Privacy Policy
How we collect, use, and protect your personal data
1. Introduction
Accelory ("we", "our", or "us") operates the website accelory.net and the Seto platform (useseto.com), collectively referred to as our "Services". This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Services.
By accessing or using our Services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, password, and organisation details when you create an account.
- Event Data: Event names, dates, venues, guest lists, seating arrangements, dietary preferences, and other event-related information you input into Seto.
- Payment Information: Billing address and payment card details, processed securely through our third-party payment processor (Stripe). We do not store full card numbers on our servers.
- Communications: Messages, feedback, and support requests you send to us.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, timestamps, and session duration.
- Device Information: Browser type, operating system, device identifiers, and screen resolution.
- Log Data: IP addresses, referring URLs, and access times.
- Cookies and Similar Technologies: As described in our Cookie Policy.
2.3 Information From Third Parties
- OAuth Providers: If you sign in via Google or other OAuth providers, we receive your name, email, and profile picture.
- Integration Partners: Data from third-party services you choose to connect with Seto (e.g., calendar integrations).
3. How We Use Your Information
We use your information to:
- Provide and maintain our Services, including event management, guest tracking, seating orchestration, and check-in functionality.
- Process transactions and send related billing information.
- Send service communications, including account confirmations, event reminders, RSVP notifications, and security alerts.
- Improve our Services by analysing usage patterns and user feedback.
- Provide AI-powered features, such as intelligent seating suggestions, using anonymised and aggregated data patterns.
- Ensure security by detecting and preventing fraud, abuse, and unauthorised access.
- Comply with legal obligations and respond to lawful requests from authorities.
4. Data Sharing and Disclosure
We do not sell your personal data. We share information only in the following circumstances:
- Service Providers: With trusted third parties who assist in operating our Services (hosting, payment processing, email delivery, analytics), bound by data processing agreements.
- Event Collaboration: Guest information is shared with event organisers and team members you explicitly grant access to within Seto.
- Legal Requirements: When required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
- With Your Consent: When you explicitly authorise sharing with a specific third party.
5. Data Retention
- Account Data: Retained for as long as your account is active and for 30 days after deletion to allow recovery.
- Event Data: Retained for as long as you maintain an active account. You may delete individual events at any time.
- Usage Analytics: Aggregated and anonymised data may be retained indefinitely for product improvement.
- Legal Compliance: Certain records may be retained longer as required by applicable law.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Regular security audits and penetration testing.
- Role-based access controls and multi-factor authentication for internal systems.
- SOC 2 Type II compliance (in progress).
For more details, see our Security page.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data ("right to be forgotten").
- Restrict processing of your data in certain circumstances.
- Port your data to another service in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us at privacy@accelory.net.
8. International Data Transfers
Our Services are operated from the United Kingdom. If you access our Services from outside the UK, your information may be transferred to and processed in the UK or other jurisdictions. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required.
9. Children's Privacy
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on our Services at least 30 days before changes take effect. Your continued use of our Services after changes become effective constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy:
- Email: privacy@accelory.net
- Post: Accelory, United Kingdom
- Data Protection Officer: dpo@accelory.net
Version History
1 version available