Privacy Policy
Effective date: 1 September 2026
Last updated: 4 September 2026
Porta is an event guest-management and check-in service provided by Leapa Systems Limited ("Leapa", "we", "us" or "our"). Porta includes the Porta Dashboard web application, the Porta Frontline iPad application, our websites, APIs and related support services.
This policy explains what personal data Porta handles, why we handle it, where it may be processed, how long we keep it and the choices available to customers, authorised staff and event guests.
1. Who is responsible for the data
For customer-account, security, billing, service-operation and support data, Leapa determines why and how the data is used.
For guest lists and event instructions uploaded or entered by an organisation, the organisation normally determines why the guest data is used. Leapa processes that data to provide Porta under the organisation's instructions. Questions about why an organiser invited a person, what guest information the organiser supplied, or how the organiser intends to use an attendance record should normally be directed to that organiser first. Leapa will assist the organiser with appropriate requests.
2. Personal data we handle
Depending on how Porta is used, we may handle:
- Customer and authorised-user data: name, work email address, organisation, role, account identifiers, authentication challenges, session records and support communications.
- Event data: event name, dates, timezone, venue, notes, event logo, field configuration and operational status.
- Guest data: title, name, organisation, email address, telephone number, group, guest type, party size, notes, organiser-defined custom fields and QR reference.
- Attendance data: number checked in, check-in time, check-in station, registration timing, corrections and an audit history of operational changes.
- Device and security data: an app-generated device identifier, device session and event identifiers, station name, credential generation, session times, synchronisation status, network address or network prefix used for security controls, request metadata and security events.
- Technical, enquiry and support data: service logs, error information, app and service version, website-enquiry contact details and Event plans, correspondence and information a person chooses to provide when requesting support.
Porta includes configurable free-text guest fields. Customers should not enter sensitive personal data unless it is necessary for the event, lawful to do so and protected with appropriate access restrictions.
3. How we obtain personal data
We obtain personal data when:
- Leapa provisions a customer account or an authorised organiser signs in;
- a customer creates an event or imports, enters or edits a guest list;
- authorised event staff prepare an iPad, add or edit a guest, or record an attendance change through Porta Frontline;
- a device synchronises event information with Porta;
- a person contacts Leapa for support, privacy assistance or another enquiry;
- Porta's servers create security, authentication, audit and operational logs.
We do not use the iPad camera to photograph guests. Porta Frontline uses camera access only when the user chooses to scan a Porta Staff Access or Guest QR code. Camera frames are processed for QR recognition and are not saved by Porta or uploaded to our servers.
4. Why we use personal data
We use personal data to:
- create and administer customer access;
- authenticate authorised organisers and event devices;
- create, prepare and operate events;
- import, display, search, update, synchronise and export guest records;
- record attendance and maintain an operational audit trail;
- provide offline check-in and reconcile changes when a device reconnects;
- prevent unauthorised access, abuse, fraud and service disruption;
- provide support and communicate important service or security information;
- maintain, troubleshoot, back up and recover the service;
- comply with legal obligations and establish, exercise or defend legal claims;
- produce aggregate service information that does not identify an individual.
We do not sell personal data. We do not use Porta data for third-party advertising, cross-app tracking or data-broker activity. We do not use one customer's guest lists or spreadsheet structure to train or improve suggestions for another customer. Porta does not currently use guest data for generative-AI training or external AI inference.
Where the EU GDPR, UK GDPR or another law requires a legal basis, we rely on:
- performance of a contract or steps requested before a contract for customer administration and delivery of Porta;
- our and our customers' legitimate interests in operating events, securing accounts, preventing misuse, supporting users and improving service reliability, after considering the interests and rights of affected people;
- compliance with legal obligations and the establishment, exercise or defence of legal claims; and
- consent where the law requires it for a genuinely optional activity. Consent may be withdrawn for future processing without affecting earlier lawful use.
When Leapa processes guest data only on an organisation's documented instructions, that organisation determines the applicable legal basis. Porta does not make decisions based solely on automated processing that produce legal or similarly significant effects on people.
5. When information is required
An authorised organiser's email address is required to authenticate and provide Porta Dashboard access. A valid Staff Access credential and a station name are required to prepare Porta Frontline for an event. Guest fields are controlled by the relevant organiser; individual guest fields may be optional unless the organiser explains otherwise.
If required access information is not provided, Porta may be unable to authenticate the user, prepare the iPad or provide the requested function. Camera permission is optional because Staff Access can be entered numerically and guests can be found by search.
6. Sharing and service providers
We disclose personal data only as reasonably necessary to operate Porta, follow a customer's lawful instructions, protect the service or comply with law. Recipients may include:
- authorised personnel of the customer that controls the relevant account and event;
- infrastructure and hosting providers used to run Porta;
- transactional-email providers used to deliver sign-in codes and service messages;
- security, availability-monitoring, backup and technical-support providers;
- professional advisers, insurers, auditors, regulators, courts or law enforcement where disclosure is lawful and necessary;
- a successor in connection with a genuine corporate reorganisation, merger or transfer, subject to appropriate confidentiality and data-protection terms.
Service providers must be bound by contractual or other safeguards requiring appropriate confidentiality, security, purpose limitation and retention. They may not use Porta customer or guest data for their own advertising.
These categories include infrastructure hosting and managed backup,
transactional email, availability/backup monitoring and application
distribution. Current named providers, their purposes and applicable processing
locations are documented in a controlled customer subprocessor schedule
supplied with the DPA/onboarding or through an authenticated customer channel.
Affected customers receive direct advance notice of material additions or
replacements where the applicable agreement requires it. Individuals may ask
privacy@porta.events for information relevant to their personal data.
7. International processing
Personal data may be processed outside the place where a customer, staff member or guest is located, including in Hong Kong and Malaysia and in locations used by our service-provider categories described above. Where applicable, we use an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another legally recognised transfer mechanism, together with appropriate technical and organisational measures. A person may contact us for more information about an applicable safeguard.
Customers must not use Porta in a jurisdiction that requires a specific data location or transfer mechanism unless that requirement has been agreed with Leapa in writing. Availability of Porta Frontline in an App Store territory does not by itself represent that Porta Dashboard or the commercial service is offered in every country.
8. Retention and deletion
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, the customer's instructions, security, dispute resolution and applicable legal obligations.
- Event and guest information remains available to an active customer until the customer deletes it, the customer agreement specifies another period, or it is no longer reasonably required for the service.
- Closing or permanently closing an event makes it operationally read-only; it does not by itself delete the event history.
- When an authorised organiser chooses Delete Event, the event is removed from normal use and remains recoverable for 30 days. It is then permanently deleted from the live service.
- Authentication challenges, sessions, security-limit records, operational logs and audit records follow documented schedules based on their security and accountability purposes.
- A website enquiry is delivered through our transactional-email provider to a monitored Leapa mailbox. The form does not create a Porta Account, CRM record or marketing profile. The resulting correspondence is kept only for as long as reasonably necessary to respond, follow up a genuine business request, protect Porta or meet a legal obligation.
- Encrypted backups are kept under a rotating schedule of up to 12 monthly recovery points. Data deleted from the live service may therefore remain in a protected backup until that backup expires. Backup data is isolated from ordinary use and is accessed only for recovery, integrity testing or a legal obligation. If an older backup is restored, completed deletion obligations are reapplied before normal service resumes.
- Separate transaction, tax, contract, security or dispute records may be kept for the period required or permitted by law even after service data is deleted.
An authorised customer may request earlier account closure or deletion. A guest may also request access, correction or deletion as described below. Deletion may be limited where retention is required by law, necessary for security or legal claims, or directed by the customer that controls the event data. We will explain any applicable limitation.
9. Offline data on iPads
After an event is prepared, Porta Frontline stores an app-scoped local event copy and pending changes, protected by iOS device and app isolation, so authorised staff can operate offline. The device-session credential is stored through iOS secure storage.
The customer is responsible for controlling physical access to its iPads, using device passcodes and current iPadOS security updates, and removing Event access when it is no longer required. Changing Staff Access removes the active event session from normal app use, subject to synchronising any pending work. iOS may retain app data in a device backup according to the customer's Apple and device-management settings.
10. Security
Porta uses measures designed for the nature of the data and operational risk, including encrypted network transport, scoped access, secure credential storage, customer and event isolation, rate limits, audit records, restricted production administration, encrypted off-server backups and recovery testing.
No system is completely secure. Customers must protect Staff Access codes, authorised devices and organiser email accounts and must contact us promptly if they believe access has been compromised.
11. Cookies and local storage
Porta's public website does not use advertising or analytics cookies. Porta Dashboard uses an HttpOnly session cookie, a security token and local browser storage needed for authentication, security and user-selected appearance. Porta Frontline uses app-scoped storage for the prepared event, offline changes, device settings and secure session credentials. We do not use these technologies for third-party advertising or cross-site tracking.
12. Privacy rights and requests
A person may ask whether we hold personal data about them and may request access, correction or deletion. Depending on applicable law, a person may also have rights to receive a portable copy, object to or restrict processing, withdraw consent, opt out of a sale or sharing, limit use of sensitive personal information, and complain to a privacy regulator. We do not discriminate against a person for exercising an applicable privacy right. Porta does not sell personal data or share it for cross-context behavioural advertising.
Requests may be made at https://porta.events/privacy#choices or by emailing
privacy@porta.events. Please provide enough information to identify the
relevant account, event or organiser without sending unnecessary identity
documents. We may need to verify the requester's identity and authority.
If the request concerns a guest list controlled by a customer, we may refer the request to that customer or consult the customer before acting. We will not disclose information about another person or account. An authorised agent may submit a request where local law permits, subject to verification of the agent's authority.
Additional information for people in the EEA, United Kingdom, California and
other listed regions is available at
https://porta.events/privacy#regional-rights.
People in the EEA or United Kingdom may complain to the supervisory authority
where they live or work, or where they believe a data-protection infringement
occurred. We encourage contacting us first so we can try to resolve the issue.
13. Children
Porta is a business event-operations service and is not directed to children. Customers must have appropriate authority and provide any notices or consents required before entering a child's personal data into Porta.
14. Changes to this policy
We may update this policy when Porta, our providers or legal requirements change. We will publish the updated policy with a new effective date and give additional notice where a material change requires it.
15. Contact us
Leapa Systems Limited
1104A, 317-319 Des Voeux Road Central, Sheung Wan, Hong Kong
Privacy: privacy@porta.events
Support: support@porta.events
Telephone: +852 3426 3692
For Hong Kong personal-data matters, individuals may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong.
Contact details for any EEA or United Kingdom representative required for the markets in which Porta is offered will be published in the Regional Privacy Notice before those markets are enabled.
Privacy Choices
Porta gives customers, authorised staff and event guests ways to ask about personal data handled through the service.
Make a request
Email privacy@porta.events with one of these subjects:
- Access request — ask whether Porta holds personal data about you and request a copy where applicable.
- Correction request — identify personal data you believe is inaccurate and provide the correct information.
- Deletion request — ask for personal data to be deleted where applicable.
- Consent or objection request — withdraw a consent you previously gave to Leapa or object to a particular use.
- Privacy question — ask how Porta handles a particular category of data.
Please include:
- your name and a safe way to contact you;
- whether you are a customer user, event staff member or event guest;
- the relevant organisation and Event, if known;
- enough detail to locate the information or understand the request.
Do not send a passport, identity card, complete guest list, Staff Access code, QR credential or one-time sign-in code with the initial request. We may ask for proportionate verification after reviewing the request.
Guest-list requests
An event organiser normally controls why its guest list and attendance data is used. If a request concerns that data, contacting the organiser may be the fastest route. Leapa may forward the request to, or consult, the responsible customer before acting. We will not disclose another person's data or confidential event information.
Customer controls
Authorised Porta Dashboard users can correct guest records, export Event data and choose Delete Event. A deleted Event is removed from normal use, recoverable for 30 days and then deleted from the live service. Backup copies expire under the protected rotation described in the Privacy Policy.
Account closure and organisation-wide export or deletion requests must be made
by an authorised Customer representative through support@porta.events or
privacy@porta.events.
Response and limitations
We will acknowledge a request, verify identity and authority where needed, and respond within the period required by applicable law. A request may be limited where retention or non-disclosure is required by law, necessary to protect another person, needed for security or legal claims, or subject to the lawful instructions of the customer controlling the Event data. We will explain an applicable limitation.
For more information, read the Porta Privacy Policy at
https://porta.events/privacy.
Regional rights and regulator information are available at
https://porta.events/privacy#regional-rights.
Leapa Systems Limited
1104A, 317-319 Des Voeux Road Central, Sheung Wan, Hong Kong
Privacy: privacy@porta.events
Telephone: +852 3426 3692
Regional Privacy Notice
Effective date: 1 September 2026
Last updated: 28 August 2026
This notice supplements the Porta Privacy Policy for people whose personal data is protected by the laws described below. Leapa Systems Limited ("Leapa") provides Porta. Capitalised product names have the meanings given in the main Privacy Policy.
If this notice and the main Privacy Policy differ, this notice applies only to the extent required by the law that protects the person making the request. Rights may be subject to conditions, exceptions and identity verification.
European Economic Area
When the EU General Data Protection Regulation applies:
- the purposes and legal bases are described in sections 1 and 4 of the main Privacy Policy;
- a person may have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent where processing is based on consent;
- a person may complain to the data-protection authority where they live or work, or where they believe an infringement occurred;
- Leapa does not use solely automated decisions that produce legal or similarly significant effects;
- transfers from the EEA may use an adequacy decision, the European Commission's Standard Contractual Clauses or another permitted mechanism, with supplementary measures where appropriate; and
- when Leapa is a processor for a customer, the customer remains responsible for the lawful basis and primary notice for its Event and Guest data, and Leapa supports the customer under applicable data-processing terms.
United Kingdom
When the UK GDPR applies, people have corresponding rights to be informed, access, rectification, erasure, restriction, portability, objection and rights concerning automated decision-making. A person may complain to the UK Information Commissioner's Office.
Restricted transfers may use UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another permitted mechanism.
California
Where the California Consumer Privacy Act applies, a California resident may have rights to know, access, correct and delete personal information; receive a portable copy; opt out of sale or sharing; limit certain use and disclosure of sensitive personal information; and receive equal service and pricing after exercising a right.
Porta does not sell personal information, share it for cross-context behavioural advertising or use it for targeted advertising. We therefore do not currently provide a "Do Not Sell or Share My Personal Information" control. If that practice changes, the required control and notices must be introduced before the change. We do not knowingly sell or share the personal information of people under 16.
The categories collected, sources, purposes and recipient categories are described in sections 2, 3, 4 and 6 of the main Privacy Policy. Retention is described in section 8. An authorised agent may make a request, subject to verification allowed by law.
Canada
Where Canadian federal or provincial privacy law applies, a person may request access to and correction of their personal information and may challenge our compliance. Consent may be withdrawn for future use where processing is based on consent, subject to legal or contractual restrictions. Cross-border service providers may make information subject to the laws of their processing locations.
Australia and New Zealand
Where Australian or New Zealand privacy law applies, a person may request access to or correction of personal information and may complain about how it is handled. If a complaint is not resolved, the person may contact the Office of the Australian Information Commissioner or New Zealand Office of the Privacy Commissioner, as applicable.
Brazil
Where Brazil's Lei Geral de Proteção de Dados applies, a person may request confirmation and access, correction, anonymisation, blocking or deletion where applicable, portability, information about sharing, review of applicable automated decisions, and withdrawal of consent. A person may also complain to the Autoridade Nacional de Proteção de Dados. International transfers use a mechanism permitted by applicable Brazilian law.
Singapore and Japan
Where Singapore's Personal Data Protection Act or Japan's Act on the Protection of Personal Information applies, a person may exercise the access, correction, withdrawal, deletion or other rights available under the applicable law. Overseas transfers are protected as required by the relevant law.
Making a request
Use https://porta.events/privacy#choices or email
privacy@porta.events. The response process, organiser relationship and
identity-verification rules in the main Privacy Policy apply.
Controller contact
Leapa Systems Limited
1104A, 317-319 Des Voeux Road Central, Sheung Wan, Hong Kong
Email: privacy@porta.events
Telephone: +852 3426 3692