1. Scope and roles
This page explains the data-protection framework used when Domplatta supports registration, check-in, badge printing, access, sessions, lead retrieval, reporting and related event operations.
For most customer events, the event organizer or customer decides why attendee data is processed and how the event is operated. That organization will normally act as the controller. Domplatta or the contracted service provider will normally act as a processor when it handles event data on the controller’s documented instructions.
Domplatta acts separately as a controller for its own website enquiries, commercial discussions, account administration, security records and legal obligations. The exact allocation of responsibilities is confirmed in the applicable proposal, service agreement and data-processing agreement.
2. Event data that may be processed
- Identity and contact
- Name, email address, telephone number, organization and professional role.
- Registration
- Ticket or attendee type, registration answers, unique identifiers, QR codes, status and eligibility information.
- Event operations
- Check-in and check-out timestamps, badge data, print and reprint records, desk or kiosk activity, access decisions and exception handling.
- Agenda and engagement
- Session selections, attendance, waitlist status, lead-retrieval interactions and organization relationships.
- Technical and audit
- User account, role, permission, device, integration, webhook, import, export and activity-log information.
Customers should configure forms and imports to collect only data that is necessary for the event. Special-category data should not be collected unless the controller has identified an appropriate legal basis and additional safeguards.
3. Purposes and lawful bases
The controller determines the lawful basis for each event workflow. Depending on the circumstances, processing may be necessary to perform a contract or take steps requested by an attendee, comply with a legal obligation, protect vital interests, carry out a task in the public interest, or pursue legitimate interests that are not overridden by individual rights.
Consent should be used only where it is appropriate, freely given, specific, informed and capable of being withdrawn. Consent for optional marketing, profiling or third-party lead sharing must be separated from access to services where those activities are not necessary for participation.
4. Processor commitments
Where Domplatta processes data for a customer, the applicable data-processing agreement should cover documented instructions, confidentiality, security, subprocessor controls, assistance with individual rights, incident cooperation, deletion or return of data, and information needed to demonstrate compliance.
Domplatta personnel and authorized operators should receive only the permissions required for their role. Customer administrators remain responsible for configuring access, reviewing users and removing access that is no longer required.
5. Retention, return and deletion
Event data is retained for the period agreed with the controller. The retention period should reflect the event lifecycle, contractual support, reconciliation, reporting, dispute handling and legal-record requirements.
At the end of the agreed period, data should be exported, returned, deleted or anonymized according to the controller’s instructions. Backup copies may remain for a limited recovery period and should be isolated from routine use until overwritten under the backup schedule.
6. International transfers and subprocessors
Hosting, email delivery, CRM, automation or other services may involve subprocessors. The production customer should receive the applicable subprocessor information before deployment.
Where personal data is transferred outside the European Economic Area, the parties should use an applicable transfer mechanism and assess supplementary measures where required. This may include an adequacy decision, approved standard contractual clauses or another mechanism permitted by data-protection law.
7. Individual rights
Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to certain decisions based solely on automated processing.
Requests concerning a customer event should normally be directed to the event organizer identified on the registration form or event notice. Domplatta will support the controller with technically reasonable searches, exports, corrections, restrictions or deletions when required under the applicable agreement.
Individuals may also lodge a complaint with the competent supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
8. Security and incident cooperation
Appropriate technical and organizational measures should be selected according to the risks of each deployment. These may include protected connections, role-based access, scoped permissions, validation, signed integrations, audit logging, backups and recovery procedures.
A suspected personal-data incident should be reported promptly through the agreed support or security channel. Where Domplatta acts as processor, it will provide available information to the controller so the controller can assess notification and communication duties.