Wiredin Events LLC

Privacy Statement

Effective Date: 26 July 2026 | Version 6.0 | Last Reviewed: 26 July 2026

1. Introduction and Scope

Wiredin Events LLC ("Wiredin", "we", "us", or "our") is a healthcare engagement agency and professional conference organizer (PCO) established in Dubai, United Arab Emirates. In the course of our activities we collect and process personal data belonging to event attendees, healthcare professionals, speakers, faculty, scientific committee members, sponsors, exhibitors, suppliers, website visitors, and users of our digital platforms.

This Privacy Statement explains what personal data we collect, why we collect it, the legal bases on which we process it, with whom we share it, how long we keep it, how we protect it, and the rights available to you. It is the single authoritative reference for all Wiredin systems and services, including: the Wiredin corporate website and any microsites or event websites we operate; our event and congress registration systems, including online registration forms, on-site registration, badge issuance, and attendance tracking; Scholaris (scholaris.health), our continuing medical education (CME) platform for healthcare professionals; and our customer relationship management (CRM) and communications systems used to manage contacts and send communications.

This Statement applies to individuals whose personal data we process regardless of their location. Our delegates, faculty, sponsors, and platform users are based in the United Arab Emirates, across the Gulf Cooperation Council region, and internationally. Your personal data is processed and stored primarily in the United Arab Emirates, subject to the international transfer safeguards described in Section 10, irrespective of the country from which you register or access our platforms.

Not every system collects every category of data described in this Statement. Section 5 sets out which categories of personal data are collected by which system. Where a specific event, program, or platform requires additional or different processing, we will provide a supplementary notice at the point of collection.

By using our websites and platforms, and by completing registration for an event we organize or co-organize, you confirm that you have read and agree to this Privacy Statement and to the applicable event terms and conditions. That wording is shown at the point of registration. Where we contact you about our other events and educational activities, we do so on the basis described in Section 7, and you may object or unsubscribe at any time as described in Section 14.

2. Data Controller and Contact Details

The data controller responsible for the processing described in this Statement is:

Wiredin Events LLC
Concord Tower, Dubai Media City, Dubai, United Arab Emirates
Trade License No.: 952713 (Dubai Department of Economic Development)
Email for privacy matters: privacy@wiredin.ae

Data protection queries, requests, and complaints under this Statement should be directed to the contact details above.

For certain events, Wiredin acts as a processor on behalf of a client (for example, a pharmaceutical company, medical society, or government entity that commissions an event). Where that is the case, the client is the data controller, and this will be indicated in the event-specific registration notice. This Statement continues to describe our security and handling practices in those situations.

3. Legal Framework

This Statement is prepared in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") and its Executive Regulations, together with other applicable UAE legislation. Where we process personal data of individuals located in other jurisdictions (for example, international delegates or faculty), we take account of the data protection laws applicable to those individuals, including, where relevant, the EU/UK General Data Protection Regulation ("GDPR") for delegates from those jurisdictions.

Nothing in this Statement limits any right you have under applicable law.

4. Key Definitions

  • Personal data means any data relating to an identified natural person, or a natural person who can be identified directly or indirectly by way of linking data, including name, identification number, location data, online identifiers, or factors specific to physical, physiological, economic, cultural, or social identity.
  • Sensitive personal data means data that directly or indirectly reveals racial or ethnic origin, religious or philosophical beliefs, political opinions, criminal records, biometric data, or data concerning health.
  • Processing means any operation performed on personal data, including collection, storage, recording, organization, use, disclosure, transfer, or erasure.
  • Controller means the party that determines the purposes and means of processing.
  • Processor means the party that processes personal data on behalf of a controller.

5. Personal Data We Collect, by System

We apply the principle of data minimization: we collect only what is necessary for the stated purpose. Individual events may collect a subset of these categories; the registration form for each event shows exactly what is requested for that event.

5.1 Corporate Website and Event Websites. Contact and inquiry data (name, email, phone, organization, job title, message content); Newsletter and marketing data (email and preferences); Technical and usage data (IP address, browser/device info, pages visited, cookie identifiers, see Section 9).

5.2 Event and Congress Registration Systems. Identity data (full name, title, gender, nationality, date of birth); Contact data (email, phone, address, city, country); Professional data (employer, department, job title, specialty, license number and issuing authority e.g. DHA/DOH/MOHAP, years of experience); Registration and eligibility data (registration category, fee category, proof of eligibility such as student card, enrollment letter, employer letter, or where specifically required an identity document, see Section 6); Payment data (method, transaction reference, billing/invoicing; full card numbers processed by licensed payment providers, not stored by Wiredin); Event participation data (sessions attended, badge scans, check-in/out, workshop selections, dietary/accessibility requirements, travel/accommodation where arranged by us); Audio-visual data (photos/recordings, where notified); Communications data (correspondence with our registration team).

Note on dietary and accessibility requirements: these may indirectly reveal health or religious information, which is sensitive personal data. We collect them only where volunteered, use them solely to accommodate participation, restrict access, and delete them after the event.

5.3 Scholaris (CME Platform). Scholaris collects a narrower set of data than event registration and does not collect identity documents, date of birth beyond accreditation needs, payment card details, or dietary/accessibility data. Account data (name, email, hashed password, country, professional role); Professional data (specialty, place of work, license number where required for CME/CPD credit); Learning data (courses, assessments, credits, certificates, activity for accreditation evidence); Technical data (login records, IP, device/browser, cookies).

5.4 CRM and Communications. Our CRM consolidates professional contact information (name, role, specialty, institution, email, phone, country) from event registrations, Scholaris accounts, business interactions, and public professional sources, plus a record of our communications and your stated preferences. We do not store identity documents, payment data, or sensitive personal data in the CRM.

6. Identity Documents (Emirates ID, Passport, and Similar)

For most events, no identity document is required. We may request a copy of, or the number from, an identity document only where: a government authority, regulator, or venue requires verified identification as a condition of the event permit or venue access; verification is required to confirm eligibility for a restricted or discounted registration category and no less intrusive proof is sufficient; or required by law.

Safeguards applied when identity documents are collected:

  • The requirement and reason are stated at the point of collection.
  • Documents are stored in a segregated, access-restricted repository, separate from our general contact database, with access limited to named personnel.
  • Documents are encrypted in transit and at rest.
  • Documents are not used for any other purpose, not added to marketing or CRM records, and not shared with sponsors or exhibitors.
  • Documents are deleted once the verification or regulatory purpose is fulfilled, or at the end of any mandated retention period.

Where a less intrusive document (student card, employer letter) is sufficient, we accept it instead.

Speakers and faculty are a separate case. Government event-licensing rules require individual speaker permits, and the documents required depend on nationality and residency status. For events licensed in Abu Dhabi, the Department of Culture and Tourism, Abu Dhabi requires a recent photograph for UAE citizens and residents, and a passport copy with a recent photograph for GCC and other foreign nationals, with a UAE visa copy in addition where the speaker enters on a mission or visit visa. Dubai events holding a DET or DTCM permit have equivalent requirements. We collect these documents only to obtain the permit that allows the speaker to present, applying the same safeguards above. A speaker cannot be confirmed without the permit, so this collection is a regulatory requirement rather than a matter of choice.

7. Purposes of Processing and Legal Bases

Under the PDPL, processing requires consent unless another lawful basis applies, including performance of a contract, compliance with a legal obligation, or other cases set out in the PDPL. Our purposes and bases:

  • Event registration and delivery (badges, confirmations, attendance, delegate services): performance of a contract; consent for optional fields.
  • CME/CPD accreditation (attendance, results, certificates, credit reporting): performance of a contract; compliance with accreditation requirements.
  • Identity and eligibility verification (discounted categories; permit or venue security): compliance with a legal or regulatory obligation; performance of a contract; consent where neither applies.
  • Payments and accounting (fees, invoices, VAT compliance): performance of a contract; compliance with legal obligations.
  • Sponsor and exhibitor reporting (aggregate attendance statistics; attendee details only as described in Section 8): consent.
  • Marketing and scientific communications (upcoming congresses, CME programs relevant to your specialty): legitimate interest, with the right to object at any time.
  • Platform operation and security (accounts, authentication, fraud prevention, troubleshooting): legitimate operation of our services; compliance with legal obligations.
  • Compliance and legal claims (lawful requests from authorities; legal claims): compliance with legal obligations; exercise of legal rights.
  • Photography and recording at events (documentation, reporting, promotional material where notified): consent, provided at registration or venue, with the ability to object.

Where we rely on consent, you may withdraw it at any time as described in Section 13 (this does not affect processing already carried out).

8. Disclosure and Sharing of Personal Data

We do not sell personal data. We share it only as follows:

  • Accrediting and regulatory authorities: attendance and credit data for CME/CPD validation.
  • Event clients: where a client or society commissions an event and Wiredin acts as processor, data is shared with that entity as controller as disclosed in the event-specific notice; otherwise post-event reporting to a society is provided in aggregate form.
  • Sponsors and exhibitors: where a sponsor arranges attendance, we receive those delegates' details from the sponsor to register them; reporting we give sponsors after an event is aggregate composition only and does not identify individuals; badge scanning records attendance; any identifiable sharing with a sponsor for a specific event is stated at the point of collection.
  • Service providers: registration and event technology, CME hosting, email delivery, payment processing, cloud storage, badge printing, AV production, under confidentiality and data protection contracts.
  • Venues and security: the minimum data required for access or permit purposes.
  • Dubai government authorities (DET/DTCM): where an event uses a DET code or requires a DET or DTCM permit, we share the required delegate data; DTCM operates under the DET umbrella; DET is data controller for what it receives, under its own notice at dubaidet.gov.ae, contact privacy@dubaidet.ae.
  • Abu Dhabi government authorities (DCT Abu Dhabi): events in Abu Dhabi are licensed under the Abu Dhabi Events Licensing System, Decree No. 54 of 2016, via the TAMM platform; speakers and faculty need individual permits per Section 6; ticketed events use the DCT E-Ticketing System; DCT Abu Dhabi is data controller for data it receives, under its own policy at dct.gov.ae.
  • Professional advisers and authorities: auditors, legal advisers, insurers, courts, and public authorities where required by law.
  • Corporate transactions: data may transfer as part of a merger, acquisition, or asset transfer, subject to this Statement.

9. Cookies and Similar Technologies

Our websites use cookies falling into: strictly necessary (site and platform operation, authentication, security, no consent required); functional (remember preferences); analytics (understand site usage); and marketing (only where deployed on a specific site and disclosed in its cookie banner). Non-essential cookies are set only with consent, which you can give, refuse, or withdraw via the cookie banner or browser settings. See the Cookie Notice for the full list on this site.

10. International Transfers of Personal Data

Some service providers, faculty, accrediting bodies, and clients are outside the UAE, and some systems are hosted on cloud infrastructure outside the UAE. Where personal data is transferred outside the UAE we do so in accordance with the PDPL and its Executive Regulations: to jurisdictions recognized as providing adequate protection; or subject to appropriate safeguards such as contractual clauses equivalent to PDPL obligations; or where a specific PDPL derogation applies, including your express consent after being informed of the absence of adequate protection, or where necessary for performance of a contract with you. Contact us for more information about safeguards applied to a specific transfer.

11. Data Retention

We retain personal data only as long as necessary for the purposes collected, legal, regulatory, accounting or accreditation requirements, or to establish, exercise or defend legal claims. Indicative periods:

  • Identity documents collected for verification: deleted promptly once the purpose is fulfilled, unless a specific period is mandated.
  • Event registration records: generally 5 years from close of the event cycle.
  • CME/CPD records and certificates (Scholaris): retained for the period required by the accrediting authority, to allow re-issuance.
  • Financial and invoicing records: retained per UAE commercial, tax and VAT legislation.
  • Marketing contact data: until you withdraw consent or object, or it is no longer accurate or necessary.
  • Dietary and accessibility data: deleted after the event.
  • Website technical logs: retained briefly for security and troubleshooting, then deleted or anonymized.
  • Job applicant data: generally 2 years from application, unless earlier deletion is requested.
  • Correspondence: as long as necessary for the matter and any limitation periods.

When no longer required, data is securely deleted or irreversibly anonymized.

12. Security of Personal Data

We apply technical and organizational measures proportionate to the data and risks:

  • Encryption in transit and at rest.
  • Role-based access controls.
  • Segregated, restricted storage for identity documents and higher-risk data.
  • Hashed password storage.
  • Contractual obligations on service providers.
  • Logging and monitoring of access.
  • Staff confidentiality obligations and awareness training.
  • Periodic review of security measures and access rights.

No system is guaranteed absolutely secure; contact us immediately if you believe your interaction with us is no longer secure.

13. Your Rights

Subject to the PDPL and applicable law:

  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object, including to direct marketing.
  • Rights relating to automated decision-making. Wiredin does not currently carry out solely-automated decisions producing legal or similarly significant effects.

To exercise these rights, contact us using the Section 2 details. We may verify your identity first. We will respond within legally required timeframes. You may lodge a complaint with the UAE Data Office or another competent supervisory authority.

14. Consent, Withdrawal, and Marketing Preferences

Where processing is based on consent, you may withdraw it at any time, free of charge, via the unsubscribe link in any marketing email, your Scholaris account settings, or by contacting us. Withdrawal does not affect processing necessary for a contract with us or required by law.

Unsubscribe operates at more than one level: from a specific mailing or campaign, from communications relating to a specific Society, or from all Wiredin communications. A request to stop all communications is always available and honored in full; each request is tracked separately.

Marketing communications are sent only to individuals who have consented or, where permitted by law, existing contacts regarding similar services, always with a clear opt-out. Scientific and educational communications to healthcare professionals are managed in accordance with applicable UAE health authority rules.

15. Minors

Our websites, events, and platforms are directed at professionals and adults. We do not knowingly collect data from individuals under 18. Contact us to delete any such data if identified.

16. Third-Party Websites and Services

Our platforms may link to third-party websites (sponsors, venues, accrediting bodies, payment providers). This Statement does not apply to them; we are not responsible for their privacy practices.

17. Personal Data Breach Notification

In the event of a personal data breach that would prejudice your privacy or the confidentiality or security of your data, we will notify the UAE Data Office and, where required, affected individuals, within PDPL-prescribed timeframes, with information on the nature of the breach and measures taken.

18. Changes to This Statement

We may update this Statement periodically to reflect changes in our activities, systems, or legal obligations. The current version and effective date are published here. Material changes will be highlighted; where a change requires renewed consent, we will seek it. This Statement, from Version 6.1 onward, replaces and supersedes any shorter privacy policy previously published on the Wiredin website. Where an earlier version conflicts with this Statement, this Statement applies.

19. Contact and Complaints

Wiredin Events LLC, privacy@wiredin.ae, +971 4 454 9815, Concord Tower, Dubai Media City, Dubai, United Arab Emirates. If unresolved, you may lodge a complaint with the UAE Data Office or another competent supervisory authority.