Privacy Policy
Last updated: October 21, 2025
PRINTER'S ACADEMY ON LINE LLC. d/b/a dinnerHQ ("dinnerHQ")
This Privacy Policy is provided by PRINTER'S ACADEMY ON LINE LLC., a Florida limited liability company located at 3870 NE 167th St, North Miami Beach, FL 33160, doing business as dinnerHQ ("dinnerHQ").
0. Overview
This Privacy Policy describes the types of personal information dinnerHQ collects from website visitors and people who use our Services, how we use and share that information, and the choices you have. Please read it carefully to understand our practices and how we will treat your information.
Capitalized terms not defined in this Policy have the meaning given in our Terms of Use.
1. Who we are
dinnerHQ operates curated B2B networking dinners in the United States.
Postal address: 3870 NE 167th St, North Miami Beach, Florida 33160, USA
Email: [email protected]
We take privacy seriously and align our practices with leading U.S. and international frameworks, including the GDPR and California CCPA/CPRA.
2. Definitions
“Services” means our public website at www.dinnerhq.com (the “Site”) and the curated B2B networking dinners and related features we operate (for example, ticketing and attendee rosters).
“Personal Information” means information about an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to that person’s identity.
“Third‑Party Products/Service Providers” are products or services not owned or controlled by dinnerHQ (for example, Luma for ticketing or Stripe for payments). Their own privacy notices apply to their handling of information.
3. Scope of this Policy
This Policy explains how we collect, use, share and protect personal information when you:
- browse www.dinnerhq.com (the “Site”);
- purchase or manage a ticket via Luma or other ticketing widgets embedded in the Site;
- interact with our emails, SMS messages or social‑media ads; or
- attend a dinnerHQ event;
- network with other professional attendees via dinner‑specific rosters or post‑event follow‑up messages.
This Policy does not cover third‑party websites or services that link to or from us. Their own privacy statements apply.
Controller details: The controller responsible for the processing of personal information is dinnerHQ. You can reach us at the address and email listed above.
4. Acceptance of this Policy
By accessing or using the Services, you agree to this Privacy Policy. If you do not agree, do not use the Services. You can contact us at [email protected] with questions about this Policy.
5. Updates to this Policy
We may update this Policy from time to time. When we do, we will post the revised version on this page and update the effective date at the top. Where required, we will provide additional notice (for example, by email or banner). Your continued use after an update constitutes acceptance of the revised Policy.
5a. Legal Basis for Processing Your Data
Under GDPR and similar privacy laws, we must have a legal basis to process your personal information. We rely on the following bases depending on the processing activity:
| Processing Activity | Legal Basis | Explanation |
|---|---|---|
| Account creation, event registration | Contract Performance (GDPR Art. 6(1)(b)) | Necessary to provide services you requested |
| Professional profile enrichment and event curation | Legitimate Interest / Contract Performance where needed | Used to verify professional context, curate relevant dinners, recommend events, and assess event fit |
| Profile matching, embeddings, and sponsor relevance analysis | Legitimate Interest (GDPR Art. 6(1)(f)) | Used internally to compare professional relevance and improve recommendations; raw embeddings and similarity scores are not shared with sponsors |
| Transactional emails (confirmations, reminders) | Contract Performance | Event confirmations, updates, attendance logistics |
| Sharing professional data with event sponsors | Legitimate Interest (GDPR Art. 6(1)(f)) | Necessary to operate free B2B networking events via sponsor funding |
| Marketing emails/SMS (optional) | Consent (GDPR Art. 6(1)(a)) | You can opt out anytime |
| Security logging, fraud prevention | Legitimate Interest | Protecting our systems and users |
| Tax, accounting, legal compliance | Legal Obligation (GDPR Art. 6(1)(c)) | Required by law |
Legitimate Interest Assessment: Sponsor Data Sharing
Our Legitimate Interest:
dinnerHQ provides free B2B networking events by securing corporate sponsorships. Sponsors fund events in exchange for access to target professional audiences. Without sponsor data access, we cannot secure funding, and events would require $200-400 ticket prices, excluding many professionals. This model enables us to provide free event access to all attendees, creating valuable networking opportunities that would otherwise be financially inaccessible.
Necessity:
Sponsor data sharing is necessary for our business model. We cannot offer free events without it. Alternative funding models would require paid tickets, significantly reducing accessibility for emerging professionals and small business owners.
Balancing Test (Your Rights vs. Our Business Needs):
- Limited professional context — We may share human-readable professional context such as business email, company, job title, industry, seniority, role focus, relevant professional background, attendance history, and professional profile links, but not raw provider payloads, profile embeddings, similarity scores, or internal matching logic
- Reasonable expectations — B2B networking events inherently involve professional contact sharing. Attendees reasonably expect sponsors to have access for networking purposes
- User benefit — Free access to valuable B2B networking events (average value $250/event) that would otherwise require ticket purchases, plus networking opportunities that create professional connections
- Transparency — Full disclosure in Terms of Use and event pages before registration
- Safeguards — Sponsors bound by anti-spam rules (CAN-SPAM, GDPR, CASL); cannot resell, broker, or relicense attendee data to third parties without consent
- User control — You can choose not to attend if you disagree; you can opt out of sponsor emails individually
Conclusion: Legitimate Interest is the appropriate legal basis. User consent is not required for this processing activity.
Your Right to Object: You can object to sponsor data sharing under GDPR Article 21 by:
- Not attending dinnerHQ events
- Emailing [email protected] to opt out of future sharing
- Contacting sponsors directly to opt out of their communications
We will honor objections for future processing (we cannot retroactively revoke past data sharing).
6. Information we collect
We collect information from the following sources: (a) directly from you; (b) automatically from your device and browser; (c) from event partners and service providers that help us operate dinners (for example, Luma, Stripe); (d) from publicly available professional and company sources; and (e) from third-party professional or business data providers, where allowed by law and subject to our vendor review and data protection requirements.
| Category | Examples | How we collect it |
|---|---|---|
| Identifiers | Name, business email, phone, postal address, professional profile URL, company & job title | Forms you complete, ticket checkout (Luma), voluntary profile updates, business‑card exchange |
| Company information | Company name and domain, company size/headcount, industry, location, growth signals, and other company attributes | Contact forms, RSVP flows, public company sources, company websites, business directories, and third-party professional/business data providers |
| Professional profile and enrichment data | Current role, work history, education, seniority, skills, role focus, professional interests, derived affiliations, and similar business profile context | Profile forms and surveys, event interactions, publicly available professional/company sources, and third-party professional/business data providers |
| Derived matching and recommendation data | Profile segments, event-fit signals, sponsor relevance indicators, recommendation scores, and profile embeddings or other machine-readable representations | Generated by dinnerHQ from information you provide, event activity, public professional/company sources, and third-party professional/business data providers |
| Payment references | Last 4 digits of card, card type, Stripe payment ID, purchase metadata (amount, currency, timestamp) | Processed by Stripe; dinnerHQ receives only tokens & receipts, never full card numbers |
| Event‑preference data | Dietary notes, allergy-related meal notes, accessibility requests, vertical/industry interests, seating requests | Ticket checkout or post‑purchase survey |
| Marketing & engagement data | Email opens/clicks, SMS interactions, ad-campaign membership, cold outreach responses, unsubscribe status | Managed via email, CRM, analytics, advertising, and outbound communication providers |
| Device & usage data | IP address, browser type, pages visited, time on page, referring URL | Cookies, web beacons, Google Analytics, Vercel edge functions |
| Customer‑support records | Messages, attachments, call notes | Zendesk or direct email |
We do not intentionally collect sensitive data such as social-security numbers, government identifiers, or detailed health records. We may collect limited dietary, allergy-related, accessibility, or safety information if you choose to provide it for event logistics.
We also do not seek or require information about legally protected characteristics (for example race, color, religion, national origin, disability, or medical details). Please do not provide such information.
We do not intentionally use professional enrichment to infer sensitive characteristics such as race, religion, health status, political opinions, union membership, sexual orientation, or similar protected traits. If a public or third-party source includes information that appears sensitive or irrelevant to professional event curation, we aim to exclude it from matching and sponsor-facing summaries.
6.1 Data Sharing with Sponsors (All Events)
IMPORTANT: By registering for any dinnerHQ event (sponsored or non-sponsored), you acknowledge that dinnerHQ will share your professional contact information with:
- Current event sponsors (if the event you attend is sponsored)
- Potential future sponsors (for business development and sponsorship opportunities)
What we share:
- Full name
- Business email address
- Company name
- Job title
- Industry/vertical
- Relevant human-readable professional context, such as seniority, role focus, company attributes, professional background, education, or derived business affiliations relevant to the event or sponsor audience
- Professional profile URL (if provided)
- Event attendance history (which events you attended)
What we do not share: We do not share raw third-party provider payloads, underlying enrichment records, profile embeddings, similarity scores, internal recommendation scores, or proprietary matching logic with sponsors. Sponsor-facing context is limited to human-readable professional information intended to support relevant networking and sponsor follow-up.
How sponsors use your data:
Sponsors may contact you for:
- Business development outreach
- Product/service information
- Event invitations
- Professional profile connection requests
Your control:
- You can opt out of future sponsor sharing by emailing [email protected]
- Opt-out does not apply retroactively (sponsors who already received your data keep it)
- To avoid sponsor data sharing entirely, do not register for dinnerHQ events
Visa Gift Card Incentives (Select Events):
Some events offer Visa gift card incentives ($60-$120) for attendance. These are:
- Conditional — dinnerHQ reserves ultimate discretion to deny for any reason
- Not payment for data — You share professional data with sponsors for networking purposes, regardless of gift card availability
- Attendance rewards — Incentive for participating, not compensation or reimbursement
For full gift card terms, see our Terms of Use Section 2.4.
7. How we use your information
We process personal information to:
- Provide our service — issue tickets, confirm restaurant logistics, handle seating and send pre‑/post‑event communications.
- Process payments via Stripe and detect fraud.
- Curate and recommend events — use professional profile data, company attributes, derived affiliations, and matching signals to recommend dinners, assess event fit or eligibility, form relevant attendee groups, and personalize outreach.
- Evaluate sponsor relevance — use professional and company context to understand whether an event audience is relevant to current or prospective sponsors, without sharing raw enrichment payloads, embeddings, or similarity scores.
- Operate, secure and improve the Site and any future mobile app.
- Facilitate networking — share limited professional contact details (name, company, role, professional profile link) with other confirmed attendees so you can follow up after the dinner.
- Send marketing emails/SMS you opt into; you may unsubscribe at any time.
- Comply with law — e.g. tax, accounting and lawful requests.
- Defend our rights and prevent misuse of our services.
We rely on one or more of the following legal bases, as applicable: (i) performance of a contract (ticket purchase), (ii) our legitimate interests in running and marketing the business, (iii) your consent (for optional newsletters/texts), and (iv) compliance with legal obligations.
Legal basis for processing (GDPR/UK GDPR)
- Contract — to issue tickets, manage attendance and provide customer support.
- Legitimate interests — to operate, secure and improve our Services and communicate relevant offers; we balance these interests against your rights.
- Consent — for optional marketing emails/SMS and certain cookies; you may withdraw at any time.
- Legal obligation — to comply with tax, accounting and law‑enforcement requests.
Automated profiling and human review. We may use automated tools to help classify professional profiles, generate embeddings or other machine-readable representations, recommend events, assess event fit, evaluate sponsor relevance, and support eligibility or waitlist decisions. These tools support dinnerHQ operations and are not intended to make decisions with legal or similarly significant effects without meaningful human involvement. If you believe an automated recommendation, eligibility decision, or profile classification is inaccurate or unfair, you may contact us to request human review.
8. Cookies & similar technologies
We use first‑ and third‑party cookies, pixel tags and local‑storage objects to recognise your browser, analyse traffic, remember preferences and measure ad performance. You can control cookies through your browser settings. Blocking all cookies may degrade Site functionality.
Key third‑party cookies/pixels:
- Google Analytics 4 — site analytics (IP anonymised)
- PostHog — user behavior analytics and feature flags
- Meta (Facebook) & LinkedIn Insight Tags — conversion tracking & retargeting
- Stripe — checkout session, fraud prevention and payment performance
- Loops — email campaign analytics
Third‑party use of cookies. Some content and features are provided by service providers who may set their own cookies and similar technologies. These providers may associate cookie data with information they have about you from other services and use it for advertising or measurement.
Website Analytics (Google). We use Google Analytics to understand aggregate Site usage. Learn more in Google’s privacy policy and control collection using Google’s opt‑out add‑on.
Google Ads/AdWords. We may use Google Ads remarketing to reach people who previously visited our Site. Manage your preferences at Google Ads Settings or visit the Network Advertising Initiative opt‑out page.
Meta (Facebook) Ads. You can control ad personalization from Meta at Facebook Ad Preferences.
LinkedIn Ads. Manage LinkedIn ad settings at LinkedIn Advertising Preferences.
9. Who we share information with
We disclose information only as needed to run the service:
| Type | Recipient | Purpose |
|---|---|---|
| Database | Neon DB (US data centers only) | PostgreSQL database hosting |
| Cloud hosting & CDN | Vercel Inc., Cloudflare Inc. | Web hosting, edge functions, media delivery |
| Ticketing & event management | Luma Inc. | Ticket sales, attendee roster, check‑in |
| Payment processing | Stripe, Inc. | Secure card processing, fraud screening |
| Email & newsletter | Postmark, EmailBison, Loops, Clay Inc., HubSpot Inc., Arcanine Technologies Inc., and similar communication/CRM providers | Transactional emails, sponsor and attendee communications, outbound campaigns, CRM, and reply management |
| Professional/business data enrichment | LeadMagic, RapidAPI, Apify, CRM enrichment tools, and other third-party professional/business data providers or API marketplaces | Email verification, professional profile enrichment, company attribute enrichment, event curation, and sponsor relevance analysis |
| AI, embeddings & automation | OpenRouter, OpenAI-compatible model providers, and similar AI infrastructure providers | Profile embeddings, professional matching, recommendation assistance, content generation, and operational automation |
| SMS & telephony | Cloudtalk Inc., Twilio, Inc. | Event‑reminder SMS |
| Rewards fulfillment | Tremendous and similar reward fulfillment providers | Gift card or attendance incentive fulfillment where offered |
| Advertising pixels | Meta Platforms, LinkedIn Corp., Google Ads | Ad measurement & retargeting |
| Customer support | Zendesk Inc. | Ticketing and chat |
| Analytics | PostHog (user analytics), Google Analytics (advertising), Meta (advertising), Vercel Inc. (performance metrics) | User behavior analytics, ad performance, site performance |
| Error monitoring | Sentry | Application error monitoring, debugging, and reliability |
| CI/CD & code hosting | GitHub, Inc. | Version control, CI/CD workflows |
| Event sponsors | Corporate sponsors of dinnerHQ events (varies by event) | Professional networking, business development outreach, sponsorship ROI assessment |
| Other attendees | Fellow participants in the same dinner | Professional networking & follow‑up |
We require each service provider to keep information confidential and to use it only for the purpose we disclosed it.
Event sponsors: We may share professional contact information and limited human-readable professional context (for example, name, business email, company, job title, industry, seniority, role focus, relevant company attributes, professional background, attendance history, and profile URL if provided) with event sponsors to enable professional networking, business development, and sponsorship ROI assessment. This data sharing applies to all dinnerHQ events (both sponsored and non-sponsored community dinners). We do not share raw third-party provider payloads, embeddings, similarity scores, or internal matching logic with sponsors. Sponsors must comply with anti-spam laws (CAN-SPAM, GDPR, CASL) and cannot resell, broker, or relicense your data to third parties without your consent. See Section 6.1 for full details.
Payment processing: We use Stripe to process payments and do not store full credit‑card numbers. Stripe handles card data in accordance with its own privacy policy and PCI‑DSS requirements. We receive tokens and limited payment metadata (e.g., last four digits, card brand, amount).
We may also share information (i) to comply with law or valid legal process, (ii) to enforce our Terms of Use, (iii) in connection with a business transfer such as a merger or sale, or (iv) with your consent.
Sponsor Disclosures Are Not Data Broker Activity
dinnerHQ does not provide attendee lists to data brokers. We disclose professional information to event sponsors and prospective sponsors for the sponsor-funded networking, business development, and sponsorship purposes described in this Policy and our Terms of Use. Sponsors are contractually restricted from reselling attendee data or using it outside the disclosed sponsorship purposes. Where applicable law requires an opt-out for targeted advertising or other regulated disclosure, we will provide and honor the opt-out rights required by that law for future disclosures.
Categories of personal information disclosed for a business purpose (last 12 months)
| Category | Recipient types | Purpose |
|---|---|---|
| Identifiers | Hosting/platform, email & newsletter providers, ticketing, analytics, advertising platforms | Operate Services, communications, analytics, ad measurement |
| Company & professional info | Ticketing, email & CRM tools, professional/business data providers, event sponsors, and confirmed attendees where applicable | Event logistics, attendee networking, targeted communications |
| Payment references | Stripe (payment processor) | Process payments and prevent fraud |
| Device & usage data | Analytics providers, security tools | Site performance, security, usage insights |
| Marketing & engagement data | Email platforms, advertising platforms | Campaign performance, retargeting (where permitted) |
| Customer‑support records | Zendesk | Support ticketing and communications |
10. International transfers
dinnerHQ is based in the United States. When you access our services from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to the US.
We use appropriate safeguards for international data transfers where required, including Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), transfer impact assessments, vendor security review, data minimization, and contractual confidentiality or data protection commitments. Safeguards may vary by vendor, service, and transfer type.
Request Documentation: For more details on our data processing practices, international transfer safeguards, and key service providers, see our Data Processing and Transfer Addendum. You can also request a copy by emailing [email protected] (GDPR Article 46(2)(c) right to information about safeguards).
If you object to international data transfers, you may choose not to use our services. We cannot provide our services without transferring data to US-based processors. However, where technically feasible, we can accommodate requests to store your data on EU servers — email [email protected] to request EU-based hosting options.
11. Retention
We keep information only as long as necessary to fulfil the purposes in Section 7, to resolve disputes or as required by law (e.g., U.S. tax regulations). When no longer needed, we securely delete or de‑identify it.
Professional enrichment records, derived affiliations, profile embeddings, and matching or recommendation signals are retained only as long as needed for event curation, sponsor relevance assessment, dispute resolution, legal compliance, and service improvement. When no longer needed, we delete, de-identify, or regenerate these derived records from updated source data as appropriate.
12. Your choices & rights
- Email & SMS marketing — click “Unsubscribe” in any message or email [email protected].
- Cookies — use browser controls to block or delete cookies.
- Access / correction / deletion — U.S. residents may request a copy or deletion of personal information by emailing [email protected].
- Professional profile and automated profiling rights — you may ask us to explain, correct, delete, or stop using professional enrichment data, derived affiliations, profile embeddings, or automated recommendation and eligibility signals associated with your profile, subject to legal and operational limitations.
- California residents — you have CCPA rights to know, delete and opt out.
- EEA/UK/Swiss visitors — you have GDPR rights of access, rectification, erasure, restriction, objection and data portability, exercisable via the same email. Because we are not established in the EEA, we process your data on the Article 3(2) GDPR extraterritorial basis.
We will respond within 30 days (or the period required by applicable law). We may ask for identity verification.
Do Not Track. At this time there is no industry standard for recognizing browser “Do Not Track” signals. We honor legally required browser or platform opt-out signals where required and technically feasible. You can also control cookie-based tracking via your browser settings.
California privacy rights (CCPA/CPRA)
California residents have rights to know, delete, correct, opt out of certain regulated disclosures, and limit use of sensitive personal information. We may disclose professional profile information to sponsors and disclose identifiers or device data to advertising partners for targeted or cross-context behavioral advertising. You can opt out of future regulated disclosures via cookie settings or by emailing [email protected].
Opt Out of Regulated Disclosures. If you wish to opt out of future disclosures that applicable law treats as targeted advertising or another regulated disclosure, contact us at the email above and adjust your cookie preferences. We will honor valid opt-out signals to the extent required by law.
EEA/UK/Swiss supplemental notice
Users in the European Economic Area, the United Kingdom, and Switzerland have additional rights under GDPR/UK GDPR:
- Access — request copies of your personal information.
- Rectification — request correction of inaccurate data or completion of incomplete data.
- Erasure — request deletion under certain conditions.
- Restriction — request we limit processing under certain conditions.
- Objection — object to processing based on legitimate interests and to direct marketing.
- Portability — request transfer of your data to you or another provider in a structured, commonly used, machine‑readable format.
- Withdraw consent — when we rely on consent, you may withdraw it at any time.
We may request reasonable information to verify your identity before responding. We do not charge a fee unless a request is manifestly unfounded, repetitive, or excessive.
Complaints: You may lodge a complaint with your local Data Protection Authority at any time.
Automated decision review: If automated profiling materially affects your dinner recommendations, event eligibility, or sponsor-facing professional context, you may request human review, contest the outcome, and provide additional information for correction.
Controller vs. processor: Where we process information on behalf of event partners or other customers, those entities act as the controller. Please contact the relevant controller to exercise your rights for that data.
International transfers: When we transfer personal information outside the EEA/UK, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses or their UK equivalents.
13. Security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access (GDPR Article 32).
Technical Measures
- Encryption: HTTPS/TLS in transit and encryption-at-rest controls provided by our hosting, database, storage, and payment providers
- Access Controls: Access to production systems is limited to authorized personnel and reviewed when roles or needs change
- Network Security: Managed infrastructure controls, rate limiting, request filtering, and provider-level network protections
- Security Review: Code review, dependency updates, provider security documentation, and monitoring to identify and remediate risks
- Logging & Monitoring: Application and infrastructure monitoring to investigate errors, abuse, and reliability issues
- Backups: Backup practices depend on the provider and data type, and retained data remains subject to applicable deletion and retention limits
Organizational Measures
- Staff Awareness: Personnel with access to personal data are expected to follow security and privacy procedures
- Incident Response: Procedures for investigating incidents and providing legally required notices
- Data Minimization: Collection, sponsor disclosures, and provider disclosures limited to data reasonably needed for the stated purpose
- Vendor Management: Review of key vendors and use of appropriate contractual, technical, and operational safeguards based on vendor role and risk
- Confidentiality: Personnel and relevant service providers are subject to confidentiality obligations
- Access Reviews: Periodic access review and revocation of unnecessary access permissions
Security Limitations: No internet transmission is ever 100% secure. By using our services, you acknowledge this inherent risk. We cannot guarantee absolute security but commit to implementing industry-standard safeguards appropriate to the risk.
Data Breach Notification
If we become aware of a personal data breach that compromises your information, we will:
- Notify Regulators: We will notify relevant regulators where required by applicable law
- Notify You: We will inform affected individuals where required by applicable law
- Provide Details: Notification will include the nature of the breach, likely consequences, and mitigation measures taken
- Cooperation: We will cooperate fully with any regulatory investigation and provide necessary documentation
Legal Remedies: Applicable privacy laws may provide remedies or compensation for certain violations. Nothing in this Policy limits rights that cannot legally be limited.
14. Responsible disclosure of security vulnerabilities
If you discover or suspect a security vulnerability in our Services, please notify us immediately at[email protected]. If, during testing, you encounter any sensitive data, stop the test and do not share that data. We will investigate in a reasonable timeframe and may limit access while an issue is assessed.
15. Children’s privacy
Our Services are intended for adults 18 years and older. We do not knowingly collect information from children. If you believe we have done so inadvertently, please contact us for removal.
16. Contact
Privacy Contact
For data protection inquiries, privacy rights requests, or to exercise your rights under applicable data protection laws, contact our privacy team:
Email: [email protected]
Subject Line: "Privacy Request" or "Data Protection Inquiry"
General Privacy Inquiries
For general questions about this Policy or your personal information, email [email protected] or write to the Florida address above.