Privacy Policy & Data Collection
Event Renaissance Feedback
Effective Date: February 6, 2026
Last Updated: September 30, 2026
Overview
Event Renaissance Feedback is designed with privacy as a core principle. The feedback form does not ask for and does not store any attendee identity: no name, no email, no account, no cookie tying a submission back to a person. It does record the submitter's IP address and browser user agent string with every submission, for abuse protection -- see below for why and how that is used.
Data Collection Summary
✅ What We Collect
The feedback form collects the following data, per submission:
| Data Field | Type | Purpose | Required |
|---|---|---|---|
| Event Code | Text | Links feedback to the conference event | Yes |
| Session | Text | Identifies which session the feedback is for | Yes |
| Were the stated learning objectives met? | Rating (1-5) | CPE program evaluation criterion | Yes |
| Were the stated prerequisite requirements appropriate and sufficient? | Rating (1-5) | CPE program evaluation criterion | Yes |
| Was the time allotted to the learning activity appropriate? | Rating (1-5) | CPE program evaluation criterion | Yes |
| Was the presenter effective? | Rating (1-5) | CPE program evaluation criterion | Yes |
| Were program materials ... relevant, and did they contribute to the achievement of the learning objectives? | Rating (1-5) | CPE program evaluation criterion | Yes |
| Additional Comments | Text (max 1000 chars) | Captures qualitative feedback | No |
| Submission Timestamp | DateTime | Records when feedback was submitted | Auto |
| IP Address | Text | Abuse/spam protection (rate limiting) | Auto |
| User Agent String | Text | Abuse/spam protection (bot/script detection) | Auto |
The five rating questions and the free-text comment above are the current (v1) question set, wired up in database-seed-v3.sql and served by GET /api/questions; wording matches the NASBA Statement on Standards for CPE Programs evaluation criteria. An earlier version of this document described a different set of fields (Module ID, Speaker Knowledge, Content Depth, Module Satisfaction) from a prior release -- those fields no longer exist in the schema or the form.
Why IP address and user agent are recorded
POST /api/feedback is a public, unauthenticated endpoint that accepts public URLs derived from a session's QR code, and organizers announce sessions to rooms of hundreds of attendees sharing the venue's network. The IP address and user agent are recorded solely to rate-limit and detect scripted or abusive submission patterns; they are not linked to any attendee identity, not displayed alongside feedback in the admin UI's normal reporting views, and not used for tracking, profiling, marketing, or any purpose beyond abuse protection.
❌ What We DO NOT Collect
The feedback form does not collect:
- ❌ Names
- ❌ Email addresses
- ❌ Phone numbers
- ❌ Device identifiers (beyond the user agent string noted above)
- ❌ Browser fingerprints
- ❌ Geographic location
- ❌ Any cookies (zero
document.cookieusage anywhere in the codebase) - ❌ Any account, login, or other identity linking a submission to an attendee
Live counter — organizer view
The live counter screen (count.html) is an organizer-facing display. It shows aggregate feedback counts and a QR code that points submitters to the feedback form. The live counter:
- Does not collect any data about the organizer or any submitter
- Does not use cookies of any kind (zero
document.cookieusage anywhere in the codebase) - Stores user-display preferences (theme, sound on/off, refresh interval, celebration level) in browser
sessionStorageonly — these are erased when the browser session ends and never sent to a server - Includes a session switcher that lets the organizer change which session is displayed without reloading the page; this affects display only and does not introduce any new data collection or persistence
How Data is Used
Primary Purpose
Feedback data is used exclusively to:
- Improve Session Quality - Identify strengths and areas for improvement in session content and delivery
- Evaluate Speaker Performance - Provide constructive feedback to speakers
- Optimize Content Depth - Ensure technical level matches audience needs
- Aggregate Analytics - Generate statistical insights on conference programme effectiveness
Data Access
- Administrators - Authorized event organizers and administrators can view aggregated and individual feedback
- Speakers - May receive anonymized feedback summaries relevant to their sessions
- Analysts - Statistical reports may be generated for program evaluation
Data Sharing
- Feedback data is not sold to third parties
- Feedback data is not shared outside Event Renaissance and the organizers of the event it was collected for
- Aggregate statistics (with no identifying information) may be included in reports
Data Retention
| Data Type | Retention Period | Deletion Policy |
|---|---|---|
| Active Event Feedback | Duration of the event + 2 years | Retained for programme improvement |
| Archived Feedback | Up to 5 years | Retained for historical analysis |
| Deleted Feedback | Immediate | Permanently removed from database |
User Rights:
- Feedback is anonymous, so individual deletion requests cannot be processed
- Event organizers can delete all feedback associated with an event
- Bulk deletion capabilities are available to administrators
Technical Security
Data Protection Measures
- Encryption in Transit
- All data transmitted via HTTPS/TLS encryption
- Secure connections between frontend and backend
- Encryption at Rest
- Azure SQL Database with encryption enabled
- Secure storage of all feedback data
- Access Control
- Admin panel requires authentication
- Role-based access control (RBAC)
- Session management with expiration
- Database Security
- Parameterized queries (SQL injection prevention)
- Azure SQL firewall rules
- Regular automated backups
Anonymous Feedback Guidelines
For Feedback Providers
Please DO:
- ✅ Provide honest, constructive feedback
- ✅ Comment on content quality and delivery
- ✅ Suggest improvements
Please DO NOT:
- ❌ Include your name or contact information
- ❌ Include names of other attendees
- ❌ Include sensitive or confidential information
- ❌ Include any personally identifiable information
Note: The form itself does not ask for attendee identity, but the free-text comment field is unmoderated -- users are responsible for not voluntarily including their own or others' personal information there.
Compliance
Regulatory Alignment
This application is designed to comply with:
- GDPR (General Data Protection Regulation) - Anonymous data collection
- CCPA (California Consumer Privacy Act) - No personal information collected
- FERPA (if applicable to educational contexts) - No student records
- Internal Privacy Policies - Organization-specific requirements
Data Classification
All collected feedback is classified as:
- Public or Internal Use Only - No confidential or sensitive data
- Non-Personal Data - Cannot be used to identify individuals
- Aggregate Statistical Data - When used in reports
User Rights
Feedback carries no attendee identity, so an individual submission cannot be traced back to a specific person by anything the form collects:
- Right to Access - Not applicable to feedback content (no attendee identity is collected); the IP address and user agent recorded for abuse protection are not attendee-identifying on their own
- Right to Deletion - Feedback is not linked to an identity, so a per-person deletion request cannot be fulfilled; event organizers can delete all feedback for an event
- Right to Correction - Not applicable (no personal profile is stored)
- Right to Portability - Not applicable (no personal profile is stored)
Event-Level Deletion:
- Event organizers can delete all feedback for specific events
- Bulk deletion available through admin panel
Changes to This Policy
We reserve the right to update this privacy policy. Changes will be:
- Documented with effective dates
- Communicated to users through the application
- Posted in the repository and documentation
Version History:
- v1.0 (Feb 6, 2026) - Initial privacy policy, PII collection removed
Contact Information
For questions about this privacy policy or data practices:
This feedback application is operated by Event Renaissance, which is responsible for the data described above. If you have a question about this policy, or about feedback you submitted, contact Event Renaissance through the organisers of the event you attended.
Transparency Commitment
This document describes exactly what the feedback form collects, what it does not collect, and why -- including the IP address and user agent recorded for abuse protection, which are the only two values that are not supplied deliberately by the person submitting.
The source code for this application is not public. Where this policy makes a factual claim about what the software does, that claim is maintained against the code by the people who operate it; the sections above are written to be specific enough to hold the operator to it.
Summary
- 🔒 No identity requested: No name, email, account or cookie
- 📊 Answers are not linked to you: Feedback is stored without attendee identity
- 🛡️ IP and browser recorded for abuse protection only: Never shown beside your answers, never used to identify you
- 🔐 Secure storage: Encrypted in transit and at rest
- ✅ Aligned with GDPR and CCPA principles
This privacy policy is part of the Event Renaissance Feedback documentation.
