Brytspace Terms and Conditions

Last updated: July 31, 2026

1. Data controller

  • Legal name: BrytSpace SL
  • Tax ID (NIF): B21978127
  • Registered address: Calle Eduardo Dato 2, 5B, 28010 Madrid, Spain
  • Trade name: Brytspace
  • Domains: brytspace.com and app.brytspace.com
  • Primary email: technology@brytspace.com
  • Alternative email: carlota@brytspace.com

BrytSpace SL has not appointed a Data Protection Officer. Privacy-related inquiries and requests to exercise data protection rights may be sent to technology@brytspace.com or carlota@brytspace.com.

2. Scope of this Privacy Policy

This Privacy Policy explains how Brytspace collects, uses, stores, shares, and protects personal data through its website, application, and services related to the planning, contracting, coordination, and execution of events.

It applies to:

  • Browsing and forms on brytspace.com.
  • Registration, access, and use of app.brytspace.com.
  • CRM functionality, digital proposals, budgets, and document management.
  • The contracting and coordination of venues, suppliers, and services.
  • The management of clients, prospective clients, suppliers, collaborators, and attendees.
  • Operational, commercial, and support communications.

3. Individuals covered by this Privacy Policy

This Privacy Policy may apply to:

  • Individuals who browse the website or contact Brytspace.
  • Registered users and members of organizations with access to the platform.
  • Representatives, employees, and collaborators of client companies.
  • Suppliers, venues, and professionals providing services.
  • Attendees, guests, speakers, staff members, or other individuals associated with an event.
  • Individuals who receive commercial communications from Brytspace.

4. Categories of personal data

4.1. Identification and contact information

  • First and last name.
  • Email address and telephone number.
  • Postal address.
  • Identification documents, where necessary.
  • Handwritten or electronic signature.
  • Image or photograph.

4.2. Professional and business information

  • Company, job title, department, and responsibilities.
  • Professional contact information.
  • Relationship with the event or project.
  • Status as a representative, stakeholder, contact person, or decision-maker.
  • History of meetings, communications, and commercial follow-up.

4.3. Registration and platform usage data

  • Username and protected credentials.
  • Organization, role, and permissions.
  • Settings and preferences.
  • Login and activity history.
  • Technical, security, and audit logs.
  • Comments, messages, documents, and actions performed through the account.
  • Event type, purpose, date, schedule, and location.
  • Briefing, requirements, number and profile of attendees.
  • Budget, costs, margins, and profitability.
  • Creative and financial proposals.
  • Venues and suppliers considered.
  • Approvals, rejections, ratings, and reasons.
  • Tasks, responsible parties, hours spent, and project status.
  • Documentation required to organize and execute the event.

4.5. Attendee and guest data

  • Name, company, job title, and contact information.
  • Attendance confirmation and accreditation.
  • Transportation or accommodation information.
  • Photographs and videos.
  • Dietary preferences.
  • Allergies, intolerances, and accessibility requirements.
  • Other logistical information strictly necessary for the event.

4.6. Supplier data

  • Identification and professional information.
  • Services, locations, rates, and availability.
  • Photographs, videos, portfolios, and references.
  • Contracts, certificates, insurance policies, licenses, and policies.
  • Invoices, bank details, payments, and ratings.

4.7. Financial, contractual, and billing data

  • Budgets, proposals, contracts, and service orders.
  • Tax ID (NIF or CIF) and tax address.
  • Bank or payment information.
  • Invoices, charges, payments, commissions, refunds, and outstanding balances.
  • Accounting and tax information.

Where a specialized payment provider is involved, that provider may directly process full payment card details or other payment method information.

Brytspace may receive payment confirmations, transaction identifiers, tokens, or partial payment information necessary to manage the transaction.

4.8. Documents, communications, and images

  • Contracts, proposals, invoices, policies, authorizations, and certificates.
  • Emails, messages, notes, comments, and support communications.
  • Signatures and records of acceptance.
  • Photographs and videos related to the event.

4.9. Technical data, browsing information, and marketing preferences

  • IP address, device, operating system, and browser.
  • Technical identifiers, error logs, and performance data.
  • Pages and features used.
  • Cookies, pixels, and similar technologies.
  • Consent records, communication preferences, and unsubscribe requests.

5. Sources of personal data

Personal data may be obtained directly from the data subject or from third parties authorized or otherwise legally permitted to provide it.

Sources may include:

  • The data subject.
  • The company or organization for which the individual works.
  • A client company organizing an event through Brytspace.
  • A supplier, venue, or collaborator.
  • Other authorized users within the same organization.
  • Forms, contracts, proposals, and documents uploaded to the platform.
  • Public or professional sources where their use is lawful and relevant.
  • Website activity and technology providers involved in delivering the service.
PurposeUse of personal dataPrimary legal basis
Inquiries and proposalsRespond to requests, arrange meetings, assess needs, and prepare budgets or proposals.Pre-contractual measures and legitimate interests.
Accounts and platformRegister users and manage access, roles, permissions, and features.Performance of a contract.
Event managementDesign, plan, coordinate, execute, and close events.Performance of a contract, pre-contractual measures, and legitimate interests.
Clients and suppliersManage relationships, availability, documentation, contracting, payments, and service quality.Performance of a contract and legitimate interests.
Billing and complianceIssue and receive invoices, maintain accounting records, and comply with tax and legal obligations.Legal obligation and performance of a contract.
Support and securityResolve incidents, protect accounts, prevent fraud, and investigate unauthorized access.Performance of a contract, legal obligation, and legitimate interests.
Newsletter and marketingSend content, updates, event information, and commercial communications.Consent, prior contractual relationship, or another legally permitted basis.
Analytics and advertisingMeasure usage, campaigns, and audiences through cookies or similar technologies.Consent for non-essential technologies.
Claims and disputesRespond to requests and establish, exercise, or defend legal claims.Legal obligation and legitimate interests.

7. Health data, accessibility information, and other special categories of personal data

Allergies, intolerances, accessibility requirements, and certain dietary preferences may reveal information relating to health, religious beliefs, or other special categories of personal data.

Brytspace will not request this information on a general basis or use it for purposes incompatible with the organization of the event.

  • Such data will only be collected when strictly necessary.
  • Access will be limited to individuals who need the information for the relevant purpose.
  • Where Brytspace acts as data controller, explicit consent or another valid legal basis under Article 9 of the GDPR will be required.
  • Where Brytspace acts as data processor, the client must determine the applicable legal basis and provide the required information to the individuals concerned.
  • Diagnoses, medical records, or excessive medical information should not be uploaded or provided.

8. Brytspace as data controller and data processor

8.1. Brytspace as data controller

Brytspace will act as data controller where it determines the purposes and means of processing.

This may include processing relating to website and platform users, client representatives, suppliers, billing, commercial communications, security, and operation of the service.

8.2. Brytspace as data processor

Where a client company uploads or provides personal data relating to attendees, employees, guests, or other third parties for the purpose of organizing an event, the client may act as data controller and Brytspace as data processor.

In such cases, processing will be carried out in accordance with the client's documented instructions and the applicable data processing agreement.

  • The client will determine the purpose of processing and the applicable legal basis.
  • The client will provide the required information to affected individuals and obtain any necessary consents.
  • Brytspace will implement appropriate security measures and manage its subprocessors.
  • This Privacy Policy does not replace the applicable data processing agreement.

9. Recipients and service providers

Personal data will only be disclosed or made available to third parties where necessary for the relevant purpose.

Recipients may include:

  • Client companies and authorized users.
  • Venues and suppliers selected for an event.
  • Banks and payment service providers.
  • Electronic signature and document management services.
  • Hosting, database, storage, and backup providers.
  • Email, CRM, support, communications, and analytics tools.
  • Artificial intelligence providers.
  • Accountants, auditors, lawyers, and other professional advisers.
  • Public authorities, regulators, courts, and tribunals.
  • Potential purchasers or investors in connection with corporate transactions, subject to appropriate safeguards.

Brytspace must maintain an up-to-date internal inventory of processors and subprocessors, including the services they provide, their location, categories of data processed, security measures, and the applicable international transfer mechanism where relevant.

10. International data transfers

Based on the information currently available, Brytspace's main infrastructure is hosted in Spain.

However, providers of analytics, advertising, communications, payments, support, or artificial intelligence services may process data or allow access to data from countries outside the European Economic Area.

Where applicable, international data transfers may be based on:

  • An adequacy decision adopted by the European Commission.
  • The EU-U.S. Data Privacy Framework where the recipient participates in the framework.
  • Standard Contractual Clauses.
  • Binding Corporate Rules.
  • Additional technical, contractual, or organizational safeguards.

Data subjects may request information regarding the safeguards applied to international transfers by contacting technology@brytspace.com.

11. Data retention

Personal data will be retained for as long as necessary to fulfill the purpose for which it was collected and, afterward, may be restricted or blocked for the applicable statutory limitation or legal retention periods.

CategoryRetention criteria
AccountsWhile the account remains active. After termination, data that must be retained for legal obligations or potential liabilities will be deleted or restricted as appropriate.
Clients, contracts, and eventsDuring the relationship and, as a general rule, for up to five years after its termination, unless a longer applicable period applies.
Proposals not resulting in a contractUp to 24 months from the last interaction, unless the individual objects, requests deletion, or another justification applies.
Commercial and accounting documentationSix years, without prejudice to any other specific statutory periods.
Tax informationFor the applicable statutory limitation period, generally four years, without prejudice to interruptions or inspections.
MarketingUntil consent is withdrawn, the individual objects, or unsubscribes. Minimum information may be retained on suppression lists.
Technical and security logsFor as long as necessary to protect the service, investigate incidents, and demonstrate actions taken.
Data processed on behalf of clientsIn accordance with the client's instructions and the applicable data processing agreement.
CookiesAccording to the retention period specified in the cookie settings panel and Cookie Policy.

Deleted data may remain restricted and available solely for the purpose of addressing potential liabilities.

After the applicable period expires, the data will be securely deleted or anonymized.

12. Artificial intelligence and automated decision-making

Brytspace may use artificial intelligence tools to classify information, prepare drafts, summarize documents, improve search functionality, recommend venues or suppliers, identify inconsistencies, and support customer service.

  • AI tools will be used for assistance and support purposes.
  • Outputs should be reviewed before decisions are made or information is shared externally.
  • Brytspace will not make decisions based solely on automated processing that produce legal effects or similarly significant effects, unless specific information is provided and the required safeguards are in place.
  • Confidential content will not be used to train general-purpose models for purposes unrelated to the service without an appropriate legal basis and specific information being provided.
  • Personal data entered into AI tools will be limited to what is strictly necessary.

13. Data subject rights

Data subjects may exercise the following rights, where applicable:

  • Access to their personal data and information about how it is processed.
  • Rectification of inaccurate or incomplete personal data.
  • Erasure of personal data where legally applicable.
  • Objection to processing based on legitimate interests or to direct marketing.
  • Restriction of processing in the circumstances provided by law.
  • Data portability where applicable.
  • Withdrawal of consent without affecting the lawfulness of processing carried out before withdrawal.
  • The right not to be subject to certain decisions based solely on automated processing.

Requests may be sent to technology@brytspace.com or carlota@brytspace.com and should indicate the right being exercised and provide the information necessary to locate the relevant personal data.

Brytspace may request additional information where it has reasonable doubts regarding the identity of the person making the request.

Data subjects also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) if they believe that the processing of their personal data does not comply with applicable data protection law.

14. Account deletion and data export

Users may request deletion of their account by sending an email to technology@brytspace.com or carmen@brytspace.com.

It is not necessary to contact both addresses.

Account termination does not necessarily result in the immediate deletion of all information.

Brytspace may restrict or retain data where necessary to comply with legal obligations, manage invoices and payments, or address potential liabilities.

Users may request a copy of the personal data they have provided and, where applicable, receive it in a structured, commonly used, and machine-readable format.

15. Security

Brytspace will implement technical and organizational measures appropriate to the level of risk in order to protect personal data against loss, alteration, destruction, unauthorized access, or unauthorized disclosure.

Measures may include:

  • Role-based access controls and permissions.
  • Authentication and credential protection.
  • Encryption where appropriate.
  • Backup and recovery procedures.
  • Activity and audit logs.
  • Vulnerability and incident management.
  • Supplier assessments and confidentiality commitments.
  • Internal privacy and security procedures.

Users must protect their login credentials and immediately report any suspected unauthorized access.

16. Third-party data and minors

Any person who provides personal data relating to another individual represents that they have authorization or another valid legal basis to do so, that they have informed the individual where required, and that the data is accurate, relevant, and limited to what is necessary.

The services are not intended for minors to directly enter into contracts or create accounts.

Where an event includes minor attendees, the organization responsible for the event must have the necessary authorizations and legal bases to process their personal data and images.

17. Commercial communications

Brytspace may send newsletters, content, updates, invitations, and commercial communications where there is consent, a prior contractual relationship relating to similar Brytspace services, or another legally permitted basis.

Each commercial communication will include a simple and free method for unsubscribing.

Operational communications relating to accounts, events, bookings, payments, or security are not considered advertising and may be sent where necessary to provide the service.

18. Changes to this Privacy Policy

Brytspace may update this Privacy Policy to reflect legal, technological, organizational, or service-related changes.

Where a change is material, users will be informed through the website, application, email, or another appropriate communication channel.

Do you need help?
Do you need help?Contact us via WhatsApp.