EVRA

Privacy Policy

GDPR and Data Protection Notice

Effective date: 8 September 2026 · Last updated: 8 September 2026

Security Bookers Limited trading as EVRA (“EVRA”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, store and share personal data when you visit EVRA, create or use an account, list or provide services, make or manage a booking, communicate through the Platform or otherwise interact with us.

For the processing described in this Policy, Security Bookers Limited trading as EVRA is the data controller, except where otherwise stated.

1. Who we are

EVRA is operated by Security Bookers Limited trading as EVRA, 3/4 Pembroke Street, Dublin 2, Ireland. VAT No. 3452000CH. EVRA provides a platform through which businesses and their teams can discover, compare, enquire about, book and manage venues and event suppliers.

2. Who this Privacy Policy applies to

This Policy applies to website visitors; Customer account users; employees and representatives using EVRA for their organisation; Vendors, Venues and their personnel; prospective Customers, Vendors and Venues; people communicating with EVRA or through the Platform; attendees or other persons whose data is provided in connection with an Event; and other business contacts.

3. Personal data we collect

Depending on how you interact with EVRA, we may collect identity and contact data (such as name, work email, phone, job title, employer and business address); account and authentication data; profile and preference data; Event and Booking data; communications; transaction and billing data; technical and usage data; and information you choose to provide.

Please avoid providing special-category or other sensitive personal data unless it is genuinely necessary and lawful for the relevant Event or Booking.

4. Customer and company account data

For Customer accounts we may process names and business contact details, employer, role, permissions, team membership, enquiries, Booking history, budgets and approvals, preferred or approved suppliers, invoices, payment records, messages and Platform activity. We use this to provide EVRA, administer company accounts, facilitate Bookings and payments, provide support and improve the Platform.

5. Vendor and Venue data

For Vendors and Venues we may process business and representative contact details, business address, company and tax information, VAT details, bank or payout information, identity or verification information where required, Services, availability, pricing, media, quotes, Booking history, communications, reviews, settlement records and performance information.

Information intended for a listing, such as business name, description, photographs, Services, pricing, location and reviews, may be displayed to Customers or publicly where appropriate.

6. Booking and Event data

When an enquiry or Booking is made, we process information needed to facilitate it, including Customer and Vendor details, Event requirements, date, location, attendee numbers, selected Services, quotes, offers, prices, status, payments, cancellations, amendments and communications. Relevant information may be shared between the Customer and the applicable Vendor or Venue.

7. Payment, billing and transaction data

We may process billing names and addresses, invoice information, transaction references, amounts, payment status, refunds, commissions, fees, settlement information and VAT/tax records. Payment card details may be collected directly by payment providers; EVRA need not store complete card details where processed securely by those providers.

We retain accounting and transaction records where required to meet tax, accounting and legal obligations.

8. Communications and messaging

EVRA may process and retain messages, attachments, quotes, offers, Booking documents and system notifications to facilitate Bookings, provide support, maintain Booking records, resolve disputes, protect users and enforce applicable terms.

9. Verification, fraud prevention and security

We may process data to verify accounts, Vendors and Venues; authenticate users; prevent fraud; detect misuse; protect accounts; investigate suspicious activity; enforce terms; and protect EVRA and its users. We may use specialist verification, payment or fraud-prevention providers.

10. Website usage, cookies and analytics

When you use EVRA we may collect IP address, device and browser information, operating system, pages viewed, referring source, visit times, interactions, session information and cookie or similar identifiers.

Cookies may be used for essential functionality, authentication and security, preferences, analytics and performance, and marketing or advertising where applicable. Where consent is legally required, non-essential cookies will not be used until consent is obtained. Cookie preferences should be manageable through EVRA’s cookie controls and further details provided in a separate Cookie Policy.

11. Marketing communications

We may communicate with existing and prospective business Customers, Vendors and Venues about EVRA, including product updates, features, event ideas, newsletters, relevant offers and marketplace opportunities, where we have an appropriate lawful basis and comply with applicable electronic-marketing law.

You may unsubscribe using the link in marketing emails or object to direct marketing at any time. Operational messages about accounts, Bookings or payments are not marketing communications.

12. Information we receive from third parties

We may receive business contact or other relevant information from your employer or organisation, another EVRA user, Vendors or Venues, publicly available business websites, professional networking platforms, business directories, referral partners, payment and verification providers and other legitimate business sources.

Where data is obtained indirectly, EVRA will provide required transparency information in accordance with applicable law, subject to lawful exceptions.

13. Purposes and lawful bases

EVRA may rely on performance of a contract to create and administer accounts, provide Services, facilitate Bookings, process payments and provide support; legitimate interests to operate and improve the marketplace, communicate with business contacts, maintain security, prevent fraud, resolve disputes and protect commercial interests; legal obligations for tax, accounting, company-law, regulatory and lawful-authority requirements; and consent where appropriate, including certain marketing or non-essential cookies.

Where legitimate interests are relied upon, EVRA considers whether those interests are overridden by the rights and freedoms of affected individuals. Where processing is based on consent, consent may be withdrawn at any time without affecting earlier lawful processing.

14. Who we share personal data with

Depending on use of EVRA, data may be shared with Customers; Vendors and Venues; payment, banking and payout providers; cloud hosting providers; communications and messaging providers; email providers; analytics providers; identity-verification and fraud-prevention providers; CRM and customer-support providers; professional advisers; insurers; regulators or authorities where required; and prospective purchasers, investors or advisers in connection with a corporate transaction.

Service providers acting as processors on EVRA’s behalf are subject to appropriate contractual data-protection obligations. EVRA does not sell personal data.

15. Payment providers

Specialist payment providers may process personal data in accordance with their own privacy terms and legal obligations. EVRA may receive information confirming transactions, verification, payment status, refunds, disputes and payouts.

16. Retention

EVRA keeps personal data only as long as reasonably necessary for the purposes for which it was collected and to meet legal, tax, accounting, regulatory, fraud-prevention and dispute-resolution requirements.

Retention depends on the data type. Account data may be retained while an account is active and for an appropriate period afterwards; Booking and transaction records for applicable legal/accounting periods; communications where relevant to a Booking or dispute; marketing data until objection, unsubscribe or no longer needed; and security records for an appropriate investigation period. Data no longer required will be deleted or anonymised in accordance with EVRA’s retention procedures.

17. International data transfers

Some technology providers may process data outside Ireland or the EEA. Where required, EVRA will use an appropriate transfer mechanism, such as an adequacy decision, approved Standard Contractual Clauses or another lawful GDPR mechanism, and will implement supplementary safeguards where appropriate.

18. Automated tools and AI

EVRA may use automated technologies and AI to assist with generating or improving listings, matching Customers with Vendors or Venues, search and recommendations, analysing Booking requirements, customer support, fraud/security monitoring and improving Services.

EVRA does not intend to make decisions producing legal or similarly significant effects on individuals based solely on automated processing unless there is an appropriate lawful basis and the safeguards required by law are provided.

19. Security

EVRA uses appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, misuse, alteration, disclosure and destruction. Measures may include access controls, authentication, encryption, secure infrastructure, monitoring, backups and internal access restrictions.

No online system can guarantee absolute security.

20. Your GDPR rights

Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, data portability and objection; the right to withdraw consent where processing relies on consent; and rights relating to qualifying automated decision-making. You may object to direct marketing at any time.

These rights are subject to the conditions and exemptions in applicable data-protection law.

21. Exercising your rights

To exercise a data-protection right or ask a privacy question, contact info@evra.ie. EVRA may need to verify your identity and will respond within the time limits required by law. There is normally no fee, although GDPR permits a reasonable fee or refusal in certain cases involving manifestly unfounded or excessive requests.

22. Complaints

If you have concerns, please contact EVRA first so we can investigate. You also have the right to complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, Ireland, or another competent supervisory authority where applicable.

23. Children

EVRA is a business-to-business corporate-events platform and is not intended for children to create accounts. We do not knowingly seek to collect personal data directly from children through EVRA accounts. Information relating to children should only be provided where genuinely necessary for an Event and where there is an appropriate lawful basis.

24. Changes to this Privacy Policy

EVRA may update this Policy to reflect changes to the Platform, processing activities, providers or law. The latest version will be published on www.evra.ie with the revised last-updated date. Where a change materially affects how personal data is used, additional notice will be provided where required.

25. Contact EVRA

Security Bookers Limited trading as EVRA, 3/4 Pembroke Street, Dublin 2, Ireland.

Email: info@evra.ie · Website: www.evra.ie