Back to Home
Legal

Symposia Privacy Policy

Last updated: 2 June 2026

This Privacy Policy explains how the Symposia conference management platform ("Symposia", "we", "us", "our") collects, uses, and protects personal data when you use our services. This policy is governed by the EU General Data Protection Regulation (GDPR) and applicable Croatian data protection law.

1. Who We Are

Symposia is operated by 9th Hour d.o.o., a limited liability company incorporated in Croatia (European Union). Symposia is a software-as-a-service (SaaS) platform that helps conference organisers manage registrations, abstracts, invoicing, scheduling, and certificates.

When processing attendee and conference data on behalf of an organiser, 9th Hour d.o.o. acts as a data processor, and the conference organiser is the data controller. For our own platform operations (such as managing organiser accounts), 9th Hour d.o.o. acts as the data controller.

Company: 9th Hour d.o.o.
Registered seat: Croatia (European Union)
Privacy contact: privacy@getsymposia.app

9th Hour d.o.o. makes a Data Processing Agreement (DPA) available to conference organisers governing the processing of attendee data on their behalf.

2. What Data We Collect

2.1 Attendee Registration Data

When you register for a conference through Symposia, we collect:

  • Identity information: title, first name, last name, email address, phone number, institutional affiliation
  • Accompanying person name (if applicable)
  • Conference preferences: selected ticket type, conference section
  • GDPR consent flag recorded at the time of registration

2.2 Billing Data (Proforma Invoices)

If your registration requires payment, we collect the billing details needed to issue a proforma invoice:

  • Invoice recipient name or company name
  • Full street address, city, postal/zip code
  • VAT/tax identification number
  • Additional invoice notes

2.3 Abstract Submissions

If you submit an abstract, we collect:

  • Abstract title, content, and references
  • Author information (names, emails, institutions)
  • Uploaded files (PDF or Word documents)
  • Corresponding author email

2.4 Speaker Profile Data

If you are listed as a speaker, we may collect and display:

  • Biography
  • Avatar/profile image
  • Website
  • Email address

2.5 Mobile App Data

  • One-time verification codes sent to your email for mobile login
  • Session ratings and feedback you submit about conference sessions

2.6 Communications Data

  • Stored copies of emails we send on the organiser's behalf, including the recipient address, subject line, and full message body, retained in our email logs

2.7 Technical Data

  • Authentication tokens stored in secure HttpOnly cookies
  • Timestamps of registration, submissions, and check-ins
  • Email delivery records (recipient, subject, delivery status)
  • IP addresses and request metadata, captured by our web server and error-monitoring tooling (see Section 5)
  • Product analytics events describing how you interact with the platform (see Section 5)

3. How We Use Your Data

We process your personal data to provide the conference management services on behalf of the organiser, and to operate and improve the platform:

  • Registration processing: creating and managing your conference registration
  • Communication: sending confirmation emails, registration links, abstract review notifications, and invoices
  • Abstract management: facilitating the submission and peer-review process
  • Certificate generation: producing attendance and presentation certificates using your name
  • Invoicing: generating and delivering proforma invoices for conference fees
  • Analytics & reliability: understanding how the platform is used and detecting, diagnosing, and fixing errors (see Section 5)

4. Legal Basis for Processing

We process your data based on the following legal grounds under the GDPR:

  • Consent: you provide consent when registering for a conference, and analytics cookies are set only where you consent via our cookie banner
  • Contractual necessity: processing is necessary to fulfil the registration and services you requested
  • Legitimate interest: of the conference organiser to manage their event, and of 9th Hour d.o.o. to secure, maintain, and improve the platform (including error monitoring and, where permitted, analytics)

5. Cookies, Analytics & Error Monitoring

Symposia uses cookies and similar technologies for authentication and session management, and for product analytics. We use the following tools:

  • Essential cookies: required for authentication and to keep you signed in. These are always active.
  • Analytics (PostHog): we use PostHog, loaded in your browser and hosted in the EU (eu.i.posthog.com), to understand how the platform is used. PostHog records product events such as sign-up, login, attendee and group registration, abstract submission, and conference create/update/delete actions. For attendees and purchasers, your email address may be used as the analytics identifier. Analytics cookies are set on the basis of your consent, collected through the cookie consent banner in the app, and/or our legitimate interest in improving the service.
  • Error monitoring (Sentry): we use Sentry to detect and diagnose technical errors. Sentry is configured to capture IP addresses and request metadata on error events to help us reproduce and fix issues.

We do not use advertising cookies or sell your data to advertisers. You can manage your analytics preferences through the cookie consent banner in the app.

6. Data Sharing & Sub-processors

We do not sell your personal data. Your data may be shared with:

  • The conference organiser (data controller) who manages the event you registered for

To operate the platform, 9th Hour d.o.o. engages the following sub-processors. Each is contractually bound to protect your data and to process it only on our instructions:

Sub-processor Purpose Region
Supabase Database and file storage hosting European Union
PostHog Product analytics European Union
Sentry Error monitoring European Union

7. Data Storage and Security

  • Your data is stored in the European Union, on Supabase's EU region infrastructure
  • We use encryption in transit (HTTPS/TLS) and at rest
  • Passwords are hashed using industry-standard algorithms and are never stored in plain text
  • Access to personal data is restricted to authorised personnel only

8. International Transfers

All of our infrastructure and sub-processors — database, file storage, product analytics, error monitoring, and PDF rendering — are hosted within the European Union. We do not transfer your personal data outside the EU/EEA.

9. Data Retention

Attendee and event data is retained for the duration of the conference and one (1) month after the conference end date. After this period:

  1. All attendee data is exported and delivered to the conference organiser
  2. The data is permanently deleted from our servers

The invoices generated by Symposia are proforma invoices, not fiscal/tax invoices. They are therefore not subject to statutory tax-retention periods, and the same conference-duration-plus-one-month retention rule applies to them.

Organiser account data — organiser user accounts and the conferences they create — is retained until the account is closed.

10. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict processing of your data
  • Data portability – receive your data in a structured, machine-readable format
  • Object to certain types of processing
  • Withdraw consent at any time

To exercise any of these rights, contact us at privacy@getsymposia.app or reach out to the conference organiser directly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

12. Contact

If you have questions about this Privacy Policy or how your data is processed, please contact:

9th Hour d.o.o.
Email: privacy@getsymposia.app