1. Introduction and scope
Scytale Research EOOD ("we", "us", "our") organises Lugano Summit 2027 — The Private Wealth Summit and operates the website at www.luganosummit.org. Many of the people who visit this site, write to us or join the Lugano Circle do so in a private capacity, and discretion is a condition of their participation rather than a courtesy. We therefore collect no more personal data than we need, treat it as confidential and process it strictly in accordance with the law.
This policy explains what personal data we collect, why we collect it, what we do with it, who we share it with, how long we keep it and what rights you have. It applies when you:
- visit or use the public pages of this website;
- write to us, submit the contact form or apply to the Lugano Circle;
- hold an account and use the Lugano Circle members' area; or
- attend, speak at, sponsor or otherwise take part in the summit.
It is issued in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Bulgarian Personal Data Protection Act.
This policy does not apply to websites operated by other organisations. This site links to third-party sites — partners, sponsors, speakers and their institutions, the venue and our own profiles on social platforms. Once you follow a link, the operator of the site you arrive at becomes responsible for your data under its own privacy policy, which will differ from this one. We check the pages we link to when a link is made, but we cannot monitor them continuously.
2. Who we are (controller and contact)
The controller responsible for the processing described in this policy is:
Scytale Research EOOD
5 Slavyanska Street, floor 2
Sredets district
Sofia 1000
Bulgaria
info@luganosummit.org
www.luganosummit.org
Our data protection contact is Svetoslav Boyadzhiev, who can be reached at dataprotection@scytale.digital, or by post at the address above marked "Data Protection". Any question about this policy, and any request to exercise the rights set out in section 11, may be sent to him or to info@luganosummit.org.
Further company and publisher details are set out in the Imprint.
3. The personal data we collect
3.1 Data you give us
Most of the personal data we hold is data you have given us yourself:
- Enquiries and partnership requests. Through the contact form or by email: your first and last name, your email address, your organisation and position, your country, the nature of your interest (attendance, speaking, sponsorship, media or another topic), a description of who you are, and the content of your message.
- Applications to the Lugano Circle. Your name, email address, country, organisation and position, your primary pillar and the category that describes you, what you tell us about yourself and your reasons for applying, and the name of any member who referred you.
- Your member account. The email address the account is issued to, and the password you set, which we never see in readable form.
- Your member profile. First and last name, email address, the city and country you are based in, your organisation, your primary sector, the pillars you have marked as interests, a short biography in your own words, and your membership tier and start date.
- Activity in the members' area. The convenings you reserve a seat for and the number of guests you register, the briefings you like, the comments you write, and the messages you send the Circle team through the member contact form.
- Participation in the summit. The details we need to admit you and run the event: name, organisation and position as they appear on your badge, contact details, any dietary or accessibility requirements you tell us about, and, where you ask us to coordinate them, travel or accommodation arrangements.
Supplying this data is voluntary. We cannot, however, answer an enquiry, assess an application, admit you to the summit or give you access to the members' area without it.
Please do not send us special categories of personal data — health information, for example — except where we specifically ask for it, as we do with dietary and accessibility requirements, and please do not include confidential third-party information in a first approach.
3.2 Data collected automatically
When any page of this website is requested, our hosting provider records the technical information that every web server records in order to deliver a page and keep the service secure: the IP address of the requesting device, the browser type and version, the operating system, the referring address, the pages and files requested, and the date and time of the request. This information is held in server logs, is not combined with other sources and is not used to build a profile of an individual visitor.
Because the typefaces, the Supabase JavaScript library and — in the members' archive — video thumbnails and embedded film are loaded from third-party servers, the IP address of your device is also transmitted to those providers so that they can return the file. Section 6 explains who they are.
If you are signed in to the members' area, your browser stores a session token so that you stay signed in between pages. Section 5 explains this.
Our public forms carry a hidden field that is invisible to a human but is filled in by automated submission scripts. We use it to discard spam. It collects nothing about you.
We operate no analytics. There is no measurement service, no advertising, no tracking pixel and no cross-site tracking on this website.
3.3 Data collected at the event
At the summit itself we process the participant and guest lists, admission and badge records, the sessions and dinners you attend, dietary and accessibility requirements, and any travel or accommodation arrangements we coordinate for you. The venue and our security staff may process data of their own under the venue's house rules.
The summit is professionally photographed and filmed, and sessions may be recorded, streamed and published. Section 10 sets out what that means and how to object.
4. How and why we use it
We use personal data only for the purposes for which it was given to us, and on the following legal bases under Article 6(1) GDPR:
- To answer enquiries, partnership, speaking and media requests — Art. 6(1)(b) GDPR, steps taken at your request before entering into a contract, and Art. 6(1)(f), our legitimate interest in responding to people who approach us.
- To assess and administer applications to the Lugano Circle — Art. 6(1)(b) GDPR, steps taken before entering into a contract. The tick-box on the application form records your agreement to our assessing the application on this basis.
- To issue and operate member accounts, to display the member directory, to take RSVPs for convenings, to publish briefings and to run the members' archive — Art. 6(1)(b) GDPR, performance of the membership, supported by Art. 6(1)(f), our legitimate interest in running a functioning members' network.
- To register, admit and look after participants, speakers and partners at the summit — Art. 6(1)(b) GDPR, performance of a contract with you.
- To send the transactional email the service depends on — invitations, password resets, seat confirmations and waiting-list notices, and copies of form submissions to the organising team — Art. 6(1)(b) GDPR, and Art. 6(1)(f) where you are not the contracting party.
- To keep this website, the members' area and our systems secure and available, to investigate faults and to prevent spam, abuse and unauthorised access — Art. 6(1)(f) GDPR.
- To document the summit in photography, film and writing and to promote future editions — Art. 6(1)(f) GDPR for general audience and atmosphere material, and Art. 6(1)(a), your consent, where an image or interview focuses on you individually.
- To send occasional written updates about future editions and Circle activity to people who have asked for them — Art. 6(1)(a) GDPR, your consent, which is voluntary and may be withdrawn at any time.
- To meet our accounting, tax and commercial record-keeping duties — Art. 6(1)(c) GDPR, compliance with a legal obligation under Bulgarian law.
- To establish, exercise or defend legal claims and to enforce our Terms & Conditions — Art. 6(1)(f) GDPR.
Where we rely on legitimate interests we have weighed our interest against your interests, rights and freedoms, and you may object as described in section 11. Where we rely on consent, withdrawing it does not affect the lawfulness of anything we did beforehand.
We do not sell or rent personal data, and we do not make it available to third parties for their own marketing purposes. We take no automated decisions producing legal or similarly significant effects concerning you, and we do not carry out profiling. Applications to the Circle are read and decided by people.
5. Cookies and similar technologies
Cookies are small text files that a website asks your browser to store on your device, so that the site can recognise the same browser across requests. Local storage works in a comparable way. Cookies are usually divided into strictly necessary cookies, without which a requested service cannot be provided; functional cookies, which remember preferences; and analytics or advertising cookies, which measure behaviour or target advertising.
We use strictly necessary cookies and equivalent storage only. This site carries no analytics, no advertising, no tracking pixels and no marketing cookies. We do not use functional cookies, we do not track your behaviour across other websites, and we do not build behavioural profiles. Because nothing here requires consent, no cookie banner is required and none is shown.
What is actually stored on your device is this:
- The Supabase session cookie. The members' area runs on Supabase. When you sign in, Supabase issues a session token, held as a cookie or an equivalent local storage entry, which is sent back with each request so that the site knows you are still signed in and can refresh the session before it expires. It is set only once you sign in, it carries no advertising identifier, and it is cleared when you sign out.
- Short-lived technical entries set during sign-in — for example the values used to complete an invitation or a password-reset link. These are discarded as soon as sign-in completes.
You can set your browser to refuse cookies, to warn you before one is stored or to delete those already set. The public pages of this site will continue to work if you do. The members' area will not: blocking the session token makes it impossible to remain signed in.
6. Third parties and processors
We use a small number of service providers to deliver this website and the members' area. Each acts only on our documented instructions, under a data-processing agreement satisfying Article 28 GDPR where it acts as our processor, is bound to confidentiality and to appropriate technical and organisational measures, and may not use the data for its own purposes.
- Vercel — hosts and delivers this static website. Vercel serves every page and records the server logs described in section 3.2.
- Supabase — provides the database, the authentication, the file storage and the server-side functions behind the members' area. Member accounts, profiles, RSVPs, briefings, comments, messages, form submissions and the private media bucket all live there.
- Resend — delivers the email the site sends: invitations and password resets, seat confirmations and waiting-list notices, and copies of form submissions to the organising team. Resend receives the recipient's address and the content of the message.
- Google — supplies the typefaces used across the site through Google Fonts, which are loaded from Google's servers when a page opens, so your IP address is transmitted to Google. Film in the members' archive is hosted on YouTube as unlisted video and embedded through youtube-nocookie.com, so Google is contacted only when a member presses play, although the still thumbnail is fetched from img.youtube.com when the page loads. Google's own notice is at policies.google.com/privacy.
- jsDelivr — a public content delivery network from which the members' area loads the Supabase JavaScript library. It receives the IP address of the requesting device in order to return the file.
None of the above sets an advertising cookie on this site.
Beyond those providers, we disclose personal data outside our own organisation only in the following circumstances:
- Event suppliers. The venue, caterers, photographers, film crew, transport and security suppliers who make the summit possible receive what they need to do so — for example your name and dietary requirements, so that you can be seated and fed.
- Our co-host. Where an enquiry specifically concerns BIL Suisse as co-host of the summit, its participation or a partnership in which it is involved, we share with it only what is needed to deal with that enquiry.
- At your request. We pass your details to a third party where you have asked us to or agreed that we should — for instance to introduce you to a partner or another member.
- Professional advisers — our accountants, auditors, insurers and lawyers, bound by professional confidentiality.
- For legal reasons. Where we are required to disclose by law, by a court or by a competent authority; where disclosure is necessary to detect, prevent or address fraud, a security incident or a technical problem; where it is necessary to enforce our terms; or where it is necessary to establish, exercise or defend legal claims or to protect the rights, property or safety of our guests, our staff or the public. We disclose only what the circumstances require, and we tell the person concerned unless we are prohibited from doing so.
7. International transfers
Our processing takes place principally within the European Economic Area.
The summit is held in Switzerland, so data needed for the event — participant lists, dietary requirements, venue logistics — is transferred to our Swiss venue and suppliers. Switzerland is recognised by the European Commission as providing an adequate level of protection, so no further safeguard is required.
Some of the providers named in section 6 are established outside the EEA, or may process data on servers outside it, including in the United States. Where that happens and no adequacy decision applies, the transfer takes place only under appropriate safeguards within the meaning of Chapter V GDPR — as a rule the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organisational measures. The hosting region of our Supabase project is recorded in our processor register.
You may ask us for a copy of the safeguards in place by writing to the contact address in section 15.
8. How long we keep it
We keep personal data only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires us to keep it, and then delete it or restrict it from further use:
- Enquiries and correspondence — up to 24 months after our last exchange with you, unless the enquiry leads to a contractual relationship or we are required to keep it for longer.
- Applications to the Lugano Circle — for the duration of the membership where an application is accepted and, where it is declined, for up to 24 months afterwards, so that a renewed application can be considered consistently.
- Member accounts, profiles and directory entries — for as long as the membership lasts, and deleted at your request or within a reasonable period after it ends. Your directory entry is withdrawn from view as soon as the account is closed.
- RSVPs, comments, likes and messages to the Circle team — for the duration of the membership, and deleted with the account. You can delete your own comments at any time.
- Event registration and participation records, contracts and invoices — for the statutory retention periods applicable under Bulgarian accounting and tax law.
- Data processed on the basis of consent — until you withdraw your consent, after which we keep only the minimal record needed to honour the withdrawal.
- Server logs — for a short period only, as required for security and troubleshooting.
- Photographs and recordings of the summit — as part of the permanent archive of the event, subject to any objection you make under section 10.
9. The members' area and the directory
The Lugano Circle members' area is the signed-in part of this website. It runs on Supabase, as described in section 6.
9.1 Accounts are invitation-only
There is no public registration and no self-service sign-up. Accounts are issued by the organisers to individuals admitted to the Circle: we send the invitation, and you set your own password when you follow it. You sign in with that email address and password.
9.2 Your profile is a directory entry
The purpose of the Circle is introduction between principals. The profile fields listed in section 3.1 — your name, city, organisation, sector, interests, biography and email address — are visible to every other signed-in member as a directory. Please complete them on that basis, and put nothing in your biography that you would not want a fellow member to read.
You may edit every field of your profile yourself at any time from the profile page, and you may ask us to remove your entry or close your account by writing to us.
9.3 Convenings, briefings and messages
When you reserve a seat at a convening, your name appears on the attendee list for that convening, which other signed-in members can see. Guest numbers are recorded but guests are not named publicly.
Comments you write on briefings are visible to all signed-in members, together with your name. You can delete your own comments; organisers can also remove a comment. Likes are recorded as a count.
Messages you send the Circle team through the member contact form are visible only to you and to us — never to other members.
9.4 The private archive
The members' area holds an archive of photography and film from previous editions of the summit. The files are uploaded by us, not by members, and are held in a private Supabase Storage bucket. Nothing in that bucket is world-readable or reachable by a search engine: an image is served only to a signed-in member, through a short-lived signed link generated for that request. Film is held on YouTube as unlisted video, watchable only by someone with the link and invisible in search and on our channel, and is embedded as described in section 6.
If you appear in the archive and would rather not, section 10 explains how to tell us.
9.5 Access control
Nothing in the members' area is visible to the public or to search engines, and nothing can be read without a valid session. Access is enforced at the database level by row-level security, so that a signed-in member reaches the directory and their own records and nothing else, and an unauthenticated request reaches nothing at all.
10. Photography and filming at events
The Lugano Summit is professionally photographed and filmed. Keynotes, panels and parts of the receptions and dinners are recorded, and the resulting material is used to document the edition and to promote future ones — on this website, in the members' archive, on our social and YouTube channels, and in press and partner communications. Sessions may be streamed or published in full.
By attending the summit you should assume that you may appear in photographs or recordings made in the public areas of the venue and during the programme. We rely on our legitimate interest in documenting and promoting the event (Art. 6(1)(f) GDPR) for general audience and atmosphere material, and on your consent (Art. 6(1)(a) GDPR) where an image or an interview focuses on you individually.
If you would prefer not to be photographed, please tell the registration desk when you arrive. We will record your preference, mark it discreetly on your badge and instruct our photographers accordingly.
You may also object afterwards, at any time, by writing to info@luganosummit.org or to our data protection contact. We will remove the material concerned from our own channels and from the members' archive without undue delay, although we cannot always recall material already published by the press or distributed by third parties.
11. Your rights
As a data subject you have the following rights in respect of the personal data we hold about you:
- Access — to obtain confirmation of whether we process data concerning you, a copy of that data, and information about the purposes, the recipients and the retention period (Art. 15 GDPR).
- Rectification — to have inaccurate data corrected without undue delay and incomplete data completed (Art. 16 GDPR).
- Erasure — to have your data deleted where one of the grounds in Article 17 GDPR applies, for instance where it is no longer needed for the purpose for which it was collected or where you have withdrawn the consent on which it rested.
- Restriction of processing — to require us to limit our use of your data in the circumstances set out in Article 18 GDPR, for example while its accuracy is being checked.
- Data portability — to receive the data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where this is technically feasible (Art. 20 GDPR).
- Objection — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests, and to object at any time and without giving reasons to processing for direct marketing purposes (Art. 21 GDPR). Where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless we need the data to establish, exercise or defend legal claims.
- Withdrawal of consent — where processing rests on your consent, to withdraw it at any time with effect for the future, without affecting the lawfulness of the processing carried out beforehand (Art. 7(3) GDPR).
- Complaint to a supervisory authority — to lodge a complaint with a data protection authority (Art. 77 GDPR). Ours is the Commission for Personal Data Protection of the Republic of Bulgaria (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria, www.cpdp.bg. You may instead complain to the supervisory authority of the Member State in which you live or work, or in which you believe the infringement occurred.
We would ask you to raise any concern with us first, since most can be settled quickly and directly.
If you hold a member account, the quickest route to your data is the profile page of the members' area: everything we hold there is displayed, and you can correct or replace any of it yourself.
Otherwise, write to dataprotection@scytale.digital or info@luganosummit.org and tell us what you need. We answer within one month. If a request is unusually complex we may extend that period as the GDPR allows, and we will tell you if we do and why. We may ask you for information sufficient to satisfy us of your identity before we act, precisely because we do not want to disclose your data to somebody else. Exercising these rights costs nothing.
12. Security
We apply appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. This website is served in full over an encrypted TLS connection. The members' area is protected by individual authentication, access to member records is enforced at the database level by row-level security, and the media bucket is private and served only through short-lived signed links.
Internally, access to enquiry, membership and participation data is confined to the small number of people who need it in order to do their work, all of whom are bound to confidentiality. Our service providers are chosen with their security standards in mind, and our systems are kept up to date.
No transmission over the internet and no method of electronic storage can be guaranteed to be completely secure, and we do not claim otherwise. Please do not send us sensitive financial details by unencrypted email. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and you, as the GDPR requires.
13. Children
This website, the Lugano Circle and the summit are directed at professional adults. They are not intended for children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe that a child has provided us with personal data, please write to us at dataprotection@scytale.digital and we will delete it without undue delay.
14. Changes to this policy
We may amend this policy from time to time to reflect changes in the way we work, in the services we rely on or in the law. The version published on this page is always the one in force, and the date at the head of the page shows when it was last revised.
Where a change materially affects how we process your data, we will draw it to your attention rather than relying on your noticing it here, and where a change requires your consent we will ask for it before it takes effect.
15. Contact
For any question about this policy, about how we handle your personal data, or to exercise any of the rights in section 11:
Scytale Research EOOD
5 Slavyanska Street, floor 2, Sredets district, Sofia 1000, Bulgaria
Data protection contact: Svetoslav Boyadzhiev —
dataprotection@scytale.digital
General enquiries:
info@luganosummit.org
Company and publisher details are set out in the Imprint. The terms governing use of this website, participation in the summit and membership of the Circle are set out in our Terms & Conditions.

