Skip to main content
🛡️

Privacy Policy

Transparent and complete information on how your personal data is processed, in accordance with Articles 12, 13 and 14 of the GDPR.

Last updated: September 30, 2026

About this policy

This policy describes how REALITIM EURL, publisher of the Ultiplace website (hereinafter “we”, “Ultiplace”), collects and processes your personal data when you use our services (website, virtual trade shows, exhibitor and organizer spaces, public API, email communications).

We are committed to strictly complying with the General Data Protection Regulation (GDPR, EU 2016/679) and the amended French Act No. 78-17 of January 6, 1978 (Data Protection Act).

Data controller

The data controller is:

REALITIM EURL

34 rue Joncours, 44100 Nantes, France

RCS Nantes 838 763 902

General contact: contact@realitim.com

Data protection contact: dpo@realitim.com

When Ultiplace processes data on behalf of an organizer or an exhibitor (for example visitors of a trade show), Ultiplace acts as a processor within the meaning of Article 28 of the GDPR. In that case, the organizer or the exhibitor is the data controller. The terms of this relationship are set out in our data processing agreement (DPA) (available in French).

Data we collect

Depending on how you use the platform, we may collect the following categories of data:

Identity and contact
  • Last name, first name, email, city
  • Profile photo (optional)
  • Phone number (optional, on business card)
  • Postal address (optional)
Professional data
  • Company, job title, industry
  • Professional bio, experience
  • LinkedIn profile (if OAuth sign-in is used)
Published content (UGC)
  • Exhibitor listings, virtual booths, descriptions
  • Posts, comments, recommendations, follows
  • Messages exchanged in chat or private messaging
  • Uploaded documents and media
Billing data (professional users)
  • Email, name, billing address
  • Stripe customer ID
  • Last digits of the card (never the full number)
  • Payment and invoice history
Technical and browsing data
  • IP address, browser type, operating system
  • Pages viewed, session duration
  • Session identifiers, authentication tokens
  • Approximate geolocation (if allowed)
Calendar data (if you connect Google Calendar or Outlook)
  • Email address and name of the connected Google / Microsoft account
  • Busy time slots of your calendar (without event titles or details)
  • Appointment events created by Ultiplace in your calendar
  • Encrypted access tokens (see the “Google data and Limited Use” section)
Trade show usage data
  • Trade shows visited, booths viewed, documents downloaded
  • Conferences attended, viewing time
  • Business cards exchanged, contacts added
  • AI interactions in booth chats (AI Pro offer)

We never collect sensitive data within the meaning of Article 9 of the GDPR (racial origin, political opinions, religion, health data, sexual orientation…) unless you choose to voluntarily publish it in public content (for example a post). We strongly advise against publishing such information.

Purposes and legal bases

Each processing activity relies on an identified legal basis:

Provide and manage your account
Legal basis: Performance of a contract (Art. 6.1.b GDPR)
Examples: Registration, authentication, access to personalized spaces, support
Enable use of the platform
Legal basis: Performance of a contract (Art. 6.1.b GDPR)
Examples: Creation of trade shows and booths, networking, messaging, live conferences
Process subscriptions and invoice
Legal basis: Performance of a contract + legal obligation (Art. 6.1.b and 6.1.c GDPR)
Examples: Stripe payments, invoice generation, accounting retention (10 years)
Send transactional emails
Legal basis: Performance of a contract (Art. 6.1.b GDPR)
Examples: Confirmations, reminders, alerts, invoices, security notifications
Improve the service and measure audience
Legal basis: Consent (Art. 6.1.a GDPR) — analytics cookies
Examples: Google Analytics, Vercel Analytics, Microsoft Clarity
Marketing communications
Legal basis: Legitimate interest or consent, depending on the case (Art. 6.1.f / 6.1.a GDPR)
Examples: Newsletter, marketing content (you can unsubscribe at any time)
Moderate content and ensure security
Legal basis: Legal obligation + legitimate interest (Art. 6.1.c and 6.1.f GDPR)
Examples: Abuse prevention, reports, DSA compliance, fraud prevention
Calendar synchronization and appointment booking (optional)
Legal basis: Consent (Art. 6.1.a GDPR) — you voluntarily connect your calendar
Examples: Display of available time slots, double-booking prevention, creation of appointments with a Google Meet link
Exhibitor AI assistant (AI Pro offer, optional)
Legal basis: Performance of the AI Pro contract (Art. 6.1.b GDPR)
Examples: Automatic response generation, FAQ, content processing via OpenAI

Recipients and processors

Your data is accessible to our authorized teams (support, technical, sales, moderation) and may be shared with technical processors selected for their level of security and GDPR compliance. The full list is kept up to date below.

List last updated on May 19, 2026. In the event of an addition, professional customers are notified at least 30 days before it goes live.

Hosting & infrastructure

Vercel Inc.
📍 United States (compute hosted in the EU — Paris cdg1)
Purpose: Website hosting, API execution, technical logs
Data: IP addresses, request logs, HTTP headers
Retention: 30 days (logs)
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →DPA →
Google Firebase (Google Cloud)
📍 Ireland (EU) / United States
Purpose: Firestore database, file storage, Cloud Functions, Realtime Database
Data: All account data, profiles, published content, messages, media
Retention: Until account deletion
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →DPA →

Authentication

Google Firebase Authentication
📍 Ireland (EU) / United States
Purpose: Account creation, email/password authentication, Google OAuth
Data: Email, hashed password identifier, OAuth identifiers, session tokens
Retention: Until account deletion
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →
LinkedIn (Microsoft)
📍 Ireland (EU) / United States
Purpose: Sign-in with LinkedIn (OAuth), optional import of professional information
Data: LinkedIn identifier, name, profile photo, job title (with consent)
Retention: Until the account is unlinked or deleted
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →

Payment & billing

Stripe Payments Europe Ltd.
📍 Ireland (EU) — transfers to Stripe Inc. (USA) under safeguards
Purpose: Subscription payments, invoicing, automatic VAT calculation (Stripe Tax)
Data: Email, name, address, customer ID, amounts, last digits of card, invoices
Retention: 10 years (accounting obligation)
Legal basis: Performance of a contract and legal obligation (Article 6.1.b and 6.1.c GDPR)
🌍 Covered by SCCsPrivacy policy →DPA →

Communication & emails

Twilio SendGrid
📍 Ireland (EU) / United States
Purpose: Sending transactional emails (confirmation, notifications, invoices, unsubscribe)
Data: Email, first name, last name, email content, open / click status
Retention: 30 days (sending logs)
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →

Search

Algolia SAS
📍 France
Purpose: Unified search engine (trade shows, exhibitors, profiles, public content)
Data: Indexed public data (titles, descriptions, slugs, industries, cities)
Retention: As long as the item is published
Legal basis: Legitimate interest (Article 6.1.f GDPR) — public visibility
🌍 Fully processed in the EUPrivacy policy →

Audience measurement

Vercel Analytics
📍 United States
Purpose: Anonymous audience measurement, Web Vitals performance
Data: Pages viewed, session duration, technical performance (no user identifier)
Retention: 30 days
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →
Google Analytics 4
📍 Ireland (EU) / United States
Purpose: Traffic statistics and browsing behavior
Data: Pages viewed, traffic source, pseudonymous GA identifier
Retention: 14 months
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →
Microsoft Clarity
📍 Ireland (EU) / United States
Purpose: Heatmaps and anonymized session recordings to improve the experience
Data: Mouse/keyboard interactions, scrolling, page paths (no direct identifier)
Retention: 13 months
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →

Marketing & advertising

Google Ads
📍 Ireland (EU) / United States
Purpose: Advertising conversion tracking, remarketing
Data: Advertising identifier, conversions, inferred interests
Retention: 13 months
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →
Meta Facebook Pixel
📍 Ireland (EU) / United States
Purpose: Conversion tracking and custom audiences (Facebook / Instagram)
Data: Advertising identifier, conversion events
Retention: 13 months
Legal basis: Consent (Article 6.1.a GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →

Video & streaming

Amazon Web Services (IVS, S3, CloudWatch, MediaConvert)
📍 Luxembourg (EU) — Paris eu-west-3 data centers
Purpose: Live streaming of conferences, storage of video replays, logs and metrics
Data: Conference video / audio streams, replays, technical metadata
Retention: According to the trade show organizer's configuration
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Fully processed in the EUPrivacy policy →DPA →
VideoSDK Live, Inc.
📍 United States / India
Purpose: 1-to-1 video calls in exhibitor booths (video chat)
Data: Real-time audio / video streams (not recorded by default), session identifier
Retention: No storage by default (real-time transit)
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by SCCsPrivacy policy →

Artificial intelligence

OpenAI Ireland Ltd.
📍 Ireland (EU) — processing may take place in the United States
Purpose: Exhibitor AI assistant (AI Pro offer): response generation, moderation, embeddings, FAQ
Data: Content of messages exchanged with the assistant, descriptions and documents provided by the exhibitor
Retention: 30 days (OpenAI logs) — content is not used to train models (standard API)
Legal basis: Performance of a contract when the exhibitor subscribes to the AI Pro offer (Article 6.1.b GDPR)
🌍 Covered by SCCsPrivacy policy →DPA →

Monitoring & support

Sentry (Functional Software, Inc.)
📍 United States
Purpose: Detection of technical errors to ensure service availability
Data: JavaScript stack trace, user identifier (UID), URL, browser version
Retention: 90 days
Legal basis: Legitimate interest (Article 6.1.f GDPR) — security and stability
🌍 Covered by SCCsPrivacy policy →

Geolocation

Google Maps Platform (Places API)
📍 Ireland (EU) / United States
Purpose: Address and city autocomplete in forms
Data: Location input, IP address
Retention: According to Google's policy
Legal basis: Performance of a contract (Article 6.1.b GDPR)
🌍 Covered by the EU-US DPFPrivacy policy →
Nominatim (OpenStreetMap Foundation)
📍 Germany (EU)
Purpose: Reverse geocoding (GPS coordinates → city) for visitor profiles
Data: Approximate GPS coordinates, IP address of the server request
Retention: According to the OSMF policy
Legal basis: Consent (Article 6.1.a GDPR) — the user authorizes geolocation
🌍 Fully processed in the EUPrivacy policy →

Apart from this list, your data is neither sold, rented, nor disclosed to third parties for commercial purposes. Disclosure to a public authority only takes place upon judicial request or legal obligation.

Transfers outside the European Union

When your data is transferred to a third country (in particular the United States for some processors), these transfers are strictly governed by one of the mechanisms provided for in Chapter V of the GDPR.

Data Privacy Framework (DPF)
For DPF-certified processors (Google, Microsoft, Meta, Vercel…)
Standard Contractual Clauses (SCCs)
For processors not certified under the DPF (Stripe Inc., OpenAI, Sentry…)

The mechanism applied to each processor is specified in section 5 above, as a colored label.

Retention periods

We apply the following retention periods:

User account
Until you request deletion or after 3 years of total inactivity.
3 years max after inactivity
Accounting and tax data
Invoices, proof of payment (legal obligation).
10 years
Trade show visit sessions
Inactive sessions are purged automatically.
7 days
Trade show visit history
For the organizer's statistics.
30 days
Email delivery logs
Deliverability status (SendGrid).
30 days
Cookie preferences
Cookie ultiplace_consent.
12 months
Analytics data (GA4, Clarity)
Pseudonymized, for audience measurement purposes.
13-14 months
Technical error logs (Sentry)
Diagnostics and security.
90 days
AI conversations (AI Pro offer)
OpenAI logs kept in accordance with their standard policy. Not used for training.
30 days (OpenAI)

Once these periods have elapsed, the data is deleted or anonymized. Some data may be archived for longer to meet our legal obligations or civil limitation periods (notably 5 years as proof of performance of the contract).

Data security

We implement appropriate technical and organizational measures to protect your data against loss, alteration or unauthorized access (Article 32 GDPR):

Encryption
HTTPS everywhere, TLS 1.2+, encryption at rest with our hosting providers.
Strong authentication
Hashed passwords, Google and LinkedIn OAuth, signed session tokens.
Access segregation
Granular Firestore security rules, limited and logged admin access.
Continuous monitoring
Error detection (Sentry), real-time alerts.
Backups
Automatic daily backups performed by our hosting providers (Firebase, AWS).
Incident procedure
In the event of a breach likely to result in a risk to your rights, notification to the CNIL within 72 hours and information of the individuals concerned.

Processing using artificial intelligence

Ultiplace uses artificial intelligence models for certain features, mainly the exhibitor AI assistant (AI Pro offer, optional).

When you chat with an exhibitor who has enabled the AI Pro offer, all or part of the conversation may be sent to OpenAI (the exhibitor's processor) to generate an automatic response.

You keep the right at any time to request human intervention (Article 22 GDPR) by contacting the exhibitor's team directly. Conversations are not used to train OpenAI models (standard API settings).

Other AI features may be used internally to enrich the directory (generated trade show descriptions) without processing personal data of identified users.

Google data: data obtained through Google APIs (Google Calendar) is never transferred to any AI / machine learning model or service (including OpenAI), and is never used to create, train or improve generalized AI models. See the next section.

Google data (Google Calendar) and “Limited Use” requirements

If you choose to connect your Google Calendar account to Ultiplace(an optional feature that you can enable and disable at any time from your settings), Ultiplace accesses some of your Google data through Google APIs. This section describes precisely what is accessed, how it is used, stored and shared.

Data we access
  • Google account identity (email address, name, identifier) — to identify the connected account
  • “Busy / free” time slots of your calendar (Free/Busy API) — without the title, description or attendees of your personal events
  • Creation, modification and deletion of the appointment events booked through Ultiplace (with a Google Meet link)
Permissions (scopes) requested: calendar.events, calendar.freebusy, openid, email, profile.
How we use it
Solely to provide the user-facing appointment booking feature: display your actually available time slots, prevent double bookings, and create, move or cancel the appointments made on the platform. These data are not used for any other purpose (advertising, profiling, resale, commercial analysis).
Storage and security
We only keep the OAuth access and refresh tokens, encrypted, as well as the email and identifier of the connected account, in our Firestore database (EU region). The content of your calendar is not copied or stored: busy slots are queried on demand and only cached temporarily in memory.
Sharing and transfer
We do not sell, rent or transfer your Google data to third parties, except: (a) the details of an appointment (date, time, video conference link) are visible to the attendees of that appointment; (b) to our technical hosting providers acting as processors (section 5); (c) where required by law; (d) with your explicit consent.
Artificial intelligence
Google data is neither used to develop, improve or train generalized AI / ML models, nor transferred to any third-party AI service.
Human access
Our teams do not read your Google data, except with your explicit consent for a support request, for security reasons (for example an abuse investigation), to comply with the law, or when the data is aggregated and anonymized for internal operations.
Deletion and revocation
You can disconnect your calendar at any time from your settings (Ultiplace then revokes the token with Google and deletes the connection data), or remove access from your Google account (myaccount.google.com/permissions). You can also request deletion by writing to dpo@realitim.com.

Google user data & Limited Use compliance statement

Ultiplace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

In particular, Ultiplace does not use, transfer, or sell Google user data (raw, aggregated, or derived) to develop, improve, or train generalized artificial intelligence and/or machine learning models, and does not transfer such data to any third-party AI/ML service. Google user data is used solely to provide and improve user-facing appointment scheduling features (availability display, double-booking prevention, creation of appointments with Google Meet), is not used for advertising, and is not sold to data brokers or other third parties. Humans do not read this data unless we have your explicit consent, it is necessary for security purposes, it is required to comply with applicable law, or the data is aggregated and anonymized for internal operations.

You can disconnect your calendar at any time from your account settings or revoke access at myaccount.google.com/permissions. Contact: dpo@realitim.com.

Your rights over your data

As a data subject, you have the following rights:

Right of access
Obtain a copy of your data (Art. 15 GDPR)
Right to rectification
Correct inaccurate data (Art. 16 GDPR)
Right to erasure
Request deletion (Art. 17 GDPR)
Right to restriction
Restrict certain processing (Art. 18 GDPR)
Right to data portability
Receive your data in a reusable format (Art. 20 GDPR)
Right to object
Object to processing (Art. 21 GDPR)
Automated decisions
Request human intervention (Art. 22 GDPR)
Complaint to the CNIL
Lodge a complaint with the supervisory authority (Art. 77 GDPR)

To exercise your rights, use our dedicated form (available in French, directly accessible from your personal space) or write to dpo@realitim.com.

We undertake to reply within one month of receiving your request, which may be extended by two months in case of complexity.

Minors

Ultiplace is a platform intended for professionals and is not designed for minors under 15. If you notice that an account belongs to a minor without parental authorization, please contact us immediately at dpo@realitim.com so that we can delete it.

Changes to this policy

We may update this policy to reflect technical, legal or operational changes. The date of the last update is shown at the top of the page. In the event of a substantial change, we will inform you by email or through a visible notice on the site before it takes effect. You may request the version history at any time by writing to us.

Contact and complaints

A question about your data?

Our team replies quickly.

You may also lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris).