Atlas Digital Summit ("we", "us", "our") is a private, invite-only executive conference on web infrastructure security and sustainability in the evolving world of artificial intelligence and machine learning, held in Reykjavik, Iceland. This Privacy Policy explains what personal data we collect through atlasdigitalsummit.com and our event operations, why we collect it, who we share it with, and the choices you have.
We are the data controller for the personal data described here. If you have any question about this policy, contact jason@atlasdigitalsummit.com.
2. Information We Collect
Information you provide
Invite requests & newsletter signup
Name and email address
Company and job title (where requested)
Industry sector (e.g. Hosting, Datacenter, Security, AI Architect)
VIP ticket registration (including partner pages such as CloudLinux, Monarx, WebPros, WHT and others)
Optional profile photo, which you may crop before upload
Your choice of whether to be featured publicly on our website
Optional indication of interest in sponsoring
The partner or campaign page the registration came from
A unique ticket reference and QR code are generated for each confirmed registration and emailed to you. The QR code encodes only your ticket reference — it does not contain your personal details.
Contact form
Name, company, company type / industry, email address and your message
The details you type into the visa invitation letter tool are used in your browser only to produce a PDF. They are not transmitted to or stored on our servers.
Information collected automatically
Page analytics (cookieless): page path, referring source, browser user-agent string, device category (desktop/mobile/tablet) and a random session identifier that lives only in the memory of the open browser tab. We do not store your IP address in analytics and we do not build cross-site profiles. See section 12.
Abuse prevention: IP addresses are processed temporarily for rate limiting on forms and admin login, and are deleted automatically (rate-limit records within 2 hours).
Engagement events: anonymous counts of sponsorship tier clicks, sponsor "Visit Website" clicks and sponsorship prospectus downloads. These record the item clicked and a timestamp, not who clicked it.
Failed registrations: if a VIP registration errors out, we log the submitted name, email, company and error reason so we can follow up and complete your registration.
Email engagement: our email provider records deliveries, opens, clicks, bounces and unsubscribes for messages we send you.
Server logs: our hosting and backend providers keep short-lived operational logs (including IP address) for security and troubleshooting.
3. How We Use Your Information
Review invite requests and determine fit for a private, C-level event
Issue VIP tickets with personalised QR codes and send confirmation emails
Send event updates, agenda changes and newsletters you have signed up for
Respond to contact and sponsorship inquiries
Arrange catering based on dietary preferences and order merchandise in the right size
Display attendee and speaker information publicly where you have opted in (section 5)
Understand which pages and sponsors generate interest, in aggregate
Prevent spam, abuse and fraudulent registrations, and secure administrative access
Meet legal, accounting and event-safety obligations
We do not sell your personal data, and we do not share it with advertisers.
4. Lawful Basis for Processing
Where the GDPR (as applied in the EEA, Iceland and the UK) applies, we rely on:
Contract: processing registrations, issuing tickets and delivering the event you signed up for.
Consent: newsletter subscriptions, optional profile photos and public homepage/attendee features. You may withdraw consent at any time.
Legitimate interests: running a private invite-only event, curating the attendee list, aggregate cookieless analytics, sponsor engagement counts, and protecting our site from abuse.
Legal obligation: where retention or disclosure is required by law.
5. Information Shown Publicly
Some details are published on this website. This only happens as described below:
Featured attendees: your name, job title, company and profile photo appear on our homepage only if you selected "feature me" during registration. You can ask us to remove you at any time and we will do so promptly.
Speakers, table leads and panellists: name, photo, role, company, biography and the sessions they lead are published as part of the event programme, on the basis of their participation agreement.
Company logos: we display logos of attending and sponsoring companies. Logos are company identifiers, not personal data.
Publicly displayed information is indexable by search engines and AI crawlers. Private areas — including VIP registration records, the visa letter tool and the Atlas Manager admin area — are excluded from indexing and blocked in robots.txt.
6. Third-Party Services
We use a small set of processors and services to run the site and the event:
Managed cloud infrastructure — our hosting, database, file storage and serverless application functions. Stores registration, newsletter, analytics and admin data.
Resend — transactional and newsletter email delivery, including open, click, bounce and unsubscribe tracking.
Google reCAPTCHA — spam and bot protection on our forms. Google may collect your IP address and interaction data; see Google's Privacy Policy.
Open-Meteo — supplies live Reykjavik weather on our Travel & Logistics page. Your browser requests forecast data for Reykjavik only; no personal data or your own location is sent.
We disclose personal data to these providers only as needed to deliver the service, and we require them to protect it. We may also disclose data where required by law, or to protect our rights and the safety of attendees.
7. International Transfers
Atlas Digital Summit takes place in Iceland, and our attendees are international. Some of our processors operate in the United States and other countries outside the EEA. Where personal data is transferred outside the EEA/UK, we rely on the processor's Standard Contractual Clauses or an equivalent approved safeguard.
8. Data Storage & Security
All data is stored on managed cloud infrastructure with encryption at rest, and all traffic is encrypted in transit over HTTPS/TLS.
Row-Level Security policies restrict access at the database level; registration tables are not publicly readable.
Administrative access to Atlas Manager uses passwordless one-time passcodes (OTP) sent by email, plus short-lived session tokens presented on each request. Admin sessions are rate limited (3 OTP requests per hour).
Uploaded profile photos are validated to image types only and can only be written by our server-side functions, never directly by visitors.
Security controls fail closed: if a rate-limit or authorisation check cannot be completed, the request is denied.
No system is perfectly secure. If a breach affecting your personal data occurs, we will notify affected individuals and the relevant supervisory authority as required by law.
9. Data Retention
Registration & VIP ticket data: kept through the event and for up to 24 months afterwards for verification, feedback and notice of the following edition, unless you ask us to delete it sooner.
Newsletter subscriptions: kept until you unsubscribe or ask for deletion.
Profile photos: deleted on request, and removed from public display immediately when you opt out.
Rate-limit records: deleted automatically within 2 hours.
Analytics records: retained in aggregate for up to 24 months; they contain no IP address or directly identifying data.
Failed-registration records: deleted once resolved, or within 12 months.
Contact & sponsorship inquiries: kept for up to 24 months for follow-up.
10. Your Rights
Depending on where you live, you may have the right to:
Access: obtain a copy of the personal data we hold about you.
Rectification: correct inaccurate or incomplete details.
Erasure: ask us to delete your data ("right to be forgotten").
Restriction & objection: limit or object to certain processing, including processing based on legitimate interests.
Withdraw consent: unsubscribe from emails or opt out of public display at any time.
Portability: receive your data in a structured, machine-readable format.
Complain: lodge a complaint with your local data protection authority — in Iceland, the Data Protection Authority (Persónuvernd).
The quickest way to exercise any of these rights is our privacy request form — you'll get a reference number and an emailed confirmation immediately. You can also email jason@atlasdigitalsummit.com. We respond within 30 days, and we may ask you to verify your identity first. Every newsletter also contains a one-click unsubscribe link.
11. Cookies & Local Storage
We keep this deliberately minimal. We use no advertising cookies, no third-party tracking cookies and no cross-site profiling.
Consent preference: your choice on our cookie banner is saved in your browser's local storage so we don't ask again. It never leaves your device.
Admin session: when an administrator signs in to Atlas Manager, a short-lived session token is stored in their browser and sent with each admin request. This applies to our team only, not to visitors.
Google reCAPTCHA: Google may set its own cookies when a protected form loads. This is required for spam protection and is governed by Google's privacy policy.
Analytics: uses no cookie and no persistent storage at all — see section 12.
Consent is granular. Strictly necessary items above keep the site working and cannot be switched off; analytics is optional and off unless you allow it. You can change your selection or withdraw consent entirely at any time using (also linked in the footer of every page). Withdrawing consent stops analytics collection immediately and clears the stored preference.
12. Analytics
We run our own first-party, cookieless analytics instead of a third-party analytics platform. For each page view we record the page path, the referring source (for example "linkedin.com" or "direct"), a device category, the browser user-agent string, and a random session identifier held only in the memory of your open tab — it is discarded when the tab closes and cannot be used to recognise you on a later visit or on any other site.
We do not store IP addresses with analytics, we do not fingerprint devices, and we do not share analytics data with any third party. Automated traffic (bots, crawlers, link previewers and security scanners) is filtered out both in the browser and on the server before anything is recorded. Our hosting platform also produces its own aggregate traffic statistics from server-side request logs.
13. Children's Privacy
Atlas Digital Summit is a professional, invite-only event for senior industry executives. Our website and services are not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or for legal, operational or regulatory reasons. Material changes will be posted on this page with a revised "Last updated" date, and where required we will notify you directly.
15. Contact Information
Questions about this policy, or a data request? Contact us: