Privacy Policy
Effective Date: August 29, 2026
Last Updated: August 29, 2026
1. Introduction and Scope
Welcome to BSides Singapore Security Conference (“the Conference”). We are committed to protecting your personal data in accordance with the Personal Data Protection Act 2012 (including its 2020/2021 amendments) of Singapore and other applicable data protection laws.
This Privacy Policy outlines how we collect, use, disclose, and process your personal data across all touchpoints, including:
- Our official website (hosted via GitHub Pages and protected by Cloudflare)
- Ticketing and registration platforms (such as RSVPify)
- Speaker submission platforms (such as
cfp.directory) - On-site event check-in, badge printing services, and physical venue access control
- On-site photography, media capture, and post-event analytics
By registering for, attending, or interacting with the Conference and its digital infrastructure, you consent to the data practices described in this Privacy Policy.
2. Personal Data We Collect
We limit the collection of personal data to what is strictly necessary for organizing, securing, and managing the event. Depending on your interaction with us, we may collect the following categories of information:
- Identity & Demographic Data: Full name, gender, and age range (collected during ticketing and registration).
- Contact Details: Business, personal, or educational email addresses.
- Professional Information: Occupation, job title, and professional or educational affiliations (also collected via
cfp.directoryfor accepted speakers). - Operational Preferences: Dietary requirements (collected solely for the purpose of managing catering safety and logistics).
- On-Site & Technical Data:
- Physical check-in timestamps and badge access logs used for venue security and capacity management.
- Technical telemetry, IP addresses, and routing data processed via Cloudflare and GitHub Pages for Layer 7 security and DDoS mitigation.
- Event photographs and video recordings (which may include clear headshots or ambient/blurred crowd captures).
3. Purposes for Collection, Use, and Disclosure
In compliance with the PDPA, we collect, use, and disclose your personal data strictly for the following operational purposes:
- Ticketing & Access Control: Processing ticket registrations via RSVPify, issuing digital confirmations, printing physical badges via our on-site vendor, and verifying identity for venue entry and security.
- Event Logistics & Safety: Managing dietary requirements with catering providers and scheduling speaker sessions.
- Communications: Sending essential administrative notices, schedule updates, logistical instructions, and post-event feedback requests.
- Media & Publicity: Capturing event photography and videography for post-event highlights, archives, press releases, and promotional materials for future editions of the Conference. (Note: Clear on-site signage will indicate areas where photography is active).
- Sponsor Interaction Disclaimer: Sponsors operating at the event are independent entities. We do not cross-pass or transfer your registration database to sponsors. If you choose to share your contact details directly with a sponsor on-site (e.g., via independent badge scans at booths or business card drops), that interaction is governed entirely by the respective sponsor’s privacy policy and independent consent framework.
4. Data Intermediaries and Third-Party Services
To facilitate the Conference, we engage trusted third-party service providers and technology platforms who act as data intermediaries. These include:
- GitHub Pages & Cloudflare Personal: For static website hosting, edge security, and Layer 7 DDoS mitigation.
- RSVPify: For ticket sales, registration management, and attendee data processing.
cfp.directory: For managing speaker submissions and proposal reviews.- On-Site Check-In Vendors: Temporary data processing services strictly localized for badge printing and queue management during event days.
Where your data is transferred, hosted, or processed outside of Singapore by our global infrastructure providers, we ensure that appropriate safeguards are in place to provide a standard of protection comparable to the PDPA.
5. Data Retention and Anonymization Schedule
- Active Retention Period: All identifiable personal attendee and speaker data will be securely stored for no longer than necessary to fulfill the purposes outlined above, and in any event, will be fully purged or permanently deleted within one (1) year following the conclusion of the Conference.
- Transition to Anonymized Metrics: Following the one-year purge of identifiable records, retained data will be permanently anonymized. Fully aggregated, non-identifiable statistical metrics (such as total attendance counts, generalized age-range distributions, and aggregate occupation percentages) may be kept to plan, scale, and budget requirements for future conference editions.
6. Your Rights Under the PDPA
Under the Singapore PDPA, you possess certain rights regarding your personal data:
- Access & Correction: You have the right to request access to a copy of the personal data we hold about you and to request corrections if any information is inaccurate or incomplete.
- Withdrawal of Consent: You may withdraw your consent for the collection, use, or disclosure of your personal data at any time by submitting a written request to our Data Protection Officer (DPO). Please note that withdrawing consent for essential data (such as identity or ticketing information) may impact your ability to attend or access the event.
7. Data Protection Officer (DPO) Contact
If you have any questions, feedback, or formal requests regarding this Privacy Policy, your personal data, or our compliance with the PDPA, please contact our designated Data Protection Officer:
- Email: info@bsidessg.org