Privacy Policy


Privacy Policy

Last updated: 2 September 2026

IAG Global (“IAG Global”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information you provide to us or that we collect when you use our website or our mobile application.

This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you visit or use the IAG Global website (the “Website”) and the IAG.global mobile application (the “App”), a private event companion and year-round member hub for members of our professional network.

For the purposes of the UK GDPR, EU GDPR, and comparable data-protection laws, IAG Global is the data controller of the personal information described in this policy.

By using the Website or the App, you acknowledge that you have read and understood this Privacy Policy.

1. Information We Collect

Depending on how you interact with our Website or App, we may collect the following types of information:

Information you provide to us

You may provide personal information when you:

  • Complete a contact or enquiry form;
  • Request information about our services;
  • Subscribe to newsletters or marketing communications;
  • Communicate with us by email, telephone, or other means;
  • Apply for a position or submit information for recruitment purposes; or
  • Otherwise voluntarily provide information to us.

This information may include your name, email address, telephone number, company name, job title, postal address, and the contents of your enquiry or communication.

Information collected automatically

When you visit our Website, certain information may be collected automatically, including:

  • IP address;
  • Browser type and version;
  • Device type;
  • Operating system;
  • General geographic information;
  • Pages visited and interactions with the Website;
  • Date and time of visits;
  • Referring websites; and
  • Other technical or usage information.

We may collect this information using cookies, analytics technologies, server logs, and similar technologies.

Information we collect in the App

We only collect information necessary to operate the App and deliver the member experience. The App does not integrate third-party advertising networks, behavioural trackers, AI services, or payment processors.

Account and authentication data

  • Email address — used to create your account, sign you in, and deliver one-time passcodes (OTPs).
  • Password — stored in hashed form by our authentication provider. We never see your plaintext password.
  • Authentication tokens and session data — issued when you sign in and refreshed automatically. The “Remember me” option stores your email locally on your device to pre-fill it on the next launch.
  • Account role flags — an internal flag indicating whether you are a Member and/or Administrator.

Member profile data

  • Full name
  • Company / organisation
  • Role or job title
  • Phone number (optional)
  • Short biography (optional)
  • Region (Europe, Americas, Asia Pacific, Africa & Middle East)
  • LinkedIn profile URL (optional)
  • Profile photo / avatar (optional)

Event and RSVP data

  • Conferences and remote events you RSVP to attend
  • Session reminder preferences (which sessions and how many minutes before)
  • Sessions you hide or remove from your personal schedule (stored on device)

Community and messaging content

  • Community posts you publish
  • Comments you make on posts
  • Post likes
  • Private messages you send to other members (individual and group), including timestamps and read status
  • Photos you upload to sessions or the community feed

Device and usage data

  • Notification tokens issued by iOS or Android when you enable push notifications
  • Notification preferences stored locally on your device
  • Basic error logs generated when something goes wrong (used only for diagnostics; not linked to third-party analytics services)

Optional feedback

If you delete your account, we may collect an optional reason (e.g. “Not using it”, “Privacy”, “Bugs”, or a free-text “Other” response) to help us improve the product. Providing a reason is entirely voluntary.

What we do not collect in the App

  • We do not integrate third-party advertising or behavioural-tracking SDKs.
  • We do not process payments in the App. No card or billing data is collected.
  • We do not use AI/LLM services or send your data to AI providers.
  • We do not collect precise device location. Any map or venue coordinates displayed in the App are stored by administrators as part of event details, not sourced from your device.
  • We do not read your device contacts. The “Save to Contacts” feature only writes a selected member’s public profile fields into your device address book with your permission.

2. How We Use Your Information

We may use personal information for purposes including:

  • Responding to enquiries and requests;
  • Providing information about our services;
  • Communicating with you about our business;
  • Managing our relationship with customers, prospective customers, suppliers, and business contacts;
  • Sending marketing communications where permitted by law;
  • Improving, maintaining, and developing our Website and services;
  • Understanding how visitors use our Website;
  • Monitoring Website security and preventing fraud, misuse, or unauthorised activity;
  • Complying with applicable legal and regulatory obligations; and
  • Establishing, exercising, or defending our legal rights.

In the App, we use personal information to:

  • Create and secure your account — Email, password (hashed), OTP, session tokens
  • Populate the member directory so others can find and message you — Name, role, company, region, avatar, LinkedIn, email, phone (as entered)
  • Enable RSVPs, session scheduling, and event participation — RSVP records, reminder preferences
  • Deliver community posts, comments, likes, and messaging — Post/message/comment content, participant IDs, timestamps
  • Send push notifications for session reminders, new messages, and post activity — Push token, message metadata, sender name and avatar
  • Provide event photos, resources, and documents — Uploaded images and files
  • Debug and improve reliability — Server-side error logs
  • Comply with legal obligations and enforce our terms — Account and usage data as necessary

We will only use your personal information where we have a lawful basis to do so. We do not use your personal data for advertising, profiling, or automated decision-making that produces legal effects.

3. Legal Basis for Processing

Where applicable, we process personal information on one or more of the following legal bases:

Consent — where you have given us permission to process your information for a specific purpose, including where you enable push notifications, upload optional profile fields, or share optional deletion feedback;

Contract — where processing is necessary to enter into or perform a contract with you, including processing needed to provide you with the App and member services you have signed up for;

Legitimate interests — operating and improving our Website and App, keeping them secure, and enabling member-to-member networking within a private community;

Legal obligation — where processing is necessary for us to comply with a legal or regulatory requirement.

Where we rely on consent, you may withdraw your consent at any time.

4. Cookies and Similar Technologies

Our Website may use cookies and similar technologies to provide functionality, understand Website usage, remember preferences, and improve your experience.

Cookies may be categorised as:

  • Strictly necessary cookies, which are required for the Website to operate;
  • Functional cookies, which help remember preferences and improve functionality; and
  • Analytics cookies, which help us understand how visitors use the Website.

Where required by law, we will request your consent before placing non-essential cookies on your device.

You can manage cookie preferences through our cookie consent tools or through your browser settings. Disabling certain cookies may affect Website functionality.

The App does not use cookies or third-party behavioural-tracking technologies.

5. Marketing Communications

Where permitted by applicable law, we may send you information about IAG Global, our services, events, news, or other business-related information.

You can opt out of marketing communications at any time by using the unsubscribe mechanism included in our communications or by contacting us using the details provided below.

6. Sharing Your Information

We do not sell or rent your personal information.

We may share personal information with trusted third parties where necessary to operate our business or provide our services. These may include:

  • Website hosting and technology providers;
  • IT, cybersecurity, and infrastructure providers;
  • Analytics and communications providers;
  • Professional advisers, such as lawyers, accountants, or auditors;
  • Service providers acting on our behalf; and
  • Government authorities, regulators, courts, or law-enforcement bodies where required or permitted by law.

Where appropriate, we require third-party service providers to protect personal information and only process it in accordance with our instructions and applicable law.

Other members (App)

The App is a private community. Once you sign in, your profile (name, role, company, region, avatar, and any optional details you provide such as LinkedIn, phone, and bio) is visible to other authenticated members. Community posts, comments, RSVPs, and messages are visible to their intended audience (all members for posts; recipients for messages).

Sub-processors we rely on for the App

  • Supabase (OnSpace Cloud) — Authentication, database hosting, file storage, serverless functions — All account, profile, event, message, and uploaded content
  • Apple Push Notification Service (APNs) and Google Firebase Cloud Messaging (FCM) — Delivering push notifications to your device — Push token, notification title/body, sender avatar (iOS)
  • Expo / EAS — App build, delivery, and OTA runtime support for the React Native / Expo framework used to build the App — No direct access to your personal profile data; may process technical crash or update telemetry
  • Apple App Store and Google Play — Distribution of the App — Standard app-store metadata (not personal data we control)

Each sub-processor is bound by their own privacy commitments and applicable data-protection laws.

7. International Transfers

Some of our service providers or business partners, including Supabase, Apple, and Google, may be located outside the country in which you are based.

Where personal information is transferred internationally, we will take appropriate steps to ensure that the transfer is lawful and that your information continues to receive an appropriate level of protection in accordance with applicable data protection laws. Where such transfers take place from the UK/EEA, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or equivalent mechanisms offered by our providers.

8. Data Retention

We retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, accounting, contractual, or reporting requirements.

The specific retention period may vary depending on the type of information and the purpose for which it is processed.

For the App specifically:

  • Account and profile data — Kept while your account is active. Deleted when you delete your account.
  • Community posts, comments, RSVPs, messages — Kept for as long as they remain relevant to the community record; content authored by you is deleted or attributed as “Deleted user” when you delete your account.
  • Uploaded photos (avatar, event photos) — Kept until you replace, remove, or delete your account.
  • Session reminder preferences and on-device settings — Stored on your device until you clear the App’s data or uninstall it.
  • Deletion-reason feedback — Retained in aggregate/administrative form to help improve the product; not linked back to a deleted user’s identifiable profile.
  • Server-side error logs — Automatically rotated on a short cycle (typically no longer than 30–90 days).

When personal information is no longer required, we will take reasonable steps to securely delete or anonymise it.

9. Data Security

We take reasonable technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

App data is stored on managed cloud infrastructure operated by Supabase (via OnSpace Cloud), which hosts your account and authentication records, structured data (profile, RSVPs, posts, comments, messages, events, sessions), and uploaded images in a secure object-storage bucket. Small pieces of data are also stored locally on your device using the operating system’s secure storage: the email you optionally save with “Remember me”, notification and session-reminder preferences, and sessions you have chosen to hide from your personal schedule.

Our security measures include:

  • All traffic between the App and our servers is encrypted using TLS/HTTPS.
  • Passwords are hashed with industry-standard algorithms by our authentication provider.
  • Database access is protected by Row-Level Security policies, meaning users can only read and write data they are authorised to access.
  • Sensitive administrative actions (such as account deletion) run in isolated server-side functions with restricted database privileges.
  • Access to production systems is restricted to authorised personnel only.

However, no method of transmitting information over the internet or storing information electronically can be guaranteed to be completely secure. If we become aware of a data breach affecting your personal data, we will notify you and the appropriate authorities as required by law.

10. Your Privacy Rights

Depending on your location and applicable law, including the UK GDPR, the EU GDPR, and the California Consumer Privacy Act (CCPA/CPRA), you may have rights relating to your personal information, including the right to:

  • Request access to personal information we hold about you;
  • Request correction of inaccurate or incomplete information;
  • Request deletion of your personal information;
  • Request restriction of processing;
  • Object to certain processing;
  • Request portability of certain information;
  • Withdraw consent where processing is based on consent;
  • Not be discriminated against for exercising these rights; and
  • Lodge a complaint with the relevant data protection authority.

To exercise your rights, please contact us using the details below. We will respond within the timeframe required by applicable law (typically 30 days).

We may need to verify your identity before responding to a request. Certain rights may be subject to legal limitations or exemptions.

11. Third-Party Websites

Our Website and App may contain links to websites, platforms, or services operated by third parties.

We are not responsible for the privacy practices, content, security, or policies of third-party websites. We recommend reviewing the privacy policy of any third-party website you visit.

12. Children’s Privacy

Our Website and App are not intended to knowingly collect personal information from children. The App is intended for adult professional members of IAG Global and is not directed to children under 16.

If you believe that a child has provided personal information to us, please contact us so that we can take appropriate steps to address the matter.

13. Device Permissions and Notifications (App)

The App only requests the permissions listed below, and only when the corresponding feature is used. You can revoke any of these permissions at any time from your device settings.

  • Photo library — To let you choose a profile avatar, upload session photos, or attach images to community posts. We only access the specific image you pick.
  • Contacts (write) — Only used by the “Save to Contacts” button on a member’s profile, which writes their public identity fields into your device address book. We do not read your existing contacts.
  • Notifications — To deliver session reminders, new-message alerts, and post-activity notifications you have opted into.

Push notifications are optional. When you enable them, the App may send you reminders for sessions you plan to attend (5, 15, 30, or 60 minutes before), alerts for new direct or group messages including the sender’s name and (on iOS) their avatar as an attachment, and alerts related to comments on your posts.

Notification content is generated on your device from data already synced from our servers. You can disable notifications at any time by turning them off in your device settings or in the App’s profile settings.

14. Account and Data Deletion (App)

You can delete your account and associated personal data directly from within the App at any time:

  1. Open the App and go to Profile.
  2. Scroll to Account Controls.
  3. Tap Delete my account.
  4. Optionally share a reason (Not using it, Privacy, Bugs, or Other — you can skip this).
  5. Confirm the two-step confirmation prompt.

Once confirmed, we will delete your authentication record so you can no longer sign in, remove your profile from the member directory, and delete or anonymise messages, RSVPs, posts, and comments you authored, in accordance with Section 8.

Deletion is permanent and cannot be undone. If you cannot access the App to delete your account, email [email protected] from the address on file and we will process the deletion for you.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our business, Website, App, technology, or legal and regulatory requirements.

When we make changes, we will update the “Last updated” date at the top of this Privacy Policy. Where appropriate, we may provide additional notice of material changes, including inside the App or by email.

16. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how we handle personal information, please contact us:

IAG Global

Privacy and data requests: [email protected]

General enquiries: [email protected]

Address: Veerhaven 17, 3016 CJ, Rotterdam

Website: www.iag.global

If applicable, you may also contact the data protection authority in your country or region if you have concerns about our processing of your personal information.

17. Governing Law

This Privacy Policy is intended to comply with applicable data protection and privacy laws. The interpretation and application of this Privacy Policy may be subject to the laws applicable to IAG Global and its users.

Image: Zurich – IAG Assembly, 2020