What is GDPR?
The EU General Data Protection Regulation, GDPR (2016/679) is a regulation in EU law on data protection and privacy for all individuals within the European Union. It replaces the 1995 Data Protection Directive (Directive 95/46/EC). The GDPR lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.
What we have done in order to comply with the General Data Protection Regulation (GDPR)
The security and protection of our customers’ data is of paramount importance to us. We welcome the GDPR as directed by the EU in order for every company to be more transparent about how customers’ data is used. To that end, our Terms of Service, Privacy Statement and Data Processing Agreement have been written with the GDPR in mind, and ReactLive has been built from the start to meet its requirements.
Our Terms of Service & Privacy Statement
Our Terms of Service, Privacy Statement and Data Processing Agreement are written with particular emphasis on being easy to understand and as transparent as possible. In summary, ReactLive stores all personal data in the EU. Any personal data collected adheres to the “Privacy by default” guidelines as stated in the GDPR. This means that the strictest privacy settings are applied to your personal data by default. The data collected is used solely for the purposes of providing a service to our customers and is not used for marketing purposes or sold to any third party under any circumstances.
AI processing and the GDPR
ReactLive uses AI to help event organisers run live events: drafting answers to audience questions, grouping duplicate questions, checking contributions before they are shown to the audience, suggesting polls, and producing event reports. We have designed these features to meet the GDPR’s requirements for lawful, transparent and accountable processing.
Processing stays in the EU, on our infrastructure. ReactLive’s AI features run on open-source models hosted by ReactLive on our own infrastructure in the EU. Audience contributions and organiser material are not transmitted to any third-party AI service. No customer data is used to train or fine-tune our models.
Human oversight by design. Every AI agent in ReactLive runs on a setting the event organiser controls — Off, Assist or Auto. On the default Assist setting, a person approves any consequential action (an answer, a poll, a hold) before it happens. Auto mode performs only the types of work the organiser has approved in advance, within rules the organiser defines, and a person can take over at any moment. ReactLive does not make decisions producing legal or similarly significant effects on data subjects by solely automated means (GDPR Article 22).
Nothing is silently removed. Contributions held by the Protect agent are never deleted automatically; they remain with a moderator, with the reason attached, for a human decision.
Every AI action is logged. AI actions are recorded in the event’s audit history alongside human actions, so an organiser can show what was processed, what was proposed, and who approved it.
Grounded, cited answers. AI-drafted answers are produced only from material the organiser has supplied and carry a reference to their source, so organisers can verify what the AI relied on.
What we have built into the ReactLive Console in order to comply with the GDPR
Privacy settings
The Console contains a privacy section that allows our customers to set their data requirements for each event — including whether participants must consent before submitting personal data, and what personal data (if any) is requested — and to review the sub-processors that ReactLive uses.
Full control over participant data
Under the GDPR data subjects have the right to access the personal data stored on their behalf. In addition, they have the Right to be Forgotten, the Right to Portability and the Right to Rectification of their data. Should a participant exercise their rights, ReactLive gives you (the Controller) complete control to accommodate those requests from the Console.
Access to personal data
Data subjects can request and access any data that a data controller is holding on them and find out whether that data is being processed, where it is held, and for what purpose. From the participant record, the data controller has access to and can manage all of the personal data that ReactLive holds for that participant.
Right to be forgotten
The GDPR states that, if requested by the data subject, a company must erase the personal data it holds on that data subject and cease any further processing of that data. If requested to do so, the data controller can erase the participant’s data from the participant record in the Console.
Right to portability
The GDPR requires that a data subject be able to receive personal data concerning them in a commonly used, machine-readable format free of charge, and to transmit it to another controller. The data controller can export participant records in an electronic format from the Console.
Right to rectification
The data subject has the right to rectification of inaccurate personal data concerning them. If requested to do so, the data controller can update the participant’s data from the participant record in the Console.
Extra data management options for Data Controllers
Delete workspaces, events & accounts
On request, customers have the option to delete their workspace on ReactLive, individual events, and/or team member accounts. Customers can add and remove team members as necessary at any time.
Audit history & data breach management
Organisations need to be able to capture security events in the form of audit logs to confirm whether a breach has taken place, measure its impact, and determine what must be reported to the supervisory authority and, ultimately, the affected data subjects. The ReactLive audit history tracks anything in the Console that can be added, updated or deleted — including workspaces, events, team members, participant contributions and every AI action — recording who (or which agent) made the change and when. This gives an administrator a log to refer to in case of a security incident or an audit.
Access control
Events can be made invite-only, with sign-in via Google, Microsoft or email. Role-based access controls what each team member can see and do in the Console. Enterprise plans add SSO.
Privacy Statement for data controllers
The privacy settings include a place for our customers to reference their own Privacy Statement. If the organiser chooses to request consent from participants before they submit personal data, the organiser’s Privacy Statement is linked in the consent statement.
Individual event settings
Consent for personal data to be processed
ReactLive can display a consent checkbox on the audience page before a participant is asked for any personal data (for example, a name or email address). This allows the data controller to explicitly obtain consent from the data subject before collecting personal data from them. Where an event does not request personal data, participants can take part without providing any.
Account creation on the ReactLive website
On creating an account, ReactLive needs certain personal data in order to allocate the account correctly. The information we collect is name and email address. Users must agree to the ReactLive Terms of Service and Privacy Statement at this stage, and wherever a ReactLive account is created — for example, when a new user is invited to an existing workspace.
Sub-processors
ReactLive uses the following sub-processors to provide the service. We will update this list, and notify customers under the terms of our Data Processing Agreement, before any new sub-processor is used.
| Sub-processor | Purpose | Location |
|---|---|---|
| AWS | Infrastructure hosting, including the servers on which our AI models run | EU |
| Azure | Infrastructure hosting, including the servers on which our AI models run | EU |
| Sendgrid | Transactional email (e.g. reply notifications, account emails) | US |
| Twilio | Transactional email (e.g. reply notifications, account emails) | US |
| AWS | Transactional email (e.g. reply notifications, account emails) | EU |
| Stripe | Subscription billing | EU |
No third-party AI service providers are used. AI processing is performed on ReactLive’s own infrastructure listed above.
Revised: 06 October, 2026
ReactLive Ltd. · Questions about GDPR or data protection: hello@reactlive.com