Privacy Policy
Last updated: August 2026
1. Privacy at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit our website or use our SaaS platform. Personal data is any data by which you can be personally identified.
This Privacy Policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done. We treat your personal data confidentially and in accordance with applicable data protection laws and this Privacy Policy.
Data Collection on Our Website
Data processing on this website is carried out by the website operator. You can find their contact details in the "Data Controller" section of this Privacy Policy.
Your data is collected partly because you provide it to us — for example, data you enter in a registration form, contact form, or sign-up. Other data is collected automatically or with your consent when you visit the website by our IT systems.
2. Data Controller
The data controller for data processing on this website is:
Quick-Event — a brand of ThePlus UG (haftungsbeschränkt)
Hüchtingstraße 5
28816 Stuhr
Germany
Email: info@quick-event.com
The data controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data (e.g., names, email addresses, etc.).
3. Your Rights
You have the right to receive free information at any time about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data.
Your rights at a glance:
- Right of access (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure ("right to be forgotten", Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
If you have given consent to data processing, you may withdraw it at any time with effect for the future. Data processing that has already taken place is not affected by this.
4. Hosting and Email Dispatch
Hetzner Online (Hosting)
We host our website and our SaaS platform on servers rented from:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
The live system runs in the Nuremberg data centre; backups are stored in the Falkenstein data centre. Both locations are in Germany. We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR.
When you visit our website, the server records the request in a log entry (IP address, time of the request, page requested, browser and operating system). This is technically necessary to deliver the page and to detect faults and attacks; the legal basis is Art. 6(1)(f) GDPR. These log entries are deleted after 30 days.
Twilio (SendGrid, Email Dispatch)
Transactional emails — registration confirmations, tickets, invitations sent by event organisers — are dispatched via SendGrid. The provider is:
Twilio Ireland Limited
3 Dublin Landings, North Wall Quay
Dublin 1, D01 C4E0
Ireland
We use SendGrid’s EU Data Residency, so email content and recipient addresses are processed on servers within the European Union. Dispatch is necessary to perform the contract or, for invitation mailings, rests on the legitimate interest of the event organiser; the legal basis is Art. 6(1)(b) and Art. 6(1)(f) GDPR. A data processing agreement pursuant to Art. 28 GDPR is in place.
Protective Measures
To protect the platform, we operate the following measures on our own infrastructure:
- Transport encryption: all connections run over TLS; unencrypted connections are refused.
- Rate limiting: the number of login and registration attempts per address is limited, counted across all instances.
- Bot defence on the login and registration endpoints.
IP addresses and request timestamps are processed for this purpose. The processing is necessary to protect our platform and rests on Art. 6(1)(f) GDPR.
5. Database and Storage
Your data is stored in a PostgreSQL database that we operate ourselves on the Hetzner infrastructure described in section 4, in the Nuremberg data centre in Germany. Files you upload — logos, images, PDFs — are held in object storage at the same provider, likewise in Germany.
Security Measures
- Encryption in transit: every connection to the database and to the object storage is TLS-encrypted.
- Encryption at rest: the storage media are encrypted at the level of the data centre infrastructure; backups are stored encrypted.
- Backups: continuous backup to a second German data centre (Falkenstein), retained for at least 30 days.
- Separation: every record carries the event it belongs to, and every query is restricted to it. Accounts of event participants are held in separate tables from those of the organisers.
- Passwords are stored only as a hash with a random salt.
No data leaves the European Union in the course of this storage.
6. Analytics Tools and Tracking
Marketing Tags (only after consent)
Analytics and marketing tags are loaded only after you have given your consent in the cookie banner. Until then, no such tag runs. Where tags are used, requests are routed through our own domain and forwarded server-side, so no data flows directly from your browser to a third-party domain. You can withdraw your consent at any time in the cookie settings; the legal basis is Art. 6(1)(a) GDPR together with § 25(1) TDDDG.
Tracking that an event organiser sets up for their own event pages is a separate matter and is described in section 9.
PostHog (Product Analytics, Session Replay, and Error Reporting)
In addition to the tools described above, we use PostHog to understand how our website and our SaaS platform are used, and to detect and diagnose technical faults. The provider is:
PostHog, Inc.
2261 Market Street #4008
San Francisco, CA 94114
USA
We use the European instance of PostHog. All analytics data is processed and stored on servers within the European Union. Data is transmitted to PostHog exclusively via our own domain and not directly from your browser to a third-party domain.
Unlike the tools described above, PostHog is currently activated for all visitors and does not depend on the cookie banner. Your right to object is set out at the end of this section.
Data Collected by PostHog
- Usage Data: pages viewed, navigation within the application, and actions performed (for example, creating an event or submitting a form)
- Technical Information: browser, operating system, device type, screen resolution, referrer URL, and an approximate geographic location derived from your IP address
- Pseudonymous Identifier: a randomly generated identifier stored in your browser in local storage and in a cookie, so that repeat visits can be recognised as belonging to the same visitor
- Error Reports: in the event of a technical fault, the error message, the technical stack trace, and the page on which the fault occurred
We do not use PostHog's automatic capture of all clicks and form interactions; only the events described above are recorded. A personal profile is created only once you log in to a customer account; visitors who are not logged in remain pseudonymous. Before transmission, addresses of pages visited are cleared in your browser of any personal data they may contain (for example, email addresses or names).
Session Replay
PostHog also allows us to record a reconstruction of individual browsing sessions ("session replay"). This is not a video recording of your screen. It is a reconstruction of the page content and of your interactions with it — mouse movements, clicks, scrolling, and page changes — assembled from the technical structure of the page.
- Where we record: only on our public website, in the customer login area, and in the platform settings. Public event pages on which participants register for an event are not recorded.
- When we record: recording does not begin when the page loads. It starts only after your first interaction with the page.
- Entries in input fields are masked: text you type into an input field is replaced with placeholder characters in your browser before transmission and never reaches us in legible form. This applies to all input fields, including passwords and payment details.
- One deliberate exception: entries in our contact form — name, email address, and message — are transmitted in legible form. We do this in order to be able to respond to your enquiry; you are sending us this content in any event when you submit the form.
- Retention period: session recordings are automatically deleted after 90 days.
Legal Basis and Right to Object
Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in analysing usage in order to improve our website and our platform, in identifying and correcting technical faults, and in being able to respond to enquiries. You have the right to object to this processing at any time pursuant to Art. 21 GDPR. To do so, please write to us at info@quick-event.com; we will then exclude your data from analysis and delete any recordings already stored. You can also prevent this processing yourself by deleting the cookies and local storage entries set by our website in your browser settings.
7. SSL/TLS Encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the fact that the address bar in your browser changes from "http://" to "https://" and by the padlock symbol in your browser bar.
When SSL/TLS encryption is activated, the data you transmit to us cannot be read by third parties. Our entire infrastructure (website, API, database connections) exclusively uses encrypted connections.
8. Customer Accounts and Event Registration
We distinguish between two types of users of our platform, which result in different data processing:
Customer Registration (Event Organizers)
Event organizers can register on our website to gain access to our SaaS platform and create and manage events. This constitutes a contract for the use of our services.
The following mandatory information is collected during customer registration:
- Email address (as username and for communication)
- Name (first and last name of the contact person)
- Company name/organization (optional)
- Password (stored in encrypted form)
Additional information may be provided optionally to complete the profile. Processing is based on Art. 6(1)(b) GDPR for contract performance.
Event Participants (Guests without a Customer Account)
Event participants register directly for specific events without creating a customer account with us. They interact exclusively with the event pages of our customers. In this case, we act as a data processor for the respective event organizer.
The following data may be collected during event registration (depending on configuration by the event organizer):
- Name and contact details
- Event-specific information (e.g., dietary requirements, hotel rooms)
- Attendance confirmations and check-in status
- Payment information (processed via Stripe)
Important Note: The respective event organizer (our customer) is legally responsible for event participant data. Please address questions about your participant data directly to the organizer.
Data Deletion
Customer Account Data: Data collected during customer registration is stored for as long as the customer account exists. Upon account deletion, data is deleted unless statutory retention periods apply.
Event Participant Data: This is managed in accordance with the requirements of the respective event organizer and applicable retention periods.
9. Data Processing for Event Organizers
As a SaaS platform for event management, we process participant data on behalf of our customers (event organizers) for their events. In this relationship, we act as a data processor within the meaning of Art. 28 GDPR.
Different Data Processing Roles
For our customers (event organizers): We are the controller for their customer account data and the provision of our SaaS services.
For event participants: We are the data processor and process their data exclusively on behalf of and in accordance with the instructions of the respective event organizer.
Participant Data Processed
Depending on the event configuration by our customers, the following participant data may be processed:
- Name and contact details of event participants
- Event-specific registration data and preferences
- Selection of options (e.g., workshops, meals, accommodation)
- Check-in status and attendance confirmations
- Payment data (processed via Stripe as payment service provider)
Legal Basis and Responsibility
Controller for Participant Data: The respective event organizer (our customer) is the data controller for all participant data of their event and determines the purposes and means of data processing.
Our Role: We process participant data exclusively in accordance with the instructions of the event organizer and on the basis of a data processing agreement pursuant to Art. 28 GDPR.
Your Rights as Event Participant: For questions about your participant data, or requests for access, correction, or deletion, please contact the respective event organizer directly, as they are the data controller.
10. Retention Periods
The retention period depends on the role in which we process your data:
Customer Account Data (Event Organizers)
For data for which we are the controller:
- Customer Account Data: Until deletion of the customer account
- Billing Data: 10 years (statutory tax retention obligation)
- Contract Data: 6 years after contract end (§ 257 HGB)
- Support Communications: 3 years after last contact
Event Participant Data (Data Processing)
For participant data for which we are the data processor:
- Event Participant Data: As required by the event organizer, maximum 7 years after the event
- Check-in Data: In accordance with the deletion requirements of the event organizer
- Payment Data: In accordance with payment service provider requirements (Stripe)
Technical Data
System-related data independent of user role:
- Server Logs: Maximum 30 days
- Analytics Data: 26 months (Google Analytics standard, only with consent)
- Security Logs: 12 months for security purposes
Deletion Requests: Customers may request the deletion of their customer account data at any time. Event participants should contact the respective event organizer for deletion requests.
11. International Data Transfers
The processing of your data takes place within the European Union and the European Economic Area. Our hosting, our database, our file storage, and our email dispatch all run on servers within the EU; hosting and storage are in Germany.
Some of the service providers we use are companies whose parent company is based outside the EU, even though the processing itself takes place within the EU:
- Twilio (SendGrid): contracting party Twilio Ireland Limited, processing via EU Data Residency.
- Stripe: contracting party Stripe Payments Europe Limited, Ireland; processing within the EU/EEA.
- PostHog: contracting party PostHog, Inc., USA; processing exclusively on the European instance.
Where a contracting party is established outside the EEA, the transfer is covered by standard contractual clauses pursuant to Art. 46(2)(c) GDPR. A current list of all processors, stating the contracting party, its registered office, and the place of processing, is available from us on request.
12. Contact and Complaints
For questions about the collection, processing, or use of your personal data, or for requests for information, correction, blocking, or deletion of data, and revocation of granted consents, please contact:
Quick-Event — a brand of ThePlus UG (haftungsbeschränkt)
Hüchtingstraße 5
28816 Stuhr
Germany
Email: info@quick-event.com
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority regarding our processing of personal data. The competent authority is the supervisory authority of your habitual residence, your place of work, or our company's registered office.
The competent authority for our company is:
The State Commissioner for Data Protection Lower Saxony
Prinzenstraße 5
30159 Hanover
Website: https://lfd.niedersachsen.de
13. Data Processing Agreement (Art. 28 GDPR)
If you use Quick Event to run your own events, you are the controller for your participants’ data and we act as your processor. For that relationship we provide a ready-to-sign data processing agreement together with its two annexes:
- Data processing agreement (PDF)
- Annex 1 — Technical and organisational measures (PDF)
- Annex 2 — Processors and where data is held (PDF)
Add your details, sign, and send the agreement to info@quick-event.com; you will receive a counter-signed copy. If your organisation requires its own template instead, write to the same address.
Annex 2 is also the current list of the processors we use, stating the contracting party, its registered office, and the place of processing.