Legal

Privacy Policy

Effective from 6 August 2026. Operated by iConf.me.

This policy explains what personal data iConf.me collects when you use iConf.me, why we collect it, and what rights you have over it.

Two different relationships. If you are a conference organiser using this platform, we are the data controller for your account. If you are a delegate registering for a conference hosted here, the organiser is the controller and we act as their processor — contact the organiser directly about your registration data.

Data we collect

Organiser accounts

  • Account details — name, email address, password (stored only as a bcrypt hash, never in readable form), organisation name.
  • Conference details — everything you enter about your event, and the content you publish.
  • Security records — sign-in times, IP address and browser user-agent, retained to detect unauthorised access. IP capture can be disabled at the platform level.
  • Billing records — subscription and payment history. We never see or store your card details; those are handled entirely by our payment provider.

Conference delegates

Where an organiser uses this platform for registration, we store the information their form collects on their behalf — typically name, email, affiliation and any requirements you disclose, such as dietary or accessibility needs. Access is restricted to that conference's team and to platform staff performing support, and every such access is recorded.

Public conference websites

Visiting a conference website does not require an account and does not set advertising or tracking cookies. Standard server logs are kept for security and diagnostics.

Why we process it

PurposeBasis
Providing the service you signed up forPerformance of a contract
Sending verification, password reset and service noticesPerformance of a contract
Detecting and investigating abuse or unauthorised accessLegitimate interests
Meeting accounting and tax obligationsLegal obligation

Who we share it with

We do not sell personal data. We share it only with providers that operate parts of the service:

ProviderPurposeLocation
CHIPPayment processingMalaysia
ResendTransactional email deliveryUnited States
CloudflareContent delivery and network securityGlobal
Akamai (Linode)Server hostingSingapore

Some of these operate outside Malaysia, so your data may be transferred across borders under the safeguards those providers offer.

How long we keep it

  • Active accounts — for as long as the account is open.
  • Closed accounts — up to 12 months, so an account closed by mistake can be recovered, then deleted or anonymised.
  • Financial records — for the period your tax authority requires, which may exceed the above.
  • Backups — data removed from the live system persists in encrypted backups until those age out.

How we protect it

  • Encrypted in transit (HTTPS), with strict transport security enforced.
  • Passwords hashed with bcrypt; never stored or transmitted in readable form.
  • Each conference's data is isolated from every other conference, enforced at several independent layers and covered by an automated test suite that runs on every change.
  • Access to production is restricted and audited. Passwords, tokens and payment credentials are excluded from logs by design.

No system is perfectly secure, and we do not claim otherwise. We will notify affected users and any relevant authority of a breach where the law requires it.

Your rights

Where the UK or EU General Data Protection Regulation applies to you, you have the rights set out below. Where it does not, we extend the same handling anyway — running two standards would mean the weaker one governs most people by accident.

Two of these you can exercise yourself, immediately, without asking us. Article 12(2) requires us to facilitate your rights, and a notice that says "write to us and wait" satisfies the letter of that and not the point of it.

Your rights and how to exercise them
RightHow
Access and portability (Articles 15, 20)
A copy of your data, in a form you can read and move elsewhere.
Sign in and use Your data and privacy. It downloads immediately as JSON.
Rectification (Article 16)
Correct anything inaccurate.
Sign in and edit it under Your account.
Erasure (Article 17)
Deletion of your personal data.
Sign in and use Your data and privacy. See the limits below.
Restriction and objection (Articles 18, 21) Write to support@iconf.me .
Withdraw consent (Article 7(3)) We rely on contract and legitimate interests rather than consent, so there is normally nothing to withdraw. If that ever changes, withdrawal will be as easy as giving it.

What deletion does and does not remove

Being specific here matters more than sounding accommodating, because a promise to erase everything is one we could not keep.

  • Removed: your name, email address, password, sign-in state, the addresses your actions came from, and invitations sent to you.
  • Kept, with you detached from them: payment records and the audit trail. Article 17(3)(b) and (e) leave records outside the right where they are needed for a legal obligation or the defence of legal claims — tax law requires transaction records to be kept for years, and an audit trail that the person it records can empty is not an audit trail. Both are kept with the link to you severed, so they no longer identify you.
  • Not yours to delete: conference website content, which belongs to the organisation. Erasing it because one person left would take a live conference site down as a side effect.

Deletion takes effect 14 days after you ask, and you can cancel it at any point in between. The delay is a protection rather than a hesitation: an account taken over by somebody else must not be destructible before you can notice.

Response times

Requests made through the dashboard are immediate. Requests by email are answered within one month, as Article 12(3) requires, extendable by two further months for complex requests — we will tell you within the first month if that applies and why.

Complaints

You may complain to a supervisory authority, and you do not have to raise it with us first. In the EU that is the authority where you live, work, or where the issue arose; in the UK it is the Information Commissioner's Office. We would rather you told us as well, but that is a preference, not a condition.

If you are a delegate, direct requests about registration data to the conference organiser, who controls it. We are their processor for that data and will assist them in responding.

Legal bases

Article 6 requires us to name one for each purpose, so:

Legal basis for each purpose
PurposeBasis
Providing the platform to an account holderPerformance of a contract, Article 6(1)(b)
Taking payment and keeping the records of itContract, and legal obligation for retention, Articles 6(1)(b) and 6(1)(c)
Security, abuse prevention and the audit trailLegitimate interests, Article 6(1)(f) — keeping a multi-tenant platform safe for the other tenants on it
Service email about your own accountContract, Article 6(1)(b). We send no marketing email.

International transfers

Some processors listed above operate outside Malaysia, the UK and the EEA. Where personal data reaches them, transfers rely on the standard contractual clauses those providers publish, or on an adequacy decision where one exists. The processor list on this page is the complete one; if it changes, this page changes with it.

Cookies

Strictly necessary cookies only: a session cookie to keep you signed in, and a token that protects forms against cross-site request forgery. There is no advertising, no third-party analytics, and no tracking of any kind.

This is why you have not been shown a cookie banner. The ePrivacy rules require consent for cookies that are not strictly necessary; we set none, so there is nothing to consent to. A banner asking permission for cookies that do not exist would be theatre.

The public marketing pages and every published conference website load no third-party resources at all — typefaces included. Nobody outside this platform learns you visited.

Changes

Material changes will be notified by email or through the dashboard before they take effect. The effective date at the top of this page always reflects the current version.

Contact

Questions about this policy: support@iconf.me
iConf.me