1. Who we are
GastFlo is an event registration and accreditation platform operated by Mavenzone ( “we”, “us”, or “our”). This Privacy Policy explains how we handle personal information when you visit gastflo.com, request access to the service, use the client portal, or register for an event hosted on GastFlo.
For privacy enquiries relating to the platform, contact us at enquiries@gastflo.com.
2. How roles are split (controller vs processor)
GastFlo is designed for business events. Data protection roles depend on whose data is involved:
- Your event organiser (the client organisation that runs the event) is the Data Controller and Data Owner for attendee and event operational data. They decide what to collect, why, and how long to keep it within the platform.
- Mavenzone acts as a Data Processor when we host, secure, and operate GastFlo on the organiser's instructions. We do not become the owner of client attendee data merely by hosting it.
- For information you submit on our marketing site (for example a request-access enquiry), Mavenzone is the Data Controller for that enquiry.
- For your own client-portal account (organiser staff), Mavenzone is typically the Data Controller for account administration and the Processor for attendee data you manage on behalf of your organisation.
If you are an event attendee and want to access, correct, or delete your registration data, contact the event organiser first. They control the event and can export, update, or anonymise records in the portal. Contact us if you need help reaching the right organiser or if your request concerns how the platform itself processes data.
3. Personal information we process
The categories below reflect what the platform is built to store and process. Actual fields collected for a given event depend on the organiser's configuration (for example whether email, phone, or company is required for a delegate type).
Event attendees (delegates)
- Identity and contact details: display name, first and last name, email address, phone number.
- Professional details: company, job title, delegate type or category.
- Registration and attendance: registration status, check-in status and timestamps, walk-in or on-site registration where enabled.
- Credentials and badges: opaque check-in codes (stored as cryptographic hashes, not plain text), badge print status, badge layout fields shown on printed credentials.
- Seating (when enabled): table or seat assignments linked to a delegate.
- Communications metadata: confirmation email dispatch status when the organiser enables email delivery.
Client organisation users (portal accounts)
- Account identifiers: email address and authentication data managed through our identity provider.
- Profile and membership: name where provided, organisation membership, role (for example owner, admin, operator).
- Actions you take in the portal, recorded in audit logs as described below.
Marketing and access requests
- If you use the request-access form on our website, you may provide your name, organisation, email, phone, and event details. The form opens your email client with a pre-filled message to us; we receive whatever you choose to send.
Technical, security, and operational data
- Network and device data: IP address and request metadata used for rate limiting, abuse prevention, and security monitoring.
- Structured application logs and optional error reports (when error reporting is configured).
- Audit events: time-stamped records of significant actions in the platform (for example registration changes, credential issuance, check-in, exports, retention operations) to support accountability and troubleshooting.
- Files uploaded by organisers (for example event branding or badge assets) stored in our cloud storage.
Local print agent
Badge printing uses a local print agent installed on equipment on the organiser's network. Print jobs (including badge content with delegate fields) are queued in the platform and retrieved by the agent; physical printing happens on printers the organiser controls. The organiser is responsible for securing that on-site environment.
4. How we use personal information
- Provide the service: event registration pages, delegate management, accreditation, badge design and printing workflows, check-in, seating, and reporting.
- Operate accounts: authentication, organisation membership, invitations, and role-based access.
- Communicate with you: respond to access requests and support enquiries; send transactional emails when organisers enable them (for example registration confirmations or credential delivery).
- Security and integrity: tenant isolation, rate limiting, fraud and abuse prevention, credential lifecycle controls, and incident investigation.
- Compliance and auditing: maintain audit trails required for operational accountability.
- Improve reliability: monitor errors and performance when observability tools are enabled.
- Retention management: apply event-level retention settings and anonymise expired operational personal data as configured.
5. Legal bases (South Africa — POPIA)
Where the Protection of Personal Information Act, 2013 (POPIA) applies, we rely on the following grounds depending on context:
- Performance of a contract: processing necessary to provide the platform to client organisations and to register attendees at their events.
- Legitimate interests: securing the service, preventing abuse, maintaining auditability, and improving reliability, balanced against data subject rights.
- Legal obligation: where we must retain or disclose information to comply with applicable law.
- Consent: where organisers collect optional information or send marketing communications to attendees — organisers are responsible for obtaining valid consent where required.
Organisers using GastFlo for events in other countries remain responsible for identifying and documenting appropriate legal bases under their local laws.
6. Who we share information with
We do not sell personal information. We share data only as needed to operate the service:
- The event organiser and their authorised staff (within the permissions they configure).
- Infrastructure subprocessors that host or deliver the service on our behalf (see section 7).
- Professional advisers or authorities when required by law or to protect rights and safety.
Organisers may export attendee or event data from the portal. Exports intended for operational use include personal information; exports after retention expiry are designed to redact personal information where retention rules apply.
7. Subprocessors
We use reputable third-party providers to host and deliver GastFlo. These providers process data on our instructions and under contractual safeguards. Current categories include:
- Supabase — database, authentication, file storage, and related APIs.
- Vercel — application hosting and content delivery.
- Resend — transactional email delivery (when email is enabled for an environment).
- Sentry — optional error aggregation when error reporting is configured.
Subprocessor regions may include facilities outside South Africa. See section 8 on cross-border processing.
8. International transfers
Personal information may be processed in countries other than your own, including where our hosting or database providers maintain infrastructure (commonly the United States and the European Union). Where POPIA requires it, we implement appropriate safeguards for cross-border transfers, such as contractual protections with subprocessors and limiting access to what is necessary to provide the service.
9. Retention and deletion
Retention depends on the type of data and the event organiser's settings:
- Event operational data (registrations, attendance, credentials): retained for the period configured on the event (default 365 days after the event context), after which personal fields are anonymised through automated retention processes. Organisers may trigger retention propagation earlier where supported.
- Audit records: retained to preserve an accountability trail when operational rows are anonymised.
- System logs: retained for a limited operational window appropriate for security and troubleshooting.
- Backups: disaster-recovery backups may retain copies until the backup provider's rotation period expires, even after live data is anonymised.
- Marketing enquiries: retained only as long as needed to respond and manage the commercial relationship.
- Portal accounts: retained while the organisation's subscription or contract is active and for a reasonable period thereafter for legal and administrative purposes.
Organisers are responsible for configuring retention appropriately for their events and legal obligations.
10. Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit (HTTPS) for web and API traffic.
- Row-level security and organisation-scoped access controls in the database.
- Hashed storage for opaque check-in credential secrets (plain codes are not stored at rest).
- Rate limiting on public registration, check-in, authentication, and print-agent endpoints.
- Audited access for Mavenzone support staff — unrestricted unaudited cross-tenant access is prohibited.
- Role-based permissions in the client portal.
No method of transmission or storage is completely secure. If you believe your interaction with us is no longer secure, contact us promptly.
11. Your rights
Under POPIA (and, where applicable, other laws), you may have rights to access, correct, delete, restrict, or object to processing of your personal information, and to lodge a complaint with the Information Regulator (South Africa).
Event attendees: exercise these rights with the event organiser in the first instance. They control your registration record.
Portal users and marketing enquiries: contact us at enquiries@gastflo.com. We may need to verify your identity and, for attendee requests, coordinate with the relevant organiser.
12. Children
GastFlo is intended for business and professional events. Organisers should not collect personal information from children without appropriate authority and safeguards. If you believe we have processed a child's information without proper basis, contact us and we will work with the organiser to address it.
13. Cookies and similar technologies
The client portal and authentication flows use essential session and security cookies (or equivalent browser storage) provided through our authentication service. These are necessary to keep you signed in and to protect the service. We do not use third-party advertising cookies on GastFlo.
14. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be posted on this page. Continued use of the service after changes take effect constitutes acceptance where permitted by law.
15. Related documents
Use of the platform is also governed by our Terms of Use. Client organisations may have separate commercial agreements with Mavenzone that prevail where they conflict with these public terms.
