Q&A Events
  • Live Q&A
  • Features
  • Pricing
  • Docs
Log in Try for free
  • Live Q&A
  • Features
  • Pricing
  • Documentation
  • Guides
  • Blog
  • Roadmap
  • Support
Use cases
  • Conferences
  • Webinars
  • Streamers
  • Hybrid events
Compare
  • vs Slido
  • vs Mentimeter
Log in Try for free

Privacy Policy

Last updated: 2026

This Privacy Policy describes how Big Dreams Group LTD ("we", "us", "our") collects, uses, stores and shares personal data when you visit the Q&A Events website (qna.events) or use the Q&A Events platform (app.qna.events) (together, the "Service").

We are the data controller for personal data processed in connection with the Service.

Big Dreams Group LTD
Registered in Bulgaria, EIK 206986388
42 Boulevard General Skobelev, Sofia, Bulgaria
Email: [email protected]

1. Personal data we collect

We collect the following categories of personal data:

  • Account data - name, email address, password, optional organisation name and billing contact, captured when you create an account or complete a purchase.
  • Billing data - billing name, address, country, VAT identifier (where supplied) and limited card details returned by our payment processor for receipts and reconciliation. We do not see or store full card numbers.
  • Event data - event names, dates, branding settings, embed configurations and the content of audience contributions to your events: submitted questions, votes, poll responses and timestamps.
  • Audience data - when an attendee participates in an event you have created, we may capture their display name (if they enter one), the content of their submission and minimal request metadata. Anonymous submissions can be enabled per event.
  • Technical data - IP addresses, browser information and request logs used to operate and secure the Service.
  • Communications - the contents of any emails or support requests you send us, retained for as long as needed to resolve the issue.
  • Analytics data - on the marketing site only, after you have given consent. See section 7 below.
  • Advertising measurement data - when you reach the marketing site from one of our advertisements, which campaign you arrived from, the page you landed on, the site that referred you, your device type, your country, a visitor reference we derive from your IP address and browser and rotate every day, and the fact that the visit led to a trial signup. Where the advertising platform supplies one, this also includes the identifier of that advertisement click. See section 7 below.

2. Lawful basis for processing

We rely on the following lawful bases under the GDPR:

  • Performance of a contract (Art. 6(1)(b)) - to create and operate your account, run your events, process payments and provide customer support.
  • Legitimate interests (Art. 6(1)(f)) - to keep the Service secure, prevent abuse, debug technical issues, defend against claims, measure our own advertising in our own records, and operate our business. Our legitimate interests are balanced against your rights and freedoms.
  • Consent (Art. 6(1)(a)) - for non-essential analytics on the marketing site, for advertising measurement by third parties where consent is required, and for any optional marketing communications.
  • Legal obligation (Art. 6(1)(c)) - to retain invoices, tax records and other documents required by Bulgarian or EU law.

3. How we use personal data

  • To create, operate, secure and improve the Service.
  • To process payments and issue invoices.
  • To send transactional communications (receipts, invoices, password resets, security alerts, service notices).
  • To respond to support requests and feedback.
  • To detect, investigate and prevent abuse, fraud or violations of the Terms of Use.
  • To comply with applicable laws and respond to lawful requests from public authorities.

We do not use personal data for automated decision-making that produces legal effects or similar significant impacts on you.

4. Where personal data is stored

The Service runs on infrastructure located in the European Union. Application servers, databases and primary backups all reside in the EU.

A small number of sub-processors (see section 6) may process limited data outside the EU under appropriate safeguards: Standard Contractual Clauses, adequacy decisions and additional contractual or technical measures where required.

5. Retention

  • Account data is retained while your account is active. After account closure we delete or anonymise it within 30 days, except records we must retain for legal reasons.
  • Event data and audience submissions are retained while the host's account is active. Hosts can delete events and exports at any time. Deleted data is purged within 30 days; routine backup copies age out shortly after.
  • Invoices and tax records are retained for the period required by Bulgarian accounting and tax law (currently 10 years).
  • Logs and security records are retained for a maximum of 12 months.
  • Communications with support are retained for up to 24 months after the issue is resolved.

6. Sharing and sub-processors

We do not sell personal data. We share personal data with the following categories of recipient:

  • Hosting provider - operates our EU-based servers and databases.
  • Payment processor - a regulated third-party payment processor handles card payments on our behalf. We do not see or store full card numbers.
  • Transactional email provider - delivers receipts, password resets and other system emails.
  • Analytics providers - Google (Google Analytics 4) and Microsoft (Clarity), only on marketing pages and only after consent. See section 7.
  • Advertising measurement - OpenAI, only on marketing pages, to report whether an advertisement we ran led to a trial signup. See section 7.
  • Professional advisers - lawyers, accountants and auditors as needed.
  • Public authorities - where we are required to do so by law or where necessary to protect our rights or the rights of others.

Sub-processors are bound by contractual confidentiality and data-protection obligations. A current sub-processor list is available on request from [email protected].

7. Cookies, analytics and advertising measurement

Strictly necessary cookies are first-party only and used for authentication, CSRF protection and session continuity. These are set without prompting and cannot be disabled because the Service relies on them to function.

Analytics cookies are loaded only on the marketing site (qna.events) and only after you click "Accept" on the consent banner. Specifically:

  • Google Analytics 4 - aggregated pageview and event data so we can understand which marketing pages people read. IP addresses are anonymised at collection. Operated by Google Ireland Limited; data may be transferred to the United States under Standard Contractual Clauses.
  • Microsoft Clarity - session recordings and heatmaps so we can see where the marketing site confuses people. Clarity automatically masks form inputs and personally identifiable text. Operated by Microsoft Corporation under Standard Contractual Clauses.

Advertising measurement applies when you reach the marketing site from one of our advertisements. We currently advertise in ChatGPT and on LinkedIn. For every campaign we keep our own record of the visit, described below. For ChatGPT campaigns we additionally use OpenAI's measurement pixel to learn whether a click led to a trial signup:

  • OpenAI measurement pixel - loaded on marketing pages only. It stores two cookies in your browser on this domain: __oppref, the identifier of the advertisement click you arrived with, kept for 30 days, and __obref, a random browser reference. When you start a trial, the pixel reports that a signup happened so the advertisement can be credited. Where OpenAI's automatic matching setting is enabled on our advertising account, details you type into a form on the marketing site, such as an email address, may be hashed in your browser and sent to OpenAI to match the signup. Operated by OpenAI in the United States, with transfers covered by the data-protection terms of our advertising agreement.

In the European Economic Area, the United Kingdom and Switzerland, the pixel loads only after you click "Accept" on the consent banner. Everywhere else it loads when the page opens. We do not use it to build advertising profiles or to show you personalised advertising on our own site.

Our own record. For every campaign, LinkedIn included, we record the visit in our own systems: which campaign you arrived from, the page you landed on, the referring site, your device type, your country and a daily-rotating visitor reference. Where the advertising platform supplies a click identifier we record that too, and keep it with your account if you start a trial, so we can tell which campaigns bring customers. This record stays on our EU infrastructure and is covered by our retention rules for account data. We run no LinkedIn tracking tag on this site, so LinkedIn receives nothing about your visit.

To carry that attribution from the page you land on through to a signup, we store which campaign you arrived from in a first-party session cookie. It holds the campaign name and nothing else, no identifier for you, it is never sent to anyone outside our systems, and your browser deletes it when you close it. This cookie is separate from the analytics and advertising tools the consent banner controls, and it is only set if you arrive from one of our advertisements.

If you click "Reject", none of the third-party tools above load and no analytics or third-party advertising cookies are set. The first-party campaign cookie described above is not affected by that choice, because it identifies a campaign rather than a person and is shared with nobody. If the advertising pixel had already loaded because you are outside the regions listed above, clicking "Reject" stops it measuring and it does not load again. Your choice is remembered in your browser. You can change it at any time by clearing your browser storage for this site, after which the consent banner will reappear on your next visit.

The authenticated app surfaces (app.qna.events) do not load any third-party analytics or advertising tools.

8. Your rights under the GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights:

  • Access - request a copy of the personal data we hold about you.
  • Rectification - ask us to correct inaccurate or incomplete data.
  • Erasure - ask us to delete data we no longer have a lawful basis to hold.
  • Restriction - ask us to limit how we process data while a complaint is investigated.
  • Portability - request a machine-readable copy of data you have provided to us.
  • Objection - object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent - where processing is based on consent (e.g. analytics), withdraw it at any time without affecting processing that already took place.

To exercise any of these rights, email [email protected]. We will respond within one month and may need to verify your identity before acting on the request.

You also have the right to lodge a complaint with a supervisory authority. You may complain to the supervisory authority in your country of residence, or to the Bulgarian supervisory authority where we are established:

Commission for Personal Data Protection (CPDP)
2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
Phone: +359 2 915 3 518
Email: [email protected]
Website: www.cpdp.bg

9. Children

The Service is not directed at children under 16 and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact [email protected] and we will delete it.

10. Security

We use industry-standard technical and organisational measures to protect personal data, including encryption in transit, secure password storage and access controls. No system can be perfectly secure; we maintain incident-response procedures and will notify affected users and the relevant supervisory authority of personal data breaches as required by Art. 33 and 34 GDPR.

11. Changes to this policy

We may update this policy when our practices change or when required by law. Material changes will be announced by a notice on the Service or by email to the address on your account. The "Last updated" date at the top of this page shows when the policy was most recently changed.

12. Contact

For privacy or data-protection enquiries, contact [email protected]. We will route the request to the appropriate person internally.

Q&A Events

EU-hosted live audience Q&A and polling for conferences, webinars, hybrid events and broadcasts.

Product

Live Q&A Features Pricing Use cases Roadmap

For

Conferences Webinars Streamers Hybrid events

Compare

Slido alternative Mentimeter alternative

Resources

Documentation Guides Blog Support

About

Contact Terms Privacy
Part of

© 2026 Q&A Events. All rights reserved.

Terms of Use Privacy Policy
We use cookies to understand how this site is used and to measure our advertising. Analytics stay off until you accept. See our privacy policy.