Privacy Policy
Last updated
Template notice: this page is a general template and is not legal advice. It will be replaced by the final text reviewed by our legal counsel.
This Privacy Policy explains how Zufest ("Zufest", "we", "us") processes personal data when you use our websites, applications and services, and the rights you have.
1. Our role
We are the controller for personal data we process to run our websites and your Zufest account. When you register for an event, the event's organiser decides how your registration data is used; for that data we act on the organiser's behalf, and the organiser's own privacy notice also applies.
2. Data we collect
- Account data: your name, email address, password (stored only as a secure hash) and profile details you choose to add.
- Registration and order data: tickets, registrant details and payment status. Card details are handled by the payment provider, not stored by us.
- Event activity: check-ins, agenda choices, questions, votes, messages, connections and posts you make in an event.
- Contact form messages: the details you send us, with your IP address and browser type to protect against abuse.
- Technical data: logs, device and browser information needed to keep the Service secure and working.
3. Why we use it
- To provide the Service and the features you use (performance of a contract).
- To keep the Service secure, prevent fraud and abuse, and fix problems (legitimate interests).
- To answer your messages and send service emails (contract and legitimate interests).
- To meet legal obligations, such as accounting and tax rules.
- For optional communications, only with your consent where the law requires it.
4. Who can see your data
Organisers of events you register for see your registration. Other attendees see only what your privacy settings allow; your email address and phone number are shared only on a business card you choose to share. We use service providers (such as hosting, email and payment providers) under contracts that protect your data. We do not sell personal data.
5. International transfers
Where data is transferred outside your country, we use appropriate safeguards such as standard contractual clauses.
6. How long we keep it
We keep personal data for as long as your account is active or as needed to provide the Service, then delete or anonymise it unless the law requires us to keep it longer.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your data, to object to or restrict processing, and to withdraw consent. You can also complain to your data protection authority. To exercise your rights, contact us through the contact page.
8. Security
We protect data with measures such as encryption in transit, hashed passwords, access controls and short-lived access links for protected content.
9. Changes
We will post any changes on this page and update the "Last updated" date above. If a change is significant we will tell you in advance.
Questions about this page? Contact us.