The data controller for personal data collected through the TripnBusiness platform is:
In accordance with the GDPR, each processing activity relies on a legal basis.
| Processing Purpose | Legal Basis (GDPR) | Retention Period |
|---|---|---|
| Account management and authentication | Performance of contract (Art. 6.1.b) | Account duration + 3 years |
| Event registration and management | Performance of contract (Art. 6.1.b) | 5 years after the event |
| Payment processing and transactions | Performance of contract (Art. 6.1.b) | 10 years (accounting obligations) |
| Electronic wallet management | Performance of contract (Art. 6.1.b) | 10 years (legal obligations) |
| Networking and B2B meeting services | Performance of contract (Art. 6.1.b) | Account duration + 1 year |
| Transactional notifications | Performance of contract (Art. 6.1.b) | Account duration |
| Marketing communications | Consent (Art. 6.1.a) | Until consent is withdrawn |
| Usage statistics (anonymised) | Legitimate interest (Art. 6.1.f) | Retained indefinitely in anonymous form |
| Fraud prevention and security | Legitimate interest (Art. 6.1.f) | 5 years after detection |
| Legal and fiscal obligations | Legal obligation (Art. 6.1.c) | As required by applicable law |
| E-SIM service | Performance of contract (Art. 6.1.b) | E-SIM contract duration + 1 year |
TripnBusiness never sells, rents or transfers your personal data to third parties for commercial purposes. Data sharing is limited to situations strictly necessary for the provision of the service.
We engage technical service providers who process data on our behalf, strictly under our instructions and bound by confidentiality agreements. These include:
Within networking features, certain profile information (name, professional title, company, photo) may be visible to other attendees registered for the same event. You can manage your profile visibility in the application settings. Scanning a badge via QR Code implies sharing your contact information with the participant who scans it.
TripnBusiness may be required to disclose personal data to competent authorities upon judicial request or legal obligation, strictly limited to what is required by law.
Where data is transferred to countries outside the European Economic Area (EEA), TripnBusiness ensures such transfers are governed by appropriate safeguards under the GDPR, including: European Commission adequacy decisions, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs).
These cookies are essential to the operation of the platform and cannot be disabled. They include session, authentication and security cookies (CSRF token). Legal basis: legitimate interest.
These cookies remember your preferences (language, display settings) and improve your experience but are not essential. Legal basis: consent.
These cookies collect anonymised information about platform usage (pages visited, session duration) to help us improve our services. Legal basis: consent or legitimate interest depending on the nature of the data.
On your first visit to the website, a consent banner allows you to configure your preferences. You may update these at any time via your browser settings or through the platform’s cookie management centre. On the mobile app, analytical data is collected only with your consent at installation or via app settings.
In accordance with the GDPR (Articles 15 to 22), you have the following rights regarding your personal data:
Obtain confirmation that data concerning you is being processed and receive a copy of it.
Request correction of inaccurate or incomplete data. Most information can be updated directly in the app.
Request deletion of your data when it is no longer necessary, unless a legal obligation requires its retention.
Receive your data in a structured, machine-readable format (JSON or CSV) and transfer it to another controller.
Object to processing based on legitimate interest or to direct marketing at any time.
Request restriction of processing when you contest the accuracy of data or the lawfulness of processing.
Withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
Define instructions regarding the retention, deletion or communication of your data after your death.
To exercise any of these rights, contact our DPO at dpo@tripnbusiness.com, enclosing a copy of a valid identity document. We will respond within 1 month of receiving your request (extendable by 2 months for complex requests).
If you believe your rights are not being respected, you may lodge a complaint with the competent supervisory authority: in France, the CNIL (www.cnil.fr), or the data protection authority in your country of residence.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, TripnBusiness will notify the competent supervisory authority within 72 hours of becoming aware of the incident (Art. 33 GDPR). Where the breach is likely to result in a high risk, you will be informed without undue delay (Art. 34 GDPR).
The TripnBusiness platform is exclusively intended for professionals and adults aged 18 or over. TripnBusiness does not knowingly collect personal data from minors. If you become aware that a minor has provided us with personal data without the consent of their legal guardian, please contact us so that we may delete it.
The TripnBusiness platform integrates or provides access to third-party services whose data processing is governed by their own privacy policies, independent of this policy:
We encourage you to review the privacy policies of these third-party services before using them.
TripnBusiness collects and analyses aggregated, anonymised usage data (event registrations, feature usage rates, website and app traffic, system performance) to continuously improve its services. These analyses do not allow individual Users to be identified and are never shared with third parties for commercial purposes.
TripnBusiness reserves the right to update this privacy policy to reflect legal, regulatory or technical developments. In the event of a material change, you will be notified by email and/or in-app notification at least 30 days before the changes take effect.
For any questions regarding this privacy policy, the exercise of your rights, or to report a data protection incident:
You may also lodge a complaint with the competent national supervisory authority: