Procurement, Security & Data Protection

One page for your purchasing and IT-security review: where data lives, who owns it, how buying works, and what happens after the event.

EU hosting
Frankfurt, Germany (Google Cloud, region europe-west3)

GDPR-aligned
Data minimization,
no attendee data selling

PO-friendly
Formal quotes,
VAT invoices, bank transfer

Fixed EUR quotes
Set before launch —
no per-attendee fees

Data protection & privacy

  • Infrastructure is hosted in Frankfurt, Germany (Google Cloud, region europe-west3).
  • We adhere to strict data minimization: attendees can use the full agenda without creating an account — sign-in is optional and only needed for interactive features.
  • We do not sell attendee data and we do not run third-party ad tracking inside the app.
  • A Data Processing Agreement (DPA) and answers to your security questionnaire are available on request.
  • See also the Privacy Policy.

Data ownership & lifecycle

  • You own your conference data. We use it to publish the agenda and operate the app — nothing else.
  • During a free evaluation: if you don't proceed, the event is removed before the attendee access window — no residue, no follow-up obligations.
  • After the event: your programme can stay archived and browsable for your community, or be fully removed — your choice, on request.
  • Programme and engagement data exports are available on request so nothing is locked in.
  • Leaving is simple by design: your programme's source of truth never moves — it stays in your Indico, EasyChair, ConfTool, or spreadsheet throughout. If you switch tools next year, there is nothing to migrate back.

Purchasing process

  • We are accustomed to working with university finance departments and corporate procurement teams.
  • Formal quotes and VAT invoices to facilitate Purchase Orders and bank transfers.
  • Quotes are in EUR, based on programme complexity — fixed before launch, with no per-attendee or per-ticket fees.
  • Academic and non-profit discounts available on request.
  • See the Refund Policy and Pricing.

Security & access control

  • Institutional sign-in via any OIDC-compliant identity provider: available on request — ORCID, LinkedIn, and Google already run on the same provider registry.
  • Organizer console uses role-based access: per-event admin, moderator, and speaker roles with granular capabilities.
  • Attendee accounts are anonymous by default; optional sign-in via ORCID, LinkedIn, Google, or e-mail code.
  • Stricter governance requirements (audit, exports, SLAs) are covered by the Enterprise plan.
Timeline note for tenders and POs: book 4+ weeks before your event for guaranteed setup and review timelines. The evaluation itself is free with your live data — the go-live decision is due one week before your event.
Request a DPA or formal quote Read the full FAQ

We usually reply within 24 hours: office@hepcon.app