Legal

Privacy Policy

Bridged ("we", "us") provides AI-powered agents and engagement software to events and conference organisers. This policy explains what personal data we handle, why we handle it, and what rights you have.

Last updated: 27 August 2026

When an event organiser uses our platform, we process data about their attendees, registrants and subscribers on their instructions. The organiser is the data controller. Bridged is a data processor. We do not decide what data is collected or what it is used for — the organiser does. If you attended an event and want your data changed or deleted, contact the organiser first, or contact us and we will pass the request on.

The organiser

Data controller

Bridged

Data processor

1

Data we process for organisers

Depending on what the organiser has configured, this can include:

  • Registration and attendee records (name, email address, phone number, job title, company, ticket type)
  • Session attendance, check-in and scanning data
  • Messages exchanged with our agents across channels such as WhatsApp, email and web chat
  • Engagement signals such as opens, clicks, replies and content viewed
  • Any other data the organiser chooses to send us through an integration or upload

We process this data only to deliver the service to the organiser: running the agents, personalising communications, producing analytics and reporting, and supporting and maintaining the service in line with our contract with them. We do not sell it, we do not share it with other organisers, and we do not use it to build advertising profiles.

The legal basis for processing attendee data is determined by the organiser, not by us. Organisers are responsible for having a valid basis and for providing their own privacy information to attendees.

2

AI and automated processing

Our agents use large language models to generate responses and personalise content. Some of these models are operated by third-party providers under contract with us. Where that happens:

  • Data is sent only as needed to produce a response
  • We use enterprise arrangements that prohibit providers from training their models on organiser data
  • We do not make automated decisions that produce legal or similarly significant effects on individuals

A human at the organiser can review any agent conversation.

3

Sharing and sub-processors

We engage sub-processors to deliver the service:

  • Cloud infrastructure and hosting providers used to run the platform
  • AI model providers as described above
  • Communication providers used to deliver email and messaging

All sub-processors are bound by written agreements with confidentiality and security obligations. Organisers can request our current sub-processor list at any time by emailing us, and we notify them before adding a new one.

We may also disclose data where we are legally required to do so. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

4

International transfers

We are based in the United Kingdom and use infrastructure located in multiple regions. Where personal data leaves the UK or EEA, we rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), together with additional technical safeguards such as encryption in transit and at rest. Organisers with data residency requirements can discuss region-specific hosting with us.

5

Retention

  • Organiser data is retained for the term of the contract and deleted or returned within 90 days of termination, unless the organiser asks otherwise or the law requires longer.
  • Agent conversation logs are retained for the period configured by the organiser.

Where the law requires us to keep certain records, for example for legal claims or financial compliance, we may retain them after a deletion request and will delete them once that obligation ends.

6

Security

We use encryption in transit and at rest, role-based access controls, least-privilege access for staff, network isolation, logging and monitoring, and regular dependency and vulnerability review. Access to organiser data by our staff is limited to what is needed for support and operations. We will notify affected organisers without undue delay if a personal data breach occurs.

7

Your rights

If UK/EU GDPR applies to you, you have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and complain to your local supervisory authority.

If you are a California resident, you have the right to know what personal information is collected and how it is used, to request deletion or correction, to opt out of sale or sharing (note that we do neither), and not to be discriminated against for exercising these rights. You may use an authorised agent to make a request.

Because we act on the organiser's instructions, these rights are exercised through them. You can go to the organiser directly, or unsubscribe from their emails using the link in any message.

If you contact us instead, email team@bridged.media with the subject line "Data Request" and include:

  • Your full name
  • The email address or phone number the data is likely held under
  • The event or organiser it relates to, if you know it
  • What you want done (access, correct, delete, or stop processing)

We will forward the request to the relevant organiser and support their response. We will not act on it independently unless they instruct us to.

8

Cookies

Our website uses cookies necessary for it to function, and, where you have consented, analytics and marketing cookies. Where a consent tool is presented, you can change your choices through it at any time. You can also block or delete cookies through your browser settings, though parts of the site may not work as intended. The in-product experience uses only cookies necessary to operate the platform.

9

Changes to this policy

We may update this policy from time to time. Material changes will be notified to organisers by email or through the product. The date at the top shows when this version took effect.

10. Contact

Talk to us about your data

Privacy queries and data requests
team@bridged.media

If you are in the UK or EU and are not satisfied with our response, you may complain to your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk).