PRIVACY POLICY
Minimum data, a defined purpose and individual control.
This policy explains how Quórum 12 handles applications, subscriptions, events, payments and portal access data.
Current version: 19 September 2026.
1. Controller and contact
Quórum 12 is responsible for the processing associated with this website. To request access, correction or deletion, write to info@quorum12.com.
2. Data we collect
We may collect name, role, organization, sector, professional email, phone, referral where applicable, interests, communication preferences, registrations, and billing or transaction data. We also retain date, language, consents and minimum technical security data. Quórum 12 does not store card numbers or payment authentication data.
3. Purpose
We use these data to assess membership, administer subscriptions, communicate selected content and events, manage registrations and payments, protect the website and maintain traceability. Data are not added to marketing lists unrelated to Quórum 12.
4. Basis for processing
Processing is based on express consent, requested pre-contractual steps and, where relevant, performance of membership, registration or purchase. Acceptances are recorded against the current version.
5. Providers and transfers
Infrastructure, email, automation, online events and payments may require providers that process data under Quórum 12 instructions and with access limited to what is necessary. Card data will be processed exclusively through a certified payment gateway.
6. Retention
Unsuccessful applications are generally retained for no more than twelve months. Subscription data are retained while the subscription remains active; after cancellation, only minimum evidence is kept. Transaction data are retained for applicable legal and accounting periods.
7. Rights
A person may request information, access, correction, updating or deletion and withdraw consent where applicable by writing to info@quorum12.com. Every communication will include an unsubscribe route.
8. Security
The website applies server-side validation, least privilege, encryption in transit, consent records and audit logs. Administrative access is individual and restricted to authorized persons through strong authentication. No system eliminates all risk, so trade secrets or restricted information must not be submitted.