Industry · Event agencies

Event planning software for agenciesEvery client in their own brand.

One system for every client, each in their own brand, with the paperwork their procurement asks for. AirLST keeps website, invitation, guest list and report together per project, under your client’s domain and sender.

  1. 1
    Design per client

    Website, registration and ticket in the client’s corporate design, on their domain.

  2. 2
    Sender per client

    Invitations go out from the client’s verified sender.

  3. 3
    Handover with a report

    Reporting, survey and export to wrap up for the client.

01Rules

What your client’s procurement expects from the agency

Four rules that apply as soon as an agency handles attendee data for a client. For each: what it means for the project, and where it comes from.

01

Vendor oversight: FTC Safeguards Rule

Financial institutions select service providers that can keep customer information safe, require safeguards by contract and assess providers periodically. An agency working for a bank or insurer is such a provider, and so is the software behind it.

Source: 16 CFR 314.4 (Cornell LII)
02

Deletion passed down: CCPA

Californians can ask a business to delete their personal information, and the business tells its service providers to do the same. For an event, that request may reach the agency and its software.

Source: California Attorney General: CCPA
03

EU clients and events: Art. 28 GDPR

A processor works under a contract, uses sub-processors only with the client’s authorization and under the same obligations, and deletes or returns all data at the end of the service.

Source: Art. 28 GDPR (gdpr-info.eu)
04

Joint controllers: Art. 26 GDPR

If agency and client decide purposes and means together, they are joint controllers and need an arrangement on who meets which obligation.

Source: Art. 26 GDPR (gdpr-info.eu)

These summaries are not legal advice; what counts are your contracts and the requirements of your clients’ legal and privacy teams. How AirLST processes data is described in the Trust Center.

02Roles

Who decides in the agency, and what each needs

Project lead

How do we build the third project this week, in the client’s brand?

Event website, registration and invitation from a template, in the client’s corporate design and under their domain.

Event websites
Agency owner

Does one system for every client pay off?

One system instead of tools per project, list prices on the pricing page, partner terms on request.

Pricing
Privacy and security

What do we hand the client’s procurement team?

Data processing agreement, subprocessor list, hosting in Germany and AirLST’s TISAX assessment, collected in the Trust Center.

Trust Center
Account manager

What does the client get after the event?

Reporting with RSVPs, attendance and no-show rate, a post-event survey, and an export of the guest list.

Event reporting
04Product

What agencies ask for and how AirLST delivers it

Standard means: in the product and documented on the feature page. Custom build means: AirLST builds it for you in the project; scope and effort are part of the conversation.

RequirementStandardCustom buildMore
Brand and domain per clientEvent website and registration in the client’s corporate design, under their domain, without AirLST branding.–Event websites
Sender per clientInvitations from the client’s sender, with verified email address and domain.–Invitation emails
Templates for recurring formatsInvitation, registration page and confirmation set up once, copied per event or client.–Invitation emails
Reporting for the clientRSVPs, attendance and no-show rate per event, post-event survey, guest list export.–Event reporting
DPA and subprocessor listData processing agreement with AirLST and the subprocessor list for your client contract.–Trust Center
Tenants per clientSeparate tenants with their own logins, so each client sees only their events, are a custom build.–Custom development
Deletion log per projectA log of export and deletion of all attendee data at project end is a custom build.–Custom development
Billing per projectBilling per client or project and partner terms are available on request.–Custom development

Security and data protection

  • TISAX-assessed

    AirLST has been assessed under TISAX, the information security standard of the automotive industry.

    TISAX at AirLST
  • Hosted in Germany

    The platform runs on Amazon Web Services in Germany. The AWS infrastructure holds ISO/IEC 27001, SOC 2 and BSI C5; these are certifications of our hosting provider, not of AirLST.

    Data hosting
  • GDPR and DPA

    Processing follows the GDPR, with a data processing agreement; the current list of subprocessors is provided with it.

    GDPR
  • Signed at the guest

    Consents and NDAs are signed digitally and stored with the guest record; the entrance sees at the scan whether the signature is there.

    Event access control
Paid eventsStripeMolliePayPal

Tickets and fees are paid in the registration form through Stripe, Mollie or PayPal. Revenue goes straight to your account; card data stays with the provider.

Event ticketing
05Setup

How agencies typically set up AirLST

  1. 01

    One design per client

    Colors, type and logo of the client in website, registration, invitation and ticket.

  2. 02

    Domain and sender

    Own domain for the event website, verified sender for the invitations.

  3. 03

    One template per format

    Conference, customer day and incentive each set up once, copied per project.

  4. 04

    Report as handover

    Reporting, survey and export as the wrap-up for the client.

  5. 05

    Contract before kickoff

    DPA with AirLST and the subprocessor list in the package for client procurement.

06Proof

What is documented, and what we settle on request

Case study · Telefónica2,000attendees, one design

Templates in the corporate design, events planned in-house

Landing pages, tickets and emails adjusted by drag and drop; the same principle carries templates per client.

Read the case study
Product · White label

Guests see your client, not the software

Corporate design, own domain and own sender per event: event websites.

  • Corporate design
  • Own domain
  • Own sender
Partners · Terms

Partner terms on request

What applies to your agency we discuss in a meeting; list prices are on the pricing page.

  • Meeting
  • Pricing

The agency is a vendor

For a client in financial services, the agency is a service provider under the FTC Safeguards Rule: selected for its ability to keep customer information safe, bound by contract and assessed periodically (16 CFR 314.4). Clients in other industries ask the same questions in their security questionnaires.

The client buys the event. Their procurement checks the chain behind it.

The chain behind the event

For events with attendees in the EU, a sub-processor needs the client’s authorization and carries the same obligations as the agency (Art. 28 GDPR). For the agency that means: contract with the client, contract with the software, list of subprocessors. What AirLST provides is in the Trust Center.

The project ends with deletion

Deletion requests under the CCPA are passed on to service providers (California Attorney General), and under the GDPR a processor deletes or returns all data at the end of the service. In AirLST the agency exports guest list, reporting and survey as the handover; a deletion log per project is available through custom development.

08FAQ

Frequently asked questions about event planning software for agencies

What does a client’s procurement team ask an event agency for?

Usually a contract on how attendee data is handled, the list of vendors behind the agency, and evidence of security. Under the FTC Safeguards Rule, financial institutions must select service providers that can maintain appropriate safeguards, require them by contract and assess them periodically (16 CFR 314.4). What AirLST provides for that, from the data processing agreement to the subprocessor list, is in the Trust Center.

What happens to attendee data when the project ends?

Under the CCPA, consumers can ask a business to delete their data and the business tells its service providers to do the same (California Attorney General); under the GDPR, a processor deletes or returns all data at the end of the service, as the client chooses (Art. 28 GDPR). In AirLST the agency exports guest list and report for the client; a deletion log per project is a custom build.

Is an agency a processor or a joint controller under the GDPR?

It depends on who decides. An agency that only follows the client’s instructions is a processor and needs a contract under Art. 28; an agency that decides purposes and means together with the client can be a joint controller under Art. 26, with an arrangement on who does what (Art. 26 GDPR). Agency and client settle this with their privacy teams.

Can every client get their events in their own brand, without AirLST branding?

Yes. Event website and registration run in the client’s corporate design under their domain; guests see the client, not the software behind it (event websites). Invitations go out from the client’s sender with a verified sender domain (invitation emails).

Can clients see only their own events?

Separate tenants per client with their own logins are a custom build. Which separation your clients require is part of the conversation.

Are there partner terms for agencies?

Partner terms are available on request. List prices are on the pricing page; what applies to your agency we discuss in a meeting.
Events made easy

Three clients. Three brands. One system.

In 15 minutes we show you how brand, domain and sender per client, templates and the handover after the project come together in AirLST, and talk about partner terms.