Privacy Policy
How AirBalloon collects, uses, shares, and protects personal information across the platform and the conferences run on it.
Effective Date: [DATE] Last Updated: [DATE] Version: 1.0 (Draft)
This is a working draft prepared from the platform architecture documents. Bracketed placeholders (legal address, jurisdiction, contact email, DPO details) must be replaced and the final text reviewed by qualified counsel before publishing.
1. Introduction
Airballoon ("Airballoon", "we", "us", or "our") is a conference management platform operated by Lumvex Labs LLC ([Address — Street, City, State, ZIP, Country]). Airballoon helps academic and professional organizations run the full lifecycle of a conference: paper submission and peer review, author camera-ready, registration and payments, presentation/scheduling, attendee networking, and conference websites.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over it. It applies to:
- Visitors to airballoon.com and conference websites we host;
- Organizers, conference chairs, program chairs, and other staff who use the platform to run a conference;
- Authors, co-authors, reviewers, area chairs, and program-committee members participating in submission and peer review;
- Attendees who register for, or interact with, conferences run on the platform;
- Users of our mobile and web applications, including the social/networking features.
If you are interacting with a conference run on Airballoon, the conference Organizer is generally an independent controller of your data for the purposes of running their conference; Airballoon acts as a processor on the Organizer's behalf for that conference data, and as an independent controller for our own platform-account, billing, and security data. Section 5 explains this in more detail.
2. Information We Collect
We collect information in three ways: (a) information you give us directly, (b) information we receive about you from a conference Organizer or another user, and (c) information collected automatically when you use the platform.
2.1 Account and Profile Information
When you create an Airballoon account or are added to a conference, we collect:
- Name, email address, password (hashed), and login credentials;
- Affiliation, title, role (e.g., author, reviewer, attendee, organizer), country, and time zone;
- Profile information you choose to add (biography, areas of expertise, ORCID, photo, social links);
- Authentication identifiers from federated sign-in providers, where used (e.g., AWS Cognito, institutional SSO).
2.2 Submission and Review Content
For conferences using our Submission & Review service we collect:
- Paper, abstract, poster, and proposal files and metadata (title, abstract, keywords, topics, track);
- Co-author lists, author affiliations and ORCIDs, and conflict-of-interest disclosures;
- Reviews, scores, meta-reviews, rebuttals, decisions, and reviewer/area-chair comments;
- Camera-ready files, copyright forms, and revision history;
- Communications related to a submission (notifications, author–chair correspondence).
2.3 Registration and Payment Information
For conferences using our Registration service we collect:
- Registration type, ticket selections, paper-coverage selections, dietary and accessibility preferences;
- Billing name, billing address, organization, tax ID where provided, and registration receipts;
- Exemption codes used and verification documents you upload (where the conference uses external registration);
- Limited transaction metadata (amount, currency, status, timestamp, last 4 digits of card, card brand).
Payment card numbers are processed directly by Stripe, Inc. Airballoon does not receive or store full card numbers, CVV codes, or full bank-account numbers. See Section 5 for more on Stripe.
2.4 Communications and Webmail
The platform includes an in-app webmail system used for conference correspondence (e.g., chair-to-author notifications, reviewer assignments, registration confirmations). We collect:
- Message content, subject lines, recipients, attachments, folder labels, read/flag state;
- Email-template variables and rendered output;
- Delivery and bounce information from upstream email providers (e.g., AWS SES).
2.5 Presentation, Scheduling, and Social Features
Where a conference enables the Presentation System or the Social/Networking features, we collect:
- Session schedules, speaker assignments, recordings and slide decks you choose to upload;
- Live-session join URLs (Zoom/Teams/Meet/Webex), which are provided by the Organizer or by you;
- For virtual or hybrid sessions you join through our video provider (Zoom), attendance data: your name, email address, and the times you join and leave plus your total time in each session. We use this to give the Organizer attendance counts and analytics and to issue attendance certificates. Access is limited to the conference's organizers and session chairs and to your own records; it is retained per Section 7 and deleted with the conference's data;
- Networking-call metadata (we use AWS Chime SDK for in-platform small-group calls — call duration, participants, and connection diagnostics, but not recordings unless you start one);
- In-app messages, channel posts, attendee-directory entries, interest tags, meeting requests, and event RSVPs;
- For the mobile app: device push tokens, opt-in location for the "Find Me / Venue Map" feature, and connection requests.
2.6 AI-Assisted Features
Some features (e.g., AI-assisted review summarization, suggested keywords, translation) send content to AI services on our behalf. When you use these features we process the input you provide (e.g., paper excerpts, review drafts, message text). See Section 5.4 for the providers used and our retention practices.
2.7 Automatically Collected Information
When you use the platform we automatically collect:
- IP address, user agent, device type, operating system, browser, and approximate location derived from IP;
- Pages visited, features used, timestamps, referrers, and session identifiers;
- Diagnostic and error logs, performance metrics, and security telemetry;
- Cookies and similar technologies (see Section 8).
2.8 Information from Third Parties
We may receive information about you from:
- Conference Organizers who add you to a conference, invite you as a reviewer/PC member, or upload a roster;
- Co-authors who list you on a submission;
- Identity providers and SSO systems you use to sign in;
- Stripe (transaction status, payout status, account verification status);
- Institutional or sponsor systems that integrate with a conference.
2.9 Information We Do Not Knowingly Collect
We do not intentionally collect special-category personal data (race, religion, health, sexual orientation, biometric or genetic data) except where you voluntarily provide it (e.g., dietary or accessibility needs at registration), and we do not knowingly collect personal data from children under 16. See Section 11.
3. How We Use Information
We use personal information for the following purposes and on the legal bases identified (where the GDPR or comparable laws apply):
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the platform | Authenticate you, route submissions to reviewers, send notifications, render schedules | Performance of a contract |
| Run a conference on behalf of an Organizer | Manage submissions, reviews, decisions, registrations, badges | Performance of a contract; legitimate interests of the Organizer |
| Process payments and remit funds | Charge registration fees, calculate and deduct platform fees, issue receipts and refunds | Performance of a contract; legal obligation (tax/AML) |
| Communicate with you | Service emails, conference announcements, security alerts | Performance of a contract; legitimate interests |
| Improve and secure the platform | Debug, monitor abuse, prevent fraud, run aggregated analytics | Legitimate interests |
| Comply with law | Tax, accounting, anti-fraud, lawful requests | Legal obligation |
| Marketing about Airballoon | Product announcements (separate from conference-specific mail) | Consent / legitimate interests; you can opt out at any time |
We do not sell personal information, and we do not use submission content, reviews, or attendee personal data to train general-purpose AI models. AI features described in §2.6 process your content only to return a result to you; we do not retain that content for model improvement beyond what is necessary to operate and debug the feature.
4. Roles: Controller vs. Processor
Airballoon's role differs by data category:
- Conference data (submissions, reviews, registrations, attendee lists, conference-specific messages): the Organizer is the controller; Airballoon is a processor acting on the Organizer's documented instructions.
- Account, billing, security, and product-improvement data for the Airballoon platform itself: Airballoon is the controller.
If you have questions about how a particular conference uses your data — including its retention, sharing, and deletion practices — contact the Organizer first. We will support your request and will route it to the Organizer where they are the controller.
5. How We Share Information
We share personal information only as described below.
5.1 With Conference Organizers and Other Conference Participants
- Organizers (conference chairs, PC chairs, registration chairs, and other roles they assign) can see the data in their own conference, including registrant lists, submissions, reviews, and assignment data, scoped by role.
- Authors and reviewers see information about their own submissions and assignments; identity blinding is applied where the conference is configured for single- or double-blind review.
- Attendees opting into the directory or networking features make limited profile information visible to other attendees of the same conference.
5.2 With Service Providers ("Sub-processors")
We rely on the following categories of providers to operate the platform. Current providers include:
| Provider | Purpose | Data categories |
|---|---|---|
| Amazon Web Services (AWS) — Amplify, Cognito, DynamoDB, S3, SES, Lambda, CloudFront | Hosting, authentication, database, file storage, email delivery, CDN | All platform data, in our AWS account |
| Stripe, Inc. | Payment processing (Stripe Connect / Express); Airballoon never receives raw card data | Payment, billing, KYC/identity verification, payout |
| AWS Chime SDK | In-platform small-group voice/video calls | Connection metadata, audio/video streams (transient) |
| Zoom Video Communications | Hosting live virtual/hybrid sessions on Airballoon's Zoom account, including webinars for keynote/plenary sessions; we receive participant attendance data for sessions we host | Session metadata, recordings, and participant name/email + join/leave times and duration |
| Microsoft Teams, Google Meet, Cisco Webex (where an Organizer uses their own links) | Live sessions hosted on the Organizer's own account | Join URLs and session metadata as exposed by the provider |
| AWS Bedrock (e.g., Amazon Nova) and other LLM providers | AI-review and AI-assist features | Submitted content for the request only |
| LibreTranslate (self-hosted or vendor-hosted) | Translation | Text submitted for translation |
| Email-deliverability providers | Outbound transactional/conference email | Headers and message content |
| Analytics, error-monitoring, and customer-support tools | Operational telemetry and support | Pseudonymized usage and error logs; support conversations |
We require sub-processors to handle data under contract terms at least as protective as ours, and to use your data only to provide services to us.
5.3 With Authorities and to Protect Rights
We may disclose information when we reasonably believe doing so is required by law, legal process, or government request, or is necessary to investigate or prevent fraud, abuse, security incidents, or violations of our Terms of Service, or to protect the rights, property, or safety of users, the public, or Airballoon.
5.4 In Corporate Transactions
If Airballoon (or Lumvex Labs LLC) is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred subject to standard confidentiality obligations and continued protection at least as protective as this Policy.
5.5 With Your Direction
We share personal information at your direction or with your consent, including via integrations you connect (e.g., ORCID, calendar, institutional SSO, organizer-side SCM/CRM integrations).
6. International Data Transfers
Airballoon is operated from the United States and primarily hosts data in AWS regions in the United States. If you access the platform from another country, your information will be transferred to, stored in, and processed in the United States and other countries where our sub-processors operate.
For transfers from the European Economic Area, the United Kingdom, or Switzerland, we use the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) as our transfer mechanism, supplemented by appropriate technical and organizational measures.
7. Data Retention
We retain personal information for as long as needed to provide the service and for the purposes described in this Policy. Default retention periods:
| Category | Retention |
|---|---|
| Account profile while account is active | Indefinitely; deleted on account closure (or as a conference's controller directs) |
| Conference data (submissions, reviews, registrations) | For the duration of the conference and its archive period (typically 3–7 years, set by the Organizer) |
| Payment and tax records | 7 years from the transaction, to meet financial-records obligations |
| Webmail messages | For the conference's archive period, then purged unless legal hold applies |
| Backups and disaster-recovery copies | Up to 35 days beyond the live record |
| Security and audit logs | Up to 24 months |
| Aggregated, de-identified analytics | May be retained indefinitely; cannot be re-associated with you |
Where Airballoon acts as a processor, retention is set by the Organizer; we delete or return conference data on the Organizer's documented instruction or on contract termination, subject to legal-hold requirements.
8. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies to:
- Keep you signed in and remember preferences (essential);
- Measure traffic and feature usage (analytics);
- Diagnose errors and performance problems (operational).
We do not use third-party advertising cookies, and we do not engage in cross-site behavioral advertising. Where required (e.g., EEA/UK), we display a cookie banner allowing you to accept or reject non-essential categories. You can also control cookies through your browser settings; disabling essential cookies will prevent the platform from working.
9. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- Encryption of data in transit (TLS) and at rest (AWS-managed keys);
- Role-based access controls, least-privilege IAM policies, and audit logging;
- PCI-DSS-compliant payment processing through Stripe — we do not handle raw cardholder data;
- Regular vulnerability scans, dependency monitoring, and security review of code changes;
- Backup and disaster-recovery procedures across AWS availability zones;
- Background checks and confidentiality obligations for personnel with production access.
No system is perfectly secure. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by applicable law.
10. Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the personal data we hold about you;
- Rectification — correct inaccurate or incomplete data;
- Deletion / erasure — request deletion of your data, subject to legal exceptions;
- Restriction / objection — limit certain processing, including objecting to processing based on legitimate interests;
- Portability — receive a machine-readable copy of data you provided to us;
- Withdraw consent — where processing is based on consent, withdraw it at any time;
- Non-discrimination (California) — exercise your rights without retaliation;
- Lodge a complaint with your local data-protection authority.
How to exercise your rights: email support@airballoon.ai (mark it Attn: Privacy) from the address associated with your account, or use the "Privacy Request" form in your account settings. We respond within the time required by applicable law (typically 30 days under GDPR; 45 days under CCPA, with one possible 45-day extension).
Where Airballoon is a processor: if your request concerns conference-specific data, we will route it to the Organizer (controller) and assist them in responding.
10.1 Specific U.S. State Rights
In addition to the rights above, U.S. residents may:
- Request information about the categories of personal information we collected, used, disclosed, or sold in the prior 12 months. We do not sell personal information as the term is defined under the California Consumer Privacy Act, and we do not "share" personal information for cross-context behavioral advertising.
- Designate an authorized agent to act on your behalf; we will require verification.
- Appeal a denied privacy request by replying to our response email; we will reconsider within 60 days.
We do not knowingly process the personal information of California consumers under 16 for sale or sharing.
11. Children's Privacy
The platform is intended for users aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, contact us at support@airballoon.ai (mark it Attn: Privacy) and we will delete it.
Where a conference allows youth participation (e.g., student programs), the Organizer is responsible for obtaining any legally required parental consent.
12. Marketing and Communications Choices
- Service emails (registration confirmations, security alerts, account notices) are required and cannot be turned off while you have an active account.
- Conference emails are sent on behalf of the Organizer; opt-out options are governed by the conference and applicable law.
- Airballoon product marketing — you can unsubscribe via the link in any marketing email or via your account settings; this will not affect service or conference emails.
13. Third-Party Sites and Services
The platform may link to, or integrate with, third-party services (Zoom, Stripe, ORCID, institutional systems, etc.). Their privacy practices are governed by their own policies. We encourage you to review them before using those services.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top;
- Notify you by email or in-product notice for significant changes;
- Where required, obtain your consent before applying the change to data we already hold.
Continued use of the platform after the effective date of an update constitutes acceptance of the updated Policy.
15. Contact Us
Data Controller (for Airballoon platform data): Lumvex Labs LLC, doing business as Airballoon [Street Address] [City, State, ZIP] [Country]
- All inquiries: support@airballoon.ai
- Data Protection Officer / EU representative: [name and contact, if appointed]
- Postal mail: address above, marked "Attn: Privacy"
We use a single contact address. For privacy-specific requests, mark your email Attn: Privacy.
If you contact us about a conference-specific request, please tell us the conference name so we can route the request to the right controller.
Document Version: 1.0 (Draft) — Reference: docs/225-Privacy-Policy.md