Espresso Meetup

Privacy Policy

Firehouse Technologies (Pty) Ltd  ·  EspressoMeetup Platform

Last updated: 28 February 2026

Please note that Firehouse Technologies is a private limited liability company duly registered and operating in accordance with the laws of South Africa. For more information regarding your personal information lawfully stored or used by Firehouse Technologies, please contact tracy.harley@espressomeetup.com who will gladly assist.

1

Important Information and Who We Are

1.1 Purpose of this Privacy Policy

This Privacy Policy aims to give you information on how Firehouse Technologies collects and processes your personal data through any form of your engagement with us, such as when contracting or corresponding with us, when using our Platform Services, accessing or using the Platform, or providing us with your personal information in any other way (such as when registering for or participating in events).

It is important that you read this Privacy Policy together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data. This Privacy Policy supplements other notices and is not intended to override them.

1.2 Responsible Party and Operator

Firehouse Technologies is the "Responsible Party" (and, where applicable under GDPR, the "Data Controller") and is responsible for your personal data in instances where we decide the processing operations concerning your personal data. Sometimes, but very rarely, we may also operate as an "Operator" ("Data Processor" under GDPR) of personal data on behalf of a third-party Responsible Party, where that Responsible Party's privacy terms will apply.

We have appointed an Information Officer at Firehouse Technologies who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact the representative using the details set out below.

1.4 Changes to the Privacy Policy and Your Duty to Inform Us of Changes

This Privacy Policy version was updated on 28 February 2026. It is important that the personal data we hold about you is accurate and current. Please update your personal data yourself using the relevant prompts in your Profile or keep us informed if your personal data changes during your relationship with us.

1.5 Third-Party Links on Platform or Otherwise

The Platform may include links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements or terms. When you leave our Platform or engage with such third parties, we encourage you to read the distinct privacy policy of every third party you engage with.

2

The Data We Collect About You

  • Identity Data including full name, username or similar identifier, date of birth, gender, job title, and company/organisation name and registration details
  • Contact Data including email address, physical/registered addresses, social media contact details, and telephone numbers
  • Financial Data including bank account details, third-party payment provider information, and payment card details (which we do not store but only provide to our authorised third-party payment service provider under contract with us)
  • Transaction Data including details about payments to and from you, contracts, contractual terms, contract fees, subscriptions, invoices, and other details of products and services you have obtained from us
  • Technical Data including internet protocol address/es, your login data, browser type and version, time zone setting and location, cookies, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access the Platform
  • Profile Data including your Platform username and password, event preferences, matchmaking profile information, feedback, ratings, and reviews
  • Usage Data including information about how you use our Platform, events, and Services
  • Marketing and Communications Data including your preferences in receiving notices and marketing from us and your communication preferences

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you. In this case, we may have to cancel Platform access or Services you have with us, but we will notify you if this is the case at the time.

3

How Is Your Personal Data Collected?

We use different methods to collect data from and about you, including through direct interactions when you:

  • Use our Platform Services
  • Use our Platform
  • Contract with us as an Organiser
  • Register for or participate in an event as a Delegate or Exhibitor
  • Complete online profile information
  • Request information to be sent to you
  • Give us feedback

We may also receive data about you from third parties and publicly available sources, including:

  • Google — search information provider, based in California, United States
  • LinkedIn — professional networking platform, based in California, United States
  • Meta Platforms, Inc. (Facebook/WhatsApp) — based in California, United States, for WhatsApp-based communications
  • Amazon Web Services, Inc. (AWS) — based in the United States, for transactional email delivery via AWS Simple Email Service (SES)
  • Identity and access management services, based in the United States
4

How We Use Your Personal Data

We will only use your personal data when the law allows us to and for legitimate reasons. Most commonly, we will use your personal data in the following circumstances:

  • Where we have your express consent to do so
  • Where we need to consult with you or perform on the Services contract we are about to enter into or have entered into with you
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests
  • Where we need to comply with a legal or regulatory obligation

4.1 Purposes for Which We Will Use Your Personal Data

The table below describes all the ways we plan to use your personal data, which legal bases we rely on, and the specific External Third Parties your personal data may be shared with.

Purpose / ActivityType of DataLawful BasisExternal Third Parties
To engage with you after you have contacted us requesting an engagement via the Platform or otherwiseIdentity · Contact · Marketing and CommunicationsExpress consent · Performance of a contract · Legitimate interests (records & growth)Render.com · AWS SES · Microsoft 365 · Google · LinkedIn · Meta / WhatsApp
To provide you with our Platform Services as contracted (including event setup, matchmaking, and meeting scheduling)Identity · Contact · Financial · Transaction · Profile · Technical · Usage · Marketing and CommunicationsPerformance of a contract · Express consent · Legal obligation · Legitimate interestsRender.com · AWS SES · Microsoft 365 · Google · LinkedIn · Meta / WhatsApp · Sentry · Cloudflare
To contract with you as an Organiser using the Platform to create and manage eventsIdentity · Contact · Financial · TransactionPerformance of a contract · Express consent · Legal obligation · Legitimate interestsRender.com · AWS SES · Microsoft 365
To allow you to use the Platform or participate in any event as a Delegate or ExhibitorIdentity · Contact · Usage · Technical · ProfilePerformance of a contract · Express consentRender.com · AWS SES · Google · Sentry · Cloudflare · Meta / WhatsApp
To provide your information to authorised third-party service providers who need it to deliver their servicesIdentity · Contact · Financial · Transaction · ProfilePerformance of a contract · Legitimate interests · Express consentRender.com · AWS SES · Sentry · Meta / WhatsApp
To process and service your payment for services rendered by Firehouse Technologies or through the PlatformIdentity · Contact · Financial · TransactionPerformance of a contract · Legitimate interests · Express consentAs notified at the time of payment (bank transfer, EFT, or such other method as agreed)
To manage our relationship with you, including notifying you about changes to our terms, Privacy Policy or Platform ServicesIdentity · Contact · Marketing and Communications · ProfilePerformance of a contract · Legal obligation · Legitimate interests · Express consentRender.com · AWS SES · Microsoft 365 · Meta / WhatsApp
To administer and protect our organisation and our Platform (including troubleshooting, data analysis, testing, system maintenance, support, reporting, and hosting of data)Identity · Contact · Technical · Usage · ProfileLegitimate interests (IT & network security, fraud prevention) · Legal obligation · Express consentRender.com · AWS SES · Sentry · Cloudflare · Microsoft 365
To deliver relevant Platform content and services to you and measure the effectiveness of information we serve to youIdentity · Contact · Usage · Marketing and Communications · Technical · ProfileLegitimate interests (service development & growth) · Express consentRender.com · Google · Meta / WhatsApp
To provide you with direct and user-specific marketing, and make suggestions about events or services of interestIdentity · Contact · Technical · Usage · ProfileLegitimate interests (service development & growth) · Express consentRender.com · AWS SES · Microsoft 365 · LinkedIn · Meta / WhatsApp

4.2 Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. You will receive marketing communications from us if you are using our Services, have requested information from us, have participated in any of our Platform's events or services, or if you provided us with your details when registering for an event — and in each case, you have not opted out.

4.3 Third-Party Marketing

Whilst we may use your personal data within Firehouse Technologies, we will get your express opt-in consent before we share your personal data publicly with any entity outside Firehouse Technologies for marketing purposes.

4.4 Opting Out

You can ask us to stop sending you marketing messages at any time by contacting us at any time and requesting us to cease or change your marketing preferences. Where you opt out of receiving marketing messages, this opt-out will not apply to other personal data of yours which we process for another lawful basis.

4.5 Change of Purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis which allows us to do so.

5

Disclosures of Your Personal Data

We may have to share your personal data with the parties set out below for the purposes set out in the table above:

  • Internal Third Parties as set out in the Glossary
  • External Third Parties as set out in the Glossary
  • Specific third parties listed in the table in Section 4.1
  • Third parties to whom we may choose to sell, transfer, or merge parts of our organisation or our assets. If a change happens to our organisation, then the new owners may use your personal data in the same way as set out in this Privacy Policy

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions and standards.

6

Cookies

The Platform may make use of "cookies" to automatically collect information and data through the standard operation of Internet servers. Cookies are small text files a website can use to recognise repeat users, facilitate the user's on-going access to and use of a website, and allow a website to track usage behaviour and compile aggregate data to improve functionality.

The type of information collected by cookies is not used to personally identify you. If you do not want information collected through the use of cookies, there is a simple procedure in most browsers that allows you to deny or accept the cookie feature. Please note that cookies may be necessary to provide you with certain features available on our Platform, and if you disable cookies you may not be able to use those features. If you do not disable cookies, you are deemed to consent to our use of any personal information collected using those cookies, subject to the provisions of this Policy.

7

International Transfers

We share your personal data within Firehouse Technologies, and this may involve transferring and processing your data outside of South Africa, including to countries in the European Economic Area and the United States.

Our primary infrastructure provider is Render.com, whose servers are located in the EU (Frankfurt, Germany). This means your data is primarily processed within the EU, providing a high level of data protection consistent with GDPR standards. Transactional and event-related emails are sent via AWS Simple Email Service (SES), operated by Amazon Web Services, Inc. in the United States. WhatsApp-based communications are facilitated via Meta Platforms, Inc., also based in the United States.

Whenever we transfer your personal data out of South Africa or the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will always have a contract in place covering the processing of data and service-provision between the parties
  • Where we use certain service providers, we may use specific Standard Contractual Clauses (SCCs) approved by the European Commission or equivalent contracts which give personal data the same protection it has in South Africa or the EEA
  • Where applicable, we rely on adequacy decisions, the EU–US Data Privacy Framework, or other recognised transfer mechanisms
8

Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorised way, altered or disclosed. These measures include:

  • Industry-standard OWASP security practices applied to our application development
  • Encrypted data and files at rest and in transit (TLS 1.2+ for all data in transit)
  • Hosting on Render.com, a SOC 2 Type II and ISO 27001 certified infrastructure provider, in the EU (Frankfurt)
  • Cloudflare WAF (Web Application Firewall) providing DDoS protection and traffic filtering
  • Sentry application monitoring for real-time error detection and anomaly alerting
  • Multi-factor authentication (MFA) required for all infrastructure access
  • Role-based access control (RBAC) within the EspressoMeetup Platform, with per-event permission scoping
  • Annual security reviews and ongoing dependency vulnerability scanning in our CI/CD pipeline

In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a legitimate need to know. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

9

Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including the purpose of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data, any other applicable law requiring us to retain the data, and whether we can achieve those purposes through other means. Details of retention periods for different aspects of your personal data are available from us by contacting us.

In some circumstances you can ask us to delete your data. In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.

10

Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data where we are the relevant "Responsible Party" (or "Data Controller"). Please contact us to find out more about, or to exercise, these rights:

Right to request access to your personal data
Right to request correction of your personal data
Right to request erasure of your personal data
Right to object to the processing of your personal data
Right to request a restriction of processing your personal data
Right to request transfer of your personal data
Right to withdraw consent

You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. We try to respond to all legitimate requests within one month.

11

Glossary

11.1 Lawful Basis

Legitimate Interest

The interest of our organisation in conducting and managing our business to enable us to give you the best service and the most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) before we process your personal data for our legitimate interests.

Performance of Contract

Processing your personal data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

Comply with a legal obligation

Processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.

Consent

You have given clear consent for us to process your personal data for a specific purpose. You have the right to withdraw consent at any time.

11.2 Third Parties

External Third Parties include:

  • Authorised third-party Service Providers under contract with Firehouse Technologies who need your personal information in order to contact and transact with you pursuant to your use of the Platform
  • Specific third parties who have been identified in the table in Section 4.1
  • Service providers acting as operators who provide IT and system administration services
  • South African or other national governments and/or their respective authorities pursuant to our adherence with anti-corruption and crime-fighting legislation
  • Professional advisers acting as operators or joint responsible parties including lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services as required

11.3 Your Legal Rights

Under POPIA and, where applicable, the GDPR, you have the right to request access, correction, erasure, restriction, and portability of your personal data, as well as the right to object to processing and to withdraw consent. Please see Section 10 for full details on how to exercise these rights.

Questions about your privacy?

Our Information Officer is happy to help with any privacy-related queries or requests.

tracy.harley@espressomeetup.com