PlanEvents
ENFRNL
Last updated: 8 September 2026

Privacy Policy

1. Scope and legal framework

This Privacy Policy explains how PlanEvents collects, uses, stores, discloses and otherwise processes personal data in connection with the PlanEvents website, application, marketplace, professional portal and related services available through planevents.eu.

PlanEvents is a commercial name operated by BrandLabel Agency, an independent business established at Rue de la Marjolaine, 1120 Brussels, Belgium, registered for VAT under number BE1040366570. For the purposes of Regulation (EU) 2016/679 of 27 April 2016, commonly referred to as the General Data Protection Regulation or “GDPR”, BrandLabel Agency acts as the controller of the personal data described in this Privacy Policy.

The processing of personal data by PlanEvents is governed principally by Regulation (EU) 2016/679, including in particular the principles set out in Article 5, the lawfulness requirements in Article 6, the transparency obligations in Articles 12 to 14, the rights of data subjects in Articles 15 to 22, the requirements relating to data protection by design and by default in Article 25, processor arrangements under Article 28, security obligations under Article 32, personal data breach obligations under Articles 33 and 34, and the rules on international transfers contained in Chapter V of the GDPR. The processing is also subject to the Belgian Law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data and any other applicable Belgian or European data protection legislation. (EUR-Lex)

This Privacy Policy applies to clients who create event requests, professionals who register to access marketplace opportunities, persons acting on behalf of businesses, visitors to the Platform, persons contacting PlanEvents, and any other identifiable natural person whose personal data is processed through the Platform.

This Privacy Policy does not replace the PlanEvents Terms and Conditions, Professional or Marketplace Terms, Cookie Policy or Refund Policy. Those documents regulate separate aspects of the contractual and technical relationship with PlanEvents.

2. Controller and contact details

The data controller is:

BrandLabel Agency PlanEvents Rue de la Marjolaine 1120 Brussels Belgium VAT: BE1040366570 Email: support@planevents.eu

PlanEvents has not appointed a Data Protection Officer. Requests concerning privacy, personal data or the exercise of rights under the GDPR may be sent to the email address above.

3. Definitions

For the purposes of this Privacy Policy, “personal data” has the meaning given in Article 4(1) GDPR and means any information relating to an identified or identifiable natural person.

“Processing” has the meaning given in Article 4(2) GDPR and includes any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, anonymisation and deletion.

“Client” means a registered user who creates or manages an event request through PlanEvents.

“Professional” means a registered professional user whose business profile has been submitted for verification and who may, once approved, access marketplace opportunities corresponding to the services and geographic coverage declared in that professional profile.

“Event request” means information submitted by a Client concerning an event for which the Client wishes to identify or contact relevant professionals.

“Lead” or “opportunity” means an event request made available, subject to applicable matching conditions, to one or more approved Professionals.

“Processor” means a natural or legal person that processes personal data on behalf of PlanEvents within the meaning of Article 4(8) GDPR.

“Recipient” means a natural or legal person to whom personal data is disclosed within the meaning of Article 4(9) GDPR.

4. Data protection principles

PlanEvents processes personal data in accordance with Article 5 GDPR.

Personal data must be processed lawfully, fairly and transparently. It must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes. Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. It must be accurate and, where necessary, kept up to date. Personal data must not be retained in identifiable form for longer than necessary for the relevant purposes, subject to applicable legal retention duties. It must also be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.

PlanEvents applies the principles of data protection by design and by default under Article 25 GDPR by restricting access to marketplace information, redacting pre-purchase event data, limiting disclosure to eligible Professionals, using role-based access controls, applying private storage and signed access links to sensitive evidence, maintaining retention rules and applying deletion or anonymisation procedures where appropriate. (EUR-Lex)

5. Legal bases for processing

PlanEvents does not rely on a single legal basis for all processing. The applicable legal basis depends on the purpose and context of the processing.

Where processing is necessary to create and maintain a user account, provide the Platform, process an event request, operate the marketplace, provide a purchased lead, administer a professional profile, process a quality claim or otherwise perform services requested by the user, processing is generally based on Article 6(1)(b) GDPR because it is necessary for the performance of a contract or to take steps at the data subject’s request before entering into a contract.

Where processing is required to comply with Belgian or European tax, VAT, accounting, anti-fraud, regulatory or other statutory obligations, PlanEvents relies on Article 6(1)(c) GDPR.

Where processing is necessary for the legitimate interests of PlanEvents or another party, including platform security, prevention of fraud and abuse, maintenance of audit records, prevention of duplicate or fraudulent requests, defence of legal claims, verification of professional eligibility, investigation of quality claims, moderation and protection of the marketplace, PlanEvents may rely on Article 6(1)(f) GDPR, provided that those interests are not overridden by the interests or fundamental rights and freedoms of the data subject.

Where PlanEvents relies on consent, including optional direct marketing communications or future non-essential tracking technologies where applicable, the legal basis is Article 6(1)(a) GDPR. Consent is not treated as a condition for processing that is objectively necessary to provide the core PlanEvents service. Where consent is relied upon, it may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal in accordance with Article 7 GDPR. (EUR-Lex)

6. Client account data

Clients must create an account before submitting an event request.

During registration and account use, PlanEvents may process information including the Client’s full name, email address, password credentials in protected form, confirmation of the applicable age requirement, acceptance of applicable terms and privacy notices, marketing preference, language preference, registration timestamps, account status and related authentication information.

Passwords are processed through the authentication infrastructure used by PlanEvents and are not made available to Professionals.

PlanEvents may also receive authentication and security metadata from its authentication provider, including login timestamps, authentication events, IP addresses, User-Agent or browser information and related request metadata.

This information is processed for account creation, authentication, security, fraud prevention, account administration and provision of the Service.

7. Event request data

When a Client submits an event request, PlanEvents may process the Client’s name, email address, telephone number, company or organisation name where relevant, event type, whether the event is private or professional, event date or date range, flexible-date status, event start and end time, city, region, postcode, country, expected guest-number range, preferred contact languages, preferred contact method, selected service categories and subcategories, event description, request title, request confirmation number, submission language, creation and update timestamps and request status.

PlanEvents may also process geographic data derived from or associated with the submitted event location for matching and marketplace functionality. Stored latitude and longitude coordinates are not disclosed to Professionals through the ordinary marketplace lead-unlock process.

Clients should not include unnecessary personal data, contact information, medical information, religious information or other sensitive personal information in free-text event descriptions, service answers or additional-requirement fields.

PlanEvents applies technical warnings to free-text fields and automated filtering to reduce the risk that direct contact information or unnecessary identifying information is disclosed before a lead is purchased. This filtering does not provide an absolute guarantee that contextual information contained in free text cannot identify the Client, the event, a venue, an organisation or another person.

8. Disclosure of event requests to Professionals

PlanEvents operates a marketplace in which approved Professionals may obtain access to event opportunities relevant to the services they provide.

Before a lead is purchased, only an approved Professional whose declared services and geographic coverage satisfy the applicable marketplace eligibility rules may access the relevant preview.

The pre-purchase preview may contain whether the event is private or professional, event type, fixed date, date range or flexible-date status, city and region, expected guest-number range, preferred contact languages, matching service subcategories, the event start and end time and the event description.

The Client’s full name, company or organisation name, email address, telephone number, postcode, preferred contact method and stored geographic coordinates are not displayed as structured fields in the pre-purchase preview.

PlanEvents also applies automated filtering to free-text information in an attempt to remove email addresses, website addresses, phone-number-like strings, the contact’s full name, company or organisation name and postcode. Automated filtering cannot guarantee that all identifying information will be removed. An unusual venue, contextual description, social-media identifier or other information may still allow a person or event to be identified.

Following a successful purchase of a lead, the purchasing Professional receives the information required to contact the Client and assess the relevant opportunity. This may include the Client’s full name, company or organisation name where provided, email address, telephone number, preferred contact method, preferred contact languages, postcode and country, together with city and region, the complete unredacted event description, the complete relevant service-question answers, complete relevant additional requirements, request title, confirmation number, submission language and current request status.

A Professional does not obtain access through a lead purchase to the Client’s password, authentication credentials, marketing preferences, internal account user identifier or stored latitude and longitude coordinates.

Service matching is disclosed only for subcategories offered by the Professional. Purchasing a lead does not grant access for unrelated professional categories.

A Client’s event request may be made available to multiple eligible Professionals. Up to five verified Professionals per requested service may receive the relevant event and contact information where they purchase access. Each service closes independently at capacity or when the Client stops new Professionals; completed purchases retain access under the marketplace rules.

Before submission, Clients are presented with a marketplace disclosure explaining the difference between the redacted preview and the information disclosed after a Professional purchases access. Submission requires acknowledgement that eligible Professionals may receive the relevant event information and contact the Client.

The version of the Privacy Notice and marketplace disclosure acknowledged by the Client, together with the relevant timestamp, is recorded for accountability and evidential purposes.

9. Automated rules-based marketplace matching

PlanEvents uses automated, rules-based filtering to determine which approved Professionals are eligible to see, receive notifications about and purchase a particular event opportunity.

The matching process may take into account the service categories selected by the Professional, the services requested by the Client, the event’s Belgian region, the Professional’s selected covered regions, the Professional’s business base, the Professional’s declared travel radius, the geographic relationship between the event location and the professional’s business location, whether the request is active and unexpired, whether unlock capacity remains available and whether the Professional is attempting to access their own request.

Marketplace matching requires service-category eligibility, selected Belgian region eligibility and applicable travel-radius eligibility. Missing location coordinates are not used to broaden marketplace access.

The matching mechanism is deterministic and rules-based. It does not currently use artificial intelligence, behavioural profiling, predictive scoring or a compatibility score to determine which Professional should obtain a contract.

The system does not evaluate a Professional’s expected quality, likelihood of conversion, reliability, price competitiveness or personal characteristics, and it does not select a winning Professional. Matching Professionals decide independently whether to purchase the opportunity. The Client remains free to contact, accept, reject or contract with any Professional.

PlanEvents does not currently regard this matching process as constituting a decision based solely on automated processing that produces legal effects or similarly significantly affects a natural person within the meaning of Article 22 GDPR. This assessment may be reviewed if the Platform later introduces automated scoring, ranking, recommendation, risk classification, automated suspension or other processing capable of producing such effects.

A Professional who believes that their marketplace eligibility has been determined incorrectly may contact PlanEvents for review.

10. Professional registration and business verification

Professionals must register and undergo verification before obtaining marketplace access.

At registration, PlanEvents may process the Professional’s full name, email address, password credentials in protected form, confirmation that the user is at least eighteen years of age, confirmation that the user is authorised to represent the relevant business, acceptance of applicable Terms and Privacy Notice and optional marketing consent.

After email verification, the Professional may be required to provide a legal business name, optional trading name, contact person, business role, telephone number, optional website, registered Belgian address, Belgian VAT number, services offered, additional service descriptions where applicable, regulatory or authorisation numbers where required for specific services, business base, travel radius, Belgian regions covered, optional company introduction and a declaration concerning accuracy and legal compliance.

Belgian Professional VAT and business information is checked against BCE/KBO data. VIES may be used for VAT numbers from other European Union countries where applicable. Information may also be subject to manual administrator verification.

Professional verification information is processed to determine marketplace eligibility, protect Clients and other Professionals, prevent impersonation and fraud, comply with applicable commercial requirements and maintain the integrity of the Platform.

11. Payments and Stripe

Lead purchases are processed using Stripe.

PlanEvents may process and retain payment and transaction information including the Professional and Event Request identifiers, billing status and monthly limit, currency and amounts, billing identity and address, saved-card brand, last four digits and expiry, Stripe Customer, Setup Session, Payment Method and Payment Intent identifiers, PlanEvents invoice identifier and number, Peppol delivery status, payment timestamp, credit allocation and related accounting or audit information.

Complete card numbers, card verification values and other complete payment-card credentials are not received or stored by PlanEvents. Payment-card information is entered into and processed through Stripe’s payment infrastructure.

Stripe processes personal data under its own applicable contractual and privacy framework. Depending on the processing activity and legal relationship, Stripe may act as an independent controller or processor for certain processing activities.

Payment information is processed for performance of the purchase contract under Article 6(1)(b) GDPR, compliance with legal and tax obligations under Article 6(1)(c) GDPR and prevention of fraud or defence of legal claims under Article 6(1)(f) GDPR.

12. Credits and quality claims

Where a Professional submits a quality claim concerning a purchased lead, PlanEvents processes information necessary to evaluate and administer that claim.

This may include the claim reason, written explanation, evidence description, additional information, claim status, associated request and purchase references, monetary amounts, timestamps, administrator notes, review decisions, claim history, credit-restoration information and risk or fraud-prevention indicators.

A Professional may upload supporting images. Depending on the claim, these images may contain bounced-email notices, invalid-number messages, call-log screenshots, WhatsApp or SMS delivery-failure information, customer cancellation messages, evidence of duplication, evidence concerning authorisation of a request, before-and-after request information or other material relevant to the claim.

Submitted images may be technically resized or converted before storage. The Platform may retain the converted image together with technical metadata such as the original filename, dimensions, file size and storage path.

Quality claims are reviewed manually by authorised PlanEvents personnel.

Where reasonably necessary to verify a claim, prevent fraud, resolve a dispute or establish the circumstances of an event request, PlanEvents may contact the Client using the contact details associated with the request. PlanEvents may explain the substance of the Professional’s allegation or show limited supporting material where this is reasonably necessary for verification. PlanEvents may record and take account of the Client’s response.

PlanEvents does not intentionally disclose unrelated evidence or unrelated personal data where it is not necessary for the investigation.

Quality-claim evidence is stored in a private storage environment. Access is restricted to the Professional who submitted the claim and authorised administrators, using access controls and short-lived signed access mechanisms where applicable.

13. Referral and Promotional Programmes

Where a Professional participates in a PlanEvents referral or promotional programme, PlanEvents may process information relating to the referral and the resulting Promotional Credits, including the referral or partner code, referring Professional account identifier, referred Professional account identifier, referral status, registration and approval status, Promotional Credits granted, relevant timestamps and information reasonably necessary to identify duplicate, fraudulent or abusive participation.

This information is processed for the administration and operation of the relevant programme, management of Professional accounts and Credits, prevention and detection of fraud or abuse, enforcement of the applicable Terms and the establishment, exercise or defence of legal claims.

PlanEvents does not require a referring Professional to provide PlanEvents with the personal contact details of another Professional in order to use a partner code. A Professional may independently share their own partner code with another professional, who may then choose whether to register with PlanEvents.

Referral and promotional programme records are retained for as long as reasonably necessary to administer the programme, maintain relevant account and transaction history, prevent fraud and abuse, comply with applicable legal obligations and establish, exercise or defend legal claims, in accordance with the retention principles described in this Privacy Policy.

14. Special-category and sensitive information

PlanEvents does not currently require Clients to provide detailed health information as part of the ordinary event-request process.

Certain event requirements may nevertheless indirectly reveal sensitive circumstances. In addition, users may voluntarily place health-related information, religious information, accessibility information or other categories of sensitive data in free-text fields or supporting evidence even where PlanEvents has not requested that information.

Article 9 GDPR imposes additional restrictions on the processing of special categories of personal data.

Users are requested not to provide special-category personal data unless it is genuinely necessary for the relevant event request, legal claim, quality claim or other specific purpose.

Where special-category data is provided incidentally or voluntarily, PlanEvents will limit access and further processing to what is necessary and legally permitted and will apply the additional safeguards required by applicable law.

Where future functionality intentionally requires the systematic processing of special-category data, PlanEvents will assess and document the applicable Article 9(2) condition before such processing is introduced.

15. Marketing communications

Marketing communications are optional.

Where a user chooses to receive marketing communications, PlanEvents records the relevant consent, the version of the consent wording and the time at which consent was provided.

Marketing consent may be withdrawn at any time through the available preference controls or by contacting PlanEvents.

Withdrawal of marketing consent does not affect operational, transactional, contractual, security or legally required communications that PlanEvents must send independently of marketing consent.

PlanEvents retains evidence of consent and withdrawal where necessary to demonstrate compliance with Article 7 GDPR and to respect future objections or opt-out requests.

PlanEvents does not currently use user email addresses for advertising audiences or behavioural advertising.

If PlanEvents later introduces advertising audience matching, personalised advertising or similar processing, this Privacy Policy and, where relevant, the Cookie Policy and consent mechanism will be updated before such processing is implemented.

16. Cookies and similar technologies

PlanEvents may use strictly necessary technical mechanisms required for authentication, security, session management, language preferences and operation of the Platform.

With prior consent, PlanEvents uses Google Analytics 4 and Vercel measurement services for aggregate usage, navigation, technical-performance and predefined marketplace-event measurement. These technologies remain disabled before consent and after refusal.

The analytics implementation does not send names, email addresses, phone numbers, full postal addresses, VAT numbers, contact persons, request contact details, free-text messages or claim evidence. Google Signals, advertising personalisation and Google user-provided data collection are disabled.

Where prior consent is legally required for non-essential cookies or similar technologies, those technologies will not be activated solely on the basis that a user has continued to browse the Platform.

Additional information is set out in the separate PlanEvents Cookie Policy.

17. Authentication, technical information and security logs

PlanEvents and its infrastructure providers process technical information for authentication, security, fraud prevention, abuse prevention, debugging, availability and operational monitoring.

This information may include IP address, browser or User-Agent information, request timestamps, authentication timestamps, login events, failed login attempts, request route, HTTP status information, request identifiers, security events, application error information and processor-generated runtime or authentication logs.

PlanEvents uses IP-derived hashed identifiers in short-lived rate-limiting controls. These counters are normally maintained for approximately ten minutes and are not used by PlanEvents to create a persistent device fingerprint.

Where Cloudflare Turnstile or equivalent bot-protection mechanisms are used, technical information including the user’s IP address may be transmitted to that provider for security and abuse-prevention purposes.

Supabase and Vercel may generate authentication, database, access, infrastructure and runtime logs containing IP addresses, User-Agent information, timestamps and request metadata as part of providing authentication, hosting, storage, database and application infrastructure.

PlanEvents also maintains operational audit information relating to registrations, event requests, professional verification and review, moderation, appeals, quality claims, administrator decisions and other significant platform actions.

18. Email communications

Transactional and operational emails may be sent through Resend.

PlanEvents may process the recipient email address, message type, delivery status, timestamp, relevant event or account identifiers and related technical information necessary to send and monitor transactional communications.

Transactional emails may include account verification messages, event-related notifications, marketplace notifications, security communications, claim-related information and other communications necessary to operate the Service.

19. Hosting, database and storage infrastructure

PlanEvents uses third-party infrastructure providers to host and operate the Service.

Supabase is used for database, authentication and storage functionality. Vercel is used for application hosting and runtime infrastructure. Stripe is used for payment processing. Resend is used for email delivery. Cloudflare Turnstile may be used for bot and abuse prevention.

These providers may process personal data on behalf of PlanEvents or, for certain activities, as separate controllers, depending on the nature of the service and applicable contractual arrangements.

Where a provider acts as a processor on behalf of PlanEvents, PlanEvents uses contractual arrangements intended to satisfy Article 28 GDPR.

PlanEvents maintains internal records concerning its processing activities and processors and reviews such arrangements when service providers or processing activities change.

20. International transfers

Certain providers used by PlanEvents may operate, store information or engage subprocessors outside Belgium or outside the European Economic Area.

Where personal data is transferred to a third country or international organisation, PlanEvents applies the requirements of Chapter V GDPR.

Transfers may take place on the basis of an adequacy decision under Article 45 GDPR or, where no adequacy decision applies, subject to appropriate safeguards under Article 46 GDPR, including Standard Contractual Clauses adopted or approved by the European Commission where appropriate.

Where required by applicable law, PlanEvents or its relevant provider may assess whether additional technical, contractual or organisational safeguards are necessary in view of the laws and practices of the destination country.

Derogations under Article 49 GDPR are not intended to be used as a routine substitute for the transfer mechanisms provided in Articles 45 and 46.

21. Data retention

PlanEvents applies category-specific retention periods in accordance with the storage-limitation principle under Article 5(1)(e) GDPR. Personal data may be retained for longer where necessary to comply with a legal obligation, establish, exercise or defend legal claims, investigate fraud, respond to a regulator, preserve evidence subject to a legal hold or resolve an active dispute.

Abandoned quality-claim uploads are retained for twenty-four hours and are then deleted.

Resolved quality-claim evidence is retained for two years after final resolution and is then deleted, unless a legal hold or ongoing dispute requires longer retention.

Personal data contained in closed or expired event requests is retained for two years following closure or expiry and is then anonymised, unless a pending quality claim, legal hold or other lawful reason requires continued identifiable retention.

Security and abuse logs maintained under the PlanEvents retention framework are retained for one year and are then deleted.

Transactional email records are retained for ninety days and are then deleted.

In-app notifications are retained for two years and are then deleted.

Processed Stripe webhook records are retained for two years and are then deleted.

Ordinary operational audit records are retained for two years and are then deleted. Records that form part of a GDPR request, legal matter, security investigation, accounting record or another separately governed category are subject to the applicable retention period for that category.

Records evidencing Privacy Notice acknowledgements, Terms acceptance, marketplace disclosures and marketing consent or withdrawal are retained for six years and are then deleted unless a longer period is necessary for a legal claim or statutory requirement.

GDPR request records are retained for six years after completion of the relevant request and are then deleted.

Accounting, VAT, invoicing and legally required payment records are retained for the period required by applicable Belgian tax and accounting law. Belgian VAT rules generally require invoices, accounting books and supporting documents to be kept for ten years. Information that must legally remain part of such records will not be removed merely because another user record is deleted. Personal data not required for the relevant legal obligation may be deleted or anonymised where legally and technically appropriate. (FOD Financiën)

Managed backups are subject to a maximum target lifecycle of ninety days and age out through the relevant backup lifecycle rather than through the ordinary database-deletion process.

22. Account closure, erasure and anonymisation

A request to erase personal data does not necessarily require PlanEvents to delete every record associated with the account.

Article 17 GDPR provides a right to erasure in the circumstances specified in that Article, subject to the exceptions provided by applicable law.

Where a valid erasure request is granted, PlanEvents may delete or anonymise personal data that is no longer necessary for a lawful purpose.

PlanEvents may retain information where processing remains necessary for compliance with a legal obligation, establishment, exercise or defence of legal claims, fraud prevention, investigation of disputes or another lawful ground recognised by the GDPR.

The PlanEvents technical architecture permits the removal or anonymisation of account-identifying information while preserving accounting, payment, dispute or other records where continued retention is legally justified.

Anonymised data that can no longer reasonably identify a natural person is not personal data for the purposes of the GDPR.

23. Data subject rights

Subject to the conditions, restrictions and exceptions provided by the GDPR and applicable Belgian law, individuals whose personal data is processed by PlanEvents may exercise the rights described in Articles 15 to 22 GDPR.

Under Article 15 GDPR, a data subject may request confirmation as to whether PlanEvents processes personal data concerning them and, where applicable, access to that data and the information required by the GDPR.

Under Article 16 GDPR, a data subject may request rectification of inaccurate personal data and completion of incomplete personal data.

Under Article 17 GDPR, a data subject may request erasure of personal data where the statutory conditions are met.

Under Article 18 GDPR, a data subject may request restriction of processing in the circumstances provided by that Article.

Under Article 20 GDPR, where processing is based on consent or contract and carried out by automated means, the data subject may have the right to receive personal data they provided in a structured, commonly used and machine-readable format and, where technically feasible, to transmit that data to another controller.

Under Article 21 GDPR, a data subject may object to processing based on legitimate interests in circumstances provided by that Article. A data subject may object at any time to processing of their personal data for direct-marketing purposes.

Where processing is based on consent, consent may be withdrawn at any time under Article 7 GDPR.

PlanEvents does not require users to exercise these rights through a self-service interface. Requests may be submitted to support@planevents.eu.

PlanEvents may take reasonable steps to verify the identity of the person making the request before disclosing, correcting, deleting, exporting or otherwise acting upon personal data.

PlanEvents maintains an administrator-only GDPR request register recording the request, verification status, relevant actions and outcome.

Where appropriate, PlanEvents can provide a structured export of relevant user data, correct data, restrict or anonymise information and record the completion or rejection of a request.

Requests are handled in accordance with Article 12 GDPR. PlanEvents will respond without undue delay and, in principle, within one month of receipt. Where permitted by Article 12(3) GDPR, that period may be extended by a further two months taking into account the complexity and number of requests, provided that the data subject is informed of the extension and reasons for it within the initial one-month period. (EUR-Lex)

24. Right to lodge a complaint

Under Article 77 GDPR, a data subject has the right to lodge a complaint with a competent supervisory authority if they consider that the processing of personal data relating to them infringes the GDPR.

For PlanEvents, the relevant Belgian supervisory authority is the Belgian Data Protection Authority, also known as the Autorité de protection des données or Gegevensbeschermingsautoriteit.

The exercise of this right is without prejudice to any other administrative or judicial remedy available under Articles 78 and 79 GDPR. (Gegevensbeschermingsautoriteit)

25. Security of personal data

PlanEvents implements appropriate technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access in accordance with Article 32 GDPR.

These measures may include authenticated access, role-based access control, database row-level security policies, restricted administrator permissions, private storage, signed temporary links, encryption in transit, processor security controls, rate limiting, bot protection, audit logging, data-minimisation measures, redaction of marketplace previews, retention controls and controlled anonymisation.

No information system can provide an absolute guarantee of security. PlanEvents therefore applies security measures proportionate to the nature, scope, context and purposes of processing and the risks to the rights and freedoms of natural persons.

26. Personal data breaches

PlanEvents maintains procedures for identifying, investigating and documenting incidents involving personal data.

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, PlanEvents will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two hours after becoming aware of the breach, in accordance with Article 33 GDPR.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, PlanEvents will communicate the breach to affected data subjects where required by Article 34 GDPR.

Where an exception under Articles 33 or 34 applies, PlanEvents will document the relevant assessment and decision. (EUR-Lex)

27. Data protection records and accountability

PlanEvents maintains internal documentation intended to demonstrate compliance with the accountability principle under Article 5(2) GDPR.

This may include records of processing activities, retention schedules, processor records, privacy-notice and consent versions, GDPR request records, security and audit records and records relating to disputes or claims.

Where Article 30 GDPR requires a record of processing activities, PlanEvents maintains such records describing relevant processing purposes, categories of data subjects and personal data, recipients, international transfers, retention periods and security measures.

28. Children and age restrictions

PlanEvents is intended for adult users.

Clients must be at least eighteen years of age to use the Platform and submit event requests.

Professionals must be at least eighteen years of age and must also confirm that they are authorised to represent the relevant business.

PlanEvents does not knowingly offer the Service to children.

If PlanEvents becomes aware that an account has been created in violation of these requirements, it may take appropriate steps to restrict or close the account and process associated personal data in accordance with applicable law.

29. Third-party links and services

The Platform may contain links to websites, services or resources operated by third parties.

PlanEvents is not responsible for the privacy practices of independent third-party websites or services that are not acting as processors on behalf of PlanEvents.

Users should review the privacy information provided by those third parties before submitting personal data to them.

30. Analytics, advertising and artificial intelligence functionality

With prior consent, PlanEvents uses Google Analytics 4 and Vercel measurement services for aggregate platform analytics. PlanEvents does not use these tools for behavioural advertising, cross-site tracking or remarketing, and does not use Meta Pixel.

PlanEvents does not currently transmit user personal data to OpenAI, Anthropic, Google AI or another artificial-intelligence provider for AI-based processing of event requests, marketplace matching or professional selection.

If PlanEvents later introduces analytics, advertising, artificial-intelligence functionality or another materially new processing activity, the legal basis, processor or controller status, data categories, retention, international transfers and any applicable consent or transparency requirements will be assessed before the processing is activated.

This Privacy Policy and any applicable Cookie Policy or consent mechanism will be updated where required.

31. Changes to this Privacy Policy

PlanEvents may amend this Privacy Policy where necessary to reflect changes in the Platform, processing activities, processors, technical infrastructure, legal requirements or regulatory guidance.

The date of the current version is displayed at the beginning of this Privacy Policy.

Where a change materially affects how personal data is processed or where applicable law requires notice, PlanEvents will provide appropriate information before the change takes effect.

Where processing depends on consent, a change to the Privacy Policy will not retrospectively create consent for a materially different processing activity.

PlanEvents records the applicable version of relevant privacy and marketplace acknowledgements where required for accountability.

32. Contact

Questions concerning this Privacy Policy, the processing of personal data or the exercise of rights under the GDPR may be addressed to:

BrandLabel Agency PlanEvents Rue de la Marjolaine 1120 Brussels Belgium VAT: BE1040366570 Email: support@planevents.eu

PlanEvents

A focused marketplace connecting event needs with verified professionals across Belgium.

Company information
VAT number
BE 1040.366.570
Email
support@planevents.eu
Telephone
+32 2 315 68 38
PlatformEvent ServicesHow it worksProfessional pricingCreate an event requestJoin as a professionalLog in
Policies & legalLegal noticePrivacy noticePlatform termsCookie policyProfessional & marketplace termsRefund Policy
© 2026 PlanEvents
Plan. Connect. Succeed.
Your privacy on PlanEvents

We use necessary storage for security and sign-in. With your permission, Google Analytics helps us understand how PlanEvents is used. We do not use advertising cookies.

View cookie policy