EventsThis explains what personal data we handle, why, who else sees it, and what you can ask us to do about it. Because the platform is used by many independent organisers, the first section — who is actually responsible for your data — is the one that decides which of us you need to talk to.
⚠️ Draft — not yet reviewed by a lawyer. It was written against what the platform actually does, field by field, so that a qualified adviser has something concrete to review. It must not be relied on as legal advice, and it should not be published until it has been checked against the QFC Data Protection Regulations 2021 — which are the rules that apply to a QFC-registered company, in place of Qatar's national Personal Data Privacy Protection Law — and the law of any other market you operate in.
eHaris Events is a platform that independent organisers use to run their own events. That means two different organisations handle your data, for different reasons, and which one you need depends on what you are asking about.
| Data | Who decides how it is used | Our role |
|---|---|---|
| Your account, your saved events, your tickets across all organisers | Us | Controller |
| The details you gave when registering for a particular event | That event's organiser | Processor, acting on their instructions |
| Answers to registration questions the organiser wrote | That organiser | Processor |
| Arrival, badge and gate-scan records at an event | That organiser | Processor |
| Platform security, fraud prevention, billing and service analytics | Us | Controller |
| Our own newsletter and platform marketing | Us | Controller |
In practice: ask the organiser about anything to do with a specific event — why they wanted your passport number, what they did with the list afterwards, or to be removed from their mailing. Ask us about your account, your ticket history, our own emails, or if an organiser will not respond. We will always help you reach them, and where we are the processor we will pass your request on and support them in answering it.
Where an organiser runs their own branded registration page against our API, they present their own privacy notice and their own terms. Ours still describes what happens to the data once it reaches us.
Our details are in section 17. The controller for platform data is eHaris International LLC (registration QFC 01336), 9th Floor, Office No. 1, Tech Circle, QFC Tower 1 No. 98, Doha, State of Qatar. We are established in the Qatar Financial Centre, so the data protection rules that apply to us are the QFC Data Protection Regulations 2021, overseen by the QFC Data Protection Office.
Organisers can add their own questions to a registration form. We do not choose those questions, and the answers belong to the organiser's copy of your data, not to your account profile.
Some organisers ask for things that carry extra legal weight — identity or passport numbers, nationality, date of birth, dietary or accessibility needs that reveal health or religion. Where that happens, the organiser is responsible for having a proper basis for asking, for telling you why, and for any regulatory permission that category requires. If you are asked for something that seems unnecessary, ask them before answering — and tell us if you think it is being misused.
| Purpose | Basis |
|---|---|
| Taking your registration and issuing your ticket | Performing the contract you entered into |
| Taking payment, refunding, and handling chargebacks | Performing the contract; legal obligation for records |
| Sending confirmations, tickets, joining details, changes and reminders | Performing the contract — these are not marketing and you cannot opt out of them while you hold a booking |
| Checking you in, printing badges, controlling entry | Performing the contract, on the organiser's instructions |
| Running your account, saved events and reward points | Performing the contract |
| Marketing from us, from an organiser, or from partners | Your consent, given separately for each, and withdrawable |
| Preventing fraud, abuse and ticket touting; securing the platform | Our legitimate interest in a service that works and is not defrauded |
| Understanding how the platform is used, and fixing errors | Our legitimate interest in improving the service |
| Telling an organiser where their registrations came from | Legitimate interest; reported to them in aggregate, per registration only for their own event |
| Accounting, tax, and responding to lawful requests | Legal obligation |
Where we rely on consent, refusing costs you nothing but the thing you refused — you can always register for an event without agreeing to receive marketing.
These providers process personal data on our behalf. Each is bound to use it only for the purpose we engaged them for.
| Provider | What they do | Where |
|---|---|---|
| Neon | Managed PostgreSQL — the primary database | EU / US |
| Google Cloud (Cloud Run, Secret Manager) | Application hosting and secrets | EU / US |
| ZeptoMail (Zoho) | Default outbound email — confirmations, tickets, reminders | EU / US |
| UploadThing | Image and file storage — event covers, logos, badge assets | US |
| PostHog | Product analytics and error monitoring | EU / US |
| Cloudflare (Turnstile) | Bot protection on public registration endpoints | Global |
| QNodeHub | Card payment processing (hosted checkout) | Qatar |
| Google (OAuth, Meet) | Optional sign-in, and online-event meeting links | Global |
| Zoom | Optional online-event meeting links and attendance sync | Global |
| Microsoft (Teams, Graph) | Optional online-event meeting links and attendance sync | Global |
| OpenFreeMap / Photon | Map tiles and address search on the discover map | EU |
Organisers may connect their own email or payment provider instead of ours. Where they do, that provider is the organiser's choice and appears in the organiser's own privacy notice, not this table.
We are based in the State of Qatar. Some of the providers in section 6 operate outside Qatar, so your data may be processed in other countries whose laws differ. Where that happens we rely on contractual protections with those providers requiring them to protect the data to the standard described here.
An organiser may also be based outside your country. Registering for their event necessarily sends your details to them.
We treat marketing as something you opt into, never something you get by default because you bought a ticket. There are three separate permissions, each independent, each unticked until you tick it:
Each message identifies its sender and carries a one-click unsubscribe. You can also manage every permission from your account, and withdrawing one takes effect across future events — a purchase later on will not quietly opt you back in.
Withdrawing marketing consent does not stop the operational messages about a booking you hold: you will still get your ticket, and you will still be told if the event moves.
Where an organiser markets to you using their own systems after exporting their attendee list, their notice governs it and the unsubscribe has to be honoured by them.
| What | How long |
|---|---|
| Account and profile | While your account is open, then deleted or de-identified after closure |
| Orders, tickets and payment records | As long as tax and accounting law requires, counted from the event |
| Attendance and gate scans | While the organiser needs them to report on their event, then de-identified |
| Consent records | Kept after consent is withdrawn — the record of the withdrawal is the proof that it happened, and deleting it would destroy the evidence it exists to provide |
| Marketing contact details | Until you unsubscribe. We then keep the minimum needed to make sure we do not contact you again |
| Security and delivery logs | A short rolling window, then deleted |
| Backups | Deletions reach backups on the backup rotation, not instantly; restored data is re-deleted |
To be confirmed before publication: the exact periods above need real numbers, set against Qatari tax and accounting requirements. Publishing vague retention periods is a common way to make a promise you cannot keep.
Data is encrypted in transit. Passwords are stored as hashes and never in a readable form. Organiser payment and email credentials are encrypted at rest. Access inside the platform is limited by role, so a person can only reach the organisations and events their permissions cover. Attendee details inside a ticket QR are encrypted so that only authorised check-in devices can read them, while the reference number stays readable by an ordinary camera.
No system is perfectly secure. If a breach occurs that puts you at risk, we will notify you and the relevant authority as the law requires.
Depending on where you live, you can ask to:
Write to privacy@eharis.com. We will respond within 30 days and will verify who you are first — usually by writing to the address already on the record, so that a request cannot be used to extract someone else's data.
Where your request concerns data an organiser controls, we will pass it to them and tell you we have. Some rights have limits: we cannot delete records we must keep for tax, and we cannot delete the record of an unsubscribe without risking contacting you again by mistake.
Our staff can access account data where it is needed to support you, investigate abuse, or keep the platform running. The platform also lets a platform administrator sign in as another user in order to reproduce a problem they have reported. While that is happening, a banner is displayed in the session so it is never invisible, and the action is written to an audit record.
We mention this because it is the kind of capability most policies leave out, and because you are entitled to know it exists.
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Automated checks flag suspected fraud, abuse and bot traffic, and may block a request or hold an order — a person reviews anything that affects an account, and you can ask for that review by contacting us.
The platform is not intended for children, and accounts are for adults. Children may of course attend events, and an adult may register on their behalf — where an organiser collects a child's details, the organiser is responsible for the additional protections that requires under whichever data protection regime applies to them, which for an organiser registered in Qatar outside the financial centre can include obtaining prior regulatory permission.
If you believe a child has given us personal data directly, tell us and we will remove it.
We will publish any update here with a new version number and effective date. Where a change materially affects how we use data we already hold, we will tell you before it takes effect. This version is 2026-08-09, in effect from 9 August 2026.
eHaris International LLC (registration QFC 01336)
9th Floor, Office No. 1, Tech Circle, QFC Tower 1 No. 98, Doha, State of Qatar
+974 66342747
Privacy questions and requests: privacy@eharis.com
If you are unhappy with our response, you can complain to the QFC Data Protection Office, which supervises data protection in the Qatar Financial Centre, or to the data protection authority in your own country. We would rather hear from you first and put it right.
See also our Terms & Conditions, which set out the roles this policy refers to.