VESPER
VESPERHomeGatheringsAboutFAQContactRequest invitation

Legal

Privacy Policy

Last updated: 20 July 2026

1. Who we are

Vesper – Marbella Circle is a private gathering concept operated by Avenoriva OÜ, an Estonian private limited company with registry code 17556457 and registered office at Tartu mnt 67/1-13b, Tallinn, Estonia.

For the purposes of the General Data Protection Regulation (“GDPR”), Avenoriva OÜ is the data controller.

Contact:

Avenoriva OÜ
Registry code 17556457
Tartu mnt 67/1-13b
Tallinn, Estonia
contact@vespercircle.com

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, store and protect personal data when individuals:

  • visit the Vesper website;
  • submit a request for an invitation;
  • communicate with Vesper;
  • receive an invitation;
  • book or attend a Vesper gathering;
  • subscribe to information about future Vesper gatherings.

3. Personal data we collect

Invitation requests

When an individual requests an invitation, we may collect:

  • full name;
  • email address;
  • city or place of residence;
  • profession or company;
  • LinkedIn profile or website, where voluntarily provided;
  • information provided in response to the question about why the individual would like to attend Vesper;
  • confirmation that the applicant is at least 21 years of age;
  • marketing preference and newsletter consent status;
  • date and time of submission and consent records.

Booking and event administration

Where an invitation is accepted, we may also collect:

  • billing and payment information;
  • transaction or invoice references;
  • telephone number where required for event administration;
  • details relating to attendance;
  • the name and contact details of an invited partner;
  • dietary, allergy or accessibility information;
  • communications relating to the gathering;
  • records required for accounting, legal and administrative purposes.

Vesper does not store complete payment card details. Payment information may be processed by a bank or payment service provider.

Technical information

The website may automatically process limited technical information necessary for security and operation, such as:

  • IP address;
  • browser and device type;
  • date and time of access;
  • security and server logs;
  • information required for form submission and website functionality.

4. Information about partners

Where an approved applicant identifies a partner, Vesper may receive the partner’s name or contact details from the original applicant.

The information will be used only to contact the partner regarding their personal invitation and attendance. A partner will not be added to a marketing list unless the partner personally provides marketing consent.

The person providing another individual’s information should ensure that the individual is aware that their details will be shared with Vesper.

5. Why we process personal data

We process personal data for the following purposes:

Invitation assessment

To receive, review and respond to requests for invitations and to select a balanced group of guests.

Legal basis: steps taken at the applicant’s request before entering into a contract and Vesper’s legitimate interest in curating private gatherings.

Booking and event delivery

To issue invitations, manage bookings, receive payments, communicate with guests and provide the gathering.

Legal basis: performance of a contract and steps taken before entering into a contract.

Age and safety requirements

To confirm compliance with the minimum age of 21 and to protect the safety, privacy and integrity of Vesper gatherings.

Legal basis: legitimate interests and compliance with applicable obligations.

Accounting and legal compliance

To issue invoices, maintain accounting records, comply with tax obligations and respond to lawful requests.

Legal basis: compliance with legal obligations.

Dietary, allergy or accessibility information

To make reasonable arrangements for a guest’s attendance. Where information reveals health-related data, it will be processed only with the guest’s explicit consent.

Legal basis: consent and, where applicable, explicit consent under Article 9 GDPR.

Future gathering announcements

To send private invitations, news and announcements about future Vesper gatherings.

Legal basis: consent under Article 6(1)(a) GDPR.

Marketing consent is optional and is not a condition of submitting an invitation request or attending a gathering.

Security and legal claims

To prevent misuse, maintain website and event security and establish, exercise or defend legal claims.

Legal basis: legitimate interests and applicable legal obligations.

6. Newsletter and marketing communications

Vesper sends information about future gatherings only to individuals who have agreed to receive such communications or where another lawful basis clearly applies.

Marketing consent:

  • is optional;
  • is not pre-selected;
  • does not affect the assessment of an invitation request;
  • may be withdrawn at any time;
  • is recorded separately from event administration.

Every marketing email will include a clear unsubscribe option.

Withdrawing marketing consent does not affect administrative emails concerning an existing invitation, payment or booked gathering.

7. How long we retain personal data

We retain personal data only for as long as necessary.

Unless a longer period is required by law:

  • invitation requests that do not result in a booking may be retained for up to 12 months;
  • general correspondence may be retained for up to 24 months;
  • booking and event administration records may be retained for up to three years after the gathering where necessary for legal claims;
  • accounting and transaction records are retained for seven years or for another legally required period;
  • dietary and allergy information is normally deleted within 30 days after the gathering unless a legal issue requires longer retention;
  • newsletter information is retained until consent is withdrawn or the subscription becomes inactive and is removed;
  • records demonstrating that marketing consent was given or withdrawn may be retained where necessary to demonstrate compliance;
  • security logs are retained only for a limited period necessary for website security.

Where an individual withdraws newsletter consent, their email address may be kept on a suppression list to ensure that further marketing messages are not sent.

8. Who may receive personal data

Where necessary, personal data may be shared with:

  • website hosting and form service providers;
  • email and newsletter service providers;
  • banks and payment service providers;
  • accountants, legal advisers and professional consultants;
  • the venue, catering providers and other event partners where necessary to deliver the gathering;
  • IT and security providers;
  • public authorities where disclosure is legally required.

Service providers may process data only for the agreed purpose and under appropriate contractual and confidentiality obligations.

Vesper does not sell personal data.

9. International transfers

Some technology providers may process data outside the European Economic Area. Where this occurs, Vesper will use an appropriate legal safeguard, such as an adequacy decision, Standard Contractual Clauses or another mechanism recognised under GDPR.

10. Individual rights

Subject to applicable law, individuals may have the right to:

  • request access to their personal data;
  • request correction of inaccurate information;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • receive certain data in a portable format;
  • withdraw consent at any time;
  • lodge a complaint with a data protection authority.

Consent may be withdrawn without affecting processing that took place before withdrawal.

Requests can be sent to contact@vespercircle.com.

Individuals may also contact the Estonian Data Protection Inspectorate or the competent data protection authority in their country of residence.

11. Automated decision-making

Vesper does not use solely automated decision-making to approve or reject invitation requests. Applications are reviewed individually.

12. Age requirement

Vesper gatherings are available only to individuals aged 21 or over. The website and invitation process are not directed at individuals under 21.

13. Security

Vesper applies reasonable organisational and technical measures designed to protect personal data against loss, unauthorised access, alteration or disclosure.

No internet transmission or storage system can be guaranteed to be completely secure.

14. Changes to this Privacy Policy

This Privacy Policy may be updated when our services, technology or legal obligations change. The latest version will always be published on this page.

15. Contact

Questions about privacy or personal data may be sent to:

contact@vespercircle.com