Legal
Privacy Policy
Last updated: 18 July 2026
01Who we are
This policy explains how [Company legal entity](“Congressio”, “we”, “us”) processes personal data when you use the Congressio platform (the “Service”). For personal data that event organizers collect from their participants, the organizer is the data controller and Congressio acts as a processor on their behalf; in that case the organizer’s own privacy notice also applies.
02Data we collect
- Account data — your name, email address, password (stored only as a hash), organization membership, role, and interface preferences such as language.
- Submission and review data — the abstracts, papers, files, reviews and scores that authors and reviewers create within an event.
- Registration data — the answers attendees give to an event’s registration form, their ticket type, and check-in status.
- Payment metadata — for paid tickets and subscriptions, we store limited metadata such as amount, currency, status and a payment reference. Card details are entered directly with our payment processor Stripe; Congressio never sees or stores full card numbers.
- Technical data — basic logs, device and browser information, and security events needed to operate and protect the Service.
- Third-party sign-in — if you choose “Sign in with Google” or “Sign in with Apple”, we receive your name and email address from that provider to create or link your account. We do not receive your provider password.
- Mobile app data — in the Congressio mobile app we store a device push-notification token so we can deliver event notifications, and, with your permission, use the camera solely to scan attendee badge QR codes at check-in. Camera images are processed on device to read the code and are not stored or transmitted.
03Why we use it and our legal bases
We process personal data for the purposes below. Where the GDPR applies, the relevant legal basis is indicated:
- To provide the Service — create accounts, run submissions, review, registration and programs (performance of a contract).
- To take payments and prevent fraud (performance of a contract; legal obligation).
- To send service and transactional emails, such as confirmations and notifications (performance of a contract; legitimate interests).
- To secure, maintain and improve the Service (legitimate interests).
- To comply with legal and accounting obligations (legal obligation).
- For optional communications where required, only with your consent (consent).
04Sub-processors
We rely on a small number of vetted providers to run the Service. Each processes personal data only on our instructions and under appropriate agreements:
- Neon — managed PostgreSQL database hosting, located in the European Union.
- Stripe — payment processing for subscriptions and attendee tickets.
- Amazon Web Services (SES) — transactional email delivery.
- Amazon Web Services (S3) — storage of uploaded files and documents.
- Vercel — application hosting and content delivery.
- Upstash — rate limiting and ephemeral caching.
- Expo (Expo Application Services) — mobile app delivery and push-notification routing.
- Google (Firebase Cloud Messaging; Google Sign-In) — Android push-notification delivery and, if you use it, Google sign-in.
- Apple (Apple Push Notification service; Sign in with Apple) — iOS push-notification delivery and, if you use it, Apple sign-in.
We keep an up-to-date list and will provide details of the specific regions and safeguards on request via [DPO / privacy contact email].
05Data retention
We keep personal data for as long as your account or the relevant event is active, and afterwards only as long as needed for the purposes described here — for example to comply with legal, accounting and tax obligations, or to resolve disputes. Event content and participant data are retained on behalf of the organizer according to their instructions; when an account is closed we delete or anonymize data within a reasonable period, subject to those obligations and to backups that expire on a rolling basis.
06Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time.
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data where there is no overriding reason to keep it.
- Portability — receive certain data in a structured, machine-readable format.
- Objection and restriction — object to, or limit, certain processing.
You can delete your account at any time — in the mobile app under Settings → Delete account, or on the web at congressio.net/delete-account. To exercise any other right, contact us at [DPO / privacy contact email]. If your request concerns data held on behalf of an event organizer, we may direct you to, or coordinate with, that organizer. You also have the right to lodge a complaint with your local data protection authority.
07Cookies
Congressio uses a minimal set of cookies. We use a strictly necessary authentication cookie to keep you signed in and to protect your session, and a locale cookie to remember your interface language. We do not use advertising cookies. Because these cookies are essential to providing the Service you requested, they are set without requiring consent, while non-essential cookies (if any are introduced) would be used only with your consent.
08International transfers
We aim to keep primary data storage within the European Union (our database is hosted in the EU). Some sub-processors may process data outside the EU/EEA. Where that happens, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision to protect your data.
09Children
The Service is intended for professional and organizational use and is not directed to children. We do not knowingly collect personal data from children under the age required by applicable law. If you believe a child has provided us with personal data, please contact us so we can remove it.
10Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “last updated” date above and, where appropriate, provide additional notice.
11Contact and data protection officer
For privacy questions or to exercise your rights, contact our data protection contact at [DPO / privacy contact email], or write to [Company legal entity], [address]. For general enquiries you can also use our contact page or email hello@congressio.net.