Privacy Policy
This is an informative translation. In case of discrepancy, the Spanish version shall prevail.
For the purposes of this Privacy Policy, Eventgoing (eventgoing.com and its subdomains) is also referred to as the Platform.
1. Data controller
The data controller for personal data collected through the Platform is:
- Owner: Juan García Fernández
- Email: hello@eventgoing.com
2. What data we collect
2.1. Organizer data
When an Organizer creates an account on the Platform, the following data is collected:
- Name.
- Email address.
- Password (stored in encrypted form using bcrypt or argon2; the Platform has no access to the plain-text password).
- Access IP address.
- Account creation date.
- Activity logs.
2.2. Attendee data
When an Attendee responds to an invitation through the Platform, the following data is collected:
- Name.
- Email address.
- Attendance response (RSVP).
Attendees do not need to create an account on the Platform. Their data is provided by themselves when responding to an invitation, or by the Organizer when setting up the event.
2.3. Technical data
During use of the Platform, the following is automatically collected:
- IP address.
- Server access logs.
The Platform currently does not use web analytics tools.
2.4. Commercial priority list data
When a person joins the priority list to be informed about paid plan availability, the following is collected:
- Name.
- Email address.
- Selected plan of interest.
- Date and time of joining the list.
- Evidence of consent (acceptance, date/time and accepted Privacy Policy version).
- Technical request metadata (IP address, user-agent and time zone, when available).
When joining the priority list is done from an authenticated Organizer account (account area), the email associated with that account will be used to process the request for plan information.
3. Purposes of processing
Personal data is processed for the following purposes:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and manage Organizer account | Name, email, password | Performance of contract (Terms of Use) |
| Allow event creation and management | Event and Organizer data | Performance of contract |
| Manage attendance responses (RSVP) | Name, email and Attendee response | Organizer's legitimate interest in managing its event |
| Send service-related communications | Organizer or Attendee email | Performance of contract or legitimate interest |
| Ensure Platform security | IP, logs | Owner's legitimate interest |
| Manage commercial priority list and notify about paid plan availability | Name, email, plan of interest, consent evidence | Data subject consent |
| Manage requests for plan information made from authenticated Organizer account (account area) | Account email, name, plan of interest, request date | Pre-contractual measures at data subject request / legitimate interest |
| Manage account deletion requests (immediate or scheduled), including possible cancellation before effective date | Account identifiers, subscription status, request/schedule/cancellation dates and optional reason provided by Organizer | Performance of contract and compliance with legal data protection obligations |
| Execute technical deletion or anonymization of account and associated resources when applicable | Account data, event/guest/staff relationships and operational metadata needed for execution | Legal obligation (right to erasure) and Owner's legitimate interest in preserving system integrity and security |
| Prevent abuse and protect lead-capture endpoint (rate limiting and technical traceability) | IP, user-agent, time zone, request date | Owner's legitimate interest |
| Comply with legal obligations | Data required by the obligation | Legal obligation |
4. Attendee data and Organizer role
The Organizer may enter Attendee data on the Platform when managing events. The Organizer is responsible for:
- Having a legitimate basis to provide Attendee data to the Platform.
- Informing Attendees about the processing of their data.
- Handling Attendee rights regarding data provided by the Organizer.
The Platform processes Attendee data for the purpose of providing service to the Organizer. When an Attendee responds directly to an invitation, they provide data voluntarily for the specific purpose of confirming or declining attendance.
5. Recipients and processors
Personal data may be shared with the following service providers, acting as data processors:
| Provider | Service | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting (VPS servers) | Germany (EU) |
| Brevo (Sendinblue) | Transactional email delivery | France (EU) |
Both providers are located in the European Union and subject to the GDPR.
Personal data is not sold or disclosed to third parties for commercial or advertising purposes.
6. International transfers
No transfers of personal data outside the European Economic Area are currently carried out.
If an international transfer becomes necessary in the future, safeguards provided by the GDPR will be applied (adequacy decisions, standard contractual clauses, or other appropriate safeguards).
7. Data retention
Personal data will be retained for the following periods:
- Organizer data: while the account remains active. After account deletion is requested, data will be deleted except as noted below.
- Scheduled deletion requests: when the Organizer chooses deletion at end of period, minimal scheduling metadata will be retained until the effective date or until the Organizer cancels the schedule from its account area.
- Attendee data: while the event to which it is linked remains active on the Platform. If the Organizer deletes the event or account, associated Attendee data will be deleted.
- Activity logs: may be retained for up to 30 days after account deletion for security and legal compliance reasons.
- Data subject to legal obligations: retained for the period required by applicable law.
- Commercial priority list: data will be retained while the commercial contact purpose related to launch or paid-plan availability exists and, in any case, periodically reviewed for deletion or anonymization when no longer necessary for that purpose.
When deletion is executed, the Platform will apply technical deletion and/or anonymization procedures to the account and associated resources. Minimal technical records may be retained for the strictly necessary period for security, fraud prevention and regulatory compliance.
8. Data subject rights
Under the GDPR and Spanish Organic Law 3/2018 on Personal Data Protection and guarantee of digital rights (LOPDGDD), data subjects may exercise the following rights:
- Access: know what personal data is being processed.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of personal data.
- Restriction: request restriction of processing in certain circumstances.
- Portability: receive personal data in a structured, commonly used format.
- Objection: object to processing based on legitimate interest.
To exercise any of these rights, data subjects may contact the email indicated in section 1, proving identity.
The Owner will respond within one month of receiving the request, extendable by two additional months depending on complexity or number of requests.
If the data subject considers its rights not adequately addressed, a complaint may be filed with the Spanish Data Protection Agency (www.aepd.es).
9. Attendee data: exercise of rights
Attendees whose data has been entered by an Organizer should first contact the Organizer to exercise rights of access, rectification, erasure or objection.
If the Attendee cannot contact the Organizer or receives no response, they may contact the Owner via the contact email.
10. Security
The Platform applies reasonable technical and organizational measures to protect personal data against unauthorized access, alteration, loss or destruction. Measures include:
- Passwords stored encrypted using secure algorithms (bcrypt or argon2).
- Communications between browser and Platform transmitted via HTTPS.
- Restricted access to infrastructure.
No system is completely secure. The Owner cannot guarantee absolute data security, but commits to acting with reasonable diligence and to notifying security breaches as required by applicable law.
11. Minors
The Platform is not directed at minors under 16 years old. Data of minors under that age is not intentionally collected. If the Owner becomes aware that data from a minor has been collected without parental or guardian consent, it will be deleted.
12. Modifications
The Owner may update this Privacy Policy at any time. Modifications will be published on the Platform with the last-updated date.
In case of substantial modifications, the Owner will make reasonable efforts to inform registered Users via the email associated with their account.
13. Contact
For any enquiry related to this Privacy Policy or personal data processing:
Email: hello@eventgoing.com