Privacy Policy
Last updated: April 30, 2026
This Privacy Policy explains how Global Cyber Institute (“we,” “us,” or “the Institute”), a U.S. 501(c)(3) non-profit organization, collects, uses, and protects information through legaltechconference.com (“the Directory”).
1. Who we are
Global Cyber Institute is the data controller for personal information collected through the Directory. Contact us at privacy@legaltechconference.com for any privacy-related questions.
2. What we collect
Information you provide
- Account data — name, email, organization, password (when you create an account).
- Submission data — conference details, contact info, organizer name (when you submit a listing).
- Payment data — billing details for paid listings, processed by Stripe (we do not store card numbers).
- Communications — emails or messages you send us.
Information collected automatically
- Usage data — pages viewed, search queries, referring URLs, device and browser info.
- Cookies — essential cookies for authentication; optional analytics cookies (you may opt out).
3. How we use it
- Operate and improve the Directory and its search/filter functions.
- Process paid listings via Stripe and send transactional emails.
- Send our monthly digest (if you subscribed); unsubscribe at any time.
- Detect fraud, abuse, and policy violations.
- Comply with legal obligations.
We do not sell personal information. We do not share data with advertisers for cross-site tracking.
4. Third-party services
The Directory uses the following processors:
- Supabase — database and authentication (US/EU data centers).
- Stripe — payment processing for paid listings.
- Vercel — hosting and edge delivery.
- Email provider — transactional and digest emails.
Each processor is bound by its own privacy commitments and our Data Processing Agreements.
5. Your rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion (subject to legal record-keeping obligations).
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent for marketing communications.
Submit requests to privacy@legaltechconference.com. We respond within 30 days.
6. California (CCPA) and EU (GDPR)
California residents have the right to know what categories of personal information are collected, the purposes of collection, and to whom it is disclosed, plus rights to delete and to opt out of “sale” (we do not sell). EU residents have the GDPR rights listed above. The legal basis for processing is contract (account/listing) and legitimate interest (analytics, fraud prevention) or consent (marketing).
7. Retention
Account and listing data is retained for the life of the account and 7 years thereafter for tax and audit purposes. Analytics data is aggregated after 14 months. You may request earlier deletion subject to legal obligations.
8. Security
We use industry-standard safeguards including TLS encryption in transit, encrypted database storage, password hashing, and access controls. No system is perfectly secure; we will notify affected users and applicable authorities of any breach as required by law.
9. Children
The Directory is not directed to children under 13 (or 16 in the EU) and we do not knowingly collect their information.
10. Changes
We will post material changes to this policy at this URL with a new “Last updated” date and, when appropriate, notify registered users by email.
11. Contact
Global Cyber Institute
Privacy: privacy@legaltechconference.com
General: hello@legaltechconference.com