EventKP

Legal

Privacy Policy

GDPR-focused privacy policy explaining processing of account, RSVP, guest, marketplace, and billing data.

Last updated: June 29, 2026Version 9PDF (soon)

1. Overview

This Privacy Policy explains how EventKP GmbH ("EventKP", "we", "us") collects, uses, discloses, and protects personal data when you visit our marketing websites, create an account, build event experiences, collect RSVPs, use the vendor marketplace, participate as an agency or vendor, or otherwise interact with our Services.

We are committed to GDPR-aligned privacy practices for customers in the European Economic Area, United Kingdom, Switzerland, and Turkey (KVKK). This policy should be read together with our Terms of Service, Cookie Policy, and Data Processing Agreement where EventKP processes data on your behalf.

If you are a guest responding to an RSVP hosted by an EventKP customer, the event organizer is typically the data controller for your RSVP data. This policy explains EventKP's role as platform provider and, where applicable, independent controller for account and billing data.

2. Data Controller and Contact

EventKP GmbH is the data controller for personal data processed in connection with your EventKP account, billing, platform security, product analytics, and direct marketing communications you opt into.

Contact: [email protected]. Data Protection Officer (where appointed): [email protected]. Postal: EventKP GmbH, Privacy Office, Musterstraße 1, 10115 Berlin, Germany.

For event-specific guest data collected through customer-published forms, the event organizer or agency remains responsible for providing privacy notices and handling data subject requests, while EventKP acts as processor under the DPA.

3. Categories of Personal Data

Account data: name, email, password hash, organization, role, locale preferences, and authentication logs. Billing data: subscription plan, invoices, payment method tokens (processed by payment providers), tax identifiers where provided.

Event and website data: event names, dates, venues, published content, custom domains, theme selections, and configuration metadata. RSVP and guest data: guest names, email, phone (optional), attendance responses, dietary requirements, plus-one details, check-in timestamps, and communication history.

Marketplace data: vendor profiles, service categories, quotes, messages, reviews, and transaction metadata. Usage data: IP address, device identifiers, browser type, pages viewed, feature usage, crash reports, and security signals. Marketing data: newsletter subscriptions and campaign engagement where consented.

4. Sources of Data

We collect data directly from you when you register, complete forms, upload guest lists, configure events, or contact support. We also receive data from integrated services you connect (e.g., payment processors, email providers) and from cookies or similar technologies as described in our Cookie Policy.

Event organizers may import guest contact details they obtained lawfully. You must not upload data without proper consent or legal basis. Vendors and agencies may provide business contact information for marketplace listings.

We may receive fraud prevention signals and deliverability metrics from subprocessors to protect the platform and improve communications.

5. Purposes and Legal Bases (GDPR)

Service delivery (Art. 6(1)(b) GDPR): creating accounts, hosting event websites, processing RSVPs, enabling marketplace interactions, providing customer support, and fulfilling our contract with you.

Security and fraud prevention (Art. 6(1)(f) GDPR): monitoring abuse, protecting accounts, investigating incidents, and maintaining audit logs. Legitimate interests balanced against your rights.

Legal compliance (Art. 6(1)(c) GDPR): tax, accounting, regulatory requests, and responding to lawful authority demands. Marketing with consent (Art. 6(1)(a) GDPR): newsletters and promotional emails where you opt in, with easy unsubscribe.

6. RSVP and Guest Data Processing

When you use RSVP features, guest personal data is stored in tenant-isolated databases associated with your account. You determine which fields are mandatory, retention periods, and export policies supported by your plan.

EventKP provides encryption in transit, role-based access, and optional data residency configurations where available. You must configure guest-facing privacy notices linking to your policies or EventKP-hosted legal pages as appropriate.

Guests may contact the event organizer to exercise rights. EventKP assists customers with technical export and deletion tools but does not adjudicate organizer-guest disputes.

7. Marketplace and Vendor Data

Vendor profiles display business names, descriptions, service areas, portfolio media, and contact channels you choose to publish. Quote and messaging data is visible to participating event owners and agencies according to permission settings.

We process marketplace data to facilitate discovery, reputation signals, dispute tooling, and platform integrity. Vendors must not share unnecessary personal data in public listings.

Agencies managing client events may access vendor interactions on behalf of clients when authorized. Access is logged for security review in supported plans.

8. Sharing and Disclosure

We share data with subprocessors that help us operate the Services—cloud hosting, email delivery, payment processing, analytics, customer support tools, and AI inference providers. A current subprocessor list is maintained in our DPA and trust documentation.

We may disclose data if required by law, court order, or governmental request, or to protect rights, safety, and integrity of users and the platform. Business transfers: in mergers or acquisitions, data may transfer subject to continued protections.

We do not sell personal data. We do not share guest lists with unrelated third parties for their marketing.

9. International Transfers

EventKP may process data in the EU and other countries where subprocessors operate. When transferring personal data outside the EEA or UK, we implement appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or supplementary measures.

Customers requiring EU-focused processing should review available data residency options and subprocessors in their plan documentation.

Transfer impact assessments are conducted for high-risk processing and updated when subprocessors change materially.

10. Data Retention

Account data is retained while your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. Billing records are retained per tax and commercial law requirements.

Guest and RSVP data retention is configurable by event owners within plan limits. Upon account deletion, we delete or anonymize data according to our backup cycles and legal holds.

Security logs may be retained longer for incident investigation and compliance audits.

11. Security Measures

We implement encryption in transit (TLS), encryption at rest for sensitive stores, access controls, least-privilege permissions, vulnerability management, and employee security training.

Production access is restricted and logged. We perform regular reviews of subprocessors' security posture. No method of transmission or storage is 100% secure.

You must protect credentials and configure team permissions appropriately. Report suspected breaches to [email protected] promptly.

12. Your Rights Under GDPR

Depending on jurisdiction, you may have rights to access, rectify, erase, restrict processing, data portability, object to processing based on legitimate interests, and withdraw consent without affecting prior lawful processing.

To exercise rights relating to your EventKP account, email [email protected] with verification information. We respond within statutory timelines (typically one month under GDPR).

You may lodge a complaint with a supervisory authority, e.g., Berlin Commissioner for Data Protection and Freedom of Information, or your local authority.

13. Turkey (KVKK) Notice

For users in Turkey, personal data may be processed under KVKK Law No. 6698 for purposes stated in this policy. You may have rights to learn whether data is processed, request information, correction, deletion, and object to automated decisions where applicable.

Cross-border transfers comply with KVKK requirements including consent or permitted transfer mechanisms where required.

Applications may be submitted to [email protected] in Turkish or English.

14. Children's Data

EventKP Services are not directed to children under 16. We do not knowingly collect children's personal data through our account registration flows.

Event organizers may collect family event attendance including minors as part of guest lists. Organizers are responsible for lawful bases and parental notices where required.

Contact [email protected] if you believe we collected a child's data inappropriately.

15. Automated Decision-Making and AI

We may use automated systems for fraud detection, spam prevention, and product recommendations. These do not produce legal effects on you without human review unless disclosed otherwise.

AI-assisted content generation for event websites or legal drafts produces suggestions requiring human review before publication. AI providers may process prompts according to their policies and our data processing agreements.

You can contact us for information about significant automated processing affecting your account.

16. Cookies and Similar Technologies

We use cookies and similar technologies as described in our Cookie Policy. Essential cookies support authentication and security. Analytics and marketing cookies require consent where mandated.

You can manage preferences via our cookie banner and browser settings. Blocking essential cookies may impair functionality.

17. Marketing Communications

We send product updates and promotional emails only with consent or where permitted as soft opt-in for similar services. Every marketing email includes an unsubscribe link.

Event organizers send transactional and invitation emails to guests under their own responsibility and must honor opt-outs for non-essential marketing.

18. Processors and Onward Transfers

Subprocessors are bound by data processing agreements requiring confidentiality, security, and deletion obligations. We maintain an inventory reviewed at least annually.

Customers acting as controllers may request subprocessor notifications and object on reasonable grounds where contractually available.

19. Data Breach Notification

We maintain incident response procedures. Where a breach likely affects your rights, we notify supervisory authorities and affected customers within GDPR timelines.

Customers must notify EventKP without undue delay if they suspect a breach affecting data processed through the platform.

20. Data Processing Agreement

When you process guest or client personal data using EventKP, our DPA forms part of your agreement and defines processor obligations, subprocessor rules, assistance with data subject requests, and deletion upon termination.

Enterprise customers may request custom DPA amendments subject to negotiation.

21. Changes to This Policy

We update this policy for legal, product, or security changes. Material updates are announced via email or in-product notice with a revised effective date.

Version history is published in the Legal Content Center.

22. Contact

Privacy inquiries: [email protected]. DPO: [email protected]. Postal: EventKP GmbH, Privacy Office, Musterstraße 1, 10115 Berlin, Germany.

This policy was expanded under S55F production legal content standards.

23. Lawful Bases in Practice

For account administration we rely on contract performance. For product analytics on pseudonymized usage metrics we rely on legitimate interests balanced against privacy impact assessments. For optional marketing emails we rely on consent with granular opt-in records stored with timestamps and source URLs.

Event organizers choosing to collect optional guest phone numbers must document their own lawful basis—often legitimate interest for event logistics or consent for marketing follow-up. EventKP logs which fields were presented as required or optional in form configuration to support accountability.

Where we process data as processor, we do not determine purposes beyond providing the contracted platform capabilities you enable.

We maintain an internal register of processing activities for platform operations and review it when launching new features that touch personal data, such as marketplace messaging or AI-assisted content suggestions.

24. Organizer Responsibilities for Guest Data

If you are a wedding planner, corporate host, or agency, you must provide guests a privacy notice before or at the point of data collection. Notices should identify you as controller, describe RSVP purposes, retention, recipients, and rights contact.

You should minimize collected fields to what is necessary for seating, catering, and security. Special category data (health/dietary) requires heightened care—enable only when justified and protected.

Export tools allow CSV/JSON download; secure these exports and delete them when no longer needed.

When guests exercise access or erasure rights, you must respond within applicable statutory deadlines. EventKP provides search and bulk export to assist but cannot respond on your behalf without instruction.

Agencies must ensure data processing agreements with their clients cover use of EventKP as a tool and clarify controller/processor roles.

25. Marketplace Privacy

Vendor contact details visible in quotes are shared only with parties to that transaction. Public vendor profiles display information vendors choose to publish.

Reviews and ratings may be moderated for abuse. We retain marketplace communications for dispute resolution periods defined in vendor terms.

Lead forms capture business contact data; vendors must not repurpose leads for unrelated marketing without lawful basis.

26. Payment Data

Card data is processed by PCI-compliant payment providers; EventKP stores tokens and billing metadata, not full card numbers. Invoices include transaction references for accounting.

Billing addresses may be used for tax determination and fraud checks. Refund records are retained for audit purposes.

27. Technical Logs

Server logs retain IP addresses, user agents, request paths, and correlation IDs for approximately ninety (90) days unless extended for security investigations. Logs are access-restricted and used for troubleshooting, abuse detection, and capacity planning.

Communication logs for RSVP emails record delivery status, template identifiers, and timestamps without storing full message bodies indefinitely unless configured for compliance archives.

28. Anonymization and Aggregation

We may create aggregated statistics that do not identify individuals for product improvement and marketing benchmarks. Aggregates may be retained indefinitely.

When accounts are deleted, residual analytics may remain only in non-identifying aggregate form.

29. Personnel Access

EventKP personnel access production data on a least-privilege basis with multi-factor authentication. Access is logged and reviewed. Support staff may view account metadata to resolve tickets you initiate.

Personnel are trained on confidentiality and GDPR fundamentals annually. Violations trigger disciplinary procedures.

30. DPIA and ROPA Support

Enterprise customers may request descriptions of processing activities to support records of processing and data protection impact assessments. We provide template language describing EventKP subprocessors and security measures.

High-risk processing such as large-scale guest health data remains your responsibility as controller; evaluate whether a DPIA is required before enabling sensitive fields.

31. Supervisory Authorities

EEA residents may contact their local supervisory authority. Our lead supervisory contact for cross-border processing is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

Turkish residents may apply to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) regarding processing for which EventKP is controller.

32. Additional Disclosures (US Visitors)

While EventKP primarily serves EU and Turkish markets, US visitors may have state privacy rights regarding sale/share of personal information—we do not sell personal information as defined by CPRA.

We do not use sensitive personal information for inferring characteristics for unrelated purposes.

33. Retention Schedule Summary

Account profile: life of account + 24 months. Billing: 10 years where tax law requires. RSVP responses: organizer-configured, default until event deletion + 90 days. Marketing consents: until withdrawal + proof retention. Security logs: 90 days default.

Legal holds may extend retention when litigation or regulatory investigations require preservation.

35. Security Incidents Affecting Guest Data

If a platform incident likely affects guest personal data you control, we notify you without undue delay with information to support your regulator and guest notifications.

You are responsible for external communications to guests when you are controller, unless otherwise agreed in enterprise contracts.

36. Data Accuracy

You are responsible for accuracy of guest lists and profile data you enter. Guests may request corrections through you; self-service RSVP edit links may be enabled per event settings.

34. Privacy Questions

For complex processing questions, contact [email protected] with your organization name and event identifiers. We respond in English, German, or Turkish where possible.

This Privacy Policy was expanded under S55F production legal standards covering RSVP, marketplace, agencies, and GDPR-aligned operations.

37. Platform Data Flows

EventKP processes data across interconnected modules: marketing site visits, authenticated app usage, published event microsites, RSVP endpoints, vendor dashboards, and agency multi-tenant workspaces. Each module applies consistent access controls while allowing organizers to configure what is collected from guests.

Data flows from guest browsers to API endpoints over TLS, through validation layers, into tenant-scoped databases, and optionally to webhooks or exports you enable. We do not monetize guest lists or sell attendee data to data brokers.

When you delete an event, associated RSVP records enter deletion queues subject to backup retention windows described in our retention schedule.

38. Authentication Data

We store password hashes using industry-standard algorithms, never plaintext passwords. OAuth or SSO logins where enabled receive subject identifiers and tokens according to the identity provider's policies.

Session tokens expire based on security settings. Concurrent session revocation is available in account security settings for compromised credentials.

39. Email and SMS Processing

Invitation and reminder content is transmitted to email service providers as processor data on your instructions. We record metadata logs for deliverability diagnostics. SMS where offered requires additional compliance configuration and may be limited by region.

You must include accurate sender identification and unsubscribe mechanisms in marketing messages you send through integrations.

40. Check-In and QR Codes

QR check-in associates scans with guest records for attendance tracking. Scan timestamps and device identifiers may be logged for fraud prevention. Display check-in data only to authorized event staff roles.

41. Media Uploads

Photos and files uploaded to galleries are stored in object storage with access URLs. You must have rights to distribute uploaded media. We may generate thumbnails and optimized variants automatically.

42. AI Feature Processing

When you use AI-assisted writing for event stories, FAQs, or legal drafts, prompts and outputs may be sent to inference providers under data processing terms. Do not include unnecessary personal data in prompts. Review AI outputs before publishing to guests.

43. Agency Client Data

Agencies processing client events must maintain contracts authorizing processing. Separate client events by workspace permissions. Client export upon contract termination is your responsibility using platform export tools.

44. Vendor Due Diligence

Vendors publishing portfolio media and contact details consent to marketplace display terms. EventKP moderates reported violations but does not guarantee vendor compliance with local licensing laws.

45. Product Research

With consent or on anonymized datasets, we may analyze feature usage to prioritize roadmap investments. Research does not re-identify individual guests without separate legal basis.

46. Reporting Concerns

Employees and users may report privacy concerns to [email protected]. We investigate good-faith reports and prohibit retaliation against reporters.

47. Standard Contractual Clauses

Where personal data transfers to countries without adequacy decisions, we implement EU Commission Standard Contractual Clauses with subprocessors and make summaries available to enterprise customers upon request.

Transfer risk assessments are reviewed when adding subprocessors in new regions or when regulatory guidance changes.

48. Legitimate Interest Assessments

We document balancing tests for security monitoring, service improvement analytics, and fraud prevention. You may object to processing based on legitimate interests where GDPR Article 21 applies and we cannot demonstrate compelling grounds.

49. Processor Transparency

A high-level description of categories of processors is published in trust documentation. Enterprise customers receive advance notice of new subprocessors with objection windows contractually defined.

50. Guest Data Portability

Organizers can export guest RSVP data in structured formats to fulfill portability requests they receive. EventKP does not provide guest-facing self-service portals unless configured by the organizer.

51. Account Closure

When you close your account, we delete or anonymize personal data according to retention schedules. Billing records may survive as required by commercial law. Backups roll off on cyclical schedules.

52. Annex A — Processing Activities Summary

Account management processing includes registration, authentication, profile updates, team invitations, and billing profile maintenance. Data categories: identity, contact, credentials (hashed), organization metadata, and audit logs of administrative actions.

Event operations processing includes hosting public microsites, storing published sections, managing custom domains, and serving media assets you upload. Data categories: event metadata, published content, configuration JSON, and CDN access logs.

RSVP processing includes invitation delivery metadata, guest responses, custom field values, check-in scans, and communication history. Lawful basis is determined by the event organizer; EventKP provides tooling only.

Marketplace processing includes vendor listings, lead capture, quote exchanges, and optional reviews. Business contact details may be visible to transaction participants as configured.

53. Annex B — Security Overview for Customers

Production environments enforce TLS 1.2+, encrypted storage for sensitive columns, role-based access control, and periodic access reviews. Vulnerability findings are triaged by severity with defined remediation targets.

Customer administrators should enable MFA, restrict admin roles, rotate API keys, and review integration permissions regularly.

Subprocessors undergo security review prior to onboarding and periodic reassessment thereafter.

Questions about privacy practices for AI, marketplace, or RSVP modules may be directed to [email protected] with reference to this annex.

Personal Data

Information relating to an identified or identifiable natural person, including names, email addresses, phone numbers, RSVP responses, and online identifiers when linkable to a person.

Processing

Any operation performed on personal data such as collection, storage, adaptation, transmission, erasure, or restriction under GDPR Article 4(2).

Controller vs Processor

A controller determines purposes and means of processing; a processor processes personal data on behalf of a controller pursuant to documented instructions.

A GDPR Article 6 ground such as consent, contract, legal obligation, vital interests, public task, or legitimate interests that justifies processing.

Data Subject Access Request

A request by an individual to exercise rights such as access, rectification, erasure, restriction, portability, or objection regarding their personal data.

Standard Contractual Clauses

European Commission-approved contractual clauses used to safeguard international transfers of personal data to countries without adequacy decisions.

Data Processing Agreement

A contract governing processor obligations when EventKP processes personal data on your behalf, including subprocessor rules and security measures.

Legitimate Interests

A legal basis allowing processing that is necessary for purposes pursued by the controller or third party, balanced against individual rights and freedoms.

Freely given, specific, informed, and unambiguous indication of agreement to processing of personal data, withdrawable at any time without detriment where applicable.

Pseudonymization

Processing personal data so it can no longer be attributed to a specific data subject without additional information kept separately.

54. Document History

This Privacy Policy version reflects S55F production legal expansion covering EventKP RSVP, marketplace, agency, billing, and GDPR-aligned operations. Prior versions remain available in the admin Legal Content Center.

Terms · Privacy · Cookies