Legal
Privacy Policy
How EventNook Pte. Ltd. collects, uses, discloses, and protects personal data through the NookPass event companion app — for organizers, attendees, participants, exhibitors, and speakers.
Last updated: 6 August 2026 · Version 1.0 · Effective 6 August 2026
This policy is a comprehensive general template. It should be reviewed by qualified legal counsel and adapted to your actual data practices, sub-processors, and jurisdictions before publication.
1. Who we are
NookPass is an event companion application operated by EventNook Pte. Ltd. ("EventNook", "NookPass", "we", "us", "our"), a company incorporated in Singapore. We provide software that helps event organizers run conferences, exhibitions, corporate events, tradeshows, and similar gatherings, and that helps attendees navigate and take part in those events.
We take privacy seriously. EventNook maintains an information security management system certified to ISO/IEC 27001 and handles personal data in accordance with Singapore's Personal Data Protection Act 2012 (the "PDPA") and, where applicable, the EU/UK General Data Protection Regulation ("GDPR").
2. Scope of this policy
This policy applies to personal data we process in connection with:
- the NookPass mobile and web applications and related services (the "Service");
- the NookPass website; and
- communications between you and EventNook about the Service.
It applies to organizers (those who create and run events), attendees and participants (including delegates, guests, speakers, and exhibitor staff), and visitors to our website. It does not cover the independent privacy practices of event organizers or third-party platforms, which are governed by their own policies.
3. Our roles: controller and processor
The capacity in which EventNook processes personal data depends on the context:
As a processor / data intermediary
For most attendee data processed within a specific event, the organizer is the controller — they decide what is collected and why — and EventNook processes that data on their behalf and under their instructions.
As a controller
For data we determine the purposes of — such as account administration, service security, product improvement, and our own communications — EventNook acts as the controller.
Where an organizer is the controller, please also review that organizer's own privacy notice for the event you are attending.
4. Definitions
- Personal data — information about an identified or identifiable individual.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
- Controller — the party that determines the purposes and means of processing.
- Processor / data intermediary — a party that processes data on behalf of a controller.
- Organizer — a customer that creates or manages an event on NookPass.
- Attendee / participant — an individual who uses the app in connection with an event.
5. Information we collect
5.1 Information you provide to us
- Account and profile — name, email address, password (stored hashed), organization, job title, biography, photo, social or contact links, and other profile fields you choose to complete.
- Event and registration data — ticket or registration type, booking reference, sessions and workshops you register for, dietary or accessibility preferences where an organizer collects them, and check-in records.
- Agenda and engagement — sessions you bookmark, your personal schedule, poll responses, survey answers, and questions you submit in live Q&A.
- Networking and connections — connection requests, in-app messages, meeting bookings, and business cards you scan.
- Exhibitor and lead data — where you visit or interact with an exhibitor, or an exhibitor scans your badge, contact and interaction details captured as a lead for that exhibitor.
- User content — photos, documents, comments, and other content you upload or post.
- Support — information you provide when you contact us for help.
5.2 Information we collect automatically
- Usage data — features and screens used, actions taken, and time spent, used to operate and improve the Service.
- Device and technical data — device model, operating system, app version, language, unique device or installation identifiers, and network information.
- Log data — IP address, access times, and diagnostic or crash information.
- Location — approximate or precise location only where you enable it, for features such as venue wayfinding.
5.3 Information from third parties
- From organizers — the attendee list and registration details for their event.
- From registration platforms — where an organizer connects a system such as EventNook, Eventbrite, Luma, Cvent, or Bizzabo, the attendee and ticket data the organizer chooses to sync.
- From authentication providers — basic profile information if you sign in using a third-party login you choose.
6. How we use personal data
| Purpose | Examples |
|---|---|
| Provide the Service | Agenda, digital badge, maps, speakers, live Q&A, announcements, document sharing, photo albums. |
| Enable interactions you initiate | Connecting with attendees, messaging, scanning to connect, sharing your details with an exhibitor. |
| Support organizers | Attendance, engagement, and lead reporting for their own event, under their instructions. |
| Communicate | Service, security, and event-related notifications; responses to your requests. |
| Security and integrity | Authentication, fraud and abuse prevention, and protecting users. |
| Improve NookPass | Analytics and product development, using aggregated or de-identified data where practical. |
| Legal and compliance | Meeting legal obligations and enforcing our terms. |
7. Legal bases for processing
Where the GDPR or similar laws apply, we rely on one or more of the following:
- Performance of a contract — to provide the Service you or your organizer signed up for.
- Consent — for optional features such as certain notifications, precise location, or optional profile fields. You may withdraw consent at any time.
- Legitimate interests — to secure and improve the Service and to run events effectively, balanced against your rights.
- Legal obligation — where processing is required by law.
Under the PDPA, we collect, use, and disclose personal data with consent (including deemed consent) or as otherwise permitted, including under the legitimate-interests and business-improvement exceptions.
8. Cookies and similar technologies
Our website and web app use cookies and similar technologies to keep you signed in, remember preferences, maintain security, and understand usage. Strictly necessary technologies are always active; others are used in line with your choices where consent is required. You can control cookies through your browser settings; disabling some may affect functionality. Our mobile apps use device storage and software development kits for equivalent purposes.
9. Push notifications and communications
With your permission, we send push notifications for event updates, reminders, room changes, and networking activity. You can turn these off in your device settings. Service and security messages that are essential to your use of the Service may still be sent.
10. How we disclose personal data
- To your event organizer — organizers can access attendee data for their own event, including participation, engagement, and leads captured by exhibitors.
- To other attendees — only the profile information you choose to make visible, and details you share by connecting or scanning.
- To exhibitors — where you interact with an exhibitor or allow a badge scan, the associated lead information.
- To service providers and sub-processors — see section 11.
- Through integrations — see section 12.
- For legal reasons — to comply with law, respond to lawful requests, or protect rights, property, safety, and security.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not sell personal data, and we do not use attendee event data for our own advertising.
11. Service providers and sub-processors
We engage trusted vendors to help us operate the Service — for example, cloud hosting and storage, database and infrastructure services, messaging and email delivery, error monitoring, and analytics. These providers process personal data on our behalf under written agreements that require appropriate confidentiality and security safeguards, and only for the purposes we specify. A current list of key sub-processors is available to organizers on request.
12. Registration platform integrations
Organizers may connect NookPass to third-party registration or event platforms, including EventNook, Eventbrite, Luma, Cvent, and Bizzabo. When enabled, attendee and ticket data flows between those platforms and NookPass as the organizer configures. Your use of those platforms is governed by their own privacy policies, and EventNook is not responsible for their independent practices.
13. International data transfers
EventNook is based in Singapore, and we and our service providers may process personal data in countries other than your own. Where we transfer personal data across borders, we use appropriate safeguards — such as contractual protections consistent with the PDPA and, for transfers subject to the GDPR, standard contractual clauses or another lawful transfer mechanism — so that the data remains protected.
14. Data retention
We keep personal data only as long as necessary for the purposes described:
| Category | Typical retention |
|---|---|
| Attendee event data | For as long as the organizer's account or instructions require, then deleted or de-identified. |
| Account and profile | While your account is active and for a reasonable period afterwards. |
| Messages and connections | For the duration of the event and a limited period after, per organizer settings. |
| Logs and diagnostics | A limited period for security and troubleshooting. |
| Legal or financial records | As required by applicable law. |
15. How we protect data
We maintain administrative, technical, and physical safeguards designed to protect personal data, including encryption in transit and at rest, access controls, and monitoring, as part of our ISO/IEC 27001-certified information security program. No method of transmission or storage is completely secure, but we work continually to protect your information. See our Security Overview for more detail.
16. Your rights and choices
Depending on your location, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten"), subject to legal limits;
- obtain a portable copy of certain data;
- object to or restrict certain processing;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority (in Singapore, the Personal Data Protection Commission).
17. How to exercise your rights
For data processed on behalf of an organizer (most attendee data), please contact that organizer first, as they control it; we will assist them in responding. For data EventNook controls, or if you cannot reach the organizer, contact us using the details in section 22. We may need to verify your identity before acting, and we will respond within the timeframes required by applicable law.
18. Children's privacy
NookPass is designed for professional and organized events and is not directed to children. We do not knowingly collect personal data from children below the age of consent in their jurisdiction. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
19. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Some features (such as suggested connections) use simple logic to make recommendations, which you are free to ignore.
20. Third-party links and content
The Service may contain links to third-party websites or embed third-party content. We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.
21. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "last updated" date and, for material changes, provide additional notice through the app or by email. Your continued use of the Service after changes take effect constitutes acceptance where permitted by law.
22. How to contact us
For privacy questions or to exercise your rights, contact our Data Protection Officer:
EventNook Pte. Ltd.
Attn: Data Protection Officer
Email: [email protected]
Singapore
For individuals in the EU/UK, you may also have the right to contact your local data protection authority.