Privacy and Cookies

Effective date: 1 September 2026

This notice explains how Arterion Pty Ltd (ACN 620 173 668) (Arterion, we, us, or our) handles personal information when you use Find a Conference, including its Website, Conference App, Account, checkout, support channels, and related services (the Service). Arterion is based in New South Wales, Australia.

1. Contact us

For privacy questions or requests, email support@findaconference.net.

2. Information we collect

We collect information necessary to provide, secure, and improve the Service:

  • Account and authentication information: your email address, display name, profile settings, authentication provider, account identifiers, session details, and, when you use social sign-in, information made available by Google, Microsoft, or LinkedIn to complete sign-in.
  • Service information: watchlist entries, notes, preferences, home city and country, travel settings, Ideal Customer Profile information, scoring preferences, and conference suggestions you submit.
  • Transaction information: subscription, entitlement, checkout, and payment status information we receive from Polar. Polar, as merchant of record, handles payment-card information through its hosted checkout.
  • Communications: information you send us in support requests, feedback, or contact forms.
  • Waitlist information: your email address, the plan you asked about, how you reached us, a record of the wording you were shown and when, your survey answers, and your email preferences. Our survey asks about your professional use of conferences. We do not ask for sensitive information, and you can skip any question.
  • Technical and security information: session-related IP address and browser information, authentication and security logs, and information needed to prevent abuse and maintain the Service.
  • Public conference information: professional information published by conference organisers and other public sources, such as speaker or organiser names, roles, organisations, biographies, public social handles, and business contact details.

3. How we use information

We use personal information to:

  • provide, personalise, and administer the Service and your account;
  • process subscriptions, purchases, refunds, and access entitlements;
  • respond to support requests and communicate service or transaction information;
  • tell you when a plan you asked about is available, and ask you for feedback on planned features, until you unsubscribe;
  • send you updates about Find a Conference, and contact you about how you choose conferences, where you asked us to, until you withdraw;
  • use waitlist survey answers to help prioritise what we build;
  • secure the Service, prevent fraud or misuse, and investigate incidents;
  • source, verify, display, correct, and maintain public conference information; and
  • measure aggregate use of the Service as described in section 5.

We do not sell or provide personal information to conference organisers, advertisers, data brokers, or other third parties for their own marketing. We do not use personal information for targeted advertising, and we do not use it to train AI models or make automated decisions about you. Our AI-assisted work is limited to public conference information.

4. Legal grounds

Australian privacy law does not use the same legal-basis framework as some other laws. Where applicable, including under the UK GDPR or EU GDPR, we process information to perform a contract with you; for our legitimate interests in operating, securing, improving, and understanding the Service; to comply with legal obligations; or with your consent where required. We will obtain consent for processing where the law requires it.

Where the UK GDPR or EU GDPR applies, our legal basis for the waitlist emails described above is your consent. You can withdraw it at any time by using the unsubscribe link in any of those emails or by emailing us, and withdrawing it does not affect anything we did beforehand.

5. Analytics

We use a self-hosted analytics service to understand aggregate use of the Service. It retains anonymous session records that group page views and events for aggregate reporting, including the dimensions described below. These records do not include a user ID, account ID, email address, name, or other stable identifier. They may be classified as anonymous or signed in for aggregate reporting. It does not set analytics cookies or provide session replay. It respects your browser's Do Not Track setting.

Information Purpose and limits Retention
IP address Processed transiently to derive an anonymous session hash. The raw IP address is not stored. Transient only
Country, browser, operating system, device class, screen size, and language Aggregate reporting and service improvement. Region and city are not collected. 13 months
Hostname, page path, page title, external referrer domain, and campaign labels Understand acquisition and navigation. URL hashes and arbitrary query parameters are removed; only utm_source, utm_medium, and utm_campaign may be retained. Advertising click IDs are excluded. 13 months
Named events and controlled properties Measure key journeys, such as app CTA clicks, signup and checkout starts, contact-form submission, joining a plan waitlist, answering the waitlist survey, navigation, and selected Conference App functions. Properties use controlled, low-cardinality values only. 13 months
Page performance measurements How quickly and how steadily a page loaded and responded on your device, including largest contentful paint, interaction to next paint, cumulative layout shift, first contentful paint, and time to first byte. Used to find and fix slow or unstable pages. Timings only, recorded against the same page path and title as a page view. 13 months
Anonymous session dimensions Conference App reporting may classify a session as anonymous or signed in, and by Plan and active Lens. No user ID, account ID, email address, name, or other stable identifier is sent. 13 months

Analytics never receives form values, search text, personal preference values, home location, or arbitrary URL parameters. Analytics data older than 13 months is deleted. Deleted data may remain in encrypted backups for up to seven additional days before those backups expire.

6. Cookies and browser storage

We use strictly necessary authentication cookies to keep you signed in and protect the Service. These cookies use same-site settings.

The Website and Conference App may also use browser local storage to remember choices such as theme, display settings, and locally held personalisation preferences or notes. You can clear this storage in your browser settings, although doing so may reset those choices. Local storage is not sent to Umami.

The Website also uses browser session storage to carry information you have just entered between the steps of a form. This is held only in the tab you are using and is cleared when that tab closes, or sooner once the step it was needed for is finished.

7. Service providers and overseas processing

We use providers that process information on our behalf or as independent controllers for their services. These include AWS for hosting and infrastructure in Sydney, Australia; Polar for hosted checkout and payment administration; Resend and Google Workspace for email; Google, Microsoft, or LinkedIn when you choose their sign-in service; OpenStreetMap Nominatim to geocode a saved home city and country; and self-hosted Umami for analytics. Resend also holds our waitlist contacts and their email preferences, and provides the unsubscribe and preference page linked from those emails.

Some providers may process information outside Australia, including in the United States. We take reasonable steps to use providers with appropriate contractual, technical, and security safeguards, but overseas recipients may be subject to the laws of their location.

8. Retention

We retain personal information only while reasonably needed for the purposes in this notice, including to provide the Service, resolve disputes, enforce our agreements, and meet legal, tax, accounting, security, and fraud-prevention obligations. Support and contact records are reviewed and deleted or de-identified when no longer reasonably needed.

We keep waitlist information until 12 months after the plan you asked about becomes available. Where you have asked for updates or agreed to be contacted about how you choose conferences, we keep that preference until you withdraw it. If you unsubscribe or withdraw, we stop emailing you and keep a record of that so we do not add you again, and we keep survey answers only while they are useful for planning what to build.

If you request account deletion, we normally delete or de-identify your account profile, watchlist, preferences, and other account-linked Service information within 30 days, subject to legal obligations, dispute or security needs, and backup expiry. We may retain limited billing and transaction records for at least five years where required by Australian tax, accounting, fraud-prevention, or dispute requirements. Polar retains information under its own policies.

9. Your rights and choices

You may ask us to access, correct, delete, or provide a copy of your personal information, or to restrict or object to particular processing where applicable. You can request account deletion, correct public conference information about you, or ask us to remove it by emailing support@findaconference.net. We may ask for reasonable information to verify your identity before acting on a request.

We aim to acknowledge requests promptly and normally respond within 30 days. If a request is complex, we may take longer where permitted by law and will tell you why. If you are in a jurisdiction that gives you additional rights, including the UK or certain US states, you may exercise those rights through the same contact channel. You may also have a right to appeal or complain to a relevant regulator.

10. Children

The Service is not directed to children. You must be at least 18 years old to create an account or purchase a subscription. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

11. Security

We use reasonable technical and organisational safeguards, including access controls, encryption in transit and at rest where appropriate, restricted infrastructure access, and backups, to protect personal information. No system is completely secure, and we cannot guarantee absolute security.

12. Complaints

Please contact us first so we can try to resolve a privacy concern. Australian residents may also complain to the Office of the Australian Information Commissioner at oaic.gov.au. People outside Australia may have the right to complain to their local privacy regulator.

13. Changes to this notice

We may update this notice from time to time by posting the updated version and effective date. For material changes, we will give account holders at least 30 days' notice by email or in the Service where practical. Changes needed for law, security, or fraud prevention may take effect sooner.