1. Who we are
EXA is an event platform for guest lists, RSVPs, ticketing, table bookings, and access control. It is operated by The Exhibit ("we", "us", "our"). Our public website, dashboard, RSVP pages, and related services are covered by this policy.
Questions about privacy can be sent to exa@theexhibit.co.
2. Scope of this policy
This policy applies to personal data processed through:
- the EXA marketing website and contact forms;
- the EXA dashboard (invite-only accounts for organisers and staff);
- public RSVP, invite, and related event pages;
- ticket purchase and check-in flows;
- email, SMS, and WhatsApp messages we send on behalf of organisers or for account administration;
- support, demos, and other communications with us.
It does not apply to websites, apps, or services that we do not control, even if they are linked from EXA or used by an event organiser independently of our platform.
3. Our role vs. event organisers
We are the controller of data about website visitors, demo/contact enquiries, and EXA dashboard accounts (for example names, emails, and login details of invited staff).
Event organisers are typically the controller of guest, invitee, RSVP, ticketing, and attendance data they upload or collect through EXA for their events. In that case we act as a processor: we host and process that data to provide the service they requested.
If you are a guest and want to correct or delete your RSVP or ticket details, start with the organiser who invited you. We can help where we are legally required to, or where the organiser asks us to.
4. Data we collect
Depending on how you use EXA, we may collect:
- Account and identity data: name, email, phone number, role, hashed password, and event-access permissions for invited dashboard users.
- Event and guest data: guest names, emails, phone numbers, RSVP status, household or plus-one details, dress-code or location details provided for an event, ticket types, table packages, and check-in records.
- Transaction data: ticket orders, amounts, payment status, and references from our payment provider. We do not store full card numbers on EXA servers.
- Communications data: invite and confirmation emails, WhatsApp/SMS delivery status, and messages you send us.
- Media: event images and other files uploaded to our media host.
- Technical data: IP address, browser type, device information, approximate location derived from IP, pages viewed, and diagnostic logs needed to run and secure the service.
- Support and enquiry data: information you submit via contact forms, email, or demos.
We do not intentionally collect special-category data (such as health, religion, or biometric identifiers) unless an organiser includes it in event fields they control. Organisers should not collect sensitive data through EXA unless they have a lawful basis and have told guests why it is needed.
5. How we use data
We use personal data to:
- create and manage invite-only dashboard accounts;
- run events: guest lists, RSVPs, tickets, tables, and door/access checks;
- send invitations, reminders, confirmations, and operational messages by email, SMS, or WhatsApp;
- process payments and prevent fraud or abuse;
- provide support, investigate incidents, and improve reliability;
- personalise event pages (for example extracting colours from an uploaded event image on the device or server);
- comply with law, enforce our terms, and protect guests, organisers, and The Exhibit;
- operate, secure, and develop EXA, including limited analytics and product improvement.
We do not sell personal data. We do not share guest lists with other organisers or competitors. Organiser-controlled guest data is processed only to provide EXA to that organiser, except where we must disclose it by law or to protect safety.
6. Artificial intelligence and automated processing
EXA may use automated tools and, where enabled, third-party AI services to help operate the product. This can include extracting visual themes from event images, assisting with copy or support, classifying or summarising operational data, detecting abuse, or improving deliverability and product features.
When we use AI or similar automation:
- we do so to provide, secure, or improve EXA — not to sell profiles or ads based on your data;
- we do not use guest or organiser personal data to train publicly available foundation models that would let others identify you;
- if a third-party AI provider is used, we only send the minimum information needed for that feature and require the provider to process it under contract;
- we do not make solely automated decisions that produce legal or similarly significant effects about you (for example refusing entry or a refund) without human involvement where the law requires it;
- AI outputs can be incomplete or incorrect. Organisers remain responsible for reviewing guest-facing content and access decisions.
You may contact us to ask whether a particular feature uses AI, to object to certain automated processing where the law allows, or to request human review of a decision that significantly affects you.
7. Legal bases
Where data protection law requires a legal basis (including Nigeria's NDPR/NDPA and, where applicable, GDPR), we rely on one or more of the following:
- Contract: to create accounts, run the platform, send operational event messages, and process tickets you or an organiser requested.
- Legitimate interests: to secure the service, prevent fraud, improve EXA, and communicate about products you already use, balanced against your rights.
- Consent: where required for optional cookies, certain marketing, or WhatsApp/SMS where local rules require opt-in. You can withdraw consent without affecting processing already carried out.
- Legal obligation: to keep records, respond to lawful requests, or meet tax and accounting rules.
Organisers are responsible for having a lawful basis to upload guest contacts and to send invites. By using EXA they confirm they are authorised to provide those contacts.
10. Retention
We keep personal data only as long as needed for the purposes above, including:
- dashboard accounts: while the account is active and for a reasonable period after closure or last login;
- pending invites: until they expire, are accepted, or are revoked;
- event, guest, RSVP, and ticket records: for the life of the event plus a period needed for support, disputes, and law;
- payment and tax records: for the period required by applicable law;
- logs and security data: for a shorter operational period unless needed for an investigation.
When data is no longer required we delete or irreversibly anonymise it, unless a longer hold is legally required.
11. Security
We use technical and organisational measures appropriate to the risk, including encrypted transport (HTTPS), hashed passwords, access controls (including invite-only dashboard registration and role-based permissions), and restricted staff access. No online service is completely secure. Please use a strong unique password and tell us promptly if you suspect unauthorised access.
12. International transfers
EXA is operated from Nigeria and may use processors in other countries. Where data is transferred internationally, we take steps required by applicable law, such as contracts with processors and assessing that the destination provides an adequate level of protection.
13. Your rights
Subject to applicable law, you may have the right to:
- access a copy of personal data we hold about you;
- correct inaccurate data;
- delete data, or restrict or object to certain processing;
- receive data in a portable format;
- withdraw consent where processing is based on consent;
- complain to a relevant data protection authority.
To exercise these rights, email exa@theexhibit.co. We may need to verify your identity. If we process data only as a processor for an organiser, we will direct you to that organiser or assist them with your request.
14. Children
EXA is not directed at children under 16, and we do not knowingly collect personal data from children for dashboard accounts. Event organisers are responsible for obtaining any parental consent required if they invite minors to an event. If you believe a child has provided us data in error, contact us and we will delete it where appropriate.
15. Communications
We send service messages that are necessary to run accounts and events (invites, RSVP confirmations, tickets, password resets, security notices). Marketing from The Exhibit is optional; you can opt out of marketing emails using the unsubscribe link or by contacting us. Opting out of marketing does not stop operational event or account messages.
WhatsApp and SMS are used when an organiser (or you) requests that channel. Message and data rates may apply. You can usually stop WhatsApp/SMS by following the instructions in the thread or by contacting the organiser or us.
16. Third-party links
EXA may link to organiser websites, payment pages, WhatsApp, social media, or other services. Their privacy practices are their own. Review their policies before providing them with information.
17. Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be notified by email or an in-product notice where appropriate. Continued use of EXA after an update means you acknowledge the revised policy.
18. Contact
For privacy requests, complaints, or questions about data or AI processing, contact The Exhibit at exa@theexhibit.co. You can also reach us via our contact page.
This policy is provided for transparency. It is not legal advice and does not create rights beyond those required by applicable law or a written contract with The Exhibit.