Legal
Privacy policy
What we collect, why we collect it, where it lives, and what you can ask us to do about it.
Last updated: 6 September 2026
Who we are
Procurevent provides event procurement software for European buyers and their suppliers. For personal data collected through this website and through your own use of our application, we act as the controller.
Procurevent is operated by Event Clinic Kft., registered at 1054 Budapest, Aulich u. 3., Hungary, EU VAT number HU8221506. The same company operates event.clinic.
We have not appointed a Data Protection Officer. We are not required to, and we would rather say so plainly than leave the question open. Privacy questions go toprivacy@procurevent.com and reach the people who can actually answer them.
Controller and processor — an important distinction
Procurevent handles personal data in two quite different capacities, and your rights differ depending on which applies:
| Situation | Our role | What that means |
|---|---|---|
| You contact us, register as a supplier, or hold a Procurevent user account | Controller | We decide why and how your data is used, and you exercise your rights directly with us. |
| A buyer organisation uses Procurevent and its data includes personal data (supplier contacts, colleagues, attendees) | Processor | The buyer decides why and how that data is used. We act on their instructions, under a data processing agreement. Requests about that data go to them. |
The precise split is confirmed contractually per service model rather than assumed. A data processing agreement is available on request — ask atprivacy@procurevent.com. Event Clinic Kft. also publishes one for its event.clinic service, and the Procurevent agreement follows the same structure.
What we collect through this website
This website sets no cookies and runs no analytics — see the cookie policy. The only personal data it collects is what you type into a form and send us.
Enquiry and demo requests
- Your name and work email address
- Your organisation and country
- Which description fits you (buyer, supplier, agency, venue)
- The procurement category you are interested in, if you tell us
- Anything you write in the message field
Legal basis: your consent, given by submitting the form. We use these details only to respond to your enquiry. We do not add enquiries to a marketing list and we do not sell or share them.
Supplier registration
- Legal company name, country and service region
- Main contact name and email address
- The categories your company works in
- Website or portfolio link
Legal basis: performance of a contract, or steps taken at your request before entering one. We ask only what makes your company eligible for relevant buyer invitations. Company registration details, insurance, credentials and references are requested later, inside the application, when an opportunity actually requires them. We never ask for payment details at registration.
What the application processes
Inside Procurevent, the data belongs to the organisation using it. That typically includes user accounts and roles, supplier company profiles and contacts, compliance documents, request and quote records, clarification messages, approvals, awards and the audit log of who did what and when.
Two things are worth stating plainly because they are enforced technically rather than by policy:
- Suppliers cannot see each other. No supplier can access a competitor's submission, pricing, or the invitation list for a request. This is enforced by database policy, not by application logic that could have a gap.
- Organisations cannot see each other. Row-level security is forced on every tenant table, and each request runs with its tenant identity scoped to a single database transaction.
- A supplier that publishes its profile shows buyers its registered details, not its contact card. A supplier chooses when to become discoverable, by completing its profile. From that point a buyer organisation can see that company record and the registered company details a supplier gives us: VAT and registration numbers, and the registered address. A supplier that has not published, or that withdraws, is not visible to buyers it has no relationship with.
- The business contact email address and telephone number sit behind an invitation. A buyer organisation can read them only where it has actually invited that supplier to quote. This is enforced by database policy, in the same way as the two separations above, rather than by application logic that could have a gap. We are stating it because it is a deliberate choice: being discoverable is how a supplier gets invited, and it should not by itself hand a contact list to every buyer on the platform.
- Procurevent’s own staff can see the records above. The separations on this page are between customers — they are what stops one organisation reading another’s data, and they are not a statement that the data is hidden from us. A small number of our staff can read organisation records, including contact details, in order to operate the service: to investigate a fault you report, to verify a supplier that asks to be verified, and to answer questions about your own account. We are saying so plainly rather than leaving it implied by the sentences above.
Where your data is hosted
Our database runs on PostgreSQL in Frankfurt, Germany, inside the EU. That was chosen when the project was provisioned rather than migrated to later.
Who else processes your data
We use a small number of infrastructure providers. Each acts as a processor or subprocessor under contract, and we maintain a subprocessor register.
| Provider | Purpose | Region | Status |
|---|---|---|---|
| Neon | Managed PostgreSQL database | EU — Frankfurt | In use |
| Cloudflare | CDN, web application firewall, edge compute | Global edge | In use |
| Cloudflare R2 | Private file storage | EU jurisdiction | In use |
| Clerk | Authentication and identity | United States | In use |
| Brevo | Transactional email | EU — France | In use |
| Stripe | Subscription payments | Ireland and United States | In use |
The status column is not decoration. Every provider listed above is connected and processing today. Naming one that processes nothing would overstate what happens to your data as surely as omitting one would understate it — and this table said the opposite of the truth until 5 September 2026, listing three live providers as planned and omitting our payment processor entirely. It is corrected here rather than quietly.
Where a provider processes data outside the EEA, we rely on the EU–US Data Privacy Framework and Standard Contractual Clauses. Cloudflare and Clerk are covered by both; Stripe processes EU payments through Stripe Payments Europe in Ireland, with Standard Contractual Clauses for any onward transfer to the United States. Neon stores data in the EU — Frankfurt. Our Cloudflare R2 bucket is created in the EU jurisdiction, so uploaded files are stored in the EEA. Brevo is a French company and processes in the EU.
How long we keep it
We keep personal data only as long as the purpose it was collected for requires. Rather than publish durations we cannot yet stand behind, these are the principles the retention schedule is built on:
- Enquiries are kept only as long as needed to deal with them and any follow-up.
- Procurement records are kept for the term of the customer's agreement, because an award must remain reconstructable — that is the point of an audit trail.
- Audit records are immutable by design. They cannot be edited or deleted, which is a deliberate control and a genuine constraint on erasure requests touching them.
- Deleting a tenant removes its data, subject to legal retention exceptions.
Your rights
Under the GDPR you can ask us to:
- Confirm what personal data we hold about you, and give you a copy
- Correct anything inaccurate
- Delete your data, where no legal or contractual obligation requires us to keep it
- Export your data in a portable format
- Restrict or object to a particular use
- Withdraw consent, where consent was the basis for the processing
Email privacy@procurevent.com. If we act as processor rather than controller for the data in question, we will tell you promptly and point you to the organisation that controls it.
You also have the right to complain to a supervisory authority. In Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
Data minimisation, in practice
We try to earn this rather than claim it. This website sets no cookies and runs no analytics. Our forms ask for the fewest fields that make the next step possible — no phone number, no job title, no company size, no budget band. Supplier onboarding is staged so documents are requested only when an opportunity needs them. The public directory we read venue and company data from carries no personal contact data at all.
Changes to this policy
We will update the date at the top when this changes. For any change that materially affects how we use personal data, we will contact account holders directly rather than relying on you to notice an edit.