How we handle your personal data
This Privacy Policy explains how Evendoro handles personal data. We act in two distinct roles under GDPR, which we define below:
When you interact directly with us (e.g., visiting our website, creating an account), we collect and process the following data for our own business purposes:
Lawful Basis for this Processing: We process this data based on the necessity to fulfill a contract with you, or for our legitimate interests in operating our business and providing you with a functional service.
The event organizer provides us with your data to power the event app. We process the following categories of personal data on their instructions:
We do not process any financial or sensitive data (e.g., credit card information).
Lawful Basis for this Processing: We process this data solely on the instructions of the event organizer, who is responsible for establishing the legal basis for processing your data (e.g., legitimate interests or consent).
We process all data to:
We do not sell your personal data. We use the following trusted third-party services to operate our platform. Not all of these services process attendee data — see Section 14 for the full Data Processing Agreement and the DPA-specific sub-processor list.
Infrastructure & Hosting
Content Delivery, Security & Infrastructure
File & Document Storage
Email Delivery to Attendees
Business & Organizer Communications
Internal Team Communications
Mobile Push Notifications
Website Analytics (Consent)
Customer Support Chat (Consent)
Demo Booking & Scheduling
Interactive Demo.
We use cookies and similar technologies to support essential app functions, such as maintaining your login session and measuring app performance. Non-essential cookies (analytics, live chat) are loaded only after you give consent via our cookie banner. See our Cookie Policy for details on each cookie type and how to control them.
Your data is primarily stored on servers located within the EU. In cases where our sub-processors are based outside the EU (e.g., the United States), we ensure that your data is protected through appropriate legal safeguards, such as the use of Standard Contractual Clauses (SCCs), as required by GDPR.
The party responsible for fulfilling your data rights depends on the type of data we hold:
The event organizer is the Data Controller responsible for fulfilling your rights (e.g., the right to access, rectify, or erase your data). You should contact the event organizer directly. If they fail to respond in a timely manner, you may contact us at privacy@evendoro.com, and we will work with the organizer to help facilitate your request.
If you have created an account directly with us and wish to exercise your data rights (including your right to be forgotten), please contact us directly at privacy@evendoro.com.
We retain personal data for the duration of the event as per the organizer's instructions. The event organizer, as the Data Controller, is responsible for establishing a retention schedule for their events, including for recurring or multi-event apps. We will retain and delete data according to their instructions, as long as such instructions comply with GDPR principles.
Our services are not intended for children under the age of 16. We do not knowingly process personal data from children under this age without parental consent.
We use reasonable technical and organizational measures to protect your data, including data encryption, secure access controls, and regular security reviews. We are committed to protecting your data from unauthorized access, loss, or misuse.
We may update this policy from time to time. We will post any changes on our website and in the app with a new "Effective Date."
If you have any questions or concerns about our Privacy Policy or data processing practices, please contact us at: privacy@evendoro.com.
When event organizers ("Organizers") use Evendoro to manage attendee data, Evendoro acts as a Data Processor on their behalf. This section constitutes the Data Processing Agreement ("DPA") between Evendoro and the Organizer in accordance with GDPR Article 28. By entering into a Service Proposal with Evendoro, the Organizer agrees to the terms of this DPA.
Evendoro commits to the following obligations when processing Attendee Data on the Organizer's behalf:
Hetzner, DigitalOcean
Infrastructure & Hosting
Cloudflare
Content Delivery, Security & Infrastructure
AWS (S3)
File & Document Storage
Postmark
Email Delivery
Apple (APNs), Google (Firebase)
Mobile Push Notifications
Data Protection Contact: For DPA-related enquiries, please contact us at privacy@evendoro.com.
A countersigned DPA addendum is available upon request for enterprise or institutional clients.