Privacy and Consent
This page applies from 7 September 2026 and replaces every earlier version.
1. Who is responsible for your data
1.1 HOLISTICON is a holistic fair that is currently run by Regurk Limited, Venture Hub, 136 Capel Street, D01 T2C9 Dublin, CRO number 813619, VAT ID IE4735160KH ("HOLISTICON", "we", "us"). We are the data controller for the personal data described on this page. Write to us at be@holisticon.ie about anything to do with your data.
1.2 Exhibitors who receive your details when you redeem a Badge benefit are separate, independent controllers of what they receive (see section 5).
2. The short version
- We collect what we need to run the fair, your account, your Badge and your orders, and nothing for its own sake.
- We never sell data, never run advertising trackers and never profile you.
- The only time your details go to an exhibitor is when you choose to redeem a benefit at their stall, and you are asked for your consent at that moment, every time.
- Marketing email goes only to people who asked for it and confirmed it; every mail has an unsubscribe link that works at once.
- You can see, correct, download or delete what we hold, and you can delete your whole account yourself from the account page.
- Our database lives in Ireland.
3. What we collect, when, and why
3.1 Just visiting the website
3.1.1 Our web host, Cloudflare, receives the technical data any website receives when you visit - your IP address, browser type and the pages requested - to deliver the pages and to protect the site from abuse. We do not keep a log of individual visits.
3.1.2 To count visits we use Cloudflare's aggregate analytics, fed by a small beacon from our own site. It records the page and the kind of action (a page view, a ritual draw, a share) together with Cloudflare's coarse location for your connection (country and city, never a precise position). It sets no cookie, records no IP address, no browser fingerprint and no identifier that could tie a visit to you.
3.1.3 The site's light and dark themes follow the sky where you are. To do that we use the approximate location that comes with your connection to work out local time of day. It is used for the page you asked for and not stored. If you pick a theme yourself, that choice is kept in a cookie (see section 8).
3.1.4 The daily draw, the whispering well and similar features keep what you drew today in your own browser's storage so that the page can show it again. Nothing leaves your device unless you have an account and choose to keep an entry (see 3.2.4).
3.2 Creating an account
3.2.1 To hold a Badge, keep favourites, reserve a session or exhibit, you need an account. We ask for your email address and, optionally, your name. Signing in works with a link or a code we send to that address; we store no password.
3.2.2 We use your email address to sign you in, to send you the messages your account needs (a sign-in link, a purchase confirmation, a reservation, a change to a session you reserved) and to answer you when you write to us. These messages are not marketing and cannot be unsubscribed from while you hold an account.
3.2.3 Your account also holds your theme preference, the exhibitors you have hearted, your Badge and its history, your session reservations and any Badge benefits you have redeemed.
3.2.4 If you choose to keep a daily draw or a note in your account, the text you write is stored with your account for you alone. We do not read it, use it or share it; it is deleted with your account.
3.3 Buying a Badge
3.3.1 Payment is taken by Stripe, our payment provider. Your card details go to Stripe directly and never reach us; we receive and keep a payment reference, the amount and the date, and a record of which Badge you bought and for which event.
3.3.2 If your Badge comes with items sent to you, we ask for a delivery name and address and, for clothing, a size. We pass those, with your email address for delivery updates, to our print and fulfilment partner, Gelato, who produces and ships the items.
3.3.3 The Badge itself is a code tied to your account, shown in the app or on the site, and a short fallback code for when a camera does not cooperate.
3.4 Redeeming a Badge benefit at a stall
3.4.1 This is the one moment your details go to someone else. When you redeem an exhibitor's benefit, you confirm on your own phone that your name and email address may be shared with that exhibitor so that they can stay in touch with you. Nothing is shared until you confirm, and the confirmation is asked for at every redemption.
3.4.2 What is shared: your name, your email address, the exhibitor's benefit as it was when you redeemed it, and the date. The exhibitor then holds those details under their own responsibility (section 5).
3.4.3 You can withdraw your consent for any exhibitor at any time from your account. That marks the redemption as "no further contact" on our side and in the exhibitor's own list of the people who redeemed with them; you can also tell the exhibitor directly. We keep the record of the redemption itself so that a benefit cannot be used twice.
3.5 The newsletter
3.5.1 You join our newsletter by asking for it - on the website, at an event or when creating an account - and confirming from the email we send you (double opt-in). We keep your email address, your name if you gave it, when and where you asked, and when you confirmed.
3.5.2 Every newsletter carries an unsubscribe link. Unsubscribing takes effect immediately and we keep your address on a suppression list only so that we never write to you again by mistake.
3.5.3 Where we write to exhibitors or to people whose details we gathered from public business listings, we say so in the email, and the same unsubscribe rule applies.
3.6 Writing to us
3.6.1 The contact form asks for your name, email address, phone number if you wish, and your message, so that we can reply. It reaches us through our email provider, Resend, and is kept as ordinary correspondence.
3.7 The Treasures shop
3.7.1 For an order we collect your email address, your delivery name and address, and what you ordered. Payment is taken by Stripe as in 3.3.1. Your order and delivery details go to Gelato, who produces the items and ships them, and we keep the order, the delivery estimate and any tracking code so that we can help if something goes wrong.
3.8 Reserving or buying a session ticket
3.8.1 A reservation links your account to the session. For a paid session the payment is handled as in 3.3.1. If a session is moved or cancelled we email everyone who reserved it.
3.9 Exhibitors
3.9.1 When you register as an exhibitor we collect your business name, your name, email address, phone number, what you offer, and the profile you write: description, intro line, photos, website and social links. Your public profile - name, offering, intro line, description, photos and links - is published on the website, in the app and in the hall guide, because that is what a listing is. Your email and phone number are not published.
3.9.2 We keep your bookings, payments (references, amounts, dates), your Badge offer, the sessions you present, the leads that attendees share with you, your loyalty points and any notes we write to run the event. If you opt in to the practitioner directory, your public profile stays listed until you opt out.
3.9.3 We send exhibitors the messages their participation needs - booking and payment confirmations, reminders about a profile or a balance, schedule changes - and, separately, news and invitations to future events, from which you can unsubscribe.
3.10 At an event
3.10.1 We take photographs and video at our events for our records and to promote HOLISTICON, and you may appear in them. Tell a member of our team on the day if you would rather not be photographed, and write to us afterwards if you find yourself in a picture you would like removed from what we control. Exhibitors agree to event photography as part of exhibiting.
3.10.2 An exhibitor scanning your Badge sees only that it is valid and which benefit applies; the details in 3.4.2 are shared only when you confirm.
3.11 The HOLISTICON app
3.11.1 The app is the same account and the same data as the website. It asks for camera access only when you scan a code, and only while you scan. It runs no advertising.
3.11.2 You get the app from Apple's App Store or from Google Play. When you download or update it, Apple or Google collect the data that comes with using their store - your store account, your device, the download itself - as independent controllers under their own privacy notices, not on our instructions. We see only aggregate figures from them, such as how many people installed the app, never who.
3.11.3 Notifications. The app can send you notifications - a reminder before an event, a change to a session you reserved, news we think you will want - but only once you have turned them on in the app or on your phone, and you can turn them off again at any time in the same place. To deliver them, the app registers a device token with Apple's notification service on iPhone and with Google's Firebase Cloud Messaging on Android; we keep that token with your account so that we know which phone to reach. The token identifies the app on your device, not you by name, and it is deleted when you turn notifications off, sign out or delete your account. Apple and Google see the token and the message itself as they deliver it.
4. The legal grounds we rely on
- Performing our contract with you: your account, sign-in messages, Badge purchases, session reservations, shop orders, exhibitor registration, bookings and payments.
- Your consent: the newsletter, notifications from the app, sharing your details with an exhibitor at a redemption, keeping a note in your account, exhibitor news mailings, and anything else we ask you to tick. You can withdraw consent at any time; what was done before you withdrew stays lawful.
- Our legitimate interests, balanced against yours: keeping the site secure and free of abuse, counting visits in aggregate, answering your messages, photographing our events, telling exhibitors what their participation needs, and defending our legal position if we must.
- Legal obligations: keeping payment and booking records for as long as tax and company law require.
5. Who sees your data
5.1 Exhibitors, only as described in 3.4, and only after you confirm. From that moment the exhibitor is responsible for what they received under the General Data Protection Regulation and the Data Protection Act 2018: our terms oblige them to use your details only for the purpose you agreed to, to stop when you ask, never to pass them on, and to delete them when they no longer need them. Complaints about an exhibitor's use of your details can come to us as well as to them.
5.2 The people who help us run HOLISTICON, who process data on our instructions and may not use it for anything else:
- Cloudflare - hosting of the website and the booking system, protection against abuse, the bot check on our forms (Turnstile) and the aggregate visit counts.
- Supabase - the database that holds accounts, Badges, bookings and everything in section 3, hosted in Ireland.
- Stripe - payments. Stripe is a controller of the payment data it collects and has its own privacy notice.
- Resend - delivery of our emails.
- Gelato - production and shipping of Badge items and shop orders.
- Sanity - our editorial content, which holds no visitor data.
- Expo - the service that builds and updates the app, and that hands our notifications to Apple and Google for delivery.
- Google Firebase Cloud Messaging and Apple Push Notification service - delivery of notifications to Android and iPhone (3.11.3).
- Apple and Google - the app stores, as independent controllers of their own store data (3.11.2), not on our instructions.
5.3 Nobody else, except a public authority that has a lawful right to ask, or a professional adviser bound to confidentiality, or a successor who takes over running HOLISTICON, who would take over this page's promises with it.
5.4 We do not sell personal data, rent it, or share it with advertisers, data brokers or social networks.
6. Where your data is kept
6.1 Our database is hosted in Ireland. Our email provider, payment provider and print partner may process data in other countries, including the United States; where they do, the transfer is covered by the European Commission's standard contractual clauses or by an adequacy decision, and by the provider's own EU data protection terms.
7. How long we keep it
- Your account and everything in it: until you delete it. Deleting your account from the account page removes your profile, your Badge, your favourites, your redemptions and your newsletter subscription at once.
- Payment and order records: the reference, amount and date are kept for as long as tax and company law require, currently six years, in our accounts and with our payment provider, even after an account is deleted.
- Newsletter: until you unsubscribe, after which only your address stays on the suppression list.
- Correspondence: for as long as it is useful to the matter it concerns, then deleted.
- Redemption details shared with an exhibitor: on our side, with your account; on the exhibitor's side, under their own responsibility and our terms.
- Exhibitor accounts: while you exhibit with us and for as long as booking and payment records must be kept; write to us to close an exhibitor account.
- Event photographs: for as long as we promote HOLISTICON, unless you ask us to remove one you appear in.
- Notification tokens: until you turn notifications off, sign out or delete your account.
- Aggregate visit counts: they contain nothing about you and are kept as statistics.
8. Cookies and browser storage
8.1 We set only the cookies the site needs to work:
- a session cookie that keeps you signed in, set when you sign in and removed when you sign out or it expires;
- hc-theme, which remembers the theme you chose, if you chose one;
- Cloudflare's cookies for security and for the Turnstile bot check on our forms, which tell humans from bots and are not used to track you across sites.
8.2 Small preferences - today's draw, a dismissed reminder, a collapsed section - are kept in your own browser's storage and never leave your device.
8.3 We use no advertising cookies, no third-party analytics and no social media pixels, so there is no cookie banner: there is nothing to consent to. If that ever changes, we will ask first.
9. Your rights
9.1 Under the GDPR you may ask us, at any time and free of charge:
- for a copy of the personal data we hold about you, and to have it in a form you can take elsewhere;
- to correct anything that is wrong;
- to delete your data (and you can delete your account yourself);
- to restrict or object to how we use it, including any use based on our legitimate interests;
- to withdraw a consent you have given, from your account for exhibitor contact and the newsletter, or by writing to us for anything else.
9.2 Write to be@holisticon.ie from the address on your account and we act within a month, sooner where we can. We may ask you to confirm it is you before releasing anything.
9.3 If you are unhappy with how we handle your data or your request, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, www.dataprotection.ie. We would be grateful for the chance to put things right first.
10. How we protect your data
10.1 Everything travels encrypted between you and us. Sign-in works with one-time links and codes, so there is no password to steal. Card details never touch our systems. Access to the database is limited to the people who run HOLISTICON, and every form on the site carries a bot check. No system is perfectly safe, and if a breach ever affected your data we would tell you and the Data Protection Commission as the law requires.
11. Children
11.1 Our website, app and Badge are for adults. We do not knowingly collect data from anyone under 16, which is the age of digital consent in Ireland, and if we learn that we have, we delete it. Children are welcome at our events in the care of an adult.
12. Changes to this page
12.1 We update this page when what we do changes, and the date at the top always says which version you are reading. If a change matters to you - a new purpose, a new kind of sharing - we tell account holders by email before it takes effect.
13. Contact
13.1 For anything to do with your data: be@holisticon.ie, or by post to Regurk Limited, Venture Hub, 136 Capel Street, D01 T2C9 Dublin.