Privacy Notice

Copenhagen Event Company ApS

Last updated: 7 July 2026

  1. Introduction

Copenhagen Event Company ApS (“CEC”, “we”, “our”, or “us”) is a Professional Congress Organiser (PCO) specialising in the planning and delivery of congresses, conferences, meetings, corporate events and incentive programmes in Denmark and internationally.

We are committed to protecting your privacy and processing your personal data in a transparent, secure and lawful manner.

This Privacy Notice explains how we collect, use, store and protect your personal data when you:

  • register for a congress, conference or event organised by CEC;
  • visit our website;
  • contact us by email, telephone or through our website;
  • are employed by, or represent, one of our clients, suppliers or business partners; or
  • otherwise interact with Copenhagen Event Company ApS.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Danish Data Protection Act and other applicable legislation.

  1. Data Controller

Copenhagen Event Company ApS

CVR/VAT No.: 40711805

Østvej 13 C

DK-3230 Græsted

Denmark

Email: bo@cecevent.dk

Telephone: +45 25 90 12 12

Website: www.copenhageneventcompany.dk

 

  1. Categories of Personal Data

Depending on the services we provide, we may process the following categories of personal data:

  • Name
  • Job title
  • Company or organisation
  • Postal address
  • Email address
  • Telephone number
  • Country of residence or nationality (where relevant)
  • Flight and travel information
  • Hotel accommodation details
  • Arrival and departure information
  • Registration details
  • Payment and invoicing information
  • Dietary requirements and allergies
  • Accessibility requirements
  • Visa-related information
  • Emergency contact information (where applicable)
  • Photographs and video recordings taken during events
  • Email correspondence
  • Other information necessary to provide the contracted services.

We only collect personal data that is relevant and necessary for the purposes described in this Privacy Notice.

  1. Purposes of Processing

We process personal data in order to:

  • administer registrations;
  • organise and deliver congresses, conferences and events;
  • communicate with delegates, speakers, exhibitors and sponsors;
  • arrange accommodation and transportation where required;
  • prepare delegate lists and name badges;
  • provide customer support;
  • manage invoicing and accounting;
  • issue invitation letters for visa applications;
  • comply with legal obligations;
  • protect our legitimate business interests.
  1. Legal Basis for Processing

Our legal basis for processing personal data includes:

Article 6(1)(b) GDPR
Performance of a contract or taking steps prior to entering into a contract.

Article 6(1)(c) GDPR
Compliance with legal obligations, including accounting and bookkeeping legislation.

Article 6(1)(f) GDPR
Our legitimate interests in planning, managing and documenting professional events and maintaining business relationships.

Article 6(1)(a) GDPR
Consent, where required, including for marketing communications.

Where we process special categories of personal data, such as dietary requirements, allergies or accessibility requirements, we do so only where necessary for the provision of our services and in accordance with Article 9 GDPR.

  1. Sharing of Personal Data

We only disclose personal data where necessary for the performance of our services.

Recipients may include:

  • hotels;
  • conference venues;
  • restaurants and catering providers;
  • transport companies;
  • technical suppliers;
  • badge printing providers;
  • interpreters;
  • destination management companies;
  • public authorities (for visa support where applicable);
  • clients organising the event, where this forms part of the contracted services.

We never sell personal data to third parties for marketing purposes.

  1. Data Processors

CEC uses carefully selected data processors who process personal data on our behalf.

These include:

  • Microsoft 365 Business (email, document management and Microsoft OneDrive)
  • Conference Manager (event registration and delegate management)
  • e-conomic (accounting and invoicing)

Data Processing Agreements have been concluded where required under Article 28 GDPR.

  1. International Transfers

As a general rule, personal data is processed within the European Economic Area (EEA).

Where personal data is transferred outside the EEA, appropriate safeguards are implemented, including the European Commission’s Standard Contractual Clauses (SCCs), adequacy decisions or other lawful transfer mechanisms under Chapter V GDPR.

  1. Retention Periods

We retain personal data only for as long as necessary.

Our standard retention periods include:

  • Event registrations: up to 30 days after completion of the event unless otherwise agreed with the client.
  • Accounting documentation: 5 years in accordance with Danish bookkeeping legislation.
  • Email correspondence: for as long as necessary for the relevant business relationship.
  • Consent records: until consent is withdrawn or no longer relevant.
  1. Information Security

CEC has implemented appropriate technical and organisational security measures, including:

  • Multi-Factor Authentication (MFA), where applicable;
  • individual user accounts;
  • password policies;
  • encrypted communication;
  • Microsoft OneDrive for secure document storage;
  • anti-virus protection;
  • regular software updates;
  • access control based on business need;
  • confidentiality obligations for employees;
  • ongoing risk assessments.

Employees may work remotely using company-approved devices or private devices that comply with CEC’s Information Security Policy.

  1. Cookies

Our website uses cookies.

Necessary cookies ensure the proper functioning of the website.

Statistical and any marketing cookies are only used following your consent through our cookie banner.

Further information is available in our separate Cookie Policy.

  1. Your Rights

Under the GDPR, you have the right to:

  • access your personal data;
  • request rectification of inaccurate information;
  • request erasure where applicable;
  • request restriction of processing;
  • receive your personal data in a structured, commonly used format (data portability);
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with a supervisory authority.

To exercise your rights, please contact:

bo@cecevent.dk

  1. Supervisory Authority

If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with:

The Danish Data Protection Agency (Datatilsynet)

Carl Jacobsens Vej 35

DK-2500 Valby

Denmark

Website: www.datatilsynet.dk

  1. Changes to this Privacy Notice

CEC may update this Privacy Notice from time to time in order to reflect changes in legislation, our services or our data processing activities.

The most recent version will always be available on our website.

Contact

Copenhagen Event Company ApS

CVR/VAT No. 40711805

Østvej 13 C

DK-3230 Græsted

Denmark

Email: bo@cecevent.dk

Telephone: +45 25 90 12 12

Website: www.copenhageneventcompany.dk