Legal & Trust

Data Protection & Security at ADVCY

Last updated: 31 August 2026

Privacy is part of how ADVCY designs its products.

Our approach is based on the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability.

Privacy by design

New ADVCY functionality is assessed for privacy implications during product design. Depending on the feature, this includes consideration of:

  • the information genuinely required;
  • controller and processor roles;
  • lawful basis;
  • transparency;
  • consent;
  • user controls;
  • retention;
  • deletion;
  • security;
  • third-party access;
  • international transfers;
  • children’s privacy;
  • profiling; and
  • the need for a DPIA.

Data minimisation

We aim to collect and expose only information required to provide a feature. For example, a pass verifier should not need an attendee’s complete conversation history simply to determine whether a credential is valid.

Wallet identifiers

Technical identifiers associated with wallet passes are treated according to the risk that they can identify or single out a user or pass holder.

Apple Wallet update infrastructure can involve device library identifiers and push tokens. These identifiers are used only where necessary to maintain authorised pass functionality and are protected as technical credentials.

Location

Where venue coordinates are embedded into a pass and Apple or Google uses them to determine pass relevance, ADVCY does not describe that functionality as ADVCY tracking attendees unless actual device-location information is returned to ADVCY.

Any feature that causes ADVCY to receive precise or live location information is separately assessed.

Marketing

ADVCY distinguishes operational service communications from direct marketing.

Our systems and commercial terms are designed around the principle that installing a wallet pass is not blanket consent to unrelated marketing.

Marketing permissions must be recorded where required. Opt-outs and objections must be respected.

Apple Wallet

ADVCY does not use Apple Wallet change messages for advertising or non-critical marketing.

Google Wallet

Issuer-triggered Google Wallet messaging is subject to Google’s technical and anti-spam restrictions and to applicable privacy and marketing law.

AI

ADVCY may use AI to power concierge and recommendation functionality. Client Personal Data is processed according to our DPA.

We do not sell Client Personal Data or use attendee conversations to train a public foundation model unless expressly agreed and lawfully implemented.

Security controls

Our security programme uses risk-appropriate measures which can include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • least-privilege access;
  • authentication controls;
  • secrets management;
  • logging and monitoring;
  • vulnerability management;
  • backup and recovery;
  • secure development practices;
  • incident response procedures;
  • environment segregation; and
  • supplier security reviews.

Data breaches

We maintain an incident-response process.

Where we act as Processor, affected Controllers are notified without undue delay after we become aware of a qualifying Personal Data Breach involving their Client Personal Data.

Where ADVCY acts as Controller, we assess applicable notification obligations to regulators and affected individuals.

Data-subject rights

ADVCY maintains procedures for:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent;
  • direct-marketing opt-out; and
  • applicable automated-decision rights.

More information is available at advcy.ai/data-rights.

Privacy complaints

ADVCY provides an electronic route for privacy complaints. We acknowledge data-protection complaints within 30 days and respond without undue delay.

International transfers

Where ADVCY makes a restricted international transfer, we use an appropriate legal transfer mechanism and conduct required assessments.

Subprocessors

Material subprocessors are listed at advcy.ai/subprocessors.

Governance

ADVCY maintains or is implementing proportionate compliance documentation including:

  • records of processing;
  • Data Processing Addenda;
  • supplier reviews;
  • Subprocessor records;
  • retention rules;
  • consent records;
  • suppression controls;
  • DPIAs where required;
  • Legitimate Interests Assessments where appropriate;
  • security incident records; and
  • data-rights records.

Contact

Questions can be sent to community@advcy.ai.