Legal

Privacy Policy

Last updated: September 2026

BadgeMe ("we", "us") provides event-management and attendee-engagement services to event organizers ("organizers"), who in turn collect data from their event participants ("attendees"). This policy explains what personal data we process on the marketing site and platform, why, and what your rights are.

Who we are

BadgeMe is provided by the company operating badgeme.eu, established in the European Union. For questions about this policy or your data, contact info@badgeme.eu. Where a controller relationship applies, the organizer running an event is the controller of attendee data, and BadgeMe acts as their processor under a data-processing agreement.

Data we collect

  • Marketing & sales enquiries: name, email, company, VAT ID, phone and message content you submit through our contact and invoice-request forms.
  • Accounts: name, email, organization, hashed password and account status when you register for BadgeMe.
  • Payments: processed exclusively by Stripe. We store the amount, currency, plan, Stripe session and payment-intident identifiers — never full card numbers.
  • Platform data: event, registration, check-in, networking and engagement data processed on behalf of organizers.
  • Technical data: minimal server logs (IP, user agent, timestamps) needed for security and abuse prevention.

Legal bases (GDPR Art. 6)

  • Contract (6(1)(b)): providing the platform, processing purchases, and answering pre-sales requests.
  • Legitimate interests (6(1)(f)): security, fraud prevention, service improvement, B2B follow-ups.
  • Consent (6(1)(a)): optional marketing emails and any attendee-facing features configured to require opt-in (e.g., AI-based networking suggestions).

Where data lives

BadgeMe is EU-hosted. Production databases and application servers are located within the EU. We do not transfer personal data outside the EEA except to sub-processors providing ancillary services (Stripe for payments, our cloud and email providers), relying on EU adequacy or standard contractual clauses where required.

Retention

  • Sales enquiries: up to 24 months, then deleted or anonymized.
  • Order/payment records: as required by applicable tax and accounting law (typically 10 years).
  • Platform data: retained per the organizer's configuration; organizers can delete events and attendee records at any time, and we honor deletion without undue delay.

Your rights

You may request access, rectification, erasure, restriction, data portability, or object to processing, and withdraw consent at any time. Contact info@badgeme.eu; we respond within 30 days. Attendee requests may be routed to the relevant event organizer, who is the controller for their event's data. You also have the right to complain to your EU data-protection authority.

Cookies

Our marketing site uses only functionally required cookies: an encrypted, HttpOnly session cookie once you sign in to purchase, and standard anti-forgery protection. We do not run advertising or cross-site tracking cookies. Payment pages on Stripe may set their own cookies under Stripe's policy.

Security

TLS everywhere, encrypted at-rest storage, least-privilege access, hashed passwords, rate limiting, and monitoring. No method is perfect; report concerns to info@badgeme.eu.

Changes

We will post any policy changes on this page and update the date above. Material changes affecting active customers are announced by email.