Eventleaf Security Guide
PCI Compliance
The Payment Card Industry (PCI) Data Security Standards (DSS) is a global information security standard designed to prevent fraud by protecting the way credit card data is processed and stored. Organizations that process credit card payments must follow PCI DSS standards.
Eventleaf is certified PCI DSS 3.2 compliant. The service is audited on a regular basis by SecurityMetrics, a PCI qualified auditor. In order to achieve PCI certification, Eventleaf maintains rigorous data security standards to ensure that its customer's credit card information remains safe and secure. Further information is available upon request.
ISO/IEC 27001
Eventleaf is currently in the process of obtaining ISO/IEC 27001 certification. Our information security management system (ISMS) is being implemented in accordance with ISO/IEC 27001 requirements to ensure continual improvement of our security controls and risk management practices.
EU-U.S. Data Privacy Framework and UK Extension Commitment
As part of its commitment to protecting personal privacy, Eventleaf complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, as set forth by the U.S. Department of Commerce. Jolly has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF as described in the site Privacy Policy. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
GDPR Compliance
In May 2018, the EU General Data Protection Regulation (GDPR) went into effect. This law requires that Eventleaf and event organizers using the service provide users with details of how their personal data will be processed.
How will Eventleaf use your personal data
Your personal data will be collected and processed by Eventleaf when:
- We have your consent
- It is necessary for use of the Eventleaf site and services
- We are required by law to provide it for legal or regulatory obligations
Transfer of personal data
Eventleaf is a global service provider and your data may be stored outside of the country where it was provided. If your personal data is ever transferred from one of our systems to another, we take steps to ensure that appropriate safeguards are in-place to protect your data. Your data is further protected by our participation in the EU-U.S. DPF, as described above.
Personal data retention
Your personal data is retained as long as necessary to provide you with the ability to use Eventleaf products and services as well as for other important purposes such as resolving transaction disputes and other legal obligations.
Typically your personal data can be deleted immediately, either by managing your account or upon request, barring any pending or recent transactions.
Eventleaf as a data controller
Eventleaf acts as a data controller, per the EU data protection laws, when someone creates an account on Eventleaf.com. For example, if you are organizing an event, Eventleaf will be a data controller in regards to your personal data.
Eventleaf as a data processor
Eventleaf acts as a data processor, per the EU data protection laws, in regards to the use and collection of personal data when someone registers for an event and to assist organizers in regards to administering events (e.g. sending invitation emails, reminders, surveys, payment processing, etc). Eventleaf does not control what personal data is collected during the registration process or entered by an organizer, nor does it manage the validity of the collected data.
If you have any questions regarding your personal data related to an event, please contact the event organizer as they are the data controller in this case.
Your rights
It is your right to request information on what personal data Eventleaf maintains about you as well as to correct or delete your personal data. For assistance, please contact us.
Hosting Environment
Eventleaf is hosted on Microsoft Azure, which maintains numerous industry-recognized security and compliance certifications. Additional information is available through the Microsoft Trust Center.
Security Audits and Vulnerability Testing
Eventleaf is scanned for security vulnerabilities on a quarterly basis by SecurityMetrics, a PCI-qualified and well-reputed independent security vendor. These scans assess our web infrastructure, applications, and systems for known vulnerabilities and misconfigurations. Findings are reviewed and remediated on a priority basis in accordance with industry-standard risk ratings. Results and remediation summaries are available to enterprise customers upon request under a confidentiality agreement.
Eventleaf also conducts periodic application security assessments and reviews remediation efforts to ensure identified vulnerabilities are addressed according to their severity.
Secure Software Development
Security is integrated throughout Eventleaf's software development lifecycle. Source code changes are managed through Azure DevOps and undergo multiple peer code reviews, followed by testing by multiple peers, before progressing to quality assurance testing.
Development, testing, staging, and production environments are logically separated. Deployments are performed through controlled CI/CD pipelines requiring approval before release, and production deployment is further restricted through additional authorization controls. Software dependencies are regularly reviewed for known vulnerabilities, and security updates are applied as part of our ongoing maintenance process.
Access Control and Privileged Access Management
Eventleaf maintains a tiered, role-based access control system for all internal staff. Access to customer data is granted strictly on a need-to-know basis, with different levels of administrative access assigned to support staff based on their specific job responsibilities. No employee is granted broader access than is required to perform their role.
All staff accounts with access to customer data are protected by multi-factor authentication (MFA). Upon an employee's termination or role change, access to all systems containing customer data is revoked immediately. Eventleaf maintains documented procedures to ensure prompt deactivation with no gaps in enforcement.
Access to development resources, deployment pipelines, and production environments is granted according to job responsibilities using the principle of least privilege.
Access permissions are reviewed periodically to ensure employees retain only the minimum level of access necessary to perform their responsibilities.
Data Protection
Passwords are stored using industry-standard one-way cryptographic hashing with unique salts. Sensitive customer data requiring encryption is protected using AES-256 encryption while stored. Data is maintained in Microsoft Azure and all data communications are encrypted in transit using TLS 1.2 and TLS 1.3.
Encryption Key Management
Encryption keys are securely managed and protected in Microsoft Azure Key Vault using industry best practices. Access to encryption keys is restricted to authorized systems and personnel, and key management procedures include regular rotation where appropriate.
Data Breach Detection and Notification
Eventleaf has implemented automated monitoring systems that detect suspicious activity on customer accounts in real time. Upon detection of suspicious activity, the affected customer account is automatically suspended to prevent further unauthorized access, and both the customer and Eventleaf's support team are immediately notified.
In the event of a confirmed or reasonably suspected data breach, Eventleaf will notify affected customers without undue delay and no later than 24 hours after becoming aware of the incident. Notifications will include a description of the suspected or confirmed breach, the data potentially affected, and the steps Eventleaf has taken or is taking to investigate and remediate the issue.
Data Deletion and Customer Control
Customers can delete most of their data, including personal information and event records, directly through the Eventleaf platform. To request complete removal of their data from Eventleaf systems, customers must contact Eventleaf. Eventleaf may retain limited non-personal records for transaction history, data integrity, or legal compliance purposes, with all personally identifiable information removed or masked.
Artificial Intelligence and Data Use Policy
Eventleaf does not use any artificial intelligence or machine learning tools in the operation of its platform. Customer data - including any anonymized, aggregated, or derived forms of such data - is never used to train, develop, test, or improve any AI or machine learning models, whether operated by Eventleaf or any third party. Customer data is used solely for the purpose of providing and maintaining the services contracted by the customer.
Privacy
We have a strict policy to respect the privacy of customer information. We will not disclose your information to third parties without your express permission. For more information, please refer to our Privacy Policy.
If you have any questions or would like more information, please contact us.