Bernhard Götzendorfer
Rittingergasse 15/11
1210 Vienna, Austria
Email: office@gotzendorfer.at
We process personal data only to the extent necessary for providing our services. Processing is carried out on the basis of the GDPR (General Data Protection Regulation) and the Austrian DSG (Data Protection Act).
When you visit our website, the following technical data is automatically collected: IP address, browser type, operating system, referrer URL, time of access. This data is necessary for the technical operation of the website (legal basis: Art. 6(1)(f) GDPR — legitimate interest).
When creating an account we collect: email address, and optionally your name (when signing in via Google or Apple). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
When photos are uploaded, we process: image files, upload timestamp, event association, and optionally the uploader's name (max. 100 characters). GPS location data from EXIF metadata is automatically stripped on upload (privacy protection measure). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
Payment data is processed directly by our payment service provider Stripe. We do not receive complete credit card numbers. We store: payment status, invoice data, selected plan, Stripe payment ID. Available payment methods are currently credit card, EPS, and Klarna, plus Apple Pay on supported devices and, depending on country and device, further payment methods provided by Stripe such as Link, Amazon Pay, or Bancontact (via Stripe Automatic Payment Methods). Legal basis: Art. 6(1)(b) GDPR — performance of a contract.
When a photo is reported by a user, we collect: reason for the report, optional description, reporter's IP address, timestamp, and the associated photo/event reference. The event owner is notified by email.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting users from inappropriate content and maintaining platform integrity. Report data is retained for the duration of the event plus 30 days.
When a co-admin is invited to manage an event, we collect: invited person's email address, invitation token (UUID), invitation status (pending/accepted), date of invitation, and the inviting user's reference.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (enabling collaborative event management as part of the service). Invitation tokens expire automatically after 7 days. Co-admin memberships are retained until the event is deleted.
When a plan upgrade is performed, we create an audit record in theplan_changestable containing: event reference, previous plan, new plan, price paid, Stripe payment ID, and timestamp.
Legal basis: Art. 6(1)(c) GDPR — legal obligation. This data is part of our accounting records and must be retained for 7 years in accordance with the Austrian Federal Fiscal Code (§ 132 BAO).
If you participate in the commission program as an event helper, we process the following data:
Legal basis:Art. 6(1)(b) GDPR — performance of the commission program contract.
Retention:7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code) for tax-relevant records.
If you apply for the EventDrop Partner Program, we process the following data:
Legal basis:Art. 6(1)(b) GDPR — performance of the partner program contract.
Retention:Financial records (commission amounts, payouts, IBAN/BIC) are retained for 7 years pursuant to § 132 BAO (Austrian Federal Fiscal Code). Non-financial data (name, website, motivation) is deleted upon partner account closure or program termination.
We use Sentry (Functional Software, Inc., San Francisco, USA) for error monitoring to ensure the stability and security of our application. When an error occurs, the following technical data is automatically transmitted:
Data minimization: Error reports may contain technical diagnostic data (e.g. browser type, error context, technical identifiers). We configure collection in line with data minimization (sendDefaultPii: false): no photo contents are transmitted, no cookies are read, and no session replays are recorded during normal usage. IP addresses are not stored permanently.
Legal basis:Art. 6(1)(f) GDPR — legitimate interest in maintaining application security and stability. Error monitoring is essential for detecting and resolving technical issues that affect all users.
Retention:Error data is automatically deleted after 90 days by Sentry.
Data transfer: Data may be processed in the USA. Sentry participates in the EU-U.S. Data Privacy Framework.
We use cookies to ensure the basic functions of the website and to improve your user experience. The legal basis for the use of technically necessary cookies is § 165 TKG 2021 (Austrian Telecommunications Act). For non-essential cookies (functional, analytics, marketing), we obtain your prior consent in accordance with § 165(3) TKG 2021 and Art. 6(1)(a) GDPR.
Cookie categories:
sc_guest, links an anonymous support inquiry to your own session and lets the host see how many guests contributed photos — it holds a random identifier, never your name), and a local storage flag recording that you dismissed the “Install app” prompt (pure UI state, not used for tracking). Legal basis: § 165(3) TKG 2021 — strictly necessary cookies are exempt from the consent requirement.ed_ref) stores for 30 days which partner referred you to EventDrop (first-click attribution). Set only with your consent. Legal basis: Art. 6(1)(a) GDPR.ed_src) stores for 30 days which campaign channel (e.g. QR flyer, print ad) brought you to EventDrop (first-click attribution). Set only with your marketing consent. Legal basis: Art. 6(1)(a) GDPR.We work with the following service providers. All listed US-based providers rely on a valid transfer mechanism under Chapter V GDPR: either the adequacy decision for the EU-US Data Privacy Framework (DPF, Art. 45 GDPR) or EU Standard Contractual Clauses (SCCs, Art. 46 GDPR). The mechanism relied upon is stated for each provider below. Should the transfer basis relied upon for a provider change, we will update this information beforehand and state the mechanism then relied upon (adequacy decision or appropriate safeguards pursuant to Art. 46 GDPR).
Data Processing Agreements (GDPR Art. 28): We have concluded data processing agreements (DPAs) in accordance with Art. 28 GDPR with all listed processors. These agreements govern the lawful processing of personal data on our behalf and ensure the required technical and organizational measures. Copies are available on request at office@gotzendorfer.at.
Changes to the list of processors: This list may change. We will inform you of any material change in advance and give you the opportunity to object in accordance with Art. 28(4) GDPR. Version of this list: August 21, 2026.
Uploaded photos are automatically analyzed by artificial intelligence (Google Gemini, called directly via the Google Gemini API). Purpose of processing:
Together with each photo, the event title, the event description, and the event type are transmitted as context to improve the quality of the analysis.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving user experience and protecting against inappropriate content.
Photos are transmitted to the AI provider for analysis and processed solely to provide this feature. Storage by the provider occurs only within the scope of its API policies (e.g., for abuse monitoring). There is no profiling. Your photos are not used to train AI models.
No automated individual decision-making (Art. 22 GDPR):The AI processing does not produce decisions with legal or similarly significant effects on users. There is no profiling as defined by Art. 4(4) GDPR. All AI results (tags, highlights, captions, moderation flags) serve solely as suggestions and can be overridden by the event owner.
EventDrop offers an AI-powered support chat to help users with questions about the platform. Requests are processed by the AI language model Google Gemini (Google LLC, see section 5).
Data processed during chat interactions:
Escalation:If the AI assistant cannot resolve your inquiry, the verbatim transcript of your conversation (your messages and the assistant’s replies) together with a short summary and — if you are logged in — your email address is forwarded by email (sent via Resend, see section 5) to our support team (office@gotzendorfer.at) for manual handling. It is used solely to answer that inquiry.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (providing customer support as part of the service). Message contents are not permanently stored and are not used to train AI models. Chat metadata (status, timestamps, session ID, language and — for signed-in users — your user ID) is automatically deleted after 90 days — for escalated inquiries after 12 months.
When creating an event, the entered event title may be transmitted to the AI language model Google Gemini (Google LLC, see section 5) to generate:
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (assisting event creation as part of the service). The event title is processed to provide this feature; storage by the provider occurs only within the scope of its API policies (e.g., for abuse monitoring), and it is not used to train AI models. Suggestions are optional and can be modified or ignored by the user.
Personal data is deleted as soon as the purpose of processing no longer applies, unless legal retention obligations require longer storage.
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Payment & invoice data | 7 years | § 132 BAO |
| Account data | Until deletion + 30 days | Art. 6(1)(b) GDPR |
| Event photos | Until manual deletion, at the latest 30 days after event expiry (automatic deletion) | Art. 6(1)(b) GDPR |
| Server logs | 30 days | Art. 6(1)(f) GDPR |
| Analytics data | 365 days | Art. 6(1)(a) GDPR |
| Consent records | 3 years | Art. 7(1) GDPR |
| Photo reports | Event duration + 30 days | Art. 6(1)(f) GDPR |
| Co-admin invitation tokens | 7 days | Art. 6(1)(b) GDPR |
| Co-admin memberships | Until event deletion | Art. 6(1)(b) GDPR |
| Plan change audit records | 7 years | § 132 BAO |
| Commission data | 7 years | § 132 BAO (tax-relevant records) |
| Partner data (financial) | 7 years | § 132 BAO |
| Partner data (non-financial) | Until partner account closure | Art. 6(1)(b) GDPR |
| Error monitoring data (Sentry) | 90 days | Art. 6(1)(f) GDPR |
| Support chat metadata (status, timestamps, session ID, language, user ID for signed-in users —message contents are not stored permanently) | 90 days; escalated inquiries 12 months | Art. 6(1)(b) GDPR |
| AI analysis results for photos (caption, tags, quality score, moderation classification — stored with the photo record) | Same as the photo itself — deleted together with the photo/event (30 days after expiry) | Art. 6(1)(f) GDPR |
This section is addressed to business owners and their staff whose professional contact details we did not obtain from them directly, but from publicly accessible sources — for example in order to assess whether a collaboration within the EventDrop partner programme is a fit. It describes a separate processing activity and applies regardless of whether you hold an EventDrop account. It is provided in fulfilment of our information obligation under Art. 14 GDPR.
Bernhard Götzendorfer
Sole proprietorship
Rittingergasse 15/11
1210 Vienna, Austria
Email: office@gotzendorfer.at
No data protection officer has been appointed; the conditions of Art. 37 GDPR are not met (see section 9). Data protection enquiries relating to this processing are handled at the address above.
We did not obtain this data from you. It originates from the following publicly accessible sources:
On request we will tell you the specific source and, where available, the specific source URL from which your data originates.
The legal basis is Art. 6(1)(f) GDPR — our legitimate interest. The legitimate interests pursued are: initiating a business relationship with professionally suitable service providers, keeping the underlying business data correct and up to date, avoiding unnecessary and misdirected contact, and being able to reliably honour objections. Recital 47 GDPR expressly recognises processing for direct marketing purposes as a possible legitimate interest.
Whether contact may actually be made through a particular channel (email, telephone, messaging) is additionally governed by telecommunications and unfair-competition law and is assessed separately for each channel and each country.
The core processing takes place on servers located within the EU/EEA; for the AI-based classification, data is transmitted to Google LLC in the USA (see the third-country note below). The following categories of recipients are involved:
We do not publish your personal contact details and we do not sell, rent or otherwise pass this data on to third parties for their own purposes.
With the exception of the AI-based classification, all recipients named above process this data on servers within the EU/EEA. For the AI-based classification and structuring described above, the data is transmitted to Google LLC in the United States. This transfer is based on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); Google LLC is certified under the DPF. Should the transfer mechanism relied upon change, we will update this information beforehand and state the mechanism then relied upon (adequacy decision or appropriate safeguards pursuant to Art. 46 GDPR).
For the sake of completeness: until 3 May 2026 we used a US-based service provider (Apollo.io) to enrich company data. That use has been discontinued and will not be resumed. If you would like to know whether your record was affected, please contact us at the address given above.
We store this data only for as long as it is required for the purposes set out above, i.e. for the assessment of a possible partnership, for source verification, for data quality and for the establishment, exercise or defence of legal claims. Records that are not relevant, that turn out to be incorrect, or that have been objected to are deleted, corrected or reduced to a suppression entry.
If you object, we retain a suppression entry for an unlimited period. This entry contains only a keyed cryptographic hash of the identifier concerned (e.g. of your email address), not the identifier itself. This is exactly what enables us to honour your objection permanently and to prevent the same contact details from being collected again from a public source at a later date.
You have the rights set out in section 7 in respect of this processing as well: access (Art. 15 GDPR, including information about the source of the data), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), insofar as applicable. To exercise them, please write to office@gotzendorfer.at. We will respond within one month.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data which is based on Art. 6(1)(f) GDPR.
Where personal data is processed for direct marketing purposes, you have the right to object at any time without giving any reason. If you object to processing for direct marketing purposes, your personal data will no longer be processed for such purposes.
A short message to office@gotzendorfer.at is sufficient — a reply to a message you received from us is equally sufficient. No particular form is required, no reason has to be given, and it is free of charge. We record the objection on the same working day and will not contact you again.
You also have the right to lodge a complaint with a supervisory authority in respect of this processing. The competent authority in Austria is the Austrian Data Protection Authority — contact details in section 10.
You have the following rights under the GDPR:
To exercise your rights, please contact: office@gotzendorfer.at
You have the right to object at any time, on grounds relating to your particular situation, to the automatic AI analysis of your photos (section 5a), which is based on Art. 6(1)(f) GDPR (legitimate interest).
An informal email to office@gotzendorfer.at is sufficient — please name the photo or event concerned. The photo will then be excluded from automatic analysis, and analysis results already stored will be removed.
In addition to your right to data portability under Art. 20 GDPR, Regulation (EU) 2023/2854 (EU Data Act, applicable since September 2025) grants you the right to access and transfer data generated through your use of our digital service. You can export all your data at any time via Settings > Data Export in your account. The export includes your profile, events, uploads, comments, reactions, analytics, plan changes, event members, payment history, photo reports, event extensions, recap videos, commissions, commission payouts, partners, partner referrals, partner payouts, and partner payout adjustments in machine-readable JSON format.
The appointment of a data protection officer is not required, as the conditions under Art. 37 GDPR (in conjunction with § 5 DSG) are not met. EventDrop is operated as a small business. There is no core activity consisting of regular and systematic large-scale monitoring of data subjects, nor large-scale processing of special categories of data. For data protection inquiries, please contact office@gotzendorfer.at.
You have the right to lodge a complaint with the Austrian Data Protection Authority:
Österreichische Datenschutzbehörde / Austrian Data Protection Authority
Barichgasse 40-42
1030 Wien
www.dsb.gv.at
Last updated: August 2026