Privacy Policy
Last updated: October 10, 2026
Last updated: October 10, 2026
Last updated: October 10, 2026
Bernhard Götzendorfer
Rittingergasse 15/11
1210 Vienna, Austria
Email: office@gotzendorfer.at
For events that a company or another organisation holds through EventDrop in the course of its professional or business activity (a company party, for example), that organisation is the controller for the photos and videos uploaded there and for the names, comments and reactions provided; we then process these data on its behalf (Art. 28 GDPR). Requests concerning these data are best addressed to the organisation; if they reach us, we forward them. For the processing we carry out under our own responsibility at such events as well — for example abuse protection via the IP address, error monitoring, handling reports under the Digital Services Act, counting the use of the service per event, and billing — we remain the controller, and this privacy policy applies.
We process personal data only to the extent necessary for providing our services. Processing is carried out on the basis of the GDPR (General Data Protection Regulation) and the Austrian DSG (Data Protection Act).
When you visit our website, the following technical data is automatically collected: IP address, browser type, operating system, referrer URL, time of access. This data is necessary for the technical operation of the website (legal basis: Art. 6(1)(f) GDPR — legitimate interest).
When creating an account we collect: email address, and optionally your name (when you sign in with Google on the website; this is not available in the app). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
When photos are uploaded, we process: image files, upload timestamp, event association, and optionally the uploader's name (max. 100 characters). From the photo's EXIF metadata we keep only the capture date and time (the camera's clock), so the gallery can be grouped by day; all other EXIF metadata, including GPS location data, is automatically stripped on upload (privacy protection measure). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
Payment data is processed directly by our payment service provider Stripe. We do not receive complete credit card numbers. We store: payment status, invoice data, selected plan, Stripe payment ID. Available payment methods are currently credit card, EPS, and Klarna, plus Apple Pay and Google Pay on supported devices and, depending on country and device, further payment methods provided by Stripe such as Link, Amazon Pay, or Bancontact (via Stripe Automatic Payment Methods). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
After buying a package or an upgrade, the confirmation page asks you how you heard about EventDrop (a choice from a fixed list, optionally a short free text). Answering is voluntary, and you can skip the question. We store your answer separately from the payment data, linked to your purchase, and delete it after 13 months — earlier, together with your account, if you delete it first. Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding how buyers find EventDrop.
When a photo is reported by a user, we collect: reason for the report, optional description, reporter's IP address, timestamp, the associated photo/event reference, and — if provided — the optional email address and language of the reporting person. The event owner is notified by email.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting users from inappropriate content and maintaining platform integrity. For the optional email address and language: Art. 6(1)(c) GDPR in conjunction with Art. 16(5) DSA (legal obligation) — used exclusively to inform the reporting person of the outcome of our review, as required by the Digital Services Act. Report data is retained for the duration of the event plus 30 days.
In addition, every report is sent as a copy by email (delivered via Resend, see section 5) to our support mailbox office@gotzendorfer.at: reason, description, time, title and code of the event, and the identifiers of the photo and of the report — without the email address of the reporting person. This lets us review the report ourselves when a legal violation is reported or when the reporting person disagrees with the event creator's decision. If you have entered an email address, we promptly send you a confirmation of receipt (Art. 16(4) DSA) and later the notice of the decision. Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 16(4) and (6) DSA. The copy in the support mailbox is not deleted automatically together with the report; we keep it to handle the report and to demonstrate compliance with our obligations under the DSA, and delete it six months after receipt of the report – if the reported photo is held as evidence for an authority, only once the authority releases it.
When a co-admin is invited to manage an event, we collect: invited person's email address, invitation token (UUID), invitation status (pending/accepted), date of invitation, and the inviting user's reference.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (enabling collaborative event management as part of the service). Invitation tokens expire automatically after 7 days. Co-admin memberships are retained until the event is deleted.
When a plan upgrade is performed, we create an audit record in theplan_changestable containing: event reference, previous plan, new plan, price paid, Stripe payment ID, and timestamp.
Legal basis: Art. 6(1)(c) GDPR — legal obligation. This data is part of our accounting records and must be retained for 7 years in accordance with the Austrian Federal Fiscal Code (§ 132 BAO).
If you participate in the commission program as an event helper, we process the following data:
Legal basis: Art. 6(1)(b) GDPR — performance of the commission program contract.
Retention: 7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code) for tax-relevant records.
If you apply for the EventDrop Partner Program, we process the following data:
Legal basis: Art. 6(1)(b) GDPR — performance of the partner program contract.
Retention: Financial records (commission amounts, payouts, IBAN/BIC) are retained for 7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code). Non-financial data (name, website, motivation) is deleted upon partner account closure or program termination.
We use Sentry (Functional Software, Inc., San Francisco, USA) to detect errors and performance problems in our application and to keep it stable and secure. The following is transmitted:
Data minimisation: We have set the automatic collection of the Sentry SDK explicitly for every data category. On its own, the SDK collects no user data or IP addresses, no cookies, no content of HTTP requests and responses, no values of local program variables, no database query results and no content of AI requests or responses. No photo contents are ever transmitted. As error context we transmit the result of a server action (for example success or an error code), unless it carries access capabilities or extensive personal data. Addresses and technical headers of requests (e.g. browser type, language) are transmitted without the headers that carry an IP address or a user identifier; we remove email addresses and access capabilities before sending. We do not record session replays.
Transmission route: Error reports and performance data from your browser are sent to Sentry via an address on our own domain (eventdrop.at/monitoring). Our server forwards only the report itself, without your IP address and without any other details of your request; Sentry sees our server as the sender. CSP reports are sent by your browser directly to Sentry; in doing so, Sentry technically receives your IP address.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the stability and security of the application. You can switch off the performance measurement in your browser with the “Usage measurement” switch in the cookie settings (objection under Art. 21(1) GDPR); the transmission of errors is not affected.
Retention: Sentry deletes the data after 90 days at the latest.
Data transfer: Data may be processed in the USA. Sentry is certified under the EU-U.S. Data Privacy Framework; transfer basis: Art. 45 GDPR (adequacy decision), in the alternative EU Standard Contractual Clauses (Art. 46 GDPR).
EventDrop is also available as an app for iOS (App Store) and Android (Google Play). The app is a companion app for hosts: it displays the eventdrop.at service in an embedded browser view. The processing described in this Privacy Policy for the website therefore applies, with the following specifics:
We use cookies to ensure the basic functions of the website and to improve your user experience. The legal basis for the use of technically necessary cookies is § 165 TKG 2021 (Austrian Telecommunications Act). For non-essential cookies (functional, marketing), we obtain your prior consent in accordance with § 165(3) TKG 2021 and Art. 6(1)(a) GDPR.
Cookie categories:
sc_guest) is set as soon as you open an event gallery or upload page. It holds a random identifier, never your name, is HttpOnly (your browser does not let any script read it), signed by us, and expires after 24 hours. It is what lets you take back your own reaction and delete a photo you uploaded with "Remove my photo", keeps your personal progress on an event's photo tasks, links an anonymous support inquiry to your own session, lets the host see how many guests contributed photos, and keeps you on the same display variant while we compare two layouts of a page. For that comparison we only count, per variant, that a section was seen and whether it was clicked — no profile is built, and the identifier is not written to those counts. Legal basis: § 165(3) TKG 2021 and Art. 6(1)(f) GDPR — the cookie is technically necessary for the functions you are using, so we do not ask for consent for it.ed_promo_seen) so it was not shown to you again. That pop-up no longer exists, so no new cookie of this kind is written; if your browser received one earlier it is still there, is never read, carries no value other than “dismissed”, and expires on 3 October 2026 at the latest. Legal basis: § 165(3) TKG 2021 — strictly necessary cookies are exempt from the consent requirement.eventdrop-shared) until you confirm them on an event’s upload page. The files stay on your device and are only transmitted to us when you actually upload them. They are discarded automatically after 24 hours, and immediately once you have accepted or discarded them. Legal basis: § 165(3) TKG 2021 — without this temporary storage the sharing action you triggered yourself cannot be carried out.eventdrop-saved) of which uploads you have already saved, so that only new ones are offered to you on your next visit — and whether you have dismissed the note about saving to Google Photos. Stored per entry: the event ID, the upload ID, a checksum of the file, the time, the method used, and the file size — no names, no photo. The data never leaves your browser, and it is only created the first time you actually save something, not merely by opening the gallery. It is removed when you clear this website’s data in your browser; in Safari it is removed automatically after 7 days without a visit, unless you have added the page to your home screen. Legal basis: § 165(3) TKG 2021 — without this local record the save function you triggered yourself could not tell new files from ones you already have.eventdrop-last-event: event code, event title and time of the visit, 30 days) so that we can offer you a direct way back to it after you share photos through your device’s share menu. This entry is only written if you consent to this category, it never leaves your device, and it is removed automatically after 30 days. If you decline this category, we remove the stored preferences and this entry when you save your settings. Legal basis: Art. 6(1)(a) GDPR.ed_ref) stores for 30 days which partner referred you to EventDrop (first-click attribution). Set only with your consent. Legal basis: Art. 6(1)(a) GDPR.ed_src) stores for 30 days which campaign channel (e.g. QR flyer, print ad) brought you to EventDrop (first-click attribution). Set only with your marketing consent. When you register an account or create an event, we additionally store the resulting channel as a short text value on that account or event — not as a cookie on your device, and never the advertising click identifier itself (see section 6). Legal basis: Art. 6(1)(a) GDPR.ed_click) stores for 90 days the click identifier (gclid, gbraid, wbraid from Google Ads or fbclid from Meta) that the advertising platform appends to the link of an ad you clicked (first-click attribution), so that an order placed days later can still be attributed to that ad. A second cookie (ed_utm) stores, for the same period, the campaign labels from that link (utm_source, utm_medium, utm_campaign, utm_content, utm_term) — short text values naming the campaign, not you. Both are set only with your marketing consent and deleted when you withdraw it. On our marketing landing pages and on the order confirmation page, the Google tag additionally sets its own cookie (_gcl_aw) linking that click to your visit — and, once an order is confirmed, to the conversion. What we use this for is described in section 5d. Click and campaign identifiers contained in the address you opened are held only transiently in your browser’s memory until you decide; without your consent we discard them with the next page you open. At registration and when an event is created we additionally store the campaign labels and the TYPE of the click identifier (gclid/gbraid/wbraid/fbclid) as text values on that account or event — only if you gave marketing consent, and never the click identifier itself (see section 6). Legal basis: Art. 6(1)(a) GDPR._fbp) is set by the Meta pixel (Facebook/Instagram ads) on our marketing landing pages, when you create an event, and on the order confirmation page — only with your marketing consent — and stores a browser identifier for up to 90 days so that Meta can measure whether one of our ads led to a visit, an event being created, or an order. Without marketing consent the Meta pixel is not loaded at all. Details on what is transmitted: section 5. Legal basis: Art. 6(1)(a) GDPR.Cookieless usage measurement. We measure the use of this website with Vercel Web Analytics and Vercel Speed Insights: which pages are used and how fast they load. Neither sets a cookie nor accesses information stored on your device — so we do not ask for consent for it. The identifier a visit is grouped under expires after at most 24 hours; you are not recognised across several days or on other websites. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in knowing which pages are used, where visitors leave, and whether the site loads fast enough. You can switch this measurement off at any time — in the cookie banner under “Settings”, switch “Usage measurement”. That is your objection under Art. 21(1) GDPR.
Timestamp, the page and page type requested, referring website, campaign parameters from the address (utm_source, utm_medium, utm_campaign, ref), approximate location at country, region and city level, device type, browser and operating system; for Speed Insights additionally page-load measurements. Vercel evaluates your IP address only to derive that approximate location and the identifier, and does not store it. In addition, named partner-programme events (page view, application start, checkout start), ratings of help articles (helpful yes/no, together with the article) and, on the home page, whether the pricing section came into view and clicks on links to create an event (where on the page the link sat, the plan preselected in it if any, and which version of the home page was shown) — without name, email address or account ID, but linked to the same daily identifier as your page views. Recipient: Vercel Inc., see processors below.
We work with the following service providers. All listed providers based outside the EU/EEA rely on a valid transfer mechanism under Chapter V GDPR: either an adequacy decision (for the US: the EU-US Data Privacy Framework, DPF, Art. 45 GDPR) or EU Standard Contractual Clauses (SCCs, Art. 46 GDPR). The mechanism relied upon is stated for each provider below. Should the transfer basis relied upon for a provider change, we will update this information beforehand and state the mechanism then relied upon (adequacy decision or appropriate safeguards pursuant to Art. 46 GDPR).
Data Processing Agreements (GDPR Art. 28): The data processing agreements under Art. 28 GDPR with the listed processors are concluded on their standard terms — depending on the provider, by accepting its terms of service or by a separate acceptance in the customer account. They govern the lawful processing of personal data on our behalf and the required technical and organizational measures. On request we tell you which version applies with which provider; copies are available at office@gotzendorfer.at.
Changes to the list of processors: This list may change. We will inform you of any material change in advance and give you the opportunity to object in accordance with Art. 28(4) GDPR. Version of this list: September 30, 2026.
Uploaded photos are automatically analyzed by artificial intelligence (Google Gemini, called directly via the Google Gemini API). Purpose of processing:
Together with each photo, the event title, the event description, and the event type are transmitted as context to improve the quality of the analysis.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving user experience and protecting against inappropriate content.
The event host can switch the automatic analysis off for their event at any time. Photos uploaded while it is off are not sent to the AI provider, and the upload form then shows no AI notice. Photos that were already analysed keep their results.
Photos are transmitted to the AI provider for analysis and processed solely to provide this feature. Google stores requests only for a limited period in order to detect abuse and does not use them for training. There is no profiling. Your photos are not used to train AI models.
No automated individual decision-making (Art. 22 GDPR): The AI processing does not produce decisions with legal or similarly significant effects on users. There is no profiling as defined by Art. 4(4) GDPR. Tags, highlights and captions serve solely as suggestions and can be overridden by the event owner. If the moderation flags a photo as inappropriate, however, it is hidden automatically for everyone — including the host — and is left out of the ZIP download and the recap video. The photo is not deleted by this, and the flag cannot be lifted in the app.
EventDrop offers an AI-powered support chat to help users with questions about the platform. Requests are processed by the AI language model Google Gemini (Google LLC, see section 5).
Data processed during chat interactions:
Escalation: If the AI assistant cannot resolve your inquiry, the verbatim transcript of your conversation (your messages and the assistant’s replies) together with a short summary, the email address for our reply (your account address if you are logged in, otherwise the one you chose to give in the chat, if any), the page on which you opened the chat, the event code if you were on an event page, and your browser and device details (user agent) is forwarded by email (sent via Resend, see section 5) to our support team (office@gotzendorfer.at) for manual handling. It is used solely to answer that inquiry.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (providing customer support as part of the service). Message contents are not permanently stored and are not used to train AI models. Chat metadata (status, timestamps, session ID, language and — for signed-in users — your user ID; after an escalation additionally the email address for our reply, the page, the event code if any and the browser and device details) is automatically deleted after 90 days — for escalated inquiries after 12 months.
When creating an event, the entered event title may be transmitted to the AI language model Google Gemini (Google LLC, see section 5) to generate:
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (assisting event creation as part of the service). The event title is processed to provide this feature; storage by the provider occurs only within the scope of its API policies (e.g., for abuse monitoring), and it is not used to train AI models. Suggestions are optional and can be modified or ignored by the user.
We advertise EventDrop in Google Ads. So that a later order can be attributed to the ad that led to it, the Google tag (gtag.js, Google LLC — see section 5) runs in two places only: as a pure conversion-linker, without any order data, on our marketing landing pages (start page, pricing, occasion pages, comparison pages and a few more — the definitive list is GOOGLE_ADS_CSP_PATHS in src/lib/analytics/google-ads.ts), and with the actual order data described below on the order confirmation page (/checkout/erfolg). It does not run in event galleries, on upload pages or in your dashboard; on every other page our Content Security Policy blocks any connection to Google’s advertising hosts.
The two places transmit different things. On the landing pages the tag sets its own first-party cookie (_gcl_aw), linking a click identifier already present in the page URL to your visit — no order value, currency, email hash or transaction reference is sent there. The audience-and-remarketing beacon described below runs there too, and carries none of that data either. Only on the order confirmation page, once an order is confirmed, does the tag additionally transmit the order data listed below.
Nothing happens without your marketing consent. Without it the Google tag is not even requested: no connection to googletagmanager.com, no cookie-less advance signals, and no transmission of your IP address to Google. We deliberately use Google’s Consent Mode in its “Basic” variant, not “Advanced” — the latter would send pings to Google before you have decided anything.
When an order is confirmed, the following is transmitted:
ed_click cookie, if one was stored (see section 4).With your marketing consent we also allow Google to use this data for advertising personalisation (Consent Mode signals ad_storage, ad_user_data, ad_personalization) — the same signal also triggers the Google tag’s own audience-and-remarketing beacon on every page where it runs (see above), carrying no order data of its own. We have no influence on Google’s further processing; Google describes it in its own privacy policy. Uploaded photos, event content and your name are never transmitted to Google Ads.
Legal basis: Art. 6(1)(a) GDPR (consent) and § 165(3) TKG 2021 for storing and reading data on your device. You can withdraw your consent at any time in the cookie settings, with effect for the future; the ed_click cookie is then deleted and no Google tag is loaded any more. Recipient and third-country transfer: Google LLC (Mountain View, USA), DPF-certified, transfer basis Art. 45 GDPR — see section 5.
In addition to the scripts in your browser (sections 5 and 5d), we transmit a confirmed purchase directly from our server to Meta (Conversions API) and to Google Ads. Browser scripts frequently fail to run, and without a reliable measurement we would be spending advertising budget on numbers that do not exist.
For a confirmed order we transmit:
ed_click cookie, section 4), which happens only with your marketing consent.To Meta we additionally transmit the creation of an event — the fact alone, without title, without names and without a monetary value. The browser event and the server event carry the same event identifier so that Meta counts them as one event rather than two. With both events we also send Meta the address of the page on which the event took place, without any parameters (eventdrop.at/checkout/erfolg or eventdrop.at/event/erstellen) — the same for every buyer.
Google Ads: the server-side upload happens only when a Google click identifier (gclid, gbraid or wbraid) is available — and that identifier is only ever stored with your marketing consent. Without your consent nothing is transmitted to Google Ads from our server either.
Refund: if an order that we previously transmitted to Google Ads from our server is refunded in full, we also tell Google Ads from our server that it no longer counts as a purchase. For this we transmit only the order reference and the time of the refund. This also happens if you have withdrawn your consent in the meantime, because it only corrects data that has already been transmitted. Legal basis: Art. 6(1)(f) GDPR (accuracy of the measurement data already transmitted).
Meta: the server-side transmission happens only with your marketing consent. It does not depend on a script running in your browser — it also takes place when no Meta pixel was loaded — but it does depend on your consent: we record it at the moment of purchase (or of the event creation; for a purchase as a note in the payment data at Stripe, see section 5) and transmit nothing without it. If no click identifier was stored, what is transmitted is the amount, the currency, the order reference and the email hash. Legal basis: Art. 6(1)(a) GDPR (consent) — the same basis as the browser path (sections 5 and 5d). You can withdraw your consent at any time with effect for the future in the cookie settings; from that moment nothing more is transmitted.
Until they are transmitted, these events are held in a queue on our server and are deleted there automatically after 13 months (see the retention periods below). Uploaded photos, event content and your name are never transmitted to Meta or Google Ads. Recipients and third-country transfer as in section 5: Meta Platforms Ireland Limited and Google LLC, DPF-certified, transfer basis Art. 45 GDPR.
FotoDrop (fotodrop.at) is another service of the same controller (section 1): a family album by subscription. The host or a co-admin of a private event may have photos of the event copied into a FotoDrop album of their family. This is not a transfer to another provider but processing by the same controller for a further purpose: keeping memories of the event privately over the long term.
When: only if you, as host or co-admin, trigger the copying yourself and, to do so, sign in to FotoDrop with the confirmed email address of the account with which you trigger it. Without this step nothing is copied. Company events are excluded.
Which photos: only photos for which a notice about this possibility was shown at upload and whose uploader did not object to the copying. Photos uploaded before that notice are therefore never copied. Also excluded are hidden photos, photos with an open report, photos still awaiting the host's approval, and photos blocked as evidence for an authority (section 6). We currently do not copy videos.
Which data: the image files themselves — without location data, because we already remove GPS data and the other EXIF metadata on upload (section 3.3) —, the capture time, technical details of the file (size, file type, checksum) and identifiers for the photo and the copying; to match the copying to your FotoDrop account, also the email address of the account that triggered it. Not copied: guests' names, file names, image descriptions (including automatically generated ones), comments, reactions, guests' contact details and reports.
Legal basis: for the details of your account and your instruction, the performance of the contract with you (Art. 6(1)(b) GDPR). For the guests who uploaded the photos and for the people shown in them, our legitimate interest and that of the host in keeping memories of the event privately (Art. 6(1)(f) GDPR). This interest is balanced by the exclusions above, the notice at upload and the option to object to the copying or to revoke the license later (Terms, section 10).
Retention: the copies belong to the FotoDrop album and follow its retention periods (FotoDrop privacy policy). The expiry or deletion of the EventDrop event does not delete them. We remove a copy from FotoDrop if the photo is removed in EventDrop because of a report, an erasure request or a revocation by the uploader, or if the host or a co-admin deletes or hides it. We keep the record of a copying (triggering account, time, photos copied) until the event is deleted (section 6).
Your rights: please send requests concerning either service to office@gotzendorfer.at — also after the event has been deleted. Anyone shown in a copied photo can also request its removal without an account via FotoDrop's removal form (fotodrop.at/entfernen). Your rights under section 7 remain unaffected.
Without photos: separately from the copying, there are two links to FotoDrop through which no photos are transferred. The FotoDrop trial link that hosts find in EventDrop carries a signed code without any personal data. And if you redeem a FotoDrop voucher code at EventDrop, FotoDrop learns on request only the status of the code and the time of redemption — not who redeemed it or for which event.
Personal data is deleted as soon as the purpose of processing no longer applies, unless legal retention obligations require longer storage.
Deletion can be suspended: if a photo is blocked as evidence for an authority, we do not delete it until the authority releases it (Art. 17(3)(e) GDPR). That also applies when the event's retention period has expired, when the event is to be deleted or when an account is scheduled for deletion — the deletion of the event concerned and of the account it belongs to is then suspended as a whole and carried out after the release. Only the operator of EventDrop sets and lifts such a block; the reason is recorded in a log.
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Payment & invoice data | 7 years | § 132 BAO |
| Withdrawal declarations via “Withdraw from contract” (name, email address, contract details, optional message, time of receipt) — to process the withdrawal and prove its timely receipt and confirmation | 7 years from receipt | Art. 6(1)(c) GDPR in conjunction with § 13a FAGG, § 132 BAO |
| Account data | Until deletion + 30 days | Art. 6(1)(b) GDPR |
| Event photos | Until manual deletion, at the latest 30 days after event expiry (automatic deletion) | Art. 6(1)(b) GDPR |
| Server logs | 30 days | Art. 6(1)(f) GDPR |
| Server-side usage counters (gallery and live-wall views, ZIP/device saves, print-card downloads, A/B measurements) — plain event counters per event: no name, no IP address, no user identifier and no guest session identifier; linked to the host's account via the event | 365 days | Art. 6(1)(f) GDPR (legitimate interest: measuring and improving the service) |
| Usage measurement (Vercel Web Analytics, Vercel Speed Insights; see § 4) — no cookie and no access to your device; page, referrer, campaign parameters, approximate location, device, browser, load times | Identifier at most 24 hours; evaluation aggregated at the processor | Art. 6(1)(f) GDPR (legitimate interest: reach and load-time measurement; objection under Art. 21(1) via the cookie banner) |
| Advertising click identifier (ed_click cookie, stored on your device; see § 4 and § 5d) | 90 days; deleted when you withdraw marketing consent | Art. 6(1)(a) GDPR |
| Meta pixel identifier (_fbp cookie, stored on your device; see § 4 and § 5) | Up to 90 days; not set without marketing consent | Art. 6(1)(a) GDPR |
| Consent records | 3 years | Art. 7(1) GDPR |
| Photo reports (incl. the optional email address/language of the reporting person, used only for the confirmation of receipt and to notify them of the review outcome) | Event duration + 30 days | Art. 6(1)(f) GDPR |
| Copy of each photo report in our support mailbox (without the email address of the reporting person) | 6 months after receipt of the report; if the reported photo is held as evidence for an authority, until it is released | Art. 6(1)(c) GDPR with Art. 16 DSA |
| Co-admin invitation tokens | 7 days | Art. 6(1)(b) GDPR |
| Co-admin memberships | Until event deletion | Art. 6(1)(b) GDPR |
| Plan change audit records | 7 years | § 132 BAO |
| Email suppression list (bounces/complaints) — deliverability / protection against repeated sends to undeliverable addresses | Until manual removal, at the latest with account deletion | Art. 6(1)(f) GDPR |
| Commission data | 7 years | § 132 BAO (tax-relevant records) |
| Partner data (financial) | 7 years | § 132 BAO |
| Partner data (non-financial) | Until partner account closure | Art. 6(1)(b) GDPR |
| Error monitoring data (Sentry) | 90 days | Art. 6(1)(f) GDPR |
| Support chat metadata (status, timestamps, session ID, language, user ID for signed-in users; for escalated inquiries additionally the email address for our reply — your account address if you are signed in, otherwise the one you chose to give —, the page on which you opened the chat, the event code if you were on an event page, and your browser and device details (user agent); message contents are not stored permanently) | 90 days; escalated inquiries 12 months | Art. 6(1)(b) GDPR |
| AI analysis results for photos (caption, tags, quality score, moderation classification — stored with the photo record) | Same as the photo itself — deleted together with the photo/event (30 days after expiry) | Art. 6(1)(f) GDPR |
| AI usage log (per AI call: time, use case, provider, model, token count, estimated cost, duration, outcome or error type) — no user, event or guest identifier, no IP address, no content of the request or the response | 13 months | Art. 6(1)(f) GDPR — cost control and operation of the AI features |
| Checkout telemetry (pseudonymised: no email, no name, no IP — identifiers only as HMAC-SHA256, plus plan, amount, coupon and campaign parameters, outcome of the order attempt incl. error code) | 13 months | Art. 6(1)(f) GDPR |
| Advertising conversion queue (pseudonymised: SHA-256 hashed email address, advertising click identifier, order value and currency — transmitted to Google and Meta only with marketing consent) | 13 months | Art. 6(1)(a) and Art. 6(1)(f) GDPR |
| Partner referral click counter (daily total per partner link — nothing about the person clicking: no IP address, no browser fingerprint, no visitor identifier) | For as long as the partner account exists — the counter rows are deleted automatically together with it | Art. 6(1)(b) GDPR |
| On-device save manifest (IndexedDB eventdrop-saved, stored on your device; see § 4) | Until you clear this website's data in your browser; in Safari after 7 days without a visit, unless added to your home screen | § 165 (3) TKG 2021 |
| Acquisition channel of the account (short text value naming the campaign channel you first came through, recorded once at registration — plus the campaign labels utm_source/utm_medium/utm_campaign and the TYPE of advertising click identifier, the latter only if you gave marketing consent; never the click identifier itself) | For as long as the account exists — deleted together with it (see “Account data”) | Art. 6(1)(f) GDPR — utm labels and click-ID type: Art. 6(1)(a) (consent) |
| Acquisition channel of an event (same values, recorded once when that event is created — independent of the account value) | For as long as the event exists — deleted together with it | Art. 6(1)(f) GDPR — utm labels and click-ID type: Art. 6(1)(a) (consent) |
| Answer to “How did you hear about us?” after a purchase (a choice from a fixed list, optionally a short free text) — voluntary; linked to the purchase and to your account | 13 months; earlier together with your account if you delete it first | Art. 6(1)(f) GDPR — legitimate interest: understanding how buyers find EventDrop |
| Security audit log (administrative and system actions — acting account, its email address, IP address, action, target) | 12 months | Art. 6(1)(f) GDPR — detection and investigation of misuse of administrative functions |
| Data-processing agreement record (company data, authorised representative, DPO contact where given) | Until the account is deleted. After that, a minimised record (company name, country, version and language of the agreement, time of conclusion and of deletion, a hash of the account identifier — no representative, no DPO contact, no address) for 3 years from the end of the calendar year in which the account was deleted | Art. 6(1)(b) and (c) GDPR, Art. 28(3) GDPR; the minimised record after account deletion: Art. 6(1)(f) in conjunction with Art. 17(3)(e) GDPR (evidence for legal claims) |
| Redeemed partner promotions (discount via a partner’s link: which promotion, your account and the time — recorded when checkout starts, so that each promotion applies only once per account) | Until your account is deleted — removed together with it | Art. 6(1)(b) GDPR |
| Partner packs and their redemption codes (for buyers: purchase, codes, validity and status of each code; for everyone who redeems a code: the time of redemption, your account and the event the code was redeemed on — the buyer of the pack only sees whether and when a code was redeemed, not by whom) | 7 years from the end of the calendar year of the latest of these events: purchase, refund or chargeback of the pack, redemption or revocation of one of its codes (proof of purchase). After that, a daily automatic deletion run removes the pack together with its codes — never while one of its codes can still be redeemed. When you delete your account, its link to packs and redemptions is removed — issued codes remain valid for whoever holds them | Art. 6(1)(b) and (c) GDPR, § 132 BAO |
| Copying into a FotoDrop family album (section 5f): for each photo, whether the notice about the copying was shown at upload and whether the uploader objected; for each copying, its record (triggering account, time, photos copied) | Notice and objection: as long as the photo. Record of a copying: until the event is deleted. The copies in FotoDrop follow FotoDrop’s retention periods; the expiry or deletion of the event does not delete them | Art. 6(1)(b) and (f) GDPR |
This section is addressed to business owners and their staff whose professional contact details we did not obtain from them directly, but from publicly accessible sources — for example in order to assess whether a collaboration within the EventDrop partner programme is a fit. It describes a separate processing activity and applies regardless of whether you hold an EventDrop account. It is provided in fulfilment of our information obligation under Art. 14 GDPR.
Bernhard Götzendorfer
Sole proprietorship
Rittingergasse 15/11
1210 Vienna, Austria
Email: office@gotzendorfer.at
No data protection officer has been appointed; the conditions of Art. 37 GDPR are not met (see section 9). Data protection enquiries relating to this processing are handled at the address above.
We did not obtain this data from you. It originates from the following publicly accessible sources:
On request we will tell you the specific source and, where available, the specific source URL from which your data originates.
The legal basis is Art. 6(1)(f) GDPR — our legitimate interest. The legitimate interests pursued are: initiating a business relationship with professionally suitable service providers, keeping the underlying business data correct and up to date, avoiding unnecessary and misdirected contact, and being able to reliably honour objections. Recital 47 GDPR expressly recognises processing for direct marketing purposes as a possible legitimate interest.
Whether contact may actually be made through a particular channel (email, telephone, messaging) is additionally governed by telecommunications and unfair-competition law and is assessed separately for each channel and each country.
The core processing takes place on servers located within the EU/EEA; for the AI-based classification, data is transmitted to Google LLC in the USA (see the third-country note below). The following categories of recipients are involved:
We do not publish your personal contact details and we do not sell, rent or otherwise pass this data on to third parties for their own purposes.
With the exception of the AI-based classification, all recipients named above process this data on servers within the EU/EEA. For the AI-based classification and structuring described above, the data is transmitted to Google LLC in the United States. This transfer is based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); Google LLC is certified under the DPF. Should the transfer mechanism relied upon change, we will update this information beforehand and state the mechanism then relied upon (adequacy decision or appropriate safeguards pursuant to Art. 46 GDPR).
For the sake of completeness: until 3 May 2026 we used a US-based service provider (Apollo.io) to enrich company data. That use has been discontinued and will not be resumed. If you would like to know whether your record was affected, please contact us at the address given above.
We store this data only for as long as it is required for the purposes set out above, i.e. for the assessment of a possible partnership, for source verification, for data quality and for the establishment, exercise or defence of legal claims. Records that are not relevant, that turn out to be incorrect, or that have been objected to are deleted, corrected or reduced to a suppression entry.
If you object, we retain a suppression entry for an unlimited period. This entry contains only a keyed cryptographic hash of the identifier concerned (e.g. of your email address), not the identifier itself. This is exactly what enables us to honour your objection permanently and to prevent the same contact details from being collected again from a public source at a later date.
You have the rights set out in section 7 in respect of this processing as well: access (Art. 15 GDPR, including information about the source of the data), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), insofar as applicable. To exercise them, please write to office@gotzendorfer.at. We will respond within one month.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data which is based on Art. 6(1)(f) GDPR.
Where personal data is processed for direct marketing purposes, you have the right to object at any time without giving any reason. If you object to processing for direct marketing purposes, your personal data will no longer be processed for such purposes.
A short message to office@gotzendorfer.at is sufficient — a reply to a message you received from us is equally sufficient. No particular form is required, no reason has to be given, and it is free of charge. We record the objection on the same working day and will not contact you again.
You also have the right to lodge a complaint with a supervisory authority in respect of this processing. The competent authority in Austria is the Austrian Data Protection Authority — contact details in section 10.
This section provides disclosures for users in the United States under the California Online Privacy Protection Act (CalOPPA) and describes rights available under other U.S. state comprehensive privacy laws. It supplements, and does not replace, the GDPR-based disclosures above, which already apply to all users of EventDrop.at regardless of location.
We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration, and we have not done so in the preceding 12 months. The service providers listed in Section 5 above process data on our behalf, under contract, to operate EventDrop.at — they do not receive your data as an independent sale.
One transfer deserves to be named here, because some U.S. state privacy laws treat it as “sharing” for targeted advertising rather than as a sale. If — and only if — you have switched on marketing consent, the order confirmation page transmits your order value, the currency, the Stripe checkout session ID, your email address as a SHA-256 hash and the advertising click identifier to Google LLC, so that we can measure which of our Google Ads ads led to the order, and we permit Google to use that data for advertising personalisation (Section 5d describes this in full). Marketing consent is off by default: unless you turn it on in the cookie settings, nothing is transmitted and no Google tag is even loaded. Turning it back off is the opt-out, it is reachable from every page, and it takes effect immediately.
EventDrop.at runs no advertising or analytics tag that follows you across other operators’ websites. The single third-party advertising tag we use — the Google Ads conversion measurement described in Section 5d — loads on the order confirmation page only, only after you have given marketing consent, and it reports a completed order rather than your browsing. Because we operate no cross-site profile that a browser signal could switch off, our systems do not currently respond differently to a detected “Do Not Track” (DNT) signal — the cookie settings, not DNT, are the control that actually takes effect here. The cookies we do set are described in Section 4 above; the non-essential ones are the first-party attribution cookies ed_ref, ed_src and ed_click, all set exclusively with your prior marketing consent, plus Google’s own _gcl_aw cookie, which the tag writes on the order confirmation page.
Depending on your state of residence, you may have rights under a state comprehensive privacy law (for example the California Consumer Privacy Act as amended by the CPRA, or comparable laws in other states) to know what personal information we hold about you, to request its deletion, to correct inaccurate personal information, and to receive a portable copy of it. We do not differentiate these rights by state: every user of EventDrop.at, regardless of location, already has self-service access to the same underlying tools that the GDPR rights in Section 7 above describe — data export (portability and access) via Settings > Data Export, and account deletion (erasure) via Settings > Account Deletion. We do not sell personal information; the one transfer a state law may classify as “sharing” for targeted advertising is the Google Ads conversion measurement described above, and it occurs only while marketing consent is switched on. Withdrawing that consent in the cookie settings is the opt-out from targeted advertising, and it is effective immediately. For a correction request, or if self-service access does not cover what you need, contact office@gotzendorfer.at. We will not discriminate against you for exercising any of these rights.
You have the following rights under the GDPR:
To exercise your rights, please contact: office@gotzendorfer.at
You have the right to object at any time, on grounds relating to your particular situation, to the automatic AI analysis of your photos (section 5a), which is based on Art. 6(1)(f) GDPR (legitimate interest).
An informal email to office@gotzendorfer.at is sufficient — please name the photo or event concerned. The photo will then be excluded from automatic analysis, and analysis results already stored will be removed.
In addition to your right to data portability under Art. 20 GDPR, Regulation (EU) 2023/2854 (EU Data Act, applicable since September 2025) grants you the right to access and transfer data generated through your use of our digital service. You can export all your data at any time via Settings > Data Export in your account. The export includes your profile, events, uploads, comments, reactions, analytics, plan changes, event members, payment history, photo reports, event extensions, recap videos, commissions, commission payouts, partners, partner referrals, partner payouts, and partner payout adjustments in machine-readable JSON format.
The appointment of a data protection officer is not required, as the conditions under Art. 37 GDPR (in conjunction with § 5 DSG) are not met. EventDrop is operated as a small business. There is no core activity consisting of regular and systematic large-scale monitoring of data subjects, nor large-scale processing of special categories of data. For data protection inquiries, please contact office@gotzendorfer.at.
You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde / Austrian Data Protection Authority
Barichgasse 40-42
1030 Wien
www.dsb.gv.at
Last updated: October 2026