Legal
Data processing terms
For organisers: the terms on which we process personal data on your behalf.
Last updated 25 August 2026
These terms apply where you run an event on B2Pair. For that data you are the controller and we are your processor. They form part of our terms of service and are made between you and Limitless Outsourcing LLC, of Bill Klinton 3, Prishtina 10000, Kosovo.
What we process, and why
- Subject matter: providing the B2Pair platform for your event.
- Duration: for as long as you keep the event, plus the periods in the retention section below.
- Nature and purpose: hosting your attendee list, matching people to each other, carrying messages and meetings between them, and producing the AI results your people ask for.
- Categories of data subject: your attendees, your exhibitors and their staff, and your own team.
- Categories of personal data: identity and contact details, professional information, what somebody said they came to do, meetings and messages at your event, attendance records, and payment details where you sell tickets.
- Lead capture: where an attendee presents their badge to one of your exhibitors, the card they chose to share passes to that exhibitor. They become a controller of it in their own right from that moment, and their obligations to that person are theirs rather than yours or ours.
- No special-category data is required by the product. If you collect any through your own registration questions, you are responsible for the additional basis it needs.
What we will and will not do
- We process on your documented instructions, which are the settings you choose and the features you use. Anything outside them needs an instruction from you, unless a law we are subject to requires it — in which case we will tell you first, unless that law forbids it.
- If we think an instruction of yours breaks data protection law, we will tell you. We will not simply carry it out and leave you to find out later.
- We do not use your attendee data for our own purposes, do not sell or rent it, and do not use it to train any model.
- We do not contact your attendees on our own behalf. Nothing goes to your list that you did not send.
- Everybody with access is bound by confidentiality that survives their leaving, and access is limited to the people who need it to do their job.
Security
The measures are described in full in the privacy policy. In summary:
- Access rules are enforced by the database on every query, not only by the application, so a defect in our own code cannot bypass them.
- Your staff hold named roles with specific capabilities; somebody on the door cannot read what your attendees came to buy.
- Passwords are hashed. Images are re-encoded, which removes embedded metadata including camera location; a PDF is kept as it was sent, because re-encoding would rewrite the document, and it is only ever downloaded rather than displayed.
- Files sent inside a conversation are served only to the two people in it, enforced by the database rather than by the address being hard to guess.
- Administrator access to any account is logged with a stated reason, the person is notified, and they can end it themselves.
- Data is encrypted in transit, and at rest by the hosting providers named below.
Sub-processors
This is the complete list, and it is short on purpose. Each one is set out in full — what they do, where the data sits, and what makes the transfer lawful — on the sub-processor page.
- Vercel Inc. — Running the application itself. (Frankfurt, Germany (eu-central-1))
- Supabase — The database, and the files people upload. (Frankfurt, Germany (eu-central-1))
- Resend — Sending email: ticket codes, notifications, password resets. (Ireland (eu-west-1))
- Anthropic PBC — The AI features. Text is sent to produce a result and is not used to train any model. (United States)
There is no payment provider on that list, because the product does not take card payments today. Each sub-processor is bound by written terms no less protective than these, and we remain answerable to you for what they do.
We will tell you before adding or replacing a sub-processor that handles attendee data, with at least thirty days’ notice. If you object on reasonable data protection grounds within that time and we cannot offer an alternative, you may end the affected event without penalty.
Your exhibitors are not our sub-processors
Worth being exact about, because it is the question a legal team asks. An exhibitor who scans a badge is not processing data on your behalf or on ours — the attendee handed it to them, deliberately, for their own purposes. They are a controller from that point, and what they do with it afterwards is between them and the person who handed it over.
What we do for you is make that exchange a deliberate act rather than a silent one: the attendee chooses what is on the card, is told it is shared when somebody scans them, and can change or empty it whenever they like. Anybody who has made themselves invisible to an exhibitor cannot be scanned by them at all.
Transfers
B2Pair is operated from Kosovo, which does not hold an adequacy decision from the European Commission. Attendee data is stored in Frankfurt, and we access it from Kosovo. That access is a restricted transfer, and it is covered by the standard contractual clauses in our data processing terms.
The European Commission’s standard contractual clauses of 4 June 2021, Module Two (controller to processor), are incorporated into these terms, with you as data exporter and us as data importer. Where you need them as a signed annex rather than by reference, ask and we will send one.
The same clauses, or an equivalent safeguard, cover each sub-processor listed above. The AI features send text to the United States; the remainder of your data stays in Frankfurt.
Helping you meet your own obligations
- Data subject requests: the export and the deletion are in the product and your attendees can use them without asking anybody. Where a request comes to you directly, we will help you answer it, and where one comes to us we will pass it to you rather than answer for you.
- Breach notification: we will tell you without undue delay and in any case within forty-eight hours of becoming aware, with what we know, what we are doing, and what we do not know yet.
- Assessments: we will give you the information you reasonably need for a data protection impact assessment or a prior consultation with your authority.
- Security: we will help you meet your own obligations under Articles 32 to 36, taking into account what we know that you cannot.
Retention, and the end
While you are a customer
Event data is kept while you keep the event, because it is your record of what happened.
When you leave
You can export everything before you go. On your instruction we will delete or return your data within thirty days, except where law requires a copy to be kept — financial records being the usual case, which is typically seven years and is not ours to shorten. Anything kept for that reason stays protected by these terms for as long as we hold it.
What we cannot delete for you
An attendee’s own account is theirs, not yours. Removing your event does not delete the person’s B2Pair account, their profile or their connections, because those exist independently of your event and only they can end them.
Audits
On request we will provide the documentation we hold about how the above is implemented, and answer reasonable written questions, within thirty days.
If that is not enough, you may audit us on site once in any twelve months, on thirty days’ written notice, during business hours, under confidentiality, and at your own cost. We will agree a scope that does not put another customer’s data at risk, and a regulator with the power to require an audit is not subject to any of these conditions.
Liability
The limits in our terms of service apply to these terms as well, and to the standard contractual clauses so far as the law allows them to.
If your legal team needs this as a signed document rather than a page, say so when you request access and we will send one.