Legal
Privacy Statement
Last updated: 20 August 2026
This Privacy Statement explains how Bizcon RSVP ("Bizcon", "we", "us") processes personal information when you use bizconrsvp.com and related services. It is written for organisation customers, their staff, invitees, and attendees of professional summits and conferences hosted on the Platform.
It complements — and does not replace — privacy notices that an event organisation may provide to its guests.
1. Roles: who is responsible for your data
- Event organisations generally act as the controller of invitee and attendee data for their events (who is invited, registration answers, categories, communications, and event-day records).
- Bizcon provides the Platform as a multi-tenant service provider / processor for that organisation data, and as a controller for account, billing contact, product analytics, security, and support data we need to operate the service.
If you are an invitee or attendee, questions about why you were invited or what an organiser collected should usually go to that organisation first. You may also contact us at the address below.
2. Whose data we process
- Organisation owners, admins, and event staff
- Invitees and registered attendees (delegates, speakers, sponsors, exhibitors, VIPs, media, government or official guests, investors, and other categories defined by the organiser)
- People who request a demo or contact us via our website
- Website visitors (limited technical data)
3. Categories of personal data
Depending on your role and the event configuration, we may process:
- Identity and contact — name, email, phone, company, job title, country, category.
- Account data — authentication identifiers via our identity provider (Clerk), organisation membership, and event roles.
- Invitation and registration — invitation status and timestamps, registration form answers, dietary or accessibility information if the organiser requests it, application submissions where public apply is enabled.
- Networking profile — interests, looking-for / offering, industries, geographies, directory visibility, and matchmaking preferences.
- Meetings and calendar — meeting requests, scheduled times, rooms, and calendar connection tokens when you connect Google Calendar (or other providers when available) to sync meeting invites.
- Event operations — session registrations, QR / check-in status, communications history, exports performed by authorised staff.
- AI matchmaking — structured profile fields and optional AI-generated insights when both the event and the relevant attendees have opted in.
- Technical and security — IP address (e.g. audit / rate limiting), device or browser metadata, logs needed to secure the service, and bot-protection signals (e.g. Turnstile) on public flows.
We aim to collect only what is necessary for the stated event and platform purposes.
4. How we use personal data
- Provide and secure multi-tenant event workspaces
- Send and track invitations, registration, reminders, and transactional emails on behalf of organisations
- Operate attendee portals, profiles, privacy controls, directories, meetings, agenda, and check-in
- Run optional matchmaking and AI insights where enabled and opted in
- Sync accepted meetings to connected calendars
- Produce organiser reports and exports for authorised staff
- Maintain audit logs for invite, register, check-in, admin, and export actions
- Improve reliability, prevent abuse, and respond to support or demo requests
- Comply with legal obligations
5. Legal bases
Where data protection law requires a legal basis (for example GDPR / UK GDPR / POPIA concepts), we rely on: performance of a contract (providing the Platform or completing registration); legitimate interests (securing the service, product improvement, fraud prevention) balanced against your rights; consent where required (certain marketing, optional AI insights, calendar OAuth grants); and legal obligation where applicable. Organisations are responsible for their own basis when they invite and process guest data.
6. Sharing and processors
We do not sell personal data. We share data with:
- The host organisation and its authorised staff for the relevant event
- Other attendees only as permitted by privacy settings and feature design (e.g. directory fields you allow)
- Service providers that host or power the Platform (e.g. cloud hosting and database, email delivery, authentication, bot protection, object storage, optional AI providers, calendar APIs)
- Authorities when required by law or to protect rights and safety
Tenant isolation is enforced so one organisation cannot access another organisation's events, guests, or reports through the Platform's normal authorisation model.
7. International transfers
Infrastructure and providers may process data in regions outside your country. Where required, we use appropriate safeguards (such as standard contractual clauses or equivalent measures) with processors.
8. Retention
We retain personal data for as long as needed to provide the service to the organisation, comply with law, resolve disputes, and maintain security records. Organisations may cancel registrations or manage event data according to product tools. Account and audit records may be kept longer where necessary for security and compliance.
9. Security
We apply layered controls appropriate to an event platform holding personal and commercially sensitive information, including authentication, organisation- and event-scoped authorisation, hashed invitation / QR tokens, rate limiting on sensitive flows, encryption of certain secrets (e.g. calendar tokens), and audit logging. No method of transmission or storage is perfectly secure; please protect invitation links and account credentials.
10. Your choices and rights
- Attendees can manage profile and privacy settings (directory visibility, matchmaking, AI insights, email/phone visibility) in the attendee portal where available.
- You may disconnect calendar integrations from the Calendar page.
- Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability or complaint to a supervisory authority.
To exercise rights relating to an event's guest list, contact the organising organisation and/or hello@bizconrsvp.com. We may need to verify identity and may redirect attendee requests to the relevant organisation when they are the controller.
11. Children
Bizcon is designed for professional events and is not directed at children. We do not knowingly collect personal data from children under 16 (or higher age where required locally) for Platform accounts. If you believe we have, contact us to delete it.
12. Cookies and similar technologies
We use cookies and similar technologies necessary for authentication, session security, and core product function. Bot-protection widgets on public invite/register flows may set their own cookies. Optional analytics cookies, if introduced, will be described and controlled as required by law.
13. Changes
We may update this Privacy Statement as the product or law evolves. The "Last updated" date at the top will change when we do. Significant changes may also be communicated through the product or by email to organisation contacts where appropriate.
14. Contact
Privacy enquiries: hello@bizconrsvp.com.
Related: Terms of Service.