Events run with Pavoot
Depending on the event, the organizer may use Pavoot to handle your name, contact details, company, job title and LinkedIn profile; your registration answers and RSVP; your check-in; notes the organizer's team took after meeting you; and the invitations, reminders and follow-ups sent to you by email or text message. For paid events, payment is handled by Stripe; Pavoot receives the payment status, not your card details. Emails may include a small image and link redirects that show the organizer whether an email was opened or a link clicked. More detail is in section 5 of our Platform Privacy Policy.
To stop receiving messages from an organizer, or to access, correct or delete your data, contact the organizer named in the invitation.
Photo matching: what data we handle
This section and the sections that follow, up to Security, apply only when the organizer offers photo matching.
Pavoot handles only the data needed to provide the event organizer's photo matching service. Depending on the event, this may include:
- Your name and contact details, such as your email address or phone number.
- The photo you provide during registration.
- A biometric template, which is a mathematical representation derived from your photo and used only to match you to event photos and videos.
- Event photos, videos, file metadata, and matching results.
- Technical data needed to operate and secure the service, such as your IP address.
The people covered by this notice are attendees who register biometric data and other individuals who appear in event media uploaded by the organizer.
Special categories. Pavoot processes biometric data only to match you to event media on the organizer's instructions. Photographs may incidentally reveal characteristics such as ethnic origin or religious belief. Pavoot does not analyze these characteristics or use them for any purpose, and does not retain or act on inferences about them.
Why we handle it, and the legal basis
The event organizer uses your data to find photos and videos of you from the event and deliver them to you. Pavoot processes the data only for that purpose and only on the organizer's documented instructions. Pavoot does not use attendee photos or biometric templates for its own purposes or to train artificial intelligence models.
Legal basis. For the photo matching service, the event organizer relies on your consent under Article 6(1)(a) GDPR. Your face data is biometric data, a special category under Article 9 GDPR. The organizer processes it on the basis of your explicit consent under Article 9(2)(a), which you give in the organizer's registration form. The organizer is responsible for obtaining and recording that consent. Pavoot does not collect consent from attendees.
Withdrawing consent. You can withdraw at any time. Withdrawal deletes your biometric template and stops further matching. It does not affect processing that already took place, and it does not automatically delete photos already delivered to you or held by the organizer. To withdraw, contact the event organizer.
How long it is kept
Your biometric template is kept for the period set by the event organizer and deleted at the end of that period, when you withdraw consent, or when the organizer's contract with Pavoot ends, whichever comes first. The organizer controls how long event photos and videos are retained outside Pavoot.
Who else is involved
Approved cloud hosting and facial matching service providers may process your biometric data as Pavoot's sub-processors. They may handle it only to provide the event organizer's service under contractual data protection and confidentiality obligations. Pavoot does not allow them to use your biometric data for their own purposes.
For more information about the service providers involved in handling your data, contact the event organizer named in your registration.
Where it is stored and international transfers
Your photo, biometric template, and matching data are stored and processed using approved cloud infrastructure. The event organizer can provide the storage location and the current providers relevant to your event.
Pavoot Inc. is based in the United States, so personal data may be transferred to or accessed from the United States. Where personal data is transferred to or accessed from outside the EU/EEA or Switzerland, Pavoot relies on data protection contracts approved for international transfers: the European Commission's Standard Contractual Clauses, with the Swiss addendum where applicable. Additional protections include encryption in transit and at rest, access controls, least privilege permissions, and logical separation between organizations.
Your rights and how to use them
Depending on the law that applies, you may ask to access, correct, delete, restrict, or receive a copy of your data. You may object where applicable, withdraw consent at any time, and lodge a complaint with your local data protection authority. In Switzerland, this is the Federal Data Protection and Information Commissioner.
Questions: contact the event organizer named in your registration. The organizer is responsible for responding to your request. Pavoot will assist and act on the organizer's instructions.
Security
Pavoot applies technical and organizational measures to protect your data while acting on the event organizer's instructions. These include:
- Encryption in transit using TLS and HTTPS.
- Encryption of personal data at rest.
- Least privilege access controls and restricted administrative access.
- Logical separation of data between event organizers.
- Processes for responding to security incidents and personal data breaches.
- Deletion or return of data when instructed by the organizer.
No method of transmission or storage is completely secure, but Pavoot works to reduce risk, limit access, and help the organizer meet its data protection obligations.
