Eventact (“Eventact,” “we,” “us,” or “our”) provides an online event management,
ticketing, and attendee communication platform (the “Platform” or “Services”). This Privacy Policy
explains how we collect, use, disclose, and secure personal information when you access or interact with our websites
(including eventact.com), mobile or web applications, communications interfaces, and related software tools.
Please note the critical distinction regarding how personal data is governed across our Platform:
For Event Participants / Attendees: The event organizer (“Organizer”) hosting or managing
the event is the Data Controller (or “Business”) of your personal data. Eventact processes your personal data
strictly on behalf of, and under the direct operational instructions of, the Organizer as a Data Processor (or
“Service Provider”). If you have questions about an Organizer’s data practices or wish to exercise
statutory data protection rights regarding event registration or event communication records, please direct your request
directly to the Organizer.
For Organizers and General Website Visitors: Eventact acts as the Data Controller regarding direct
customer accounts, billing details, platform administrative access, and technical data collected through direct
interactions with our corporate websites.
1. Information We Collect
A. Information Processed on Behalf of Organizers (Participant Data)
When you register for an event, check in, interact with an event website or app, or communicate with an Organizer via our
tools, we process data collected on the Organizer’s behalf:
- Contact Information: Full name, business or personal email address, phone number, physical address.
- Professional & Demographic Details: Job title, organization/company name, professional bio, industry interests, social profiles, and demographic selections.
- Registration & Preference Data: Ticket types, session registrations, workshop selections, dietary preferences, accessibility requirements, and responses to custom form questions configured by the Organizer.
- Media & Digital Credentials: Profile photos, badge photos, digital wallet pass identifiers, and barcode/QR check-in tokens.
- Communications & Messaging Data: If you receive messages from or interact with an Organizer via integrated messaging channels (such as SMS, WhatsApp Business, push notifications, or web chat), we process your phone number, message metadata (timestamps, read/delivery receipts), and any text, images, or selections you transmit.
- Financial & Transaction Records: For paid registrations, payments are routed directly through secure, third-party payment gateways. Eventact does not receive, store, or process raw credit card numbers or sensitive CVV/CVC codes on its servers.
B. Technical and Diagnostic Data (Collected Automatically)
When you access our Platform or browse our websites, our servers automatically log technical diagnostics:
- Device & Network Information: IP address, operating system, browser type and version, hardware device identifiers, and language preferences.
- Platform Interaction: Visited pages, access timestamps, referring URLs, features accessed, API calls, and system crash logs.
C. Organizer Account Data
If you establish an Eventact administrator account or communicate with our sales and technical support teams:
- Name, business contact information, billing records, administrative credentials, and communication history.
2. How We Use Information
We process personal data solely for legitimate business purposes and according to the instructions of our customers:
- Delivering Platform Services: Managing event registration workflows, generating digital passes and attendee badges, processing check-ins, and maintaining event web apps.
- Facilitating Event Communications & Two-Way Messaging: Enabling Organizers to transmit confirmations, schedule modifications, transactional alerts, and automated notifications via email, SMS, push notifications, and instant messaging services (including WhatsApp Business Cloud API). Organizers remain solely responsible for obtaining and maintaining all necessary participant consents, opt-ins, and permissions required by applicable telecommunications laws and third-party platform messaging policies before sending communications.
- Security & System Integrity: Detecting, preventing, and responding to cyber incidents, fraudulent transactions, unauthorized account access, or violations of service terms.
- Platform Maintenance & Optimization: Diagnosing server latency, debugging application errors, and analyzing performance to ensure platform availability and reliability.
- Legal & Regulatory Obligations: Complying with applicable statutory requirements, court orders, subpoenas, or official legal proceedings.
3. Sharing and Disclosure of Information
Eventact does not sell, rent, or trade personal data to third parties. We share or disclose information only under the
following conditions:
- To the Respective Organizer: Attendee data collected during registration or messaging interactions is directly available to the Organizer and their authorized administrators.
- Communications Infrastructure Providers (Sub-Processors): To deliver automated and interactive event messages, phone numbers and message payloads are transmitted through authorized telecommunications aggregators, SMS gateways, and messaging network providers—including Meta Platforms, Inc. (for the WhatsApp Business Cloud API)—strictly for delivery, routing, and processing.
- Technical Service Providers (Sub-Processors): We work with vetted third-party vendors for cloud server hosting, database infrastructure, email delivery, system monitoring, and technical support tooling. All sub-processors are bound by strict contractual confidentiality, data security standards, and restrictions prohibiting the use of personal data for any purpose other than providing their designated services.
- Corporate Transactions: In the event of a merger, acquisition, reorganization, financing, or sale of company assets, personal data held by Eventact may be transferred to the acquiring entity subject to standard confidentiality protections.
- Legal Mandates & Safety: We may disclose information if required to do so by applicable law, or where we determine in good faith that such disclosure is necessary to comply with judicial processes, protect individual physical safety, or defend the legal rights and property of Eventact and our users.
4. Cookies, Web Beacons, and Tracking Technologies
- Essential Operational Cookies: We utilize first-party cookies and session storage mechanisms strictly necessary to maintain active user authentication, preserve registration session state, and enforce security controls.
- Performance & Analytics: We may utilize privacy-compliant analytics tools (such as Google Analytics) to assess traffic trends and platform navigation patterns. You can opt out of Google Analytics tracking across web platforms via the Google Analytics Opt-out Browser Add-on.
- Web Beacons & Tracking Pixels: Transactional emails or system notifications sent via the Platform may include lightweight tracking pixels to measure delivery success and open rates for administrative reporting.
- Do Not Track Signals: Due to the absence of a standardized technical consensus regarding browser-based “Do Not Track” (DNT) signals, our Platform does not modify its data collection practices in response to automated DNT headers.
For additional information on our use of cookies, please consult our separate
Cookie Policy.
5. Data Retention
- Participant Information: We retain attendee and registration records in accordance with the documented instructions and retention preferences set by the respective Organizer. Organizers retain full administrative capability to modify, export, archive, or permanently purge participant records from the Platform.
- Organizer Administrative Data: We retain customer account and transactional records for the duration of the active business relationship, or as necessary to fulfill contractual obligations, defend legal claims, and comply with tax and accounting rules.
6. Information Security
We maintain industry-standard administrative, physical, and technical safeguards designed to protect personal data against
accidental loss, unauthorized access, destruction, alteration, or disclosure. Protections include encrypted data transmission
(HTTPS/TLS), firewalls, role-based access restrictions, and periodic security evaluations. While we implement robust defenses,
no internet transmission or digital storage architecture can be guaranteed 100% secure. If you suspect an unauthorized
compromise of your account credentials, please notify our team immediately.
7. Children’s Privacy
The Platform is designed and intended solely for commercial, professional, and adult organizational use. We do not knowingly
collect personal data directly from children under 16 years of age. Where an Organizer manages an event involving minors, the
Organizer bears full responsibility for securing all necessary parental or guardian consents mandated by applicable privacy
regulations. If we determine that personal information from an individual under 16 was collected without valid legal consent,
we will delete that data expeditiously.
8. Notice for California Residents (CCPA / CPRA)
This section applies to California residents pursuant to the California Consumer Privacy Act, as amended by the California
Privacy Rights Act (collectively, “CCPA”).
- Service Provider Designation: For attendee data processed on behalf of Organizers, Eventact operates as a “Service Provider.” Attendee requests to exercise CCPA rights should be directed to the relevant event Organizer.
- Categories of Data Handled: In the preceding 12 months, Eventact may have processed identifiers (e.g., name, email, IP address, phone number), commercial transaction data, internet/network activity logs, professional or employment details, and inferences drawn from these categories.
- No Sale or Cross-Context Behavioral Sharing: Eventact does not sell personal information and does not share personal information for cross-context behavioral advertising.
- Consumer Rights: Eligible California residents have the right to request access to the specific categories and pieces of personal data collected, request correction of inaccurate records, request deletion of personal information (subject to legal exceptions), and be free from discriminatory treatment for exercising their privacy rights.
For inquiries regarding personal data for which Eventact serves as the direct Business/Controller, contact us at
privacy@eventact.com.
9. European & UK Data Protection (GDPR / UK GDPR)
For event participants and clients located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please
refer to our dedicated Eventact GDPR Compliance & Data Transfers Page. That page details our
lawful bases for data processing, data subject rights (access, correction, erasure, portability, restriction, and objection),
our Data Processing Addendum (DPA), and standard contractual safeguards for international data transfers.
10. Modifications to This Policy
We may update this Privacy Policy from time to time to reflect operational, technical, or legal developments. Any revisions
will be published on this page with an updated “Last Updated” date at the top. We encourage users and clients to
review this policy periodically.
If you have questions, feedback, or concerns regarding this Privacy Policy or our security and data practices, please reach
out to: