Privacy policy & GDPR

This page is maintained by basiq Events to explain how we handle personal data and how we comply with the EU General Data Protection Regulation (GDPR).

1. Who we are

basiq Events ("we", "us") is an event management platform operated by basiq, India. For privacy questions or data requests, contact info@basiq.in.

2. Data we collect

  • Account data: name, email, password hash, profile photo (optional), authentication provider.
  • Workspace data: organization name, billing plan, team members and roles.
  • Event data: event details, ticket categories, sessions, sponsors, speakers, files you upload.
  • Attendee data: name, email, phone (optional), registration answers, check-in timestamps, poll/Q&A submissions, feedback responses.
  • Technical data: IP address, user agent, error logs for security and reliability.

3. How we use data

To operate the service (registration, check-in, certificates, reporting), authenticate users, prevent abuse, comply with legal obligations, and improve the product. We do not sell personal data and we do not use attendee data to train AI models.

4. Lawful bases (GDPR Art. 6)

  • Contract — to provide the service you sign up for.
  • Legitimate interest — security, fraud prevention, product analytics.
  • Consent — optional marketing communications and non-essential cookies.
  • Legal obligation — accounting, tax and lawful requests.

5. Your rights under GDPR

  • Access — request a copy of your data.
  • Rectification — correct inaccurate data.
  • Erasure ("right to be forgotten") — delete your account and personal data.
  • Restriction & objection — limit how we process your data.
  • Data portability — export your data in a machine-readable format.
  • Withdraw consent — at any time, without affecting prior processing.
  • Complain to your supervisory authority.

To exercise any right, email info@basiq.in. We respond within 30 days.

6. Data retention

Account and event data is retained while your account is active. On deletion, personal data is removed within 30 days, except where retention is required by law (e.g., tax records).

7. Sub-processors & international transfers

We rely on vetted infrastructure providers for hosting, database, email and analytics. Where data is transferred outside the EEA, we use Standard Contractual Clauses (SCCs) and equivalent safeguards.

8. Security

Data is encrypted in transit (TLS) and at rest. Access is least-privilege and audited. Row-level security is enforced at the database. Report a security issue to info@basiq.in.

9. Cookies

We use strictly necessary cookies for authentication and session management. Optional analytics cookies are only set with your consent.

10. Children

basiq Events is not intended for children under 16. We do not knowingly collect data from children without parental consent.

11. Organizer responsibilities

Event organizers are independent data controllers for their attendees and must obtain their own lawful basis (typically consent or contract) before collecting registrations. basiq Events acts as the data processor for organizers under a Data Processing Agreement (available on request).

12. Changes

We will notify users of material changes via email or in-app notice at least 14 days before they take effect.