PrivacyPolicy

How Spextacle Events collects, protects and isolates attendee and organizer data.

Last updated: August 3, 2026

Template, pending legal review

This policy is a template describing how the Spextacle Events platform is built and operated. It is not legal advice and must be reviewed by qualified counsel and aligned with each organizer’s own notices and data processing agreement, before it is relied upon.

1. Introduction

This Privacy Policy explains how Spextacle ("we", "us", or "our") collects, uses, discloses, and safeguards information in connection with Spextacle Events, our event management and access control platform, together with our websites, portals, registration pages, and scanner applications (collectively, the "Service").

By accessing or using the Service, you agree to the practices described in this policy. If you do not agree, please discontinue use of the Service.

2. Our Role: Organizer as Controller, Spextacle as Processor

Events on the platform are run by our customers, the organizers, agencies, and authorities who license Spextacle Events (each an "Organizer"). For attendee, participant, and staff records held inside an Organizer’s event, the Organizer decides what is collected and why; they are the controller and we act as processor on their documented instructions.

We act as controller for a narrower set of data: the accounts of Organizer staff who administer the platform, our billing records, and the enquiry and demo-booking details submitted through this website.

If you are an attendee and want to exercise your rights over your registration record, contact the Organizer of the event first. We will support them in responding.

3. Information We Collect

Registration and participant data. Whatever an Organizer configures in their registration form, typically name, contact details, employer, job title, and preferred language, and where an accreditation process requires it, nationality, identity or travel document details, and uploaded documents such as a CV or company letter. Forms may also capture dietary, accessibility, or medical needs, which are treated as sensitive data.

Badge photographs. Where the Organizer issues photo credentials, an attendee photo is stored and printed onto the badge so staff at a checkpoint can confirm the badge belongs to the person presenting it.

Credential and access data. Badge and QR identifiers, ticket tier, zone entitlements, entry limits, and validity windows.

Scan and access logs. Every scan decision, checkpoint, device, timestamp, and whether entry was allowed or denied, including anti-passback and offline denials, together with check-in, session attendance, and workforce check-in records. Scans captured offline are held encrypted on the device and reconciled when the device reconnects.

Commerce data. Ticket orders, invoices, refunds, and promo code use. Card and bank details are handled by the payment gateway, not stored by us.

Communications. Emails and messages sent through the platform (confirmations, invitations, approval decisions, reminders), and delivery status for those messages.

Account and technical data. Login credentials for Organizer staff, audit records of administrative actions, plus IP address, device and browser type, and usage activity collected through cookies and similar technologies.

4. How We Use Information

To deliver the Service: process registrations, run approval workflows, issue and print badges, evaluate access rules at checkpoints, manage sessions and orders, and send the notifications an event requires.

To secure events: verify credentials at the door, enforce zone, capacity, and time-window rules, detect badge sharing and other misuse, and maintain the audit trail Organizers and their security partners rely on.

To support and improve the platform: diagnose faults, monitor performance and capacity, and develop features. Where we analyse usage for product improvement we work with aggregated or de-identified data wherever practical.

To meet legal obligations, respond to lawful requests, and establish or defend legal claims.

We do not use attendee data for our own marketing, and we do not sell personal information.

5. Legal Bases for Processing

Where the GDPR, the Saudi Personal Data Protection Law (PDPL), or a comparable regime applies, processing is carried out under one or more of the following bases, determined by the Organizer for event data: performance of a contract (registering, admitting, and invoicing a participant); legitimate interests (event security, fraud prevention, service integrity); consent (marketing communications, optional photographs, and sharing details with sponsors or exhibitors); and legal obligation (accreditation, tax, and record-keeping duties).

Sensitive categories such as health, dietary, or accessibility needs are processed only where an Organizer collects them and only on an appropriate basis, typically explicit consent.

6. Badge Photographs and Biometrics

Badge photographs are used for visual identity verification and printed credentials. The platform admits people by scanning a QR code or NFC credential; it does not perform facial recognition or any other biometric matching, and photographs are not converted into biometric templates.

7. Tenant Isolation and Data Residency

Spextacle Events is multi-tenant by design but not commingled: each tenant’s event data is held in its own isolated database, with tenant context enforced on every request so records cannot be read across tenants. Shared resources such as templates are kept separate from tenant data.

The hosting region for a tenant is agreed with the Organizer and can be aligned with regional data residency requirements. Where an Organizer requires in-country hosting, that is arranged as part of their deployment.

8. Service Providers and Sub-processors

We rely on a limited set of providers to run the Service: cloud hosting and infrastructure, payment gateways (such as Stripe, Moyasar, and Tap) for ticket and order processing, email and SMS delivery providers for event communications, and error monitoring and analytics tooling.

Providers are engaged under written terms that limit them to processing data for the purposes we specify. A current list of sub-processors is available to Organizers on request, and material changes are notified in line with the applicable data processing agreement.

9. How We Share Information

With the Organizer of the event you registered for, including their designated staff, approvers, and accredited on-site teams.

With venue operators, security providers, or public authorities where an Organizer’s accreditation process requires it and the law permits or obliges the disclosure, common for government-adjacent events.

With sponsors or exhibitors only where the attendee has explicitly opted in to that sharing.

With our service providers, as described above, and with a successor entity in the event of a merger or acquisition, subject to the same protections.

Where required by law, court order, or to protect the rights, safety, or property of Spextacle, our customers, or the public.

10. Cookies and Tracking Technologies

We use cookies and similar technologies to keep you signed in, remember language and theme preferences, secure sessions, and understand how our sites are used. You can control cookies through your browser settings, though some features, including portal sign-in, will not work without them.

11. Data Retention After an Event

Event data is retained for the period the Organizer configures for their event. Registration records, badge photographs, and scan logs are typically kept for a defined window after the event closes so that attendance can be reconciled, incidents investigated, and reporting completed, then deleted or anonymised.

Audit logs and financial records may be retained longer where accounting, tax, or security obligations require it.

When an Organizer’s subscription ends, we make their tenant data available for export for an agreed period, after which the tenant database is deleted, including from backups on the normal backup rotation.

12. Security Practices

We implement administrative, technical, and physical safeguards designed to protect information. These include encryption in transit and at rest, encrypted offline manifests on scanner devices (AES-256-GCM) with a deny-first policy so unknown credentials are refused when a device is offline, role-based access control with least-privilege administration, per-tenant database isolation, comprehensive audit logging of administrative and access decisions, and the ability to revoke a badge, device, or account immediately.

We describe our practices rather than claim third-party certifications. Where an Organizer requires evidence for their own assurance process, we will provide documentation of these controls on request.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

13. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent you have given.

For data held inside an event, direct your request to the Organizer, who decides how it is handled; we assist them as processor. For data we control, website enquiries, demo bookings, and Organizer staff accounts, contact us using the details below.

You may also lodge a complaint with your local supervisory authority.

14. International Data Transfers

Events frequently involve participants from many countries, and information may be processed or stored outside your own. Where data is transferred internationally, we use appropriate safeguards such as standard contractual clauses or an equivalent mechanism recognised by the applicable regime, and we honour any residency commitment agreed with the Organizer.

15. Children and Dependents

The Service is not directed to individuals under the age of 16, and we do not knowingly collect their personal information directly. Where an Organizer enables dependent or accompanying-guest registration, details of a minor may be submitted by a parent or guardian, who is responsible for providing any consent required.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date above.

17. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@spextacle.com. If your question concerns a specific event, please tell us which event so we can route it to the right Organizer.