Privacy notice
Last updated: 22 August 2026
This privacy notice provides comprehensive information to users of the SpotMe/Onomi Services and Backstage users in the EU, within the meaning of Art. 12 para. 1 GDPR. In this notice, “SpotMe/Onomi” refers to the services and platform operated by SpotMe SA d/b/a Onomi, Avenue du Théâtre 1, 4th floor, 1005 Lausanne, Switzerland (see Definitions).
SpotMe/Onomi provides the Services as a processor to Clients, who act as controllers and use the Services for the purposes described in their own privacy notice. In case of any inconsistency between this document and the Client’s privacy notice, the Client’s notice prevails. SpotMe/Onomi is committed to protecting the confidentiality of the information you share and to strict compliance with applicable data protection law.
The service provided by SpotMe/Onomi
SpotMe/Onomi specializes in virtual, hybrid, and in-person event and engagement application solutions, built autonomously by Clients or with the assistance of a trained team of specialists. Each application gives App Users a digital way to interact and communicate during events, meetings, or community engagements: posting questions, receiving learning material, communicating in real time with other App Users, taking notes, casting votes, and more — the exact functionality depending on the feature set the Client enables.
Types of data collected
Usage data
Using and navigating the Services (and any third-party application embedded in them) implies the communication of usage data, acquired implicitly through internet communication protocols. Usage data includes, but is not limited to: IP addresses or domain names of the devices used, URI addresses, the time of the request, the method used to submit the request, the size of the file received in response, the server response code, country of origin, browser and operating system features, per-visit time details (such as time spent on each page), the path followed within the platform, and other parameters about the device and IT environment.
Usage data is not collected to identify App Users or Backstage Users; however, identification may become possible through further processing or combination with information held by third parties. In case of willful misconduct, fraud, or criminal offence, usage data could be used to ascertain individual responsibility. The legal basis for the temporary storage of data and log files is Art. 6 para. 1 lit. f GDPR: this processing is strictly necessary for the operation of the App, so there is no possibility of objection.
Data communicated by App Users and Backstage Users
To use the Services, App Users and Backstage Users may need to register and provide the information requested in the relevant forms completely and truthfully. Fields marked “optional” (or not marked with ”*”) may be left blank without affecting the request. The data collected for registration is: email address, first name, last name, password.
Personal data is processed upon prior, free, and informed consent where the law requires it, and solely for the purposes in this notice. Users are responsible for any third-party personal data they obtain, publish, or share through the Services and confirm they have that third party’s consent. Registration data is archived and deleted after 2 years. As the processing aims at the fulfilment of a contract, the legal basis is Art. 6 para. 1 lit. b GDPR.
Mode and place of processing
Methods. Data is processed with appropriate security measures to prevent unauthorized access, disclosure, modification, or destruction, using computers and IT-enabled tools, following organizational procedures strictly related to the stated purposes.
Place. Data is processed at the Client’s operating offices and wherever the parties involved in the processing are located. For further information, contact privacy@spotme.com.
Retention. Data is kept for the time necessary to provide the Services requested, or as stated by the purposes in this document.
Purposes of processing
Usage data is processed solely to:
- permit navigation and use of the Services from an operational and technical point of view;
- fulfil specific user requests (contact, assistance, and similar);
- allow registration and access to the personal area of the platform;
- improve the navigation experience;
- ensure the security of data and of the platform;
- identify unique devices, run hosting and backend infrastructure, and deliver push notifications;
- send informational messages and reminders related to the App and Backstage, where applicable.
Data communicated voluntarily by users is processed to:
- provide the Services;
- monitor and analyze traffic for analytics purposes;
- fulfil duties which lie with the Client under applicable laws and regulations;
- send advertising and informational messages promoting the Client’s service, upon the user’s consent;
- where applicable, allow third parties involved in providing the Services to fulfil their contractual obligations.
If an event uses an Activity challenge module that includes step count data and participants allow it on their devices, that data is collected solely to foster engagement, used only within that event’s challenge, reported in aggregate form, and not retained or processed as health data or personal activity profiles.
How it works for App Users
Other users of the App might access, re-post, or share what an App User has published — potentially including personal data such as name, screen name, location, and event participation. For each event, the Event Organizer determines the rules for how individually identifiable information is made accessible to other App Users; SpotMe/Onomi enforces those rules, including withholding data gathered under a commitment of anonymity. Examples of how participant information may be made available:
- contact and profile information may be shared with other attendees or exhibitors when the App User instructs the App to share it (e.g. a business-card exchange);
- session attendance data may go to the Event Organizer or session sponsor when the App User checks in (or is checked in) to a session;
- poll and survey data may go to the Event Organizer or the poll’s sponsor;
- winners of networking games or challenges may be announced or displayed.
App Users who are not comfortable with this may return their device (if one was provided), delete the App, or request deletion of their personal data from the Event Organizer.
How it works for Backstage Users
Backstage Users’ data is not shared with others, unless those others are also Backstage Users listed by the same Client under the same Organization — in which case the visible data is their names.
Data communicated to SpotMe/Onomi
Automatically collected. The platform is usually a closed environment: App Users authenticate via an email link or similar scheme, Backstage Users via email and password. Where no authentication scheme is available, App Users provide email address, first name, and last name. SpotMe/Onomi does not automatically collect personally identifiable information from App Users via the service; use of the Services may nonetheless imply automatic collection of usage data such as IP address, operating system, and browser type.
Communicated by the Client. As part of running an event, SpotMe/Onomi may receive personally identifiable information about users — such as name, surname, and email address — to enable platform features. SpotMe/Onomi does not own this data and processes it as data processor, according to the instructions and terms of the agreement with the Client, who remains the sole data controller.
Data transfers
Liability. Clients are solely liable for the lawful transmission of personal data to SpotMe/Onomi. They must inform data subjects accurately about intended transfers, collect prior explicit consent where needed, and inform users about any profiling performed through the Services — including any required notifications to data protection authorities. Clients must provide their users a privacy notice covering the processing SpotMe/Onomi performs on their behalf, are solely liable for enforcing consent revocations and data-subject requests (informing SpotMe/Onomi without undue delay), and are solely liable for damage arising from unlawful processing of data transferred to SpotMe/Onomi.
Transfers to Switzerland. Lawfully carried out pursuant to the European Commission’s adequacy decision 2000/518/EC of 26 July 2000.
Transfers to the US. SpotMe Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, as set forth by the U.S. Department of Commerce, and has certified its adherence to the applicable DPF Principles. If there is any conflict between this notice and the DPF Principles, the Principles govern. To learn more and view the certification, visit dataprivacyframework.gov.
To provide the Services, personal data may be collected, accessed from, transferred to, or stored in the United States, the EEA, Switzerland, Singapore, and the UK (where SpotMe Inc. operates or engages subprocessors). SpotMe Inc. is responsible for personal data it receives under the DPF and subsequently transfers to third parties acting as agents on its behalf, and complies with the DPF Principles for all onward transfers, including the Accountability for Onward Transfer principles. Individuals can contact privacy@spotme.com with inquiries or complaints. SpotMe Inc. commits to cooperate and comply with the advice of the panel established by the EU data protection authorities, the UK ICO, and the Swiss FDPIC for unresolved complaints concerning data received in reliance on the DPF.
Detailed information on the processing of personal data
- Unique device identification. SpotMe/Onomi may associate a randomly generated identification code with the user’s device, used exclusively for statistical purposes in aggregate and anonymous form.
- Hosting and backend infrastructure. Services that host data and files enabling the App to run and be distributed. Some work through geographically distributed servers (CDNs), making it difficult to determine the actual storage location of personal data.
- Push notifications. SpotMe/Onomi may send push notifications to the user.
Cookies
SpotMe/Onomi uses cookies. For this website, see the cookie policy. For the platform and services, see spotme.com/specifications.
Additional information about data collection and processing
Legal action. Personal data may be used for legal purposes by the Client, in court or in stages leading to possible legal action arising from improper use of the Services. Where processing is necessary to fulfil a legal obligation of the Client, Art. 6 para. 1 lit. c GDPR is the legal basis.
System logs and maintenance. For operation and maintenance, the platform or third-party services may collect system logs recording interaction with the App or Backstage, or use other personal data (such as IP address) for this purpose; the legal basis for their temporary storage is Art. 6 para. 1 lit. f GDPR.
Children under 13. The Service is directed to the general public. Neither Client nor SpotMe/Onomi knowingly collects information from children under 13. If such data is inadvertently collected, it is deleted as quickly as possible; if you believe we might hold information from a child under 13, contact privacy@spotme.com.
Additional and specific information. SpotMe/Onomi may provide data subjects with additional information concerning particular services on request; more details about the collection or processing of personal data may be requested at any time via privacy@spotme.com.
The rights of data subjects
Data subjects have the right, at any time, to know whether their personal data is stored, to consult the data controller or SpotMe/Onomi about its content and origin, to access it, to verify its accuracy, and to ask for it to be supplemented, cancelled, updated, or corrected, transformed into anonymous format, or blocked where held in violation of the law — as well as to oppose its processing for legitimate reasons, to request data portability, and to revoke any consent given. Requests should be sent to the data controller (the Client) at the contact information in its privacy notice, or to privacy@spotme.com. Data subjects can lodge a complaint with the competent supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement.
Personal data breaches. Where SpotMe/Onomi is the data processor, it notifies the data controller without undue delay after becoming aware of a personal data breach. Where SpotMe/Onomi is the data controller, it notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware (with reasons for any delay beyond that), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The notification describes the nature of the breach (categories and approximate numbers of data subjects and records concerned), names a contact point, describes the likely consequences and the measures taken or proposed — including mitigations. SpotMe/Onomi documents all personal data breaches, their effects, and the remedial action taken.
Questions, access, correction, deletion
App Users and Backstage Users are entitled to request information about any of their data that SpotMe/Onomi has stored, its origin, recipients, and purpose. For questions about data protection, or to access, port, correct, block, or delete personal data, to object to processing, or to revoke an authorization, users can act directly in the App (depending on version) or contact: SpotMe SA d/b/a Onomi, Attn: Data Protection Officer, Avenue du Théâtre 1, 4th floor, 1005 Lausanne, Switzerland — or the Data Protection Officer at privacy@spotme.com.
Changes to this privacy notice
The data controller reserves the right to change this notice at any time by giving notice on this page. Check this page often, referring to the date of the last modification at the top. A user who objects to any change must cease using the platform and may request that the data controller remove their personal data. Unless stated otherwise, the then-current notice applies to all personal data the data controller holds about users.
Definitions
- App User (also “Event Participant” or “User”) — the end user of a Workspace, who must coincide with or be authorized by the data subject to whom the personal data refers.
- Backstage — the web-based content management system for creating and managing workspaces: design, content, configuration, and analytics.
- Backstage User — an individual assigned and authorized by the Client to access and manage the App’s functionality via Backstage.
- Client — the natural or legal person who has purchased SpotMe/Onomi services for professional, commercial, or entrepreneurial purposes and has access to the Service.
- Cookies — small pieces of data stored in the user’s device.
- Data controller (or owner) — the person or body which, alone or jointly, decides the purposes, methods, and means of processing personal data, including security measures. Unless otherwise specified, the data controller of the platform is the Client.
- Data processor — the person or body authorized by the data controller to process personal data in compliance with this notice.
- Data subject — the legal or natural person to whom the personal data refers.
- Event Organizer — any user granted permission by the Client to define the functionality and permissions of the App during an event or community engagement.
- Organization — a deployment with a defined set of Backstage Users; the virtual space provided to the Client, containing all Client data, separate from all other Organizations.
- Personal data (or data) — any information regarding a natural person, legal person, institution, or association which is, or can be, identified, even indirectly, by reference to any other information.
- Services — the services (access to software, content, platform, infrastructure, and storage) provided to the Client and made available online by SpotMe/Onomi, including associated offline or mobile components, which may entail processing App Users’ data.
- SpotMe/Onomi — the company SpotMe SA d/b/a Onomi, with registered office at Avenue du Théâtre 1, 4th floor, 1005 Lausanne, Switzerland, and its affiliates SpotMe Holding SA, SpotMe Inc., SpotMe Pte. Ltd., and SpotMe EOOD.
- SpotMe/Onomi App (or “the App”) — the software used by event participants to access the event, via web app (browser) or mobile app.
- SpotMe/Onomi Cloud — the backend system for Backstage, the apps, and the core and advanced modules; it allows the Client to upload and store data in Workspaces, configure application templates and system objects, and deploy applications to App Users.
- SpotMe/Onomi Platform — the entire solution: Backstage, the App, and the Cloud.
- Usage data — information collected automatically from the App or Backstage (or third-party services employed in them), as described above.
- Workspace (or “Event”) — a virtual space provided to the Client containing all Client data related to a specific event; it belongs to an Organization and is separate from all other Workspaces.
Legal information
Notice to European users: this privacy statement has been prepared in fulfilment of the obligations under Art. 13 and Art. 14 of the General Data Protection Regulation (Regulation (EU) 2016/679), and under Directive 2002/58/EC as revised by Directive 2009/136/EC on the subject of cookies. This privacy notice relates solely to SpotMe/Onomi.
With respect to personal data received or transferred pursuant to the Data Privacy Framework, SpotMe Inc. is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, SpotMe Inc. may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. Under certain conditions, as described on the Data Privacy Framework website, you are entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.