Event planning software for agenciesEvery client in their own brand.
One system for every client, each in their own brand, with the paperwork their procurement asks for. AirLST keeps website, invitation, guest list and report together per project, under your client’s domain and sender.
- 1Design per client
Website, registration and ticket in the client’s corporate design, on their domain.
- 2Sender per client
Invitations go out from the client’s verified sender.
- 3Handover with a report
Reporting, survey and export to wrap up for the client.
What your client’s procurement expects from the agency
Four rules that apply as soon as an agency handles attendee data for a client. For each: what it means for the project, and where it comes from.
Vendor oversight: FTC Safeguards Rule
Financial institutions select service providers that can keep customer information safe, require safeguards by contract and assess providers periodically. An agency working for a bank or insurer is such a provider, and so is the software behind it.
Source: 16 CFR 314.4 (Cornell LII)Deletion passed down: CCPA
Californians can ask a business to delete their personal information, and the business tells its service providers to do the same. For an event, that request may reach the agency and its software.
Source: California Attorney General: CCPAEU clients and events: Art. 28 GDPR
A processor works under a contract, uses sub-processors only with the client’s authorization and under the same obligations, and deletes or returns all data at the end of the service.
Source: Art. 28 GDPR (gdpr-info.eu)Joint controllers: Art. 26 GDPR
If agency and client decide purposes and means together, they are joint controllers and need an arrangement on who meets which obligation.
Source: Art. 26 GDPR (gdpr-info.eu)These summaries are not legal advice; what counts are your contracts and the requirements of your clients’ legal and privacy teams. How AirLST processes data is described in the Trust Center.
Who decides in the agency, and what each needs
How do we build the third project this week, in the client’s brand?
Event website, registration and invitation from a template, in the client’s corporate design and under their domain.
Event websitesDoes one system for every client pay off?
One system instead of tools per project, list prices on the pricing page, partner terms on request.
PricingWhat do we hand the client’s procurement team?
Data processing agreement, subprocessor list, hosting in Germany and AirLST’s TISAX assessment, collected in the Trust Center.
Trust CenterWhat does the client get after the event?
Reporting with RSVPs, attendance and no-show rate, a post-event survey, and an export of the guest list.
Event reportingTypical work in an event agency
How each event runs in AirLST is described on the linked page. Here only why it comes up in an agency.
What agencies ask for and how AirLST delivers it
Standard means: in the product and documented on the feature page. Custom build means: AirLST builds it for you in the project; scope and effort are part of the conversation.
| Requirement | Standard | Custom build | More |
|---|---|---|---|
| Brand and domain per clientEvent website and registration in the client’s corporate design, under their domain, without AirLST branding. | – | Event websites | |
| Sender per clientInvitations from the client’s sender, with verified email address and domain. | – | Invitation emails | |
| Templates for recurring formatsInvitation, registration page and confirmation set up once, copied per event or client. | – | Invitation emails | |
| Reporting for the clientRSVPs, attendance and no-show rate per event, post-event survey, guest list export. | – | Event reporting | |
| DPA and subprocessor listData processing agreement with AirLST and the subprocessor list for your client contract. | – | Trust Center | |
| Tenants per clientSeparate tenants with their own logins, so each client sees only their events, are a custom build. | – | Custom development | |
| Deletion log per projectA log of export and deletion of all attendee data at project end is a custom build. | – | Custom development | |
| Billing per projectBilling per client or project and partner terms are available on request. | – | Custom development |
Security and data protection
- TISAX-assessed
AirLST has been assessed under TISAX, the information security standard of the automotive industry.
TISAX at AirLST - Hosted in Germany
The platform runs on Amazon Web Services in Germany. The AWS infrastructure holds ISO/IEC 27001, SOC 2 and BSI C5; these are certifications of our hosting provider, not of AirLST.
Data hosting - GDPR and DPA
Processing follows the GDPR, with a data processing agreement; the current list of subprocessors is provided with it.
GDPR - Signed at the guest
Consents and NDAs are signed digitally and stored with the guest record; the entrance sees at the scan whether the signature is there.
Event access control
Tickets and fees are paid in the registration form through Stripe, Mollie or PayPal. Revenue goes straight to your account; card data stays with the provider.
Event ticketingHow agencies typically set up AirLST
- 01
One design per client
Colors, type and logo of the client in website, registration, invitation and ticket.
- 02
Domain and sender
Own domain for the event website, verified sender for the invitations.
- 03
One template per format
Conference, customer day and incentive each set up once, copied per project.
- 04
Report as handover
Reporting, survey and export as the wrap-up for the client.
- 05
Contract before kickoff
DPA with AirLST and the subprocessor list in the package for client procurement.
What is documented, and what we settle on request
Templates in the corporate design, events planned in-house
Landing pages, tickets and emails adjusted by drag and drop; the same principle carries templates per client.
Read the case studyGuests see your client, not the software
Corporate design, own domain and own sender per event: event websites.
- Corporate design
- Own domain
- Own sender
Partner terms on request
What applies to your agency we discuss in a meeting; list prices are on the pricing page.
- Meeting
- Pricing
The agency is a vendor
For a client in financial services, the agency is a service provider under the FTC Safeguards Rule: selected for its ability to keep customer information safe, bound by contract and assessed periodically (16 CFR 314.4). Clients in other industries ask the same questions in their security questionnaires.
The client buys the event. Their procurement checks the chain behind it.
The chain behind the event
For events with attendees in the EU, a sub-processor needs the client’s authorization and carries the same obligations as the agency (Art. 28 GDPR). For the agency that means: contract with the client, contract with the software, list of subprocessors. What AirLST provides is in the Trust Center.
The project ends with deletion
Deletion requests under the CCPA are passed on to service providers (California Attorney General), and under the GDPR a processor deletes or returns all data at the end of the service. In AirLST the agency exports guest list, reporting and survey as the handover; a deletion log per project is available through custom development.


