Privacy Policy

How we handle your personal data

Effective Date: September 16, 2025

1Introduction and Our Roles

This Privacy Policy explains how Evendoro handles personal data. We act in two distinct roles under GDPR, which we define below:

  • Data Controller: We act as a Data Controller when we determine the purpose and means of processing personal data. This applies to data we collect for our own business purposes, such as information from our website users, billing data, and direct account holders.
  • Data Processor: We act as a Data Processor when we process personal data on behalf of our clients, the event organizers ("Data Controllers"). This applies to all attendee data uploaded to the event apps.

2Data We Collect and Process as a Data Controller

When you interact directly with us (e.g., visiting our website, creating an account), we collect and process the following data for our own business purposes:

  • Account Information: Your name, email address, and password hash, which you provide when creating an account.
  • Billing & Contact Data: Your company's name, address, and contact details for billing and contract management.
  • Website Usage Data: Information about your visit to our website, such as IP address, browser type, and pages viewed, collected via cookies for analytics.

Lawful Basis for this Processing: We process this data based on the necessity to fulfill a contract with you, or for our legitimate interests in operating our business and providing you with a functional service.

3Data We Process on Behalf of Organizers (as a Data Processor)

The event organizer provides us with your data to power the event app. We process the following categories of personal data on their instructions:

  • Account & Profile Information: Your name, email address, company, job title, country, language, and other information provided by the event organizer.
  • Usage Data: Information about your interactions within the app, such as sessions you view and messages you send.
  • Technical Data: Your device ID, IP address, and other technical information necessary for the app to function.

We do not process any financial or sensitive data (e.g., credit card information).

Lawful Basis for this Processing: We process this data solely on the instructions of the event organizer, who is responsible for establishing the legal basis for processing your data (e.g., legitimate interests or consent).

4How We Process and Use Data

We process all data to:

  • Provide and maintain the event app's features (e.g., login, personalized agendas, and networking).
  • Enable communication within the app (e.g., push notifications and messaging).
  • Improve the app's functionality and performance.

5Data Sharing & Third-Party Processors

We do not sell your personal data. We use the following trusted third-party services to operate our platform. Not all of these services process attendee data — see Section 14 for the full Data Processing Agreement and the DPA-specific sub-processor list.

Hetzner, DigitalOcean

Infrastructure & Hosting

Cloudflare

Content Delivery, Security & Infrastructure

AWS (S3)

File & Document Storage

Postmark

Email Delivery to Attendees

Gmail (Google)

Business & Organizer Communications

Slack (Salesforce)

Internal Team Communications

Apple (APNs), Google (Firebase)

Mobile Push Notifications

Google Analytics (GA4)

Website Analytics (Consent)

Crisp

Customer Support Chat (Consent)

Zeeg GmbH

Demo Booking & Scheduling

Arcade Software Inc.

Interactive Demo.

6Cookies and Tracking

We use cookies and similar technologies to support essential app functions, such as maintaining your login session and measuring app performance. Non-essential cookies (analytics, live chat) are loaded only after you give consent via our cookie banner. See our Cookie Policy for details on each cookie type and how to control them.

7International Data Transfers

Your data is primarily stored on servers located within the EU. In cases where our sub-processors are based outside the EU (e.g., the United States), we ensure that your data is protected through appropriate legal safeguards, such as the use of Standard Contractual Clauses (SCCs), as required by GDPR.

8Your Data Rights

The party responsible for fulfilling your data rights depends on the type of data we hold:

For Event Data:

The event organizer is the Data Controller responsible for fulfilling your rights (e.g., the right to access, rectify, or erase your data). You should contact the event organizer directly. If they fail to respond in a timely manner, you may contact us at privacy@evendoro.com, and we will work with the organizer to help facilitate your request.

For Evendoro Account Data:

If you have created an account directly with us and wish to exercise your data rights (including your right to be forgotten), please contact us directly at privacy@evendoro.com.

9Data Retention

We retain personal data for the duration of the event as per the organizer's instructions. The event organizer, as the Data Controller, is responsible for establishing a retention schedule for their events, including for recurring or multi-event apps. We will retain and delete data according to their instructions, as long as such instructions comply with GDPR principles.

10Children's Privacy

Our services are not intended for children under the age of 16. We do not knowingly process personal data from children under this age without parental consent.

11Security

We use reasonable technical and organizational measures to protect your data, including data encryption, secure access controls, and regular security reviews. We are committed to protecting your data from unauthorized access, loss, or misuse.

12Changes to this Policy

We may update this policy from time to time. We will post any changes on our website and in the app with a new "Effective Date."

13Contact Us

If you have any questions or concerns about our Privacy Policy or data processing practices, please contact us at: privacy@evendoro.com.

14Data Processing Agreement

When event organizers ("Organizers") use Evendoro to manage attendee data, Evendoro acts as a Data Processor on their behalf. This section constitutes the Data Processing Agreement ("DPA") between Evendoro and the Organizer in accordance with GDPR Article 28. By entering into a Service Proposal with Evendoro, the Organizer agrees to the terms of this DPA.

Evendoro commits to the following obligations when processing Attendee Data on the Organizer's behalf:

  • Processing Instructions: Evendoro will process Attendee Data only on documented instructions from the Organizer, as set out in the applicable Service Proposal and these Terms.
  • Confidentiality: All personnel authorised to process Attendee Data are bound by appropriate confidentiality obligations.
  • Security: Evendoro implements appropriate technical and organisational measures to protect Attendee Data, in accordance with GDPR Article 32.
  • Data Breach Notification: Evendoro shall notify the Organizer without undue delay, and in no event later than 72 hours, after becoming aware of a personal data breach affecting Attendee Data. Evendoro will provide reasonable assistance to the Organizer in notifying relevant authorities or data subjects if required.
  • Sub-Processors: Evendoro uses the following sub-processors that may access Attendee Data. Equivalent data protection obligations are imposed on all of them. The Organizer will be notified in advance of any material changes.

    Hetzner, DigitalOcean

    Infrastructure & Hosting

    Cloudflare

    Content Delivery, Security & Infrastructure

    AWS (S3)

    File & Document Storage

    Postmark

    Email Delivery

    Apple (APNs), Google (Firebase)

    Mobile Push Notifications

  • Data Subject Rights: Evendoro will assist the Organizer in responding to data subject rights requests (including access, erasure, portability, and restriction) where technically feasible within the platform.
  • Data Return and Deletion: Evendoro will delete or return Organizer data upon written request or where required by applicable law, in line with standard procedures.
  • Audit and Assistance: Upon reasonable written request, Evendoro will provide information necessary to demonstrate compliance with this DPA and support the Organizer in carrying out data protection impact assessments (DPIAs) where required. Any such audits shall be conducted at the Organizer's sole expense and subject to reasonable advance notice and confidentiality obligations.
  • International Transfers: Where Attendee Data is transferred outside the EU/EEA, Evendoro will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required.

Data Protection Contact: For DPA-related enquiries, please contact us at privacy@evendoro.com.

A countersigned DPA addendum is available upon request for enterprise or institutional clients.