Controller: Exponaut OÜ
Version: 1.0 · Last updated: 8 September 2026
Applies to: ssdexpo.com, map.ssdexpo.com, our SSD 2027 forms, our newsletters, and the SSD 2027 event in Riga, 16–17 June 2027.
Exponaut OÜ is an Estonian private limited company. We organise the Supply Security & Defence Expo (SSD 2027), taking place in Riga, Latvia on 16–17 June 2027. We also organised the previous edition, SSD 2026.
| Legal name | Exponaut OÜ |
| Registry code | 16067851 |
| VAT ID | EE102309052 |
| Registered address | Laeva 2, 10111 Tallinn, Estonia |
| Country of establishment | Estonia (EU/EEA) |
| Privacy contact | 2027@ssdexpo.com |
| Responsible board member | Rainis Vares |
We are the data controller for everything described in this notice: we decide why and how your personal data is used, and we are accountable for it.
We have not appointed a Data Protection Officer. We are not required to under Article 37 of the GDPR: we are not a public authority, our core business is running a trade expo rather than large-scale monitoring of people, and we do not process special-category data at scale. Please use the privacy contact address above for anything covered by this notice.
This notice explains what personal data we collect, why, on what legal basis, how long we keep it, who we share it with, and what you can do about it. It covers you if you:
It does not cover what other companies do with your data once you deal with them directly, for example an exhibitor whose stand you visit, or the venue operator in Riga. Those organisations are separate controllers with their own notices.
Form: Book a Booth on ssdexpo.com, and the booking form on map.ssdexpo.com
| What we collect | First name, last name, job title/position, work email, phone, company/organisation name, full postal address, city, state/region, postcode, country, company VAT number, indoor/outdoor preference, booth size, preferred payment method, and whether you opt in to our procurement platform. |
| Why | To quote for, contract, invoice and deliver your exhibition stand; to issue a valid VAT invoice; to plan the floor layout; to contact you about your stand before and during the event. |
| Legal basis | Art 6(1)(b) GDPR: steps taken at your request before entering a contract, and performance of that contract where you are contracting in your own name (for example as a sole trader). Once the contract is signed with a company, we rely on Art 6(1)(f), our legitimate interest in administering a business contract through a named contact person, since you personally are not the counterparty. Art 6(1)(c), legal obligation, for the invoice, the VAT number and the accounting record. The procurement-platform opt-in is separate consent, Art 6(1)(a), and refusing it has no effect on your booking. |
| Do you have to provide it? | Yes, for the fields marked required. We cannot quote for or contract a stand without them, and we cannot issue a compliant invoice without the company details and VAT number. |
| Retention | Enquiries that do not convert: 24 months from last contact. Signed contracts, invoices and related accounting documents: 7 years from the end of the financial year in which the transaction was recorded (Estonian Accounting Act § 12; Taxation Act § 58). |
| Shared with | Typeform (form capture), Pipedrive (CRM), Microsoft 365 (email), our accountant and, where relevant, the Estonian Tax and Customs Board. Stand-build and venue contractors receive only the operational details needed to build and site your stand. |
| What we collect | Name, job title, organisation, work email, phone, country, and your registration preferences. |
| Why | To register you, produce your badge, manage entry to the venue, and send you operational information about the event (times, agenda, venue, changes). |
| Legal basis | Art 6(1)(b): your registration is the contract for admission. Art 6(1)(c) for invoicing where the registration is paid. Operational emails about the event you registered for are not marketing and are covered by the same basis. |
| Retention | Registration and attendance records: event date + 12 months. Paid registrations: financial records kept 7 years as above. |
| Shared with | Typeform, Pipedrive, Microsoft 365, and the venue/security operator in Riga where access control requires it. |
| What we collect | Name, contact details, employer, job title, biography, proposed topic, and anything else you choose to include (for example a CV or photo). |
| Why | To assess your application, build the conference programme, and publish speaker details if you are selected. |
| Legal basis | Art 6(1)(b): steps at your request before a speaking agreement. Art 6(1)(f) for programme selection and internal review. Publishing your name, photo and biography on our website and in marketing: Art 6(1)(b) where the speaker agreement covers it, otherwise Art 6(1)(a) consent, which you can withdraw. |
| Retention | Unsuccessful applications: 12 months. Successful applications: with the contract file, 7 years for the financial record; published biographies remain online until you ask us to remove them or the event archive is retired. |
| Please note | Do not send us health information, political or trade-union affiliation, or other special-category data. We do not ask for it and will delete it if it arrives. If you tell us about accessibility or dietary requirements, that is health or religious-belief data under Art 9. We ask for it only with your explicit consent (Art 9(2)(a)), use it only to make arrangements for you, and delete it within 30 days after the event. |
| What we collect | Email address, and where you gave them: name, company, country, job title. Plus engagement data from Mailchimp (whether an email was opened, which links were clicked). |
| Why | To send SSD event news, exhibiting and attendance opportunities, and Baltic Defence Weekly. |
| Legal basis | See section 4.5. It is set out in full because our position differs depending on how we obtained your address and where you are. |
| Retention | Until you unsubscribe or object, and in any event we re-permission or delete subscribers with no opens or clicks in 24 months. Unsubscribe records are kept indefinitely in minimal form (hashed email + date + source) so that we can prove we honoured your request and never email you again. This is required to comply with Art 21(3) and is not a failure to erase. |
| Shared with | Mailchimp (Intuit Inc.), Pipedrive. |
We think you are entitled to know how our list was built, so here it is plainly.
Our subscriber records came from several places: newsletter sign-ups on our sites, visitor and exhibitor registrations for previous SSD editions, business cards and contacts collected at trade events, and business-contact research. The provenance is not uniform, and for part of the list we cannot produce a dated, per-person opt-in record.
We deal with that as follows, rather than asserting a blanket "you consented":
In every case, in every message, and without giving a reason, you can unsubscribe and we will stop.
| What we collect | Contact name, company, email, phone, and the details of what you supply. |
| Why | To evaluate suppliers and manage the event supply chain. |
| Legal basis | Art 6(1)(b) pre-contractual steps, and Art 6(1)(f) for supplier management. |
| Retention | 24 months from last contact if no engagement follows; otherwise with the contract file (7 years). |
| Shared with | Airtable (the RFI form), Pipedrive, Microsoft 365. |
| What we collect | Whatever you send us: name, email, company, the content of your message, and any file you upload. |
| Why | To answer you and keep a record of the exchange. |
| Legal basis | Art 6(1)(b) where you are asking about a product or service, otherwise Art 6(1)(f), our legitimate interest in responding to and recording correspondence. |
| Retention | General correspondence: 3 years. Correspondence about a contract or invoice: 7 years with the contract file. |
| Note on uploads | Image files can contain hidden metadata (author name, software, sometimes location). We do not use it, but we do not always strip it. Remove metadata before uploading if that matters to you. |
We keep a business-contact record for exhibitors, prospects, speakers, suppliers and partners: name, job title, employer, business contact details, our correspondence with you, and the status of any commercial discussion.
Legal basis: Art 6(1)(f), our legitimate interest in managing business relationships and in offering the next edition of an event to a previous customer or a relevant professional contact. Recital 47 of the GDPR expressly recognises direct marketing as capable of being a legitimate interest. We hold a written legitimate-interests assessment. Contract and invoice data also sits under Art 6(1)(b) and Art 6(1)(c).
Retention: reviewed every 24 months; records with no meaningful interaction for 36 months are deleted or reduced to a company-level record with no named individual.
You can object at any time under Art 21(1), and absolutely and without reasons if the processing is for direct marketing (Art 21(2)).
Not every record in our CRM came from the person it describes. We also obtain business-contact data from:
We use only business-contact information: name, job title, employer, work email, work phone, country. We do not build profiles from personal or private sources.
Where we obtain your data this way, we will tell you at the latest when we first contact you, and in any event within one month, as Art 14(3) requires. Legal basis: Art 6(1)(f), with the legitimate-interests assessment described above. You have the same rights as everyone else, including the absolute right to object to marketing.
Where we hold business contact details that did not come from you directly, we write to you once to say so, explain what we hold and why, and give you a one-click way to object.
Covered in full in section 6. Legal basis: your consent (Art 6(1)(a) GDPR, and Article 5(3) of the ePrivacy Directive as transposed in Estonia through the Electronic Communications Act). We do not rely on legitimate interest for analytics or advertising cookies; that basis is not available for storing or reading information on your device.
Our web hosts record IP address, browser type, pages requested, and timestamps, to keep the sites available and defend against attack. ssdexpo.com is hosted in Estonia by Zone Media OÜ; map.ssdexpo.com is hosted by Netlify, Inc. Legal basis: Art 6(1)(f). Retention: up to 12 months.
| Record | How long we keep it | Why |
|---|---|---|
| Contracts, invoices, accounting source documents | 7 years from the end of the financial year in which the transaction was recorded | Estonian Accounting Act § 12; Taxation Act § 58. Documents relating to long-term rights or obligations: 7 years after expiry of validity |
| Booth enquiries that did not convert | 24 months from last contact | |
| Visitor registration and attendance | Event + 12 months | |
| Accessibility / dietary requirements | Event + 30 days | Art 9 data, kept to the minimum |
| Speaker applications (unsuccessful) | 12 months | |
| Newsletter subscription | Until you unsubscribe; re-permissioned or deleted after 24 months of no engagement | |
| Unsubscribe / suppression list | Indefinite, minimal form only (hashed email, date, source) | Required to keep honouring your objection (Art 21(3)) |
| CRM business-contact records | Reviewed every 24 months; deleted or anonymised after 36 months of no interaction | |
| Consent records (cookies and marketing) | For as long as we rely on that consent, plus 3 years | To prove consent under Art 7(1); 3 years is the Estonian general limitation period for claims |
| Google Analytics user- and event-level data | 14 months | GA4 setting. Aggregated standard reports are not affected by this setting, and age/gender/interest data always expires at 2 months |
| Google Ads audience membership | Up to 540 days | See section 6.4 |
| General email correspondence | 3 years (7 years if contract- or invoice-related) | |
| Web server and security logs | Up to 12 months |
When you first visit ssdexpo.com, you are asked to choose. Until you choose:
You can accept everything, reject everything, or choose category by category, on the first screen. Rejecting takes no more effort than accepting. You can change your mind at any time using Cookie settings in the footer of every page; doing so stops the relevant tags immediately and clears the cookies they set. Refusing costs you nothing: the whole site, including every form, remains available.
We keep a record of what you chose and when, so we can prove it. We store your choice for 6 months and will not ask you again within that window unless what we do materially changes.
map.ssdexpo.com shows no banner because there is nothing to ask about: the booth map loads no analytics or advertising tag. The only thing it stores is your dark or light view preference.
The categories are the same four you see in Cookie settings. The full item-by-item list, with lifetimes and domains, is in our Cookie Policy.
Strictly necessary, always on, no consent needed: your cookie choice (ssd_consent and wp_consent_*, 6 months); WordPress login and security cookies, set only for signed-in editors; the small items Typeform's script stores on our own domain when you dismiss a form pop-up; the booth map's dark/light preference; and two session-only items that stop one form submission being counted twice.
Audience measurement, only with your consent: Google Analytics 4 cookies _ga and _ga_<property> (2 years) for the three properties named in 6.3.
Advertising and remarketing, only with your consent: Google Ads cookies _gcl_au, _gcl_aw and related _gcl_* cookies (90 days), Google's _gcl_ls entry in your browser's local storage, and our own ssd_attr record of the advertising click that brought you here (90 days). Google's own third-party cookies (IDE on doubleclick.net, NID on google.com) are set by Google once this category is on.
Embedded content from other companies, only with your consent: the supplier request-for-information form hosted by Airtable (Formagrid, Inc.). If you decline this category, the form is replaced by a short description and a Load this form button. One click loads it, for that form only.
Our Typeform forms, including Book a Booth, are not in any consent category. Nothing is fetched from Typeform until you click a button to open a form, and that click is itself the action the law requires. Typeform's own cookies, set inside its frame once a form is open, are on Typeform's list linked from the Cookie Policy.
Our Google tag (container GT-P3NZ39KH, installed through the WordPress "Site Kit by Google" plugin) sends data to three Google Analytics 4 properties, all belonging to Exponaut OÜ:
G-ZG230N314L, our main SSD 2027 property (property ID 540079661);G-Y0BBQH3HBH;G-NS5SLYBTN3.The same tag also sends conversion and remarketing data to Google Ads account AW-644215519.
Google Signals is enabled on our Analytics properties. It adds cross-device and demographic reporting for people who are signed in to a Google account. It sets no cookie on our domain, and it operates only when you have switched on advertising.
If you consent to advertising cookies, Google may add you to remarketing audiences used to show you our ads elsewhere. Some of those audiences have a membership duration of up to 540 days, which is Google's maximum.
We want to be explicit about something that is otherwise invisible.
Our forms carry hidden fields that can capture advertising and analytics identifiers alongside the details you type in: gclid, wbraid and gbraid (Google advertising click identifiers), msclkid and fbclid (Microsoft and Meta click identifiers, where present), client_id and session_id (read from the Google Analytics cookie on your device), and utm_source / utm_campaign (campaign labels carried in the link you clicked).
We use these to understand which campaigns generate genuine enquiries.
If you decline advertising cookies, the identifier fields are submitted empty. We do not attach an advertising identifier to your name, company and VAT number for someone who has said no. The utm campaign labels carry no device identifier and are kept either way.
Where you consent or decline, we pass your choice to Google using Google Consent Mode (the ad_storage, analytics_storage, ad_user_data and ad_personalization signals). This is a technical mechanism for transmitting your decision. It does not replace your decision, and it does not create consent. For visitors in the EEA, the UK and Switzerland our defaults are set to denied until you choose otherwise.
We use Google's advanced consent mode. In plain terms: the Google tag does load on the page, and while your choice is denied your browser still contacts Google, but the request carries no cookie and no identifier. It is a basic, cookieless signal that a page was viewed. Nothing that can single you out is stored or transmitted. When you accept, the corresponding cookies are created from that point onward.
Select Cookie settings in the footer of any page, or go to Cookie preferences. That opens the same panel you saw when you first arrived. Reject all withdraws everything in one click. You do not have to email us, ring us, or sign in.
The moment you withdraw:
_gcl_ls entry, and our own ssd_attr record;ssd_consent), so that we do not ask you the same question again on the next page;Two limits, stated rather than left for you to discover: we cannot delete Google's own cookies on google.com and doubleclick.net (use your browser settings or Google's My Ad Center); and withdrawing stops future collection but does not erase what was lawfully collected while your consent was in force. If you want that deleted too, ask us under section 9.
We do not sell personal data. We share it with the service providers below, who process it on our instructions under written data processing terms, and with professional advisers, auditors, the Estonian Tax and Customs Board, and law-enforcement or regulatory bodies where we are legally obliged to.
| Provider | What it does for us | Where data is processed | Transfer safeguard |
|---|---|---|---|
| Microsoft Ireland Operations Limited (Microsoft 365) | Email and office systems | European Union / EFTA, under the Microsoft EU Data Boundary, with limited defined exceptions for some security and support scenarios | Standard Contractual Clauses in Microsoft's Data Protection Addendum; Microsoft Corporation is also certified under the EU–US Data Privacy Framework |
| Pipedrive OÜ | CRM | European Union | No transfer outside the EU |
| Typeform, S.L. | Forms on ssdexpo.com and the booth map | European Union (Spain); some of Typeform's sub-processors are in the United States | Standard Contractual Clauses for Typeform's onward transfers |
| Intuit Inc. (Mailchimp) | Newsletter and marketing email | United States | EU–US Data Privacy Framework; Standard Contractual Clauses as fallback |
| Google Ireland Limited / Google LLC | Analytics and advertising | European Union and United States | EU–US Data Privacy Framework (Google LLC); Standard Contractual Clauses as fallback |
| Formagrid, Inc. (Airtable) | Supplier request-for-information form | United States | Standard Contractual Clauses |
| Zone Media OÜ | Hosting of ssdexpo.com | Estonia | No transfer outside the EU |
| Netlify, Inc. | Hosting of map.ssdexpo.com | United States and EU edge locations | Standard Contractual Clauses |
| Our accountant | Bookkeeping and statutory accounts | Estonia | No transfer outside the EU |
You can ask us for a copy of the Standard Contractual Clauses we rely on, by emailing 2027@ssdexpo.com.
Some of the providers above are in the United States. When your data goes there, it is protected by one of two mechanisms:
We keep Standard Contractual Clauses in place even where an adequacy decision applies, so that a change in that decision does not leave a transfer unprotected. The Data Privacy Framework adequacy decision is in force but is under challenge before the Court of Justice, and we monitor its status.
You have the following rights over your personal data. They are free to exercise, and we will respond within one month. If a request is complex we may extend that by a further two months, and we will tell you within the first month if we do. We may need to verify your identity first.
To exercise any of these, email 2027@ssdexpo.com. Where a right relates to marketing, you can also just use the unsubscribe link, and for cookies you can use Cookie settings in the footer.
Your right to stop marketing
You can object to direct marketing at any time, and we must stop. There is no balancing test and you do not have to give a reason. This covers our newsletters, event promotion, and any profiling connected to that marketing. Use the unsubscribe link in any email, or write to 2027@ssdexpo.com. An objection takes effect across all our systems (Mailchimp, Pipedrive and our advertising audiences), not just the one you contacted. (GDPR Art 21(2)–(4).)
If you think we have handled your data wrongly, please contact us first at 2027@ssdexpo.com. We would rather fix it.
You can also complain directly to our supervisory authority:
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
Telephone: +372 627 4135
Email: info@aki.ee · Web: www.aki.ee (English: www.aki.ee/en)
Electronic submissions should be digitally signed and sent to info@aki.ee.
You may instead complain to the supervisory authority in the country where you live, where you work, or where the problem happened (Art 77(1)). For example, if you are in Latvia:
Datu valsts inspekcija (Data State Inspectorate)
Elijas iela 17, Riga LV-1050, Latvia · +371 67 223 131 · pasts@dvi.gov.lv
Note that for cookies and similar technologies, the "one-stop-shop" rule does not apply: the authority in your own country can act directly, even though we are established in Estonia.
We do not make decisions about you solely by automated means that produce legal effects or similarly significantly affect you. Nobody is refused a stand, a registration or a speaking slot by an algorithm.
We do carry out limited profiling for marketing purposes: segmenting our audience by country, industry and engagement, and building advertising audiences with Google. Advertising audiences are built only where you have consented to advertising cookies, and you can object to marketing profiling at any time under Art 21(2).
We use access controls, multi-factor authentication on our business systems, encrypted connections, and reputable service providers with their own security certifications. Access to personal data inside Exponaut OÜ is limited to the people who need it for their role.
We are conscious that our audience includes government procurement staff and defence-industry personnel, and that a list of who is attending a defence expo is sensitive in commercial and security terms even though it is not "special category" data under the GDPR. We treat it accordingly: we do not sell it, and we do not share it with exhibitors except with your consent at the point of a badge scan.
If a data breach occurs that is likely to result in a high risk to you, we will tell you without undue delay, and we will notify the Estonian Data Protection Inspectorate within 72 hours as required by Art 33.
Our events and services are for professionals. We do not knowingly collect data from anyone under 16.
We will update this notice when what we do changes. If we intend to use your data for a new purpose, we will tell you about that purpose, and give you the further information Art 13(2) requires, before we start (Art 13(3)).
The version number and "last updated" date at the top of this page change whenever we amend it. We keep an archive of every published version, including the exact text of the consent banner in use at the time, so that we can show what you were told when.
Material changes will be announced by email to newsletter subscribers and by a notice on ssdexpo.com.
| Version | Date | Change |
|---|---|---|
| 1.0 | 8 September 2026 | First publication. Issued together with the cookie banner, the Cookie Policy and the consent gating of Google Analytics, Google Ads and the embedded Airtable form. |