Privacy Policy
Privacy Policy
1. Data Controller
Gibrisch Inc. ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with our website (www.gibrisch.com) and our event production services.
Gibrisch Inc. is the data controller responsible for your personal information and is committed to complying with applicable data protection laws including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy regulations.
Company Address: 250 Park Avenue South, Suite 2500 New York, NY 10003 United States
Contact Email: [email protected]
2. Information We Collect
We collect personal information through various means to provide our services and improve your experience. We have categorized the types of information we collect:
2.1 Information You Provide Directly
We collect information that you voluntarily provide to us, including:
- Contact Information - Name, email address, phone number, company name, job title, and address when you submit contact forms, request consultations, or register for events
- Communication Information - Any messages, inquiries, or correspondence you send us through our website, email, phone, or other channels
- Event Planning Details - Information about your event requirements, preferences, budget, guest lists, special requests, dietary restrictions, accessibility needs, and other event-specific details you share with us
- Payment Information - Billing address, payment method details, and transaction history when you book our services (payment processing is handled by secure third-party providers)
- Professional Background - Information about your role, organization, industry, and professional experience relevant to your event needs
- Preferences and Interests - Your communication preferences, service preferences, and interests in our offerings
- Feedback and Testimonials - Any feedback, reviews, testimonials, or case study information you agree to share
- Identity Verification - Government-issued ID or other verification information for certain event requirements
2.2 Information Collected Automatically
When you visit our website and interact with our services, we automatically collect certain information about your device and browsing behavior:
- Website Usage Data - Pages visited, time spent on pages, links clicked, search queries, and navigation patterns through our website
- Device Information - Device type, operating system, browser type and version, device identifiers, and device settings
- IP Address and Location Data - Your IP address and approximate geographic location (country, city, region level)
- Cookie and Tracking Information - Information collected through cookies, pixels, web beacons, and similar tracking technologies
- Log Files - Server logs including access times, pages accessed, referral URLs, and error messages
- Analytics Data - Information about how you interact with our website, including user sessions, conversion tracking, and user journey data
- Performance Data - Information about website performance, loading times, and technical issues you experience
2.3 Information From Third Parties
We may receive information about you from other sources:
- Business Partners and Vendors - Information from event venues, caterers, audiovisual providers, and other vendors involved in your event production
- Referral Sources - When someone refers your contact information to us for event planning services
- Publicly Available Sources - Publicly available information from websites, social media platforms, business directories, and public records
- Event Attendees - Information about attendees at your event, including names, email addresses, and attendance data
- Data Providers - Demographic and business information from third-party data providers to enhance our understanding of our clients
- Social Media Platforms - Information when you interact with us or sign in through social media accounts
- Legal and Compliance Sources - Information required for legal compliance, background checks, or fraud prevention purposes
3. How We Use Your Data
We process your personal information for various legitimate business purposes:
3.1 Service Delivery
- Providing event planning, production, and coordination services you request
- Processing and fulfilling your event bookings and contracts
- Managing vendor coordination and vendor relationships for your event
- Providing technical support and customer service
- Creating event proposals, quotes, and contracts
- Managing event logistics, timelines, and execution
- Coordinating with third-party vendors and service providers
- Processing payments and managing billing
- Providing post-event support and follow-up services
3.2 Communication
- Responding to your inquiries and requests
- Sending confirmation emails and event updates
- Providing event-related notifications and reminders
- Communicating about changes to services or policies
- Sending newsletters and promotional materials (with your consent)
- Conducting customer satisfaction surveys and feedback collection
- Marketing our services through email campaigns
3.3 Analytics and Improvement
- Analyzing website traffic and user behavior patterns
- Analyzing event performance and attendee engagement
- Improving our website, services, and customer experience
- Conducting research and analytics on service trends
- Testing new features and optimizing existing ones
- Creating aggregated and anonymized reports and statistics
- Measuring the effectiveness of our marketing efforts
3.4 Legal Compliance and Safety
- Complying with applicable laws, regulations, and legal obligations
- Responding to lawful requests from government and regulatory authorities
- Enforcing our Terms and Conditions and other legal agreements
- Protecting against fraud, abuse, and illegal activity
- Preventing and addressing technical or security issues
- Maintaining records for audit and compliance purposes
- Managing dispute resolution and legal claims
- Background checks and screening for event access
3.5 Security and Fraud Prevention
- Detecting, investigating, and preventing fraudulent transactions and security breaches
- Protecting the security of our systems and networks
- Monitoring for unauthorized access and misuse
- Maintaining security logs and audit trails
- Implementing and testing security measures
3.6 Business Operations
- Managing our business operations and internal processes
- Performance evaluation and employee management
- Creating internal reports and business analytics
- Managing vendor and contractor relationships
- Organizing and coordinating team communications
- Training and quality assurance purposes
- Archiving and record-keeping for business purposes
3.7 Marketing and Business Development
- Promoting our services and offerings
- Conducting marketing campaigns and promotional activities
- Identifying new business opportunities
- Developing new services and offerings
- Creating case studies and success stories (with consent)
- Building our client portfolio and demonstrating expertise
4. Legal Basis for Processing
We process your personal information based on the following legal bases:
4.1 Consent
Where you have explicitly consented to the processing of your personal information, such as:
- Subscribing to our newsletter or marketing communications
- Agreeing to be contacted for promotional purposes
- Allowing us to use your information for testimonials or case studies
- Accepting cookies beyond essential ones
You may withdraw consent at any time by contacting us using the information provided in this policy.
4.2 Contract Performance
We process your information to perform the services you've requested:
- Executing event production contracts
- Fulfilling event planning and coordination services
- Processing payments and managing billing relationships
- Providing customer support related to your services
4.3 Legitimate Interests
We rely on legitimate business interests to process your information for:
- Improving our services and customer experience
- Fraud prevention and security
- Marketing our services (where compliant with regulations)
- Analyzing business performance and trends
- Maintaining and improving our website
- Protecting our legal rights and interests
- Business analytics and decision-making
4.4 Legal Obligation
We process information as required by law:
- Complying with tax and accounting regulations
- Responding to legal requests and court orders
- Meeting regulatory requirements for specific industries
- Maintaining records required by law
- Fulfilling event-related legal and safety requirements
5. Data Sharing and Disclosure
We may share your personal information with third parties in certain circumstances:
5.1 Service Providers
We share necessary information with service providers who assist us in providing our services:
- Event venues, caterers, and hospitality providers
- Audiovisual and technical production companies
- Florists, decorators, and design vendors
- Entertainment and talent management companies
- Transportation and logistics providers
- Security and insurance providers
- Payment processors and financial institutions
- Email and communications platforms
- Analytics and data analysis providers
- Website hosting and cloud service providers
- Marketing and advertising platforms
All service providers are contractually obligated to use your information only as necessary to provide services and must maintain appropriate security measures.
5.2 Legal Authorities and Compliance
We may disclose information when required by law or in response to:
- Lawful government requests and court orders
- Regulatory agencies and compliance investigations
- Law enforcement requests
- Legal proceedings and litigation
- Subpoenas and civil discovery requests
- Requirements to protect public safety
5.3 Business Transfers
If Gibrisch is involved in a merger, acquisition, bankruptcy, restructuring, or sale of assets:
- Your information may be transferred as part of that transaction
- We will provide notice of any such change
- Any successor company must honor this Privacy Policy
5.4 Professional Advisors
We may share information with:
- Legal counsel and attorneys
- Accountants and financial advisors
- Insurance providers and brokers
- Consultants and business advisors
5.4 Aggregated and De-identified Data
We may share aggregated, anonymized information that cannot identify you:
- Statistical reports and analytics
- Industry benchmarks and trends
- Business insights and case studies (anonymized)
5.5 With Your Consent
We may share your information with other third parties when you explicitly consent, such as:
- Publishing testimonials or case studies
- Referrals to other service providers
- Joint marketing or partnership initiatives
- Research and academic purposes
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy:
6.1 Active Clients
- Client information is retained throughout the service relationship and for the duration of the contract
- We maintain records for 7 years after contract completion for accounting, tax, and legal compliance purposes
6.2 Prospective Clients and Inquiries
- Inquiry information is retained for 2 years to respond to requests and maintain business opportunities
- Email lists and marketing contacts are retained for 3 years unless you unsubscribe earlier
6.3 Website and Analytics
- Website usage data and analytics are typically retained for 13 months
- Server logs are retained for 90 days
- Cookies expire according to their specific duration settings (see Cookie Policy)
6.4 Marketing Communications
- Marketing email records are retained for 3 years from the last communication
- Newsletter subscriber lists are maintained until unsubscription
6.5 Payment and Billing Records
- Payment information and invoices are retained for 7 years for tax and financial compliance
- Payment method details are not retained after transaction completion
6.6 Legal and Regulatory Requirements
- Information required for legal compliance is retained for the period required by applicable law
- Records related to disputes or legal proceedings are retained for the duration of the matter plus applicable limitations periods
6.7 Deletion Requests
Upon your request, we will delete your personal information unless we are required to retain it by law or for legitimate business purposes. Deletion requests are processed within 30 days.
7. Data Security
We implement comprehensive technical and organizational security measures to protect your personal information:
7.1 Encryption
- All sensitive data transmitted over the internet is encrypted using SSL/TLS protocols
- Payment information is encrypted both in transit and at rest
- Client databases are encrypted with AES-256 encryption or equivalent
7.2 Access Controls
- Access to personal information is restricted to authorized employees, contractors, and service providers
- Employees undergo background checks and sign confidentiality agreements
- Access is granted on a need-to-know basis
- Multi-factor authentication is required for administrative access
- Regular access audits are conducted
7.3 Network Security
- Our network is protected by firewalls and intrusion detection systems
- Regular security scans and penetration testing are conducted
- We maintain a secure, monitored data center environment
- VPN and secure connections are required for remote access
7.4 Data Protection
- Regular backups are maintained for disaster recovery
- Backup data is encrypted and stored securely
- Data is segregated based on sensitivity levels
- Pseudonymization is applied where feasible
7.5 Incident Response
- We maintain an incident response plan to address security breaches
- Suspected breaches are investigated promptly
- Affected individuals are notified within 72 hours or as required by law
- We cooperate with regulatory authorities and law enforcement
7.6 Employee Training
- All employees receive data protection and security training
- Regular training updates are provided on security best practices
- Employees are trained on handling personal information appropriately
- Confidentiality is enforced through employment agreements
7.7 Third-Party Security
- Service providers are required to maintain appropriate security measures
- Vendor security assessments are conducted before engagement
- Data processing agreements include strict security requirements
- Regular audits of third-party security are performed
8. Your Rights
Depending on your location and applicable data protection laws, you may have the following rights regarding your personal information:
8.1 Right of Access
You have the right to request access to your personal information that we hold. We will provide you with a copy of your data in a structured, commonly used, and machine-readable format. This right helps you understand what information we collect and how we use it. To exercise this right, contact us with your request, and we will provide the information within 30 days.
8.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal information. If you believe any of your information is incorrect or outdated, you may request that we update or correct it. We will make corrections within 30 days and inform any recipients of the corrected information where required.
8.3 Right to Erasure (Right to be Forgotten)
Under certain circumstances, you have the right to request deletion of your personal information, including when:
- The information is no longer necessary for the purposes for which it was collected
- You withdraw your consent (where consent is the basis for processing)
- You object to processing and there are no overriding legitimate interests
- The information was collected unlawfully
- Erasure is required by law
Note: We may be unable to delete information that is required for legal, accounting, or regulatory compliance. We will retain only the minimum information necessary.
8.4 Right to Restrict Processing
You have the right to restrict how we process your personal information while you verify accuracy, challenge lawfulness, or pending a decision on your rights. During restriction, we may store your information but will not actively use it, except with your consent or for legal reasons. You may request restriction when:
- You dispute the accuracy of the information
- Processing is unlawful, but you request restriction instead of deletion
- We no longer need the information but you require it for legal claims
- You have objected to processing pending verification
8.5 Right to Data Portability
You have the right to obtain a copy of your personal information in a structured, commonly used, and machine-readable format (such as CSV or JSON) and transmit it to another data controller. This right applies where we process your information based on consent or contract. You may request your data within 30 days, and we will provide it in the requested format.
8.6 Right to Object
You have the right to object to our processing of your personal information on legitimate interest or direct marketing grounds. You may object to:
- Processing for direct marketing purposes (including email marketing)
- Processing based on our legitimate interests
- Processing for research and statistics
- Automated decision-making and profiling
We will stop processing your information unless we demonstrate compelling legitimate interests that override your rights.
8.7 Right to Withdraw Consent
If we process your information based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing before withdrawal. You may withdraw consent by contacting us, and processing will cease promptly.
8.8 Right to Lodge a Complaint
You have the right to lodge a complaint with your relevant data protection authority if you believe we have violated your rights. You may file a complaint with:
For US Residents:
- Your state attorney general's office
- Federal Trade Commission (FTC): www.ftc.gov/complaint
For EU Residents:
- Your national data protection authority (e.g., CNIL for France, GDPR authorities in your member state)
- You may find your authority at: edpb.ec.europa.eu
For California Residents (CCPA):
- California Privacy Protection Agency (CPPA)
- California Attorney General
8.9 How to Exercise Your Rights
To exercise any of these rights, please submit a written request to:
Email: [email protected] Address: 250 Park Avenue South, Suite 2500, New York, NY 10003 Subject: "Data Subject Rights Request"
Please include sufficient information to identify you and specify which right you wish to exercise. We will respond within 30 days (or up to 60 days for complex requests). We may request additional information to verify your identity before processing your request.
9. International Data Transfers
Gibrisch operates internationally and may transfer your personal information across borders:
9.1 Data Transfer Mechanisms
- EU/EEA to US: Transfers are made under appropriate safeguards including Standard Contractual Clauses (SCCs)
- Adequacy Decisions: Where applicable, we rely on adequacy decisions from relevant authorities
- Your Consent: You may consent to transfers to countries without equivalent protections
- Data Processing Agreements: All transfers are governed by data processing agreements with appropriate terms
9.2 International Standards
We comply with applicable international data protection standards and regulations when transferring data across borders.
9.3 Your Rights in Other Jurisdictions
When your information is transferred internationally, you maintain all rights under applicable data protection laws in both the source and destination countries.
10. Children's Privacy
Our services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will:
- Delete such information promptly
- Notify the parent or legal guardian
- Cease collection efforts directed at such child
For children under 13 in the US or equivalent ages in other jurisdictions, we comply with the Children's Online Privacy Protection Act (COPPA) and equivalent regulations.
If you believe a child has provided us with personal information, please contact us immediately at [email protected].
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated policy on our website
- Updating the "last modified" date at the bottom of this policy
- Sending you an email notification if the changes significantly affect your rights
- Obtaining your consent if required by applicable law
Your continued use of our services following the posting of changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.
12. Contact Us
If you have questions about this Privacy Policy, your personal information, or our privacy practices, please contact us:
Gibrisch Inc. 250 Park Avenue South, Suite 2500 New York, NY 10003 United States
Email: [email protected] Phone: +1 (212) 555-0147 Data Protection Officer: [email protected]
We will respond to your inquiry within 10 business days. If you are not satisfied with our response, you have the right to lodge a complaint with your relevant data protection authority.
Last Modified: April 2026
Effective Date: April 1, 2026