Privacy Policy
This page explains what the site of the Dushanbe International Tourism Exhibition collects, why the organizing committee needs it and what you can ask us to do with it. It describes how the site actually works rather than following a generic template: everything named here happens, and nothing beyond it does.
Who processes your data
Your data is processed by the organizing committee of the Dushanbe International Tourism Exhibition, which runs the exhibition and owns this site.
Write to info@dite.tj with any question about this document or about the data you have sent us. It is the same address the applications themselves arrive at, and it is read by the committee.
What we collect
The site collects data in one place only: the two registration forms you fill in yourself. There is nothing else — no visitor counter, no advertising pixel, no profile built from the pages you open.
- Visitor form: full name, e-mail address, phone number, nationality, gender, job title, company name, industry, country, purpose of visit, the days you plan to attend, how you heard about the exhibition, your areas of interest, whether you want news about future events, and any special requirements you describe.
- Exhibitor form: full name, passport number, contact phone, phone, e-mail address and postal address; your company details — name, legal address, contact person, phone, e-mail, website, year of establishment, memberships; what the company does, your goals for taking part, your booth requirements, and the additional information you choose to add, including an air travel itinerary if you enter one.
- Technical data recorded with a submission: your browser string (User-Agent) and a one-way fingerprint of your IP address. The address itself is never stored — only a keyed hash that cannot be turned back into an address but does reveal a repeat submission. It exists for one purpose: to rate-limit the forms so they cannot be flooded automatically.
Why we need it
Visitor data is what lets the committee issue and send your entry pass, reserve seats at the sessions you selected, and tell you about changes to the program. If you ticked the box about future events, the committee will also write to you about them; if you did not, it will not.
Exhibitor data is what lets the committee process a stand application: work out the space and equipment you need, come back to you about availability and pricing, and register your company as a participant. The passport number and address are asked for in order to register that participation, accredit the people who will work the stand and issue their passes to the venue; neither is published anywhere on the site.
Both forms are sent with your consent and not without it: the tick box at the end of each one is that consent, and the server refuses an application that arrives without it. You can withdraw it at any time — see your rights below.
Only the fields marked with an asterisk are required. Leaving the rest blank does not affect whether your application is accepted.
We do not use your data to sell you anything, and we do not pass it to third parties for advertising.
Who sees it
A submitted form is saved in the site database and, at the same moment, sent by e-mail to info@dite.tj so that the committee sees the application straight away. That message contains every field of the application — which for an exhibitor means the passport number and the address end up in the committee mailbox and in whatever backups that mailbox has.
Applications are also readable by the committee administrators in a password-protected admin area. That area keeps a log: when an administrator opens an application containing passport details, the fact is recorded together with who did it and when.
Nothing goes anywhere else. The site has no mailing-list service, no analytics account, no webhooks and no advertising integrations to send it to.
How long we keep it
Applications are kept for as long as the 2026 exhibition and its follow-up require. After that they are of no use to us, and you can ask for yours to be deleted sooner — see your rights below.
The IP fingerprint exists in two places and they behave differently: rows in the rate-limiting table are deleted as soon as their window has passed, while the fingerprint stored beside an application lives exactly as long as that application does.
Cookies and other sites
On our own domain we set no cookie for visitors at all. The only cookie the site issues is dite_admin_session, and it appears only after a committee administrator signs in to the admin area, where it keeps that session open; it is never read on the public pages. The site stores nothing in your browser either — no localStorage, no sessionStorage.
There is no analytics on the site — no Google Analytics, no Yandex.Metrica, no counter of any other kind.
Three things on these pages are loaded from servers that belong to other companies, and they are worth naming plainly: the Poppins typeface comes from Google Fonts (fonts.googleapis.com and fonts.gstatic.com), the map in the "How to Find Us" block is a Yandex Maps widget, and the gallery videos play through YouTube in its no-cookie mode (youtube-nocookie.com), where the player is created only after you click a video. Loading a file from a server shows that server your IP address and browser, exactly as it would on any site. The contents of your application are never sent to any of them.
One of those three does set cookies, and it is the map. The Yandex Maps widget writes its own cookies on yandex.ru and mc.yandex.ru — including the yandexuid identifier — the moment the map loads, which is when you scroll down to the "How to Find Us" block. They are Yandex cookies, not ours: we neither read them nor receive anything from them. We measured the rest: open a page and never scroll that far and no cookie appears at all, the YouTube player in no-cookie mode sets none even after a video starts playing, and the fonts set none at any point.
How your data is protected
Administrator passwords are not stored — only Argon2id hashes of them — and a signed-in session is stored as a hash of its token, so a copy of the database cannot be replayed as a login. The admin area is served over an encrypted connection and its session cookie is restricted to HTTPS in production.
IP addresses are stored as keyed hashes rather than as addresses, as described above.
The application lists in the admin area do not include the passport number or the address: those fields are read only when a single application is opened, and opening it is what the audit log records.
Neither the server logs nor the error messages ever contain the values you typed into a form.
Your rights
You can ask us at any time to give you a copy of what you sent, to correct something that is wrong, to delete your application, or to withdraw your consent — either for the news about future events alone, or entirely.
Write to info@dite.tj from the address you gave in the form, so that we do not have to ask you to prove the application is yours, and say what you would like done. We will reply and carry it out unless a commitment already made to you — a confirmed stand, for instance — depends on the data.
Withdrawing consent does not undo what was already done with the data before you withdrew it, such as a pass that has already been issued.
Changes to this document
If anything here stops matching how the site works, the document gets changed rather than left standing. The date at the top of this page says when that last happened, and the committee will write to you about a change that affects an application you have already sent.

