Privacy Policy of BrightPulse Activation B.V.
Effective date: July 21, 2026
1. Introduction and company information
This privacy policy explains how BrightPulse Activation B.V. collects, uses, stores, shares, and protects personal data in connection with its brand-activation services, campaigns, events, promotional activities, client projects, supplier management, website use, and related business operations.
BrightPulse Activation B.V. acts as the data controller for the personal data described in this policy, unless we expressly state otherwise.
Controller details:
- Company: BrightPulse Activation B.V.
- Address: Keizersgracht 321, 1016 EJ Amsterdam, Netherlands
- Email: [email protected]
- Phone: +31 20 794 6285
This policy applies to personal data we process about clients, prospective clients, event attendees, consumers, website visitors, business partners, suppliers, contractors, and other individuals with whom we interact in the course of our activities.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identification data: name, title, company name, job title, and business contact details.
- Contact data: email address, postal address, telephone number, and other communication details.
- Event and campaign data: registration details, attendance information, preferences, feedback, images, video recordings, and participation records.
- Website and technical data: IP address, browser type, device identifiers, log files, cookies, and usage statistics.
- Commercial and contractual data: invoicing details, payment information, service preferences, correspondence, and contract-related information.
- Marketing data: communication preferences, newsletter subscriptions, interaction history, and consent records.
- Supplier and partner data: professional contact details, service records, and compliance documentation where necessary.
- Special or sensitive data: we do not intentionally seek to collect sensitive personal data. If such data is incidentally provided, we will process it only where permitted by law and necessary for a specific purpose.
We obtain personal data directly from you, from our clients or business partners, from public sources, from event registrations, from website interactions, and from third parties that support our business operations.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our brand-activation services;
- to organize and administer campaigns, events, promotions, and experiential marketing activities;
- to communicate with clients, prospects, attendees, suppliers, and partners;
- to prepare quotations, contracts, invoices, and other business documentation;
- to manage customer and supplier relationships;
- to process registrations, attendance, participation, and feedback;
- to send marketing communications where permitted;
- to improve our services, website, and customer experience;
- to ensure security, prevent fraud, and protect our systems and business operations;
- to comply with legal, tax, accounting, and regulatory obligations;
- to resolve disputes, enforce agreements, and establish, exercise, or defend legal claims.
4. Legal basis for processing
We process personal data only where we have a valid legal basis. Depending on the context, this may include:
- Performance of a contract: where processing is necessary to enter into or perform an agreement with you or your organization.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as service delivery, marketing to business contacts, administration, fraud prevention, and service improvement, provided these interests are not overridden by your rights and freedoms.
- Consent: where you have given us clear consent, for example for certain marketing communications, cookies, photography, or video use where required.
- Legal obligation: where processing is necessary to comply with applicable laws and regulatory requirements.
- Vital interests or public task: where necessary in exceptional circumstances permitted by law.
Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
5. Data sharing and third parties
We may share personal data with third parties only where necessary and lawful. These recipients may include:
- service providers supporting hosting, IT, cloud storage, analytics, CRM, email delivery, and security;
- production partners, event venues, hostesses, promoters, photographers, videographers, logistics providers, and staffing agencies;
- payment processors, banks, insurers, accountants, auditors, and legal advisors;
- clients or business partners where sharing is necessary for project execution or reporting;
- public authorities, regulators, or law enforcement, where required by law;
- other third parties with your consent or at your direction.
We require third parties to process personal data in accordance with applicable data protection requirements and to use appropriate safeguards.
6. Data transfer to third countries
Some of our service providers or partners may be located outside the European Economic Area (EEA). If personal data is transferred to a country that does not provide an adequate level of protection, we will implement appropriate safeguards, which may include standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.
Where required, you may request further information about such safeguards by contacting us using the details provided below.
7. Storage duration
We retain personal data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law.
- Contractual and business records: retained for the duration of the relationship and thereafter as required by legal, accounting, or tax obligations.
- Marketing data: retained until you withdraw consent, object to processing, or the data is no longer needed.
- Event-related data: retained for the period necessary to administer the event, handle follow-up, and resolve any related claims.
- Technical logs and security data: retained for a limited period necessary for security, troubleshooting, and system integrity.
When personal data is no longer needed, we will delete, anonymize, or archive it in accordance with applicable law and our retention practices.
8. User rights
Subject to applicable law, you may have the following rights regarding your personal data:
- Access: to obtain confirmation as to whether we process your personal data and to receive a copy of that data;
- Rectification: to request correction of inaccurate or incomplete personal data;
- Erasure: to request deletion of your personal data in certain circumstances;
- Restriction: to request that we limit the processing of your personal data in certain circumstances;
- Data portability: to receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible;
- Objection: to object to processing based on legitimate interests and to object at any time to direct marketing;
- Right not to be subject to solely automated decision-making: where applicable, to request human intervention and challenge decisions that produce legal or similarly significant effects.
To exercise your rights, please contact us using the details in the section below. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. If you withdraw consent, we may no longer be able to provide certain services or communications to you where consent is necessary.
You can withdraw consent by contacting us at [email protected].
10. Right to complain
If you believe that our processing of your personal data infringes applicable privacy laws, you may lodge a complaint with the competent supervisory authority. Without limiting your right to do so, we encourage you to contact us first so that we can attempt to resolve your concern promptly and directly.
You may also have the right to seek a judicial remedy in accordance with applicable law.
11. Data security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, destruction, alteration, disclosure, or misuse. These measures may include access controls, encryption, secure hosting, network protections, staff confidentiality obligations, and internal procedures for handling incidents.
Although we take reasonable steps to secure personal data, no system can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of information transmitted to or from our systems.
12. Contact information
If you have any questions, requests, or concerns regarding this privacy policy or our processing of personal data, please contact:
- BrightPulse Activation B.V.
- Keizersgracht 321, 1016 EJ Amsterdam, Netherlands
- Email: [email protected]
- Phone: +31 20 794 6285
13. Changes to privacy policy
We may update this privacy policy from time to time to reflect changes in our practices, legal requirements, or operational needs. The updated version will be published with a revised effective date. Where required by law, we will provide additional notice of material changes.
We encourage you to review this privacy policy periodically to stay informed about how BrightPulse Activation B.V. protects your personal data.