Privacy Policy
Endotech Confluence

Privacy Policy

Last Updated: September 1, 2026


Endotech Confluence is a private, invitation-only companion app for guests attending an Endorphins Entertainment Pvt. Ltd. event. It is not available to the general public: you can only sign in if you were personally invited.

This policy explains what the app collects, why, who else sees it, and how to delete it. It covers the mobile app only. Our website has a separate policy.

Who is responsible

Endorphins Entertainment Pvt. Ltd. is the data controller. Contact us at [email protected] about anything in this policy, including requests to access or delete your data.

What we collect, and why

Your invitation details. We hold the email address or phone number your invitation was sent to, so we can confirm you are on the guest list when you sign in. There is no password — signing in sends a one-time code.

Your profile. Your name, job title, company, and country, plus an optional profile picture. This is shown to event organisers and, where relevant, to other guests in the app.

Your trip details. Your hotel, check-in and check-out dates, and whether you have checked in at the event. Organisers use this to run the event.

Your emergency contact. A name, relationship, and phone number, which you provide so we can reach someone on your behalf in an emergency.

Photos and videos you upload. Any media you add to the event gallery, together with who uploaded it. Other guests attending the event can see the gallery.

Your location — only while the app is open, and only if you allow it. Location is used for event check-in, travel time to venues, and, if you switch it on, sharing your position with organisers during the event. The app does not track you in the background: updates stop when you close the app or lock your phone. Location is deleted automatically once the event ends.

Emergency alerts. If you use the SOS button, we send organisers the type of alert and your location so they can help you.

Face data — optional. See the dedicated section below.

Notifications. A device token, so we can send you event announcements.

Diagnostics. Crash reports and basic device information, so we can fix problems. These are not used to identify you.

Face Data

What we collect

"Find yourself in the gallery" is an optional feature. If you choose to use it, the app asks you to take one selfie. That selfie is sent to our servers and passed to Amazon Rekognition, a service of Amazon Web Services, which converts it into a numeric face signature — a mathematical template that cannot be reversed back into a photograph. The selfie image itself is not saved: it is held in memory only for as long as the conversion takes, and is never written to our databases or file storage. What we keep is the face signature and an identifier for it.

Why we collect it

The face signature is used for exactly one purpose: to work out which photographs in this event's private gallery you appear in, so that those photographs can be shown to you under "Photos of Me". It is not used to verify your identity, to unlock the app, for security, for advertising, for profiling, for analytics, or for training any machine-learning model. We do not use it outside this event's gallery.

Where it is stored

Face signatures are stored in an Amazon Rekognition face collection hosted in the Amazon Web Services Europe (Ireland) region (eu-west-1). The identifier for your signature is stored alongside your guest record in our Google Firebase Firestore database in the europe-west1 region. Both are protected by access controls that prevent other guests from reading them.

Who it is shared with

Amazon Web Services is our only processor for face data, and processes it solely on our instructions under its data processing terms. We do not sell face data. We do not share it with advertisers, data brokers, analytics providers, or any other third party. Other guests never see your face signature — they see only the event photographs themselves.

How long we keep it

We keep your face signature until you delete it. You can delete it at any time, from any device, using Profile → Delete my data in the app. That permanently removes the signature from the Amazon Rekognition collection as well as the identifier stored with your guest record; the deletion is immediate and cannot be undone. If you take a new selfie, the new signature replaces the previous one and the previous one is permanently deleted.

Your choice

Enrolment is entirely optional. The step can be skipped during onboarding, and skipping it does not limit any other part of the app — you keep full access to the itinerary, the gallery, messaging and every other feature. If you never enrol, no face data of any kind is collected about you.

Who we share information with

We do not sell your information, and we do not share it for advertising.

We use these service providers, who process data only on our instructions:

  • Google Firebase — sign-in, database, notifications, and crash reporting. Stored in the europe-west1 region (Belgium).
  • Amazon Web Services — photo and video storage in the eu-west-3 region (Paris), delivered over Amazon CloudFront; and Amazon Rekognition for face matching, in the eu-west-1 region (Ireland).
  • Twilio SendGrid — delivery of one-time sign-in codes by email.

Event organisers working on this event can see your profile, trip details, and emergency alerts. Other guests attending the event can see your profile and the gallery. We may also disclose information where the law requires it.

Where your information is held

Your information is stored in the European Union — Belgium, France, and Ireland, as described above. Endorphins Entertainment Pvt. Ltd. is based in India, so staff there may access it to run the event. Where information moves between countries, we rely on our providers' standard contractual clauses.

How long we keep things

  • Location: deleted automatically once the event ends.
  • One-time sign-in codes: deleted as soon as they are used or expire.
  • Face signature: kept until you delete it (see above).
  • Everything else: kept while your guest account exists, so that you can use the app during and after the event.

You can delete your data at any time — see the next section.

Your choices and rights

Delete everything. Profile → Delete my data removes your face signature from Amazon Rekognition, your location, the photos and videos you uploaded, your guest record, and your sign-in account. This is immediate and cannot be undone.

Skip what you do not want. Face enrolment is optional. Location sharing is optional and only runs while the app is open. Notifications are optional. None of these are required to use the app.

Contact us. Write to [email protected] to ask what we hold about you, to correct it, to object to how we use it, or to ask for a copy. Depending on where you live, you may also have the right to complain to a data protection authority.

Children

The app is for invited adult guests attending a corporate event. It is not directed at children, and we do not knowingly collect information from anyone under 16.

Security

Access to your information is restricted by server-side security rules. Face match results can only be written by our servers, never by another guest's device, and no guest can read another guest's face signature identifier. Photos and videos are delivered over signed, expiring links.

Changes to this policy

If we change how the app uses your information we will update this page and change the date at the top. Material changes affecting face data will be brought to your attention in the app.

Contact

Endorphins Entertainment Pvt. Ltd.

Head Office:

40, Block E, Sector 3, Noida, Uttar Pradesh 201301, India

[email protected]

UAE Office:

IFZA Dubai - Building A1, Dubai Silicon Oasis, UAE

[email protected]