Privacy Policy
How Tradefairs International, the organizer of AIDC² Expo, Cairo ICT and their co-located events, collects, uses, shares and protects personal data.
Privacy Notice
How Tradefairs International collects, uses, shares and protects personal data across cairoict.com, the Exhibitor, Speaker & Visitor Zone, the Cairo ICT mobile application and at the venue.
Last updated: September 2026. This notice applies to Cairo ICT 2026 and the co-located events PAFIX, AIDC Expo, Connecta and the Innovation Arena.
1. About this notice
This notice explains what happens to personal data when you visit cairoict.com, register for the event, use the Exhibitor, Speaker & Visitor Zone, install the Cairo ICT mobile application, or attend in person. It covers visitors, exhibitors and their stand personnel, speakers, sponsors, contractors, media representatives and anyone who contacts us through the website.
We process personal data in accordance with Egypt's Personal Data Protection Law No. 151 of 2020 and its Executive Regulations. Where you are located in the European Union or the United Kingdom, we also apply the General Data Protection Regulation to the processing described here.
Separate notices apply to the venue operator, to exhibitors who collect your details on their own behalf, and to any third-party platform you reach through a link from ours. Section 18 explains where our responsibility ends.
2. Who we are
Cairo ICT is organised by Tradefairs International, Cairo, Egypt (“we”, “us”). We are the data controller for personal data collected through this website, the registration system, the Exhibitor, Speaker & Visitor Zone, the mobile application and our own operations at the venue.
Privacy questions and requests: [email protected], or the contact form. Emails from the platform are sent from an address that is not monitored, so please use one of these two routes.
3. The personal data we collect
3.1 Data you give us
Registration. Salutation, first and last name, email address, mobile number including country code, country, the event you are registering for, your intended day of attendance, and whether you attend as a trade visitor or a student. Trade visitors also provide job title, job level, organisation and industry sector, and may select the product categories they are interested in. Students provide their educational institution.
Exhibitors and stand personnel. Company details, stand and hall allocation, catalogue entry text, logo and imagery, the names, job titles, emails, mobile numbers and countries of the people you list for badges, and the commercial and financial information needed to issue orders and invoices.
Speakers. Biography, photograph, job title, organisation, session materials and the confirmations you submit through the speaker portal.
Correspondence. Inquiries sent through the website forms, which ask for your name, job title, email address and telephone number so the right desk can answer you, messages sent inside the platform to the organising team or to other participants, feedback and bug reports, and newsletter subscriptions.
Post-Show Report requests. Your name, job title, business email address, mobile number including country code, and your company name where you give it. We use these to send you the report and, because you agree to it on the form, to contact you about exhibiting and attending. The exact sentence you agreed to is stored with your request, so you can ask us what you consented to and when. You can ask us to stop at any time using the details in section 2.
Identity documents. Where you request a visa invitation letter we collect the passport details required to issue it. Section 3.5 explains how these are treated.
3.2 Data created when you use the platform
Your entrance pass and the signed QR code it carries; check-in records showing where and when a pass was scanned by our staff; sessions you bookmark and exhibitors you shortlist; meeting requests you send or receive and the responses to them; messages and their read status; your notification and email preferences; and, for accounts with two-factor authentication enabled, the fact that it is enabled and the recovery state.
3.3 Data collected automatically
IP address, browser and device characteristics, pages viewed and the time spent on them, and the referring page or campaign parameters that brought you to the site. Where the site or application encounters a fault we record diagnostic information so it can be repaired. Before a diagnostic record is stored, email addresses are masked, telephone numbers, access tokens and credentials are removed, and server file paths are shortened, so the record identifies the defect rather than the person.
Registration and login pages are protected by Cloudflare Turnstile, which assesses whether a request comes from a human without presenting a puzzle. This processes technical signals from your browser.
3.4 Data from other sources
Exhibitors and existing participants can invite colleagues and clients to register; when they do, we receive the name and email address they supply in order to send the invitation. We also receive data from partners who register delegations on behalf of their staff, and from publicly available business sources where permitted by law.
3.5 Sensitive data
We do not seek sensitive personal data. Where you volunteer accessibility or dietary requirements so that we can accommodate you, or where a passport is required for a visa invitation letter, we collect it on the basis of your explicit consent, use it only for that purpose, restrict access to the staff handling the request, and delete it once the purpose is complete. If sensitive data has to be processed in an emergency, for example a medical incident on site, we will do so to protect vital interests and will keep the record confined to that incident.
4. How we use it, and our legal basis
Under Egyptian law we must have a lawful basis for each purpose. The bases we rely on are your consent, the performance of an agreement with you, compliance with a legal obligation, and our legitimate interests where these are not overridden by your rights.
Issuing and validating your badge, admitting you to the halls and to sessions, allocating stands, processing orders and invoices, and answering your questions. Basis: performance of our agreement with you, and our legitimate interest in operating the event.
Confirmations, badge and pass emails, password resets, security notices, changes to the event, and replies to what you send us. These are not marketing and cannot be switched off while your account is open. Basis: performance of our agreement with you.
Only through the two routes described in section 5, each of which requires an act by you. Basis: your consent, recorded at the moment you give it.
Event updates, newsletters and information about future editions, with an unsubscribe link in every message and per-topic controls in your account. Basis: your consent, or our legitimate interest in contacting existing business participants about a comparable event.
Access control, incident handling, fraud and abuse prevention, rate limiting, bot protection, and enforcement of the terms of participation. Basis: our legitimate interest in a safe event and a platform that is not abused, and compliance with legal obligations.
Understanding which pages, campaigns and sessions attract interest, and improving the website, the platform and the event. Outside the European Union and European Economic Area, the United Kingdom and Switzerland, analytics and advertising measurement are on by default and you can turn them off at any time; inside those countries they load only if you consent (section 8). Basis: our legitimate interest in measuring and improving our campaigns, which you can object to at any time through Cookie settings; your consent where the law of your country requires it; our legitimate interest for aggregate operational reporting.
Accounting and tax records, responses to lawful requests from authorities, event licensing, and establishing or defending legal claims. Basis: compliance with a legal obligation, and our legitimate interest in defending our rights.
Where we rely on legitimate interests we have considered whether the processing is necessary, whether a less intrusive method would achieve the same result, and what a participant would reasonably expect at a trade exhibition. You may object to processing on this basis at any time, as described in section 15.
5. Sharing your data with exhibitors
Meeting exhibitors is the purpose of the event, so it is worth being precise about how your details reach them. There are exactly two routes, both of which require a deliberate act by you, and neither of which happens automatically because you registered or walked past a stand.
5.1 Badge scanning at the stand
Your entrance pass carries a QR code. When you present it and an exhibitor scans it, we transfer a snapshot of your registration contact details to that exhibitor: your name, job title, organisation, country, email address and mobile number, together with the date of the scan and which member of their team scanned it. This is how an exhibitor records that you visited their stand and how they follow up afterwards.
The scan is the consent. Nothing is shared until the code is presented and read, the pass cannot be read at a distance or without your involvement, and you may decline any scan without giving a reason and without affecting your access to the event.
The record the exhibitor receives is a copy taken at the moment of the scan. It does not update if you later change your profile, and because it is their record of a business contact they may keep and use it after the event under their own privacy notice. From that point the exhibitor is an independent controller of that copy. If you want it corrected or erased, contact the exhibitor; we will help you reach the right person if you ask us.
5.2 Contact requests in the platform and the application
Exhibitors can also reach you without ever meeting you, and this route is deliberately built the other way round: nothing is shared unless you approve it.
An exhibitor whose products match the sectors and interests you selected at registration may be shown that a matching visitor exists, and may send you a message or a meeting request. Until you respond, the exhibitor sees no email address and no telephone number. The message reaches you in your platform inbox and, if you have allowed it, as an email notification from us rather than from them.
If an exhibitor wants your contact details they must send a contact request, which you see as a decision with the exhibitor named and their reason stated. If you approve it, your name, job title, organisation, email address and mobile number are released to that exhibitor and recorded as a lead. If you decline, they are told only that the request was not accepted, and they cannot ask again.
When you approve a request we record the date and time, your IP address and your browser identifier as evidence of the approval. This exists so that both you and the exhibitor can rely on a verifiable record of what you agreed to, and it is never written retrospectively.
You can withdraw an approval at any time from your account. Withdrawal stops any further sharing and marks the lead as withdrawn on the exhibitor's side. It cannot recall data the exhibitor has already exported, which is why the approval screen tells you so before you decide.
5.3 What exhibitors are required to do
Exhibitors accept contractual terms requiring them to use participant data only for follow-up related to the event, to comply with applicable data protection law, to honour opt-out and erasure requests they receive directly, and not to sell or further disclose the data. We are not able to monitor what happens inside an exhibitor's own systems. If an exhibitor contacts you in a way you did not agree to, tell us at [email protected] and we will take it up with them.
6. The Cairo ICT mobile application
The application is an alternative way to use the same account and the same data described above. It does not create a second profile, and signing in to it does not change what is shared with anyone. This section describes what is specific to a mobile device.
6.1 Permissions the application asks for
Used only while a scanner screen is open, so that exhibitors can scan visitor passes at their stand and our staff can check passes at entrances. The camera reads the code and nothing else. Images are not stored, not uploaded and not retained after the frame is decoded.
If you allow them, a device token is stored so we can deliver messages, meeting requests and event alerts. The token identifies the installation, not you personally, and is deleted when you sign out, disable notifications or uninstall. You can withdraw permission in your device settings at any time without affecting anything else in the application.
Used for indoor wayfinding and, in halls equipped with beacons, to measure how visitor traffic moves between zones so that layouts and programming can be improved. This is optional, is requested separately, and the application works fully without it. Traffic analysis is reported to exhibitors and partners only in aggregate form, meaning counts and flows rather than the movements of an identifiable person. Declining has no effect on your admission or your pass.
Your entrance pass, agenda and shortlist are cached on the device so they work where mobile coverage in the halls is poor. This copy lives in the application's private storage and is removed when you sign out or uninstall.
6.2 Deleting the application
Removing the application deletes the cached copy on your device and stops notifications. It does not delete your account or the data held on our systems. To do that, use the rights in section 15.
6.3 App stores
Apple and Google operate the stores the application is distributed through and process download and diagnostic data under their own privacy policies. We do not receive the payment identity behind a store account.
7. At the venue
7.1 Access control scanning
Passes are scanned by our staff at entrances and at some session rooms and restricted areas. This records who entered, where and when. We use it to control admission, to manage capacity and safety, and to understand attendance patterns across the four days. Scanning at an entrance is not sharing with an exhibitor; the two are separate systems and section 5 governs the exhibitor side.
7.2 Photography and filming
Official photographers and video crews record the exhibition, the conference programme and stands for news coverage, the event archive and the promotion of future editions. Attending means you may appear in this material. If you would rather not appear, tell a photographer at the time, or write to [email protected] describing the image, and we will remove it from material we control. We cannot recall images already published by media organisations or by other attendees.
7.3 CCTV
The Egypt International Exhibition Center operates closed-circuit television across the venue for security. Those recordings are made and held by the venue operator as controller under its own policy and retention schedule. We request footage only in connection with a specific security or safety incident.
7.4 What other people collect
Exhibitors, sponsors, media and other attendees may photograph stands, take business cards or use their own scanning applications. Where they collect your data for their own purposes we are not the controller of it and cannot access or delete it. Their own notices apply.
8. Cookies and similar technologies
We group cookies into three categories. Necessary cookies are always on. What happens with the other two depends on where you are:
- Outside the European Union and European Economic Area, the United Kingdom and Switzerland, analytics and marketing cookies are on by default from your first page. A notice at the bottom of the page tells you so and closes by itself after 20 seconds; you can turn either category off from it, or at any time afterwards through Cookie settings.
- Inside those countries, analytics and marketing cookies load only after you accept them. Nothing is pre-selected and the notice stays until you choose.
Your choice is recorded in a cookie named cict_consent which lasts 180 days, with cict_consent_src noting whether it was your choice or the default. Which of the two rules applies is decided from your approximate country, as reported by our network provider, and kept for one day in a cookie named cict_region, which holds only the word strict or standard. If your country cannot be determined, the stricter rule applies.
When you arrive from one of our campaigns, a first-party cookie named cict_src remembers for 90 days the address you landed on, including its campaign and ad-click parameters, the site that sent you and when you arrived, so that if you register we can tell which campaign brought you. A later campaign visit replaces it. It is read only by our own registration form and it is not shared with advertising platforms. Outside the countries listed above it is set whatever your cookie choice. Inside them it is set only once you accept marketing cookies, and deleted if you withdraw that choice; if you register on the page you arrived on, the campaign details in that page's address are used without storing anything.
Your sign-in session, cross-site request protection, bot protection and the record of your cookie choice. The site cannot function without these and they are not used for advertising.
Google Analytics 4 with IP anonymisation enabled: which pages are visited, for how long and from what kind of device. Used to improve the site and to see which content leads to registrations.
Meta Pixel and the LinkedIn Insight Tag, used to measure whether our campaigns on those platforms produce registrations and to build campaign audiences. These providers may set their own cookies and act as independent controllers for that activity under their own policies.
We implement Google Consent Mode: advertising storage, advertising user data and advertising personalisation are granted by default outside the countries listed above and denied inside them until you accept the marketing category, and they follow your choice as soon as you make one. You can change your decision at any time through , which also appears in the footer of every page. Turning analytics and marketing off never restricts your access to the site, the platform or the event.
Our marketing emails contain a single tracking pixel that tells us whether the message was opened and whether links in it were followed. We use this to judge which messages are useful and to stop sending to people who never open them. Blocking remote images in your email client prevents it.
9. Marketing and your choices
Newsletter subscriptions use confirmed opt-in: we send a confirmation link and record nothing as subscribed until it is followed. Every marketing email carries an unsubscribe link that works without signing in. Account holders also have per-topic email preferences, so you can keep service messages while switching off announcements.
Some campaigns are co-branded with sponsors or partners. Where a form is sponsored, that is stated on the form itself before you submit it, and the sponsor becomes an independent controller of what you provide there. We do not sell personal data, and we do not pass your details to a partner for their own marketing without telling you at the point of collection.
10. Who else we share data with
Beyond exhibitors under section 5, personal data is disclosed to the following categories of recipient, each under contract and only to the extent needed:
- Hosting, content delivery, security and object storage providers who run the infrastructure this platform sits on.
- Email delivery providers, for service and marketing messages.
- Analytics and advertising platforms, for the measurement described in section 8.
- Registration, badge production, scanning and on-site operations contractors.
- Professional advisers, auditors, insurers and banks, where necessary.
- Public authorities, where the law requires disclosure or to establish or defend legal claims.
- The venue operator, for access, safety and security at the site.
If the business is reorganised, or all or part of it is sold, personal data may be transferred to the acquiring party or its advisers, subject to the same protections as this notice provides.
We may create aggregated or anonymised statistics, such as visitor numbers by sector or session attendance, and share these with exhibitors, sponsors, partners and the press. Once data is aggregated in this way it no longer identifies you and is not personal data.
11. How we protect your data
11.1 In transit
Every connection to this website, to the Exhibitor, Speaker & Visitor Zone and to the interfaces the mobile application uses is encrypted with HTTPS using Transport Layer Security. Plain unencrypted connections are redirected, and the site sends HTTP Strict Transport Security so that browsers refuse to connect insecurely on later visits. Session cookies are marked secure and restricted to first-party use. Internal transfers between our application servers, the database and object storage are likewise encrypted.
11.2 At rest and in the platform
Passwords are stored only as salted one-way hashes and cannot be read by anyone, including our own staff. Credentials we hold on your behalf, such as connected social accounts, are encrypted before storage. Where an account is terminated for a policy breach, the identifiers retained to enforce that decision are stored as one-way hashes rather than as readable contact details.
Access is restricted by role, so staff see only what their function requires; administrative actions are written to an audit trail; two-factor authentication is available on every account and is recommended for anyone with administrative rights. The platform applies a content security policy, frame and content-type protections, a referrer policy and a permissions policy, and rate limits sign-in attempts, registrations and messaging to frustrate automated abuse.
11.3 Resilience
The database is backed up daily with a rolling retention window, write-ahead logs are archived so the database can be restored to a point in time, and copies are held off the primary machine so that a single failure cannot destroy both the system and its backups. Restores are rehearsed rather than assumed.
11.4 The limit of any such statement
No transmission over the internet and no method of electronic storage is completely secure. We take the measures described here, but we cannot guarantee the security of data while it travels across networks we do not control. Please use a strong and unique password, enable two-factor authentication, and tell us at [email protected] immediately if you believe your account has been accessed by someone else.
12. International transfers
Our servers and storage are located in Europe, and some of our service providers process data in the European Union, the United Kingdom and the United States. Sending your data to another country is therefore inherent in operating the platform.
Where personal data is transferred outside Egypt, we do so only to a country or recipient that provides an adequate level of protection, or under contractual safeguards that impose equivalent obligations on the recipient, or with your explicit consent, or where the transfer is otherwise permitted under the Personal Data Protection Law. Where the General Data Protection Regulation applies to the transfer, we rely on standard contractual clauses. You may request further information about the safeguards used for a particular transfer.
13. How long we keep it
Kept for the event cycle and a reasonable period afterwards so that we can run the editions you may wish to attend and answer questions about your participation.
Up to 24 months from the last contact.
Until you unsubscribe. After that we keep the minimum needed to make sure we do not contact you again.
Our copy is kept for the event cycle. The exhibitor's copy is subject to their retention policy, not ours.
For the period required by Egyptian tax and commercial law.
Daily database backups are kept on a rolling 14-day window on the server, with copies held off site. Data you delete disappears from the live system at once and ages out of backups as that window turns.
Kept only as long as needed to diagnose and fix the fault, and redacted as described in section 3.3.
When a retention period ends, records are deleted or irreversibly anonymised. Where an account is deleted at your request or terminated for a breach of the terms of participation, the account and its pass are removed and only what is necessary to evidence the decision is retained.
14. Matchmaking, profiling and automated decisions
The platform suggests connections. Exhibitors describe the sectors and seniority they want to meet; visitors select the categories they are interested in; the platform compares the two and proposes matches to both sides. Organising staff may also curate suggestions by hand.
This is profiling in the sense the law uses, so we state its limits plainly. It affects which suggestions appear on a screen and nothing else. It does not decide whether you are admitted, what you pay, or what you are entitled to. No decision producing a legal effect or a similarly significant effect on you is made by automated means. A suggestion never discloses your contact details; that requires the consent described in section 5.2.
15. Your rights
Under the Personal Data Protection Law you have the right to:
- Be told the legal basis and purpose for which your data is collected, which is what this notice does.
- Access the personal data we hold about you.
- Receive a copy in a readable, structured format.
- Have inaccurate or incomplete data corrected, completed or updated.
- Have your data erased where it is no longer needed for the purpose it was collected for.
- Withdraw a consent you previously gave, at any time, without affecting processing already carried out.
- Object to processing carried out on the basis of our legitimate interests.
Where the General Data Protection Regulation applies to you, it also gives you the right to restrict processing and the right to data portability.
Much of this you can do yourself: your account lets you correct your details, change your email preferences, review and withdraw contact approvals, and see the meeting requests and messages attached to you. For anything else, write to [email protected] from your registered address, or use the contact form. We may need to verify your identity before acting, so that nobody can obtain or erase your data by pretending to be you.
We respond within 30 days. If a request is refused or restricted we will tell you why. If you are not satisfied you may complain to the Egyptian Personal Data Protection Center, and, where the General Data Protection Regulation applies, to the supervisory authority in your country.
16. Personal data breaches
If personal data we hold is subject to a breach, we will notify the Egyptian Personal Data Protection Center within 72 hours of becoming aware of it, and immediately where national security is implicated. Where the breach is likely to cause you significant harm we will also notify you directly within three working days, describing what happened, what it means for you and what we are doing about it. We keep an internal record of breaches and of the reasoning behind each notification decision.
17. Children
The event and this platform are intended for business professionals and for students attending in an educational capacity. They are not directed at children. We do not knowingly collect personal data from anyone under 16 without the consent of a parent or guardian, and we will delete such data if we become aware of it. Student registrations are expected to be made by attendees old enough to attend a trade exhibition unaccompanied, or by their institution on their behalf.
18. Third-party sites and third-party collection
This website links to exhibitor websites, partner platforms, social networks and media coverage. We do not control those sites and are not responsible for their content or their privacy practices. Read their notices before providing personal data to them.
Similarly, where an exhibitor or another attendee collects your data at the event using their own systems, they are the controller of it. Section 5 sets out the boundary between what we share and what they collect.
19. Changes to this notice
We review this notice as the platform, the event and the law develop. Changes are published on this page with a revised date, and significant changes are highlighted on the website and, where we hold your address and the change materially affects you, notified by email. Please check the date at the top before relying on a copy you saved earlier.
This notice replaces all previous privacy and cookie policies published on cairoict.com. For questions about it, write to [email protected] or use the contact form.

