Privacy Policy

Last updated 20 July 2026

This Privacy Policy explains how eventru (“we”, “us”) handles personal data when you use our event-management platform (the “Service”). It covers our own account holders and, where we act as a processor, the attendees and contacts whose data our customers manage in eventru.

Who we are

The controller of the personal data described in the “Controller and processor” section below is eventru, United Kingdom. For any privacy question or to exercise your rights, contact us at privacy@eventru.co.uk.

Controller and processor

For the account and billing data of our customers, eventru is the controller. For the event, attendee and contact data that a customer (an event agency) manages in their workspace, the customer is the controller and eventru acts as a processor on their behalf, under our data processing agreement with them. If you are an attendee or a contact and want to exercise your rights, please contact the agency running your event; we will help them respond.

What we collect

  • Account data — name, email, profile photo, workspace and role, and single sign-on identifiers where you log in with Google, Microsoft or LinkedIn.
  • Usage data — log, device and diagnostic information about how the Service is used.
  • Website analytics — when you visit our public pages (our website, event microsites, proposal pages and shared documents) we record aggregate, cookieless traffic measurements: page path, the referring site’s domain, campaign (utm) tags, a coarse device type and approximate country, and a rotating, non-reversible value derived from your IP and browser to estimate visitor numbers. We do not store your IP address and do not build cross-site profiles. See “Website analytics” below.
  • Customer Data — clients, contacts, venues, suppliers, events, agendas, budgets, invoices and attendees that our customers enter.
  • Special category data — where a customer records attendee dietary requirements, accessibility needs or medical information, this is special category data. The customer (the agency) is the controller of it and is responsible for having a lawful basis and an Article 9 condition; we process it only on their instructions and protect it with the safeguards below.
  • Integration data — where you connect email, calendar, payment or accounting providers, the data needed to operate those features (including OAuth tokens, which we store encrypted at rest).

How we use it

  • To provide, secure and improve the Service.
  • To authenticate you and enforce workspace (tenant) isolation.
  • To process payments and manage subscriptions.
  • To communicate about your account and provide support.
  • To meet legal and regulatory obligations.

Legal bases

Where UK/EU GDPR applies, we rely on: performance of a contract (to provide the Service to account holders); our legitimate interests in operating, securing and improving the Service and in limited business-to-business marketing; your consent where required (for example certain integrations or any non-essential cookies); and compliance with legal obligations (such as keeping financial records).

Cookies

We use strictly necessary cookies to keep you signed in and to operate secure integration flows. Our website analytics are first-party and cookieless (see below), and we do not use advertising or third-party analytics cookies. See our Cookie Policy for details.

Website analytics

We measure traffic to our public pages with our own first-party, cookieless analytics — no cookies are set and nothing is stored on your device. We record page views and estimate visitor numbers using a value derived in memory from your IP address and browser that is salted and rotated daily, so it cannot be traced back to you or linked across days; your IP address is never stored. We also keep the page path, the referring website’s domain, any campaign (utm) tags, a coarse device type and an approximate country.

Our legal basis is our legitimate interest in understanding and improving the reach and performance of our website and event pages (UK/EU GDPR Article 6(1)(f)); the data is aggregate and minimised, with no cross-site tracking or advertising. If your browser sends a Global Privacy Control or Do Not Track signal we do not record your visit. We retain the underlying records for a limited period (by default 90 days) and then delete them; only aggregate counts are kept beyond that.

Who we share it with

We share data with sub-processors who help us run the Service under data-protection contracts. We do not sell personal data. Our sub-processors include:

  • Vercel — application hosting.
  • Neon — database hosting.
  • Cloudflare (R2) — file and document storage.
  • Stripe — payments and subscription billing (card details are handled by Stripe; we do not store card numbers).
  • Postmark — sending transactional and workflow email.
  • Anthropic — AI features (see below).
  • Google, Microsoft, LinkedIn — sign-in, and optional calendar/mailbox features you enable.

Where you connect your own QuickBooks or Xero account, we push the invoices you approve into that account at your direction. A current list of sub-processors is available on request. We may also disclose data where required by law.

AI features

Some features use AI models (Anthropic’s Claude) to draft content and assist with planning, from data in your workspace. A person reviews AI-generated output before it is sent or used. We do not send data from your connected accounting provider to AI models, and under our agreement with the provider, data we send to the AI is not used to train their models.

Google user data (Gmail sending & calendar)

If you sign in with Google and turn on the optional mailbox-send feature, eventru requests the “Send email on your behalf” permission (the gmail.send scope). We use it only to send the specific emails you write and choose to sendfrom your own Gmail — for example a venue RFP, a proposal or an event update. We do not read, search, store, label, modify or delete your Gmail messages, and we request no other Gmail access. If you connect Google Calendar, we use that access only to show and manage the event entries you ask us to. You can disconnect Google or revoke this access at any time from your Google account.

eventru’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, do not allow humans to read it, and do not use it to train AI models — we use it solely to provide the features you have enabled.

International transfers

Some of our sub-processors process data outside the UK, including in the United States. Where that happens, we rely on an appropriate safeguard — an adequacy decision, the UK Extension to the EU–US Data Privacy Framework where the recipient is certified, or the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, as appropriate to each sub-processor.

Retention

We retain personal data for as long as needed to provide the Service and meet legal obligations. Customer Data is retained per the customer’s instructions and deleted a reasonable period after account termination. Financial records are kept for six years to meet legal requirements. Deleted data may persist in encrypted backups until those backups age out.

Security

We protect data with measures including per-workspace isolation enforced at the database (row-level security), role-based access controls, encryption in transit and at rest, encryption of stored integration tokens, and validation of uploads. No system is perfectly secure, but we work to protect your data and to notify the right people promptly if something goes wrong.

Your rights

Subject to applicable law, you may have rights to access, correct, delete, restrict or port your personal data, and to object to certain processing. Where eventru is the controller, contact us at privacy@eventru.co.uk. Where eventru acts as a processor, please direct requests to the relevant customer (controller); we will assist them as required. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.

Changes

We may update this policy from time to time. We will update the “last updated” date and, for material changes, take reasonable steps to let you know.

Contact

To exercise your rights or ask about this policy, contact us at privacy@eventru.co.uk.