Privacy Policy
InternationalVenues.com, the Owner Portal and VenuClaw — operated by Jigsaw Conferences Ltd. Last updated 26 August 2026.
Who we are
Jigsaw Conferences Ltd (company number 04788489, 3rd Floor, 45 Albemarle Street, London W1S 4JL, UK) is the data controller for personal data processed on this Platform. Contact: it@jigsawconferences.co.uk, +44 (0)800 121 4470. This policy applies worldwide, with region-specific rights explained below.
What we collect and why
- Enquiries and briefs (organisers): name, work contact details and event requirements — to deliver our venue-finding service and send proposals. Lawful bases: contract and legitimate interests.
- Venue owner accounts: name, business email, phone, venue details, listing content and account activity — to operate the Owner Portal, review and publish listings and manage enquiries. Lawful bases: contract and legitimate interests.
- Subscriptions and billing: handled by Stripe. We store subscription status and Stripe references, never full card details. Lawful bases: contract and legal obligation.
- Owner Help and support: support conversations, problem reports and limited technical context (page, venue, browser type, error references). Diagnostic data passes through an automated redaction layer that removes passwords, tokens, cookies and payment data before storage or emailing our IT team. Lawful basis: legitimate interests (providing support and fixing faults).
- Service telemetry: short-lived request references, aggregate performance and error metrics — to keep the Platform secure and reliable. Lawful basis: legitimate interests.
- Marketing: occasional service emails to business contacts, with opt-out in every message. We do not sell personal data and we do not send consumer marketing without consent.
VenuClaw AI connections (MCP)
When you connect VenuClaw to an AI assistant (such as ChatGPT, Claude, Microsoft 365 Copilot or another MCP-compatible tool), VenuClaw receives only the information your AI sends when it performs venue research — typically a city, keywords, capacity or a venue identifier. VenuClaw:
- is read-only — it cannot create bookings, enquiries or any changes on your behalf;
- cannot read your AI conversations, memories or files;
- returns publicly listed venue information only — never private owner, customer or account data;
- does not use your queries to train any AI model;
- records aggregate, privacy-safe usage counts without user identification, fingerprinting or credential storage;
- never receives or stores OAuth tokens or passwords from consumer AI connections (the Microsoft 365 enterprise connection validates organisation sign-in tokens transiently and does not store them).
You can disconnect VenuClaw at any time from your AI assistant's connector or app settings.
AI processing on the Platform
Some features (the in-portal Owner Help assistant and drafting of Journal articles) use large-language-model providers as processors. Support messages sent to the assistant are redacted of credentials before processing, are used only to generate the response, and are not used by us to train AI models. Do not include sensitive personal data in support messages.
Who we share data with
- Venues and organisers: we share enquiry details with relevant venues (and venue responses with organisers) to arrange your event — this is the core service.
- Processors: Stripe (payments), Microsoft (business email), Cloudflare (hosting, security and image storage), our cloud hosting provider, and AI model providers for the features above — each under contract and only as needed.
- Legal: where required by law, to enforce our terms, or in a business transfer.
International transfers
We are UK-based. Where data is transferred outside the UK/EEA (for example to US-based processors), we rely on adequacy regulations, the UK International Data Transfer Agreement/Addendum or EU Standard Contractual Clauses, plus supplementary safeguards.
Security and retention
We apply layered security controls (encryption in transit, access controls, tenant isolation, automated secret-redaction in diagnostics) and are certified under the UK Government Cyber Essentials scheme. We keep personal data only as long as needed for the purposes above or to meet legal obligations, then delete or anonymise it: enquiry records for the business relationship plus statutory limitation periods; support cases while open plus a reasonable audit period; billing records as required by tax law.
Cookies
We use strictly necessary cookies (sessions, security) and limited analytics. See our Cookie Policy for details and choices.
Your rights — UK and EU/EEA
Under UK GDPR and EU GDPR you may request access, correction, deletion, restriction, portability, and may object to processing based on legitimate interests, or withdraw consent at any time. Contact it@jigsawconferences.co.uk. You may complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU supervisory authority.
Your rights — USA (including California)
We do not sell or share personal information for cross-context behavioural advertising as defined by the CCPA/CPRA. US residents may request access, correction or deletion of their personal information, and will not be discriminated against for exercising these rights, by contacting it@jigsawconferences.co.uk.
Children
The Platform is a business service and is not directed at children under 18; we do not knowingly collect their data.
Changes
We will post updates to this policy here with a revised date; material changes will be highlighted on the Platform.
See also: Terms & Conditions · VenuClaw Everywhere — what VenuClaw can access.
