Draft — to be reviewed by a lawyer before publication

This text is a working draft. Items in [square brackets] are still to be completed.

Privacy Policy — InvitePro Officials

Updated: 28 September 2026

This policy explains how [Company legal name] ("InvitePro", "we") processes personal data through InvitePro Officials, a service for official events, conferences and institutional meetings, under Tanzania's Personal Data Protection Act, 2022 and its regulations.

1. Who we are

The service is provided by [Company legal name], [Registered address], registration number [Company registration number]. Privacy questions: [Privacy email].

2. The institution is the controller of delegate data

For the account data of an institution and its team, InvitePro is the controller.

For the data of delegates, committee members and meeting participants, the institution running the event or meeting is the controller. InvitePro is the processor: it processes that data on the institution's behalf and only on its instructions. The institution is responsible for having a lawful basis to collect it and for informing the delegates.

3. What is processed

On the institution's behalf we process:

  • Delegates: title and name, institution, designation, region and district, phone, e-mail, gender (optional), registration number, category, photo (optional), registration-form answers and accommodation details.
  • Attendance: the days and sessions each delegate was checked in, and the badges, letters and certificates issued.
  • Meetings: committee members, attendance, apologies, minutes, resolutions and action items.
  • Institution billing: invoice details (institution name, TIN, VRN, address, contact person) and LPO numbers.

4. Use

Data is used only to provide the service: registration and accreditation, sending badges, letters, notices and certificates, check-in at the door, attendance and allowance reports, and certificate verification. We never use delegate data for our own marketing and never sell it.

5. Certificate verification

The verification page opened from a certificate's QR only shows whether the certificate is valid, the delegate's name, the event, the event dates and the number of days attended. It shows no institution, phone number, e-mail address or other details of the delegate.

6. Retention

The institution can delete delegates, an event or a meeting at any time. Delegate data is erased [retention period] after the event ends, unless the law requires us to keep it (for example tax records of invoices).

7. Delegates' rights

A delegate who wants to access, correct or delete their data should first contact the institution that registered them. We help the institution carry out the request. You may also contact us at [Privacy email] or the Personal Data Protection Commission (PDPC).