Median26 attracts attendees, sponsors, and speakers from the EU/EEA and UK. This page summarizes how we comply with the General Data Protection Regulation (GDPR) and the UK GDPR for those visitors, in addition to the general commitments in our Privacy Policy.
1. Data controller
Median LLC, organizer of Median26 — Central Asia Crypto Summit, is the data controller for personal data collected via mediansummit.com. Contact: privacy@mediansummit.com. We have not appointed a formal EU representative under Article 27; if you believe one is required for your jurisdiction, contact us and we will address it.
2. Legal bases for processing
- Contract (Art. 6(1)(b)): issuing tickets, processing sponsorship packages, and administering speaker applications.
- Consent (Art. 6(1)(a)): marketing emails and advertising pixels (Meta, TikTok, Google) — only where you tick the consent checkbox on a form. You can withdraw consent at any time via the unsubscribe page.
- Legitimate interests (Art. 6(1)(f)): abuse/spam prevention and internal enquiry records, balanced against your rights and expectations as a website visitor.
3. International transfers
Our processors (Telegram, SendPulse, Meta, TikTok, Google, and payment providers) may process data outside the EU/EEA, including in the US. Where we transfer personal data outside the EU/EEA, we rely on those providers’ Standard Contractual Clauses (SCCs) or equivalent safeguards recognized under Chapter V GDPR.
4. Your rights under GDPR
As a data subject, you have the right to:
- Access (Art. 15) — obtain a copy of the personal data we hold about you.
- Rectification (Art. 16) — correct inaccurate or incomplete data.
- Erasure (Art. 17) — request deletion of your data, subject to our legal retention obligations.
- Restriction (Art. 18) — limit how we process your data in certain circumstances.
- Portability (Art. 20) — receive your data in a structured, machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests or direct marketing.
- Withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with your national supervisory authority (in the EU, find yours via the European Data Protection Board; in the UK, the ICO).
To exercise any right, email privacy@mediansummit.com. We respond within one month, as required by Article 12(3) GDPR (extendable by two further months for complex requests, with notice to you).
5. Data retention
We keep Event-related data (ticket, sponsorship, speaker enquiries) only as long as needed to administer the Event and for a limited period afterward for accounting/dispute purposes, then delete or anonymize it. Marketing-list data is kept until you unsubscribe or object.
6. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22).
7. Security
We use industry-standard technical measures (encrypted transport, access-restricted credentials, rate-limited public endpoints) to protect personal data against unauthorized access, loss, or misuse.
This document is a general-purpose template and does not constitute legal advice. Median26 should have it reviewed by qualified EU/UK GDPR counsel before relying on it.