Privacy Policy
CentreEvents operates across multiple countries. Which version of this Policy applies to you depends on where your organisation is based -- pick the one that matches, or ask your event organiser if you're not sure.
Last updated: 31 August 2026
1. Introduction
CentreEvents ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the CentreEvents platform (available at centre.events and related subdomains and applications).
This Policy is issued in compliance with the Botswana Data Protection Act, 2024 (Act No. 18 of 2024) ("the DPA"), in force since 14 January 2025 and administered by the Information and Data Protection Commission, and applicable international data protection standards, including the EU General Data Protection Regulation (GDPR) insofar as it governs the processing of your data by our infrastructure providers (personal data stored in the European Union, Ireland; uploaded files on Cloudflare's global infrastructure).
By using CentreEvents, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of it, please discontinue use of the platform.
2. Who We Are
CentreEvents is operated from Gaborone, Botswana. We are the data controller in respect of personal information processed through the platform on our own behalf (account management, security, platform operations). Where we process personal information on behalf of event organisers (attendee registrations, communications, check-in records), we act as a data processor on the organiser's instructions.
Data Protection contact: privacy@centre.events
General contact: hello@centre.events · +267 73 570 183
3. Personal Information We Collect
We collect personal information in the following categories:
3.1 Account and User Information
When you register an account: full name, email address, password (stored in irreversibly hashed form, we cannot recover your password), organisation name, and your assigned role on the platform.
3.2 Event Registration and Attendee Information
When you register for an event hosted on our platform, we collect on behalf of the event organiser: full name, email address, phone number (where requested), company or organisation, ticket type and pricing tier, payment status and amounts paid, a unique QR code identifier for check-in, and check-in timestamp and method. Full payment card details are handled exclusively by our payment processor and are never stored on CentreEvents servers.
3.3 RSVP and Invitation Data
When you respond to an event invitation: your RSVP response (accepted, declined, or tentative), your contact details as provided, and your IP address at the time of response.
3.4 Technical and Usage Information
We automatically collect: IP address, browser type and version, device type and operating system, pages and features used, login timestamps and session information, and user agent string. This information is recorded in our security audit logs.
3.5 Communications Data
When we send you transactional emails, our email delivery provider may collect delivery status information (whether the email was delivered). We do not use tracking pixels for marketing purposes.
3.6 Marketing Preferences
Where you have consented to receive marketing communications, we record your consent decision, the date and time it was given, and the channel through which it was obtained.
3.7 Exhibitor Lead Data
If an exhibitor at an event scans your attendee QR badge with your knowledge and agreement, your contact information may be captured as a lead. CentreEvents stores this data on behalf of exhibitors and does not use it for its own marketing.
4. Legal Basis for Processing
| Purpose | Legal Basis (DPA 2024, s.26) |
|---|---|
| Creating and managing your account | Performance of a contract (s.26(b)) |
| Processing event registrations and check-in | Performance of a contract (s.26(b)) |
| Sending transactional event communications | Performance of a contract / Legitimate interests (s.26(f)) |
| Sending marketing and promotional emails | Consent (s.26(a)): you may withdraw at any time |
| Security monitoring, fraud prevention, and audit logging | Legitimate interests (s.26(f)): platform integrity |
| Platform improvement and aggregated analytics (no identifiable data) | Legitimate interests (s.26(f)) |
| Cookie-free aggregate website traffic counting (Cloudflare Web Analytics; no cookies, no IP storage, no identifiable data -- see Section 5.2) | Legitimate interests (s.26(f)) |
| Analytics cookies (Google Analytics, Microsoft Clarity) | Consent (s.26(a)): you may withdraw at any time via the cookie banner |
| Compliance with legal obligations | Legal obligation (s.26(c)) |
| Responding to data subject requests | Legal obligation (s.26(c)) / Legitimate interests |
6. International Data Transfers
CentreEvents is based in Botswana. Your personal data (account, event, and registration information) is primarily stored and processed in Ireland (European Union) through our cloud database provider. Uploaded files (artwork, documents, and other attachments) are stored on Cloudflare's global infrastructure, which is certified under the EU-US Data Privacy Framework and subject to Standard Contractual Clauses. Ireland is one of the countries the Minister has designated, by Order published in the Gazette, as ensuring an adequate level of protection for personal data transferred from Botswana (Transfer of Personal Data Order, 2022, continued in force under the Data Protection Act, 2024 as an adequacy decision).
Processing in the EU provides meaningful protections for your data, including restrictions on onward transfers, mandatory security standards, data breach notification obligations, and enforceable data subject rights. Cloudflare's participation in the EU-US Data Privacy Framework provides equivalent safeguards for uploaded files processed on its global network.
Separately from where your account and registration data is stored, Cloudflare's network operates on an "anycast" model: rather than every visitor's request travelling to one fixed server, it is automatically routed to whichever of Cloudflare's data centres is best placed to answer it at that moment, which is often the one geographically closest to the visitor. Cloudflare operates real data centres within Southern Africa, including Johannesburg, Cape Town and Durban (and, at times, Gaborone), so a visitor in Botswana or South Africa may often have their connection served from a nearby regional facility rather than one in Europe or the United States. Exactly which facility answers a given request can change from one moment to the next -- for example during maintenance or based on network conditions -- so this is described here as how the network generally behaves, not as a guarantee that any specific city always serves any specific country. This only concerns how content is delivered and cached at the network edge; it does not change where your account, event and registration data is stored at rest, which remains Ireland (European Union) as described above.
Where your data is processed by providers located in the United States, such transfers from the EU are governed by the EU-US Data Privacy Framework and/or Standard Contractual Clauses, providing appropriate safeguards.
Your consent. When you register for an event, we ask you to agree to this international processing at the point of registration. Event organisers who use CentreEvents to collect personal information from others accept a separate, explicit data processing and international transfer agreement inside their dashboard before they can operate. You may withdraw your consent by closing your account or contacting us, subject to records we are required to keep by law.
We acknowledge our obligations under Part XIV of the Data Protection Act, 2024 in respect of cross-border data transfers, and we maintain contractual safeguards with all international processors. To request details of the safeguards in place, contact privacy@centre.events.
7. Data Retention
We retain your personal information only for as long as necessary for the purposes described in this Policy, or as required by law.
| Data Category | Retention Period | Reason |
|---|---|---|
| Active account data | Until you request deletion | Service provision |
| Transaction, billing and payment records | 20 years | Financial Intelligence Act, 2022 (s.32) record-keeping; Botswana tax law |
| Paid registration and check-in records | 20 years | Tied to the financial transaction (Financial Intelligence Act, 2022 s.32) |
| Free event registration and check-in records | 5 years from the event date | Contractual and event records |
| Audit and security logs | 3 years | Security and fraud investigation |
| Marketing consent records | Until withdrawal + 1 year | Evidence of consent lawfulness |
| Inactive accounts (no login for 3 years) | 3 years, then deleted or anonymised | Storage limitation principle (DPA 2024, s.23) |
Where a registration involves a payment, the related transaction and customer due diligence records are retained for 20 years as required by the Financial Intelligence Act, 2022. This legal obligation overrides a request to delete that specific data while the retention period runs. After the applicable retention period, your data is securely deleted or irreversibly anonymised.
8. Your Rights Under the DPA 2024
As a data subject, you have the following rights under the Botswana Data Protection Act, 2024:
Right of Access (s.42)
You may request a copy of the personal information we hold about you, together with information about how and why it is processed.
Right to Rectification (s.43)
You may request that we correct any inaccurate, incomplete, or misleading personal information we hold about you.
Right to Erasure (s.44)
You may request deletion of your personal information where there is no overriding lawful basis for continued processing. Note: we may be required to retain certain records for legal or contractual reasons.
Right to Restriction of Processing (s.45)
You may request that we restrict the processing of your personal information in certain circumstances, for example while a correction request is pending.
Right to Data Portability (s.47)
You may request your personal information in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
Right to Object (s.48)
You may object to processing based on legitimate interests, and to direct marketing at any time.
Right to Withdraw Consent (s.28)
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right to Lodge a Complaint (s.80)
You have the right to lodge a complaint with the Information and Data Protection Commission (IDPC) if you believe your rights have been infringed.
To exercise any of these rights, please submit a request at centre.events/data-request or email privacy@centre.events. We will respond within one month (extendable by up to two further months for complex requests, per section 38 of the DPA). We may ask you to verify your identity before processing your request. There is no charge for reasonable requests.
10. Security Measures
We implement appropriate technical and organisational measures to protect your personal information, including:
- All data in transit is encrypted using TLS (HTTPS)
- All data at rest is encrypted by our database provider (AES-256)
- Passwords are irreversibly hashed, we cannot retrieve your password
- Database access is controlled by row-level security policies; each user can only access data they are authorised to see
- Role-based access controls limit what each staff member can access
- All significant platform actions are recorded in a tamper-evident audit log
- Sign-in and sign-up forms are protected against automated attacks by CAPTCHA
- Regular automated database backups are maintained by our hosting provider
Despite these measures, no system can be made completely secure. In the event of a personal data breach, we will notify the Information and Data Protection Commission without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will also notify you directly without undue delay, in accordance with sections 63 and 64 of the Data Protection Act, 2024.
11. Children
CentreEvents is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@centre.events and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our practices. When we make material changes, we will notify you by email or by posting a prominent notice on the platform before the changes take effect. The "Last Updated" date at the top of this page indicates when the Policy was last revised. Continued use of the platform after the effective date of a revised Policy constitutes acceptance of the changes.
13. Contact and Complaints
For any questions, concerns, or requests relating to this Privacy Policy or our data protection practices:
Email: privacy@centre.events
General: hello@centre.events
Phone: +267 73 570 183
Post: CentreEvents, Gaborone, Botswana
If you are not satisfied with our response, you have the right to complain to the Information and Data Protection Commission (IDPC).