Privacy Policy
Last updated July 8, 2026 · Version 2026.07
This is a template pending legal review. Company registration details are placeholders.
This Privacy Policy explains how Mesher Technologies GmbH ("Mesher", "we", "us", or "our") collects, uses, discloses, and safeguards personal data when you use the Mesher platform and its related websites, consoles, and applications (together, the "Service"). It is a single global policy followed by region-specific sections for the EU/EEA, California, and Türkiye. For how we use cookies and similar technologies, see our Cookie Policy.
1. Controller and contact details
The controller responsible for your personal data is:
- Controller
- Mesher Technologies GmbH (Gesellschaft mit beschränkter Haftung)
- Address
- Friedrichstraße 123, 10117 Berlin, Germany
- Privacy contact
- privacy@mesher.events
- Data Protection Officer
- dpo@mesher.events
- EU/EEA representative (GDPR Art. 27)
- not appointed — Mesher is established in the EU/EEA
If you have any question about this policy or how we handle your data, contact us using the details above.
2. Personal data we collect
We collect the following categories of personal data, depending on how you interact with the Service:
- Account data — name, email address, password (stored only as a salted hash), organization, role, and language preference.
- Usage and log data — IP address, device and browser type, pages viewed, actions taken, timestamps, and diagnostic logs.
- Payment and billing data — billing name, address, tax/VAT identifiers, plan, invoices, and the last four digits and token of a payment method (full card numbers are processed by our payment provider, not stored by us).
- Cookie and device data — identifiers and preferences set through cookies and similar technologies (see the Cookie Policy).
- User content — information you and your organization upload or generate in the Service, such as exhibitions, exhibitor records, attendee data, messages, and documents.
- Communications — the content of support requests, emails, and other correspondence with us.
3. How we collect data
- Directly from you — when you register, configure your account, make a payment, upload content, or contact us.
- Automatically — through cookies, SDKs, and server logs as you use the Service.
- From third parties — such as your organization's administrator, single sign-on (SSO) identity providers, payment processors, and publicly available sources, where lawful.
4. Why we process your data
We process personal data for the following purposes:
- Service delivery — to create and operate your account, provide platform features, and support your use of the Service.
- Billing and payments — to process subscriptions, invoices, taxes, renewals, and refunds.
- Security and fraud prevention — to authenticate users, protect accounts, detect abuse, and maintain audit trails.
- Communications — to send service, security, and transactional messages and to respond to your requests.
- Analytics and improvement — to understand usage and improve the reliability, performance, and features of the Service.
- Marketing — to send you information about Mesher where permitted, which you can decline at any time.
- Legal compliance — to meet our legal, tax, and accounting obligations and to establish, exercise, or defend legal claims.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on the following legal bases (Art. 6(1) GDPR):
- Performance of a contract (Art. 6(1)(b))
- To provide the Service, operate your account, and process payments under our Terms of Service.
- Legitimate interests (Art. 6(1)(f))
- To secure the Service, prevent fraud and abuse, run analytics, and carry out direct marketing — balanced against your rights and interests.
- Consent (Art. 6(1)(a))
- For non-essential cookies and certain marketing. You may withdraw consent at any time, without affecting prior processing.
- Legal obligation (Art. 6(1)(c))
- To comply with tax, accounting, and other statutory duties.
7. International data transfers
Your data may be processed in countries other than your own. Where we transfer personal data outside the EU/EEA, the UK, or other regions with data-export rules, we use a lawful transfer mechanism — such as an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) with supplementary safeguards — to protect your data. You may request a copy of the relevant safeguards using the contact details above.
8. How long we keep data
We keep personal data only as long as necessary for the purposes above, then delete or anonymize it. Typical retention periods:
- Account data
- For the life of the account and a limited period after closure to handle disputes and legal claims.
- Billing and tax records
- For the period required by applicable tax and accounting law (commonly up to 10 years).
- Usage and log data
- For a limited period for security and diagnostics, then deleted or aggregated.
- User content
- Until you or your organization delete it, or the account is closed, subject to backup cycles.
9. Your rights
Subject to your local law, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase data (the "right to be forgotten") in certain circumstances.
- Restrict or object to certain processing, including direct marketing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
To exercise any right, contact privacy@mesher.events. We will respond within the time required by applicable law. You may also lodge a complaint with your supervisory authority — in our case, Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin DPA).
11. Security
We apply appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, tenant isolation, audit logging, and least-privilege practices. No method of transmission or storage is completely secure, but we work to protect your data and to address incidents promptly.
12. Children's data
The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us data, contact privacy@mesher.events and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the new version here with an updated "Last updated" date and version, and, for material changes, provide additional notice (for example, by email or an in-product message) where required.
14. EU/EEA residents
If you are in the EU/EEA, the GDPR governs our processing of your personal data. The legal bases in Section 5, the transfer safeguards in Section 7, and the rights in Section 9 apply to you. You may contact our EU/EEA representative (not appointed — Mesher is established in the EU/EEA) or lodge a complaint with your local supervisory authority.
15. California residents (CCPA/CPRA)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of "sale" or "sharing" of personal information. We do not sell your personal information and do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising your rights. To make a request, contact privacy@mesher.events.
16. Türkiye (KVKK)
If you are in Türkiye, the Personal Data Protection Law No. 6698 ("KVKK") applies. As data controller, we process your personal data based on the legal grounds in KVKK Art. 5–6. Under Art. 11, you may request information about processing, access, correction, deletion, and object to results produced solely by automated analysis. To exercise these rights, contact privacy@mesher.events.
17. Contact us
For any privacy request or question, contact Mesher Technologies GmbH at privacy@mesher.events, or by post at Friedrichstraße 123, 10117 Berlin, Germany.