Legal Center

AttendOS Privacy Policy

This Policy explains how AttendOS collects, uses, shares, protects and retains personal information.

Effective
August 6, 2026
Last updated
August 6, 2026
Version
1.0

1. Scope

This Policy applies when you:

  • access the AttendOS website or application;
  • create or manage an account;
  • create, manage, or participate in an event;
  • register for an event;
  • receive emails, QR codes, or notifications;
  • use check-in;
  • contact support;
  • interact with services linked to this Policy.

An organizer may provide a separate privacy notice regarding how they use attendee data outside of AttendOS services.

2. Who We Are and Our Data Roles

AttendOS is operated by:

AttendOS

privacy@attendos.net

In some activities, AttendOS determines the purposes and means of data processing.

In other activities, particularly when processing attendee data under the instructions of an organizer, AttendOS may act as a service provider or data processor for the organizer.

The specific role depends on the processing activity and applicable law.

3. Information We Collect

A. Account and Organization Information

  • name;
  • email;
  • phone number if provided;
  • profile picture;
  • organization name;
  • job title;
  • workspace;
  • roles and permissions;
  • account verification information.

B. Event Information

  • event name and description;
  • date, time, timezone;
  • location;
  • images;
  • forms;
  • ticket types;
  • email content;
  • check-in settings;
  • operational information.

C. Attendee Information

Depending on the form configured by the organizer:

  • name;
  • email;
  • phone number;
  • organization;
  • registration answers;
  • support needs;
  • group or family information;
  • emergency contact information;
  • accommodation or meal choices;
  • approval status;
  • QR code;
  • check-in time and location.

Organizers should not request sensitive data when not strictly necessary and without an appropriate basis.

D. Transaction Information

  • purchased plan;
  • amount;
  • currency;
  • invoice;
  • payment status;
  • transaction ID;
  • tax information.

Payment providers may process full card information. AttendOS only receives information necessary for transaction confirmation and management.

E. Device and Usage Information

  • IP address;
  • device type;
  • browser;
  • operating system;
  • access time;
  • pages and features used;
  • error logs;
  • session identifiers;
  • language;
  • timezone;
  • performance and security data.

F. Support Information

  • request content;
  • email or support conversation;
  • attachments;
  • feedback;
  • information necessary to investigate issues.

G. Images and Uploaded Content

  • event artwork;
  • logo;
  • speaker images;
  • images embedded in content;
  • necessary technical metadata;
  • safety moderation results;
  • edited versions.

4. Sources of Information

We receive information:

  • directly from you;
  • from the organizer;
  • from the workspace administrator;
  • from attendees;
  • automatically from devices;
  • from integrations you authorize;
  • from payment providers;
  • from fraud prevention or security services;
  • from public sources when permitted by law.

5. How We Use Information

AttendOS uses information to:

  • create and manage accounts;
  • provide the event builder;
  • operate registration;
  • generate and send QR codes;
  • process approvals or waitlists;
  • operate check-in;
  • send emails and notifications;
  • provide reports;
  • process payments;
  • provide customer support;
  • protect safety and security;
  • prevent fraud and abuse;
  • moderate content;
  • troubleshoot errors;
  • measure performance;
  • improve products;
  • comply with legal obligations;
  • enforce policies;
  • resolve disputes.

6. Legal Bases

Where required by law to identify a legal basis for processing, AttendOS relies on one or more of the following bases:

  • performance of a contract;
  • consent;
  • legitimate interests not overridden by individual rights;
  • legal obligation;
  • protection of vital interests;
  • other legally permissible basis.

The Organizer is responsible for determining the appropriate basis for additional data fields and purposes they establish.

7. Cookies and Similar Technologies

AttendOS may use:

  • essential cookies;
  • local storage;
  • session identifiers;
  • security technologies;
  • product analytics;
  • measurement tools;
  • personalisation preferences.

Non-essential cookies are used only where there is an appropriate legal basis and choice under applicable law.

Cookie settings:

/legal#cookies

8. How We Share Information

AttendOS may share information with:

  • event organizers;
  • authorized workspace members;
  • hosting providers;
  • email providers;
  • payment providers;
  • analytics services;
  • support providers;
  • security and fraud prevention providers;
  • image moderation providers;
  • approved AI services;
  • legal, audit, or insurance advisors;
  • competent authorities when required by law;
  • transferees in legitimate corporate transactions.

Providers shall only receive necessary data and shall be subject to appropriate obligations regarding confidentiality, privacy, and processing purpose.

Subprocessor list:

9. Organizers and Attendees

When you register for an event, your information is provided to the organizer and workspace members authorized by them.

Organizers may use the information to:

  • manage registrations;
  • communicate about the event;
  • check-in attendees;
  • provide support;
  • perform announced activities.

The organizer's use of data outside AttendOS may be subject to their own policies. AttendOS does not fully control such independent activities.

10. Artificial Intelligence

When a user actively uses an AI function, selected data may be sent to an approved AI provider to generate results.

AttendOS must:

  • only send necessary data;
  • not use private customer data to train general models without explicit permission;
  • display to the user when a function uses AI;
  • apply appropriate data protection settings and contracts;
  • not automatically publish results without confirmation, except for automation actively set up by the user.

Do not input sensitive data into AI when unnecessary.

11. Image Moderation

Uploaded images may be stored privately during safety checks.

AttendOS may process:

  • images;
  • fingerprints or hashes;
  • classification results;
  • moderation status;
  • model versions;
  • complaint information.

Only images with an approved status will be publicly displayed.

Automated results may be escalated to manual review where appropriate. Access to restricted content is limited by role and safety procedures.

12. Sale or Sharing for Advertising

Insert one legally verified statement based on actual AttendOS behavior.

If AttendOS does not sell personal information or share it for cross-context behavioral advertising, use:

AttendOS does not sell personal information for monetary consideration. AttendOS also does not share personal information for cross-context behavioral advertising, unless explicitly notified and provided with a choice as required by applicable law.

Do not publish this statement unless technically verified across:

  • advertising SDKs;
  • analytics;
  • pixels;
  • cookie providers;
  • data partnerships.

If actual behavior triggers opt-out obligations, provide the required:

  • Do Not Sell or Share My Personal Information;
  • opt-out preference signal processing;
  • notice at collection;
  • request workflow.

13. International Data Transfers

AttendOS and its providers may process data in the United States and other countries.

Where required by law, AttendOS uses appropriate data transfer mechanisms, contractual measures, and supplementary safeguards.

Information regarding applicable mechanisms can be requested via:

privacy@attendos.net

14. Data Retention

AttendOS retains information for as long as necessary to:

  • provide services;
  • maintain events;
  • fulfill user choices;
  • perform contractual obligations;
  • ensure security and prevent fraud;
  • resolve disputes;
  • comply with legal requirements;
  • maintain cyclical backups.

The specific duration depends on the type of data, account status, organizer instructions, and legal obligations.

The phrase “we retain data for as long as we deem fit” must not be used.

Publish the actual retention schedule at:

15. Security

AttendOS implements administrative, technical, and organizational measures designed to protect information, including where appropriate:

  • encryption in transit;
  • encryption at rest;
  • access controls;
  • authorization;
  • security logs;
  • backups;
  • vulnerability management;
  • authentication;
  • incident monitoring;
  • vendor management;
  • incident response plans.

No system is completely secure.

Users are also responsible for protecting their accounts and devices.

16. Data Incidents

If an incident affecting personal information occurs, AttendOS will:

  • investigate;
  • mitigate the impact;
  • implement remedial measures;
  • notify authorities or individuals when required by law;
  • maintain appropriate records.

AttendOS does not promise to notify of every incident if not required by law and if the incident does not affect personal data.

17. Privacy Rights and Choices

Depending on your place of residence and applicable law, you may have the right to:

  • know or access data;
  • rectify data;
  • erase data;
  • receive a portable copy;
  • object to or restrict processing;
  • withdraw consent;
  • opt out of sale or sharing;
  • opt out of targeted advertising;
  • request review of automated decisions under applicable law;
  • not be discriminated against for exercising rights;
  • appeal decisions regarding privacy requests.

Submit requests at:

mailto:privacy@attendos.net

AttendOS may need to verify identity and authority before processing.

18. Organizer-Controlled Requests

If AttendOS processes data under the Organizer's instructions, AttendOS may forward attendee requests to the Organizer or assist the Organizer in fulfilling the request.

Attendees should contact the Organizer directly when questions relate to the purpose or data fields determined by the Organizer.

19. Children’s Privacy

AttendOS is not designed for children under the applicable legal age to create organizational accounts or provide data without the necessary consent.

Family or children's events may use AttendOS. In such cases, the organizer is responsible for establishing appropriate consent and protection procedures.

If you discover that children's data has been improperly collected, please contact:

privacy@attendos.net

20. Sensitive Information

Organizers should only collect sensitive information when:

  • strictly necessary;
  • clearly notified;
  • there is an appropriate legal basis;
  • access is restricted;
  • retention periods are established;
  • enhanced protective measures are implemented.

AttendOS may restrict certain data fields or require additional confirmation.

21. Notices at Collection

Where required by law, AttendOS must provide a short notice at the point of collection, describing:

  • the categories of data;
  • the purposes;
  • the retention period or criteria;
  • a link to this Policy;
  • related choices.

Do not rely solely on a long Policy page if the law requires notice at the point of collection.

22. Do Not Track and Opt-Out Signals

AttendOS must accurately describe how it processes:

  • Do Not Track;
  • Global Privacy Control;
  • legally recognized opt-out signals.

Do not claim support unless it is technically implemented.

When legally required, recognized opt-out preference signals must be honored.

23. Third-Party Links and Services

AttendOS may contain third-party links or integrations.

This policy does not govern the independent activities of third parties when they determine their own processing purposes.

You should review the policies of the relevant service.

24. Changes to This Policy

AttendOS may update this Policy.

The update date and version are displayed at the top of the document.

For material changes, AttendOS will provide notice through appropriate methods. Where law requires new consent, AttendOS will request confirmation.

25. Appeals

If you are not satisfied with how your privacy request has been handled, you may:

  • request AttendOS to review it;
  • contact the competent data protection authority;
  • use other remedies as provided by applicable law.

mailto:legal@attendos.net

26. Contact

Privacy Department:

privacy@attendos.net

Address:

Change history

  • Version 1.0 · August 6, 2026 · First published version.