Privacy policy
Last updated: 18 September 2026.
This policy explains how we process the personal data of people who visit this website or contact us, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
1. Data controller
Controller: 2M GROUP EVENTOS S.L.
Tax ID (NIF): B87192498
Address: Calle de Gutierre de Cetina, 103, Local 1, Ciudad Lineal, 28017 Madrid (España)
Data protection contact: contact form (write "Data protection" in your message) or by post to the address above, marked "Data protection".
2. What data we process
Data you give us through the forms (contact, press and accreditation, event hiring, brand proposals and internships): name and surname, email address, phone number if you provide it, company or media outlet, town, event date or type, studies and school in the case of internships, and the content of your message.
Technical browsing data: IP address, browser and device type, pages visited and date and time of the visit, logged for security purposes and, only if you accept them, through analytics and advertising cookies (see the cookie policy).
We do not ask for special categories of data (health, beliefs, etc.). Please do not include them in your messages.
3. Purposes and legal basis
Answering your requests
Replying to the messages you send through the forms and handling quote or hiring requests, press accreditations and collaboration proposals. Legal basis: your consent when submitting the form (art. 6.1.a GDPR) and, when you request a quote or service, pre-contractual steps taken at your request (art. 6.1.b GDPR).
Internships
Assessing your internship application and, where appropriate, arranging the agreement with your university or school. Legal basis: your consent (art. 6.1.a GDPR) and, if the internship goes ahead, the performance of that agreement (art. 6.1.b GDPR).
Web analytics
Understanding in aggregate how the website is used (visits, page views, traffic sources) in order to improve it, with Google Analytics 4. Legal basis: your consent through the cookie banner (art. 6.1.a GDPR and art. 22.2 LSSI-CE).
Campaign measurement and advertising
Measuring the performance of our social media campaigns and showing ads for our events to people who have visited the website, with the Meta pixel (Facebook and Instagram). Legal basis: your consent through the cookie banner (art. 6.1.a GDPR and art. 22.2 LSSI-CE).
Website security
Protecting the website against abuse (for example, limiting bulk form submissions) and keeping technical access logs. Legal basis: our legitimate interest in keeping the website secure (art. 6.1.f GDPR).
Legal obligations
Responding to requests from authorities and keeping the information required by law. Legal basis: compliance with legal obligations (art. 6.1.c GDPR).
We do not make automated decisions or build profiles with legal effects on you. We do not send commercial emails without your prior express consent.
4. Retention periods
Form messages: as long as needed to handle your request and at most one year from the last communication, unless a contractual relationship begins.
Customer and contract data: for the duration of the relationship and then for the legal limitation periods (generally six years for commercial records and four for tax records).
Internship applications: up to one year from receipt, unless the internship goes ahead.
Cookies: the periods stated in the cookie policy. Google Analytics data is kept for a maximum of 14 months.
Technical security logs: up to 12 months.
After these periods, data is deleted or blocked for as long as liabilities may arise, in accordance with article 32 LOPDGDD.
5. Recipients
We do not sell or disclose your data to third parties, except where required by law. The providers of our web hosting, technical maintenance and email services access it as data processors, under contracts that guarantee confidentiality and security.
If you accept analytics or advertising cookies, browsing data is shared with:
Google Ireland Limited (Google Analytics 4), as data processor.
Meta Platforms Ireland Limited (Meta pixel), acting as joint controller for the collection and transmission of the data and as independent controller for its further processing. More information in Meta's privacy policy.
When you ask about a specific event run by another organiser or venue, we will only pass your request on to them if you expressly ask us to.
6. International transfers
Google and Meta may process data in the United States. These transfers rely on the European Commission's adequacy decision on the EU-US Data Privacy Framework, to which Google LLC and Meta Platforms, Inc. are certified, and on the standard contractual clauses approved by the European Commission.
7. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent given, without affecting the lawfulness of prior processing. To do so:
Send us your request through the contact form, writing "Data protection" and the right you wish to exercise, or
Write to 2M GROUP EVENTOS S.L., Calle de Gutierre de Cetina, 103, Local 1, Ciudad Lineal, 28017 Madrid (España), marked "Data protection".
If we have reasonable doubts about your identity, we may ask for additional information to confirm it. We will reply within one month, extendable by two further months in complex cases.
You can withdraw or change your cookie consent at any time from "Cookie settings" in the website footer.
If you believe we have not handled your rights properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD, C/ Jorge Juan, 6, 28001 Madrid · www.aepd.es).
8. Minors
The website is not aimed at children under 14 and we do not knowingly collect their data. If you are under 14, do not send us personal data without your parents' or guardians' consent (art. 7 LOPDGDD). Many of our events are restricted to adults according to their regulations and each event's terms.
9. Accuracy of data
You guarantee that the data you provide is true, accurate and up to date and that, if it belongs to someone else, you have their permission. You are responsible for telling us about any changes.
10. Security
We apply appropriate technical and organisational measures to protect your data against loss, alteration or unauthorised access: encrypted connection (HTTPS), access control to the administration area with hashed passwords and secure sessions, backups, and access limited to staff who need it.
11. Changes to this policy
We may update this policy to reflect legal changes or changes in our processing. The current version, with its update date, is always published on this page. In case of discrepancy, the Spanish version prevails.