1. Who we are
[ORGANISATION NAME] ("we", "us") operates this conference platform and related Events. This Privacy Policy explains what personal data we collect, why we process it, who we share it with, how long we keep it, and the rights available to you.
Privacy contact: [CONTACT EMAIL]
Postal / registered address: [POSTAL ADDRESS]
If we appoint a Data Protection Officer or EU/UK representative, their details will appear here: [DPO OR REPRESENTATIVE DETAILS].
2. Scope
This policy covers personal data processed when you browse our public sites, create an account, register for an Event, purchase tickets, submit a CFP or scholarship application, volunteer, sponsor, speak, message other participants, or contact us. Event-specific notices may supplement this policy where an organiser publishes additional terms.
3. What we collect at registration and related flows
Depending on the form and Event, we may collect:
- Identity and contact: name, email, phone, company, job title, country/region, dietary or accessibility notes you choose to provide
- Account data: authentication identifiers from our identity provider, profile preferences, and communication settings
- Transaction data: ticket type, order references, payment status, billing country, and limited payment metadata from our payment processor (we do not store full card numbers on our servers)
- Programme participation: sessions you save, CFP proposals, speaker bios, volunteer shifts, scholarship applications
- Onsite and virtual attendance: check-in status, badge data, virtual session join metadata where enabled
- Photography and recordings: images and audio/video captured at the Event when photography or recording is active
- Technical data: IP address, device/browser type, approximate location derived from IP, pages viewed, referrer, and cookie or similar identifiers (see our Cookie Policy)
- Communications: messages you send to us or through platform messaging tools, and support tickets
We do not require special-category data to register. If you voluntarily share health, accessibility, or similar details so we can support you at the Event, we process that information only for that purpose and with appropriate safeguards.
4. Why we process data and lawful bases
Operators in [JURISDICTION] should map each purpose to a valid lawful basis (for example GDPR Art. 6). Typical mappings for an events platform include:
- Contract: creating your account, processing registration and payment, delivering the Event, sending transactional emails (confirmation, schedule changes, venue updates)
- Legitimate interests: securing the platform, preventing fraud, understanding aggregate attendance, improving the product, limited direct marketing where permitted and subject to your opt-out rights
- Consent: non-essential cookies/analytics; marketing newsletters you opt into; sharing attendee details with sponsors (see below); optional directory visibility
- Legal obligation: tax, accounting, and responding to lawful requests from authorities
Where we rely on legitimate interests, you may object as described in Section 8. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
5. Sharing with sponsors — only on explicit consent
We do not sell your registration data. We share individual attendee contact details with Event sponsors only when you give explicit, informed consent for that purpose (for example, by opting in on the registration form or a separate consent control). Consent should name the categories of recipients or specific sponsors where practical, and you can refuse without losing access to core ticket features unless a particular benefit is clearly conditioned on that consent and lawful.
Aggregate, de-identified statistics (for example, attendee counts by industry) may be shared with sponsors without identifying you.
6. Other recipients
We may share personal data with:
- Service providers who process data on our instructions (hosting, email, payments, authentication, analytics, customer support)
- Venue, security, or catering partners when needed to run the Event safely
- Professional advisers and insurers under confidentiality obligations
- Authorities when required by law or to protect rights, safety, or property
- A successor organisation in a merger, acquisition, or asset transfer, with notice where required
List primary processors here for operator transparency: [LIST OF KEY PROCESSORS].
7. International transfers
If you are in the EEA, UK, or another region with transfer restrictions, data may be processed in countries outside your region (including where our hosting or tooling providers operate). We use appropriate safeguards such as standard contractual clauses or equivalent mechanisms where required. Details: [TRANSFER SAFEGUARDS SUMMARY].
8. Retention
We keep personal data only as long as needed for the purposes above, then delete or irreversibly anonymize it, unless a longer period is required by law. Template retention targets for operators to confirm:
- Registration and ticket records:
[RETENTION — REGISTRATIONS](for example, duration of Event plus accounting period) - Marketing contacts who have not engaged: until unsubscribe or
[RETENTION — MARKETING] - Security logs:
[RETENTION — LOGS] - Photos and recordings:
[RETENTION — MEDIA], or until a valid erasure request is fulfilled where applicable
9. Your rights
Subject to applicable law (including GDPR/UK GDPR and similar regimes), you may have the right to:
- Access the personal data we hold about you
- Export / portability — receive a copy in a structured, commonly used, machine-readable format where that right applies
- Rectification of inaccurate or incomplete data
- Erasure ("right to be forgotten") in the circumstances set out by law
- Restriction of processing in certain cases
- Objection to processing based on legitimate interests or to direct marketing
- Withdraw consent where processing is consent-based
To exercise these rights, email [CONTACT EMAIL] with enough detail for us to verify your identity and locate your records. We will respond within the period required by law (for example, one month under GDPR, extendable where permitted). You may also lodge a complaint with your supervisory authority: [SUPERVISORY AUTHORITY].
10. Children
Our Events and platform are directed at professionals and are not intended for children under [MINIMUM AGE]. We do not knowingly collect personal data from children below that age. If you believe we have, contact us so we can delete it.
11. Security
We implement technical and organisational measures appropriate to the risk, including access controls, encryption in transit, and least-privilege operational practices. No method of transmission or storage is completely secure; please use strong unique passwords and protect your devices.
12. Cookies and similar technologies
See our separate Cookie Policy for essential vs analytics cookies and how to change preferences.
13. Changes
We may update this Privacy Policy from time to time. The "Last updated" date will change when we do. Material changes will be called out on this page or by email when appropriate.
14. Contact
Privacy requests and questions: [CONTACT EMAIL].