDPL applies, including your express consent to the transfer after being informed of the absence of adequate protection, or where the transfer is necessary for the performance of a contract with you.
You may contact us using the details in Section 2 for more information about the safeguards applied to a specific transfer.
11. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, to comply with legal, regulatory, accounting, or accreditation requirements, or to establish, exercise, or defend legal claims. Indicative retention periods: identity documents collected for verification are deleted promptly once the verification or regulatory purpose is fulfilled, unless a specific period is mandated by the requiring authority. Event registration records are generally retained for 5 years from the close of the event cycle. CME/CPD records and certificates are retained for the period required by the relevant accrediting authority. Financial and invoicing records are retained per UAE commercial, tax, and VAT legislation. Marketing contact data is retained until you withdraw consent or object, or until it is no longer accurate or necessary. Dietary and accessibility data is deleted after the conclusion of the relevant event. Website technical logs are retained briefly for security and troubleshooting purposes, then deleted or anonymized. When data is no longer required, it is securely deleted or irreversibly anonymized.
12. Security of Personal Data
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction, proportionate to the nature of the data and the risks of processing. These measures include encryption of personal data in transit and at rest; role-based access controls; segregated, restricted storage for identity documents and other higher-risk data; hashed storage of account passwords; contractual data protection obligations imposed on all service providers; logging and monitoring of access to systems holding personal data; staff confidentiality obligations and data protection awareness; and periodic review of security measures and access rights. No system can be guaranteed absolutely secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately using the details in Section 2.
13. Your Rights
Subject to the conditions and exceptions in the PDPL and other applicable law, you have the following rights in relation to your personal data: right of access; right to rectification; right to erasure; right to restriction of processing; right to data portability; right to object, including to direct marketing; and rights relating to automated decision-making (Wiredin does not currently carry out decision-making based solely on automated processing that produces legal or similarly significant effects). To exercise any of these rights, contact us using the details in Section 2. We may need to verify your identity before acting on a request. We will respond within the timeframes required by applicable law. If you are not satisfied with our response, you have the right to lodge a complaint with the UAE Data Office or any other competent supervisory authority.
14. Consent, Withdrawal, and Marketing Preferences
Where processing is based on your consent, you may withdraw that consent at any time, free of charge, by using the unsubscribe link in any marketing email, adjusting your account settings on Scholaris, or contacting us using the details in Section 2. Withdrawal of consent does not affect processing that is necessary for a contract you have with us or processing required by law.
Unsubscribe options operate at more than one level. You may unsubscribe from a specific mailing or campaign, from communications relating to a specific Society where you have registered for events organized on behalf of more than one, or from all Wiredin communications. A request to stop all communications is always available and is honored in full. Each request is tracked separately.
Marketing communications are sent only to individuals who have consented to receive them or, where permitted by law, existing contacts in respect of similar services, always with a clear opt-out. Scientific and educational communications directed at healthcare professionals are managed in accordance with applicable UAE health authority rules on communications to healthcare professionals.
15. Minors
Our websites, events, and platforms are directed at professionals and adults. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete it.
16. Third-Party Websites and Services
Our websites, event apps, and communications may contain links to third-party websites, including those of sponsors, venues, accrediting bodies, and payment providers. This Statement does not apply to those third parties, and we are not responsible for their privacy practices.
17. Personal Data Breach Notification
In the event of a personal data breach that would prejudice your privacy or the confidentiality or security of your personal data, we will notify the UAE Data Office and, where required, the affected individuals, in the manner and within the timeframes prescribed by the PDPL and its Executive Regulations, together with information about the nature of the breach and the measures taken to address it.
18. Changes to This Statement
We may update this Statement from time to time to reflect changes in our activities, systems, or legal obligations. The current version, with its effective date, is published on our website and platforms. Material changes will be highlighted, and where a change requires renewed consent, we will seek it. This Statement, from Version 6.1 onward, replaces and supersedes any shorter privacy policy previously published on the Wiredin website. Where any earlier published version conflicts with this Statement, this Statement applies.
19. Contact and Complaints
Questions, requests, or complaints regarding this Statement or our handling of your personal data should be directed to:
Wiredin Events LLC — privacy@wiredin.ae — +971 4 454 9815 — Concord Tower, Dubai Media City, Dubai, United Arab Emirates.
If we are unable to resolve your concern, you may lodge a complaint with the UAE Data Office or another competent supervisory authority.
