Skip to main content
Legal

Privacy Policy

CentreEvents operates across multiple countries. Which version of this Policy applies to you depends on where your organisation is based -- pick the one that matches, or ask your event organiser if you're not sure.

Last updated: 31 August 2026

1. Introduction

CentreEvents ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the CentreEvents platform (available at centre.events and related subdomains and applications).

This Policy is issued in compliance with the Botswana Data Protection Act, 2024 (Act No. 18 of 2024) ("the DPA"), in force since 14 January 2025 and administered by the Information and Data Protection Commission, and applicable international data protection standards, including the EU General Data Protection Regulation (GDPR) insofar as it governs the processing of your data by our infrastructure providers (personal data stored in the European Union, Ireland; uploaded files on Cloudflare's global infrastructure).

By using CentreEvents, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please discontinue use of the platform.

2. Who We Are

CentreEvents is operated from Gaborone, Botswana. We are the data controller in respect of personal information processed through the platform on our own behalf (account management, security, platform operations). Where we process personal information on behalf of event organisers (attendee registrations, communications, check-in records), we act as a data processor on the organiser's instructions.

Data Protection contact: privacy@centre.events

General contact: hello@centre.events · +267 73 570 183

3. Personal Information We Collect

We collect personal information in the following categories:

3.1 Account and User Information

When you register an account: full name, email address, password (stored in irreversibly hashed form, we cannot recover your password), organisation name, and your assigned role on the platform.

3.2 Event Registration and Attendee Information

When you register for an event hosted on our platform, we collect on behalf of the event organiser: full name, email address, phone number (where requested), company or organisation, ticket type and pricing tier, payment status and amounts paid, a unique QR code identifier for check-in, and check-in timestamp and method. Full payment card details are handled exclusively by our payment processor and are never stored on CentreEvents servers.

3.3 RSVP and Invitation Data

When you respond to an event invitation: your RSVP response (accepted, declined, or tentative), your contact details as provided, and your IP address at the time of response.

3.4 Technical and Usage Information

We automatically collect: IP address, browser type and version, device type and operating system, pages and features used, login timestamps and session information, and user agent string. This information is recorded in our security audit logs.

3.5 Communications Data

When we send you transactional emails, our email delivery provider may collect delivery status information (whether the email was delivered). We do not use tracking pixels for marketing purposes.

3.6 Marketing Preferences

Where you have consented to receive marketing communications, we record your consent decision, the date and time it was given, and the channel through which it was obtained.

3.7 Exhibitor Lead Data

If an exhibitor at an event scans your attendee QR badge with your knowledge and agreement, your contact information may be captured as a lead. CentreEvents stores this data on behalf of exhibitors and does not use it for its own marketing.

5. How We Share Your Information

We do not sell, rent, or trade your personal information. We share it only in the following limited circumstances:

5.1 With Event Organisers

When you register for an event, your registration data is shared with the event organiser who hosted that event on CentreEvents. The organiser is an independent data controller in respect of how they use your information for their event operations. We recommend reviewing each organiser's own privacy practices. Our relationship with organisers is governed by our Terms of Use and, where applicable, a Data Processing Agreement.

5.2 With Service Providers (Sub-processors)

We use a small number of specialist service providers who process personal information on our behalf, under contractual data protection obligations. We describe them here by function and location. The specific identity of each sub-processor is available to data subjects and regulators on request to privacy@centre.events.

Function Purpose Location Safeguards
Cloud database, authentication and account storage Stores your account, event and registration data and manages secure sign-in European Union (Ireland, eu-west-1) GDPR (EU); encryption in transit and at rest
Application hosting, content delivery, file storage and security Serves the platform quickly and safely, protects against attacks and bots, and stores uploaded files (artwork, documents) Global edge network with points of presence worldwide, including regional facilities in Southern Africa (e.g. Johannesburg and Cape Town) -- see Section 6 below; Cloudflare is certified under the EU-US Data Privacy Framework EU-US Data Privacy Framework; Standard Contractual Clauses where applicable
Cookie-free website traffic counting (Cloudflare Web Analytics, same provider as hosting above) Counts anonymous page views and general visit trends (e.g. approximate country, browser type, referring site, page performance). Sets no cookies, stores no IP address, and cannot identify you individually or across visits -- see our Cookie Policy, Section 5. Runs for every visitor and is not affected by your cookie banner choice, because it collects no personal data requiring consent. Global edge network (same infrastructure as hosting above) EU-US Data Privacy Framework; no persistent identifiers or cross-site tracking
Transactional email delivery Sends registration, ticket and account emails (no marketing tracking pixels) United States Standard Contractual Clauses (SCCs)
Card payment processing (when enabled) Authorises and settles card payments; full card details never reach CentreEvents servers Botswana and the payment provider's processing region PCI-DSS compliance; contractual data protection terms
Platform analytics, Google Analytics 4 (with consent only) Measures how the platform is used to improve the service; IP anonymisation enabled; no advertising; cookieless by default under Consent Mode v2 United States EU-US Data Privacy Framework; Standard Contractual Clauses; Google Consent Mode v2
Session analytics, Microsoft Clarity (with consent only) Anonymised heatmaps and session recordings to identify usability issues; all form fields and sensitive data are automatically masked United States Standard Contractual Clauses; Clarity processes only after user consent is given

5.3 Legal Disclosures

We may disclose your personal information to law enforcement agencies, regulatory authorities, courts, or other public authorities when required to do so by law, court order, or other lawful legal process, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal information may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.

6. International Data Transfers

CentreEvents is based in Botswana. Your personal data (account, event, and registration information) is primarily stored and processed in Ireland (European Union) through our cloud database provider. Uploaded files (artwork, documents, and other attachments) are stored on Cloudflare's global infrastructure, which is certified under the EU-US Data Privacy Framework and subject to Standard Contractual Clauses. Ireland is one of the countries the Minister has designated, by Order published in the Gazette, as ensuring an adequate level of protection for personal data transferred from Botswana (Transfer of Personal Data Order, 2022, continued in force under the Data Protection Act, 2024 as an adequacy decision).

Processing in the EU provides meaningful protections for your data, including restrictions on onward transfers, mandatory security standards, data breach notification obligations, and enforceable data subject rights. Cloudflare's participation in the EU-US Data Privacy Framework provides equivalent safeguards for uploaded files processed on its global network.

Separately from where your account and registration data is stored, Cloudflare's network operates on an "anycast" model: rather than every visitor's request travelling to one fixed server, it is automatically routed to whichever of Cloudflare's data centres is best placed to answer it at that moment, which is often the one geographically closest to the visitor. Cloudflare operates real data centres within Southern Africa, including Johannesburg, Cape Town and Durban (and, at times, Gaborone), so a visitor in Botswana or South Africa may often have their connection served from a nearby regional facility rather than one in Europe or the United States. Exactly which facility answers a given request can change from one moment to the next -- for example during maintenance or based on network conditions -- so this is described here as how the network generally behaves, not as a guarantee that any specific city always serves any specific country. This only concerns how content is delivered and cached at the network edge; it does not change where your account, event and registration data is stored at rest, which remains Ireland (European Union) as described above.

Where your data is processed by providers located in the United States, such transfers from the EU are governed by the EU-US Data Privacy Framework and/or Standard Contractual Clauses, providing appropriate safeguards.

Your consent. When you register for an event, we ask you to agree to this international processing at the point of registration. Event organisers who use CentreEvents to collect personal information from others accept a separate, explicit data processing and international transfer agreement inside their dashboard before they can operate. You may withdraw your consent by closing your account or contacting us, subject to records we are required to keep by law.

We acknowledge our obligations under Part XIV of the Data Protection Act, 2024 in respect of cross-border data transfers, and we maintain contractual safeguards with all international processors. To request details of the safeguards in place, contact privacy@centre.events.

7. Data Retention

We retain your personal information only for as long as necessary for the purposes described in this Policy, or as required by law.

Data Category Retention Period Reason
Active account data Until you request deletion Service provision
Transaction, billing and payment records 20 years Financial Intelligence Act, 2022 (s.32) record-keeping; Botswana tax law
Paid registration and check-in records 20 years Tied to the financial transaction (Financial Intelligence Act, 2022 s.32)
Free event registration and check-in records 5 years from the event date Contractual and event records
Audit and security logs 3 years Security and fraud investigation
Marketing consent records Until withdrawal + 1 year Evidence of consent lawfulness
Inactive accounts (no login for 3 years) 3 years, then deleted or anonymised Storage limitation principle (DPA 2024, s.23)

Where a registration involves a payment, the related transaction and customer due diligence records are retained for 20 years as required by the Financial Intelligence Act, 2022. This legal obligation overrides a request to delete that specific data while the retention period runs. After the applicable retention period, your data is securely deleted or irreversibly anonymised.

8. Your Rights Under the DPA 2024

As a data subject, you have the following rights under the Botswana Data Protection Act, 2024:

Right of Access (s.42)

You may request a copy of the personal information we hold about you, together with information about how and why it is processed.

Right to Rectification (s.43)

You may request that we correct any inaccurate, incomplete, or misleading personal information we hold about you.

Right to Erasure (s.44)

You may request deletion of your personal information where there is no overriding lawful basis for continued processing. Note: we may be required to retain certain records for legal or contractual reasons.

Right to Restriction of Processing (s.45)

You may request that we restrict the processing of your personal information in certain circumstances, for example while a correction request is pending.

Right to Data Portability (s.47)

You may request your personal information in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to Object (s.48)

You may object to processing based on legitimate interests, and to direct marketing at any time.

Right to Withdraw Consent (s.28)

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

Right to Lodge a Complaint (s.80)

You have the right to lodge a complaint with the Information and Data Protection Commission (IDPC) if you believe your rights have been infringed.

To exercise any of these rights, please submit a request at centre.events/data-request or email privacy@centre.events. We will respond within one month (extendable by up to two further months for complex requests, per section 38 of the DPA). We may ask you to verify your identity before processing your request. There is no charge for reasonable requests.

9. Cookies and Tracking Technologies

We use cookies and browser storage technologies for security, functionality, and (with your consent) platform analytics. Please see our full Cookie Policy for the complete list.

In summary, we use:

  • Authentication session cookies: strictly necessary for you to log in and use the platform. Cannot be disabled while using the service.
  • Bot and abuse protection (CAPTCHA): a security technology that analyses browser-based signals to distinguish humans from bots on authentication forms. Strictly necessary for account security.
  • Analytics cookies (with consent only): we use Google Analytics 4 and Microsoft Clarity to understand how the platform is used, so we can improve it. These tools are only activated after you explicitly choose "Accept analytics" in the cookie banner. We implement Google Consent Mode v2: by default, all analytics data collection is blocked. If you decline, GA4 operates in cookieless aggregate-modelling mode only and Clarity is not loaded. No advertising cookies or cross-site tracking are used.
  • Cookie-free traffic counting (always on): separately, we use Cloudflare Web Analytics to count anonymous page views. It is not a cookie, sets nothing on your device, does not store your IP address, and cannot identify you. Because it involves no personal data, it runs for every visitor regardless of your cookie banner choice.

10. Security Measures

We implement appropriate technical and organisational measures to protect your personal information, including:

  • All data in transit is encrypted using TLS (HTTPS)
  • All data at rest is encrypted by our database provider (AES-256)
  • Passwords are irreversibly hashed, we cannot retrieve your password
  • Database access is controlled by row-level security policies; each user can only access data they are authorised to see
  • Role-based access controls limit what each staff member can access
  • All significant platform actions are recorded in a tamper-evident audit log
  • Sign-in and sign-up forms are protected against automated attacks by CAPTCHA
  • Regular automated database backups are maintained by our hosting provider

Despite these measures, no system can be made completely secure. In the event of a personal data breach, we will notify the Information and Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, in accordance with sections 63 and 64 of the Data Protection Act, 2024.

11. Children

CentreEvents is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@centre.events and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. When we make material changes, we will notify you by email or by posting a prominent notice on the platform before the changes take effect. The "Last Updated" date at the top of this page indicates when the Policy was last revised. Continued use of the platform after the effective date of a revised Policy constitutes acceptance of the changes.

13. Contact and Complaints

For any questions, concerns, or requests relating to this Privacy Policy or our data protection practices:

Email: privacy@centre.events

General: hello@centre.events

Phone: +267 73 570 183

Post: CentreEvents, Gaborone, Botswana

If you are not satisfied with our response, you have the right to complain to the Information and Data Protection Commission (IDPC).