Privacy Policy

Wines Experience · Effective date: 24 August 2026 · Last updated: 24 August 2026 · Version 1.0

This Privacy Policy (the “Policy”) describes how Piazza Italia LLC (“Company”, “we”, “us” or “our”) collects, uses, discloses, retains and protects personal information in connection with the Wines Experience mobile application, its web application, the exhibitor management area, and any related services that link to this Policy (together, the “Services”).

The Services are a professional networking platform for wine-industry trade events. Their purpose is to enable participants at an event — including buyers, importers, distributors, press and exhibiting producers — to identify relevant counterparts, communicate, and arrange business meetings. The scope of the personal information we process follows directly from that purpose, and we do not process personal information for purposes unrelated to it.

Please read this Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood it. If you do not agree with our practices, please do not use the Services.

Table of Contents

  1. Scope of This Policy

  2. Definitions

  3. Information We Collect

  4. Information We Do Not Collect

  5. How We Use Information

  6. Legal Bases for Processing

  7. Automated Processing and Match Suggestions

  8. How We Disclose Information

  9. International Data Transfers

  10. Data Retention

  11. Account Deletion

  12. Information Security

  13. Your Rights and Choices

  14. Children’s Privacy

  15. Third-Party Services and Links

  16. Changes to This Policy

  17. How to Contact Us

Annexes

  • Annex A — Additional Disclosures for the EEA, United Kingdom and Switzerland

  • Annex B — Additional Disclosures for Mexico (Aviso de Privacidad)

  • Annex C — Additional Disclosures for United States Residents

  • Annex D — Categories of Service Providers

1. Scope of This Policy

This Policy applies to personal information processed by the Company in its capacity as controller in connection with the Services, including information relating to:

  • Attendees, being buyers, importers, distributors, sommeliers, members of the press and other registered visitors to an event;

  • Exhibitor and sponsor representatives, being individuals who represent an exhibiting or sponsoring company;

  • Speakers appearing in an event programme; and

  • Organizer personnel who administer an event.

This Policy does not apply to: (a) the processing of personal information by exhibitors, sponsors or other participants who obtain information from you in the course of an event, each of whom acts as an independent controller in respect of such information; (b) third-party websites or services accessible from the Services; or (c) information that is not personal information under applicable law.

Where an event is organized by a third-party organizer using the platform, that organizer determines the purposes of processing in respect of its own event and acts as controller for it. This Policy addresses processing carried out in respect of events organized by the Company.

2. Definitions

  • “Personal information” (also “personal data”) means information relating to an identified or identifiable natural person.

  • “Processing” means any operation performed on personal information, including collection, storage, use, disclosure and erasure.

  • “Controller” means the entity that determines the purposes and means of processing.

  • “Processor” means an entity that processes personal information on behalf of, and on the documented instructions of, a controller.

  • “Event” means a trade event, fair or exhibition for which the Services are made available.

  • “Participant” means any registered user of the Services in connection with an Event.

3. Information We Collect

3.1 Information You Provide to Us

(a) Account information. Your name, email address and, where you elect to provide it, a telephone number. Your password is collected solely for authentication and is stored exclusively as a salted cryptographic hash; it is not recoverable in plain text by the Company or by any person with access to our systems.

(b) Profile information. Job title, seniority, the company or organization you represent, country, languages spoken, geographic regions in which you operate or source, a free-text biography, and up to two profile photographs.

(c) Interests and business objectives. The categories of business interest and objective you select, including wine styles, regions and types of commercial relationship sought.

(d) Visibility preferences. The setting you select governing which Participants may view your profile.

(e) Communications content. The content of messages you exchange with other Participants through the Services, and the metadata associated with them, including timestamps and the identity of the parties to the conversation.

(f) Registration responses. Any answers you provide in response to questions presented during registration or ticket purchase.

3.2 Information We Receive from Event Organizers and Third Parties

(a) From the Event organizer or its ticketing process. Your name, email address, ticket or pass type, participant group and company affiliation may be provided to us prior to your first use of the Services. This is the ordinary means by which exhibitor representative accounts are created.

(b) From exhibitors. Where an exhibitor records a note in connection with a business contact obtained from you, that note is stored in association with the contact record.

(c) From payment processors. Confirmation of payment, transaction references, amounts and status. We do not receive full payment card numbers.

3.3 Information Generated Through Your Use of the Services

(a) Activity information. Meeting requests sent and received and their status; meetings scheduled, including time and location within the venue; sessions and tastings added to your agenda; profiles viewed; and expressions of interest in other Participants.

(b) Derived matching data. A numerical vector representation derived from the interests and objectives you have selected, used exclusively to compute relevance scores between Participants. This representation is not human-readable, is not disclosed to any Participant or third party, and is deleted with your account.

(c) Contact exchange records. Where you present your badge to be scanned by an exhibitor, a record comprising your name, email address and company affiliation, together with any note recorded by that exhibitor.

(d) Communications metrics. In respect of emails sent to you in connection with an Event, delivery status and engagement events, namely delivery, opening, link clicks, bounces and unsubscribe requests.

(e) Device tokens. Where you enable push notifications, an opaque device token issued by your operating system vendor, used solely to route notifications to your device.

4. Information We Do Not Collect

The Company considers the following commitments to be a material part of this Policy:

  • The Services incorporate no third-party analytics software, no advertising software development kit, and no social media tracking pixel.

  • We do not collect or process advertising identifiers and do not track you across applications or websites operated by other companies.

  • We do not collect precise or background geolocation data. The Services do not track your movement within a venue or elsewhere.

  • We do not access your address book, contacts, calendar or photo library, other than the individual image you expressly select when setting a profile photograph.

  • We do not access the microphone or record audio. Camera access is invoked solely at the point you scan a badge or QR code.

  • We do not transmit crash reports or diagnostic telemetry to the Company or to any third party. Application errors are surfaced on your device and are not transmitted.

  • We do not process special categories of personal data within the meaning of Article 9 of the GDPR, and ask that you do not submit such information through free-text fields.

5. How We Use Information

We use personal information for the following purposes:

  1. Provision of the Services. Creating and administering your account; displaying your profile to other Participants in accordance with your visibility setting; processing meeting requests and scheduling; transmitting messages; maintaining your agenda; and issuing and validating admission credentials.

  2. Match suggestions. Computing relevance between Participants on the basis of stated interests and objectives, and presenting suggested counterparts, as further described in Section 7.

  3. Communications. Sending operational and service communications relating to an Event, your registration, your meetings and your messages, and responding to your enquiries.

  4. Transactions. Processing registrations, ticket purchases and related transactions, and maintaining associated financial records.

  5. Safety, security and integrity. Detecting, investigating and preventing fraud, abuse, spam, unauthorized access and other conduct that violates our terms or applicable law.

  6. Service maintenance and improvement. Diagnosing faults, maintaining availability, and understanding in aggregate how the Services are used in order to improve them.

  7. Legal and regulatory compliance. Complying with applicable law, including tax and accounting obligations, and responding to lawful requests from competent authorities.

  8. Establishment, exercise or defence of legal claims.

6. Legal Bases for Processing

Where the GDPR or equivalent legislation applies, we process personal information on the following legal bases:

  • Performance of a contract (Article 6(1)(b)) — for the purposes described in Section 5(1), 5(3) insofar as the communications are operational, and 5(4).

  • Legitimate interests (Article 6(1)(f)) — for the purposes described in Section 5(2), 5(5), 5(6) and 5(8). Our legitimate interests are in providing an effective networking product, protecting the Services and their users, and defending our legal position. We have assessed in each case that these interests are not overridden by your interests, rights and freedoms, taking into account that the information concerned is professional in nature, is provided by you for this express purpose, and remains under your control.

  • Compliance with a legal obligation (Article 6(1)(c)) — for the purposes described in Section 5(7).

  • Consent (Article 6(1)(a)) — for push notifications and for any processing not otherwise described in this Policy. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

7. Automated Processing and Match Suggestions

The Services compare the interests and objectives declared by Participants and generate a relevance score, which is used to order suggestions and to indicate the basis on which two Participants may find a meeting valuable.

This constitutes automated processing but does not constitute a decision producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 of the GDPR. The output is advisory only. It does not determine admission to an Event, pricing, or any entitlement, and it does not oblige any Participant to accept contact from any other. Each Participant determines independently whom to contact and whether to accept a request. You may modify or remove the interests upon which the computation is based at any time, or set your profile to hidden, in which case no suggestions are generated in respect of you.

8. How We Disclose Information

8.1 To Other Participants

Your profile, comprising your name, photograph, job title, company, country, languages and declared interests, is disclosed to other Participants in the same Event in accordance with the visibility setting you select:

  • Visible to the Event — your profile appears in the participant directory, in search results and in match suggestions.

  • Visible to matches only — your profile is disclosed only to Participants with whom a mutual connection exists.

  • Hidden — your profile is not disclosed in the directory, in search, or in suggestions.

Your email address and telephone number are not disclosed to other Participants through your profile in any visibility setting.

8.2 To Exhibitors

Where you present your badge to be scanned by an exhibitor, you thereby disclose to that exhibitor your name, email address and company affiliation as a business contact. The exhibitor receives that information as an independent controller, retains it under its own privacy practices, and may export it to its own customer relationship management systems. Deletion of your account does not, and cannot, recall information disclosed to an exhibitor in this manner, in the same way that deletion of an account would not recall a business card. Requests for erasure of such information should be addressed to the exhibitor directly.

8.3 To the Event Organizer

The organizer of an Event has access to registration information, participation records and activity in respect of that Event. Where the Company is the organizer, such access is exercised by the Company.

8.4 To Service Providers

We disclose personal information to service providers who process it on our documented instructions and are contractually prohibited from using it for their own purposes. The categories of service provider, and their functions, are set out in Annex D.

8.5 For Legal Reasons

We may disclose personal information where we determine in good faith that disclosure is reasonably necessary to: (a) comply with applicable law, regulation, legal process or governmental request; (b) enforce our terms of service, including investigation of potential violations; (c) detect, prevent or address fraud, security or technical issues; or (d) protect against harm to the rights, property or safety of the Company, our Participants or the public.

8.6 Corporate Transactions

In connection with a merger, acquisition, reorganization, financing, sale of assets, or insolvency, personal information may be transferred to a successor or acquirer. We will provide notice before personal information becomes subject to a different privacy policy.

8.7 No Sale of Personal Information

We do not sell personal information. We do not rent, trade or otherwise make personal information available to data brokers. We do not disclose personal information to advertising networks, and we do not use personal information for cross-context behavioural advertising.

9. International Data Transfers

The Company operates Events internationally and engages service providers located in jurisdictions other than your own, including the United States. Where personal information is transferred outside the European Economic Area, the United Kingdom or Switzerland, such transfer is made pursuant to an appropriate transfer mechanism, being: (a) an adequacy decision of the European Commission or equivalent determination; or (b) the Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures determined to be necessary following a transfer impact assessment. A copy of the relevant safeguards may be requested from the contact address in Section 17.

10. Data Retention

We retain personal information for no longer than is necessary for the purposes for which it was collected, subject to the following criteria:

  • Account and profile information — for the duration of your account.

  • Participation and activity records — for the duration of your account, and thereafter in the reduced form described in Section 11.

  • Message content — for so long as the relevant conversation subsists for the Participants party to it.

  • Registration, ticketing, transaction and accounting records — for the period prescribed by applicable tax and accounting legislation, typically between five and ten years from the end of the relevant financial year.

  • Email delivery and engagement metrics — for the duration of the relevant Event cycle and a reasonable period thereafter.

  • Push notification device tokens — until notifications are disabled, you sign out, or the token is invalidated by the operating system vendor.

  • Records relating to legal claims — for the duration of the applicable limitation period.

11. Account Deletion

You may delete your account at any time, without charge and without providing a reason, from within the Services: open Settings and select Delete my account. No contact with the Company is required.

11.1 Information erased. Upon deletion we erase your profile, photographs, biography, declared interests and objectives, derived matching data, expressions of interest and matches, notification settings, authentication credentials and sessions, and your participant record in respect of every Event. Profile photographs are deleted from file storage. Your profile ceases to appear in the directory, in search and in match suggestions.

11.2 Information retained, and the basis for retention.

  • Message content you originated remains accessible to the Participants with whom you corresponded, attributed to a deleted user without name, photograph or profile. A conversation constitutes a record belonging to both parties, and erasure of one party’s contributions would deprive the other of a record of a business communication in which they participated. Retention is on the basis of our legitimate interests and those of the other Participant.

  • Business contact information disclosed to an exhibitor by means of a badge scan is retained by that exhibitor as an independent controller, as described in Section 8.2.

  • Transaction and accounting records are retained for the period required by law, dissociated from your account where dissociation is technically feasible.

  • A participation record is retained by the organizer, comprising your name, email address, the Events in which you participated, the group or pass type held, the dates of registration and deletion, and summary totals of your activity. It contains no photograph, no biography and none of your declared interests. Retention is on the basis of our legitimate interest in maintaining an accurate record of the Events we have organized, including attendance and commercial history.

11.3 Objection to retention. If you wish the participation record described above to be erased, you may object by writing to the contact address in Section 17. We will assess the objection against any overriding legitimate ground or legal obligation, and where none applies we will erase the record and confirm that we have done so.

12. Information Security

We implement technical and organizational measures appropriate to the risk, including:

  • Storage of authentication credentials exclusively as salted cryptographic hashes, which are not reversible;

  • Encryption of all traffic between the Services and our servers in transit;

  • Storage of authentication tokens in the secure storage facility provided by your device’s operating system;

  • Restriction of access to production systems to personnel requiring such access to operate the Services;

  • Segregation of payment card data, which is processed by our payment processor and does not enter our systems; and

  • Minimization of collection, such that information not necessary for the purposes described in this Policy is not collected at all.

No method of transmission or storage is completely secure, and we do not warrant absolute security. In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will communicate the breach to affected individuals without undue delay where the breach is likely to result in a high risk to them.

13. Your Rights and Choices

Subject to applicable law, you may exercise the following rights:

  • Access — to obtain confirmation as to whether we process personal information concerning you and, where we do, a copy of it together with information about the processing.

  • Rectification — to obtain correction of inaccurate personal information and completion of incomplete personal information. Most profile information may be corrected directly within the Services.

  • Erasure — to obtain erasure of personal information where one of the grounds in Article 17 of the GDPR applies. Account deletion is available directly within the Services, as described in Section 11.

  • Restriction of processing — to obtain restriction of processing in the circumstances specified by applicable law.

  • Data portability — to receive personal information you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller where technically feasible.

  • Objection — to object, on grounds relating to your particular situation, to processing based on our legitimate interests, including the match suggestions described in Section 7. Where you object, we will cease processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms.

  • Withdrawal of consent — to withdraw consent at any time where processing is based on consent.

13.1 Choices available within the Services

  • Profile visibility — adjustable at any time, including to “hidden”.

  • Push notifications — may be disabled within the Services or in your device’s system settings.

  • Email communications — each communication contains an unsubscribe facility. Communications strictly necessary to the Services, such as authentication messages and changes to your scheduled meetings, will continue while your account subsists.

  • Account deletion — available within the Services at any time.

13.2 How to exercise your rights

Requests may be submitted to privacy@italianexpo.us. We will respond without undue delay and in any event within one month of receipt. That period may be extended by a further two months where necessary, taking into account the complexity and number of requests, in which case we will inform you within one month of receipt together with the reasons. No fee is payable unless the request is manifestly unfounded or excessive. We may request information reasonably necessary to verify your identity before acting on a request.

14. Children’s Privacy

The Services are professional tools intended exclusively for persons aged 18 years or older. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will delete it without undue delay. If you believe a child has provided personal information to us, please contact us at the address in Section 17.

15. Third-Party Services and Links

The Services may contain links to, or information about, exhibitor websites, sponsor materials, venue information and other third-party services. Such third parties are not controlled by us and process personal information in accordance with their own privacy policies, for which we accept no responsibility. We encourage you to review those policies before providing personal information to them.

16. Changes to This Policy

We may amend this Policy from time to time to reflect changes to the Services, our practices, or applicable law. The date of the most recent revision appears at the head of this document. Where an amendment materially affects the processing of your personal information, we will provide notice through the Services or by email in advance of the amendment taking effect, and where required by law we will obtain your consent.

17. How to Contact Us

Questions, requests and complaints concerning this Policy or our processing of personal information may be addressed to:

Piazza Italia LLC
728 Anthony Trail, Northbrook, 60062 IL
privacy@italianexpo.us

We have not designated a Data Protection Officer, not being required to do so under Article 37 of the GDPR. Enquiries submitted to the address above are handled directly by responsible personnel.

Annex A — Additional Disclosures for the EEA, United Kingdom and Switzerland

A.1 Controller. The controller is the entity identified in Section 17.

A.2 Legal bases. The legal bases on which we rely are set out in Section 6.

A.3 Legitimate interests. Where we rely on legitimate interests, those interests are: providing an effective professional networking product; protecting the security and integrity of the Services; maintaining accurate records of the Events we organize; and establishing, exercising or defending legal claims. You may obtain further information regarding the balancing assessment performed by contacting us.

A.4 Right to lodge a complaint. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. In the United Kingdom, the competent authority is the Information Commissioner’s Office. We would ask that you contact us first, as most matters are resolved more quickly directly.

A.5 Statutory or contractual requirement. Provision of your name and email address is necessary to create an account and to participate in an Event. Provision of profile, interest and objective information is optional, but the match suggestion functionality cannot operate meaningfully without it.

A.6 International transfers. See Section 9.

Annex B — Additional Disclosures for Mexico (Aviso de Privacidad)

This Annex is provided pursuant to the Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares) and its implementing regulations, and together with the body of this Policy constitutes our privacy notice for those purposes.

B.1 Identity and address of the responsible party. As set out in Section 17.

B.2 Personal data processed. As set out in Section 3. We do not process sensitive personal data.

B.3 Purposes. Primary purposes are those set out in Section 5(1) to 5(4) and 5(7), being necessary to the legal relationship between us. Secondary purposes are those set out in Section 5(5) and 5(6). You may object to processing for secondary purposes by writing to the address in Section 17, without affecting your participation in an Event.

B.4 ARCO rights. You are entitled to exercise the rights of Acceso (access), Rectificación (rectification), Cancelación (cancellation) and Oposición (objection), and to limit the use or disclosure of your personal data. A request should state your name and an address for reply, be accompanied by documentation establishing your identity or that of your legal representative, describe clearly the personal data concerned, and include any element facilitating its location. Requests should be sent to privacy@italianexpo.us.

B.5 Revocation of consent. You may revoke consent to the processing of your personal data by the same means, save where continued processing is required by law or necessary to the performance of an existing obligation.

B.6 Transfers. Transfers are as described in Sections 8 and 9. Transfers to service providers acting on our behalf do not require your consent under Article 37 of the said Law.

B.7 Supervisory authority. You may bring a complaint before the competent Mexican authority for the protection of personal data.

Annex C — Additional Disclosures for United States Residents

This Annex applies to residents of California and of other states having enacted comprehensive consumer privacy legislation, to the extent such legislation applies to us.

C.1 Categories of personal information collected. In the preceding twelve months we have collected the following categories: identifiers (name, email address, telephone number, account identifiers); professional or employment-related information (job title, seniority, employer); commercial information (registrations, tickets and transactions); internet or other electronic network activity information limited to activity within the Services; audio, electronic or visual information limited to profile photographs you upload; and inferences limited to the relevance scores described in Section 7. The sources, purposes and recipients are described in Sections 3, 5 and 8 respectively.

C.2 Sensitive personal information. We do not collect sensitive personal information as defined by such legislation, and accordingly do not use or disclose it for purposes requiring the offer of a right to limit.

C.3 Sale and sharing. We have not sold personal information and have not shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not do so. We do not knowingly sell or share the personal information of consumers under 16 years of age.

C.4 Rights. Subject to applicable law you have the right to know, the right to access, the right to delete, the right to correct, the right to opt out of sale or sharing (inapplicable, as described above), and the right not to receive discriminatory treatment for exercising any right. Requests may be submitted as described in Section 13.2, and may be submitted by an authorized agent on your behalf upon provision of evidence of authority.

C.5 Non-discrimination. We will not deny goods or services, charge different prices, or provide a different level or quality of service because you exercised a privacy right.

Annex D — Categories of Service Providers

  • Supabase — database hosting and object storage for uploaded images.

  • Railway — hosting and operation of application servers.

  • Brevo — transmission of transactional email and recording of delivery and engagement metrics.

  • Stripe — payment processing. Stripe processes payment information as an independent controller in accordance with its own privacy policy.

  • Expo — delivery of push notifications and application updates.

  • Apple and Google — distribution of the mobile application through their respective application stores, in accordance with their own privacy policies.

We review our service providers periodically and enter into data processing agreements incorporating the terms required by applicable law.