Privacy Policy
Version 2026-01
What we collect
- Your work email address, and the name, job title, department and team you provide.
- Your registrations, bookings, saved sessions and merch reservations.
- Answers to the registration form for the event you sign up to.
- Technical records needed for security: hashed session tokens, hashed IP addresses, sign-in attempts.
- Pseudonymous product analytics: which screens are opened, with no free text and no cookies.
What we do not collect
No photographs, no date of birth, no home address, no identity documents, and no health data. Dietary preferences, if the organiser asks for them, are used to plan catering and deleted after the event.
How long we keep it
- Sign-in tokens: 10 minutes, then deleted.
- Sessions: 30 days after they expire.
- Sign-in attempts: 90 days.
- Analytics events: 90 days, then only aggregates remain.
- Registrations for past events: anonymised after 24 months.
- Audit records: 24 months.
Your rights
You can export your data or ask for your account to be deleted from Profile → Privacy and data. Deletion takes effect after 30 days, and you can cancel it at any point in that window. After deletion your historical registrations remain only as anonymous counts.
Who else processes it
Hosting, email delivery, error monitoring and content delivery are handled by processors in the EU under contract. Photo galleries are hosted by third parties and open on their own sites.