Privacy notice

Last updated 4 October 2026

This notice explains what happens to your information when you sign up after scanning an event QR code, when you receive emails afterwards, and when you use the Kinetiq console as a member of an organization.

Who is responsible

The organization that ran the event or activation decides why your information is collected and how it is used. It is the controller of your information. Kinetiq is the software that organization uses, and it processes your information on the organization's behalf and on its instructions.

What is collected when you sign up at a scan

Opening the scan page does not create a record of you. A scan is recorded only when you submit the form.

The organization can also add records from its own systems, such as a purchase, a ticket or a sign-up, and link them to you by your email address.

The hosting provider's access logs may record your IP address and browser type for security and operations.

Emails you receive

Every email carries a link to your privacy preferences. Each new email's link replaces the one before it, so use the link in your most recent email. The emails contain only the event, sponsor and offer details set by the organization.

Who sees your information

How long it is kept

The organization sets a retention period between 30 days and 10 years (two years unless it changes it). When no activity has been recorded for you for that long, meaning no scan and no other interaction the organization recorded for you through its own systems, your profile is erased automatically. Purchases, tickets and sign-ups on their own do not reset that clock. Records of offers and outcomes older than that period are deleted.

When your profile is erased, the encrypted email address and its hash, your name, postal code, consent records and preference link are removed for good. Stored messages about you for the organization's own systems are stripped of your email address and details, and those not yet sent are never sent, except a message already being delivered at that moment. A copy of your information prepared at your request is replaced by a note that it was erased.

What remains has no email address attached:

If the organization has connected its own systems, they are told that your profile was erased, by its identifier. Information they had already received is held by the organization.

Short-lived records used to stop abuse, which can hold your IP address or device identifier, expire within a day.

Your choices

Cookies and local storage

If you use the console

The service keeps your email address, a hash of your password if you sign in with one (never the password itself), when you last signed in, and your sessions. The actions you take in the console are recorded in the organization's audit trail; your sign-ins and sign-outs are recorded there with your IP address, which the organization's administrators can see.

Contact

For questions about your information or to make a request, contact the organization that ran the event. If you use the console, contact your organization's administrator.