LiveEvent

Privacy policy

How LiveEvent processes the data of organisers who use the platform. Data about the participants in an event belongs to the organiser: their notice is published on their event's site.

Two roles, not to be confused

For organiser accounts - their name, email address, organisation and use of the service - LiveEvent is the controller and this policy applies. For the data of people registered to an event, LiveEvent is only a processor: the organiser decides what is collected and why, and it is to them that those people write. This distinction is not a formality: it determines who to contact.

What the platform collects about an organiser

The account: an email address and a name. The organisation: its name, its identifier, and the identity it declares to sign its emails. Usage: what is needed to run and bill the service. No behavioural tracking, no advertising trackers, no profiling.

Why, and on what basis

To perform the contract between us: providing the service, administering it, answering support requests. To meet legal obligations, notably accounting ones. Nothing else - one customer's data is never used to improve a product sold to another.

How long

The account and its content for as long as the service is used, then for the agreed retrieval period at the end of the contract. Technical email-sending records for thirteen months. Detailed traffic measurements for thirteen months. Accounting records for as long as the law requires.

Who else has access

The technical providers listed on the subprocessors page, each for what they keep running, each bound by a contract forbidding them from using this data for their own purposes. No resale, no transfer, no sharing for advertising.

Outside the European Union

Some of these providers are established in the United States. Transfers rely on the European Commission's standard contractual clauses or on the applicable data protection framework. The subprocessors page states, for each of them, what is known about their location.

Your rights

Access, rectification, erasure, restriction, objection and portability can be exercised with the contact given in the legal notice. An answer is due within a month. In case of disagreement, the data protection authority in your country can be contacted.

Security

Each organisation is isolated from the others at three levels in the database, and that isolation is checked on every request, not only at sign-in. Passwords are never stored in clear, model provider API keys are encrypted, and sharing tokens are randomly generated, expirable and revocable.