Privacy Policy
Effective date: 14 May 2026
Diplomatic Protocol Event Management (“DPEM”, “we”, “our”) is committed to protecting your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have in relation to it.
1. Who We Are
DPEM is operated from Coquitlam, British Columbia, Canada (652 Whiting Way, V3J 0K3). For data protection purposes, DPEM acts as the data controller for information collected through this platform.
Contact for privacy matters: privacy@dpem.app
2. Data We Collect
2.1 Registration and Account Data
When you register for an event or create an attendee portal account, we collect your first name, last name, email address, professional title, organisation, country, and any dietary or accessibility requirements you voluntarily provide.
2.2 Payment Data
Payment card details are processed exclusively by Stripe, Inc. and are never stored on DPEM systems. We retain a record of transaction identifiers, amounts, and payment status for accounting and fraud prevention purposes.
2.3 Event Attendance Data
We record your attendance at events, including check-in time and accreditation tier, to administer the event programme and provide post-event certificates where applicable.
2.4 Communications
If you contact us or submit an enquiry, we retain your message and contact details to respond and maintain a correspondence record.
2.5 Technical Data
Our servers log IP addresses, browser type, and page requests for security monitoring and system diagnostics. These logs are retained for up to 90 days and are not used for profiling.
2.6 Analytics
We use privacy-preserving analytics (Plausible Analytics) to understand aggregate traffic patterns. No personal identifiers or cookies are used by this service; data is processed in the EU.
3. Legal Basis for Processing
We process your data on the following legal bases under the GDPR:
- Contract performance — to register you, issue tickets, process payments, and provide event access.
- Legitimate interests — security monitoring, fraud prevention, and aggregate analytics.
- Consent — for newsletter subscriptions (which you may withdraw at any time).
- Legal obligation — where required to retain records for tax or regulatory compliance.
4. How We Use Your Data
- Processing your event registration and ticket issuance
- Facilitating on-site check-in and access control
- Sending transactional emails (booking confirmation, QR codes, reminders)
- Sending programme updates if you have subscribed to them
- Responding to your enquiries
- Preventing and detecting fraud or security incidents
- Meeting our legal and accounting obligations
5. Data Sharing
We do not sell your personal data. We share data only with service providers who act as data processors under GDPR-compliant agreements:
- Stripe, Inc. — payment processing
- Supabase, Inc. — cloud storage for event media and documents
- Resend, Inc. — transactional email delivery
- Sentry, Inc. — anonymised error reporting
- Plausible Analytics OÜ — privacy-preserving website analytics
We may disclose information when required by law or when necessary to protect the rights and safety of DPEM, our participants, or the public.
6. International Transfers
Some of our processors operate outside the European Economic Area. Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
7. Data Retention
We retain registration and payment records for seven years to meet our accounting obligations. Attendance records are retained for three years. Newsletter subscription data is held until you unsubscribe. Access logs are purged after 90 days.
8. Your Rights
Under applicable data protection law you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of your data where no overriding legal basis applies.
- Restriction — ask us to limit how we process your data in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time where processing is based on consent.
To exercise any of these rights, contact privacy@dpem.app. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
9. Cookies
DPEM uses strictly necessary session cookies for secure login and payment session management. We do not use tracking or advertising cookies. Please see our Cookie Policy for full details.
10. Security
We implement technical and organisational security measures including TLS encryption in transit, encrypted database storage, role-based access controls, and regular security audits. Payment data never transits DPEM systems.
11. Children
DPEM events are designed for professional adult audiences. We do not knowingly collect data from individuals under 16. If you believe a minor has submitted data, contact us immediately.
12. Changes to This Policy
We may update this policy to reflect changes in our practices or applicable law. Material changes will be communicated by email to registered attendees and displayed prominently on this page. Continued use of DPEM after the effective date constitutes acceptance of the updated policy.
13. Contact
For any privacy-related enquiries: privacy@dpem.app
Diplomatic Protocol Event Management
652 Whiting Way, Coquitlam, BC V3J 0K3, Canada
