Security
Security and data protection
Where your crew data lives, who can access it and what happens when you cancel. For data protection officers, IT and management, without marketing.
EU hostingServers in Germany
- GDPRprocessing under Art. 28
- DPAwith sub-processor list
- TLS encryptionevery connection
- Daily backupsencrypted, 30 days
Where the data lives
- Servers in Germany
- Application, database and cache run on servers in Germany, operated by us.
- Files, mail and AI in the EU
- Uploaded documents, transactional mail and AI features run through data centres in the EU. No transfer of crew data to third countries.
- Isolation at database level
- Every customer gets its own isolated data space. Access to another customer's data is not forbidden, it is technically impossible.
- Backups
- Daily encrypted database backups with 30 days of retention.
Who has access
- Login
- Sign-in by e-mail code or password, single sign-on with Google, Apple and Microsoft Entra ID. Passwords are stored only as hashes, sessions expire.
- Permissions
- admin users get permissions per area: planning, people, time, payroll, accreditation, guest list. Tax and bank details are visible only with the payroll permission.
- Crew self-service
- Tax ID, bank details and ID data are entered by the employees themselves in the app. Changes are logged with time and author.
- Encrypted connections
- Every connection between app, browser and servers is TLS-encrypted.
What happens at the end
- Deleting individual people
- A person can be deleted completely: account, applications, hours, documents, accreditations, across all tables of the tenant.
- Export and deletion of the tenant
- On cancellation you export your data as CSV and files, then your data is deleted completely.
- Data processing agreement
- Data processing agreement under Art. 28 GDPR on request, with the list of sub-processors.
Common questions
EVENTRA processes employee data on behalf of the organiser. Hosting and core services run in Germany and the EU, a data processing agreement with a sub-processor list is available, and data subject rights such as access and deletion are implemented technically. Responsibility for the legal basis of processing stays with the organiser.
No. Every customer's data is kept fully separate. A person working for two organisers has two separate profiles.
No external certification at present. We answer your IT's security questionnaires and walk through the architecture in a call.
Write to info@eventra.app with the subject Data protection. You will receive the DPA, the sub-processor list and answers to your questionnaire.
Book a demo
See your event in EVENTRA
30 minutes with the founder. We rebuild your event live, from the application form to the export file for your payroll office.
Your own test environment in minutes. No credit card, ends automatically.
See pricing