This Privacy Policy explains how EventQuad collects, uses, stores, and protects personal data in connection with our guest registration, event management, and related services. By using our services — whether as an event organiser or an invited guest — you agree to the practices described in this policy.
Who We Are
EventQuad is a digital guest management and event technology company operating in Nigeria. We provide end-to-end services including digital invitation distribution, RSVP management, guest verification, QR-code-based check-in, event branding, interactive polling, and integrated event gaming.
For the purposes of this policy, EventQuad acts as a data processor on behalf of event organisers (our clients) and a data controller for data collected directly through our platform, website, and contact channels.
Registered address: Nigeria
Website: www.eventquad.com
Contact: +234 802 413 0982
Data We Collect
We collect different categories of personal data depending on whether you are an event organiser, an invited guest, or a website visitor.
From Event Guests
| Data Type | Examples | Source |
|---|---|---|
| Identity data | Full name, profile photo | Guest registration form |
| Contact data | Phone number, email address | Guest registration form |
| Event data | Table/seat number, RSVP status, attendance status | Organiser assignment / check-in |
| Verification data | Unique guest ID, QR code | Generated by EventQuad |
| Custom fields | Dietary requirements, plus-one details, any fields defined by the organiser | Guest registration form |
| Device data | IP address, browser type (for event website access) | Automatically collected |
From Event Organisers
- Business name, contact person name, phone number, and email address
- Event details including name, date, venue, and guest count
- Branding assets — logos, colour schemes, invitation designs
- Billing and payment information (processed securely via our payment partners)
From Website Visitors
- Name, email, phone, and message submitted via our contact form
- IP address and browser/device information via cookies and server logs
How We Use Your Data
For Guest Data
- Generating personalised digital invitation cards on behalf of the event organiser
- Sending invitations, RSVP confirmations, reminders, and event updates via WhatsApp, Email, and SMS
- Creating and issuing a unique QR code and guest ID for event entry
- Facilitating check-in and verifying identity at the event venue
- Recording attendance status and admittance decisions in the admin dashboard
- Assigning and confirming table and seat numbers
- Populating the event's guest seating plan
For Organiser Data
- Delivering our event management services and fulfilling our contract with you
- Communicating about your event setup, progress, and delivery
- Processing payments for our services
- Sending service-related notices and updates
- Improving our platform and services
For Website Enquiries
- Responding to your enquiry and providing information about our services
- Following up on potential service agreements
Legal Basis for Processing
We rely on the following legal bases to process personal data under applicable Nigerian data protection law (Nigeria Data Protection Act 2023) and international best practice:
- Contractual necessity — processing guest data is necessary to perform the event management services contracted by the organiser.
- Legitimate interests — we may process contact and usage data to improve our platform, prevent fraud, and ensure service security, where this does not override your rights.
- Consent — where we send marketing communications or collect optional data, we rely on your explicit consent, which you may withdraw at any time.
- Legal obligation — where we are required to retain or disclose data to comply with applicable law.
Data Sharing
We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:
With Event Organisers
Guest data collected during registration is shared with the event organiser who commissioned the event. Organisers access this data through the EventQuad admin dashboard. They are contractually bound to use it only for the purposes of running their event.
With Service Providers
- Messaging providers — WhatsApp Business API, email delivery, and SMS gateway providers receive contact data to transmit invitations and notifications.
- Hosting and infrastructure — our platform is hosted on secure servers; hosting providers may have incidental access to stored data.
- Payment processors — organiser billing data is handled by our payment partners under their own privacy policies.
All third-party providers are vetted, bound by data processing agreements, and prohibited from using your data for their own purposes.
Legal Disclosures
We may disclose data if required to do so by law, court order, or government authority, or where necessary to protect the rights, property, or safety of EventQuad, our clients, or others.
Guest Data & Event Organisers
When an event organiser uses EventQuad's platform, the guests of that event are the organiser's data subjects. EventQuad processes their personal data on the organiser's instruction, acting as a data processor.
If you are a guest and have questions about why your data was collected for a specific event, or wish to exercise your rights in relation to that event, you should contact the event organiser directly. EventQuad will assist organisers in responding to such requests within applicable legal timeframes.
Organisers are responsible for ensuring they have a lawful basis to share their guests' contact details with EventQuad and for informing guests that their data will be processed for event management purposes.
QR Codes & Check-In Data
Each confirmed guest is issued a unique QR code linked to their guest profile. This QR code contains:
- A unique encrypted guest identifier
- The associated event identifier
- No raw personal data is embedded in the QR code itself
When scanned at the event, the system retrieves the guest's name, photo, seat number, and admittance status from our secure database and displays it to check-in staff. Each scan is logged with a timestamp and the device used.
Check-in data — including the time of arrival and admittance decision — is retained as part of the event record and is accessible to the event organiser via their admin dashboard.
Messaging & Communications
EventQuad sends event-related communications to guests on behalf of event organisers through the following channels:
- WhatsApp — invitation cards, RSVP confirmations, QR passes, reminders
- Email — formal invitations, confirmations, event updates
- SMS — reminders and entry pass delivery for guests without smartphones
All communications are transactional and event-specific. We do not use guest contact details for marketing our own services without separate, explicit consent.
Guests may opt out of non-essential communications by replying STOP to SMS messages, unsubscribing from emails, or contacting the event organiser. Note that opting out of communications does not revoke your event registration — your entry pass remains valid.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Guest registration data | 90 days after the event date, then securely deleted unless the organiser requests archiving |
| Check-in and attendance logs | 90 days after the event |
| Organiser account data | Duration of the contract + 2 years for legal/accounting purposes |
| Contact form enquiries | 12 months from receipt, or until the enquiry is resolved |
| Payment records | 7 years, as required by Nigerian financial regulations |
| Server and access logs | 30 days |
Upon expiry of the retention period, data is securely deleted or anonymised so it can no longer be linked to an individual.
Your Rights
Under the Nigeria Data Protection Act 2023 (NDPA) and applicable data protection law, you have the following rights in respect of your personal data:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may ask us to correct inaccurate or incomplete data.
- Right to erasure — you may request deletion of your data, subject to our legal obligations and the legitimate interests of the event organiser.
- Right to restrict processing — you may ask us to pause processing your data in certain circumstances.
- Right to data portability — you may request your data in a machine-readable format.
- Right to object — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is consent-based, you may withdraw at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encryption of data in transit (HTTPS/TLS) and at rest
- QR codes containing encrypted identifiers rather than raw personal data
- Role-based access controls limiting staff access to data on a need-to-know basis
- Secure admin dashboards protected by authentication
- Regular security assessments and updates
- Data processing agreements with all third-party service providers
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, in accordance with our legal obligations.
Cookies
Our website uses cookies and similar tracking technologies. We use the following categories:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Required for the site and event portal to function correctly (sessions, security tokens) | Session |
| Analytics | Understanding how visitors use the site so we can improve it. No personally identifiable data is shared externally. | Up to 12 months |
| Preference | Remembering your language or display preferences | Up to 12 months |
You may control cookies through your browser settings. Disabling essential cookies may affect your ability to use certain features of our platform or event portals.
Children's Privacy
Our services are not directed at children under the age of 13. We do not knowingly collect personal data from children under 13 without verifiable parental or guardian consent.
Where an event organiser expects guests under 13 to attend — such as children's birthday parties or family events — the organiser is responsible for obtaining appropriate consent from the child's parent or guardian before submitting their data to EventQuad's platform.
If you believe we have inadvertently collected data from a child under 13 without proper consent, please contact us immediately at [email protected] and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or best practices. When we make significant changes, we will:
- Update the "Last updated" date at the top of this page
- Notify registered organisers via email at least 14 days before the changes take effect
- Where required by law, seek fresh consent from affected individuals
We encourage you to review this policy periodically. Your continued use of our services after the effective date of any changes constitutes acceptance of the updated policy.
Previous versions of this policy are available on request by emailing [email protected].
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please reach out to us through any of the following:
We aim to respond to all privacy-related enquiries within 5 business days and to fulfil data subject requests within 30 days of receipt.