Legal documents

Privacy Policy of the PROD by Zowie Conference

This policy describes how personal data is processed in relation to persons visiting the event website, submitting a request to attend the PROD by Zowie conference and taking part in it. The processing of speakers’ personal data is governed by a separate document provided to speakers.

Version applies as of 25 August 2026

1. Data controller

The controller of personal data is Zowie Europe sp. z o.o. with its registered office in Warsaw, Marszałkowska 107, 00-110 Warsaw, Poland, entered in the register of entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under KRS number: 0000764826, NIP: 5272877599, share capital: PLN 20 000 (hereinafter: the “Controller”).

Contact in matters relating to personal data: contact@zowie.ai.

2. Scope of the policy

The policy covers the processing of personal data in relation to the use of the event website, the sending of an invitation by the Controller, the submission of a request to attend through the registration form, the handling of invitation codes, participation in the event and the recording of its course.

The Controller is not the same entity as Zowie, Inc. The privacy policy available at getzowie.com/privacy-policy relates to services provided by Zowie, Inc. and does not apply to the processing of personal data described in this policy, save for the cookies referred to in section 13.

The rules for requesting to attend and for taking part in the event are set out in the Terms of Participation, available on the event website.

3. Purposes of and legal bases for processing

  1. Reviewing the request to attend, verifying the invitation code and confirming the invitation, including assessing the request against the applicant’s role, scope of responsibility and fit with the attendee profile, which is necessary in order to take steps at the request of the data subject prior to entering into a contract for participation in the event (Article 6(1)(b) GDPR).
  2. Organising the event and contacting the attendee on organisational matters, including providing information on the venue, date and course of the event, which is necessary for the performance of the contract for participation in the event (Article 6(1)(b) GDPR).
  3. Recording the course of the event in the form of audiovisual recordings and photographs and using such materials in order to promote the event and the Controller’s business and to provide information about them, which constitutes a legitimate interest of the Controller (Article 6(1)(f) GDPR).
  4. Sending invitations and commercial information relating to the Controller’s products, services and events, which constitutes a legitimate interest of the Controller consisting in direct marketing (Article 6(1)(f) GDPR), whereby such information is sent by electronic mail or by telephone call following prior consent referred to in Article 398(1) of the Polish Act of 12 July 2024 Electronic Communications Law.
  5. Establishing, pursuing and defending against claims and demonstrating that the processing complies with the law, which constitutes a legitimate interest of the Controller (Article 6(1)(f) GDPR).

4. Invitation codes

Participation in the event requires an invitation code. The code is generated for the addressee of the invitation and sent by the Controller in a personalised link. Each code has an individual usage limit determined by the Organiser and communicated to the addressee when the code is provided. The addressee may use the code for their own application and share it with other persons within the assigned limit. Each person using the code submits a separate application. Sharing a code alone does not guarantee a place. Successful verification of an active code and submission of the form within the assigned limit guarantee a place at the event and constitute an individual confirmation of participation issued by name.

5. Recording of the event

The course of the event is recorded in the form of audiovisual recordings and photographs. The event is not streamed live. The Controller does not publish full recordings. Selected materials are released after the event.

Closed-door sessions, including roundtables, are not recorded. Those sessions are held under the Chatham House Rule, under which attendees are free to use the information received but may not reveal the identity or the affiliation of the person who provided it.

The recording covers the speakers’ presentations as well as shots of the room and of attendees, including persons taking the floor during Q&A sessions. Disseminating the image of an attendee who, in the recorded material, constitutes only a detail of a whole such as a gathering or a public event does not require permission under Polish law. Where an attendee is to be presented individually, in particular in a close-up shot or with their name given, the Controller obtains separate permission.

An attendee who does not wish to be recorded may use the designated area not covered by the recording, marked at the venue, and may notify the event staff or the Controller at contact@zowie.ai.

6. Live benchmark and the PROD Report

During the event, attendees may share views and information concerning the use of artificial intelligence in the organisations they represent, as part of a survey presented under the name live benchmark. Participation in the survey is voluntary and the data is provided by the attendee.

The responses are used to prepare aggregate results presented during the event and the PROD Report. The results are presented in aggregate form only, without identifying individual attendees. The processing is based on the legitimate interest of the Controller in preparing and publishing the PROD Report (Article 6(1)(f) GDPR).

Responses should not contain information constituting a trade secret of the organisation represented by the attendee, nor personal data of third parties.

7. Source of the data

The Controller processes the data provided in the registration form, the data recorded during the event and the data collected automatically through the use of the event website.

8. Recipients of the data

The Controller may disclose personal data to entities whose services it uses in the course of processing, such as providers of IT and hosting services, providers of communication and customer relationship management tools, providers of audiovisual production and editing services, marketing and event agencies, the operator of the venue at which the event is held, providers of accounting services and legal advisers.

The Controller may disclose the data to the operators of the platforms on which it publishes materials, in particular social media services and video sharing platforms, and to the recipients of its publications, including users of those services and visitors to the Controller’s websites. Publication of material on the internet means that it may be available to recipients worldwide, including outside the European Economic Area.

The Controller may disclose the data to other entities where such an obligation follows from the law.

9. Transfers outside the European Economic Area

The Controller uses the services of providers established outside the European Economic Area and, accordingly, the data may be transferred outside the EEA. The Controller uses only entities established in countries in respect of which the European Commission has decided that an adequate level of protection is ensured, entities processing data on the basis of standard contractual clauses adopted by the European Commission referred to in Article 46 GDPR, or entities processing data on the basis of the Data Privacy Framework principles.

10. Retention periods

  • Data provided in the registration form and data relating to participation in the event, for the period necessary to organise the event and subsequently until the expiry of the limitation period for claims relating to participation in the event.
  • Data stored in the invitation code system, until the end of the event and subsequently for 3 months for attendance verification purposes.
  • Data of persons whose request to attend has not been confirmed, for 12 months from the date on which the request was reviewed.
  • Recordings and photographs from the event, for the period during which such materials are used by the Controller and subsequently for the period necessary for the establishment, exercise or defence of claims.
  • Data processed for marketing purposes, until an objection is made, and, insofar as the sending of commercial information is based on consent, until consent is withdrawn. Following an objection or withdrawal of consent, the Controller retains the data to the extent necessary to demonstrate that fact and to prevent further contact.

11. Rights of data subjects

Data subjects have the following rights:

  • the right of access to personal data and the right to receive a copy thereof;
  • the right to rectification of personal data;
  • the right to erasure of personal data;
  • the right to request restriction of processing;
  • the right to data portability, insofar as the data is processed on the basis of consent or for the performance of a contract and by automated means;
  • the right to object to processing based on the Controller’s legitimate interests, on grounds relating to the data subject’s particular situation, and, in respect of direct marketing, at any time and without giving reasons;
  • the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
  • the right to lodge a complaint with the President of the Polish Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.

Exercising your rights

To exercise any of the above rights, please contact the Controller.

Following an objection, the Controller ceases processing to the extent covered by the objection unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.

12. Information on whether the provision of data is required

Providing personal data in the registration form is voluntary but necessary in order for the request to attend to be reviewed and the invitation confirmed. Failure to provide that data makes participation in the event impossible.

Giving consent to receive commercial information is voluntary and does not affect the review of the request to attend or the possibility of taking part in the event.

13. Cookies

The event website operates within the website run by Zowie, Inc. The use of cookies and similar technologies on that website is governed by the privacy policy of Zowie, Inc., available at getzowie.com/privacy-policy.

The consent to the storing of information in, and gaining access to information already stored in, the user’s terminal equipment referred to in Article 399 of the Electronic Communications Law is given and withdrawn through the consent management tool available on the website. Consent is not required in respect of information necessary for the provision of the service requested by the user.

14. Automated decision-making

The Controller does not take decisions in relation to data subjects based solely on automated processing, including profiling, which would produce legal effects concerning them or similarly significantly affect them.

15. Amendments to the policy

The Controller may amend this policy, in particular where the scope of processing or the law changes. The current version is available on the event website.

The rules for participation are set out in the Terms of participation