Privacy Policy
Last updated: August 3, 2026
1. Who we are
This Privacy Policy explains how [Legal Entity Name], doing business as Zento Events ("Zento", "we", "us"), collects and handles personal information through zentoevents.com and the Zento Events platform (together, the "Service").
When our customers use the Service to run their own events, we act as a processor on their behalf. In that case the event organizer is the controller of registrant data and their privacy notice governs how that data is used.
2. Information we collect
- Account information: name, business email, phone, company, billing contact.
- Registrant information submitted through your event forms: name, email, phone, mailing address, and any custom fields you configure.
- Transaction metadata: amounts, status, timestamps and confirmation references. Full payment card numbers are transmitted directly to your payment gateway and are not stored by Zento.
- Usage and device data: IP address, browser type, pages viewed, and timestamps, collected through server logs and limited analytics.
- Communications: messages you send us through forms, email or support.
3. How we use information
- to provide, maintain, secure and improve the Service;
- to process registrations and send transactional email such as confirmations, reminders, receipts and event updates;
- to bill subscriptions and optional services;
- to respond to inquiries and provide support;
- to detect, investigate and prevent fraud or abuse;
- to comply with legal obligations.
We do not sell personal information, and we do not use registrant data to market our own products to your attendees.
4. Legal bases
Where the GDPR or similar law applies, we process personal information on the basis of contract performance, our legitimate interests in operating and securing the Service, consent where required, and compliance with legal obligations.
5. Sharing and subprocessors
We share personal information with service providers who help us operate the Service, including cloud hosting and database infrastructure, transactional email delivery, error monitoring, and subscription billing. These providers are bound by contract to process data only on our instructions. We may also disclose information when required by law or to protect rights and safety, and in connection with a merger, acquisition or asset sale. A current list of subprocessors is available on request at [privacy@yourdomain.com].
6. Cookies
We use strictly necessary cookies for authentication and session management, and limited analytics cookies to understand aggregate site usage. You can control cookies through your browser settings; disabling necessary cookies may prevent parts of the Service from working.
7. Retention
We retain account data for the life of your subscription and for a reasonable period afterward to meet legal, tax and accounting requirements. Registrant data is retained according to the event organizer's configuration and instructions. Following termination, Customer Data may be exported for thirty (30) days and is then deleted from active systems and, on our standard schedule, from backups.
8. Security
We use TLS encryption in transit, encryption at rest, row-level tenant isolation in the database, role-based access controls, and audit logging. Payment card details go directly to your payment gateway and are never stored by Zento. No system is perfectly secure, but we work to keep this one boring.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal information, and to object to certain processing or withdraw consent. Registrants should direct requests to the event organizer that collected their data; we will assist our customers in responding. To exercise rights regarding data for which Zento is the controller, contact [privacy@yourdomain.com].
10. International transfers
Personal information may be processed in the United States and other countries where our service providers operate. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
11. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal information. If you believe a child has provided information, contact us and we will delete it.
12. Changes and contact
We may update this Policy from time to time and will revise the "last updated" date above. Questions, concerns or requests: [privacy@yourdomain.com], [Legal Entity Name], [Street Address, City, State ZIP].