Legal

Privacy Policy

This privacy policy explains which personal data we process in connection with Eventcodes and what rights you have.

Last updated: July 2026

1. Controller

The controller responsible for data processing is: Wudio GmbH Platz der Vereinten Nationen 6 10249 Berlin Germany Email: kontakt@eventcodes.de Represented by Managing Director Nico Schuck.

2. Overview

Eventcodes is a platform for managing and distributing invitation codes for events. We process personal data primarily to provide accounts and workspaces, handle code requests, send transactional emails, process payments, and ensure the technical security and analytics of event links.

We do not operate marketing tracking or advertising pixels on the website. Unless stated otherwise, processing is based on Art. 6(1)(b) GDPR (contract or pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest).

3. Hosting and infrastructure

The application is operated in EU data centers (including via DigitalOcean). Server logs (e.g. IP address, time, requested resource) may be created temporarily for operations, security, and troubleshooting.

  • Databases and cache (MongoDB / Redis or Valkey)
  • Object storage for images and files (DigitalOcean Spaces, EU region)
  • Legal basis: Art. 6(1)(b) and (f) GDPR

4. Account and dashboard login

To use the dashboard, you sign in with your email address. We send you a time-limited one-time code (OTP) by email. After successful verification, we create or update your user account.

  • Data: email address, optional name, language settings, active workspace, timestamps
  • OTP codes are stored only briefly and then deleted
  • Session cookie to maintain login (httpOnly, Secure)
  • Legal basis: Art. 6(1)(b) GDPR

5. Workspaces and team members

In workspaces you manage events, codes, settings, and team access. For invitations we process the invitee’s email address as well as role and invitation status.

  • Workspace name, members, and roles
  • optional workspace contact details and verified contact emails
  • API keys, if generated by you
  • Legal basis: Art. 6(1)(b) GDPR

6. Events, codes, and media

You can create events, configure forms, import invitation codes, and upload media. We store this content so the event page and code distribution work.

  • Event content (title, description, venue, schedule, agenda, design)
  • Event contact email for notifications
  • Invitation codes including claim status and associated recipient data
  • uploaded images/files in object storage
  • Legal basis: Art. 6(1)(b) GDPR

7. Visitor code requests (portal)

Visitors of an event page can request codes via the request form. We first verify the provided email address with an OTP. After successful verification we store the request and notify the contact email configured for the event.

The information submitted in the request form is processed solely to handle the application process – in particular to identify the requester, review and approve the request, and send invitation codes. Before submitting, the person must consent to their data being processed for this process.

  • Required: email address, requested number of codes, and consent to data processing for the application process
  • optional depending on event settings: first name, last name, company, position in the company, phone, relationship (client / employee / other), message (max. 500 characters)
  • Request status (e.g. open, approved, rejected) and timestamps
  • On approval, ticket codes may be sent to the verified email
  • Legal basis: Art. 6(1)(b) GDPR (handling the request) and Art. 6(1)(a) GDPR (consent to processing in the application process); optional fields according to the form settings you configure
  • Retention: request data is automatically deleted 3 years after the respective event ends

8. Email delivery

For transactional emails we use Mailjet. Only data required for the respective purpose is transmitted (e.g. recipient address and message content).

  • Login code for the dashboard
  • Verification code for code requests
  • Notification to the event contact email about new requests
  • Delivery of approved ticket codes
  • Workspace invitations
  • Legal basis: Art. 6(1)(b) GDPR

9. Payments and credits

Credit purchases and the customer portal are handled via Stripe. Stripe processes payment and billing data as an independent payment provider and/or processor. We store workspace billing data (e.g. billing address, VAT ID, Stripe customer reference) and booking records in the credit ledger.

Legal basis: Art. 6(1)(b) GDPR and statutory retention obligations (Art. 6(1)(c) GDPR).

10. Usage statistics for event links

When an event link is opened we collect technical usage data so workspace users can evaluate visits and reach, and so we can detect abuse.

  • IP address (including for deduplication, hashed/short-lived)
  • approximate location via local GeoIP database (country/region/city)
  • browser, device, and platform information
  • timestamp and aggregated view counts
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analytics and operational security)

11. Cookies and local storage

For login and session management we set a necessary session cookie (connect.sid). The browser may also use local storage for UI state. We do not set marketing cookies.

Legal basis for strictly necessary cookies: Art. 6(1)(b) or (f) GDPR.

12. Recipients and processors

Personal data may be transmitted to the following service providers where required for operation:

  • DigitalOcean – hosting, database, cache, object storage (EU)
  • Mailjet – transactional email delivery
  • Stripe – payment processing and customer portal
  • Workspace users of the respective event (e.g. request details in the dashboard / by notification)

13. Retention

We store personal data only as long as necessary for the stated purposes or as required by law.

  • OTP codes: a few minutes
  • Accounts, workspaces, events, and codes: for the duration of use or until deleted by you
  • Session data: for the duration of login or until the session expires
  • aggregated link statistics: limited period for analytics
  • billing and payment data: according to commercial and tax retention periods
  • Portal code requests: automatic deletion 3 years after the respective event ends

14. Your rights

Subject to statutory requirements, you have the following rights vis-à-vis us:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future

15. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. In particular, the Berlin Commissioner for Data Protection and Freedom of Information is competent, or the authority at your habitual residence.

16. Customer responsibility for event content

If you operate event forms as a workspace user and collect visitor request data, you are responsible for the lawfulness of your own processing (including informing data subjects and your own legal bases) to the extent you determine purposes and means. Eventcodes provides the technical platform.

17. Changes

We may update this privacy policy if processing or the legal situation changes. The current version is always available on this page.

For privacy questions, please contact Kontaktseite