Privacy Policy
Last updated August 28, 2026
This policy explains the privacy practices built into Yuyu. It is a general product notice and must be reviewed and supplemented by each deployment operator for its legal jurisdiction, contact details, and actual hosting arrangements.
Who is responsible for your information
Yuyu is self-hosted software. The organisation that operates this Yuyu instance is responsible for its use of personal information and for providing its own contact details, retention rules, and any notices required in its jurisdiction. Each event organiser is responsible for the information it collects from attendees through its events and registration forms.
Information the service processes
Depending on how you use the service, this may include account details such as your name and email address; organisation and event details; RSVP details such as attendee name, email address, registration answers, ticket and check-in status; and feedback submitted through an event form. The service also processes technical and security information needed to operate accounts, prevent abuse, and maintain an audit trail.
How information is used
Information is used to provide and secure the event service: to authenticate users, create and manage events, accept and manage registrations, issue tickets, support check-in, send transactional email, and investigate security or operational issues. Event organisers may use attendee information to run their events and communicate with registered attendees. Yuyu does not sell personal information.
Sharing and service providers
Information is shared only as needed to deliver the service or where required by law. A deployment operator may use infrastructure providers for hosting, private object storage, email delivery, backups, or monitoring. Organisers can access information for events and organisations they are authorised to manage. Public event pages expose only the details the organiser chooses to publish.
Security
Yuyu is designed with tenant isolation, role-based access controls, private object storage, encrypted secrets, rate limits, and security logging. No system can guarantee absolute security. Deployment operators remain responsible for securely configuring their hosting, databases, email, backups, and access controls.
Retention and deletion
Retention is determined by the hosting organisation and, where applicable, the relevant event organiser. Some short-lived operational records are automatically cleaned up by the service, but broader retention, backup, and deletion practices are set by the deployment operator. Ask the relevant organiser or instance operator about its retention schedule.
Your choices and requests
To request access, correction, deletion, or other action concerning your information, contact the organisation that hosted the event or operates this instance. It will assess and handle requests under the laws that apply to it. Account holders can also update basic profile details through their account settings.
Changes to this policy
The operator may update this policy when the service or its data practices change. The current version is published on this page. Material changes should be communicated by the operator where required by applicable law.