Privacy Policy
Discover how EventEz collects, uses, and protects your personal data. Your privacy is our priority.
Transparency
We clearly inform you about how your data is used at every step.
Security
Your data is protected by advanced technical and organizational measures.
Control
You retain control over your data with rights of access, modification, and deletion.
Data controller
The controller responsible for processing personal data collected via the EventEz platform is:
EventEz
Legal form: Limited liability company (SARL)
Registered office: Douala, Cameroon
Email: contact@eventez.online
Data Protection Officer (DPO): dpo@eventez.online
EventEz is an event management platform based in Cameroon, offering online ticketing and custom registration services. We are committed to protecting the privacy of our users and processing their personal data with the utmost care, in accordance with applicable Cameroonian legislation and the principles of the General Data Protection Regulation (GDPR).
Data collected
As part of the use of the Platform, EventEz collects and processes the following categories of personal data:
2.1 Identification data
- First and last name
- Email address
- Phone number
- Profile picture (optional)
- Company or organization name (for organizer accounts)
- Business registration number (for organizer accounts)
2.2 Connection and usage data
- IP address
- Browser type and version
- Operating system
- Pages viewed and actions performed on the Platform
- Connection dates and times
- Geolocation data (with consent)
- Device identifier (for the mobile app)
2.3 Transactional data
- History of ticket purchases and registrations
- Transaction amounts
- Payment method used (without storing card or mobile money account numbers)
- NotchPay transaction references
- Invoices generated
2.4 Event-related data
- Responses to custom registration forms
- Dietary preferences, specific needs (if requested by the organizer)
- Check-in and attendance data
- Reviews and ratings submitted
2.5 Communication data
- Messages exchanged via the integrated messaging system
- Content of notifications received
- History of exchanges with customer support
Purposes of processing
The personal data collected is processed for the following purposes:
Provision of services
Creating and managing user accounts, organizing and participating in events, processing registrations and ticket purchases, generating QR codes and invoices.
Payment management
Processing financial transactions via NotchPay, managing refunds, issuing invoices, and accounting follow-up.
Communication
Sending notifications related to events (confirmations, reminders, changes), messaging between organizers and participants, customer support.
Service improvement
Analyzing Platform usage, statistics and reports for organizers, fraud detection and prevention, improving the user experience.
Legal obligations
Compliance with tax and accounting obligations, responding to requests from competent authorities, audit logs for regulatory compliance (GDPR, DORA, NIS2).
Legal basis for processing
EventEz's processing of personal data relies on the following legal bases:
| Legal basis | Processing concerned |
|---|---|
| Performance of a contract | Account management, provision of ticketing and registration services, payment processing |
| Consent | Geolocation, non-essential cookies, marketing communications, collection of specific data via custom forms |
| Legitimate interest | Service improvement, fraud prevention, statistical analysis, Platform security |
| Legal obligation | Retention of billing data, audit logs, response to judicial requisitions |
Data recipients
Personal data collected by EventEz may be shared with the following categories of recipients:
- EventEz internal team: authorized staff who need to access data as part of their duties (customer support, technical team, moderation team).
- Event organizers: registration and attendance data is shared with the organizers of the events the user registers for, limited to the information necessary to manage the event.
- Payment provider (NotchPay): data required to process financial transactions is securely transmitted to our payment provider.
- Hosts and technical providers: data is stored on secure servers operated by our hosting providers.
- Competent authorities: in the event of a judicial requisition or legal obligation, data may be disclosed to the competent Cameroonian authorities.
EventEz never sells, rents, or transfers its users' personal data to third parties for commercial purposes without their explicit consent.
International transfers
EventEz is based in Cameroon. As part of providing its services, certain personal data may be transferred to countries outside Cameroon, in particular for:
- Hosting data on servers located in other countries
- Processing international payments via NotchPay
- Using third-party services (email services, analytics, etc.)
When such transfers take place, EventEz ensures that appropriate safeguards are put in place to protect personal data, in accordance with international data protection standards:
- Approved standard contractual clauses
- Certification of providers to recognized security standards
- Encryption of data in transit and at rest
Retention period
Personal data is retained for the period strictly necessary for the purposes for which it was collected:
| Data type | Retention period |
|---|---|
| User account data | For the duration of account use + 3 years after the last activity |
| Transactional data | 10 years (accounting and tax obligations) |
| Event registration data | Duration of the event + 1 year |
| Messages and communications | 2 years after the last exchange |
| Connection and audit logs | 1 year (legal obligations) |
| Cookies | 13 months maximum |
Upon expiry of these periods, data is irreversibly deleted or anonymized.
User rights
In accordance with applicable legislation and GDPR principles, every user has the following rights over their personal data:
Right of access
Obtain confirmation that personal data is being processed and access that data, along with information about its processing.
Right to rectification
Request correction of inaccurate or incomplete personal data. This right can also be exercised directly from account settings.
Right to erasure
Request deletion of personal data, subject to legal retention obligations (in particular tax and accounting obligations).
Right to portability
Receive the personal data provided in a structured, commonly used, machine-readable format, and transmit it to another controller.
Right to object
Object to the processing of personal data on legitimate grounds, in particular regarding profiling and commercial prospecting.
Right to restriction
Request restriction of data processing in certain cases provided for by law, for example when disputing the accuracy of the data.
How to exercise your rights
To exercise any of these rights, you can send your request to our Data Protection Officer by email at dpo@eventez.online attaching a copy of your identity document. We are committed to responding to your request within 30 days.
Data security
EventEz implements appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction:
- Encryption: sensitive data is encrypted in transit (SSL/TLS) and at rest. Passwords are hashed using advanced security algorithms.
- Strong authentication: use of JSON Web Tokens (JWT) with automatic rotation of access tokens (15 minutes) and refresh tokens (7 days).
- Access control: data access is limited to authorized staff based on the principle of least privilege, with granular roles and permissions.
- Audit and traceability: a complete audit logging system to trace all actions performed on the Platform, in compliance with GDPR, DORA, and NIS2 requirements.
- Monitoring: continuous monitoring of the Platform to detect and quickly respond to any anomaly or intrusion attempt.
- Backups: regular data backups to ensure their availability and integrity in the event of an incident.
Despite these measures, no data transmission over the Internet can be guaranteed 100% secure. In the event of a personal data breach, EventEz is committed to notifying the competent authorities and affected users within the timeframes required by law.
Changes to this policy
EventEz reserves the right to modify this Privacy Policy at any time to adapt it to legal, regulatory, or technical developments.
In the event of a substantial change, users will be informed by:
- A notification on the Platform
- An email sent to the address associated with their account
- A visible notice on the Platform's homepage
The date of the last update is shown at the top of this policy. Continued use of the Platform after the publication of changes constitutes acceptance of the new version of the Privacy Policy.
We recommend that users regularly review this page to stay informed of any changes.
Contact - Data Protection Officer
For any question regarding this Privacy Policy, the processing of your personal data, or to exercise your rights, you can contact our Data Protection Officer (DPO):
Data Protection Officer
EventEz
Address: Douala, Cameroon
Email: dpo@eventez.online
Response time: 30 days maximum
If you believe that the processing of your personal data constitutes a violation of your rights, you also have the option of lodging a complaint with the competent supervisory authority in Cameroon.
This Privacy Policy was last updated on January 1, 2026. By continuing to use EventEz, you accept the terms of this policy.
