Privacy Policy
Last updated: October 4, 2026
This describes how Edantis actually behaves today, written to be accurate rather than generic. It hasn't been reviewed by a lawyer or a data protection specialist, and shouldn't be treated as a final policy until it has.
1. Who's responsible for what
Edantis is operated by Vazantis Oy, registered in Finland (00840 Helsinki, Finland), business ID 3636621-5. Under GDPR, our role depends on whose data it is:
- For organizer account data (your own name, email, and billing details as the person running an event on Edantis), we are the data controller. This policy describes our own handling of that data directly.
- For conference participant data (the name, email, affiliation, and submission or registration details of your submitters, attendees, and reviewers), the organizer is the data controller and Edantis is the data processor, acting only on the organizer's instructions (through the features they choose to turn on). If you submitted to, registered for, or reviewed for a conference, the organizer of that specific event is who controls your data and who you should contact first about it.
2. What we collect
From organizers: name, email, password (stored as a salted hash, never in plain text), and billing information for license and add-on purchases.
From conference participants, collected on the organizer's behalf when someone submits an abstract, registers for a conference, or is invited as a reviewer: name, email, affiliation, the content of their submission or review, and, for paid registrations, the amount paid and a payment reference. We don't receive or store full card numbers; those are handled directly by our payment processor.
Automatically: standard server logs (IP address, timestamps, request metadata) kept briefly for security and debugging.
3. Why we process it, and on what basis
- To provide the service you or your organizer signed up for: performance of a contract.
- To process payments and comply with financial record-keeping obligations: contract and legal obligation.
- To keep the platform secure and prevent abuse: legitimate interest.
- To power optional AI features an organizer has chosen to enable: performance of that organizer's contract with their own participants, at the organizer's instruction.
We don't use participant or organizer data for advertising, and we don't sell personal data.
4. AI-assisted features
An organizer can optionally turn on AI features: reviewer-matching suggestions, AI-drafted schedules, automatic clustering of related abstracts, submission screening, and a public question-answering widget for attendees. When enabled, the relevant text (an abstract, a scheduling constraint, or a question an attendee types in) is sent to a third-party AI provider to generate a response. It is not used by that provider to train their models beyond standard API terms, and the widget is deliberately limited to a conference's own public program information. It doesn't have access to private reviewer identities, review scores, or a submitter's contact details.
For reviewer-matching, clustering, screening, and room assignment, an organizer with AI available chooses, per conference, between the standard third-party provider and an alternative processing option hosted in the EU. This choice is mandatory before those features run for a given conference (it's never applied silently), and submitters and attendees are shown which option is in use and asked to consent before their content is processed either way. Once a submitter, attendee, or reviewer has been added to a conference under the EU-hosted option, that conference can't be switched back to the standard provider, since doing so would go against what those people were told and agreed to.
Whether to enable AI at all, and which of these options to use, is the organizer's own decision. We don't choose it for them, and they're responsible for having a proper basis to have their conference's content processed the way they've chosen.
5. Who else processes your data
We use a small number of subprocessors to run Edantis. We don't add a new one without updating this list:
- Supabase: database, authentication, and file storage.
- Stripe: payment processing for license purchases and attendee ticket payments, and identity verification for organizers who want to receive payouts.
- OpenAI: powers the optional AI features described above, when an organizer enables them.
- RunPod: optional EU-hosted alternative for AI reviewer-matching, clustering, screening, and room assignment, when an organizer chooses it for a conference.
- Vercel: application hosting and content delivery.
- Resend: delivery of transactional email (account, submission, registration, and reviewer emails).
- Sentry: error monitoring, so we can detect and fix bugs. It receives technical error data (stack traces, request metadata), not the content of your submissions or conference.
6. International transfers
Our database, file storage, and application hosting (Supabase and Vercel) are configured to run in the EU, so that data doesn't leave the EEA in the ordinary course of running Edantis. Some of our other subprocessors (for example OpenAI, Stripe, Resend, and Sentry) may process data outside the EEA as part of their own infrastructure. Where that happens, we rely on the safeguards recognized under GDPR for that transfer, typically Standard Contractual Clauses, through that subprocessor's own data processing agreement.
7. Data retention
We draw a line between the content of an event and the personal contact details collected to run it:
- Event content (submission titles, abstracts, author names, session schedules, accepted programs, and reviews) is kept indefinitely. This is the public record an organizer is publishing on purpose (a lasting Book of Abstracts, schedule, and conference page), not personal data that needs limiting on its own.
- Direct contact information, meaning a submitter's, attendee's, or reviewer's name, email, affiliation (or areas of expertise, for reviewers), and the private link used to manage a submission, registration, or review, is automatically deleted 2 years after the conference's end date. The event record itself remains; the personal details tied to it don't.
- Payment records (amounts and payment-processor transaction references) are kept as part of the organizer's own financial and tax records and follow standard financial record-keeping periods rather than the 2-year window above.
- Organizer account data is kept for as long as the account is active, and deleted or anonymized within a reasonable period after account closure, except where we're legally required to keep financial records longer.
8. Cookies
Edantis uses one strictly-necessary cookie to keep you signed in and your session secure. We don't currently use advertising or analytics cookies, and this policy will be updated if that changes. Because we only use strictly-necessary cookies, we don't show a cookie-consent banner.
9. Your rights
If you're in the EEA, UK, or a jurisdiction with similar protections, you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. If your data was collected as part of someone else's conference (as a submitter, attendee, or reviewer), please contact the organizer of that event first. They control the data and can action most requests directly, including early deletion ahead of the standard 2-year window. If you're an organizer, or the organizer can't help, contact us directly (details below). You also have the right to lodge a complaint with your local data protection authority. In Finland, the Office of the Data Protection Ombudsman.
10. Security
We use industry-standard measures to protect personal data, including encryption in transit, access controls limiting who can reach production data, and hashed password storage. No system is perfectly secure, and we can't guarantee absolute security, but we treat data protection as an ongoing responsibility, not a one-time checkbox.
11. Children
Edantis isn't directed at children, and organizer accounts require the account holder to be at least 18. We don't knowingly collect personal data from children through the platform.
12. Changes to this policy
We may update this policy as the product changes. If a change is material, we'll make reasonable efforts to let organizers know, and we'll always keep the current version here with an updated date at the top.
13. Contact
For platform-level questions, or if you're an organizer with a question about your own account data, reach us through the contact page or privacy@vazantis.com. If your question is about data collected through a specific conference, please contact that conference's organizer first.