Skip to content

Privacy Policy

Last updated · July 17, 2026

Privacy Policy

Last updated: 16 July 2026

This Privacy Policy explains how Team Fabri Projects VOF, trading as INNOCOS (“INNOCOS”, “we”, “our”, “us”), collects, uses, shares and protects personal data when you visit our website, register for or attend our summits and business tours, subscribe to our communications, or otherwise engage with us.

1. Who we are

We are the data controller for the personal data described in this policy.

Team Fabri Projects VOF, trading as INNOCOS

Seringenstraat 18, 3620 Lanaken, Belgium

Company registration (BCE/KBO): 0782311136

Privacy contact: privacy@innocosevents.com

Because we are established in Belgium, our lead supervisory authority is the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit).

2. Scope

This policy applies to our website and registration pages; our summits, business tours and related events wherever they are held, including in the European Economic Area, the United Kingdom, Switzerland, the United States and Asia; our newsletters, marketing and research activities; and our dealings with speakers, sponsors, partners, exhibitors and suppliers.

Where an event is held outside the EEA, local privacy laws may also apply to that event in addition to this policy.

3. The personal data we collect

Information you give us directly

  • Identity and professional details: name, job title, company, professional biography, country.
  • Contact details: email address, telephone number, postal address.
  • Registration and ticketing details, including any dietary or accessibility requirements you choose to share (see section 5).
  • Billing information. Card payments are handled by our payment providers; we do not store full payment card numbers.
  • Content you provide: survey responses, questions submitted during sessions, award entries, correspondence with us, and information shared during workshops or roundtables.
  • Speaker materials: biography, photograph and presentation content.

Information collected automatically

  • Basic technical data when you visit our website (IP address, browser type, pages viewed), collected through strictly necessary cookies — see section 11.

Information from other sources

  • Publicly available professional information (for example LinkedIn or company websites), used to identify potential speakers, partners and delegates.
  • Information from your employer or a colleague where they register you for an event.
  • Information from partners or ticketing platforms where you registered through them.

4. How we use personal data, and our legal basis

Under the GDPR we must have a lawful basis for each use of your data. Ours are as follows.

To register you for and deliver an event — confirmations, joining instructions, badges, delegate lists provided to our on-site team, catering and accessibility arrangements. Legal basis: performance of a contract with you, or steps taken at your request before entering into one.

To take payment and maintain accounting records. Legal basis: performance of a contract, and compliance with a legal obligation under Belgian accounting and tax law.

To send you our newsletter and information about our summits. Legal basis: your consent. Where you are an existing customer and we are marketing our own similar events, we may rely on our legitimate interests and the “soft opt-in” permitted under applicable e-privacy rules. You may withdraw consent or object at any time — see section 12.

To share your details with our research partners and event sponsors so that they may contact you. Legal basis: your separate, specific consent. We will not do this without your opt-in — see section 6.

To photograph, film and record our events. Legal basis: our legitimate interests in documenting and promoting our events; and your consent where we use your image in a prominent, individual or testimonial capacity — see section 7.

To conduct research, surveys and post-event analysis, and to improve future events. Legal basis: our legitimate interests in understanding and improving our programme.

To administer the Beauty & Longevity CHOICE Awards, including sharing entry materials with our judging panel. Legal basis: performance of a contract with entrants, and our legitimate interests in running a credible awards programme.

To protect our business — security, fraud prevention, enforcing our terms, and establishing or defending legal claims. Legal basis: our legitimate interests, and compliance with legal obligations.

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may ask us about that assessment, and you have the right to object — see section 12.

5. Special category data

We do not seek sensitive personal data. However, dietary requirements may reveal religious beliefs or health information, and accessibility requirements may reveal health information. Where you choose to provide these, we process them on the basis of your explicit consent, solely to accommodate you at the event, and we share them with venues and caterers only as far as necessary. You are never required to provide them.

6. Sharing your data with sponsors, partners and research partners

We will only share your contact details with a sponsor, exhibitor or research partner if you have given us your specific, separate opt-in consent. We ask for this at registration, we never bundle it with your ticket purchase or with our own newsletter, and we name the organisation concerned at the point we ask.

If you consent:

  • we share only the details stated at the point of consent — typically first name, last name, job title, company, email address and country;
  • the receiving organisation becomes an independent data controller and will use your data under its own privacy policy, including to send you marketing about its products and services;
  • we cannot control, and are not responsible for, that organisation’s subsequent use of your data — but you may withdraw your consent with us at any time, and you may exercise your rights, including objection and erasure, directly against them;
  • withdrawing consent with us stops any future sharing, but does not automatically delete data already transferred. We will tell you who received your data so that you can contact them, and we will pass your request on if you ask us to.

If you do not opt in, your details are not shared — and this has no effect whatsoever on your ticket, your access to the event, or anything else you receive from us.

We do not sell personal data for money. For the position under United States law, where “sale” is defined more broadly, see section 13.

7. Photography, filming and recording at our events

Our summits and business tours are photographed and filmed, and sessions may be recorded. We use this material to report on the event, to promote future events, and in our marketing and social media. We do this on the basis of our legitimate interests, which is standard practice at professional conferences, and we make it clear through this policy, our registration process and signage at the venue.

Where we wish to use your image in a prominent, individual, testimonial or endorsement capacity, we will ask for your consent first.

If you would prefer not to be photographed or filmed, please email privacy@innocosevents.com before the event, or speak to a member of our team on site, and we will do our best to accommodate you. You may also ask us to remove a specific image of you after the event, and we will do so unless we have a compelling reason not to.

Speaker sessions are recorded and may be published. We agree the terms of this with speakers separately.

8. Who else we share data with

  • Service providers acting on our instructions — event registration and ticketing platforms, email and CRM providers, payment processors, IT hosting and security providers. They may act only on our documented instructions and are bound by written contracts under Article 28 GDPR.
  • Venues, caterers, production and badging suppliers — where necessary to admit you and to meet any dietary or accessibility needs.
  • Award judges — for entries to the Beauty & Longevity CHOICE Awards.
  • Sponsors and research partners — only with your opt-in consent (section 6).
  • Professional advisers — lawyers, accountants and insurers, where necessary.
  • Authorities — where required by law, or to establish, exercise or defend legal claims.
  • An acquirer — if our business is sold or reorganised, in which case we will tell you.

You may ask us for the identity of the specific providers we use at any time by emailing privacy@innocosevents.com.

9. International transfers

We are based in Belgium, but we run events in the United States, Asia and elsewhere, and some of our service providers are located outside the EEA. When we transfer personal data outside the EEA, we rely on one of the following safeguards:

  • an adequacy decision by the European Commission — this covers, among others, the United Kingdom, Switzerland, South Korea and Japan;
  • for the United States, the EU–US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary measures where it is not;
  • Standard Contractual Clauses for other countries without an adequacy decision.

Where you attend an event outside the EEA, we transfer the minimum data necessary to the local venue and suppliers in order to deliver that event.

You may request a copy of the safeguards we use by emailing privacy@innocosevents.com.

10. How long we keep data

Data

Retention period

We keep personal data only for as long as we need it for the purposes set out in this policy, and no longer.

We keep registration and attendance records for the duration of our relationship with you and for three years afterwards. Invoices and accounting records we keep for seven years, as Belgian law requires. If you subscribe to our newsletter, we keep your details until you unsubscribe, after which we retain a minimal suppression record indefinitely, so that we do not contact you again by mistake. Prospect and speaker research data is kept for two years from our last meaningful contact with you, and general correspondence for three years.

Dietary and accessibility information is deleted within thirty days after the event. Award entries are kept for three years, to protect the integrity of the programme. Event photography and film is retained as part of our marketing archive, and removed on request as described in section 7.

Where we no longer need your data, we delete it or anonymise it so that it can no longer be linked to you. Where data has been shared with a partner under your consent, that partner sets its own retention period as an independent controller.

11. Cookies

Our website uses strictly necessary cookies only — those required to make the site and our registration process work. Under EU e-privacy rules these do not require your consent, and we do not use advertising, profiling or third-party tracking cookies.

If this changes, we will update this policy and, where required, ask for your consent through a cookie banner before setting any non-essential cookies.

12. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (the “right to be forgotten”) in certain circumstances;
  • restrict our processing in certain circumstances;
  • object to processing based on our legitimate interests, and to object at any time to direct marketing, which we will always honour;
  • data portability — to receive data you gave us in a machine-readable format, or have it sent to another controller;
  • withdraw consent at any time where we rely on consent. This does not affect the lawfulness of processing carried out before withdrawal;
  • not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not carry out such processing.

To exercise any of these rights, email privacy@innocosevents.com. We will respond within one month, as the GDPR requires. We may ask you to verify your identity. There is no charge, unless a request is manifestly unfounded or excessive.

You can unsubscribe from marketing at any time using the link in every email.

Complaints. If you are unhappy with how we have handled your data, please tell us first and we will try to put it right. You also have the right to lodge a complaint with a supervisory authority — in particular the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, Belgium (www.dataprotectionauthority.be) — or with the authority in your country of residence or work.

13. United States residents

If you are a resident of California or another US state with comprehensive privacy legislation, you may have the right to know what personal information we collect and how we use it; to request its deletion or correction; to opt out of the “sale” or “sharing” of your personal information and of targeted advertising; and not to be discriminated against for exercising these rights.

On “sale” and “sharing”: we do not sell personal information for money. However, under California law “sale” is defined broadly to include disclosure for other valuable consideration, and our partner and sponsor arrangements may involve exchanging data-sharing for other benefits. We only ever share your details with a named partner where you have opted in (section 6), and you may withdraw that consent at any time by emailing privacy@innocosevents.com, which stops any further sharing. We do not use cross-context behavioural advertising.

To exercise US state privacy rights, email privacy@innocosevents.com. You may use an authorised agent.

14. Security

We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including access controls, encryption in transit, and contractual protections with our suppliers. No system is perfectly secure, but we take our obligations seriously, and we will notify you and the Belgian Data Protection Authority of a personal data breach where the law requires it.

15. Children

Our website, summits and business tours are directed at professionals and are not intended for children under 16. We do not knowingly collect data from children. If you believe we have, please contact us and we will delete it.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the “last updated” date above. Where changes are material, we will tell you directly. We will not use your data for a materially different purpose without a lawful basis — and where that basis is consent, without asking you first.

17. Contact

Team Fabri Projects VOF, trading as INNOCOS

Seringenstraat 18, 3620 Lanaken, Belgium

BCE/KBO: 0782311136

privacy@innocosevents.com

We aim to acknowledge privacy enquiries promptly and will respond substantively within one month, as the GDPR requires.