Privacy

Last updated August 2026

This explains what E-Venz Africa Event Hub collects, why, how long it is kept and who else sees it. It covers the platform itself. Each organiser running an event on it decides separately what to ask their own attendees — section 2 explains where the line falls.

1. Who this covers

Three kinds of people appear in the system: organisers and their team, who hold accounts; attendees, who buy or claim a ticket to somebody’s event; and speakers, who are invited or apply to a programme. What is collected differs for each, and is set out below.

2. Who decides — the organiser or us

For an organiser’s own account details, we decide what is collected and why.

For attendee data, the organiser decides. They choose which event to run, what to ask at checkout, whether to collect photographs, and who on their team may see the answers. We hold and process that data on their instruction and do not use it for our own purposes — we do not sell it, we do not market to an organiser’s attendees, and we do not move one organiser’s attendees into another’s event. If you attended an event and want your data corrected or removed, the organiser is the first place to ask; if you cannot reach them, contact us at deogracious@axel.co.ke and we will act.

3. What is collected

If you hold an account

Your name, email address, phone number where you give one, your organisation, and a hashed password — never the password itself. If you sign in with Google we receive your name, email address and profile picture from Google; we never receive your Google password. If you turn on two-factor authentication we store the secret needed to check your codes.

If you buy or claim a ticket

The buyer’s name, email address and phone number, the IP address the order was placed from, and for each attendee on the order their name and email address. If the organiser has added their own checkout questions — a dietary requirement, a job title, a t-shirt size — those answers are stored with the attendee record and exported with it. What is asked is entirely the organiser’s choice.

Payment details

Card and mobile-money details are entered on the payment provider’s own pages and never reach this platform. We store what the provider tells us afterwards: a reference, an amount, a currency, a status and a timestamp. We never see or store a card number.

Photographs, where an event uses badges

Some events issue photo badges. Where one does, the attendee is sent a private link and uploads their own picture; the organiser reviews it before it prints. Both the uploaded original and the cropped version are kept. A photograph of a face is sensitive — if you would rather not provide one, ask the organiser what the alternative is before uploading.

On the day, and afterwards

When a ticket is scanned we record which code was scanned, at which door or session, when, and by which device or member of staff. Attendance records are what certificates are then issued from. A certificate carries the holder’s name and a verification code, and anyone given that code can check the certificate is genuine — that is what makes it worth having.

If you are a speaker

Your name, biography, organisation, photograph and links. Unlike everything else on this page, a published speaker profile is deliberately public: it appears on the event page and in any widget the organiser has put on their own website. Send only what you are content to have published.

Records we keep of actions

Significant actions — deletions, refunds, permission changes — are written to an audit log with who did it, when, from which IP address and with which browser. This is what makes it possible to answer “who deleted that”, and it is not used for anything else.

4. Cookies

We use a session cookie to keep you signed in. It is strictly necessary: without it the platform cannot tell one signed-in person from another. Your theme and a few interface preferences are kept in your browser’s own storage and never sent to us. We do not run advertising trackers, and we do not use third-party analytics that follow you to other sites.

5. How long things are kept

Deleted records go to a recycle bin and are purged permanently after 30 days, which is what makes an accidental deletion recoverable. Documents collected from attendees are deleted 30 days after the event ends. The audit log is kept for two years.

Orders, attendance records and certificates are kept for as long as the organiser keeps the event, because they are the record of a transaction and of who attended.

Badge photographs are deleted 30 days after the event ends, counted from the end rather than from when you uploaded — a badge can be reprinted at the door on the last morning, so the picture has to outlive the event itself. Both the cropped version and your original upload go. The attendance record stays, because that is who came; the photograph does not.

Close your account and we delete your personal details. Records another party has a right to — an attendee’s own ticket, a financial record we are required to retain — survive that, and are held only for as long as that reason lasts.

6. Who else sees it

The organiser of the event you registered for, and the members of their team they have granted access. Beyond that:

  • the payment provider, to take the payment;
  • the email provider, to deliver a confirmation or a reminder;
  • Google, but only if you choose to sign in with Google;
  • our hosting provider, which stores the data at rest;
  • anyone we are legally required to disclose to, under a valid legal obligation.

That is the whole list. We do not sell personal data, and we do not share it with advertisers.

7. Keeping it safe

Traffic is encrypted in transit. Passwords are hashed, never stored as text. Two-factor authentication is available on every account, and access inside an organiser’s team is limited by permission — a steward on the door cannot open the finance figures. No system is perfectly secure; if a breach affects you we will tell you and say plainly what happened.

8. Your rights

You can ask for a copy of what we hold about you, ask for it to be corrected, ask for it to be deleted, or object to a particular use. Organisers can do most of this from their own dashboard. Attendees should ask the organiser first, since it is their event and their decision; if that fails, write to us and we will act.

Marketing email carries an unsubscribe link in every message and it works immediately. Transactional messages — your ticket, a change of time, a receipt — are not marketing and cannot be unsubscribed from while you hold a ticket.

9. Children

The platform is not intended for children. Where an event admits under-18s, the organiser is responsible for obtaining whatever consent the law where they are requires.

10. Where data is held

Data is stored on our hosting provider’s servers, and may be processed in a country other than your own by the providers named in section 6. Where that happens we rely on those providers’ own safeguards for international transfers.

11. Changes

When this changes we update the date at the top. If a change materially affects how we handle your data, we will tell account holders directly rather than relying on you to notice.

12. Contact

Questions about any of this, or a request about your own data: deogracious@axel.co.ke.