Version 1.0 · Effective 26 August 2026
Privacy Policy
Parallax Events is a virtual events platform, operated by Higgs Software Services Inc. of Vancouver, British Columbia, Canada (higgssoftware.ca). It is sold to organisations that run events for their own audiences, and this policy explains what happens to the data those events produce.
In short
- Your data stays yours. We process it on your instructions and nothing else.
- We never sell or rent it. There is no advertising, profiling or data broking in this business.
- We do not train models on it. Your attendees and their behaviour are not training data.
- No client's data is ever mixed with another's. Every record carries its organisation and every query is scoped to one.
- Three named sub-processors, and no others. Listed in section 6, with what each of them can see.
- We are Canadian, the data is in the United States. Said plainly in section 8, including what that means.
Who this covers
Three kinds of people appear in the platform, and this policy covers all of them.
- Your attendees. The people you invite to an event. They never create an account with us.
- Your staff. Administrators and hosts who sign in to run the event.
- Visitors to this website. Covered in section 12, and the short answer is that we collect nothing.
You control the data, we process it
In data protection terms you are the controller and we are the processor. That is not a formality, it decides who gets to make which call.
- The attendee list is yours. You gather it and you decide who is on it
- We handle it to run your event, on your instructions, and for nothing else
- You decide how long it is kept, and deleting it is something you can do yourself
- If an attendee asks us directly to delete their data, we point them at you, because it is not our decision to make on your behalf
What we handle
| Who | What we hold |
|---|---|
| Attendees | Name, email address, and any extra fields your own registration system chooses to send us |
| Attendance | When somebody arrived at the event and at each session, and when they left |
| Your staff | Name, email address, and their role in your organisation |
| Website visitors | Nothing at all |
What we do not collect. We do not record IP addresses, device fingerprints, browsing history or location, and we have no visibility of anything an attendee does outside your event.
Where it comes from
Attendee data reaches us in one of two ways, and only these two:
- Your own registration system posts it to the endpoint we give you
- Your administrator adds or imports it in the organiser panel
We never buy lists, and we never obtain data about your attendees from anybody but you.
What we use it for
Four things. This is the complete list, not an illustrative one.
- Sending the invitation and reminder emails you have written
- Letting an attendee into your event through their private link
- Showing your hosts who is in the room while a session runs
- Producing your attendance reports and exports
There is no secondary use, and no use that benefits us rather than you.
Sub-processors
Running live video needs infrastructure we do not own. These are the only companies that can ever touch your data. Each acts on our instructions, under contract, and none of them receives it for their own purposes.
| Sub-processor | What it does | What it can see | Where |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, live video, email delivery | All event data | United States |
| Zoom | Only if you choose it. Sessions you elect to run through your own Zoom account | The name and email of attendees joining that session, to register them | Your own Zoom account, under your own agreement with Zoom |
| Google Workspace | Our business email | Only what you put in an email to us | United States |
The Zoom row is worth reading twice. When you deliver a session through Zoom, the registration is created in your Zoom account using your credentials. Those attendees become registrants in a tenant you already control, under the agreement you already hold with Zoom. If you never enable Zoom delivery, no attendee data reaches Zoom at all.
We will tell you before adding a sub-processor, so you have the chance to object.
What we never do
- We never sell or rent your data, to anyone, at any price
- We never share it for advertising, profiling or audience building
- We never use it to train machine learning models, ours or anybody else’s
- We never let one client’s data reach another. Every record carries the organisation it belongs to and every query is scoped to a single one
- We never read your event content for our own purposes. Sessions are not recorded by the platform unless you turn recording on yourself
Where your data lives, and the border it crosses
We are a Canadian company and your data is stored in the United States. That is a deliberate disclosure, not a detail.
| What | Where |
|---|---|
| Platform, database, files, live video | AWS us-east-1, United States |
| Outbound email | AWS us-west-2, United States |
| Our company | Vancouver, British Columbia, Canada |
While it is in the United States it is subject to United States law, including lawful access requests by American authorities, in the same way data held in Canada is subject to Canadian law. No jurisdiction can be contracted away, and a provider telling you otherwise is overselling.
Your data is held under the same protections wherever it sits, and our agreements with sub-processors require the same of them.
If you need data kept in Canada, or in any particular region, raise it before you sign. Some public bodies and health organisations have residency rules they cannot waive. This is an infrastructure decision rather than a setting, so it is a conversation to have early.
How long we keep it
| What | How long |
|---|---|
| Event and attendee data | Until you delete it. It is not aged out on our schedule |
| A deleted event or organisation | Removed with it |
| Database backups | 7 days, then they expire |
| Operational logs | 1 month, and 3 months for a small number of them |
Operational logs record that a request happened, not what your attendees did. When your contract ends, tell us and we will remove what is left.
Security
- Encrypted in transit with TLS, and encrypted at rest in the database and in storage
- Attendees have no account and no password. They get a private link to a single event, so there is no credential to steal
- Your staff sign in through Amazon Cognito. We never see, handle or store their passwords
- Credentials and API keys are held in AWS Secrets Manager, never in our code
- File storage is private with all public access blocked, and the database is not reachable from the internet
- We will tell you without delay if a breach affects your data, so you can meet your own notification obligations
Rights and requests
If you are an attendee and want your data seen, corrected or deleted, contact the organisation that invited you. They hold the relationship and the decision. We cannot identify you to them, and we will not act on their data without their instruction.
If you are a client, most of this is in your own hands: the organiser panel exports, edits and deletes attendee records directly. For anything it does not cover, including a request you have received and need help answering, email contact@parallaxevents.com. We respond within 30 days, which is the limit PIPEDA sets.
Children
The platform is sold to organisations for professional events and is not directed at children. We do not knowingly collect data about anyone under 16. If you intend to run events for a younger audience, raise it with us first so the right safeguards and agreements are in place.
Accountability, law and complaints
Somebody is accountable by name. Canadian privacy law requires an organisation to put one person in charge of it rather than leaving it to everyone in general. Ours is reachable at contact@parallaxevents.com, and a request marked for the Privacy Officer reaches them.
As a company in British Columbia we are subject to Canada’s PIPEDA and British Columbia’s PIPA. Where your own organisation is bound by something else, GDPR, HIPAA, FERPA or a sector rule of your own, tell us during procurement so it can be written into the agreement rather than discovered later.
If we get it wrong, complain. Come to us first and we will answer. If our answer does not satisfy you, you can take it to a regulator without our permission and without going through us:
- The Office of the Privacy Commissioner of Canada
- The Office of the Information and Privacy Commissioner for British Columbia
- Your own country’s data protection authority, if you are outside Canada
These agreements are governed by the laws of British Columbia and the federal laws of Canada that apply there.
Changes to this policy
This is version 1.0, effective 26 August 2026. The version and date at the top of this page always say which one you are reading.
We will tell clients before a change that materially affects how their data is handled, rather than quietly republishing the page.
Contact
Privacy questions, security questionnaires and compliance reviews all go to the same place:
If your compliance team needs a data processing agreement, a security questionnaire completed, or answers specific to your jurisdiction, ask and we will work through it with you.