Last updated: 31 July 2026
The ESMA International Network (“ESMA”, “we”, “us”) is committed to protecting your privacy. This policy explains what personal data we collect through this website and the ESMA International Network mobile app, why we collect it, who we share it with, and the rights you have over it. It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and — because our membership spans the EU — the EU General Data Protection Regulation.
Who we are
The ESMA International Network is a non-profit membership organisation, formed in 1976, that brings together manufacturers, distributors and industry partners in the consumer goods sector. We are run by our members, on behalf of our members.
For the purposes of the GDPR, the data controller is the ESMA International Network, at:
1 Shields Court,
High Wycombe,
HP10 8JU,
United Kingdom
If you have any question about this policy or about how we handle your data, contact us at olga.mulcahy@esma.org.
The information we collect
We only collect what we need in order to run the membership network. Depending on how you use the site, that may include:
- Membership applications — your name, job title, email address, telephone number, company name, company address and country, company type and website.
- Member accounts — your login email address and a securely hashed password, plus any additional user logins you create for colleagues at your company.
- Your company profile — the description, logo, cover image, brands, product categories, trade sectors, addresses, website and social media links you choose to publish, together with the names, roles, email addresses, telephone numbers and photographs of the points of contact you list.
- Events — the events you register interest in or attend. For conventions we may also collect the details you give us on the attendee form, such as the names of colleagues attending, meal choices, dietary requirements or allergies, and accommodation preferences.
- Enquiries — the content of messages you send us through the contact form or by email.
- Profile engagement statistics — when someone clicks a contact detail, map or link on your member profile we record that a click happened, so that we can show you engagement figures in your dashboard. We record the type of click, the date and the visitor’s IP address.
- Mobile app — if you allow notifications, we store the push token that identifies your device so that we can deliver them. If you enable biometric sign-in, your credentials are held in your device’s own secure keychain and are never transmitted to us.
- Technical data — standard web server logs, including IP address, browser type and the pages requested, kept for security and troubleshooting.
We do not knowingly collect special categories of personal data. The one exception is dietary and allergy information given voluntarily on a convention attendee form, which may reveal information about your health. We collect it only so that we can cater safely at that event, we use it for nothing else, and we delete it once the event has passed.
Why we use it, and our legal basis
- To provide the membership service — managing your account, publishing your company profile in the member directory, handling event registrations and giving you access to members’ resources. Legal basis: performance of a contract with you.
- To communicate with you — responding to enquiries and sending service messages about your account, your event registrations or changes to the platform. Legal basis: performance of a contract, or our legitimate interest in running the network.
- To send you network news and event announcements — by email newsletter or, if you have allowed them, by push notification. Legal basis: your consent, which you can withdraw at any time.
- To show you engagement statistics on your own company profile. Legal basis: our legitimate interest in providing a useful membership benefit.
- To keep the platform secure — preventing spam, abuse and unauthorised access. Legal basis: our legitimate interest in protecting the service and its members.
- To meet legal obligations — such as accounting and membership records. Legal basis: compliance with a legal obligation.
Who can see your information
Your company profile in the member directory is deliberately public: the company name, description, logo, categories, country, published contact details and points of contact can be seen by anyone visiting the site. You control what appears there and can edit or remove it at any time from your dashboard. Some content — the members’ document library, certain event details and some articles — is restricted to signed-in members.
We do not sell your personal data, and we do not share it for anyone else’s marketing.
We do share limited data with the service providers who help us run the platform, and who act on our instructions only:
- our website and application hosting provider;
- Google, for reCAPTCHA spam protection on our public forms, and for Firebase Cloud Messaging, which delivers push notifications to the mobile app;
- our email delivery provider, for service emails and newsletters.
We may also disclose information where we are required to do so by law.
Transfers outside the European Economic Area
Some of our service providers, including Google, may process data outside the EEA. Where that happens we rely on the safeguards permitted by the GDPR, such as the European Commission’s standard contractual clauses or an adequacy decision.
How long we keep it
- Member accounts and company profiles — for as long as your membership is active, and for up to 12 months afterwards in case you rejoin. You can ask us to delete them sooner.
- Membership applications that are not accepted — 12 months.
- Event and attendee details — until the event has taken place, plus up to 12 months for our records. Dietary and allergy information is deleted once the event is over.
- Enquiries — up to 24 months.
- Profile engagement statistics — up to 24 months.
- Server logs — up to 12 months.
- Accounting records — for the period required by law.
Cookies
A cookie is a small file placed on your device by a website. We use as few as possible, and we do not use advertising or tracking cookies.
The cookies this website sets are strictly necessary for it to work:
- esma-session — keeps you signed in and remembers your session as you move between pages. Expires when your session ends.
- XSRF-TOKEN — a security token that protects our forms against cross-site request forgery. Expires when your session ends.
- A cookie preference cookie — remembers your choice so that we do not ask again.
In addition, when a page containing a protected form loads, Google reCAPTCHA may set its own cookies in order to tell humans from bots. These are set by Google and are governed by the Google Privacy Policy.
We do not currently run Google Analytics, or any other third-party analytics or advertising service, on this website. If that changes we will update this policy and ask for your consent first.
You can block or delete cookies in your browser settings, but the site will not work properly without the strictly necessary ones.
Your rights
Under the GDPR you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected — you can edit most of it yourself in your dashboard;
- ask us to erase your data;
- ask us to restrict how we use it;
- receive your data in a portable format;
- object to processing that we carry out on the basis of legitimate interests;
- withdraw your consent at any time, where we rely on consent.
To exercise any of these, contact olga.mulcahy@esma.org. We will respond within one month.
You can delete your account, and the personal data attached to it, at any time. See Delete your account for how to do that — in the app, on the website or by email.
If you are unhappy with how we have handled your data you can complain to the UK supervisory authority, the Information Commissioner’s Office, at ico.org.uk.
Keeping your data safe
We use appropriate technical and organisational measures to protect your information, including encryption in transit (HTTPS), hashed passwords, access controls that limit who can see member data, and regular updates to the platform. No online service can be completely secure, but we take these obligations seriously and will notify you and the Information Commissioner’s Office of any breach where we are required to do so.
Children
This is a business membership platform and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last changed. Where a change materially affects how we use your data, we will tell you directly.