**Effective date: 22 September 2026**

This policy explains what personal data EventIQ, LLC ("EventIQ", "we", "us") collects on
**eventiq.io**, including the meeting-booking pages at **eventiq.io/book**, why we collect
it, how long we keep it, who processes it on our behalf, and what rights you have.

We wrote this policy from the actual data flows of our systems rather than from a template.
Where we name a retention period, our software enforces it.

## Who we are

EventIQ, LLC, 8 The Green, Suite B, Dover, Kent County, DE 19901, United States.

For anything related to your personal data, write to **info@eventiq.io**. We
answer every request from a person; there is no ticketing bot in front of this address.

## What this policy covers

- the marketing website at eventiq.io and its subpages (guides, comparisons, the Event ROI
  Calculator, the blog);
- the forms on that site ("Book a demo", early-access and integration requests, the
  calculator's results form);
- the meeting-booking pages at eventiq.io/book, including the confirmation, reminder,
  cancellation and rescheduling emails they send;
- the same booking pages when embedded in a frame on eventiq.io.

It does not cover the EventIQ product itself once you become a customer; that relationship
is governed by your customer agreement and the data-processing terms attached to it.

## What we collect, and why

### When you book a meeting with us

The booking page asks for the minimum needed to put a meeting in a calendar and send you
the details.

| Data | Why we need it | Where it comes from |
|---|---|---|
| Name | to address you in the invitation and emails | you type it |
| Work email | to send the calendar invitation, confirmation, reminders and any change; to let you manage the booking | you type it |
| Colleagues' emails (up to five, optional) | to invite them to the same meeting as optional attendees and copy them on the confirmation | you type them |
| Your time zone | to show available times in your local time and to state the meeting time correctly in emails | detected from your browser; you can change it on the page |
| Notes and answers to the host's questions | so the person you meet can prepare | you type them |
| Which link brought you here (for example `utm_source=signature`) | to know whether our email signature, the website or the calculator leads to meetings | the link you clicked |
| Your IP address | **only** to limit how many bookings and availability requests one address can make in a short time, which protects the host's calendar from being filled by a script | your connection |

Your IP address is used as a counter key for rate limiting and for nothing else. It is not
written into your booking record, is not joined with your name or email, and the counter
expires automatically within three days.

We do not run analytics on the booking pages, and they set no analytics cookies. The only
cookies they can set are Google's reCAPTCHA cookies, and only where the abuse protection
described under "Cookies and browser storage" is switched on.

**About your colleagues' addresses.** When you add colleagues, you confirm that you are
entitled to share their work email with us for this meeting. They receive the calendar
invitation and a copy of the confirmation; they do not receive separate reminders, because
their own calendar reminds them. If a colleague would rather not be included, either of you
can write to us and we will remove them from the invitation.

### When you submit a form on the website

The forms on eventiq.io ("Book a demo", early access, "Request Integration", and the form
under the Event ROI Calculator) collect what you enter — typically name, work email, company,
job title, and, depending on the form, the number of events you run, ticket revenue, marketing
budget, the date of your next paid event, the systems you use, and whether you have technical
sign-off.

Together with the form we record **how you arrived**, so that we can tell which channels bring
the right people: the page you came from, the page you landed on, campaign parameters in the
link (`utm_*`, `gclid`, `fbclid`), which button you pressed, the address of the page you were
on, and — only if you accepted analytics — the Google Analytics client identifier. If you used the ROI
Calculator, the values you entered and the result are attached to the form so that we can
continue the conversation from the same numbers.

Form submissions are delivered through **Formspree** (see "Who processes data for us") and
then handled by our team in our email and CRM.

### When you simply browse the marketing site

**Google Analytics 4 — only if you agree.** On your first visit we ask whether we may use
Google Analytics to understand which pages are read and which paths lead to a demo request.
Until you press "Accept", the Google Analytics library is **not loaded at all**: no request is
sent to Google and no cookie is set. If you decline, it stays that way. If you accept, Google
Analytics sets the `_ga` cookie, which contains a random identifier and no personal details.
You can change your mind at any time with the "Cookie settings" link at the bottom of every
page; withdrawing consent also deletes the Google Analytics cookies already set. We ask again
after twelve months.

**Ahrefs Web Analytics — cookieless.** We also use Ahrefs Web Analytics to count visits and
see which pages and referrers bring them. It sets no cookies, stores no identifier on your
device, and does not track you across sites, which is why it does not depend on the choice
above.

Neither tool is loaded on the booking pages.

We do not use advertising pixels, session recording, or fingerprinting.

### When our own staff sign in to the booking administration

This section is for completeness. The administration area at eventiq.io/book/admin is used
only by EventIQ staff. Signing in uses a one-time link sent by email (Firebase
Authentication) and a session cookie named `__session`. Connecting a staff calendar stores
Microsoft 365 access tokens for that staff member, encrypted with AES-256-GCM, so that the
booking system can read free/busy times and create calendar events. No guest data is
involved in that sign-in.

## How we use the data

- **To run the meeting you booked.** We create a calendar event in our Microsoft 365
  calendar with a Microsoft Teams link, invite you and any colleagues you named, and send a
  confirmation, a reminder the day before and one an hour before, and a notice if the meeting
  is cancelled or moved. Those emails come from the mailbox of the EventIQ person you are
  meeting, not from a generic sender.
- **To let you manage the booking yourself.** The confirmation contains a link that lets you
  cancel or reschedule without writing to anyone. The link is unique to your booking, is
  stored only as a hash on our side, and stops working one day after the meeting.
- **To respond to your request** when you submit a form, and to follow up on it.
- **To keep the service working and safe:** rate limiting, detecting automated abuse, and,
  where enabled, Google reCAPTCHA through Firebase App Check to confirm that a booking comes
  from a real page rather than a script.
- **To measure our marketing** at the level of channels and pages, not of individuals.

We do not sell personal data, and we do not share it for cross-context behavioural
advertising.

## Legal bases (for people in the EEA, the UK and Switzerland)

| Purpose | Basis |
|---|---|
| Scheduling and running a meeting you asked for; sending the related emails | steps at your request before entering into a contract (Art. 6(1)(b) GDPR) |
| Responding to a demo, early-access or integration request | the same |
| Rate limiting, abuse prevention, security | our legitimate interest in keeping the service available and the host's calendar usable (Art. 6(1)(f)) |
| Google Analytics on the marketing site | your consent (Art. 6(1)(a)), given in the banner and withdrawable at any time under "Cookie settings" |
| Cookieless visit statistics (Ahrefs) and attribution of form submissions | our legitimate interest in understanding which channels work (Art. 6(1)(f)) |
| Following up with a business contact after a request | our legitimate interest in business-to-business communication; you can object at any time |

## Who processes data for us

We use a small number of service providers. Each processes data only on our instructions
and under a written agreement.

| Provider | What for | Where |
|---|---|---|
| Google LLC — Firebase Hosting, Cloud Functions, Cloud Firestore, Firebase Authentication, Firebase App Check / reCAPTCHA, Google Analytics | serving the website and booking pages, storing bookings and schedules, staff sign-in, abuse protection, site analytics | United States (us-central1) |
| Ahrefs Pte. Ltd. — Ahrefs Web Analytics | cookieless visit statistics for the marketing site | Singapore / EU |
| Microsoft Corporation — Microsoft 365, Exchange Online, Microsoft Teams | the calendar in which your meeting is created, the Teams meeting itself, and the mailbox that sends booking emails | Microsoft's data centres for our tenant |
| Formspree, Inc. | receiving website form submissions and forwarding them to us | United States |

We may also disclose personal data if the law requires it, to protect our rights or
safety or those of others, or as part of a merger, acquisition or sale of assets, in which
case this policy continues to apply to the transferred data.

## International transfers

Our systems run in the United States. If you are in the EEA, the UK or Switzerland, this
means your data is transferred outside your region. We rely on the European Commission's
Standard Contractual Clauses and the UK Addendum with our providers, and, where a provider is
certified under the EU–US Data Privacy Framework, on that certification.

## How long we keep it

| Data | Kept for |
|---|---|
| Booking record (name, email, colleagues, notes, answers, meeting time) | up to 24 months after the meeting date, then deleted automatically; sooner if you ask |
| Calendar event in our Microsoft 365 calendar | according to our mailbox retention settings; deleted on request |
| The emails we sent you (queue copies) | 90 days after sending, then deleted automatically |
| Your booking-management link (stored as a hash) | until one day after the meeting |
| Temporary calendar holds for the slot you chose | until one day after the meeting |
| Duplicate-request protection keys | 30 days |
| Rate-limit counters keyed by IP address or email | at most 3 days |
| Free/busy data read from our own calendar | 6 hours |
| Website form submissions | in Formspree according to its retention settings; in our mailbox and CRM for as long as we have an active business relationship or an open request |
| Google Analytics data | according to the retention period configured in Google Analytics (we use the default of 14 months for user-level data) |

"Deleted automatically" means that our database records carry an expiry date and are
removed by the platform when it passes; no one has to remember to do it.

## Cookies and browser storage

The booking pages set no cookies of our own for guests, and no analytics cookies at all.
The full list for the site is below:

| Name | Set by | Where | Purpose | Lifetime |
|---|---|---|---|---|
| `_ga`, `_ga_*` | Google Analytics | marketing site, **only after you accept** | distinguishes visitors for aggregate statistics | 2 years; deleted if you withdraw consent |
| analytics choice | EventIQ | marketing site, local storage | remembers whether you accepted or declined analytics, so we do not ask on every page | 12 months |
| `__session` | EventIQ | administration only (staff) | keeps a signed-in staff member signed in | 7 days from last use, at most 30 days |
| attribution record | EventIQ | marketing site, session storage | remembers which link you arrived by so that a later form submission can carry it | until you close the tab |
| sign-in email | EventIQ | administration only, local storage | completes a one-time sign-in link | until the sign-in completes |
| reCAPTCHA cookies | Google | booking pages, only where App Check is enabled | distinguishes real browsers from scripts | per Google's policy |

Declining analytics has no effect on your ability to use the site or book a meeting. To change
your choice, use "Cookie settings" at the bottom of any page. You can also block or delete
cookies in your browser, and opt out of Google Analytics everywhere with Google's browser
add-on at tools.google.com/dlpage/gaoptout.

## Security

Everything is served over HTTPS with HTTP Strict Transport Security and a Content Security
Policy. Data at rest is encrypted by our cloud providers; Microsoft 365 tokens for our staff
are additionally encrypted by us with AES-256-GCM before storage, with the key held in a
secrets manager rather than in the database. Access to production is limited to named
engineers. Booking management links are stored only as hashes, so a copy of our database
would not let anyone cancel or move your meeting.

No method of transmission or storage is perfectly secure. If we learn of a breach affecting
your data, we will tell you and any authority we are required to notify without undue delay.

## Your rights

Depending on where you live, you may have the right to:

- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it, including objecting to direct marketing at any time;
- receive the data you gave us in a portable format;
- withdraw consent where we relied on it, without affecting what was done before;
- complain to a data-protection authority — in the EEA, the authority of the country where
  you live or work; in the UK, the Information Commissioner's Office.

If you are a California resident, you have the rights to know, to delete, to correct, and
not to be discriminated against for exercising them. We do not sell personal information and
do not share it for cross-context behavioural advertising, so there is nothing to opt out of.

To exercise any of these rights, email **info@eventiq.io** from the address you
used with us, or tell us which address that was. We may ask for information needed to confirm
it is you. We respond within the time the applicable law allows, normally within one month.

The fastest way to cancel a meeting is the link in your confirmation email; that removes the
calendar event and stops any further emails about it immediately.

## Children

Our website and booking pages are for business use and are not directed to anyone under
sixteen. We do not knowingly collect data from children; if you believe we have, write to us
and we will delete it.

## Links to other sites

Meeting invitations link to Microsoft Teams, and the site links to LinkedIn and to
third-party products we compare against. Those sites have their own privacy policies, which
we do not control.

## Changes to this policy

When we change this policy we will post the new version here with a new effective date. For
changes that materially affect how we use data you already gave us, we will tell you by
email where we have an address for you.

## Contact

EventIQ, LLC — 8 The Green, Suite B, Dover, Kent County, DE 19901, United States
Email: **info@eventiq.io**

---

HTML version: https://eventiq.io/privacy
