Eventringo
FeaturesHow it WorksUse CasesPricingGuides
Create event →

Legal

Eventringo privacy policy

Last updated: 7 September 2026

Back to home →

Effective when this version is published as the active Privacy Policy in the Eventringo service

This translation is provided for convenience. The Czech version is the governing text.

This Privacy Policy explains how and why personal data is processed, and by whom, when you use the eventringo.com website, the Eventringo application, an Organizer account, private Event pages, galleries, photo bingo, quizzes, questions, slideshows, exports, payments, support and related features.

This Policy is not consent to every form of processing. Each processing activity relies on the legal basis described below. We request consent only where it is actually required, in particular for optional analytics and marketing emails.

1. Who runs Eventringo

Eventringo is operated by:

Filip Lněnička
place of business: Trávníčkova 465/3, Zábrdovice, 614 00 Brno, Czech Republic
ID: 22028081
entrepreneur registered in the trade register
email: support@eventringo.com
telephone: +420 777 867 380
website: https://eventringo.com

For questions and requests regarding privacy, please email support@eventringo.com. The contact person is Filip Lněnička. Eventringo does not have a designated data protection officer.

2. To whom the Policy applies

The policy applies in particular to:

  • public website visitors;
  • persons who create or use an organizer account;
  • persons who purchase an Event Pass or other paid service;
  • organizers and persons who manage the event for them;
  • participants who join a private event using a link, QR code or access code;
  • persons captured in uploaded photos;
  • people who contact support, send feedback, legal request, claim, refund request, report illegal content or object to a content decision;
  • recipients of transactional or voluntarily requested marketing e-mails.

3. Who is the controller and when Eventringo acts for the Organizer

3.1 Eventringo as a separate controller

Filip Lněnička is an independent controller, especially for the processing required for:

  • creation, security and management of the organizer's account;
  • conclusion and fulfillment of the Eventringo service contract;
  • registration of legal confirmations and versions of received documents;
  • payments, refunds, claims, accounting, taxes and fraud prevention;
  • transactional communication, support and resolution of requests;
  • protection of the service, users and legal claims;
  • the necessary technical monitoring of errors and security;
  • optional product analytics and session replay after consent;
  • sending marketing emails after consent has been granted;
  • receiving and processing notifications of illegal content, moderation by Eventringo and fulfillment of legal obligations.

3.2 The Organizer as controller of Event data

The Organizer usually determines the purposes and essential rules for using Participants' data in the Organizer's Event. In particular, the Organizer decides:

  • whom the Organizer invites to the Event and who receives its link, QR code or access code;
  • which features to enable;
  • whether and for what purpose photographs will be taken and shared;
  • whether the photo will be displayed in the gallery, bingo, leaderboard or slideshow;
  • whether photographs require the Organizer's approval before display;
  • who can view, download or export content;
  • whether and how the Organizer will use exported photographs after the Event;
  • how it handles the data it receives outside of Eventringo.

The organizer is a separate controller for these decisions. His name or title and contact e-mail for privacy protection are listed in the participant menu of the specific event under the item "Privacy and Personal Information". With a request regarding the purpose of the event, its content or further use of the export, please contact the organizer in particular.

3.3 Eventringo as processor of the organizer

If Eventringo only stores or otherwise technically processes participant data according to the organizer's instructions, it acts as a processor within the scope of these instructions. The relationship between the controller and the processor must be governed by a contract or other legal arrangement that complies with Article 28 of the GDPR before the start of such processing.

This Privacy Policy does not itself replace such a data processing agreement. Nor does it constitute the Participant's consent. If you send Eventringo a request concerning processing for which the Organizer is the controller, we will help forward it to the Organizer or provide the necessary assistance. Eventringo remains directly responsible for its own purposes.

3.4 Overlapping Roles

The same data may be processed in different roles and for different purposes. For example, Eventringo may store the photo for the organizer, but independently process the necessary technical or legal data when dealing with a security incident or reporting illegal content. We assess each such purpose separately.

4. What personal data we process

The scope of the data depends on which part of the service you use and how the event was set up by the organizer.

4.1 Organizer account and login

We may process:

  • name or display name;
  • e-mail address;
  • internal account identifier and authentication identifiers;
  • secure data required for login and account renewal; we do not know or store the password in readable form;
  • information about the selected login method and whether you wish to log in longer;
  • preferred language, currency and communication settings;
  • confirmation of age 18;
  • time, source, language, version, and cryptographic hash of legal documents accepted during registration or purchase;
  • identification of the Controller and acting person, confirmation of authority, and the time, version, language, text, and cryptographic hash of the electronically accepted DPA;
  • profile settings, overview of owned events and information about Event Passes;
  • the organizer's contact for privacy protection for individual events.

If you choose to log in via Google, we receive from Google the basic data needed to create or find an account, typically your email, name, profile picture and Google account identifier. We don't get the Google account password.

4.2 Event Data

We may process:

  • name, description, date, time, time zone and location of the event;
  • invitation, cover image, branding and organizational information;
  • internal event identifier and non-public access or connection code;
  • access, gallery, download, export, moderation, bingo, quizzes, questions, leaderboard and slideshow settings;
  • setting challenges, boxes, questions, answers and scoring;
  • the validity period of the Event Pass and the date of termination of access;
  • aggregated numbers of participants, photos, activities and feature usage;
  • the history of substantial changes, exports, moderation and deletion, if it is necessary for operation, security or documenting legal obligations.

4.3 Participants and Guest Sessions

When joining an event, we may process:

  • display name or nickname;
  • internal identifier of the participant and the event;
  • non-public guest token and session technical data;
  • connection time and last activity;
  • submitted photos and their approval status;
  • progress in bingo, points, order and time of achieved results;
  • quiz answers, answer time and assigned points;
  • questions asked and their status;
  • voting, reactions or other contributions, if enabled for the event;
  • records necessary to limit misuse, observe limits and secure the event.

A participant usually does not need a permanent account or email. A feature marked "anonymous" is anonymous to other participants in the sense that it does not display a name with the post. However, Eventringo may internally associate a post with a guest session or participant for moderation, security, and for the author to see their own posts.

4.4 Photographs and Other Content

Photographs may contain faces, appearance, environment, behavior, place, time and other information about the people captured. We also process:

  • file, technical format, size and dimensions;
  • the author of the upload, the event, the time of the upload and the related bingo challenge;
  • moderation, publication, highlighting or removal status;
  • technical variants of the photo, such as thumbnails and previews;
  • display, download or export data, if required for the operation and rules of the Event Pass.

We server-verify and re-encode photos upon receipt. This removes the original EXIF ​​metadata, including GPS data if it was included in the file. We do not use facial recognition, biometric identification, or photos to train AI models.

A photo may indirectly reveal sensitive information, such as health, religion or background. Eventringo does not collect this information in a targeted manner, nor does it profile people based on it. Organizers and users must not use the service to collect sensitive data without adequate legal grounds and guarantees.

4.5 Payments, Event Passes and Refunds

We may process:

  • selected Event Pass, price, currency, discount and tax information;
  • date and status of purchase, payment, refund, claim or dispute;
  • customer Stripe, Checkout Session, payment, refund and invoice identifiers;
  • billing and contact information you provide to us or Stripe;
  • information on whether and when the digital service was made available and used for the first time;
  • signals needed to assess a voluntary refund, in particular whether a photo or other media object has already been saved, whether the First Use of the Event Pass has occurred, whether an upgrade has been completed and whether a refund has already been issued;
  • contractual confirmation and proof of what terms and conditions were displayed and accepted at the time of purchase.

Full payment card details are processed by Stripe. Eventringo does not store them and does not normally have access to them. Stripe may act as a separate controller for certain payment, regulatory and anti-fraud activities.

4.6 Support, Legal Requests and Communications

When you contact us, we may process:

  • name, e-mail and other contact information provided by you;
  • content of the report and attachments;
  • account, event, participant, photo, purchase or refund identifier;
  • solution process, identity verification, result and related communication;
  • technical data necessary to find an error or account security.

4.7 Notification of Illegal Content and Objections

When reporting content or submitting an objection, we may process:

  • the name and e-mail of the whistleblower, unless a statutory exception applies;
  • exact URL, event or photo identifier and content type;
  • a description of the allegedly illegal content, a legal reason, a statement of good faith and information about an urgent risk to life or safety;
  • a copy or printout of the content in question and the status of the event at the time of notification;
  • internal assessment, decisions, justifications, applied restrictions, communication and audit trail;
  • e-mail, reason and desired result of the objection;
  • data necessary to prevent misuse of the notification mechanism.

4.8 Voluntary Feedback

We process answers, ratings and free text in the public feedback form. The form does not ask for a name or email, and the saved response is not associated with an account, event, IP address, or analytics identifier. To limit abuse, a separate pseudonymous technical fingerprint of the request may be used temporarily.

4.9 Technical, safety and operational data

We may process:

  • IP address, date and time of the request;
  • browser type, device, operating system and basic network data;
  • requested route, response status and limited traffic metadata;
  • internal session identifiers and pseudonymous rate-limit keys;
  • logs of logins, failures, errors, performance and security events;
  • technical data on uploading, downloading and exporting.

The Sentry settings limit the data sent: default personal data, cookies, headers, request bodies, query parameters, generative AI content, local variables and application logs are disabled; sensitive identifiers and dynamic URL parts are stripped before sending.

4.10 Optional analytics and session replay

Only if you enable analytical cookies, PostHog can process:

  • visited parts of the application and selected product events;
  • pseudonymous or internal identifier;
  • basic device, session and usage data;
  • marketing entry source, referring domain, limited campaign tags (UTM values) and approximate country inferred from the network connection, to understand where visitors come from;
  • module enablement, successful settings saves and selected configuration options such as board size or moderation mode, linked to a pseudonymous event key without sending the event's name or access code;
  • for the registered organizer, the internal UUID of the account, the distinction between paid and free users and the last type of paid Event Pass;
  • masked recording of session progress to find problems in the user interface, especially interface structure, clicks, movement between screens and page scrolling.

We do not send the host's name or email, event access code, or guest token to PostHog. All input fields are masked and texts, photos and other personal content of a particular event are excluded from the recording or masked in the browser before sending. Session replay is not intended to monitor participants or the content of their event. Analytics can be refused or revoked at any time in the Cookie settings.

Referring URLs are reduced to a domain for external sites; internal event identifiers, URL query strings and advertising click IDs are removed before sending. Campaign tags are limited to short, non-personal codes. Country is an approximate technical inference, not a verified place of residence.

5. Where we get the data from

We obtain data:

  • directly from you when registering, purchasing, connecting, uploading, communicating or submitting a form;
  • from the organizer who creates the event, sets its content or invites participants;
  • from another user who uploads a photo in which you are captured;
  • automatically from your device and use of the Service to the extent described in this Policy;
  • from login providers, in particular Google, if you choose this method;
  • from Stripe in connection with a payment, refund, invoice, discount or dispute;
  • from our technical suppliers in operation, security and error resolution;
  • from public authorities or other persons, if necessary to resolve a legal obligation, claim or illegal content.

If your information is included in a photo or other content provided by another person, we may not know your name or be able to contact you separately. We therefore make this Policy publicly available and provide relevant information in the participant layer of a specific Event.

6. Purposes and legal bases for processing

6.1 Performance of the contract and steps before concluding the contract

We use this legal ground in particular for:

  • registration, login and administration of the organizer's account;
  • event creation and management;
  • providing the Event Pass and making the purchased functions available;
  • payment, contract confirmation, transaction emails and requested refund;
  • support and resolution of service defects;
  • connecting a Participant and providing functionality the Participant actively requested, where Eventringo is the controller for that purpose.

Without data marked as mandatory, we may not be able to create an account, complete a purchase, or provide the requested functionality.

6.2 Legitimate Interests

In particular, we can base our legitimate interest on:

  • security of accounts, private events, infrastructure and users;
  • prevention of fraud, abuse, spam, unauthorized uploads and circumvention of limits;
  • limited technical error monitoring by Sentry;
  • determination of eligibility for voluntary refund and protection against double payment;
  • administration, moderation and protection of the integrity of the service;
  • arranging support, feedback and normal operational communication;
  • the application, performance and defense of legal claims;
  • basic internal statistics, if they do not require analytical cookies.

We weigh these interests against the rights of data subjects and use minimization, limited access, pseudonymisation, short retention periods and the ability to object. We do not base PostHog's optional analytics or marketing emails on this legal ground.

6.3 Consent

We use consent to:

  • analytical cookies, PostHog product analytics and session replay;
  • marketing emails and related discount offer;
  • other specific optional processing, if we explicitly ask for your consent.

Consent is voluntary and can be revoked at any time without affecting the legality of the previous processing. Opting out of analytics or marketing does not prevent the use of the basic service.

6.4 Legal Obligation

We process data if necessary in particular for:

  • accounting, tax and consumer obligations;
  • handling legal withdrawal, complaints and rights of data subjects;
  • notification and documentation of security incidents;
  • obligations regarding illegal content and cooperation with authorities;
  • compliance with a binding decision, order, or other requirement of a public authority.

6.5 Organizer's legal reason

The organizer is responsible for determining the legal basis for the data that it, as controller, collects through its event or further uses after export. Depending on the specific event, it may be, for example, consent, performance of a contract or legitimate interest. Merely entering a private event or accepting this Policy does not automatically consent to any use of the photographs.

7. How data is displayed and to whom it can be made available

7.1 Persons with access to the event

Eventringo is for private events. However, the content may be visible to anyone who obtains a valid link, QR code, access code, or already created guest session. Depending on the organizer's settings, they can see in particular:

  • name and information about the event;
  • displayed names of participants;
  • photos, their authors and related bingo challenges;
  • points, ranking and results;
  • published anonymous questions;
  • name or title and privacy e-mail of the organizer.

The access code is not intended for publication. The organizer and participants must protect it and share it only with invited persons. If the code reaches an unauthorized person, please contact the organizer or Eventringo.

7.2 Moderation, slideshow and export

The Organizer and persons authorized by the Organizer can view Content needed for moderation and can approve, hide, or remove it. Depending on the settings, approved photos may appear in the gallery, bingo, leaderboard, or slideshow and may be available for download or export.

After downloading or exporting, a copy is created outside of Eventringo. Eventringo cannot remove it remotely on a foreign device. Further use of the copy is the responsibility of the person who uses it, in particular the organizer as controller.

7.3 Employees and external experts

Only those who need it for operation, support, security, legal or accounting agenda have access to the data. To the extent necessary, we can make the data available to lawyers, accountants, auditors, insurance companies or public authorities, if there is a legal reason for this.

7.4 Sales and Advertising

We do not sell personal data. We do not use photos or participant data for our own advertising, third-party targeted advertising or AI training without a separate legal reason and corresponding information.

8. Suppliers and recipients

We mainly use the following services for operation. Each supplier receives only the data necessary for its function, and its exact role may depend on the specific activity.

8.1 Supabase

Supabase provides the PostgreSQL database, authentication, a secure server interface, and managed database backups on the production Pro plan. The production project is located in West EU (Ireland), eu-west-1. On the Pro plan, Supabase creates daily database backups and by default makes the most recent 7 days available. A database backup does not include the objects themselves stored through the Storage API or files in Cloudflare R2. The primary data region does not exclude limited global support, security, or subprocessor processing under Supabase's terms.

8.2 Cloudflare and Cloudflare R2

Cloudflare secures and delivers network traffic, and R2 is the main private repository for photos and their variants. Bucket uses the WEUR location. Location Hint is a best efforts location, not a legal guarantee that all processing will remain within the European Union only.

8.3 Vercel

Vercel hosts the website, server functions and distribution network. Eventringo uses the Pro production plan, which is covered by Vercel's DPA. Server functions are configured for Frankfurt, fra1. Static content, network layer, operational metadata, security and support can be handled through Vercel's global infrastructure.

8.4 Stripe

Stripe handles Checkout, payments, discount codes, refunds, payment disputes and fraud prevention. Depending on the specific activity, it can act as an Eventringo processor or as an independent controller, especially when fulfilling its own financial, regulatory and anti-fraud obligations.

8.5 Resend

Resend ensures the sending of transactional and, only after consent, marketing e-mails. It mainly processes recipient address, message content, delivery status and limited technical metadata.

8.6 PostHog

PostHog EU Cloud provides optional product analytics and session replay only after enabling analytical cookies. We use the limited identifiers and input field masking described in Section 4.10.

8.7 Sentry

Sentry in the German data region provides the necessary error, performance and security monitoring. Sentry does not run on public marketing sites and has a limited scope of data in the application described in clause 4.9. We do not use Session replay Sentry.

8.8 Google

Google is an optional login provider. We will only use it if you choose "Sign in with Google". Google also processes data according to its own policies and may be a separate controller for its purposes.

We regularly check the current contractual documentation and lists of suppliers' subprocessors. You can request more detailed information or a copy of the applicable warranties at support@eventringo.com; we may remove confidential or third-party personal information.

9. Transfer of data outside the European Economic Area

Some suppliers or their subprocessors operate outside the European Economic Area, particularly in the United States. Setting the European region reduces the scope of cross-border processing, but does not in itself mean that all support, security metadata or sub-processors remain in the EEA.

If there is a transfer to a third country, we use, depending on the situation:

  • decision of the European Commission on adequate protection;
  • EU–US Data Privacy Framework, if the recipient is validly certified and the transfer falls within the certification;
  • standard contractual clauses of the European Commission;
  • other additional technical, contractual and organizational measures;
  • an exceptionally different legal mechanism permitted by the GDPR.

We do not base the normal operation of the service on the user's consent to transfer to the USA. We will provide information on specific guarantees upon request to the extent that it does not endanger the safety or rights of other persons.

10. Cookies and local storage

10.1 Necessary Technologies

Without consent, we only use cookies and storage necessary for the service or function you have requested. These include in particular:

  • eventringo_cookie_consent – ​​saves the version and choice of cookies; no more than 180 days;
  • sb-* – Supabase authentication cookies; without the option to "remember" a maximum of 3 hours, with a maximum of 365 days;
  • eventringo_remember_me – login length preference; 3 hours or 365 days;
  • eventringo_tab_session – session protection in a specific tab; no more than 3 hours and, within sessionStorage, until the tab is closed;
  • eventringo_creator_last_activity – the time of the last activity used for inactivity logout; until logout or expiry;
  • eventringo_password_reset_verified – password reset protection; 15 minutes;
  • eventringo_oauth_signup – completion of registration via Google; 10 minutes;
  • eventringo_guest_[CODE] – non-public guest token for a specific event; no more than 7 days;
  • eventringo_language – selected language; to change the choice or delete the browser storage;
  • eventringo_payment_currency – selected currency; to change the choice or delete the browser storage;
  • eventringo_marketing_popup – information whether the voluntary marketing popup was closed or sent; the closing will be reminded in 7 days at the earliest, the record can be deleted by deleting the local storage;
  • eventringo.pendingEventCheckout – event settings in progress during the transition to Stripe; in sessionStorage until the tab is completed, canceled or closed;
  • eventringo_invite_page:[ID] and similar local preview settings – detailed invitation settings for a specific event; to save, reset, delete event or delete browser storage.

Stripe, Google and other services may use their own necessary or security cookies on their own domains according to their policies.

10.2 Optional Analytics

We use analytics cookies and PostHog local storage only after you select "Allow all". Without this consent, PostHog does not initialize. You can change your choice at any time through the "Cookie settings" link in the footer. Withdrawing consent stops future analytics and resets PostHog's local identity.

We keep the pseudonymous server proof of your cookie choice for 180 days. It does not contain an account, email, IP address, user-agent, URL, event or access code.

11. How long we keep data

We retain data only for as long as necessary for the purpose, contract, security, legal obligation, or legal claim. We then delete or anonymize it unless a documented legal hold applies.

11.1 Account and Events

  • Active organizer account and profile: for the duration of the account.
  • Event data, participants, photos, questions, quizzes, leaderboard, activity history and general settings: for the duration of the Event Pass and then 30 days after `access_expires_at`.
  • In case of voluntary early deletion of the event or successful voluntary refund: we delete active data and files without undue delay according to the relevant process.
  • Guest session: up to 7 days from last activity or until the event is deleted, whichever comes first.
  • Temporary upload, failed upload, rate-limit recording and fallback staging: usually no more than 24 hours, unless there is a shorter technical deadline.
  • Processed paid checkout on the server: maximum 2 days.
  • Incomplete registration of legal confirmation: 7 days for registration and 2 days for checkout.

Automatic deletion after the end of the Event Pass can only be temporarily suspended due to a specific legal obligation, dispute, security incident or documented legal claim. We regularly review the reason.

11.2 Analytics, Monitoring and Feedback

  • PostHog product analytics and session replay: maximum 12 months.
  • Sentry error and performance events: 30 days.
  • Vercel runtime logs on the Pro plan without the Observability Plus extension: no more than 1 day; we do not forward them to our own storage for longer retention unless this Policy states otherwise.
  • Voluntary public feedback: 12 months.
  • Pseudonymous cookie proof of choice: 180 days.
  • Short-term security and rate-limit data: usually no more than 24 hours; a longer safety record only on a specific incident or claim.

11.3 Marketing

  • Active marketing contact: until withdrawal of consent or opt-out.
  • Minimum proof of opt-in, opt-out and list of suppressed addresses: 3 years from the last relevant event, or longer for the duration of a specific dispute or legal obligation.

11.4 Contractual, Payment and Legal Records

  • Contract confirmations, legal acceptances, and evidence of digital-service performance: usually 3 years after the Event Pass or contractual relationship ends; longer while an open dispute, tax obligation, or legal hold continues.
  • Support, complaints, refunds, consumer and privacy requests: usually 3 years from the closing of the case; longer if necessary for an ongoing proceeding or legal claim.
  • Payment, invoicing, refund and tax records: for the period required by the relevant regulations, usually at least 5 years after the end of the relevant period; some accounting, VAT or OSS records may be kept for 10 years.
  • Audit metadata of notifications of illegal content and related decisions: usually 3 years from the final closure of the case.
  • A copy of affected Content in a DSA case: usually no more than 6 months after final closure; longer only while an appeal, proceeding, authority request, or legal hold continues.

11.5 Backups and data held by suppliers

Once deleted from active systems, restricted copies may temporarily remain in encrypted operational backups until the end of the vendor's backup cycle. Supabase Pro production database backups have a standard available history of 7 days. Photo files stored in Cloudflare R2 are not included in these database backups and follow their own object removal process. Backups are not used as a regular archive. During disaster recovery, previously required wipes must be redone. Stripe and other independent controllers may retain data for longer periods according to their own regulatory obligations.

12. Deleting an account, event and photo

The organizer can delete their own event or account in the application. Re-authentication with password and exact confirmation may be required before deletion. Deleting an account removes the active account, profile, owned events and their files, and deletes the PostHog analytics identity.

Some minimum account records are not deleted immediately if we have to keep them due to legal obligation, accounting, tax documents, contractual proof, marketing ban, security incident, DSA case or legal claim. We no longer use these records as an active user account.

A Participant can delete a photograph they uploaded if that option is available in the application. You may ask the Organizer to remove another photograph or copy through the contact shown in the Participant menu, or contact Eventringo at support@eventringo.com. We may reasonably verify your identity and connection to the photograph before handling the request.

A deletion in Eventringo will not delete a copy that someone has previously legitimately downloaded, exported, or stored outside of the Service. In this case, please contact the copy holder or organizer.

13. Your Rights

Depending on the circumstances, you have the right to:

  • obtain confirmation as to whether we are processing your personal data and access to it;
  • request the correction of inaccurate or incomplete data;
  • request erasure;
  • request restriction of processing;
  • obtain data in a portable format, if the legal conditions are met;
  • object to processing based on legitimate interest;
  • object to direct marketing at any time;
  • revoke consent at any time;
  • not be the subject of an exclusively automated decision with legal or similarly significant effects, unless the law provides for an exception;
  • file a complaint with the supervisory authority.

You can send a request to support@eventringo.com. You can also use the contact of the organizer in the participant menu for details of a specific event. If you are not sure, write to Eventringo; we will define our role and not reject a request just because it was sent to the wrong contact.

We respond without undue delay, usually within one month. In the case of complex or a larger number of applications, the deadline can be extended by up to two more months; we will inform you about the extension and the reasons in the first month. Applications are usually free.

We may reasonably verify identity before providing or erasing data. We will preferably use confirmation in the logged-in account, a response from the registered e-mail, guest session data or another less invasive method. We do not automatically ask for a copy of your ID.

The supervisory authority in the Czech Republic is:

Personal Data Protection Office
Lt. Col. Sochora 27, 170 00 Prague 7
https://uoou.gov.cz

14. Automated Processing

Eventringo automatically calculates points, order and time of results, checks limits and rate limits, evaluates technical signals for voluntary refunds and creates basic analytical reports. These processes do not in themselves create decisions with legal or similarly significant effects according to Article 22 of the GDPR.

If an automated review affects a refund, access, or moderation, and you believe the result is in error, you may request a human review at support@eventringo.com. Objections to content decisions are not exclusively decided by an automated system.

15. Children and age conditions

The organizer account and purchase are intended only for persons who have reached at least 18 years of age.

The participation part is intended for persons who have reached at least 15 years of age. A younger person may use the service only under the supervision or with the authorization of a parent, legal representative or other authorized adult. Eventringo is not intended for schools, school events or events aimed primarily at children under 15 years of age.

The organizer may not invite minors to provide more data than is necessary and is responsible for adequate information and the legal reason for their event. If we discover that a child's data has been processed in violation of these rules or the law, we will take reasonable steps to correct or delete it.

16. How we protect data

We use reasonable technical and organizational measures, in particular:

  • separation of Organizer and guest permissions;
  • row-level security in the database and server authorization checks;
  • non-public, hard-to-guess access codes and guest tokens;
  • private storage and time-limited signed file links;
  • server validation of uploads, format change and removal of EXIF/GPS metadata;
  • encrypted transmission;
  • restricted access for authorized personnel and suppliers;
  • rate limits, protection against misuse and error monitoring;
  • minimization of analytical and error data;
  • backups and secure deletion processes;
  • records and procedures for security incidents.

No service can guarantee absolute security. If you suspect misuse of your account, access code, photo or personal information, please contact us immediately at support@eventringo.com.

In the event of a security breach, we will assess the risk and fulfill notification obligations. If there is a likely risk to rights and freedoms, we will report the incident to the Office for Personal Data Protection without undue delay and, if possible, within 72 hours of discovery. In the case of a likely high risk, we also inform the affected persons, unless a legal exception applies.

17. Responsibilities of the organizer and users

In particular, the organizer must:

  • tell participants their own identity and privacy contact;
  • determine and document the legal basis for the Organizer's processing purposes;
  • set access, visibility, moderation, download and export appropriate to the nature of the event;
  • pass the access code only to the intended persons;
  • inform the participants about the photography and the intended further use;
  • handle requests from persons, if it is the controller for the given processing;
  • not to use the exports in a manner incompatible with the original purpose or the law;
  • enter into or electronically accept the required DPA with Eventringo where Eventringo processes data on the Organizer's behalf;
  • to inform Eventringo without delay about an incident or illegal use of the service.

A User may upload a photo or other content only if doing so does not infringe the rights of the persons depicted and the User has the appropriate authorization. Users should not upload identity documents, medical records, payment information, passwords, precise location data or other clearly unnecessary sensitive content.

18. Changes to this Policy

We can change the policy especially when changing the service, suppliers, legal requirements, retention periods or processing methods. For a material change, we will publish the new wording before it is used and give reasonable notice to the persons affected by the change, for example in the application or by email. If we have contact information and the change significantly affects already ongoing processing, we will provide the notification directly and clearly. We will provide information required by law before processing for a new purpose.

We will not pass off a change of legal reason or a new optional purpose as mere continued use of the service. If consent is required for new processing, we will request it separately.

The Privacy Policy is an informational document, not contractual consent to every processing activity. Its updated text is therefore not normally confirmed through a mandatory checkbox. We may record delivery or display of a notice, but that record does not itself constitute consent. We request a separate active consent only for a purpose that actually requires it, such as optional analytics or marketing.

The Czech version is the main one. Any English translation is for information; in the event of a conflict, the Czech version takes precedence to the extent permitted by legal regulations.

19. Contact

You can send questions, requests and objections regarding personal data to:

Filip Lněnička – Eventringo
Trávníčkova 465/3, Zábrdovice, 614 00 Brno, Czech Republic
support@eventringo.com
+420 777 867 380

For a particular Event, the Organizer's name and privacy email are available in the Participant menu under "Privacy and personal data".

Eventringo

Private event games, photo bingo, galleries, and live-screen moments in one playful place.

Company

FeaturesHow it WorksUse CasesPlanning guidesPricing

Legal

ContactTerms of ServicePrivacy PolicyRefund Policy

Need a custom package?

Have a bigger event or agency workflow? Contact us and we will help you set it up.

Contact package →