Skip to content
HEIventStart for free
Evaluate and secure

Approvals and privacy as mechanics

A budget item needs two signatures, an attendee list a retention period, a guest their right of access. HEIvent builds that in as a process, with approvers who need no access and retention periods that run by themselves at night.

In detail

What this area can do today; every item exists in the product and is included in the free Community edition.

  • Budget items per event with multi-level approval
  • Approvers approve via link, without an account; escalation when the deadline passes
  • Approval queue for regulated industries: registrations that need a review; flagging of healthcare professionals at registration
  • Retention period per data category; after it expires the system anonymises nightly
  • Access: export of all data about a person straight from the dashboard
  • Deletion on request, immediate and irreversible
  • Roles, single sign-on via SAML, two-factor for administrative roles, audit trail
  • Hosted in Germany; security measurements on the home page, generated daily

Budget approval without access

Whoever is to approve gets a link, not an account. They see the item, approve or reject. If the deadline passes, the system escalates to the next level; the event does not wait for an email.

Retention periods run by themselves

One retention period per data category. After it expires the system anonymises the data nightly; it does not delete, so that analyses remain. A deletion request from a person, by contrast, takes effect immediately and completely.

Access at the push of a button

All data stored about a person as an export, straight from the dashboard. The six data subject rights are implemented; the reporting channel for vulnerabilities is public under /.well-known/security.txt.

Those involved take part. Without an account.

Whoever contributes to this area from outside gets a personal link instead of an account someone has to manage.

Approvers

Budget approval via link, with escalation when the deadline passes.

All portals on the home page

Frequently asked questions about Budget and privacy

Does an approver need an account?
No. Approvers get a link to the budget item and approve through it. If the deadline passes, the approval escalates to the next level.
Does HEIvent delete attendee data automatically?
After the retention period expires, the system anonymises the data nightly; the registration remains as a number. Full deletion happens on request of the person concerned.
Does HEIvent hold an ISO 27001 or SOC 2 attestation?
No. HEIvent has no ISO 27001 or SOC 2 attestation, no external penetration test and no independent audit. What exists are daily generated measurements on encryption, tenant isolation and permissions; they are on the home page.
Where is the data stored?
On servers in Germany (Hetzner, Nuremberg and Falkenstein). There is no copy outside the EU; the optional AI features call a US service and can be switched off.

Your next event starts here.

Create an account, publish the event website, open registration. It takes an afternoon and costs nothing.