Privacy Policy

Privacy Policy

Last Updated: April 2024

This Privacy Policy explains how Gondonella Events LLC ("we," "us," "our," or "Company") collects, uses, discloses, and otherwise processes personal information in connection with our website, event management services, and other interactions with you.

Please read this Privacy Policy carefully. By accessing or using our website or services, you acknowledge that you have read, understood, and agree to be bound by all of the terms of this Privacy Policy.


1. Data Controller

Company Name: Gondonella Events LLC

Address: 450 Park Avenue South, Suite 1200, New York, NY 10016

Contact Email: [email protected]

Phone: +1 (855) 233-2839

Gondonella Events LLC ("Data Controller") is responsible for determining the purposes and means of processing your personal information. We are committed to transparent data practices and compliance with all applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy legislation.

As a premium event management company serving clients across North America, we understand that trust is fundamental to our business. This Privacy Policy sets forth our commitment to protecting your personal information and your privacy rights.


2. Information We Collect

We collect personal information through various means and from different sources. The information we collect may vary depending on your interaction with us.

2.1 Information You Provide Directly

Contact Information:

  • Full name
  • Email address
  • Phone number
  • Mailing address
  • Company name and title

Event Planning Information:

  • Event type and details
  • Expected number of attendees
  • Event date and location
  • Budget and timeline information
  • Specific service requirements and preferences
  • Venue preferences and special requests

Account Information:

  • Username and password (if you create an account)
  • Billing and payment information
  • Event history and preferences

Communication Data:

  • Content of emails, messages, and calls
  • Feedback and inquiries you submit
  • Support requests and responses
  • Testimonials and reviews

Content You Upload:

  • Event photos and videos
  • Design files and specifications
  • Attendee lists and registration information
  • Contracts and agreements

2.2 Information Collected Automatically

Website Usage Information:

  • IP address
  • Device type and operating system
  • Browser type and version
  • Pages visited and time spent
  • Referring website information
  • Click patterns and navigation paths
  • Search terms used

Cookies and Similar Technologies:

  • Cookie identifiers and preferences
  • Tracking pixels and web beacons
  • Local storage data
  • Session information

Location Information:

  • General geographic location (city/state level)
  • GPS data (if you consent on mobile devices)

Communications Data:

  • Call recordings (with consent)
  • Email open rates and click tracking
  • Delivery and read receipts

2.3 Information from Third Parties

From Service Providers:

  • Payment processors (transaction and billing information)
  • Venue and vendor partners (event coordination details)
  • Email service providers (communication records)

From Business Partners:

  • Co-event organizers or sponsors
  • Referral partners and affiliates

From Publicly Available Sources:

  • Social media profiles (LinkedIn, Instagram, Facebook)
  • Business directories and industry databases
  • Public records

From Other Users:

  • Attendee information provided by event organizers
  • Referrals and recommendations
  • Event feedback and reviews

3. How We Use Your Data

We process your personal information for legitimate business purposes. The specific ways we use your information include:

3.1 Service Delivery

  • Planning, coordinating, and managing your events
  • Communicating about event details and requirements
  • Scheduling consultations and meetings
  • Processing event registrations and attendee management
  • Providing AV, technical, and on-site coordination services
  • Creating event proposals and cost estimates
  • Managing contracts and service agreements

3.2 Communication and Support

  • Responding to your inquiries and requests
  • Sending event confirmations and reminders
  • Providing customer support and troubleshooting
  • Conducting surveys and gathering feedback
  • Sending newsletters and marketing communications (with consent)
  • Emergency communications regarding events

3.3 Business Operations

  • Scheduling and calendar management
  • Invoice generation and payment processing
  • Vendor and supplier coordination
  • Event documentation and record-keeping
  • Quality assurance and performance monitoring
  • Staff training and development

3.4 Analytics and Improvement

  • Analyzing website usage patterns and trends
  • Measuring marketing campaign effectiveness
  • Understanding user preferences and needs
  • Improving website functionality and user experience
  • Optimizing event planning processes
  • Developing new services and features

3.5 Legal Compliance and Safety

  • Complying with legal obligations and court orders
  • Maintaining required business records
  • Fraud detection and prevention
  • Security threat identification and prevention
  • Resolving disputes and enforcing agreements
  • Protecting our legal rights

3.6 Marketing and Business Development

  • Sending promotional materials and offers
  • Inviting you to webinars and industry events
  • Case study development (with consent)
  • Industry research and trend analysis
  • Referral program management

4. Legal Basis for Processing

Under applicable data protection laws, we process your personal information based on one or more of the following legal bases:

4.1 Consent

We process information based on your explicit consent for specific purposes, such as marketing communications and newsletter subscriptions. You have the right to withdraw consent at any time by contacting us.

4.2 Contract

We process information necessary to fulfill our event management contracts with you, including planning, coordination, payment processing, and service delivery.

4.3 Legitimate Interests

We process information based on our legitimate business interests, including:

  • Improving our services and website
  • Analyzing business performance
  • Preventing fraud and security threats
  • Marketing and business development
  • Understanding customer needs and preferences

When relying on legitimate interests, we balance these against your privacy rights.

4.4 Legal Obligation

We process information when required by law, including:

  • Tax and accounting requirements
  • Labor and employment laws
  • Consumer protection regulations
  • Anti-fraud and financial regulations

5. Data Sharing and Disclosure

We may share your personal information with third parties in the following circumstances:

5.1 Service Providers

We share information with vendors and service providers who assist with event management, including:

  • Venue operators and catering services
  • AV equipment rental companies
  • Transportation and logistics providers
  • Payment processors and financial institutions
  • Email and communication service providers
  • Cloud storage and IT service providers

All service providers are contractually required to maintain confidentiality and use information only for specified purposes.

5.2 Legal Requirements and Law Enforcement

We may disclose information if required by law, court order, or government request, including:

  • Compliance with subpoenas and legal process
  • Response to law enforcement inquiries
  • Cooperation with regulatory authorities
  • Enforcement of legal rights and protection from harm

5.3 Business Transfers

If Gondonella is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

5.4 With Your Consent

We may share information with third parties when you explicitly consent, such as:

  • Sharing testimonials or case studies
  • Participation in industry partnerships
  • Referral programs
  • Joint event coordination

5.5 Aggregated and De-identified Information

We may share aggregated or de-identified information that cannot reasonably identify you. This information does not constitute personal information.

5.6 Other Attendees and Collaborators

For events you attend or organize, we may share relevant information with:

  • Other registered attendees (names, affiliations)
  • Event sponsors and partners
  • Co-organizers and collaborators

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law.

6.1 Retention Periods

Event Management Information:

  • Active events: Throughout event planning and completion
  • Completed events: 3-7 years (for legal, tax, and contractual purposes)
  • Post-event records: 7 years (in accordance with business record requirements)

Customer Account Information:

  • Active accounts: During account maintenance
  • Inactive accounts: 2 years after last interaction
  • Upon account deletion: 30-60 days for backup purposes

Marketing Communications:

  • Subscribers: Until unsubscribe request
  • Non-subscribers: Removed upon request

Website Analytics:

  • Cookies: 6 months to 2 years
  • Log files: 90 days
  • Analytics data: 38 months

Sensitive Information:

  • Payment information: Minimized and retained only as required for payment processing
  • Health information: Deleted after event completion unless needed for future event planning

6.2 Deletion Requests

You may request deletion of your information subject to legal and contractual retention obligations. We will securely delete information upon request unless required to maintain it.


7. Data Security

We implement comprehensive security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.

7.1 Technical Security Measures

  • Encryption: SSL/TLS encryption for data in transit; AES-256 encryption for sensitive data at rest
  • Firewalls: Advanced firewalls and intrusion detection systems
  • Access Controls: Restricted database access with role-based permissions
  • Security Monitoring: 24/7 system monitoring and threat detection
  • Regular Updates: Timely security patches and software updates

7.2 Administrative Security Measures

  • Employee Training: Mandatory data protection and security training
  • Access Policies: Strict policies limiting access to personal information
  • Vendor Management: Contractual security requirements for service providers
  • Incident Response: Documented procedures for security breach response

7.3 Physical Security Measures

  • Facility Security: Restricted access to offices and data centers
  • Document Protection: Secure storage of physical records
  • Visitor Management: Controlled access for non-employees

7.4 Limitations

While we maintain robust security practices, no security system is completely impenetrable. We cannot guarantee absolute security of information transmitted over the internet or stored electronically. You are responsible for maintaining the confidentiality of your passwords and login credentials.


8. Your Privacy Rights

Depending on your location, you have certain rights regarding your personal information. We are committed to honoring these rights.

8.1 Right of Access

You have the right to access your personal information and receive a copy of the data we process about you. Upon request, we will provide a complete overview of information we hold.

How to Exercise: Submit a written request to [email protected] with "Data Access Request" in the subject line.

Response Timeline: 30 days

8.2 Right of Rectification/Correction

You have the right to correct inaccurate or incomplete information. We will promptly update your information upon your request.

How to Exercise: Contact us with specific corrections needed. You may update certain information through your account settings.

Response Timeline: 30 days

8.3 Right to Erasure ("Right to Be Forgotten")

You may request deletion of personal information, except where we have legal obligations to retain it. Note that deletion may not be possible if:

  • Information is needed to complete an event
  • Legal or contractual obligations require retention
  • Information is necessary for legitimate business purposes

How to Exercise: Submit a written request to [email protected] with "Erasure Request" in the subject line.

Response Timeline: 30 days

8.4 Right to Restrict Processing

You may request that we limit how we use your information. During the restriction period, we will store the information but limit its active processing.

How to Exercise: Contact [email protected] specifying which processing activities to restrict.

Response Timeline: 30 days

8.5 Right to Data Portability

You have the right to receive your information in a structured, commonly-used, machine-readable format and to transmit it to another controller.

How to Exercise: Request data portability via [email protected]. We will provide data in CSV or similar format within 30 days.

Response Timeline: 30 days

8.6 Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate interests or legal obligations.

How to Exercise: Contact [email protected] with "Objection to Processing" in the subject line.

Response Timeline: 30 days

8.7 Right to Withdraw Consent

If we process information based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to Exercise: Use the unsubscribe link in emails or contact [email protected].

Response Timeline: Immediate

8.8 Right to Non-Discrimination

We will not discriminate against you for exercising any of these rights. You will receive the same quality of service regardless of whether you exercise privacy rights.


9. International Data Transfers

Gondonella is based in the United States. If you are located in the European Union, European Economic Area, or other jurisdictions with data protection laws, your information may be transferred to and processed in the United States.

9.1 Legal Framework

We implement appropriate safeguards for international transfers, including:

  • Standard Contractual Clauses: Authorized transfer mechanisms under GDPR
  • Adequacy Decisions: Reliance on adequacy determinations where applicable
  • Consent: Your explicit consent for international transfer

9.2 Your Rights

By providing information, you acknowledge that data may be transferred and processed internationally. You maintain all privacy rights regardless of transfer location.


10. Children's Privacy

Our services are not directed to children under 16 years of age. We do not intentionally collect personal information from children under 16. If we become aware that we have collected information from a child under 16, we will delete such information promptly.

10.1 Parental Consent

If a minor provides information through our website or services, we require parental consent. Parents may contact us to:

  • Verify information we have collected
  • Request deletion of their child's information
  • Prohibit further collection or use of their child's information

Parental Contact: [email protected] with "Parental Concern" in the subject line.


11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors.

11.1 Notification of Changes

When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post the updated policy on our website
  • Send email notification for material changes
  • Require consent for new uses of information

11.2 Your Acceptance

Continued use of our services after changes indicates your acceptance of the updated Privacy Policy. We recommend reviewing this policy periodically.


12. Contact Us

If you have questions about this Privacy Policy, our data practices, or to exercise your privacy rights, please contact:

Gondonella Events LLC Privacy Department

Email: [email protected]

Mailing Address: 450 Park Avenue South, Suite 1200 New York, NY 10016

Phone: +1 (855) 233-2839

Data Protection Officer (if applicable): [email protected]

Response Timeline

We aim to respond to all privacy inquiries and requests within 30 days. Complex requests may require additional time, which we will communicate promptly.


This Privacy Policy is effective as of April 2024 and was last updated on April 2024.

Thank you for trusting Gondonella with your personal information. We are committed to protecting your privacy and maintaining your trust.