Privacy Notice, SSD 2027 (ssdexpo.com)

Controller: Exponaut OÜ
Version: 1.0 · Last updated: 8 September 2026
Applies to: ssdexpo.com, map.ssdexpo.com, our SSD 2027 forms, our newsletters, and the SSD 2027 event in Riga, 16–17 June 2027.


1. Who we are

Exponaut OÜ is an Estonian private limited company. We organise the Supply Security & Defence Expo (SSD 2027), taking place in Riga, Latvia on 16–17 June 2027. We also organised the previous edition, SSD 2026.

We are the data controller for everything described in this notice: we decide why and how your personal data is used, and we are accountable for it.

We have not appointed a Data Protection Officer. We are not required to under Article 37 of the GDPR: we are not a public authority, our core business is running a trade expo rather than large-scale monitoring of people, and we do not process special-category data at scale. Please use the privacy contact address above for anything covered by this notice.


2. What this notice covers

This notice explains what personal data we collect, why, on what legal basis, how long we keep it, who we share it with, and what you can do about it. It covers you if you:

It does not cover what other companies do with your data once you deal with them directly, for example an exhibitor whose stand you visit, or the venue operator in Riga. Those organisations are separate controllers with their own notices.


3. The short version


4. What we collect, why, and on what basis

Form: Book a Booth on ssdexpo.com, and the booking form on map.ssdexpo.com

We think you are entitled to know how our list was built, so here it is plainly.

Our subscriber records came from several places: newsletter sign-ups on our sites, visitor and exhibitor registrations for previous SSD editions, business cards and contacts collected at trade events, and business-contact research. The provenance is not uniform, and for part of the list we cannot produce a dated, per-person opt-in record.

We deal with that as follows, rather than asserting a blanket "you consented":

In every case, in every message, and without giving a reason, you can unsubscribe and we will stop.

We keep a business-contact record for exhibitors, prospects, speakers, suppliers and partners: name, job title, employer, business contact details, our correspondence with you, and the status of any commercial discussion.

Legal basis: Art 6(1)(f), our legitimate interest in managing business relationships and in offering the next edition of an event to a previous customer or a relevant professional contact. Recital 47 of the GDPR expressly recognises direct marketing as capable of being a legitimate interest. We hold a written legitimate-interests assessment. Contract and invoice data also sits under Art 6(1)(b) and Art 6(1)(c).

Retention: reviewed every 24 months; records with no meaningful interaction for 36 months are deleted or reduced to a company-level record with no named individual.

You can object at any time under Art 21(1), and absolutely and without reasons if the processing is for direct marketing (Art 21(2)).

Not every record in our CRM came from the person it describes. We also obtain business-contact data from:

We use only business-contact information: name, job title, employer, work email, work phone, country. We do not build profiles from personal or private sources.

Where we obtain your data this way, we will tell you at the latest when we first contact you, and in any event within one month, as Art 14(3) requires. Legal basis: Art 6(1)(f), with the legitimate-interests assessment described above. You have the same rights as everyone else, including the absolute right to object to marketing.

Where we hold business contact details that did not come from you directly, we write to you once to say so, explain what we hold and why, and give you a one-click way to object.

Covered in full in section 6. Legal basis: your consent (Art 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive as transposed in Estonia through the Electronic Communications Act). We do not rely on legitimate interest for analytics or advertising cookies; that basis is not available for storing or reading information on your device.

Our web hosts record IP address, browser type, pages requested, and timestamps, to keep the sites available and defend against attack. ssdexpo.com is hosted in Estonia by Zone Media OÜ; map.ssdexpo.com is hosted by Netlify, Inc. Legal basis: Art 6(1)(f). Retention: up to 12 months.


5. Retention at a glance


6. Cookies, tags and tracking

When you first visit ssdexpo.com, you are asked to choose. Until you choose:

You can accept everything, reject everything, or choose category by category, on the first screen. Rejecting takes no more effort than accepting. You can change your mind at any time using Cookie settings in the footer of every page; doing so stops the relevant tags immediately and clears the cookies they set. Refusing costs you nothing: the whole site, including every form, remains available.

We keep a record of what you chose and when, so we can prove it. We store your choice for 6 months and will not ask you again within that window unless what we do materially changes.

map.ssdexpo.com shows no banner because there is nothing to ask about: the booth map loads no analytics or advertising tag. The only thing it stores is your dark or light view preference.

The categories are the same four you see in Cookie settings. The full item-by-item list, with lifetimes and domains, is in our Cookie Policy.

Strictly necessary, always on, no consent needed: your cookie choice (ssd_consent and wp_consent_*, 6 months); WordPress login and security cookies, set only for signed-in editors; the small items Typeform's script stores on our own domain when you dismiss a form pop-up; the booth map's dark/light preference; and two session-only items that stop one form submission being counted twice.

Audience measurement, only with your consent: Google Analytics 4 cookies _ga and _ga_<property> (2 years) for the three properties named in 6.3.

Advertising and remarketing, only with your consent: Google Ads cookies _gcl_au, _gcl_aw and related _gcl_* cookies (90 days), Google's _gcl_ls entry in your browser's local storage, and our own ssd_attr record of the advertising click that brought you here (90 days). Google's own third-party cookies (IDE on doubleclick.net, NID on google.com) are set by Google once this category is on.

Embedded content from other companies, only with your consent: the supplier request-for-information form hosted by Airtable (Formagrid, Inc.). If you decline this category, the form is replaced by a short description and a Load this form button. One click loads it, for that form only.

Our Typeform forms, including Book a Booth, are not in any consent category. Nothing is fetched from Typeform until you click a button to open a form, and that click is itself the action the law requires. Typeform's own cookies, set inside its frame once a form is open, are on Typeform's list linked from the Cookie Policy.

Our Google tag (container GT-P3NZ39KH, installed through the WordPress "Site Kit by Google" plugin) sends data to three Google Analytics 4 properties, all belonging to Exponaut OÜ:

The same tag also sends conversion and remarketing data to Google Ads account AW-644215519.

Google Signals is enabled on our Analytics properties. It adds cross-device and demographic reporting for people who are signed in to a Google account. It sets no cookie on our domain, and it operates only when you have switched on advertising.

If you consent to advertising cookies, Google may add you to remarketing audiences used to show you our ads elsewhere. Some of those audiences have a membership duration of up to 540 days, which is Google's maximum.

We want to be explicit about something that is otherwise invisible.

Our forms carry hidden fields that can capture advertising and analytics identifiers alongside the details you type in: gclid, wbraid and gbraid (Google advertising click identifiers), msclkid and fbclid (Microsoft and Meta click identifiers, where present), client_id and session_id (read from the Google Analytics cookie on your device), and utm_source / utm_campaign (campaign labels carried in the link you clicked).

We use these to understand which campaigns generate genuine enquiries.

If you decline advertising cookies, the identifier fields are submitted empty. We do not attach an advertising identifier to your name, company and VAT number for someone who has said no. The utm campaign labels carry no device identifier and are kept either way.

Where you consent or decline, we pass your choice to Google using Google Consent Mode (the ad_storage, analytics_storage, ad_user_data and ad_personalization signals). This is a technical mechanism for transmitting your decision. It does not replace your decision, and it does not create consent. For visitors in the EEA, the UK and Switzerland our defaults are set to denied until you choose otherwise.

We use Google's advanced consent mode. In plain terms: the Google tag does load on the page, and while your choice is denied your browser still contacts Google, but the request carries no cookie and no identifier. It is a basic, cookieless signal that a page was viewed. Nothing that can single you out is stored or transmitted. When you accept, the corresponding cookies are created from that point onward.

Select Cookie settings in the footer of any page, or go to Cookie preferences. That opens the same panel you saw when you first arrived. Reject all withdraws everything in one click. You do not have to email us, ring us, or sign in.

The moment you withdraw:

Two limits, stated rather than left for you to discover: we cannot delete Google's own cookies on google.com and doubleclick.net (use your browser settings or Google's My Ad Center); and withdrawing stops future collection but does not erase what was lawfully collected while your consent was in force. If you want that deleted too, ask us under section 9.


7. Who we share your data with

We do not sell personal data. We share it with the service providers below, who process it on our instructions under written data processing terms, and with professional advisers, auditors, the Estonian Tax and Customs Board, and law-enforcement or regulatory bodies where we are legally obliged to.

You can ask us for a copy of the Standard Contractual Clauses we rely on, by emailing 2027@ssdexpo.com.


8. Sending data outside the EU/EEA

Some of the providers above are in the United States. When your data goes there, it is protected by one of two mechanisms:

We keep Standard Contractual Clauses in place even where an adequacy decision applies, so that a change in that decision does not leave a transfer unprotected. The Data Privacy Framework adequacy decision is in force but is under challenge before the Court of Justice, and we monitor its status.


9. Your rights

You have the following rights over your personal data. They are free to exercise, and we will respond within one month. If a request is complex we may extend that by a further two months, and we will tell you within the first month if we do. We may need to verify your identity first.

To exercise any of these, email 2027@ssdexpo.com. Where a right relates to marketing, you can also just use the unsubscribe link, and for cookies you can use Cookie settings in the footer.


10. Complaints

If you think we have handled your data wrongly, please contact us first at 2027@ssdexpo.com. We would rather fix it.

You can also complain directly to our supervisory authority:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Telephone: +372 627 4135
Email: info@aki.ee · Web: www.aki.ee (English: www.aki.ee/en)
Electronic submissions should be digitally signed and sent to info@aki.ee.

You may instead complain to the supervisory authority in the country where you live, where you work, or where the problem happened (Art 77(1)). For example, if you are in Latvia:

Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Riga LV-1050, Latvia · +371 67 223 131 · pasts@dvi.gov.lv

Note that for cookies and similar technologies, the "one-stop-shop" rule does not apply: the authority in your own country can act directly, even though we are established in Estonia.


11. Automated decision-making and profiling

We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you. Nobody is refused a stand, a registration or a speaking slot by an algorithm.

We do carry out limited profiling for marketing purposes: segmenting our audience by country, industry and engagement, and building advertising audiences with Google. Advertising audiences are built only where you have consented to advertising cookies, and you can object to marketing profiling at any time under Art 21(2).


12. How we protect your data

We use access controls, multi-factor authentication on our business systems, encrypted connections, and reputable service providers with their own security certifications. Access to personal data inside Exponaut OÜ is limited to the people who need it for their role.

We are conscious that our audience includes government procurement staff and defence-industry personnel, and that a list of who is attending a defence expo is sensitive in commercial and security terms even though it is not "special category" data under the GDPR. We treat it accordingly: we do not sell it, and we do not share it with exhibitors except with your consent at the point of a badge scan.

If a data breach occurs that is likely to result in a high risk to you, we will tell you without undue delay, and we will notify the Estonian Data Protection Inspectorate within 72 hours as required by Art 33.


13. Children

Our events and services are for professionals. We do not knowingly collect data from anyone under 16.


14. Changes to this notice

We will update this notice when what we do changes. If we intend to use your data for a new purpose, we will tell you about that purpose, and give you the further information Art 13(2) requires, before we start (Art 13(3)).

The version number and "last updated" date at the top of this page change whenever we amend it. We keep an archive of every published version, including the exact text of the consent banner in use at the time, so that we can show what you were told when.

Material changes will be announced by email to newsletter subscribers and by a notice on ssdexpo.com.


15. Version history