FEROEVENT

an Event Operating System

PRIVACY POLICY

Including Cookie Notice — applicable to all users of FeroEvent worldwide

Operated by FeroEvent Limited

Effective Date: [1st January 2026]

Last Updated: [1st January 2026]

1. Introduction and Scope

FeroEvent Limited, operating as FeroEvent (“FeroEvent,” “we,” “us,” or “our”), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights available to you, wherever in the world you access the Platform.

This Policy applies to all users of the FeroEvent website, mobile applications, and related Services, including Attendees, Hosts, and visitors who browse the Platform without registering.

For the purposes of applicable data protection law, FeroEvent Limited is the data controller of personal data processed through the Platform, except where a Host is acting as controller of Attendee data it collects independently for its own Event (see Section 9).

2. Information We Collect

2.1 Information you provide directly

  • Account information: name, email address, phone number, password, profile photo, and country/region.
  • Identity/verification information for Hosts: government-issued ID, business registration details, and bank or mobile-money payout details, where required for payout and fraud-prevention purposes.
  • Payment information: processed by our third-party payment processors (Paystack, Stripe); we do not store full card numbers on our own servers.
  • Event content: event details, livestreams, tickets, descriptions, uploaded files, images, and other materials you submit.
  • Communications: messages sent through Event group chat, support requests, event reviews and correspondence with us.

2.2 Information collected automatically

  • Device and log data: IP address, browser type, operating system, device identifiers, referring URLs, and access timestamps.
  • Usage data: pages viewed, features used, Events joined or hosted, and interaction with livestreams and recordings.
  • Livestream and recording data: audio/video streams and cloud recordings of Events, including any Content shared or discussed during the Event, where the Host has enabled recording.
  • Cookies and similar tracking technologies, as described in Section 4.
  • Approximate location data inferred from your IP address, and precise location only where you separately grant permission (e.g., for location-based Event discovery).

2.3 Information from third parties

  • Payment confirmation and fraud-screening data from Paystack and Stripe.
  • Streaming delivery and analytics data from our multistreaming and content-delivery partners (e.g., Castr).
  • Information from social login providers, if you choose to register or sign in using a third-party account.

3. How We Use Your Information

We use personal data to: create and manage accounts; process ticket purchases and Host payouts; operate livestreaming, recording, multistreaming, and file-sharing features; facilitate Event group chat; provide customer support; detect, prevent, and investigate fraud, abuse, and security incidents; communicate with you about Events, transactions, and Platform updates; personalize and improve the Platform; comply with legal, tax, and regulatory obligations; and enforce our Terms of Service and Acceptable Use Policy.

Where required by applicable law (including the EU/UK General Data Protection Regulation and Nigeria's Data Protection Act), we process personal data on one or more of the following legal bases: performance of a contract with you; your consent; our legitimate interests (such as fraud prevention, Platform security, and service improvement), balanced against your rights; and compliance with a legal obligation.

4. Cookies and Tracking Technologies

We use cookies and similar technologies (such as pixels and local storage) to operate the Platform, remember your preferences, keep you signed in, measure performance, and, where you consent, deliver relevant marketing.

Categories of cookies we use:

  • Strictly Necessary — required for core functionality such as login and checkout, and cannot be switched off.
  • Performance/Analytics — help us understand how the Platform is used.
  • Functional — remember your settings and preferences.
  • Marketing — used, only where you consent, to measure and personalize promotional content.

Where required by the law of your jurisdiction (including the EU/UK and other regions with similar requirements), we will request your consent before setting non-essential cookies, through a cookie banner or preference center. You can withdraw consent, and manage or delete cookies at any time, through your browser settings or our cookie preference tool where available.

We do not currently respond to “Do Not Track” browser signals, as no common industry standard for such signals has been adopted; you may still control tracking through the cookie tools described above.

5. How We Share Your Information

We share personal data with:

  • payment processors (Paystack, Stripe) to process transactions and payouts;
  • hosting and infrastructure providers (including Railway and our database providers) to operate the Platform;
  • streaming and multistreaming service providers (including Castr) to deliver livestream and recording features;
  • analytics and communication providers (email/SMS) to operate the Platform and communicate with you;
  • professional advisors (legal, accounting) where necessary; and
  • regulators, law enforcement, or courts where required by law or to protect our rights, safety, or property, or that of our Users.

If you register for or attend a Host's Event, we share relevant registration and attendance information (such as your name and email) with that Host so they can manage their Event; the Host's own use of that information is governed by their privacy practices and, where applicable, our Host/Organizer Agreement.

We do not sell your personal data to third parties for monetary consideration. Where required by the law of your jurisdiction (including California's Consumer Privacy Act, as amended), we will identify whether any sharing constitutes a “sale” or “sharing” under that law and provide any required opt-out mechanism.

We may share information in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.

6. International Data Transfers

FeroEvent is based in Nigeria, and personal data may be processed in Nigeria, other African markets in which we operate, and other countries where our service providers are located, which may have different data protection laws than your home country.

Where we transfer personal data of users in the European Economic Area, United Kingdom, or Switzerland to a country not deemed to offer an adequate level of protection, we will rely on an appropriate safeguard recognized under applicable law, such as the European Commission's Standard Contractual Clauses or an equivalent mechanism, and will make details available on request.

7. Data Retention

We retain personal data for as long as necessary to provide the Platform, comply with our legal and tax obligations, resolve disputes, and enforce our agreements. Event recordings are generally retained and accessible for a limited period after an Event (currently up to 72 hours for general on-demand access, or longer where the Host or applicable law requires), after which they may be archived or deleted completely from our end.

When personal data is no longer needed for these purposes, we will delete or anonymize it, save where retention is required by law (e.g., financial transaction records).

8. Data Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and restricted credential management for our infrastructure and database.

No method of transmission or storage is completely secure. In the event of a data breach affecting your personal data, we will notify you and the relevant regulator where required by applicable law.

9. Your Rights

9.1 General rights available to most users

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your personal data, subject to legal retention requirements.
  • Objection/Restriction — object to, or request that we restrict, certain processing of your data.
  • Portability — request your data in a structured, commonly used, machine-readable format.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

9.2 European Economic Area, UK, and Switzerland (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland, you have the rights listed in Section 9.1 under the GDPR/UK GDPR, and the right to lodge a complaint with your local data protection supervisory authority. We will respond to verified requests within the timeframe required by applicable law (generally one month, extendable in complex cases).

9.3 Nigeria (Nigeria Data Protection Act)

If you are located in Nigeria, you have the rights described in Section 9.1 under the Nigeria Data Protection Act 2023, and may lodge a complaint with the Nigeria Data Protection Commission (NDPC).

9.4 California and other US states

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know what personal information we collect, request deletion, correct inaccurate information, opt out of the “sale” or “sharing” of personal information (we do not sell data for money, as noted in Section 5.3), and not be discriminated against for exercising these rights. Residents of other US states with comparable privacy laws have equivalent rights under those laws.

9.5 How to exercise your rights

You may exercise these rights by contacting feroevent@feroevent.com. We may need to verify your identity before fulfilling a request. You will not be charged a fee to exercise your rights, except where permitted by applicable law for manifestly unfounded or excessive requests.

10. Children's Privacy

The Platform is not directed at children and is not intended for use by anyone under 13 years of age (or the relevant minimum age of digital consent in their jurisdiction, if higher). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it. Parents or guardians who believe their child has provided us with personal data should contact feroevent@feroevent.com.

11. Third-Party Links and Services

The Platform may contain links to third-party websites or integrate third-party services (such as payment processors and streaming destinations). We are not responsible for the privacy practices of those third parties, and encourage you to review their privacy policies.

12. Hosts as Independent Data Controllers

When a Host collects, uses, or exports Attendee information for purposes beyond operating the Event through the Platform (for example, adding Attendees to the Host's own separate mailing list), the Host acts as an independent data controller for that processing and is responsible for complying with applicable data protection law in that respect. Hosts must not use Attendee data for purposes inconsistent with this Policy or applicable law.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified through the Platform or by email before they take effect. The “Last Updated” date at the top of this Policy indicates when it was last revised.

14. Contact Us

Questions, requests, or complaints regarding this Privacy Policy or our data practices may be directed to:

FeroEvent Limited
Email: feroevent@feroevent.com