Skip to content

What happens at the party stays in the team.

An album behind a PIN. The photos sit on servers in the EU. Expiry date included.

BetaEventDrop for business is new, and we are developing it further with the first companies; feedback is welcome at office@gotzendorfer.at.

Database, authentication and photos are stored in Frankfurt am Main (eu-central-1), and the server functions run there too. Delivery goes through a global network, and some service providers are based outside the EU. So we explicitly do not promise that no data ever leaves the EU — ask, and you get the full list.

All processors in the privacy policy

Why a company party is not a wedding

At a private party the GDPR does not apply to the host at all — that is the household exemption. At a company party it falls away, and it falls away completely: any professional context ends it. That makes your company the controller, and it makes us the processor.

That is not an argument against a photo album. It is an argument against what replaces it today. A WhatsApp group, AirDrop, the assistant’s private cloud album: no deletion deadline, no contract, no withdrawal — and three years later the photos sit on forty private phones. The company would be just as responsible there. It is only that nobody notices.

So we do not promise you that “privacy is not a problem”. In the end it is you who has to be compliant, not a tool. We supply the parts you need for that — and we say, every time, where they stop.

Three properties an IT sign-off comes down to

  • An expiry date nobody has to remember

    The runtime is fixed when the event is created — 90 days on Spotlight, 365 on Premiere, counted from the event date. After that the album closes. 30 days later the photos are deleted, without anybody having to think of it.

  • A closed circle

    From Spotlight upwards the album can be closed with a PIN. Guests need no account and no app; storage is not public, and every image is served through a short-lived link rather than a permanent address. GPS coordinates are stripped from images on upload — and if stripping fails, the upload is rejected rather than stored.

  • One delete button instead of forty

    One click deletes the event: nine data tables and two storage areas, in a single pass. If any step reports an error, the operation counts as failed rather than done — a “deleted” with something still behind it would be the opposite of an answer.

Is AI running over our people’s faces?

No. There is no face recognition, no matching of individuals and no recognition across photos — not switched off, but never built.

What you switch off per event

Under “AI” inside an event you find the helpers that concern this event, each with a switch:

  • Photo analysis: checks new photos, suggests highlights, describes images
  • Invitation text: suggests wording for the invitation

The AI overview sits inside every event under “AI”

And what a per-event switch does not reach

Two surfaces run account-wide rather than per event: the suggestions while creating an event, and the support chat. A switch on the event does not reach them, and we will not pretend otherwise. If you need them off, write to us — then we will tell you what is possible.

What switching it off costs you

Without photo analysis there is no automatic check of new photos, no highlight suggestions, and the recap selects without those signals. This is stated here and not in the small print: finding it out yourself later is the most expensive way to learn it.

As long as the album stays internal, nobody needs to sign anything. The moment a picture goes outside, you need a signature from exactly the people in it.

What to do, and when an email is enough

Guideline answers for the cases that actually come up. The legal basis throughout is legitimate interest under Art. 6(1)(f) GDPR, not consent: in an employment relationship consent counts as only partly voluntary, and it can be withdrawn at any time.

Guideline answers for company parties
SituationWhat is enoughWhat is not enough
The album stays internal, PIN on, nothing goes outsideA notice and an email to everyone. No signatures. Basis: legitimate interest—
A photo is to go on the website, on LinkedIn, into recruitingIndividual, written consent from the recognisable people — beforehand and purpose-specific — plus the permission of the person who took the photoA notice · taking part in the album · “nobody objected, did they”
Portraits and small groups instead of atmosphere shotsConsent, internally as wellblanket information
Every company party, whatever the size of the companyA data processing agreement, plus a notice, an email and the record-of-processing paragrapha verbal assurance
Company with its own data protection officerthe same; involve the officer beforehand and name them in the agreementapproval that bypasses the officer
With a works council or staff representationA note beforehand. A works agreement would be needed if there were per-person evaluations — there are nonea surprise the next morning
Children at the partyParental consent, always—
Public body, corporate group, or the works council says noAll AI switches off, PIN on, short runtime — when in doubt ask your own data protection officerplaying it down

Guideline answers, not legal advice. Whether consent is required in a specific case is for the controller to judge — that is you.

You get the contract here, not by email

The data processing agreement under Art. 28(3) GDPR is readable on the page: subject matter and duration, nature and purpose, categories of data, instructions, confidentiality, technical and organisational measures, sub-processors, assistance with data subject rights, deletion at the end of the contract, records and audit rights. Plus the annex with the technical measures and the list of sub-processors.

Go to the data processing agreement

Version 2026-10-01

Questions that come up during sign-off

Do we really need a data processing agreement for the Christmas party?

As soon as the use is professional or commercial, yes — then you are the controller and we are the processor, and Art. 28(3) GDPR requires a contract for that. You conclude it yourself, with no email exchange and no waiting.

Is a notice enough, or do we need signatures?

As long as the album stays internal, a notice and an email to everyone are enough. The moment a picture goes outside — website, LinkedIn, recruiting — you need written consent from exactly the recognisable people, beforehand and purpose-specific.

Is AI running over the photos?

There is no face recognition and no matching of individuals. The two helpers that concern this event — photo analysis and invitation text — you switch off inside the event under “AI”. Two further surfaces, the suggestions while creating an event and the support chat, run account-wide; a switch on the event does not reach them.

Where are the photos stored?

Database, authentication and file storage are in Frankfurt am Main (eu-central-1), and so are the server functions. Delivery runs through a global network, and some service providers are based outside the EU — so we do not promise that no data leaves the EU. Which provider processes what is set out in full in the privacy policy and in the annex to the contract.

What happens after the party?

The album runs for the period you bought and closes afterwards. 30 days later the photos are deleted. If you want to clear up sooner, delete the event yourself — that removes data and files in a single pass.

Do we have to involve the works council?

A note beforehand is the calmer route. The album is well defensible as not being a monitoring measure: participation is voluntary, uploading needs no account and no name, there is no per-person evaluation, no link to HR data, and it ends with the expiry date. Somebody only has to write that reasoning down once.

May we use the photos internally afterwards, for example on the intranet?

Only with permission from the people who took them: the rights to a photo lie with the person who took it, including employees who take photos privately at the party. That is what the “Internal use by the organiser” switch in the event settings is for. When it is on, guests see a notice before uploading, and by uploading they allow you to use their photos internally, for example on the intranet or in internal communications. This applies to photos uploaded while the switch is on. Publishing outside the organisation still requires the consent of the person who took the photo and of the people shown.