A hand holding a smartphone with a softly glowing screen in a warm office setting

Legal

GDPR Compliance

1. Introduction

This page explains how Eventology approaches the EU General Data Protection Regulation ("GDPR") in connection with our website (eventology.me) and our event technology and management services. It supplements our Privacy Policy and applies specifically to individuals located in the European Economic Area ("EEA") whose personal data we process.

2. When GDPR Applies to Us

Although Eventology is based in Amman, Jordan, GDPR can still apply to our processing where it relates to offering services to, or monitoring the behavior of, individuals located in the EEA — for example, where an EEA-based attendee registers for an event we operate registration and access control for.

3. Our Role: Controller vs. Processor

3.1. When you interact with our website directly (browsing, contacting us, requesting a proposal), Eventology acts as the data controller for your personal data.

3.2. When we deliver registration, badge, or access control services for a client's event, we generally act as a data processor, handling attendee data under the instructions of the event organizer (our client), who acts as the data controller for that event. Where GDPR requires it, we enter into data processing arrangements with our clients covering the nature, purpose, and duration of processing, consistent with Article 28 GDPR.

4. Lawful Basis for Processing

Depending on the context, we rely on the following lawful bases: your consent (e.g., registration form submission), performance of a contract (e.g., delivering the Services you or your organization requested), and our legitimate interests (e.g., website analytics, fraud prevention), balanced against your rights.

For details on the specific cookies and tracking tools this involves, see our Cookies Policy.

5. Your Rights Under GDPR

If GDPR applies to you, you have the right to: access your personal data; request correction or erasure; restrict or object to processing; request data portability; withdraw consent at any time where processing is based on consent; and lodge a complaint with your local EU supervisory authority. To exercise these rights, contact us at [email protected]. Where your data relates to an event we processed on behalf of a client, we may direct your request to that client where they are the appropriate party to respond.

6. International Data Transfers

Where personal data is transferred outside the EEA (for example, to our infrastructure or service providers), we take reasonable steps to ensure an adequate level of protection, consistent with GDPR's rules on international transfers.

7. Representation in the EU

Article 27 of GDPR requires controllers and processors without an EU establishment to appoint an EU representative, subject to an exemption for processing that is occasional, does not involve large-scale special category data, and is unlikely to result in a risk to individuals' rights. We assess this on an ongoing basis in light of the nature and scale of our EEA-related processing. If you require our EU representative's contact details and believe Article 27 applies to a specific engagement, please contact us at [email protected].

8. Data Retention

We retain personal data only as long as necessary for the purposes described in our Privacy Policy, and in line with our standard practice of securely purging event-related data once final reporting is complete.

9. Contact Us

Eventology
Amman, Jordan
Email: [email protected]
Phone: +962 77 725 3749