Privacy Policy INTERNATIONAL FORUM ON PEDIATRICS This Privacy & Cookie Policy explains how this website collects, uses and protects personal data of users who visit or interact with the website, in accordance with Regulation (EU) 2016/679 (“GDPR”).

1. Data Controller

UpMed Congress | International Forum on Pediatrics

Email: info@upmedcongress.com

2. Types of Data Collected

2.1 Data Provided Voluntarily by the User

CONTACT FORM

When filling out the contact form, the user provides:

  • First and last name
  • Email address
  • Message content
  • Any other information voluntarily included

Purpose: responding to enquiries and providing support.
Legal basis: performance of pre-contractual measures (Art. 6.1.b GDPR).

E-COMMERCE (WooCommerce/MetForm)

When purchasing medical congress recordings, the website collects:

  • First and last name
  • Billing and/or shipping address
  • Email and phone number
  • Order details
  • Payment information (processed by secure external payment providers; the website does not store card details)

Purpose: order processing, payments, invoicing, customer support, delivery of the purchased digital content.

Legal bases:

  • Contract performance (Art. 6.1.b GDPR)
  • Legal obligations regarding invoicing and accounting (Art. 6.1.c GDPR)

2.2 Data Collected Automatically

Through technical systems and analytics tools, the website may collect:

  • IP address (anonymised when applicable)
  • Browser and device information
  • Pages visited and time spent
  • User interactions on the site

Purpose: site security, functionality improvement, anonymous statistical analysis.
Legal basis: user consent for analytics cookies when required (Art. 6.1.a GDPR).

3. Cookies and Similar Technologies

3.1 Technical (Necessary) Cookies

This website uses technical cookies and analytics cookies only.
No profiling cookies are used.

 

These cookies are essential for the website to function properly and include:

  • Session cookies
  • WooCommerce cookies (cart, checkout, order management)
  • Security and performance cookies

Legal basis: service necessity / contract performance (Art. 6.1.b GDPR).
Consent is not required.

3.2 Analytics Cookies

Used to collect aggregated statistical data about website usage (e.g. Google Analytics or similar tools).

They may collect:

  • Navigation data
  • User behaviour within the site
  • Technical information about the device

If the IP address is anonymised and data is aggregated, these cookies may be treated as technical cookies.
Otherwise, they are activated only after receiving the user’s consent through the cookie banner.

Legal basis: consent (Art. 6.1.a GDPR).

3.3 Profiling Cookies

Not used.
This website does not use cookies for advertising, marketing, or behavioural profiling.

3.4 Cookie Management

Users may:

  • Accept or refuse non-essential cookies via the cookie banner
  • Withdraw consent at any time
  • Delete or block cookies via their browser settings

4. Purposes of Processing

Personal data is processed for the following purposes:

  1. Responding to enquiries made through the contact form
  2. Allowing users to purchase congress recordings
  3. Processing orders, payments, invoicing, and providing customer support
  4. Complying with legal and accounting obligations
  5. Analysing website traffic and improving performance
  6. Ensuring website security and preventing fraudulent activity

5. Legal Bases for Processing

  • Contract performance / pre-contractual measures (Art. 6.1.b)
  • Legal obligation (Art. 6.1.c)
  • Consent for analytics cookies (Art. 6.1.a)
  • Legitimate interest for security and fraud prevention (Art. 6.1.f)

6. Processing Methods

Personal data is processed using electronic and/or manual tools, in compliance with the principles of lawfulness, fairness, transparency and data minimisation.

7. Data Retention

  • Contact form data: up to 12 months from the last communication
  • Order and invoicing data: 10 years (legal obligation)
  • Analytics data: according to the retention period set by the chosen analytics tool (e.g. 14 or 26 months)

8. Data Recipients

Personal data may be shared with:

  • Hosting providers
  • Technical service providers (WooCommerce, MetForm)
  • Payment gateways (e.g. Stripe, PayPal or others)
  • Accountants and tax consultants
  • Public authorities when required by law

If any services involve transferring data outside the EU, transfer will occur according to GDPR safeguards (Arts. 44–49 GDPR), such as Standard Contractual Clauses or adequacy decisions.

9. Security

Appropriate technical and organisational measures are implemented to protect personal data, including:

  • Secure HTTPS transmission
  • Firewall and anti-intrusion systems
  • Access restricted to authorised personnel
  • Periodic backups

10. User Rights

Users may exercise the following rights under Articles 15–22 GDPR:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to object
  • Right to data portability
  • Right to withdraw consent at any time

Requests should be sent to: info@upmedcongress.com

11. Changes to This Policy

The Data Controller may update this Policy at any time. Updates will be published on this page.