1. Identity of the Controller and Processor
The Eventy platform is operated by Solution Circle Company for Communications and Information Technology (شركة دائرة الحلول للاتصالات وتقنية المعلومات), Commercial Registration No. 1010487777, Kingdom of Saudi Arabia. You may contact us at [email protected].
When the platform is used to organize an event, the event organizer (the client) acts as the Controller of participants’ Personal Data, and the company operating Eventy acts as a Processor on its behalf under the applicable Data Processing Agreement.
The company acts as the Controller of Personal Data relating to event organizers’ accounts and the operational data required to provide, secure, and administer the platform.
2. Personal Data We Collect
We may collect and process the following categories of Personal Data:
Account data: Name, email address, mobile number, securely hashed password, and two-factor authentication settings.
Event registration data: Name, job title, organization, email address, mobile number, gender, country, city, and age, where the nature of the event requires such information.
Additional or Sensitive Data: National ID or residency number, passport number, and blood type. Such data is collected only where the event has a specific and documented purpose for doing so, the event organizer has approved its collection, and the applicable legal requirements have been satisfied.
Operational and technical data: Login records, Internet Protocol address, essential cookies, and audit logs relating to Personal Data processing activities.
Communications data and content: Data associated with invitations, registration confirmations, and reminders, including email, SMS, and WhatsApp messages, together with sending and delivery information. This data may be processed through contracted service providers.
Eventy does not store payment-card information directly on its servers.
3. Purposes and Lawful Bases of Processing
We process Personal Data only for the following specified purposes:
Creating accounts and providing event management, registration, badge issuance, access-management, and attendance services.
Sending registration confirmations, invitations, and reminders in accordance with the event organizer’s instructions.
Securing the platform, preventing fraud and misuse, and complying with the laws and regulations of the Kingdom of Saudi Arabia.
Improving the performance and reliability of the service to the extent necessary, without using Personal Data for undisclosed marketing purposes.
The lawful bases on which we rely depend on the nature of the processing and our role and may include:
Performing a contract to which the Data Subject is a party.
Complying with a legal obligation.
Pursuing a specific legitimate interest, such as protecting the platform and preventing misuse, provided that this does not prejudice the rights or interests of the Data Subject and is not relied upon for processing Sensitive Data.
Obtaining explicit consent where required by law, including when processing Sensitive Data.
Where we process participant data on behalf of an event organizer, the organizer, as the Controller, is responsible for identifying and communicating the appropriate lawful basis. We process such data in accordance with the organizer’s documented instructions.
Consent is not treated as an open-ended authorization to process Personal Data for unspecified future purposes.
4. Cookies
We use cookies that are necessary to operate user sessions, protect accounts, and maintain the security of the platform.
Optional analytics cookies or technologies are enabled only after they have been clearly disclosed, with users being given the ability to reject them or manage their preferences where legally required.
5. Disclosure and Sub-processors
We do not sell Personal Data. We disclose it only to the extent necessary for the purposes described in this Policy and only to:
The relevant event organizer and its authorized employees or representatives.
Sub-processors included in our approved sub-processor list, such as email, SMS, WhatsApp, hosting, cloud-storage, and artificial-intelligence service providers where such services are enabled for an event.
Competent authorities or other parties where disclosure is required by a legal obligation.
We require our sub-processors to process Personal Data only within the scope of their contracted services and subject to appropriate contractual and security safeguards.
6. Transfers Outside the Kingdom
Personal Data is not transferred or disclosed outside the Kingdom of Saudi Arabia unless the transfer is made for a lawful purpose and the requirements of the Personal Data Protection Law and its regulations have been satisfied.
Depending on the circumstances, these requirements may include:
Confirming that a lawful basis for the transfer exists.
Limiting the transfer to the minimum Personal Data necessary for its purpose.
Ensuring an adequate level of Personal Data protection.
Conducting a transfer risk assessment where required.
Implementing appropriate safeguards, such as Standard Contractual Clauses or other approved safeguards, where applicable.
This Policy does not constitute general consent or authorization to process Personal Data in any country or location without satisfying the applicable legal requirements.
7. Data Retention and Destruction
We retain Personal Data only for as long as necessary to fulfil the purpose for which it was collected or to meet applicable legal obligations, in accordance with our approved retention schedule.
For participant data, the default retention period is 12 months after the event ends, unless the applicable contract specifies a shorter or longer period for a legitimate and documented reason, or a different period is required by law.
We do not retain Personal Data indefinitely based on an undocumented discretionary decision. At the end of the applicable retention period, the data is securely destroyed or anonymized so that the Data Subject can no longer be reidentified.
8. Data-Subject Rights
Subject to the applicable legal limitations and exceptions, Data Subjects have the following rights under the Personal Data Protection Law:
The right to be informed about how their Personal Data is collected and processed and the lawful basis and purpose of such processing.
The right to access the Personal Data held by the Controller.
The right to request a copy of their Personal Data in a readable and clear format and, where technically feasible, in a commonly used electronic format.
The right to request the correction, completion, or updating of their Personal Data.
The right to request the destruction of their Personal Data in the circumstances provided by law.
The right to withdraw consent where consent is the lawful basis for processing, without affecting the lawfulness of processing carried out before consent was withdrawn.
A Data Subject may also request the temporary restriction of processing where the accuracy of their Personal Data is disputed, for the period required to verify its accuracy and subject to the applicable regulatory requirements.
Requests may be submitted to [email protected] or through the relevant event organizer. Where the event organizer is the Controller, we may refer the request to the organizer and assist it in responding.
We verify the identity of the person submitting a request before fulfilling it and respond within the legally prescribed period.
If a Data Subject is dissatisfied with the handling of a request or complaint, they may submit a complaint to the Saudi Data & AI Authority (SDAIA) through its official channels, including the National Data Governance Platform.
9. Sensitive Data and Minors
National ID or residency numbers, passport numbers, and blood-type information are collected only for a specific and documented event purpose, following approval by the event organizer and satisfaction of the applicable lawful basis and regulatory requirements.
The platform is not independently directed at minors or persons lacking full legal capacity. Where the nature of an event requires processing their Personal Data, such processing will be carried out with the consent of a parent, guardian, or legal representative where required.
10. Data Security and Personal Data Breaches
We implement appropriate technical and organizational measures to protect Personal Data. Depending on the nature of the processing, these measures include:
Encryption of data in transit.
Access management based on the principle of least privilege.
Logging of access and relevant activities.
Secure management of secrets and access keys.
Periodic review and updating of security controls.
Where we act as a Controller, we will notify the Competent Authority within no more than 72 hours after becoming aware of a Personal Data Breach if the incident may cause harm to the Personal Data or the Data Subject, or conflict with the Data Subject’s rights or interests. We will also notify affected Data Subjects where required by law.
Where we act as a Processor, we will notify the relevant event organizer without undue delay and cooperate with it in investigating the incident and fulfilling its legal obligations.
11. Updates to This Policy
Any material amendment to this Policy will be published with an updated version number and effective date.
We will not expand the purposes for which Personal Data is processed without an appropriate lawful basis and clear notice to Data Subjects where required.