← Back to the feedback form

Privacy Policy & Data Collection

Event Renaissance Feedback

Effective Date: February 6, 2026

Last Updated: September 30, 2026


Overview

Event Renaissance Feedback is designed with privacy as a core principle. The feedback form does not ask for and does not store any attendee identity: no name, no email, no account, no cookie tying a submission back to a person. It does record the submitter's IP address and browser user agent string with every submission, for abuse protection -- see below for why and how that is used.


Data Collection Summary

✅ What We Collect

The feedback form collects the following data, per submission:

Data FieldTypePurposeRequired
Event CodeTextLinks feedback to the conference eventYes
SessionTextIdentifies which session the feedback is forYes
Were the stated learning objectives met?Rating (1-5)CPE program evaluation criterionYes
Were the stated prerequisite requirements appropriate and sufficient?Rating (1-5)CPE program evaluation criterionYes
Was the time allotted to the learning activity appropriate?Rating (1-5)CPE program evaluation criterionYes
Was the presenter effective?Rating (1-5)CPE program evaluation criterionYes
Were program materials ... relevant, and did they contribute to the achievement of the learning objectives?Rating (1-5)CPE program evaluation criterionYes
Additional CommentsText (max 1000 chars)Captures qualitative feedbackNo
Submission TimestampDateTimeRecords when feedback was submittedAuto
IP AddressTextAbuse/spam protection (rate limiting)Auto
User Agent StringTextAbuse/spam protection (bot/script detection)Auto

The five rating questions and the free-text comment above are the current (v1) question set, wired up in database-seed-v3.sql and served by GET /api/questions; wording matches the NASBA Statement on Standards for CPE Programs evaluation criteria. An earlier version of this document described a different set of fields (Module ID, Speaker Knowledge, Content Depth, Module Satisfaction) from a prior release -- those fields no longer exist in the schema or the form.

Why IP address and user agent are recorded

POST /api/feedback is a public, unauthenticated endpoint that accepts public URLs derived from a session's QR code, and organizers announce sessions to rooms of hundreds of attendees sharing the venue's network. The IP address and user agent are recorded solely to rate-limit and detect scripted or abusive submission patterns; they are not linked to any attendee identity, not displayed alongside feedback in the admin UI's normal reporting views, and not used for tracking, profiling, marketing, or any purpose beyond abuse protection.

❌ What We DO NOT Collect

The feedback form does not collect:

Live counter — organizer view

The live counter screen (count.html) is an organizer-facing display. It shows aggregate feedback counts and a QR code that points submitters to the feedback form. The live counter:


How Data is Used

Primary Purpose

Feedback data is used exclusively to:

  1. Improve Session Quality - Identify strengths and areas for improvement in session content and delivery
  2. Evaluate Speaker Performance - Provide constructive feedback to speakers
  3. Optimize Content Depth - Ensure technical level matches audience needs
  4. Aggregate Analytics - Generate statistical insights on conference programme effectiveness

Data Access

Data Sharing


Data Retention

Data TypeRetention PeriodDeletion Policy
Active Event FeedbackDuration of the event + 2 yearsRetained for programme improvement
Archived FeedbackUp to 5 yearsRetained for historical analysis
Deleted FeedbackImmediatePermanently removed from database

User Rights:


Technical Security

Data Protection Measures

  1. Encryption in Transit
  1. Encryption at Rest
  1. Access Control
  1. Database Security

Anonymous Feedback Guidelines

For Feedback Providers

Please DO:

Please DO NOT:

Note: The form itself does not ask for attendee identity, but the free-text comment field is unmoderated -- users are responsible for not voluntarily including their own or others' personal information there.


Compliance

Regulatory Alignment

This application is designed to comply with:

Data Classification

All collected feedback is classified as:


User Rights

Feedback carries no attendee identity, so an individual submission cannot be traced back to a specific person by anything the form collects:

Event-Level Deletion:


Changes to This Policy

We reserve the right to update this privacy policy. Changes will be:

Version History:


Contact Information

For questions about this privacy policy or data practices:

This feedback application is operated by Event Renaissance, which is responsible for the data described above. If you have a question about this policy, or about feedback you submitted, contact Event Renaissance through the organisers of the event you attended.


Transparency Commitment

This document describes exactly what the feedback form collects, what it does not collect, and why -- including the IP address and user agent recorded for abuse protection, which are the only two values that are not supplied deliberately by the person submitting.

The source code for this application is not public. Where this policy makes a factual claim about what the software does, that claim is maintained against the code by the people who operate it; the sections above are written to be specific enough to hold the operator to it.


Summary


This privacy policy is part of the Event Renaissance Feedback documentation.