PRIVACY POLICY
Event BDR Platform — operated by Dilogic Group L.L.C-FZ
Last updated: 24 August 2026. Effective date: 24 August 2026.
This Privacy Policy explains how Dilogic Group L.L.C-FZ (“Dilogic Group”, “Event BDR”, “we”, “us”) collects, uses, shares and protects personal data through the Event BDR platform. It is designed to comply with the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021 and its Executive Regulations), the Saudi Personal Data Protection Law (Royal Decree M/19 of 1443H) and its Implementing Regulations, and, where applicable, the EU and UK General Data Protection Regulation (GDPR).
1. WHO WE ARE AND SCOPE
1.1 Controller. Dilogic Group L.L.C-FZ is a limited liability company established in the Meydan Free Zone, Dubai, United Arab Emirates (commercial licence 2306815.01), with registered address at Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. We operate the Event BDR platform, including the websites eventbdr.com and app.eventbdr.com and related mobile and web applications (together, the “Platform”).
1.2 Scope. This Policy applies to personal data we process about: (i) business development representatives (“Representatives” / “BDRs”); (ii) client account users (“Clients”); (iii) prospects, exhibition attendees and contacts whose data is captured as leads (“Leads”); and (iv) visitors to our websites.
1.3 Our role. We act as a data controller for Representative, Client and website-visitor data. For Lead data captured at events, we act as controller and/or processor up to the point of delivery to a Client; once a Lead is delivered, the Client is an independent controller of that Lead.
2. KEY TERMS
- “Personal Data” any information relating to an identified or identifiable natural person.
- “Processing” any operation performed on personal data, such as collection, recording, storage, use, disclosure or deletion.
- “Controller” the person that determines the purposes and means of processing.
- “Processor” the person that processes personal data on behalf of a controller.
- “Lead Data” contact and qualification information about a prospect or attendee captured through the Platform for a Client.
3. PERSONAL DATA WE COLLECT
3.1 From Representatives (BDRs): name, contact details, date of birth, nationality/ID or work-authorisation details (where required for vetting and payment), photograph, code name/initials, interview and vetting information, bank/payout details, tax information, event assignments, performance and activity data, device and log data, and communications with us.
3.2 From Clients: account holder and user names, business contact details, company details, role, billing and payment details (processed via our payment processor), briefs, scripts, target criteria, Orders, wallet and transaction data, communications, and usage/log data.
3.3 Lead Data (prospects/attendees): name, job title, company, business email, business phone, business-card or badge-scan data, and qualification notes captured in accordance with the Client's approved brief. We collect Lead Data in a business-to-business context.
3.4 Automatically: IP address, device identifiers, browser type, pages viewed, app interactions, approximate location inferred from IP address in our website analytics, cookies and similar technologies, and acceptance/clickwrap records (including timestamps and device data) evidencing agreement to our terms. Precise location, camera and microphone access in our mobile applications are addressed separately at clause 3.6.
3.5 Special categories. We do not intentionally collect special-category data. Please do not submit it. Any identity/nationality data collected for Representative vetting or payment is handled with additional safeguards and only as required by law.
3.6 DEVICE PERMISSIONS IN OUR MOBILE APPLICATIONS
Our mobile applications request the device permissions set out below. Each permission is requested at the point of first use and each may be withdrawn at any time in your device settings. Where a permission is withheld or withdrawn, the feature that depends on it will not operate; the rest of the Platform continues to function.
3.6.1 Precise location. When a Representative checks in to or out of an Assignment, the application requests precise location (satellite-level coordinates, being the ACCESS_FINE_LOCATION permission on Android and the equivalent when-in-use permission on iOS) and records those coordinates, together with their reported accuracy, against the check-in record. We use precise location for one purpose: to confirm that a Representative was physically present at the assigned venue at the assigned time. That confirmation supports attendance verification, settlement of piece pay, and the prevention of fraudulent check-ins. We do not collect location while the application is closed or running in the background, we do not build location histories or movement profiles, and we do not use location for advertising. Coordinates are held by us as operator and are not disclosed to Clients; a Client sees attendance status, not a position. Basis: performance of a contract; legitimate interests in preventing fraud.
3.6.2 Camera. The application requests camera access so that you can capture (i) check-in and on-site photographs evidencing attendance and completed work, and (ii) identity and work-authorisation documents submitted during Representative vetting, where you choose to photograph a document rather than upload a file you already hold. The camera is activated only when you open it from within the application, and never in the background. Images captured this way are the photograph and the identity documents referred to at clause 3.1 and are retained, shared and deleted on the terms that apply to those categories. Basis: performance of a contract; legal obligation in respect of identity verification.
3.6.3 Microphone. The application requests microphone access so that you can dictate text instead of typing it, for example when recording lead qualification notes. Dictation uses the speech recognition built into your own device and is configured to run on that device. Your speech is converted to text on your phone. No audio recording is transmitted to us, stored on our servers, or disclosed to any third party, and we do not receive the audio at any stage. We receive only the text you choose to save. Basis: performance of a contract; legitimate interests.
4. HOW AND WHY WE USE PERSONAL DATA (PURPOSES AND LAWFUL BASES)
We process personal data for the following purposes, relying on the lawful bases indicated (GDPR terminology, with the corresponding bases under UAE PDPL and KSA PDPL applied where relevant):
- Providing the Platform and Services — to register accounts, offer and manage Assignments and Orders, capture and deliver Leads, book Meetings, and provide reporting. Basis: performance of a contract; legitimate interests.
- Vetting Representatives — interviewing, approving and masking identities. Basis: performance of a contract; legitimate interests; consent where required.
- Verifying on-site attendance: confirming, through precise location captured at check-in and check-out and through check-in photographs, that a Representative was present at the assigned venue at the assigned time, so that work can be settled and fraudulent check-ins prevented. Basis: performance of a contract; legitimate interests; legal obligation.
- Payments and settlement — processing wallet top-ups, Client charges and Representative payouts. Basis: contract; legal obligation.
- Lead generation for Clients — capturing and qualifying B2B Leads and delivering them to Clients. Basis: legitimate interests of the Client and Event BDR in B2B marketing; consent where required by law.
- Communications and notifications — sending service emails and WhatsApp/SMS notifications about accounts, Assignments, Orders and Leads. Basis: contract; legitimate interests; consent for marketing where required.
- Security, fraud prevention and compliance — protecting the Platform, preventing circumvention and fraud, and meeting legal obligations. Basis: legitimate interests; legal obligation.
- Improving the Platform — analytics and product improvement, primarily using aggregated and anonymised data. Basis: legitimate interests.
- Evidencing agreement — recording clickwrap acceptance of our terms. Basis: legitimate interests; legal obligation.
5. LEAD DATA — SPECIAL NOTICE
5.1 B2B context and transparency. Lead Data is captured in a professional, business-to-business setting (exhibitions and events). At the point of capture, Representatives operate under the Client's approved brief and applicable event rules. Where required by law, notice is given and/or consent is obtained before capture.
5.2 Delivery to Clients. Once a Lead is delivered to a Client, the Client becomes an independent controller and is responsible for providing further privacy notices and obtaining any consents needed for its own marketing and follow-up. Event BDR is not responsible for a Client's subsequent processing.
5.3 Objection. A Lead may contact us at privacy@eventbdr.com to exercise rights in respect of data we hold; we will also direct the request to the relevant Client where the Client is the controller.
6. HOW WE SHARE PERSONAL DATA
We share personal data only as necessary and with appropriate safeguards, with:
- Clients — Lead Data captured for that Client, and relevant reporting.
- Representatives — the minimum brief and Assignment information needed to perform the Services.
- Service providers (processors) — hosting and database providers, payment processors (e.g. Stripe), communications providers (email/WhatsApp), and analytics providers, bound by data-processing terms.
- Professional advisers and authorities — where required by law, regulation, court order, or to protect our rights.
- Corporate transactions — a successor or acquirer in connection with a merger, acquisition or reorganisation.
We do not sell personal data.
7. INTERNATIONAL DATA TRANSFERS
7.1 We operate in the UAE and KSA and use service providers that may process data in other countries. Where we transfer personal data across borders, we apply safeguards required by applicable law.
7.2 UAE PDPL: transfers are made to jurisdictions with an adequate level of protection or under appropriate safeguards/contractual clauses, or on another permitted basis. KSA PDPL: transfers comply with the transfer conditions under the PDPL and its regulations. GDPR: transfers outside the EEA/UK rely on an adequacy decision or Standard Contractual Clauses (and, for the UK, the UK Addendum/IDTA) with supplementary measures as needed.
8. DATA RETENTION
8.1 We retain personal data only for as long as necessary for the purposes described, to comply with legal, tax and accounting obligations, and to establish, exercise or defend legal claims.
8.2 Indicatively: account data is kept for the life of the account and a reasonable period thereafter; transaction and payment records are kept for the period required by applicable law; Lead Data is retained as needed to deliver and support the Services and then deleted or anonymised. We may retain aggregated or anonymised data indefinitely.
8.3 You may delete your account at any time, from the Event BDR mobile app or at https://app.eventbdr.com/account/delete. Deleting an account permanently removes the information that identifies you: your name, email address, telephone number, photograph, biography, CV, work history, education, identity documents, bank details, and the notification registrations on your devices. Records of payments already made or received are retained, because we are required to keep them for tax and accounting purposes; they are disconnected from you, and your name is removed from them. Deletion signs you out on every device. You will not be able to sign in with that email address again, although the address itself is released and may be used to open a new account later.
8.4 Check-in coordinates and check-in photographs are retained with the Assignment record to which they relate, for as long as that record is needed to settle payment, resolve a dispute, and satisfy accounting obligations, after which they are deleted or anonymised. Identity and work-authorisation documents are removed when you delete your account, as described at clause 8.3. No audio is retained, because no audio is collected.
9. YOUR RIGHTS
Subject to applicable law, you may have the following rights over your personal data:
- to be informed about how we process your data;
- to access the data we hold about you;
- to rectify inaccurate or incomplete data;
- to request erasure / deletion (right to be forgotten) where applicable;
- to restrict or object to certain processing, including direct marketing;
- to data portability where applicable;
- to withdraw consent at any time where processing is based on consent; and
- to lodge a complaint with the competent supervisory authority.
9.1 How to exercise. Contact us at privacy@eventbdr.com. We will respond within the period required by applicable law. We may need to verify your identity. Where a Client is the controller of the relevant data (e.g. delivered Leads), we will refer or forward your request to that Client.
9.2 Supervisory authorities. UAE: the UAE Data Office. KSA: the Saudi Data & AI Authority (SDAIA). EU/UK: your local data protection authority or the UK ICO.
10. SECURITY
We implement appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, row-level access restrictions, and least-privilege practices. No system is completely secure; we cannot guarantee absolute security, and you are responsible for keeping your account credentials confidential.
11. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies and similar technologies to operate the Platform, remember preferences, provide security, and measure and improve performance. You can control cookies through your browser or, where provided, our cookie settings. Some cookies are strictly necessary for the Platform to function.
12. CHILDREN
The Platform is intended for business users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.
13. AUTOMATED DECISION-MAKING
We do not make decisions producing legal or similarly significant effects based solely on automated processing without appropriate safeguards. Where any such processing occurs, you may have the right to request human review.
14. CHANGES TO THIS POLICY
We may update this Policy from time to time. We will post the updated version with a revised “Last updated” date and, where required, notify you. Continued use of the Platform after an update constitutes acceptance of the updated Policy.
15. CONTACT US
For any privacy question or to exercise your rights, contact:
Dilogic Group L.L.C-FZ — Event BDR
Privacy: privacy@eventbdr.com General: support@eventbdr.com
Address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates