Heapcon 2026 Privacy Policy
Last updated: [31 August 2026]
1. Who we are
This Privacy Policy explains how Heapspace, Belgrade (Serbia), VAT number: 108772431, Registration number: 28158777 (“Heapspace”, “we”, “us”) collects and uses personal data in connection with the Heapcon 2026 conference.
Contact: heapcon@heapspace.rs
Data Protection Contact / DPO (if applicable): Dimitrije Stamenković
2. Scope
This policy covers data processed through:
-
The Heapcon website (heapcon.io/2026)
-
The Heapcon mobile app for iOS and Android, which we operate ourselves
-
Ticketing and attendee management (via Entrio)
-
On-site registration and badge QR scanning (via RentIT)
-
Interactions with conference exhibitors and sponsors at the venue
3. What data we collect
-
Registration and attendance data: name, email, company, job title/role, country, ticket type, check-in status, and similar details you provide via Entrio or to us.
-
On-site badge data: your badge contains a unique QR code that allows authorized exhibitors to retrieve your contact details when you choose to let them scan your badge.
-
Interaction data: session check-ins, workshop selections, networking preferences, dietary requirements (if provided), and general conference analytics (aggregated).
-
Communications: emails you send us and your preferences for event communications.
-
Website data: basic technical logs and analytics (IP address, device/browser info). We do not use invasive profiling.
-
Mobile app profile data: the profile you build in the app: bio, position, company, profile photo, and optional links to your LinkedIn, X/Twitter and personal website. You choose, per link, whether it is visible to all attendees or only to your accepted connections, and you choose who may send you a direct message. You may also record whether you are attending alone, which is visible only to organizers.
-
Content you create in the app: posts and photos on the attendee feed, comments, direct messages to other attendees, questions and answers during talks, and talk ratings and reviews. Ratings can be submitted anonymously; anonymous ratings are not attributed to you anywhere in the app.
-
Connections: the attendees you send, accept, or receive connection requests from.
-
Device permissions, used only when you invoke the feature: camera (scanning another attendee’s badge QR code, and taking a profile photo) and photo library (attaching images to posts, setting a profile photo). Each is requested at the point of use, can be declined, and can be revoked in your device settings. The app remains usable without either of them.
-
Push notification data: if you allow notifications, a push token issued by your device’s operating system, and whether your device is iOS or Android. Used to notify you about direct messages, connection requests and conference announcements.
-
Safety and moderation data: if you report content or block another attendee, we record the block, together with the report: what was reported, the reason you selected, any detail you add, and that you were the reporter.
The app contains no advertising, analytics or crash-reporting SDKs. We do not use advertising identifiers, and the app does not track you across other apps or websites.
4. How we use your data
-
Deliver the event you registered for (ticketing, access control, agenda communications, support).
-
Operate on-site services, including badge printing and scanning.
-
Run the mobile app (your account and sign-in, your profile and personal agenda, the attendee directory, the feed, messaging, connections and talk Q&A).
-
Send push notifications you have allowed, for direct messages, connection requests and conference announcements.
-
Keep the app safe (reviewing reports, removing content that breaches our Terms of Use, and acting on blocks).
-
Share your details with exhibitors only when you allow your badge to be scanned at their booth.
-
Event communications (program updates, logistics, post-event surveys).
-
Security and compliance (fraud prevention, health and safety, legal obligations).
-
Event analytics to improve future editions (aggregated wherever possible).
5. Legal bases (GDPR / applicable local law)
-
Contract performance: to deliver the conference you registered for, and to provide the app account you created.
-
Legitimate interests: event operations, safety, content moderation, aggregated analytics, and preventing abuse, balanced against your rights.
-
Consent: marketing you opt into, push notifications you allow, and sharing your data with exhibitors when you allow a scan. The act of allowing a booth to scan your badge is your consent to share your contact details with that exhibitor for follow-up.
6. Badge scanning at exhibitor booths (lead collection)
-
Your printed badge includes a QR code.
-
If you allow an exhibitor to scan your badge, we will provide that exhibitor with your contact details (typically name, email, company, job title/role; exact fields may vary by registration form).
-
Exhibitors may add private notes to their lead records (e.g., “interested in backend roles”).
-
No scan = no data sharing. If you prefer not to share your data with a booth, simply decline the scan.
-
Exhibitors act as independent data controllers for the data they receive via scans and must handle it in line with their own privacy obligations. You may contact them directly to exercise your rights.
Separately from exhibitor lead capture, the Heapcon 2026 app shows you a personal QR badge that other attendees can scan to open your profile and send you a connection request. Scanning an attendee badge shares nothing beyond the profile you have already chosen to make visible, and no contact details are transferred to exhibitors.
7. Who we share data with
-
Entrio (ticketing provider) for ticket purchase/claim, attendee lists, and access management.
-
RentIT (on-site registration and scanning) for badge printing and lead capture operations.
-
Brevo (email service provider) to send operational emails such as registration invitations, password resets, schedules, reminders, and post-event surveys.
-
Exhibitors/Sponsors: only when you allow your badge to be scanned at their booth.
-
Vetted processors providing hosting, email delivery, and analytics under contracts that protect your data.
These providers act as data processors, meaning they process personal data strictly according to our instructions and under appropriate data protection agreements.
We do not sell personal data.
8. International transfers
When data leaves your country/EEA/UK, we use appropriate safeguards (e.g., EU Standard Contractual Clauses) and assess the destination’s protections where required.
9. Data retention
-
Registration and operational data: for the duration of the event plus up to 24 months for accounting, compliance, and event-improvement purposes.
-
Mobile app account data: retained on the same basis as registration data above, unless you delete your account sooner.
-
Attendee-created content in the app is deleted in full within 90 days after the conference ends. This covers feed posts and photos, comments, direct messages, talk questions and answers, and talk ratings and reviews. The app is a conference tool, not a lasting social network, and we do not keep its conversations beyond the event.
-
Push tokens: deleted when you sign out or delete your account.
-
Moderation records: reports are retained after the reported content is removed, so that the record of a moderation decision outlives the content it concerned.
-
Lead data shared with exhibitors: retention is determined by each exhibitor’s policy. Contact them directly for details or deletion.
-
We keep communications and legal records for periods required by law.
10. Your rights
Subject to applicable law, you may have rights to access, correct, delete, restrict, object, and port your data, and to withdraw consent at any time (withdrawal does not affect prior processing).
To exercise rights: contact heapcon@heapspace.rs. You may also lodge a complaint with your local supervisory authority.
11. Deleting your Heapcon account
You can delete your Heapcon account at any time from inside the app: Menu → Account → Delete account. You will be asked to confirm your password. You can also request deletion by emailing heapcon@heapspace.rs.
Deletion is immediate and cannot be undone. We erase your name, email address, company, job title, bio, links and profile photo, your connections and pending connection requests, your saved agenda, and your registered devices, and your account can no longer be used to sign in.
Posts, comments, direct messages, talk ratings and questions you have already sent remain visible to other attendees, but are no longer linked to you. The author is shown as “Deleted user”. We retain them because deleting them would remove parts of other people’s conversations, including the messages that other attendees’ replies were answering. They are deleted along with all other app content within 90 days after the conference, as described in Section 9.
Deleting your app account does not delete your conference ticket or registration record held by Entrio; contact us if you want those removed as well.
12. Security
We use administrative, technical, and physical safeguards appropriate to the risks of event operations. No system is perfectly secure, but we continuously work to protect your data.
13. Children
Heapcon is a professional event not directed to children. We do not knowingly collect data from children under applicable age thresholds.
14. Changes to this policy
We may update this policy for legal, technical, or operational reasons. Material changes will be highlighted on this page prior to taking effect.
Contact: [heapcon@heapspace.rs]