Privacy policy
CRU International Limited and/or the relevant CRU group company acting as controller for the applicable activity (together, “CRU”, “we”, “us” and “our”) are committed to respecting and protecting the privacy of individuals and to complying with the UK GDPR, the Data Protection Act 2018, PECR and all other applicable data protection laws and regulations.
If you have any questions or concerns about our use of your personal information please contact us using the contact details provided elsewhere in this Privacy Policy.
This Privacy Policy explains who we are, how we collect, use, secure and share personal information when you visit our websites, enquire about or buy our products and/or services, receive communications from us, register for or attend our events or webinars, visit our offices or media pages, or otherwise interact with us. It also explains your rights and how you can exercise them.
This policy does not describe our processing of personal data relating to people who apply for jobs with us. Neither does this Policy describe our processing of personal data relating to our employees. Our processing for employment-related purposes is set out in a separate Policy that we make available to our employees.
CRU Group controller structure
For the purposes of this Privacy Policy, different CRU group companies act as controller for different processing activities. For example, CRU International Limited is responsible for personal data processed on CRUgroup.com, on our central sales and marketing platforms, and for invoicing and related commercial administration.
CRU Publishing Limited is responsible for personal data processed on our events websites, Oxford abstracts, the event registration system, and related event administration activities.
Personal data collected through CRU Publishing Limited systems may be shared with, transferred to, or accessed by CRU International Limited’s sales and marketing platforms, for central administration, customer relationship management, marketing, reporting and related business purposes. Each CRU entity will process personal data only for the purposes set out in this Privacy Policy and in accordance with applicable data protection law.
This structure reflects the fact that CRU International Limited and CRU Publishing Limited are responsible for different systems and processing activities, and that some data flows between those systems for central administration and marketing purposes.
Data Protection Officer
We have appointed a Data Protection Officer (DPO). If you wish to contact our DPO you can do so via: [email protected]
What is personal information?
Personal information is anything that enables you to be identified or identifiable. Personal information is also called “personal data”. We collectively refer to handling, collecting, protecting, storing or otherwise using your personal information as ‘processing’.
Collecting (obtaining) your Personal Information
We collect personal information directly from you in many cases, for example when you:
- enter into contractual negotiations with us
- ask us to provide a service to you or on your behalf
- search and browse our websites for content
- subscribe to or order newsletters and/or publications
- complete surveys that we use for research purposes
- register for and/or attend our events
- submit a paper for consideration at one of our events
- submit CVs or work history information
- contact us for information
- fill in forms on our websites
- provide us with business cards or other contact information
We may also obtain your personal information indirectly, such as from:
- websites
- social media
- lead generation providers
The personal information we collect about you
We may collect and otherwise process different kinds of personal data about you which we have grouped together as follows:
- Contact Data includes postal and email address and telephone numbers.
- Identity Data includes names and similar identifiers, title, date of birth and gender.
- Financial Data includes bank account and payment card details.
- Marketing and Communications Data includes your preferences in receiving marketing from us and our partners and your communication preferences.
- Transaction Data includes details about payments to and from you and other details of products, goods and services you have purchased from us.
- Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our website and services.
- Usage Data includes information about how you use our products, services and website. Where you use our event networking app or platform, we may collect usage information such as logins, profile views, searches, connection requests, session activity and feature use. We use this information to operate the platform, support event delivery, analyse engagement, improve functionality and troubleshoot technical issues. We do not monitor or record private chats, private messages or private video calls between participants unless we notify you otherwise and have a lawful basis to do so.
- Cookies and Similar Technologies Data includes information collected through cookies and similar technologies, such as IP address, device identifiers, browser type, pages visited, time spent on pages, and other usage and technical information collected when you use our websites.
Lawful Bases (legal grounds) for Processing Personal Information
Our legal basis for collecting and using your personal information depends on the personal information concerned, the context in which we collect it and the purpose for which we use it.
We will normally collect personal data from you on one or more of the following lawful bases:
- Consent: We may process your personal information where you have given us clear and informed consent to do so. You have the right to withdraw your consent at any time where we rely on consent.
- Contract: We may process your personal information where we need to deliver a contractual service to you, or because you have asked us to do something before entering into a contract, for example to provide a quote.
- Legal obligation: We may process your personal information when we need to comply with a legal obligation.
- Legitimate interest: We may process your personal information where we, or another organisation, have a legitimate interest in doing so and where those interests are not overridden by your rights and interests.
Purpose(s) for Processing Personal Information
We do not sell personal information to third parties.
We have set out below a description of the ways we use your personal information, together with the relevant lawful basis or bases for each purpose.
Please note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground(s) we are relying on to process your personal data where more than one ground has been set out in the table below.
| Purpose / Activity | Type of data | Lawful basis for processing |
| 1. To register a new client/customer | Contact Data, Identity Data | Contract |
| 2. To process and deliver an order or request | Contact Data, Identity Data, Marketing and Communications Data | Contract |
| 3. To manage our customer and business relationships | Contact Data, Identity Data, Marketing and Communications Data | Contract; Legal obligation; Legitimate interests (to keep our records updated and to understand how customers, business contacts and partners use our products/services) |
| 4. To provide marketing materials and communications | Contact Data, Identity Data, Usage Data, Marketing and Communications Data | Soft opt-in where applicable; Consent where required; Legitimate interests where permitted by law |
| 5. To administer and manage our website | Contact Data, Identity Data, Technical Data | Legitimate interests (for running our business, provision of administration and IT services, network security, fraud prevention and, where relevant, business reorganisation or group restructuring) |
| 6. To register you for and manage your attendance at an event, including providing event services such as delegate badges, access control, networking platforms and event materials | Contact Data, Identity Data, Marketing and Communications Data, Financial Data where applicable | Contract |
| 7. To administer the event and provide event services | Contact Data, Identity Data, Technical Data, Usage Data, Marketing and Communications Data | Contract; Legitimate interests where appropriate |
| 8. To manage Special Category Data which includes dietary requirements, accessibility needs, and any other information we ask you to provide that reveals health or other special category information. | Contact Data, Identity Data, Special Category Data | Consent or another applicable condition under Article 9 of the UK GDPR where required |
| 9. To share limited delegate information with other attendees, sponsors, exhibitors and event partners. Where we share this information, we will explain this at the point of collection and provide any required opt-out or consent mechanism | Contact Data, Identity Data, Marketing and Communications Data | Legitimate interests; Consent where required; PECR-compliant marketing rules where applicable |
| 10. To operate, monitor and improve the event networking app/platform | Technical Data, Usage Data, Identity Data, Marketing and Communications Data | Contract; Legitimate interests |
| 11. To take photographs and film the event for event, editorial and promotional purposes. Images or recordings may include attendees in general, background or incidental shots, and may be used on our websites, social media platforms and other promotional materials | Identity Data, Image/recording data, Contact Data where needed for administration | Legitimate interests; Consent where required |
| 12. Where permitted by law, including under PECR soft opt-in rules, we may send you marketing about CRU products, services, publications and events that we consider relevant to you | Contact Data, Identity Data, Marketing and Communications Data, Usage Data where relevant | Soft opt-in where applicable; Consent where required; Legitimate interests where permitted by law |
| 13. To transfer and share data between CRU group companies for central administration, customer relationship management, event administration, invoicing, reporting and marketing purposes | Contact Data, Identity Data, Marketing and Communications Data, Technical Data, Usage Data, Financial Data where relevant | Contract; Legitimate interests; Legal obligation; Consent where required |
| 14. For the safety and security of our staff, visitors and others | Contact Data, Identity Data | Legitimate interests (to protect and keep safe our staff, visitors and other individuals for whom we have responsibility) |
| 15. To comply with our legal obligations | Contact Data, Identity Data, Marketing and Communications Data, Technical Data, Usage Data | Legal obligation |
The lawful basis we rely on may vary depending on the context in which we collect and use your personal information. For CRU Events, please also read the CRU Events section of this Privacy Policy.
Using your Personal Information for Marketing Purposes
We may use your personal information to send you marketing communications about CRU products, services, publications and events, including other CRU products and services that we consider may be relevant to you.
We will only use your personal information for marketing purposes in accordance with applicable legal requirements, including PECR where marketing is sent by email or other electronic means.
If you wish to unsubscribe from receiving marketing materials or messages, you should look for and follow the instructions provided in the relevant communications to you. Alternatively, you can at any time contact us to request that such communications cease by emailing [email protected].
If you choose to unsubscribe from any or all mailings, we may retain information sufficient to identify you so that we can honour and respect your request.
If you fail to provide personal information
Where we need to collect personal information by law, or under the terms of a contract we have with you and you fail to provide that information when requested, we may not be able to perform the contract we have or are trying to enter into with you or provide you with products/services you have requested.
Cookies
We use a cookies tool on our website to manage consent for optional cookies. Strictly necessary cookies, including cookies used for functionality, security and accessibility, are set automatically and do not require your consent. For information about the cookies and any other similar technologies we use, please see our cookies policy.
Sharing your Personal Information
We may share your personal information with other companies in the CRU group where this is necessary for the purposes described in this Privacy Policy and where we have a lawful basis to do so.
We may transfer, share or disclose the personal data we collect from you to third parties, and where applicable their subcontractors, subsidiaries or affiliates, for:
- the purposes for which the information has been submitted
- the purposes listed above under “Purpose(s) for Processing Personal Information”
- the administration and maintenance of our websites
- the promotion and administration of our events and/or
- other internal or administrative purposes.
Intra-group sharing of personal data
Personal data collected by CRU Publishing Limited through our events websites, Oxford abstracts system and event registration system may be shared with CRU International Limited and processed in our central sales and marketing platforms for purposes such as central administration, customer relationship management, event and commercial follow-up, marketing, reporting and related business operations.
Personal data collected by CRU International Limited through CRUgroup.com or our central sales and marketing systems may similarly be shared with CRU Publishing Limited where this is necessary for event administration, invoicing, customer support or related business purposes.
Each CRU group company will only process personal data for the purposes described in this Privacy Policy and where it has a lawful basis under applicable data protection law.
Third-Party Service Providers
We may also transfer, share or disclose personal data to third-party service providers that are necessary for the fulfilment and operation of our business, for example providers of identity management, website hosting and management, data analysis, data backup, security, badging services, mailing services, hotels and other venues in connection with conferences and events that we host or co-host, and storage services.
The third-party providers may use their own subcontractors that have access to personal data. It is our policy to use only third-party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by us, and to flow those obligations down to their subcontractors.
Other disclosures:
We may also disclose personal information to third parties under the following circumstances:
- When explicitly requested by you
- When required to deliver publications or reference materials as requested by you
- When required to facilitate events hosted by us or a third party
- For regulatory compliance purposes; and/or
- As otherwise set out in this privacy statement.
We may also disclose your personal information to law enforcement, other government agencies and to professional bodies and other third parties, as required by/or in accordance with applicable law or regulation. This includes disclosures outside the country where you are located.
In some circumstances we are legally obliged to share information. For example, under a court order.
It is our policy to only share your personal information with third parties that are legally or contractually bound to protect your personal information to the same standards as we are, and that will flow those same standards to their subcontractors.
We may also share your information in the event of the non-payment of a debt. As a result, we may share personal data with the litigation and recovery specialists we instruct in order for them to identify assets and undertake recovery action.
In any scenario, we’ll satisfy ourselves that we have a lawful basis on which to share your personal information.
We will not sell your personal information to any third party.
Data processors
We share personal information with third parties that act as data processors to provide elements of our service by processing personal information on our instructions.
Where we use data processors, we have contracts in place with them to ensure that they cannot do anything with personal information we have shared with them unless we have instructed them to do it. They will hold it securely and retain it for the period we instruct them to.
These data processors commit to processing information in compliance with applicable data protection laws and to implementing appropriate security measures to protect your information.
Transfers of your personal information to outside the UK
Your personal information may be transferred (sent to or accessed from) outside the UK. Any such transfer will be only:
- To you; or
- To a recipient located in a country which provides an adequate level of protection for your personal information, for example a country in the European Union (EU), OR European Economic Area (EEA); or
- To a recipient under a contractual agreement which satisfies UK legal requirements for the transfer of personal information, to ensure that appropriate safeguards are in place to protect your personal information in accordance with UK levels of data protection; or
- To a recipient under the UK-US Data Bridge; or
- When your personal information has first been anonymised
The countries/areas to which we routinely transfer personal data to* are:
EU/EEA: To a recipient located in a country which provides an adequate level of protection for your personal information.
USA: To a recipient certified under UK- US Data Bridge, which provides an adequate level of protection for your personal information; or to a recipient not certified under UK- US Data Bridge, in which case the transfer is made using an International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses.
India: To a recipient using an International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses.
*This does not mean that your personal data will be transferred to any of these countries. For more information about transfers of your personal information to outside the UK please contact us.
Retention (Storage) of Personal Information
We will retain your personal information only for long as we need it, given the purposes for which it was collected, or as required to do so by law.
To determine the appropriate retention period for your personal information, we consider the amount, nature, and sensitivity of it, the potential risk of harm from unauthorised use or disclosure of it, the purposes for which we process it and whether we can achieve those purposes through other means, as well as applicable legal requirements.
If you would like more information about this, please ask us for a copy of our retention policy
Your data protection rights
Under data protection law, you have rights we need to make you aware of. The rights available to you depend on our reason for processing your information.
- Your right of access: You have the right to ask us for copies of your personal information. This right always applies. There are some exemptions, which means you may not always receive all the information we process.
- Your right to rectification: You have the right to ask us to rectify information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete. This right always applies.
- Your right to erasure: You have the right to ask us to erase your personal information in certain circumstances.
- Your right to restriction of processing: You have the right to ask us to restrict the processing of your information in certain circumstances.
- Your right to object to processing: You have the right to object to processing where we process your information on the basis of our legitimate interests or for direct marketing purposes, and you have an absolute right to object to direct marketing at any time.
- Your right to data portability: This only applies to information you have given us. You have the right to ask us to transfer information you gave us from one organisation to another, or to give it to you, in certain circumstances. This right only applies where we are processing information based on your consent or in connection with a contract and the processing is automated.
You also have the right to complain to the Information Commissioner’s Office (ICO) if you are unhappy with how we have handled your personal information.
You are not required to pay any charge for exercising your rights. We normally have one month to respond to you, although this may be extended in some circumstances where permitted by law.
If you wish to exercise any of your rights, please contact us at [email protected]
Security
We use appropriate technical and organisational measures to protect the personal data that we collect and process about you. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal data. Please be aware that, we cannot guarantee the security of all personal information transmitted to or by us.
Only authorised persons are provided access to your personal data that we have collected, and all such individuals are bound by a duty of confidence.
Social Media
- X
- Bluesky
We use these social media platforms to communicate and promote our services. If you message or interact with us on these platforms we may process your personal information to respond to you.
Automated Decision Making
We will not use your personal information for automated decision making or profiling
Visiting our premises
When you visit our premises you may provide your name and other personal information for security and safety reasons.
Events
If you register for or attend one of our events, we may collect and use your personal data for the following purposes:
- to process your registration and manage your attendance;
- to communicate with you about the event, including confirmations, practical arrangements and updates;
- to provide event services such as delegate badges, access control, networking platforms and event materials;
- to manage dietary requirements, accessibility requirements and other special arrangements you ask us to provide;
- to share limited delegate information with other attendees, sponsors, exhibitors or event partners where this is explained at the point of collection and, where permitted, by applicable law;
- to take photographs and film the event for event, editorial and promotional purposes;
and
- to send you marketing communications about CRU products, services, publications and events, including other CRU products and services that we consider may be relevant to you.
We rely on different lawful bases depending on the purpose of the processing. These may include:
- contract, where processing is necessary to register you for, and manage, your attendance at, the event;
- legitimate interests, where we use your data for event administration, limited event publicity or certain marketing purposes and have assessed that our interests are not overridden by your rights and interests;
- consent, where we rely on your consent, including for certain special category data such as dietary or accessibility information where consent is required; and
- PECR-compliant marketing rules, including the soft opt-in where applicable, for marketing by electronic means.
Where you register for an event, we will give you the opportunity to opt out of receiving marketing communications at that stage. In addition, every marketing email we send will include a clear and simple unsubscribe link or other easy opt-out mechanism. If you opt out, we will retain only the information necessary to ensure that we respect and record your preference.
Links to other websites
Where we provide links to websites of other organisations, this Privacy Policy does not cover how that organisation processes personal information. We encourage you to read the privacy policies on the other websites you visit.
Our contact details
If you have any questions or complaints about this Privacy Policy or the way your personal information is processed by us, or would like to exercise one of your rights set out above, please contact us by one of the following means:
- Email: [email protected]
- Form: https://www.crugroup.com/contact-us/
- Post: 1st Floor, MidCity Place, 71 High Holborn, London, WC1V 6EA, UK
Data Protection Complaints
We work to high standards when it comes to processing your personal information. If you have any queries or concerns about our handling of your personal information, please contact us directly via [email protected]
We will confirm receipt of your complaint or concern and will investigate it without undue delay. We will respond within a reasonable time and keep you informed of next steps where appropriate.
Should you remain dissatisfied following our response, you can make a complaint about the way we process your personal information to the Information Commissioner’s Office (ICO), the UK data protection regulator. Further information is available on the ICO website.
Updating
We may update this Privacy Policy from time to time. The ‘last updated’ date shows when it was last revised. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
This Privacy Policy was last updated on 01.07.2026.