Privacy Policy
Last updated: 25 July 2026
1. Who this applies to
This Privacy Policy explains how [Company Legal Name]("we", "Venuebo") handles personal data when you use Venuebo — whether you're a platform Owner, an Organization admin or staff member, a sponsor representative, or a conference delegate. Where an Organization uses Venuebo to run its own conferences, the Organization is the data controller for its delegates' and sponsors' data, and we process that data on the Organization's behalf under our Data Processing Agreement.
2. Data we collect
- Account data: name, email, and a securely hashed password (we never store passwords in plain text).
- Organization/billing data: organization name, subscription and payment status via our payment processor (we do not store your card details ourselves).
- Conference data: delegate names, job titles, employers, emails, phone numbers, profile photos, stated goals/interests, and check-in status, as entered by an Organization or by the delegate themselves.
- Sponsor intelligence data: AI-generated target scores, battle cards, leads, and meeting records created within a sponsor's workspace.
- Call transcript / pain-point data: where an Organization ingests sales-call transcripts, extracted summaries are attached to the matched delegate's profile, visible to relevant sponsors.
- Usage data: login timestamps, device/browser information, and basic server logs, for security and reliability.
3. How we use it
- To operate the service — logins, dashboards, agenda personalisation, messaging.
- To power AI-assisted features (target scoring, battle cards, drafted follow-ups, networking matches, session recommendations).
- To process payments and manage subscriptions.
- To send transactional emails (account approval, password resets, event announcements you've opted into as a delegate or sponsor).
- To maintain security, prevent abuse, and comply with legal obligations.
4. Legal basis for processing (EEA/UK users)
Where GDPR/UK GDPR applies, we (or the Organization, as controller) rely on: performance of a contract (running your account and the conference workspace), legitimate interests (security, service improvement, AI-assisted features that are core to the product), and consent where specifically requested (e.g. marketing communications).
5. Who we share data with
Personal data is shared only as needed to run the service:
- Payment processing: LemonSqueezy (subscription billing).
- Email delivery: Resend, when live email is configured for an Organization (otherwise emails stay in-app).
- AI processing: Anthropic's API, when live AI is configured (otherwise AI features run on deterministic, non-AI logic — no data leaves our servers for scoring).
- Hosting infrastructure: our hosting/infrastructure provider ([Hosting Provider Name]), who stores data on our behalf.
- Within a conference: a sponsor sees delegate contact details only once the Organization's directory unlock date has passed, matching the access rules the Organization configures.
We do not sell personal data.
6. Data retention
We retain Customer Data for as long as the Organization's subscription is active, plus a reasonable period afterward for legal/backup purposes, unless the Organization requests earlier deletion. Account data for a revoked login is deleted, but underlying conference records (e.g. a delegate's profile, pain points) are retained as part of the Organization's Customer Data unless the Organization asks us to remove them.
7. Security
Passwords are hashed (scrypt) and never stored in plain text. Access to conference data is scoped by role and by Organization — one Organization's admins cannot see another's data. Sessions use secure, HTTP-only cookies. No system is perfectly secure, and we encourage prompt reporting of any suspected vulnerability to [Contact Email].
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing. If you're a conference delegate or sponsor representative, start with your Organization's admin (they control your record); if you're an Organization admin, contact us directly at [Contact Email].
9. Cookies
We use a single functional, HTTP-only session cookie to keep you logged in. We do not use advertising or third-party tracking cookies.
10. Children's privacy
Venuebo is a B2B product not directed at children, and we do not knowingly collect personal data from anyone under 16.
11. International transfers
Data may be processed in countries other than where you're located, including [Hosting Country/Region]. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for such transfers.
12. Changes to this policy
We may update this Privacy Policy from time to time; material changes will be notified to Organization admins.
13. Contact
Questions about this policy or your data: [Contact Email].