This Policy explains what data EasyConfer may process, why it is needed, and what a user can do about their own data.
EasyConfer is a free service for event pages, attendee registration, the conference programme, introductions, chats and meetings between attendees.
Using any particular feature is voluntary. Where a feature needs certain data to work, it may be unavailable without it.
Who processes the data
The EasyConfer platform is run by the owner and administrator of the EasyConfer project.
You can get in touch about the service or about the processing of personal data through the support form on the site; for questions about personal data, choose the privacy category.
Roles differ depending on the operation:
- EasyConfer decides the processing needed for the account, sign-in, security and the technical operation of the platform;
- the organizer of an event decides what data they collect through the registration form, what mailings they send to attendees, and for what purposes they use that data;
- EasyConfer supplies the organizer with the technical means for that processing;
- the attendee controls the data and the visibility settings available to them inside the service.
EasyConfer is not the organizer of conferences, does not sell tickets, and does not decide who is admitted to a particular event.
What data may be processed
Depending on the features used, the following data may be processed.
Account and sign-in:
- name;
- email address;
- the data needed to confirm that address;
- authorization data and active sessions;
- language and interface settings;
- a profile image, where the chosen sign-in method supplied one.
Passwords are not stored in the clear.
Sign-in through an external provider. If you choose such a sign-in, the service receives only what authorization and creating or matching an account require: a user identifier, an email address, a name and a profile image where available. No access is requested to the contents of your mail, files, calendar or contacts.
Events and registration:
- the attendee's name and contact details;
- answers to the registration form's fields;
- the registration and the state of participation;
- details of the event, the programme, the speakers, the venue and the sponsors;
- the ticket, the QR code and the record of admission to the event;
- data the organizer adds while setting the event up.
What the registration form asks for is decided by the organizer of the event.
Introductions, chat and meetings:
- profile visibility settings;
- chosen talks and busy intervals;
- connection requests;
- conversations inside the event;
- meeting proposals and their state.
Mail and support:
- the recipient's address;
- the contents of a service email;
- the technical delivery status;
- a record of opting out of optional mailings;
- support requests and the answers to them.
Technical data, for security and for the platform to work:
- IP address;
- technical details of the HTTP request;
- error logs;
- records of sign-in attempts;
- rate-limiting counters;
- records of administrative actions.
What the data is used for
Data is used only as far as the service and the chosen features require, in particular:
- to create and maintain an account;
- for sign-in and security;
- to register for events;
- to issue tickets and check admission;
- to run the event's programme;
- for introductions, chats and meetings;
- to send service notifications;
- for organizers to work with the attendees of their own events;
- to answer support requests;
- to prevent abuse and technical attacks;
- to meet the requirements of applicable law.
EasyConfer does not sell personal data and does not pass it to third parties for anybody else's advertising.
EasyConfer does not use attendees' data to build advertising profiles.
On what basis
Data is processed where this is necessary to provide the features the user has chosen, to register for an event, to keep the service secure, to meet an event organizer's obligations, or to comply with the law.
For certain optional features the basis is the user's consent. Such consent is withdrawn where the interface provides for it: optional mailings through the opt-out link in the email itself, and catalogue visibility and the sharing of contacts through the switches in the profile. Consents ticked in a registration form for an event stand for as long as that registration's data is kept; there is no separate control to untick them — to stop the processing, an attendee can ask the organizer to cancel the registration or close their account, which deletes their data with it.
Where the processing of attendees' data is decided by the organizer of an event, it is the organizer who ensures there is a proper legal basis for it.
The event organizer's role
The organizer decides for themselves:
- what fields the registration form needs;
- what they ask attendees for;
- what consents and notices they use;
- what messages and mailings they send;
- for what purposes they use the data they have collected.
The organizer must use attendees' data lawfully and only for the purposes they stated.
EasyConfer is responsible for the operation of its own technical systems and for processing within its own role. The organizer is responsible for their own decisions and actions involving attendees’ data.
Where a user's request concerns data a particular organizer controls, EasyConfer may pass that request to the organizer or help the user reach them.
Who the data may be passed to
Access to data is given only as far as the feature in question requires:
- to the organizer of an event and their team, within their access rights;
- to other attendees, where the visibility settings and the user's own actions provide for it;
- to providers of server and network infrastructure;
- to providers of outgoing mail services;
- to a sign-in provider, where the user chooses that way of signing in;
- to map and geocoding services, where a user or an organizer uses the map and the address lookup;
- to the YouTube video service, where a visitor opens a video guide on the home page themselves;
- to a state authority, where disclosure is required by law and the request is a proper one.
Providers receive only the amount of data the technical operation in question requires.
Which providers are used may change as the project develops. The current list is available on request through the support form.
Where the data may be processed
EasyConfer's main server and its file storage are in a data centre within the European Union.
Particular technical providers may process data in other countries. Where data is technically transferred outside the European Economic Area, whatever contractual, technical and organizational safeguards are available for that provider are applied.
What may be public
Only data meant for the event's public page, or data the user has allowed to be shown, may be public.
An organizer may publish:
- the event's name and description;
- the programme;
- details of the speakers;
- details of the sponsors;
- details of the venue;
- images and other public content.
An attendee's profile, email address and phone number do not become public automatically: they are shown to other attendees only by that attendee's own decision and within their visibility settings.
Do not put anything in a public field that you are not ready to make public.
How long data is kept
Data is kept as long as the feature in question, the account, the running of the event, the security of the service and the requirements of law make necessary.
Where the interface specifies a retention period, that period applies.
After an account is closed or data is deleted, some of it may remain for a limited time:
- in security and audit logs;
- in backups;
- in anonymized form;
- where it is needed to resolve a dispute, to investigate an incident, or to meet the requirements of law.
Backups are not used as working storage and are overwritten in the ordinary technical backup cycle.
EasyConfer does not promise a specific timeframe for every record to disappear from all technical copies, unless that timeframe is set by law or is stated explicitly for a particular feature.
The user's rights
Within the limits of applicable law, a user may ask:
- whether their data is being processed;
- for access to their data;
- for inaccurate data to be corrected;
- for data to be deleted where there is no lawful ground to keep it;
- to withdraw a consent where it is given and taken back in the interface (section 4);
- to restrict particular kinds of processing, where the law provides for it;
- for a copy of their data in an accessible format, where that is technically and legally applicable;
- to object to processing in the cases the law provides for.
Such requests go through the EasyConfer support form under the privacy category.
To protect the user, EasyConfer may ask for reasonable proof that the request came from the owner of the account or the email address in question.
Cookies and local settings
EasyConfer may use its own cookies and the browser's local storage to:
- keep a session;
- complete a sign-in safely;
- remember the language and the appearance;
- hold technical interface settings.
EasyConfer does not use third-party advertising identifiers and does not set advertising cookies on behalf of ad networks.
The video guides on the home page are embedded from YouTube in its no-cookie mode: while a video's card is closed, the page does not contact YouTube. Once a video is opened and played, YouTube may use its own cookies under its own rules.
If optional analytics or advertising technologies appear in future, the rules for them will be described separately, and consent will be asked for where the law requires it.
Security
EasyConfer applies reasonable technical and organizational safeguards suited to the nature of the service: separation of access rights, an encrypted connection, rate limiting, security logs and backups.
No internet service can guarantee absolute security.
Keep your sign-in links, ticket QR codes and account details to yourself, and report anything suspicious through the support form.
Minors
Independent use of an EasyConfer account is intended for adults.
Where an organizer collects the data of minors, the organizer is responsible for having a lawful basis and any required notices and consents.
If EasyConfer learns that a minor's data is being processed in evident breach, the service may restrict that processing or require the organizer to act.
A free service, and voluntary support
EasyConfer is provided to users free of charge and takes no payment for access to the platform's features.
The site may offer a way to support the project voluntarily, by transferring cryptocurrency to a published wallet address. EasyConfer does not take such a transfer inside the platform, does not hold private keys, does not confirm the transaction, does not track who sent it, and does not tie a transfer to an account, an event, a plan or any additional capability.
Transactions on a public blockchain may be visible regardless of EasyConfer. The wallet, the network and how public the transfer is are the sender's own choice.
If paid features appear in future, the rules for processing payment data will be described separately before such features are used.
Changes to this Policy, and contact
This Policy may be updated when EasyConfer's features, the infrastructure it uses, or the requirements of law change. The current version is published on this page.
Where a change materially affects how users' data is processed, EasyConfer will try to give notice through the service's interface or by email, where that is reasonable and technically possible.
For questions about privacy, deletion of data or the working of the service, use the EasyConfer support form under the privacy category.
A user who believes their rights have been breached may also apply to the competent state authority or to a court, in the manner provided by the applicable law of Ukraine.