Eventact (“Eventact,” “we,” “us,” or “our”) provides an online event management, ticketing, and attendee communication platform (the “Platform” or “Services”). This Privacy Policy explains how we collect, use, disclose, and secure personal information when you access or interact with our websites (including eventact.com), mobile or web applications, communications interfaces, and related software tools.

Please note the critical distinction regarding how personal data is governed across our Platform:

For Event Participants / Attendees: The event organizer (“Organizer”) hosting or managing the event is the Data Controller (or “Business”) of your personal data. Eventact processes your personal data strictly on behalf of, and under the direct operational instructions of, the Organizer as a Data Processor (or “Service Provider”). If you have questions about an Organizer’s data practices or wish to exercise statutory data protection rights regarding event registration or event communication records, please direct your request directly to the Organizer.

For Organizers and General Website Visitors: Eventact acts as the Data Controller regarding direct customer accounts, billing details, platform administrative access, and technical data collected through direct interactions with our corporate websites.

1. Information We Collect

A. Information Processed on Behalf of Organizers (Participant Data)

When you register for an event, check in, interact with an event website or app, or communicate with an Organizer via our tools, we process data collected on the Organizer’s behalf:

B. Technical and Diagnostic Data (Collected Automatically)

When you access our Platform or browse our websites, our servers automatically log technical diagnostics:

C. Organizer Account Data

If you establish an Eventact administrator account or communicate with our sales and technical support teams:

2. How We Use Information

We process personal data solely for legitimate business purposes and according to the instructions of our customers:

3. Sharing and Disclosure of Information

Eventact does not sell, rent, or trade personal data to third parties. We share or disclose information only under the following conditions:

4. Cookies, Web Beacons, and Tracking Technologies

For additional information on our use of cookies, please consult our separate Cookie Policy.

5. Data Retention

6. Information Security

We maintain industry-standard administrative, physical, and technical safeguards designed to protect personal data against accidental loss, unauthorized access, destruction, alteration, or disclosure. Protections include encrypted data transmission (HTTPS/TLS), firewalls, role-based access restrictions, and periodic security evaluations. While we implement robust defenses, no internet transmission or digital storage architecture can be guaranteed 100% secure. If you suspect an unauthorized compromise of your account credentials, please notify our team immediately.

7. Children’s Privacy

The Platform is designed and intended solely for commercial, professional, and adult organizational use. We do not knowingly collect personal data directly from children under 16 years of age. Where an Organizer manages an event involving minors, the Organizer bears full responsibility for securing all necessary parental or guardian consents mandated by applicable privacy regulations. If we determine that personal information from an individual under 16 was collected without valid legal consent, we will delete that data expeditiously.

8. Notice for California Residents (CCPA / CPRA)

This section applies to California residents pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”).

For inquiries regarding personal data for which Eventact serves as the direct Business/Controller, contact us at privacy@eventact.com.

9. European & UK Data Protection (GDPR / UK GDPR)

For event participants and clients located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please refer to our dedicated Eventact GDPR Compliance & Data Transfers Page. That page details our lawful bases for data processing, data subject rights (access, correction, erasure, portability, restriction, and objection), our Data Processing Addendum (DPA), and standard contractual safeguards for international data transfers.

10. Modifications to This Policy

We may update this Privacy Policy from time to time to reflect operational, technical, or legal developments. Any revisions will be published on this page with an updated “Last Updated” date at the top. We encourage users and clients to review this policy periodically.

11. Contact Information

If you have questions, feedback, or concerns regarding this Privacy Policy or our security and data practices, please reach out to: