Legal
Security Overview
How EventNook Pte. Ltd. protects the data entrusted to NookPass — our controls, certifications, sub-processors, and commitments.
Last updated: 6 August 2026 · Version 1.0
🛡 ISO/IEC 27001 certified
1. Our commitment
Security is foundational to NookPass. EventNook Pte. Ltd., the company behind NookPass, operates an Information Security Management System (ISMS) certified to ISO/IEC 27001, the international standard for managing information security. Our controls cover the people, processes, and technology involved in delivering the Service.
2. ISO/IEC 27001
Certified information security management
EventNook maintains a certified ISMS aligned to ISO/IEC 27001. Certification is maintained through regular independent audits and continual improvement of our security controls. A copy of our certificate is available to customers on request under NDA.
3. Infrastructure
- NookPass runs on reputable cloud infrastructure with strong physical and environmental controls provided by the underlying platform providers.
- Environments are segregated, and production access is restricted to authorized personnel.
- We use managed, regularly patched services to reduce our attack surface.
4. Data protection
- Encryption in transit — all traffic is protected with TLS.
- Encryption at rest — stored data and file assets are encrypted at rest.
- Backups — data is backed up regularly, with restore procedures tested as part of our continuity planning.
- Data minimization — we collect and share only what is needed to provide the Service.
5. Access control
- Role-based access and the principle of least privilege govern internal access.
- Administrative access requires strong authentication and is logged.
- Access is reviewed periodically and revoked promptly when no longer needed.
6. Application security
- Secure development practices, code review, and dependency monitoring.
- All content and configuration is served through our controlled backend; direct public access to underlying data stores is denied by default.
- Input handling and output encoding protect against common web vulnerabilities.
7. Sub-processors
To deliver the Service, EventNook engages a limited number of trusted third-party sub-processors. Each is bound by contractual obligations requiring appropriate confidentiality and security safeguards, and processes personal data only on our instructions and for the purposes below. Our primary hosting and database storage are located in Singapore; certain providers (for example, email delivery and AI services) operate from other regions. This list is current as of the date above and may change; we will provide notice of material changes to organizers as required.
| Sub-processor | Purpose | Primary location |
|---|---|---|
| Supabase | Database, file storage, and authentication | Singapore (primary) |
| Amazon Web Services (AWS) | Cloud infrastructure and file storage | Singapore (primary) |
| Vercel Inc. | Application hosting and content delivery | Singapore (primary) / global edge |
| Twilio SendGrid | Transactional email delivery | United States / global |
| Google LLC — Gemini API | AI features (see section 8) | United States |
| Anthropic PBC — Claude API | AI features (see section 8) | United States |
| OpenAI, L.L.C. — OpenAI API | AI features (see section 8) | United States |
An up-to-date sub-processor list is available to organizers on request.
8. AI and machine learning
Some NookPass features use third-party artificial-intelligence models to power capabilities such as content generation and summarization, smart recommendations, and productivity assistance. For these features we may send relevant input to the following AI providers, acting as sub-processors:
- Google — Gemini API
- Anthropic — Claude API
- OpenAI — OpenAI API
Our safeguards for AI processing include:
- Data minimization — we send only the data necessary for the feature, and avoid sending sensitive data where it is not required.
- No model training on your data — we use these providers under API terms and configurations designed so that your content is not used to train their foundation models, and we rely on their enterprise/zero-retention options where available.
- No solely-automated significant decisions — AI outputs are assistive; we do not use them to make decisions producing legal or similarly significant effects about individuals.
- Human oversight — AI-generated content can be reviewed and edited by organizers before it is published.
- Transparency — where practical, AI-assisted features are identified as such in the app.
Use of AI features is subject to the applicable providers' terms and policies. Organizers who prefer not to use AI-assisted features should contact us to discuss available options.
9. Monitoring and incident response
We monitor our systems for anomalies and maintain a documented incident response process. In the event of a security incident affecting personal data, we will act promptly to contain and remediate it and will notify affected organizers and authorities as required by applicable law.
10. Business continuity
We maintain backup and recovery procedures designed to restore service and data in the event of disruption, and we review these procedures as part of our ISMS.
11. Compliance
- ISO/IEC 27001 — certified information security management.
- Singapore PDPA — we handle personal data in line with the Personal Data Protection Act.
- GDPR — where applicable, we support obligations under the EU/UK General Data Protection Regulation, including sub-processor transparency and appropriate transfer safeguards.
See our Privacy Policy for how personal data is handled.
12. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please contact us at [email protected] with details so we can investigate. Please act in good faith, avoid privacy violations and service disruption, and give us a reasonable time to respond before public disclosure.
13. Contact
EventNook Pte. Ltd.
Security team
Email: [email protected]
Singapore