Eventas AS ('Eventas', 'we', 'us', or 'our') is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our event management platform, AI services, and associated products (collectively, the 'Services'). Please read this policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agreed to the practices described herein.
Information we collect
We collect information you provide directly to us, information collected automatically when you use our Services, and information from third-party sources.
Information you provide: This includes account registration details (name, email address, job title, organisation name), payment and billing information, event data you create or import, vendor and contact lists, communications you send us, and responses to surveys or support requests.
Information collected automatically: When you use our platform, we automatically collect device identifiers, IP addresses, browser type and version, operating system, referring URLs, pages visited, features used, timestamps, and session duration. We use cookies and similar tracking technologies as described in our Cookie Policy.
Information from third parties: We may receive information from identity providers (if you use single sign-on), payment processors, and integration partners such as WhatsApp Business, calendar services, and CRM tools you connect to your Eventas account.
How we use your data
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Eventas platform and all associated AI services, including Voice AI, WhatsApp AI, and Copilot features.
- To process transactions, manage subscriptions, and send related billing communications.
- To personalise your experience and deliver AI-driven insights and automations tailored to your events and preferences.
- To send transactional emails, product updates, security alerts, and support communications.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To comply with legal obligations, enforce our Terms of Service, and resolve disputes.
- To conduct internal analytics and research to improve our Services.
We do not sell your personal data to third parties. We do not use your event data or attendee data to train our AI models without your explicit consent.
Data sharing
We may share your information in the following limited circumstances:
Service providers: We share data with trusted sub-processors who assist in operating our platform, including cloud infrastructure providers, payment processors, email delivery services, and analytics tools. All sub-processors are contractually bound to handle data securely and only as instructed.
Business transfers: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Legal requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental authority, or when we believe in good faith that disclosure is necessary to protect our rights or the safety of others.
With your consent: We may share your information for other purposes with your explicit consent.
Data retention
We retain your personal data for as long as your account is active or as needed to provide you with our Services. If you close your account, we will retain your data for up to 90 days to allow for account recovery, after which we will delete or anonymise it, unless retention is required by law.
Certain types of data may be retained for longer periods where required for legal compliance, dispute resolution, or fraud prevention. Financial records, for example, may be retained for up to seven (7) years in accordance with applicable accounting regulations.
Anonymised or aggregated data that cannot reasonably be used to identify you may be retained indefinitely for analytical purposes.
Data security
We implement technical, organisational, and administrative safeguards designed to protect your data against unauthorised access, loss, misuse, alteration, or destruction. Our security measures include:
- Encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using AES-256.
- Role-based access controls and the principle of least privilege across all internal systems.
- Multi-factor authentication requirements for all internal staff accessing production systems.
- Regular penetration testing, vulnerability scanning, and third-party security audits.
- SOC 2 Type II compliance programme (in progress; certification target: Q3 2025).
- A dedicated security incident response plan with defined escalation procedures.
No system is completely secure. If you believe your account has been compromised, please contact us immediately at hello@eventas.io.
International data transfers
Eventas AS is headquartered in Oslo, Norway, and operates within the European Economic Area (EEA). Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Transfers to countries recognised by the European Commission as providing adequate data protection.
- Binding Corporate Rules where applicable.
For Professional and Enterprise customers, we offer dedicated regional data residency options in Sweden (EU), Virginia (US), UAE, Tokyo (Japan), and Sydney (Australia), ensuring your data never leaves your chosen region.
Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data, subject to certain exceptions.
- Right to restrict processing: Ask us to limit how we process your data in certain circumstances.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or direct marketing.
- Rights related to automated decision-making: Not to be subject to solely automated decisions that produce legal or similarly significant effects.
To exercise any of these rights, please contact us at hello@eventas.io. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Children's privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we learn that we have inadvertently collected data from a person under 18, we will take steps to delete such information as quickly as possible. If you believe we may have collected data from a child, please contact us at hello@eventas.io.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (using the address associated with your account) and by displaying a prominent notice within our platform at least 30 days before the changes take effect.
Your continued use of the Services after the effective date of the updated Privacy Policy constitutes your acceptance of the revised terms. We encourage you to review this policy periodically.
Contact us
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact our Data Protection Officer:
Eventas AS · Oslo, Norway · Org. nr.: 933 980 278 · For legal inquiries, contact hello@eventas.io