Policy 2026-07-25-v1

Event data belongs in trusted hands.

A plain-language policy for organisers, staff and invited guests.

What OneEvents App processes

Depending on the event, the platform may hold names, contact details, invitation responses, admission tier, accessibility or seating notes, delivery history and check-in records. Payment credentials such as card data and mobile-money PINs must never be stored by OneEvents App.

Why it is processed

Event data is used only to create and operate the event, deliver an expected invitation, manage attendance, support event safety and operations, provide authorised exports, and meet approved financial or legal responsibilities. It must not be reused for unrelated marketing without a separate lawful basis and clear consent.

The organiser’s responsibilities

  • Invite only people the organiser is entitled to contact.
  • Use WhatsApp and email only when the recipient expects the event communication.
  • Give staff the minimum role they need and remove access promptly.
  • Never post invitation links, QR passes or exported guest files publicly.
  • Store exports securely, limit copies, and delete them when no longer required.
  • Keep accessibility and other sensitive notes relevant, minimal and private.
  • Tell OneEvents promptly about suspected loss, unauthorised access or disclosure.

Before, during and after the event

Authorised organisers can export a complete event package at any lifecycle stage. Every export is recorded in the audit history. Signed invitation and QR credentials are deliberately excluded from exports. When an event is archived, the configured retention countdown begins. The default is 90 days and may be adjusted from 30 days to seven years only where there is a genuine operational or legal need.

Retention and minimisation

After the configured post-archive period, the minimisation process removes contact details, delivery recipients, imported source rows and private files, revokes admission credentials and replaces guest names with archived identifiers. Aggregate attendance and security audit evidence may remain where necessary to preserve system integrity and accountability.

Guest rights and corrections

Guests may contact the organiser to correct their response or personal details, ask how their information is being used, or request deletion where the organiser has no continuing obligation to retain it. Organisers should escalate platform-level requests through the approved OneEvents support channel.

Security and incident response

OneEvents App uses role-scoped access, private signed links, revocable event-specific admission passes, CSRF protection, rate limiting, audit records and production HTTPS controls. No system eliminates all risk. Suspected incidents must be contained, recorded, assessed and communicated through the incident-response process without concealment.

External providers

Email, WhatsApp, payment, storage, virtual-event and MAJIK providers may process only the information required for the approved function. They must be contractually approved and configured server-side. Provider availability never overrides consent, privacy, settlement or regulatory requirements.