Document: eventOS Privacy Notice Version: 1.1 Last updated: 20 July 2026 Effective date: 20 July 2026
This Privacy Notice explains how DZND Limited (RC 9483106), registered office 2 Ayika Close, Federal Housing Estate, 3-3, Onitsha, Anambra State, Nigeria ("DZND", "eventOS", "we", "us", "our") collects, uses, shares, transfers and protects personal data when you use the eventOS platform. It is issued in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the NDPC General Application and Implementation Directive (GAID).
It applies to organisers, attendees, door-staff/organiser team members, and visitors to eventOS surfaces.
1. Who is responsible for your data (controller / processor)
1.1 DZND as controller. DZND is the data controller for personal data it processes for its own platform purposes — operating and securing the Platform, organiser onboarding and KYC, fraud and sanctions prevention, billing its platform fee, aggregate product analytics, and legal compliance.
1.2 Organiser as controller; DZND as processor. Where an organiser uses eventOS to process their attendees' data, the organiser is the controller of that attendee data and DZND acts as a processor on the organiser's behalf, under the Data Processing Addendum. For those purposes the organiser's own privacy information also applies. DZND remains an independent controller for the limited purposes in clause 1.1.
1.3 Data-protection contact. Questions or requests: privacy@dznd.studio. A Data Protection Officer (DPO) is appointed and named here where we process the personal data of more than 10,000 data subjects in a year, per NDPA §32; this is re-evaluated as we scale.
2. What personal data we collect
From organisers
- Identity and contact: name, business name, email, phone.
- Identity verification (KYC): BVN and/or NIN and verification results, processed via our verification partner Prembly; sanctions-screening results.
- Payout details: bank account number, bank code, resolved account name (via Paystack), Paystack subaccount identifiers.
- Account and security: hashed password, two-factor authentication secrets (encrypted), session, device and audit metadata.
From attendees
- Contact: name, email, and phone (where provided).
- Transaction: tickets purchased, event(s), purchase history, and Paystack payment references. We do not store card numbers, CVV, or full bank details — card data is handled by Paystack.
- Location (coarse): the city of the event.
- Ticket/admission: signed QR token material and hashes, scan/attendance records, ticket transfers.
From attendees who use the in-product AI assistant (where enabled)
- The messages you type into the assistant and the assistant's replies, kept as a conversation transcript linked to your account.
- The account context the assistant is permitted to read on your behalf to answer you — your own tickets, their status, refund status, and public event details. The assistant is read-only and is scoped to your own account: it cannot read another person's tickets, and it cannot change, cancel or transfer anything.
From attendees who use community groups (where enabled)
- Group membership, the display name shown to other members of that group, the events you share into a group, any note attached to a share, and your roll-call response (going / thinking / can't).
- Accounts you follow, mutual connections, and accounts you have blocked.
- We do not show your email address or phone number to other attendees in any group surface, and there is no public attendee directory or search.
From door-staff / organiser team members (mobile app)
- Device identifiers, push-notification tokens, encrypted offline-admission manifest data (stored encrypted on the device), and session tokens.
Automatically
- Technical/log data: IP address, request and device/browser metadata, and security and performance metrics needed to operate and protect the service.
We collect only what we need for the purposes below.
3. Why we use it, and our lawful bases (NDPA §25)
| Purpose | Lawful basis |
|---|---|
| Create and operate organiser accounts; provide the Platform | Performance of a contract |
| Verify organiser identity (KYC) and screen for sanctions/fraud | Legal obligation; legitimate interest |
| Process ticket purchases and issue/deliver tickets | Performance of a contract |
| Facilitate settlement to organisers via Paystack | Performance of a contract |
| Admit attendees (QR scan, attendance records) | Performance of a contract; legitimate interest |
| Organiser audience/post-event messaging | Legitimate interest with opt-out; consent where required for direct electronic marketing |
| Platform security, fraud prevention, abuse detection, audit logging | Legitimate interest; legal obligation |
| Product analytics in aggregate/de-identified form | Legitimate interest |
| Answer your support questions through the in-product AI assistant, including sending your message and the necessary account context to our AI provider | Performance of a contract; legitimate interest |
| Keep AI assistant transcripts for continuity of the conversation, support follow-up, safety and abuse review | Legitimate interest |
| AI tools for organisers (drafting an event from a brief, generating marketing copy, generating a post-event report from the organiser's own event statistics) | Performance of a contract (organiser); legitimate interest |
| Recommending events to you based on your ticket history, the organisers and attendees you follow, your groups, city and what is trending | Legitimate interest |
| Operate community groups: membership, invite links, sharing events into a group, roll-call responses, blocks and safety enforcement | Performance of a contract; legitimate interest |
| Comply with law; respond to lawful requests; establish/defend legal claims | Legal obligation; legitimate interest |
Where we rely on legitimate interest, we have weighed it against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting prior processing.
3.1 AI features and automated processing
Some eventOS features use artificial intelligence supplied by third-party AI providers. These features are off by default and are only active where we have switched them on for the platform.
- What is sent. When you use the AI assistant, we send your message, the recent messages in that conversation, and the minimum account context needed to answer (for example your own ticket references and their status) to our AI provider. For organiser AI tools, we send the organiser's own event details and aggregate event statistics.
- What is not sent. We do not send passwords, two-factor secrets, card or bank details, BVN/NIN or KYC results, or QR signing material to any AI provider.
- No training on your data. We engage AI providers on terms that do not permit them to use eventOS data to train their models.
- Please don't paste sensitive data. The assistant is a support tool. Do not enter card numbers, bank details, passwords, BVN/NIN or health information into it.
- AI output is not advice and can be wrong. Assistant answers and organiser AI drafts are informational, may contain errors, and do not vary your rights, your ticket, or any contract. Where an AI answer conflicts with your ticket, the event listing or these documents, those prevail.
Recommendations and profiling. Our event recommendations are produced by an automated scoring process (a form of profiling) using the signals in the table above. They only decide which events are suggested to you — they are not automated decisions that produce legal or similarly significant effects about you (NDPA §37). They do not affect pricing, ticket validity, admission, or access to your account. Recommendations never identify other individuals to you; where a social signal is used you may see an aggregate count only, and only from people whose visibility settings permit it.
4. Who we share data with (recipients and sub-processors)
We share personal data with the service providers necessary to run eventOS. Each is engaged as a sub-processor under a data-processing agreement, may process only for the purposes we specify, and is listed with role and location in the Sub-processor Register. In summary:
- Paystack (Nigeria) — payment processing, payout settlement, bank-account name resolution, and sanctions checks on subaccount creation.
- Prembly (Nigeria) — organiser KYC (BVN/NIN verification).
- Supabase (EU) — application database, authentication, and storage.
- Cloudflare (global) — image/asset hosting and object storage (event posters, ticket art) via Cloudflare Images and R2.
- Upstash (US/EU) — Redis cache, rate-limit counters, and QStash job queue (no directly-identifying PII cached; keys and counters only).
- Resend (US/EU) — transactional and broadcast email delivery.
- Termii (Nigeria) — SMS delivery.
- Railway (US) — hosting of the eventOS API and PDF-render worker.
- Vercel (global) — hosting of the eventOS web application.
- Expo (US) — push-notification delivery to the door-staff mobile app.
- Better Stack (EU/US) — logging and metrics/observability (PII-minimised).
- AI providers (US) — where AI features are enabled, the model provider that generates assistant replies and organiser AI drafts. Depending on platform configuration this is one of Anthropic, OpenAI, Google, or the Vercel AI Gateway routing to one of them. They receive only the content described in clause 3.1, process it solely to return a response, are contractually barred from training on it, and retain it only transiently for abuse-monitoring per their terms.
Where you use community groups, other members of that group see the display name on your membership, the events you share into the group, any note you attach, and your roll-call response. They do not see your email address, phone number, or which tickets you hold unless your own visibility setting for that group allows it. Blocking an attendee makes the two of you mutually invisible across member lists, roll-calls and follows.
We also share data with organisers in respect of their own attendees, with professional advisers under confidentiality, with a successor entity in a merger or acquisition, and with authorities, regulators or courts where legally required. We do not sell personal data.
5. International transfers (NDPA §41–43)
Some sub-processors process data outside Nigeria (for example Supabase, Upstash, Resend, Cloudflare, Vercel, Railway, Expo and Better Stack operate in the EU and/or the United States and via global CDNs; where AI features are enabled, our AI provider processes assistant and organiser-AI content in the United States). Where we transfer personal data outside Nigeria, we rely on an adequacy decision where available, or otherwise on appropriate safeguards — such as standard contractual clauses or the provider's binding data-processing and transfer commitments — consistent with NDPA §41–43. Details of each provider's location and transfer basis are in the Sub-processor Register.
6. How long we keep it (retention)
We keep personal data only as long as necessary for the purposes above and to meet legal, tax, accounting and dispute-resolution obligations. Indicative periods:
| Data | Indicative retention |
|---|---|
| Financial/transaction records (payments, fees, settlements) | Period required by Nigerian tax and companies law (indicatively 6 years) |
| KYC and sanctions-screening records | For the account term and as required by AML/CFT norms after closure |
| Organiser account data | While the account is active, then per our retention schedule |
| Attendee records tied to an organiser | While the organiser account is active and the retention window applies |
| Ticket/admission and scan records | Through the event and a reasonable post-event window for disputes |
| AI assistant conversations (your messages and replies) | While your account is active; deleted with your account, or sooner on request (clause 7) |
| Community group membership, shared events and roll-call responses | While you remain a member of the group; removed when you leave, are removed, or delete your account |
| Blocks between attendees | Until you remove the block, or your account is deleted |
| Security/audit logs | A rolling period appropriate to security and legal needs |
On a valid deletion request, we anonymise personal identifiers while preserving records we are legally required to keep (clause 7).
7. Your rights (NDPA §34–37)
You have the right to: access your data; rectify inaccurate data; erasure/anonymisation; restrict or object to certain processing; data portability; and to withdraw consent. eventOS provides self-service tools:
- Data export — organisers and account holders can export their data from account/privacy settings (a portable structured bundle).
- Deletion / anonymisation — available from account settings; personal identifiers are anonymised while legally-required financial records are retained in de-identified form.
To exercise rights not covered by self-service, contact privacy@dznd.studio. We respond within the timeframe required by the NDPA and may need to verify your identity. Where an organiser is the controller of the data (clause 1.2), we will direct your request to, or assist, that organiser.
You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
8. Security
We protect personal data with technical and organisational measures including: row-level security and service-role separation on the database; least-privilege API-key scopes and ownership checks on every data path; encryption in transit (TLS); encryption of sensitive material at rest (including AES-256-GCM encryption of offline mobile admission manifests, and encrypted two-factor secrets); signed admission tokens and QR codes (HMAC/Ed25519); hashed credentials; optional/ required two-factor authentication; passkey step-up and maker-checker approval for sensitive internal-admin actions; sanctions screening at onboarding; rate limiting; secret scanning in the development pipeline; PII-minimised structured logging; and immutable audit logging. No system is perfectly secure, but we work to protect your data appropriately and review our measures over time.
9. Data-breach notification
Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware, and notify affected data subjects without undue delay where the breach is likely to cause significant harm, in line with the NDPA. Where DZND is a processor for an organiser, we notify that organiser without undue delay so they can meet their own duties.
10. Cookies and similar technologies
eventOS uses strictly necessary cookies/storage to keep you signed in and to operate and secure the service, and limited functional/analytics storage. A cookie notice is presented in accordance with the GAID. See the Cookie Policy for details and choices.
11. Children
eventOS is not directed at children under 18, and we do not knowingly collect their data for account creation. Organisers are responsible for any age restrictions and any lawful processing of minors' data at their events.
12. Changes to this notice
We may update this notice. Material changes are posted here with a new "last updated" date and, where appropriate, notified to you directly.
13. Contact
DZND Limited (RC 9483106) — operator of eventOS Data-protection contact: privacy@dznd.studio Registered office: 2 Ayika Close, Federal Housing Estate, 3-3, Onitsha, Anambra State, Nigeria Supervisory authority: Nigeria Data Protection Commission (NDPC).
© 2026 DZND Limited. eventOS is a product of DZND Limited (RC 9483106).
Supplemental clarifications — 14 August 2026
The following clarifications close product-specific gaps in this Privacy Notice without replacing the notice above.
Social discovery and “People you may know”
Where attendee social discovery is enabled, eventOS may generate People you may know suggestions using limited relationship and event-context signals such as mutual connections, shared event groups, and attendance on upcoming events that an attendee has chosen to make discoverable. The purpose is to help attendees find relevant connections inside eventOS. The lawful basis is our legitimate interest in providing an expected social-discovery feature, balanced against attendee privacy and safety controls.
A People you may know suggestion can identify another eventOS attendee to you. This is different from the event-recommendation profiling described above. We do not create a public attendee directory or make private profiles searchable. Existing connections, blocked relationships, deactivated accounts and profiles that are not eligible for discovery are excluded. Where attendance contributes to a suggestion, it is used only when the relevant attendee's visibility settings permit that attendance to be discoverable. Blocking and applicable privacy controls remove the affected relationship from future recommendation eligibility.
People you may know suggestions do not determine ticket pricing, ticket validity, admission, account access, eligibility for a refund, or any other legal or similarly significant outcome. You may ignore a suggestion, change applicable privacy settings, block another attendee, or exercise the rights described in clause 7.
Offline scanning and device sync
When authorised door staff use offline-capable admission, the device may temporarily hold an encrypted event manifest and queue scan results while connectivity is unavailable. When the device reconnects, queued results are transmitted to eventOS for reconciliation with the authoritative server record. This processing is limited to event admission, fraud and duplicate-scan prevention, operational reconciliation, security and dispute handling. Organiser credentials should not be shared with door staff; scoped staff access and scan sessions are used for this purpose.
Headless API and connected systems
Where an organiser uses eventOS through API keys, webhooks, an embedded checkout or another approved headless integration, personal data may pass between eventOS and the organiser's own website, app or connected system as necessary to provide that integration. The organiser remains responsible for its own notices, lawful bases, security and use of personal data in systems it controls. DZND processes personal data according to the controller/processor roles described in clause 1 and the Data Processing Addendum. API credentials and webhook signing secrets are security credentials and must not be exposed in public client-side code.
Payout-split recipients
Where an organiser configures payout splits, we may process recipient identity, contact, bank-resolution and allocation information needed to verify the recipient, configure settlement routing, prevent fraud, maintain financial records and support reconciliation. These details are not made public merely because a recipient participates in a split.