Confidentiality & data protection.
How Eventtia collects, processes, and protects your personal data — written once, applied across every Eventtia entity, in line with GDPR, CCPA, and local data-protection law.
The full policy. Cleanly mapped.
A quick map of the policy before you dive in. Each cluster collects the sections that belong together — jump to the one you need.
Which Eventtia entity is responsible for your data, and which jurisdiction's law applies.
What we collect, why we collect it, and the legal basis for each purpose.
Who can access your data, how AI assistants connected through our MCP server use it, where it is hosted, and how long we keep it.
How children's data is handled, and what cookies the Application uses.
The rights you can exercise, our security commitments, and how to reach us.
Privacy policy, in full.
Version 1.0 · Effective 1 September 2026
Protecting your privacy is very important for Eventtia. Below you will find some useful information about the policy of Eventtia and its website www.eventtia.com (hereinafter the “Website”) relating to the processing of your personal data.
1. Data Controllers & Applicable Law
Eventtia operates through different entities. The entity responsible and the applicable law depend on your location:
US law, including CCPA in California.
EU General Data Protection Regulation (GDPR).
Colombian Habeas Data Law.
Mexican Federal Law on Protection of Personal Data.
2. What Personal Data We Collect
- a. Connection data — IP address, device info, logs, cookies.
- b. Identification data — name, email, phone, company, account info.
- c. Event data — registration info, participation, feedback, tasks.
- d. Children’s data — only when provided by event organizers. Children do not use Eventtia directly (see Section 8 below).
3. Purposes & Legal Bases
- Service delivery — managing your account and enabling event participation (contract).
- Administration & communication — updates, security alerts (contract + legitimate interest).
- Improvement — analyzing usage to improve UX (legitimate interest).
- Marketing — emails, cookies, personalized ads (consent).
- Event processing — acting as processor on behalf of organizers (contract).
4. Access & Sharing
- Eventtia staff (only as needed).
- Event organizers (controllers for their event data).
- Service providers (hosting, payment, communications).
- Legal authorities if required.
5. AI Assistants & MCP Server
When you connect an AI assistant to Eventtia through our MCP server (for example via a ChatGPT or Claude connector, or a custom agent), Eventtia processes the data needed to perform the action you request in your authorized Eventtia account. The MCP server sits on top of the Eventtia REST API and inherits the scopes and permissions of the API token you use — an assistant can only do what a human user with the same token could do.
- Event and attendee records — names, email addresses, company, attendee type, sessions, check-ins and payment status.
- Sensitive or high-risk fields, only when you explicitly request them for a specific registration or compliance workflow — date of birth, identity-document number, postal address, phone number, alternative email address and selected custom registration fields. These fields are never returned by default.
Purpose. We use this information solely to manage event registrations, attendee records, payments, sessions, check-ins and related event operations, acting as processor on behalf of the event organizer (see Section 3). We never use it for advertising and we never sell it.
Who receives it. Data is shared with the AI assistant provider you choose (for example OpenAI for ChatGPT, Anthropic for Claude, or the operator of a custom agent) only when you invoke the assistant, and its handling by that provider is governed by the provider’s own privacy terms. It is also shared with the validated sub-processors that process data on Eventtia’s behalf, only as necessary to provide the service. International transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards, as described in Section 6.
Retention and your rights. MCP request logs and Eventtia account records are retained according to Section 7 and securely deleted when no longer needed. You may exercise your privacy rights, including access, correction and deletion (Section 9), by contacting help@eventtia.com. You can revoke an assistant’s access at any time by deleting its API token in the API settings of your Eventtia Connect account.
Restricted data. Do not use AI assistants or the MCP server to submit health information, biometric data, payment-card data, national ID or Social Security numbers, or other restricted data unless Eventtia has expressly enabled and documented that use for your account.
6. Data Hosting & Transfers
All personal data of EU users is hosted within the EU and not transferred outside the EU, except to validated sub-processors under appropriate safeguards.
Personal data of users located outside the EU is hosted in the United States, with transfers only to validated sub-processors under appropriate safeguards.
Additional information.
- Eventtia only works with validated sub-processors who meet security and privacy requirements.
- A list of current sub-processors is available upon request at: help@eventtia.com
- All international transfers are protected by Standard Contractual Clauses (SCCs) or equivalent safeguards, as required by applicable law.
7. Retention
- Account data: kept as long as your account is active.
- Event data: retained as instructed by the event organizer.
- Cookies: kept 13–25 months depending on type.
- When data is no longer needed, it is securely deleted.
8. Children’s Data
Eventtia may process personal data of children only when provided by event organizers.
- Children do not use the Applications directly.
- The responsibility for obtaining parental consent lies with the event organizer (controller).
- Eventtia acts solely as processor in these cases.
9. Your Rights
Depending on applicable law, you may request:
- Access, rectification, deletion.
- Restriction or objection.
- Portability.
- Consent withdrawal.
- Post-mortem instructions (in some jurisdictions).
Complaints may be addressed to local data protection authorities (e.g., CNIL in France, FTC in the US, SIC in Colombia, INAI in Mexico).
10. Cookies
- Necessary cookies — site functionality.
- Analytics cookies — Google Analytics, with consent.
- Advertising cookies — personalized ads, with consent. (You can manage cookies via your browser or our cookie banner.)
How to deactivate cookies. You can opt to deactivate any cookies that are not needed for the use of the functionalities of our Application, such as the advertising cookies and the audience measurement cookies by disallowing cookies on the announcement available in each session.
To deactivate Google Analytics, you can directly access Google’s deactivation page and install the add-on module for browsers that is available at the following address: https://tools.google.com/dlpage/gaoptout
Please note, however, that your chosen configuration may alter your user experience of the content and services that require the use of cookies.
Instructions for removing cookies from your browser are available (in English) at the following address: https://allaboutcookies.org/how-to-manage-cookies
11. Security
We use encryption, access controls, and monitoring to protect data. In case of a breach, we will notify you and regulators as required.
12. Contact
Data protection inquiries: help@eventtia.com
13. Last Updated
September 1st, 2026.
The Data Processor Agreement details how that works.
When Eventtia acts as a processor for personal data you control as an event organizer, the Data Processor Agreement governs the relationship — including instructions, security, sub-processors, and breach notification.