Last updated 27 April 2026
1. About this Privacy Policy
Welcome to Conference Flow. This Privacy Policy outlines how the Australian National Institute of Higher Education Trust (ABN 20 459 639 129) ("Conference Flow", "we", "us", "our") collects, holds, uses, and discloses your personal information. Conference Flow is a conference directory and ticketing platform developed by the Australian National Institute of Higher Education Trust. We operate an online editorial directory and ticketing marketplace for academic and industry conferences, accessible via our website at https://www.conference-flow.com (the "Platform").
Conference Flow is operated by the Australian National Institute of Higher Education Trust (ABN 20 459 639 129), an Australian entity, and is bound by the Australian Privacy Act 1988 (Cth) (the "Privacy Act") and the 13 Australian Privacy Principles (APPs) contained within it. The Office of the Australian Information Commissioner (OAIC) is the independent national regulator for privacy and freedom of information, and this policy is designed to meet the standards and obligations they oversee.
This policy applies to all users of our Platform, including:
- Visitors: Individuals who browse our website.
- Members: Individuals who create an account on our Platform.
- Organisers: Individuals or entities who list and manage conferences, and sell tickets through our Platform.
- Attendees: Individuals who purchase tickets or register for conferences listed on our Platform.
By accessing or using our Platform, you acknowledge that you have read, understood, and agree to the collection, storage, use, and disclosure of your personal information as described in this Privacy Policy.
2. What personal information we collect
"Personal information" is defined in the Privacy Act as information or an opinion about an identified individual, or an individual who is reasonably identifiable. The types of personal information we collect depend on how you interact with our Platform.
Account Information
When you create a Conference Flow account, we collect information necessary to establish and secure your account. This includes:
- Full Name: To identify you on the Platform.
- Email Address: To serve as your unique username, for account-related communications, and for security purposes (e.g., password resets).
- Password: We collect your chosen password and store it as a secure, irreversible cryptographic hash. We never store your plain-text password.
- Organisation/Affiliation (Optional): You may choose to provide the name of your company, university, or organisation.
Profile Information
To help you get the most out of our Platform, you can choose to provide additional information for your public-facing profile. This information is optional and is only collected if you provide it. This may include:
- Avatar/Profile Picture: An image to represent you.
- Public Contact Email: An email address you are comfortable sharing publicly on your profile.
- Country of Residence: To help others understand your location.
- Organisation Name and Website: To link to your professional affiliation.
- Social Media Links: URLs to your profiles on platforms like LinkedIn, Twitter, or personal websites.
Identity and Financial Information (for Organisers)
For Organisers who wish to sell paid tickets and receive payouts, we are required to conduct identity verification ("Know Your Customer" or KYC) to comply with anti-money laundering and financial regulations. This process is managed entirely by our payment processor, Stripe, Inc. and its local entity, Stripe Payments Australia Pty Ltd ("Stripe").
- You will provide your identity documents (e.g., driver's licence, passport) and bank account details directly to Stripe through a secure portal integrated into our Platform.
- Conference Flow does not see, handle, or store this sensitive identity or bank account information. We receive a token or status confirmation from Stripe to confirm that your identity has been successfully verified, which enables us to activate payouts for your account.
Event Listing Content
Organisers provide detailed information about their conferences for publication on the Platform. This content may inadvertently contain the personal information of third parties, for which the Organiser is responsible for obtaining consent. This includes:
- Speaker Information: Names, titles, affiliations, biographies, and photos of keynote speakers, panellists, and presenters.
- Organiser Contact Details: Names, email addresses, and phone numbers of event staff.
- Sponsor Information: Names and logos of sponsoring organisations and individuals.
Ticket Purchase and Attendee Information
When you purchase a ticket for a conference through our Platform, we collect information needed to process the transaction and issue the ticket.
- Buyer Information: Your full name, email address, and billing country. We do not collect or store your full credit card number, CVC, or expiry date. This information is provided directly to our payment processor, Stripe, which processes the payment and provides us with a confirmation token.
- Attendee Information: The Organiser of a conference may require additional information from each attendee during the checkout process. This is information they need to run their event. You provide this information directly to the Organiser via our Platform. This may include details such as company name, job title, dietary requirements, or accessibility needs. Conference Flow processes this data on behalf of the Organiser.
Email Engagement Data
When we send you emails, such as newsletters or transaction confirmations, we may collect engagement data using standard industry technologies (e.g., tracking pixels). This includes:
- Confirmation that you have opened an email.
- Information on which links you clicked within the email.
- Your decision to unsubscribe from a mailing list.
Device, Log, and Analytics Data
Like most websites, we automatically collect certain information when you visit and interact with our Platform. This data helps us understand how our service is used, diagnose technical issues, and improve security. This includes:
- IP Address: Your Internet Protocol address.
- Device and Browser Information: Your browser type (e.g., Chrome, Firefox), version, operating system, and user-agent string.
- Usage Data: The pages you visit on our Platform, the time and date of your visit, the time spent on those pages, and referring URLs (the website you came from).
- Approximate Location: We may derive your approximate geographical location (e.g., city, country) from your IP address. This is not precise GPS data.
Cookies and Similar Technologies
We use cookies, which are small text files stored on your device, and other similar tracking technologies to operate and improve our Platform. Please see Section 6: "Cookies and tracking technologies" for more detail.
Communications with Us
When you contact us for support, to provide feedback, or for any other reason via our contact form, email, or other channels, we collect the content of that communication, including your name, email address, and any other information you provide.
3. How we collect personal information
We collect personal information in several ways, consistent with APP 3 and APP 5.
Directly from You
Most of the personal information we hold is collected directly from you when you voluntarily provide it. This happens when you:
- Create and update your account and profile.
- List a conference on the Platform.
- Purchase a ticket for a conference.
- Fill out a form on our website, such as a contact or support request form.
- Subscribe to our newsletters or other marketing communications.
- Communicate with us via email or other channels.
From Conference Organisers
When an Organiser lists a conference, they may provide personal information about third parties, such as speakers and staff. If you are a speaker at a conference listed on our Platform, the Organiser may have provided your name, bio, and photo to us.
From our Payment Processor (Stripe)
When an Organiser sets up an account to receive payouts for ticket sales, they provide identity and bank account information directly to Stripe. Stripe then informs us whether the verification was successful so that we can enable the payout functionality. We do not receive the underlying sensitive data.
From Third-Party Login Providers
If you choose to create an account or log in using a third-party service (e.g., Google, LinkedIn), we will receive certain information from that provider, such as your name and email address, as permitted by your privacy settings on that service. We use this information to create and authenticate your Conference Flow account.
Automatically through Technology
We automatically collect technical data, such as device, log, and analytics information, as you navigate and interact with our Platform. This is done using server logs, analytics software, and technologies like cookies.
From Publicly Available Sources
As an editorial directory, part of our service involves curating a comprehensive list of relevant conferences. To do this, our editorial team may collect information about conferences from publicly available sources, such as conference websites, academic publications, and professional social networks. This may include the names of conferences and associated speakers or organisers.
4. Why we collect, hold, use and disclose personal information (purposes)
Our collection and use of personal information is governed by APP 6 and is always for a specific, legitimate purpose related to our functions and activities. We do not use or disclose your information for a secondary purpose unless it is related to the primary purpose, you have consented, or another exception applies under the law.
Our primary purposes are:
- To Operate and Provide the Platform: To create and manage user accounts, authenticate users, host event listings, process ticket transactions, and facilitate communication between Organisers and Attendees.
- To Process Payments: We act as a limited payment collection agent for Organisers. We collect ticket purchase information to process transactions with our payment processor, Stripe, and facilitate the transfer of funds (less our fees) to the Organiser. We also collect information to comply with financial record-keeping obligations under Australian law.
- To Communicate with You: To send essential transactional and service-related communications, such as ticket confirmations, event reminders, password resets, security alerts, and updates to our terms or policies.
- To Send Marketing Communications: Where you have provided your explicit consent (opt-in), we may send you marketing emails about conferences, features, or promotions we believe may be of interest to you. You can withdraw your consent at any time (see Section 5).
- To Provide Customer Support: To respond to your enquiries, technical issues, and feedback.
- For Security and Fraud Prevention: To monitor for and prevent fraudulent activity, protect the security and integrity of our Platform, and enforce our Terms of Service. This includes analyzing IP addresses, device data, and transaction patterns.
- To Comply with Legal Obligations: To meet our legal and regulatory requirements, such as tax and financial reporting obligations, and to cooperate with law enforcement, government agencies, or court orders.
- For Analytics and Product Improvement: To analyse usage trends, understand how our users interact with the Platform, and use these insights to improve our services, develop new features, and enhance the user experience. This data is often used in an aggregated and de-identified form.
- For Editorial Curation: To identify, verify, and list relevant academic and industry conferences in our directory, ensuring the information presented is accurate and up-to-date.
5. Direct marketing and the Spam Act 2003 (Cth)
We are committed to complying with both the Australian Privacy Principles (APP 7) and the Spam Act 2003 (Cth) regarding direct marketing.
- Consent-Based: We will only send you commercial electronic messages (such as marketing emails or newsletters) if you have provided your express consent to receive them. This is typically done by opting-in via a checkbox during account creation or through a dedicated subscription form. Your consent is not a precondition for using our core ticketing service.
- Easy Unsubscribe: Every marketing email we send will include a prominent, clear, and functional "unsubscribe" link. Clicking this link will immediately remove you from that specific mailing list at no cost.
- Sender Identification: All marketing communications will clearly and accurately identify the Australian National Institute of Higher Education Trust (trading as Conference Flow) as the sender and will include our contact information.
- Preference Management: We will provide you with a a marketing preferences page within your account settings, allowing you to manage your subscriptions and communication choices in one place.
Please note that even if you unsubscribe from marketing communications, you will continue to receive essential transactional and service-related emails necessary for the operation of your account and the fulfillment of any ticket purchases (e.g., order confirmations, password resets).
6. Cookies and tracking technologies
We use cookies and similar technologies like web beacons and local storage to help provide, secure, and improve our Platform. A cookie is a small data file that is transferred to your device.
We use the following types of cookies:
- Strictly Necessary Cookies: These are essential for the Platform to function. They include cookies for user authentication (keeping you logged in), session management, and security. You cannot opt-out of these cookies as the site will not work without them.
- Functional Cookies: These cookies remember choices you make, such as your language preference or user settings, to provide a more personalised experience.
- Performance and Analytics Cookies: These cookies collect information about how you use our Platform, such as which pages you visit and if you experience any errors. We use first-party and third-party analytics providers (e.g., Google Analytics) to help us understand user behaviour and improve our services. The information collected is typically aggregated and does not directly identify you.
- Marketing and Advertising Cookies: We may use these cookies to track the effectiveness of our advertising campaigns on third-party sites (ad-attribution). They help us understand which ads lead users to our Platform.
How to Manage Cookies: Most web browsers allow you to control cookies through their settings preferences. You can set your browser to accept or reject all cookies, or to notify you when a cookie is set. However, if you disable strictly necessary cookies, some parts of our Platform may not function correctly. For more information about how to manage cookies, you can consult the help documentation for your browser.
We do not sell your personal information to third parties.
7. Disclosures to third parties
We may disclose your personal information to third-party service providers and other entities who assist us in operating our Platform and conducting our business. We only disclose the information necessary for them to perform their service, and we take steps to ensure they are bound by appropriate privacy and confidentiality obligations.
Categories of third-party recipients include:
- Payment Processors: We share transaction information with Stripe, Inc. and its Australian affiliate, Stripe Payments Australia Pty Ltd, to process payments, manage payouts, and prevent fraud.
- Cloud Hosting and Infrastructure Providers: Our Platform is hosted on infrastructure provided by partners like Cloudflare, Inc. (for security and performance) and other cloud service providers. These providers store our data, which includes your personal information.
- Email and Communication Providers: We use third-party services like Resend, Inc. to send transactional and marketing emails on our behalf.
- Analytics Providers: We share device, log, and usage data with analytics partners to help us understand and improve our Platform.
- Authentication Providers: If you log in via a third party like Google, we share a limited amount of information with them to facilitate the authentication process.
- Conference Organisers: When you purchase a ticket, we disclose your name, email, and any other information you provide during checkout, to the Organiser of that specific conference so they can manage their event and attendee list. We act as a data processor for the Organiser in this context.
- Professional Advisers: We may disclose your information to our professional advisers, including lawyers, accountants, auditors, and insurers, where necessary in the course of the professional services they provide to us.
- Legal and Regulatory Authorities: We may disclose your information if required to do so by law, or in response to a valid legal request from a court, government agency, or law enforcement body.
- Potential Acquirers: In the event of a business transition, such as a merger, acquisition, or sale of assets, your personal information may be among the assets transferred. We will notify you of any such change in ownership or control of your personal information.
Some of these third-party recipients are located overseas. Please see the next section for more details.
8. Cross-border data transfers
In order to provide our services, we may need to transfer your personal information to third-party service providers located outside of Australia. This is a key requirement of APP 8 (Cross-border disclosure of personal information).
The principal countries where our third-party service providers are located include:
- The United States of America (USA)
- Countries within the European Union (EU)
When we disclose your personal information to an overseas recipient, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles in relation to your information. These steps may include:
- Entering into legally binding contracts with the overseas recipient that oblige them to handle your personal information in a way that is consistent with the APPs.
- Confirming that the recipient is subject to a law or binding scheme that has the effect of protecting the information in a way that, overall, is at least substantially similar to the way the APPs protect the information.
However, these overseas recipients may be subject to the laws of their jurisdiction, which may be different from Australian law. By providing us with your personal information and using our Platform, you expressly consent to the transfer of your information to these overseas locations. You acknowledge that if the overseas recipient handles your personal information in breach of the Australian Privacy Principles, we will not be accountable under the Privacy Act, and you may not be able to seek redress under the Privacy Act.
9. Storage and security
We take the security of your personal information seriously and have implemented appropriate technical and organisational measures to protect it from misuse, interference, loss, unauthorised access, modification, or disclosure. This is in accordance with our obligations under APP 11 (Security of personal information).
Our security measures include:
- Encryption: We use Transport Layer Security (TLS) to encrypt all data in transit between your browser and our servers. Where supported by our cloud providers, data is also encrypted at rest.
- Access Controls: Access to personal information within our organisation is limited to authorised personnel on a "need-to-know" basis, governed by strict access control policies.
- Password Security: User passwords are not stored in plain text. They are protected using strong, one-way cryptographic hashing algorithms.
- Secure Infrastructure: We use reputable cloud hosting providers that maintain high standards of physical and network security.
- Regular Reviews: We conduct periodic security reviews of our systems and practices.
While we take all reasonable steps to secure your data, no system is 100% immune from security breaches. We cannot guarantee the absolute security of your information.
Notifiable Data Breaches (NDB) Scheme: Conference Flow is an APP entity and is therefore subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. In the event of a data breach that is likely to result in serious harm to individuals whose personal information is involved, we will assess the situation and, if required, notify both the affected individuals and the Office of the Australian Information Commissioner (OAIC).
10. Retention and deletion
We retain your personal information only for as long as it is necessary for the purposes for which it was collected, and to comply with our legal and regulatory obligations. This is in line with APP 11.2, which requires us to take reasonable steps to destroy or de-identify personal information that is no longer needed.
- Account Information: We retain your account and profile information for as long as your account is active. If you choose to delete your account, we will permanently delete or anonymise your personal information, subject to the exceptions below.
- Transaction Information: Under Australian law, we are required to retain financial records, including information related to ticket sales, for a minimum of 7 years for tax and accounting purposes. After this period, the data will be securely destroyed or de-identified.
- Event and Attendee Data: Information provided to an Organiser for a specific event is retained as long as is necessary to assist the Organiser and for our record-keeping obligations.
- Backups: We maintain secure backups of our data for disaster recovery purposes. These backups are subject to a retention schedule and are securely deleted after a specific period. Personal information within these backups will be deleted as part of this process but may persist for a limited time after a live deletion request.
Account Deletion: You can request to delete your Conference Flow account at any time through your account settings or by contacting our Privacy Officer. Upon receiving a deletion request, we will de-identify or delete your personal information from our active systems within 30 days, except for information we are legally required to retain.
11. Your rights under Australian privacy law (APP 12 & APP 13)
Under the Australian Privacy Act, you have rights to access and correct the personal information we hold about you.
Right to Access (APP 12)
You have the right to request access to the personal information we hold about you. You can make a request by contacting our Privacy Officer using the details in Section 17.
To process your request, we will need to verify your identity to ensure we are not providing personal information to an unauthorised person. We will respond to your request within a reasonable period, generally within 30 days.
In most cases, we will provide you with access to your information. However, we may refuse access in certain circumstances as permitted by the Privacy Act, for example, if giving access would have an unreasonable impact on the privacy of other individuals, or if the request is frivolous or vexatious. If we refuse access, we will provide you with a written notice explaining our reasons.
There is no fee for making a request, but we may charge a reasonable fee to cover our administrative costs of providing you with the information (e.g., for photocopying or retrieving archived files).
Right to Correction (APP 13)
You have the right to request the correction of any personal information we hold about you that you believe is inaccurate, out-of-date, incomplete, irrelevant, or misleading. Much of your account information can be updated directly by you through your account settings.
For other information, you can make a correction request by contacting our Privacy Officer. We will take reasonable steps to correct the information and will respond to your request within 30 days. If we disagree that the information needs to be corrected, we will provide you with a written notice explaining our reasons and inform you of the complaint mechanisms available to you.
12. Anonymity and pseudonymity (APP 2)
APP 2 gives individuals the option of not identifying themselves, or of using a pseudonym, when dealing with an APP entity.
You are welcome to browse the conference listings on our Platform anonymously or using a pseudonym. However, for many of our services, this is impracticable. It is not possible to:
- Create a secure, verifiable user account.
- Purchase a ticket for an event.
- List an event as an Organiser.
- Receive payouts for ticket sales.
These core functions of our Platform require us to collect your real name and email address to process transactions, prevent fraud, and ensure the integrity of our service for all users.
13. Sensitive information (APP 3.3)
"Sensitive information" is a subset of personal information that is given a higher level of protection under the Privacy Act. It includes information about an individual's racial or ethnic origin, political opinions, religious beliefs, health information, or biometric information.
We generally do not collect sensitive information. The only exception is when an Organiser may request it as part of the ticket registration process (e.g., asking about dietary requirements, which may imply health or religious information). In these cases:
- The collection is managed by the Organiser.
- You provide this information with your explicit consent.
- The information is collected only for the purpose of facilitating your attendance at the event.
We will not use or disclose this sensitive information for any other purpose without your express consent, unless required or authorised by law.
14. Children
Our Platform is not directed to or intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal information from a child under 16 without verifiable parental consent, we will take steps to delete that information from our systems. If you are a parent or guardian and believe your child has provided us with personal information, please contact our Privacy Officer.
15. How to make a privacy complaint
If you have a concern about how we have handled your personal information or believe we have breached the Australian Privacy Principles, please contact us to lodge a complaint. We take all complaints seriously and will investigate them promptly.
Please direct your complaint in writing to our Privacy Officer:
Email: hello@conference-flow.com Postal Address: The Privacy Officer, Australian National Institute of Higher Education Trust, PO Box 1234, Sydney NSW 2000, Australia
Please include your name, contact details, and a clear description of your complaint. We will acknowledge receipt of your complaint within 7 days and aim to provide a formal response and resolve the issue within 30 days.
If you are not satisfied with our response or how we have handled your complaint, you have the right to escalate the matter to the Office of the Australian Information Commissioner (OAIC).
Office of the Australian Information Commissioner (OAIC) Website: www.oaic.gov.au Phone: 1300 363 992 Mail: GPO Box 5218, Sydney NSW 2001
16. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes, we will update the "Last updated" date at the top of this policy.
If we make a material change—one that significantly alters how we handle your personal information—we will provide you with prominent notice, such as by sending an email to the address associated with your account or by posting a notice on our Platform, before the change becomes effective. We encourage you to review this policy periodically to stay informed about our privacy practices.
17. Contact us — Privacy Officer details
If you have any questions, concerns, or requests relating to this Privacy Policy or our handling of your personal information, please do not hesitate to contact our dedicated Privacy Officer.
Contact Person: The Privacy Officer Company: Australian National Institute of Higher Education Trust (ABN 20 459 639 129) Postal Address: PO Box 1234, Sydney NSW 2000, Australia Email: hello@conference-flow.com