1. Who We Are
This Privacy Policy describes how EventZero collects, uses, stores, discloses, and protects personal information in connection with our website and platform ("Service").
EventZero LLC
312 W 2nd St, Unit #A3044, Casper WY 82601, USA
EventZero LLC is the data controller for personal data processed through our Service for users outside Australia.
EventZero Pty Ltd
ACN 686 382 132 / ABN 21 686 382 132
EventZero Pty Ltd is the contracting entity and APP entity responsible for Australian customers under the Privacy Act 1988 (Cth). Both entities are bound by this Policy and operate under a shared data governance framework.
EU Representative (Article 27 GDPR)
EventZero does not currently have an establishment in the EU. Where required by applicable law upon expansion of our services to EU data subjects, we will appoint a representative under Article 27 of the GDPR and update this Policy accordingly.
UK Representative (Article 27 UK GDPR)
EventZero does not currently have an establishment in the UK. Where required by applicable law upon expansion of our services to UK data subjects, we will appoint a representative under Article 27 of the UK GDPR and update this Policy accordingly.
2. Scope
This Policy applies to all websites, web applications, and online services operated by EventZero that link to it, including our primary platform at eventzero.io.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.
3. Information We Collect
a. Information You Provide
- Account registration details (business email address, organisation name, and billing details).
- Support requests or contact-form submissions.
- Communications with EventZero staff, including by email.
b. Automatically Collected Information
- Browser type, IP address, and device identifiers.
- Usage logs, session data, and platform interaction data.
- Cookie and tracking data (see Section 11).
c. Customer Data Submitted to the Platform
EventZero processes event-related data submitted by our customers ("Customer Data"). This may include event logistics data such as flight records, venue bookings, attendance figures, and emissions-related information submitted by the customer in de-identified or aggregate form. EventZero does not require or process personal information about individual event attendees (such as names or contact details) as part of its standard platform functionality.
If you believe any data submitted to our platform inadvertently contains personal information relating to individuals, please notify us promptly at legal@eventzero.io.
In respect of Customer Data, EventZero acts as a data processor on the customer's instructions; the customer remains the data controller for such data. Processing is governed by EventZero's Data Processing Agreement (DPA) — see Section 8.
4. How We Use Information
We use collected information to:
- Provide, operate, and maintain the Service;
- Process payments and manage subscriptions;
- Respond to inquiries and support requests;
- Improve platform functionality and performance;
- Send service-related communications (not marketing, unless separately consented to);
- Comply with legal obligations and enforce our agreements.
We do not sell personal information to third parties.
5. Credential Storage and Security
When you connect a third-party integration (for example, Cvent), EventZero stores encrypted credentials or tokens solely to authenticate API requests required to provide the Service.
- Credentials are stored exclusively in Amazon Web Services (AWS) Secrets Manager, encrypted using AWS Key Management Service (KMS) (AES-256).
- Access is limited by AWS Identity and Access Management (IAM) roles under the principle of least privilege.
- Credentials are never visible in plaintext or logs.
- Credentials are deleted upon account termination or upon request, subject to backup retention (typically ≤30 days).
6. Legal Basis for Processing
6A. EU and UK Users (GDPR / UK GDPR)
Our lawful bases under the GDPR and UK GDPR include:
- Contractual necessity — to provide the Service pursuant to our agreement with you;
- Legitimate interests — improving and securing the platform, fraud prevention, and business analytics;
- Legal obligation — retaining records or responding to lawful requests by authorities;
- Consent — where required for marketing communications or non-essential cookies.
6B. Australian Users (Privacy Act 1988 (Cth))
EventZero Pty Ltd complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We collect personal information only by lawful and fair means, and only where reasonably necessary for our business functions and activities. We will not collect sensitive information without consent except as permitted by law.
6C. Other Jurisdictions
For users in other jurisdictions, we process personal information in accordance with applicable local law. Where a specific legal basis is required, we will process your information on the basis of contractual necessity, legitimate interests, or consent as appropriate. See Section 14 for jurisdiction-specific rights.
7. Disclosure and Subprocessors
We use carefully selected subprocessors to host our infrastructure and support delivery of the Service. A current list of subprocessors is available at eventzero.io/subprocessors.
We require each subprocessor to implement appropriate technical and organisational security measures. For EU and UK customers, subprocessor arrangements comply with Article 28 of the GDPR and UK GDPR respectively.
We may also disclose information:
- To professional advisers or service providers acting on our behalf, under appropriate confidentiality obligations;
- When required by applicable law, court order, or valid legal process;
- To regulatory or government authorities where we are obligated to do so;
- In the event of a merger, acquisition, or asset transfer, where the receiving entity will be bound by this Policy or a substantially equivalent one.
7A. Data Processing Agreements
Enterprise customers who require a Data Processing Agreement (DPA) may request one by contacting legal@eventzero.io. Our DPA governs the respective rights and obligations of EventZero as data processor and the customer as data controller in respect of Customer Data submitted to the platform.
8. Data Storage and International Transfers
All data processed through the EventZero platform is hosted and stored in the United States using Amazon Web Services (AWS) data centres. We do not replicate or store Customer Data in other regions.
8A. EU and UK Customers
For customers located in the EU or UK, personal data is transferred to and processed in the United States. These transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, and equivalent mechanisms under UK law (the International Data Transfer Agreement or Addendum), designed to ensure your data receives a level of protection consistent with GDPR and UK GDPR requirements.
8B. Australian Customers
Personal information collected by EventZero Pty Ltd from Australian customers is transferred to and stored by EventZero LLC in the United States. EventZero LLC is contractually bound to handle such information in a manner consistent with the Australian Privacy Principles (APPs). EventZero Pty Ltd remains accountable for ensuring this standard is maintained in accordance with APP 8.
By using the Service, Australian customers acknowledge this cross-border transfer and the protections in place. If you do not wish your personal information to be transferred overseas, please contact us at legal@eventzero.io prior to using the Service.
8C. Other International Customers
For customers in other jurisdictions (including Singapore, Japan, and other APAC markets), personal information may be transferred to and processed in the United States. We implement appropriate contractual and technical safeguards for such transfers in accordance with applicable local law. Customers in jurisdictions with specific cross-border transfer requirements should contact legal@eventzero.io to discuss applicable arrangements.
9. Data Retention
EventZero retains personal information and Customer Data for as long as necessary to provide the Service and meet our contractual and legal obligations. Retention periods vary depending on the type of data and the purpose for which it was collected.
Account and contact data (such as account holder names, business email addresses, and support communications) is retained for the duration of the customer relationship and for a period of 7 years following account termination, in accordance with applicable legal and contractual requirements.
Customer Data submitted to the platform (such as event logistics data, flight records, and emissions figures) is retained in de-identified or aggregate form and does not contain personal information about individual end users. EventZero retains this data to provide the Service and for platform analytics and improvement purposes.
Integration credentials and tokens are deleted upon account termination or upon verified request, and are not retained beyond 30 days following termination.
9A. Deletion Requests
You may request deletion of your account, associated personal information (such as account holder details and support records), and Customer Data submitted to the platform by contacting legal@eventzero.io. Deletion requests require 7 days' notice to process. We will confirm receipt of your request and action it within that period, with data purged within 30 days of the deletion date, including from backups upon their natural expiry cycle.
Note: certain records may be retained for longer periods where required by law, regardless of a deletion request (for example, financial records under applicable tax law). We will notify you if any portion of your request cannot be fulfilled and the reason why.
10. Your Rights
10A. All Users
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate or incomplete personal information;
- Request deletion of your personal information;
- Restrict or object to certain processing;
- Withdraw consent where processing is based on consent;
- Receive a copy of your data in a portable format (where applicable).
Requests can be sent to legal@eventzero.io. We may require verification of your identity before fulfilling a request. Deletion requests require 7 days' notice to process. All other requests will be responded to within the timeframe required by applicable law (generally 30 days).
10B. EU and UK Users
EU users may lodge a complaint with the relevant EU supervisory authority in the member state of your habitual residence, place of work, or place of the alleged infringement. UK users may lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk.
10C. Australian Users
Australian residents may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au if they believe their privacy rights have been interfered with. We encourage you to contact us first so we have the opportunity to address your concern directly.
10D. California Users (CCPA/CPRA)
EventZero's platform is a B2B service. We do not sell personal information. Personal information collected from California-based business users (such as account holder names and business email addresses) is collected and used solely in a commercial context and is subject to the applicable B2B provisions of the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). If you have questions about our California privacy practices, contact legal@eventzero.io.
10E. Other Jurisdictions
Users in other jurisdictions with applicable privacy laws (including Singapore under the PDPA, Japan under the APPI, and other markets) may have additional rights under local law. Please contact legal@eventzero.io to exercise any such rights. We will respond in accordance with applicable local requirements.
11. Cookies and Analytics
We use functional and analytics cookies to operate and improve our websites and platform.
- Functional cookies are necessary for the operation of the Service and cannot be disabled without affecting platform functionality.
- Analytics cookies help us understand how the Service is used and improve performance.
Where required by law (including for EU and UK visitors), we obtain consent for non-essential cookies through our cookie consent banner. You may also adjust your browser settings to block or delete cookies at any time; however, some features of the Service may not function properly if cookies are disabled.
For full details, including a list of cookies used and how to manage them, see our Cookie Policy at eventzero.io/cookies.
12. Data Security
We implement appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, or alteration, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256);
- Network isolation and firewalls within AWS;
- Role-based access control and multi-factor authentication;
- Regular vulnerability scanning and security monitoring;
- Daily encrypted backups with tested restoration procedures.
More information is available in our Security Overview at eventzero.io/security.
While we implement commercially reasonable security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Children
Our Service is directed solely to businesses and is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact legal@eventzero.io and we will take prompt steps to delete it.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Material updates will be communicated to existing customers via email or in-app notification at least 14 days before taking effect. Non-material updates (such as clarifications or corrections) will be posted on our website with an updated "Last Updated" date. Continued use of the Service after the effective date of a material update constitutes acceptance of the updated Policy.
Where changes affect the basis on which we process your personal data, we will seek fresh consent where required by applicable law.
15. Contact Us
For all privacy-related inquiries, requests, or complaints:
Privacy and Data Protection Contact
EventZero LLC
312 W 2nd St, Unit #A3044, Casper WY 82601, USA
Email: legal@eventzero.io
Web: eventzero.io/privacy
EU Representative
EventZero does not currently have an establishment in the EU. An Article 27 GDPR representative will be appointed and listed here prior to processing personal data of EU residents.
UK Representative
EventZero does not currently have an establishment in the UK. An Article 27 UK GDPR representative will be appointed and listed here prior to processing personal data of UK residents.
Document Control
Version: 2.0 | Last Updated: March 23, 2026 | Replaces: Version 1.0 dated October 7, 2025