Privacy notice
What we do with personal data, why we are allowed to, and how to make us stop.
conference.international is operated by ISO LONDON LIMITED, a limited company registered in England and Wales under company number 09219513.
Correspondence address: 81 Turners Hill, Waltham Cross, Hertfordshire, England, EN8 9BD
Email: hello@conference.international
We reply to email within two working days. There is no telephone line; email reaches us fastest.
ISO LONDON LIMITED is the controller of the personal data described here. We are registered in England and Wales under company number 09219513, and with the Information Commissioner's Office under registration reference ZC242713.
We count page views, listing views and clicks through to an organiser's own site. We store a single number per day for each of those, and nothing else: no IP address, no device or browser details, no cookie, and no identifier that could be tied to you. That means we can tell you how many times a page was opened, and we cannot tell you how many people opened it. We do not try to. If your browser sends Do Not Track or Global Privacy Control, nothing is counted at all.
1. Reading the index
You can search the whole index without an account, without a cookie banner and without being tracked. We do not use advertising or analytics cookies, we do not embed third-party trackers, and we do not build a profile of you.
Your browser stores your chosen interface language on your own device so the site opens in it next time. That stays on your device and never reaches us. When you are signed in as an organiser, your browser also holds a sign-in token, which is what keeps you signed in. Both are strictly necessary for something you asked for, so neither needs a consent banner.
Our hosting provider keeps short-lived server logs, including IP addresses, for security and to keep the service running.
2. Conference entries
A conference entry is mostly not personal data: a title, dates, a city, a subject, a link. Sometimes it includes a name or a contact address the organiser has published for that conference.
| What | Why | Our lawful basis |
|---|---|---|
| Conference details submitted to us | To publish the entry the organiser asked us to publish | Legitimate interests, and performance of a contract where the organiser has an account with us |
| Contact details published on a conference's own website, collected by our indexer | So we can tell the organiser their conference is listed and let them correct or remove it | Legitimate interests, running an accurate index and giving organisers control over their own entry |
| Organiser account: email address and a password we only ever hold as a hash | To let organisers manage their entries | Performance of a contract |
| Email alert subscriptions | To send the alerts you asked for | Consent |
| Messages sent through the contact form | To answer you | Legitimate interests |
| Payment records | To take payment, issue receipts and keep tax records | Performance of a contract, and legal obligation |
Where we rely on legitimate interests we have weighed our interest in running a useful, accurate index against your interests and rights. You can object at any time (section 6) and we will stop unless we have compelling grounds not to, which for an index entry we usually will not.
3. Email
Alerts. These are opt-in twice over: you ask for them, then you confirm from a link we email you. Nothing is sent until you confirm. Every alert carries a one-click unsubscribe link, and unsubscribing is immediate and permanent unless you ask again.
Messages to organisers about their own entry. If your conference is in our index we may write once to the contact address published for that conference, to tell you it is listed and how to correct, claim or remove it. That message contains a link that removes the entry and stops any further contact, in one click. We keep a suppression list, and an address on it is never written to again.
We do not sell, rent or share email addresses with anyone for their own marketing. Ever.
4. Who else handles the data
We use a small number of providers, each under a contract that limits them to acting on our instructions:
- Vercel, hosting and delivery of the website.
- Supabase, the database, hosted in the European Union.
- Resend, sending our email.
- PayPal, taking payment. PayPal is a separate controller for the payment itself and has its own privacy notice. We never receive your card details.
Some of these providers are in the United States. Where personal data is transferred outside the UK, it is protected by the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, or by a UK adequacy regulation.
We disclose data to anyone else only where the law requires it.
5. How long we keep it
- Conference entries are kept for good. The day after a conference ends its entry stops appearing among current conferences and is found under past conferences instead. We do not delete it, because a conference that has happened is still a fact worth recording.
- Organiser accounts, until you ask us to close the account.
- Alert subscriptions, until you unsubscribe. An address that has never been confirmed is deleted after 30 days.
- Contact form messages, 24 months.
- Payment and tax records, six years, as UK tax law requires.
- Suppression list, indefinitely, because its whole purpose is to remember not to contact you.
6. Your rights
Under the UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or send it to someone else in a portable form. You can object to processing we base on legitimate interests, and you can withdraw consent to email alerts at any time.
Write to hello@conference.international. We answer within one month and there is no charge.
If you are not satisfied with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would rather you came to us first, but you do not have to.
7. Security
The site is served over HTTPS only. Passwords are stored as salted hashes and never in a form we can read. Access to the database is limited to the parts of the service that need it. Payment card details never touch our systems.
8. Children
This is a service for conference organisers and researchers. It is not directed at children and we do not knowingly collect data about them.
9. Changes
If we change this notice we update the date at the foot of the page, and we tell subscribers about anything material.