Legal
Privacy policy
What we collect, why we collect it, where it lives, and what you can ask us to do about it.
Draft, pending legal review. This document describes how Procurevent is being built and how we intend to operate. It has not yet been reviewed by Hungarian or EU counsel, and items marked [to be confirmed] need company details or a legal decision before launch. If you need a contractual position now — a data processing agreement, for instance — please ask us directly rather than relying on this page.
Last updated: 29 July 2026
Who we are
Procurevent provides event procurement software for European buyers and their suppliers. For personal data collected through this website and through your own use of our application, we act as the controller.
Registered company name, company registration number, registered address and any data protection officer appointment are [to be confirmed] before launch. Until then, reach us at privacy@procurevent.com.
Controller and processor — an important distinction
Procurevent handles personal data in two quite different capacities, and your rights differ depending on which applies:
| Situation | Our role | What that means |
|---|---|---|
| You contact us, register as a supplier, or hold a Procurevent user account | Controller | We decide why and how your data is used, and you exercise your rights directly with us. |
| A buyer organisation uses Procurevent and its data includes personal data (supplier contacts, colleagues, attendees) | Processor | The buyer decides why and how that data is used. We act on their instructions, under a data processing agreement. Requests about that data go to them. |
The precise split is confirmed contractually per service model rather than assumed. Our data processing agreement template is [to be confirmed — pending legal review].
What we collect through this website
This website sets no cookies and runs no analytics — see the cookie policy. The only personal data it collects is what you type into a form and send us.
Enquiry and demo requests
- Your name and work email address
- Your organisation and country
- Which description fits you (buyer, supplier, agency, venue)
- The procurement category you are interested in, if you tell us
- Anything you write in the message field
Legal basis: your consent, given by submitting the form. We use these details only to respond to your enquiry. We do not add enquiries to a marketing list and we do not sell or share them.
Supplier registration
- Legal company name, country and service region
- Main contact name and email address
- The categories your company works in
- Website or portfolio link
Legal basis: performance of a contract, or steps taken at your request before entering one. We ask only what makes your company eligible for relevant buyer invitations. Company registration details, insurance, credentials and references are requested later, inside the application, when an opportunity actually requires them. We never ask for payment details at registration.
What the application processes
Inside Procurevent, the data belongs to the organisation using it. That typically includes user accounts and roles, supplier company profiles and contacts, compliance documents, request and quote records, clarification messages, approvals, awards and the audit log of who did what and when.
Two things are worth stating plainly because they are enforced technically rather than by policy:
- Suppliers cannot see each other. No supplier can access a competitor's submission, pricing, or the invitation list for a request. This is enforced by database policy, not by application logic that could have a gap.
- Organisations cannot see each other. Row-level security is forced on every tenant table, and each request runs with its tenant identity scoped to a single database transaction.
Where your data is hosted
Our database runs on PostgreSQL in Frankfurt, Germany, inside the EU. That was chosen when the project was provisioned rather than migrated to later.
Who else processes your data
We use a small number of infrastructure providers. Each acts as a processor or subprocessor under contract, and we maintain a subprocessor register.
| Provider | Purpose | Region |
|---|---|---|
| Neon | Managed PostgreSQL database | EU — Frankfurt |
| Cloudflare | CDN, web application firewall, edge compute, private file storage | Global edge; storage configuration [to be confirmed] |
| Clerk | Authentication and identity | [to be confirmed] |
| Email delivery | Transactional notifications | Provider [to be confirmed] |
Where a provider processes data outside the EEA, the transfer mechanism and safeguards are[to be confirmed — pending legal review]. We will publish the completed register before launch.
How long we keep it
Retention periods are [to be confirmed — pending legal review]. The principles we are building to:
- Enquiries are kept only as long as needed to deal with them and any follow-up.
- Procurement records are kept for the term of the customer's agreement, because an award must remain reconstructable — that is the point of an audit trail.
- Audit records are immutable by design. They cannot be edited or deleted, which is a deliberate control and a genuine constraint on erasure requests touching them.
- Deleting a tenant removes its data, subject to legal retention exceptions.
Your rights
Under the GDPR you can ask us to:
- Confirm what personal data we hold about you, and give you a copy
- Correct anything inaccurate
- Delete your data, where no legal or contractual obligation requires us to keep it
- Export your data in a portable format
- Restrict or object to a particular use
- Withdraw consent, where consent was the basis for the processing
Email privacy@procurevent.com. If we act as processor rather than controller for the data in question, we will tell you promptly and point you to the organisation that controls it.
You also have the right to complain to a supervisory authority. In Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
Data minimisation, in practice
We try to earn this rather than claim it. This website sets no cookies and runs no analytics. Our forms ask for the fewest fields that make the next step possible — no phone number, no job title, no company size, no budget band. Supplier onboarding is staged so documents are requested only when an opportunity needs them. The public directory we read venue and company data from carries no personal contact data at all.
Changes to this policy
We will update the date at the top when this changes. For any change that materially affects how we use personal data, we will contact account holders directly rather than relying on you to notice an edit.