Privacy Policy
Last updated: October 2026
This privacy policy is for everyone who registers for or attends an event that runs on Quick Event: event pages, registration, tickets and wallet passes, event emails, the event app and check-in.
Are you an event organiser with a Quick Event account, or are you visiting our website quick-event.com? Then our privacy policy for organisers and website visitors applies.
1. Who is responsible for your data
The organiser of the event decides which data is collected when you register and what it is used for. The organiser is therefore the controller within the meaning of Art. 4(7) GDPR. You will find the organiser’s name — and, where they provide them, their own privacy policy and imprint — in the footer of the event page.
We, ThePlus UG (haftungsbeschränkt), provide Quick Event as the technical platform. We process your data solely on behalf of and on the instructions of the organiser, as a processor pursuant to Art. 28 GDPR. A data processing agreement is in place between the organiser and us. We do not use participant data for our own purposes, do not sell it and do not combine it across events.
Please address requests for access, rectification or erasure to the organiser. If you contact us instead, we forward your request to the organiser without delay.
Quick Event — a brand of ThePlus UG (haftungsbeschränkt)
Hüchtingstraße 5
28816 Stuhr
Germany
Email: info@quick-event.com
2. What data is processed, and why
Which fields are asked for is decided by the organiser. Depending on the event, this can include:
- Master data: name, salutation, title
- Contact data: email address, phone number, postal address
- Organisation data: company, position
- Booking and ticket data: ticket types, options chosen (for example workshops, meals, accommodation), prices, invoices
- Attendance data: check-in and check-out at the entrance and at individual sessions
- Communication data: whether an event email was delivered or bounced
- Further information the organiser asks for in the registration form
Payment details such as card or bank data are entered directly with the payment provider Stripe. We neither receive nor store them.
The data is used to handle your registration and tickets, to manage invitations, to send you information about the event, for admission including name badges, and for the organiser’s evaluation of the event. The legal basis is determined by the organiser — usually Art. 6(1)(b) GDPR (your participation), Art. 6(1)(a) GDPR where the organiser asks for your consent, and Art. 6(1)(f) GDPR.
3. Where your data is held
Quick Event runs on servers of Hetzner Online GmbH in Germany. The live system is in the Nuremberg data centre, backups are in the Falkenstein data centre. The database and the storage for uploaded files are operated by us on this infrastructure.
- Encryption: all connections run over TLS; storage media and backups are encrypted.
- Separation: every record belongs to exactly one event, and every query is restricted to that event. Only the organiser of that event and the people they have invited to it can access it.
- Backups: continuous, kept for at least 30 days.
- Server logs: when you open a page, the server records IP address, time, page requested, browser and operating system. This is necessary to deliver the page and to detect faults and attacks (Art. 6(1)(f) GDPR). Log entries are deleted after 30 days.
4. Service providers
We use the following service providers as sub-processors. Each is bound by a data processing agreement pursuant to Art. 28 GDPR. For each we state the contracting party with its registered office and, separately, where the data is processed — the two are not always the same.
Hetzner Online GmbH — hosting, database, file storage
Industriestr. 25, 91710 Gunzenhausen, Germany. Processing: data centres in Nuremberg and Falkenstein, Germany.
Twilio Ireland Limited (SendGrid) — event emails
3 Dublin Landings, North Wall Quay, Dublin 1, D01 C4E0, Ireland. Processing: EU data centres (SendGrid EU Data Residency). Used for confirmations, tickets and invitations. Open and click tracking is switched off: our emails contain no tracking pixels, and links are not rewritten.
Stripe Payments Europe, Limited — payments
1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, D02 H210, Ireland. Processing: EU/EEA. Only for paid tickets; you enter your payment details directly with Stripe.
PostHog, Inc. (PostHog Cloud EU) — error monitoring and usage analysis
San Francisco, California, USA. Processing: exclusively on the EU instance. To detect technical faults, we record page views and error messages. On event pages and in the event app, nothing is stored in your browser for this: visits are counted using a server-side hash that changes daily. Data is sent via our own domain. There is no session recording, and clicks and entries are not captured automatically.
Google Ireland Limited (Gemini API) — AI features, only if the organiser uses them
Gordon House, Barrow Street, Dublin 4, Ireland. Processing: EU. Only if the organiser switches on the AI assistant of the event app: when you ask it something, your message and the event information needed to answer it — agenda, speakers, exhibitors, your own agenda and profile, and attendee profiles visible to you — are processed by Gemini. If the organiser does not use this feature, no participant data reaches an AI service.
No other service provider receives participant data. This list is identical to Annex 2 of our data processing agreement (see section 9). We announce any change to it in advance.
5. Cookies and tracking on event pages
Event pages and the event app store nothing in your browser that requires your consent. What they store is technically necessary: your language, your sign-in to the event app, your cookie choice where a banner is shown, and your decision to load embedded content.
Quick Event runs no advertising or analytics tags of its own on event pages and in the event app.
To show organisers how many people visit and register, we also count visits to the event page and the registration ourselves: once per day and device, using a hash that changes daily. Your IP address is not saved, no cookie is set, and the approximate city is determined on our own server, without a request to a third party.
- The organiser’s own tracking: organisers can connect their own analytics and advertising accounts (Google Analytics 4, Google Ads, Meta, Microsoft Advertising). Only then does the event page show a cookie banner, and nothing of it is loaded before you agree (Art. 6(1)(a) GDPR together with § 25(1) TDDDG). For Google Analytics 4, Google Ads and Meta, registrations and ticket purchases are relayed server-side via our own tagging server in Germany; Microsoft Advertising loads in the browser after consent. The organiser is responsible for this tracking. You can withdraw your consent at any time in the cookie settings with effect for the future.
- Embedded content: if the organiser embeds a video (YouTube, Vimeo), it is only loaded when you click it. Only then does the provider receive your IP address and technical browser data. Your choice is remembered on this device. Maps are delivered from our own servers (map data © OpenStreetMap contributors, via OpenFreeMap), so no third party receives your data; Google Maps only opens if you tap the route button.
- Push notifications: if you allow notifications in the event app, they are delivered by your browser’s push service (for example Google, Apple or Mozilla, depending on your device). The content is end-to-end encrypted; the push service only sees that a message is delivered. You can turn notifications off at any time.
The providers of these tools may also process data in the USA. Such transfers are based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR).
6. Transfers outside the EU
The platform itself — hosting, database, file storage, email dispatch, payments and error monitoring — runs entirely within the EU, and the platform’s data is held in Germany. PostHog’s contracting party is based in the USA, while processing takes place on the EU instance; standard contractual clauses pursuant to Art. 46(2)(c) GDPR are in place for this. Beyond that, data only leaves the EU through the organiser’s tracking after your consent, through embedded content you choose to load, and through push notifications you switch on.
Events without service providers that have a US parent company
At the organiser’s request, we run an event entirely without service providers that have a US parent company. Only Hetzner in Germany then processes the data: there is no online payment, no email (you save your ticket on the confirmation page and sign in to the event app with your personal link), no error monitoring, no AI features, no organiser tracking, and embedded videos and maps only appear as links. Push notifications remain available if you switch them on yourself; their content is end-to-end encrypted. We confirm all of this to the organiser in the data processing agreement.
7. How long your data is kept
How long participant data is kept is decided by the organiser. When our contract with the organiser ends, we hand over all data to the organiser and then delete it verifiably, unless statutory retention obligations apply. Backups are overwritten in their normal cycle. Server logs are deleted after 30 days.
8. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Where processing is based on consent, you can withdraw it at any time with effect for the future. Please address these requests to the organiser of the event; we support the organiser in answering them.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the country of your habitual residence or place of work. The authority competent for us is the State Commissioner for Data Protection Lower Saxony, Prinzenstraße 5, 30159 Hanover, lfd.niedersachsen.de.
9. For organisers: data processing agreement
If you run your events on Quick Event, you are the controller for your participants’ data and we are your processor. The data processing agreement and its annexes are ready to sign:
- Data processing agreement (PDF)
- Annex 1 — Technical and organisational measures (PDF)
- Annex 2 — Processors and where data is held (PDF)
Add your details, sign, and send the agreement to info@quick-event.com; you will receive a counter-signed copy.