legal · privacy · gdpr
Privacy
last updated · 2026-09-28
This policy explains how personal data is processed when you visit event-flow.ai, use the eventflow application, or open a link that an eventflow customer or we have sent you. It is provided under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
1 · controller and contact
Till Antonio Mahler, trading as Digital Music Services
Am Berlin Museum 12
10969 Berlin, Germany
Email: hello@event-flow.ai
We have not appointed a data protection officer. For any privacy question or request, write to hello@event-flow.ai.
2 · two roles: controller and processor
We are the controller for this website, for the accounts, billing and support of our customers, and for our own outreach to venues and promoters (section 7).
Inside a customer's workspace, the venue, promoter or festival that uses eventflow (our "Customer") is the controller. This covers the data of its team, artists, agents, curators, guests and business contacts, its events and its invoices. We process that data only on the Customer's behalf and instructions, under our Data Processing Agreement. If you are an artist, guest or contact of a venue, please direct requests about that data to the venue; we support it in answering them.
3 · this website
Hosting and server logs. The website is hosted by Vercel. When you visit it, standard request data is processed: IP address, browser user agent, requested URL, referrer, status and time. This is needed to deliver the pages and keep them secure. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a secure and working website.
Analytics, only with consent. On your first visit a notice asks whether we may count your visit with Vercel Web Analytics. If you decline, analytics is not loaded. The analytics is cookieless and gives us aggregate page views and visitor counts (page, referrer, browser, country). Your choice is stored in your browser's local storage under the key eventflow:consent so we do not ask again; you can reset it by clearing this site's data in your browser. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG, consent, which you can withdraw at any time with effect for the future.
Fonts. The fonts on this website are served from our own host. Your browser does not contact Google or another font provider when you visit it.
Access requests. When you request access, we collect the name and type of your venue, promoter or collective, your name and role, how many nights per week you run, the tools you use today, your reason for applying and your email address. For abuse prevention we record your IP address and browser user agent at submission, and we store your consent record. Your email address is confirmed by double opt-in. We use this data to evaluate your request and contact you about access. Legal basis: Art. 6(1)(b) GDPR, steps prior to a contract, and Art. 6(1)(a) GDPR for contacting you. These records are not yet deleted automatically. We delete them when you ask us to, and our target is to delete them at the latest 24 months after your request is closed.
4 · the eventflow application
Accounts. For each user we process name, email address, role and workspace membership, authentication data and login metadata (time, IP address, browser). Legal basis: Art. 6(1)(b) GDPR, performance of the contract with the Customer, and Art. 6(1)(f) GDPR, our legitimate interest in providing accounts to the people a Customer invites and in securing them.
When a person creates an account through self-service sign-up, we process the email address, account identity, authentication data, login metadata and workspace membership needed to create and secure the account and workspace, and the legal-acceptance record for the Terms and Data Processing Agreement version accepted at workspace creation or checkout. To prevent automated signups we use Cloudflare Turnstile, short-lived signup permissions, and rate-limit records derived from your email and IP address. Email and IP values in these signup records are stored as salted hashes.
Billing. Subscriptions and purchases are processed by Stripe. Stripe collects the billing contact, billing address, VAT ID and payment method; we receive the subscription status, plan and invoice records, not full card details. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for retaining invoices under tax and commercial law.
Support and feedback. When you contact us or send feedback from within the application, we process your message, contact details and any screenshot or attachment you include, to answer and to improve the Service. We are the controller for this (section 2), also when you write from inside a Customer's workspace. Messages in the support chat are first answered automatically by an AI model from Anthropic, which processes them as our processor; the reply draws on our published help articles, is shown to you without a person reviewing it first, and the conversation can be handed to a person at any time. We keep short guidance learned from support conversations at platform level; it is visible only to us and is used to improve the automatic support replies for all users. Legal basis: Art. 6(1)(b) and (f) GDPR.
Product analytics. We use PostHog (EU cloud, Frankfurt, host eu.i.posthog.com) to count page views in aggregate. It runs in the signed-in application and on the public pages /sign-in, /sign-up, /forgot-password, /intake/<workspace>, /submit and /help. It is cookieless: nothing is stored on your device, and each page load gets a fresh anonymous identifier that is held only in memory. Automatic click capture, session recording and person profiles are switched off, and page addresses are stripped of identifiers before sending. The IP address of your request reaches PostHog as part of the connection. PostHog is not loaded on personal link pages (section 5) or on our outreach pages (section 7). Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding which parts of the Service are used.
Error monitoring. We use Sentry (EU data region, Germany) to detect and fix errors. Error reports contain technical data such as the sanitised page address, browser, device and the error itself. Collection of default personal data such as IP addresses, cookies and request bodies is switched off. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a working and secure Service.
Workspace data. Events, lineups, artist and contact records, guest lists, invoices and uploaded files, briefings and messages are processed on behalf of the Customer (section 2). Messages a Customer sends from eventflow are delivered by Twilio SendGrid, which reports delivery, bounce and open events back to the Customer's workspace.
5 · public links
Some pages open through a personal link and need no login. What is stored depends on the page:
- Guest list links: the names you add, optional email addresses, the number of additional guests, and the time of each change.
- Door check-in: check-in status and time per guest, entered by door staff.
- Artist briefing and invoice links: the information the venue shares with you, questions you ask, invoices you upload and the result of the invoice check.
- Showcase, intake and feedback forms: the information you enter.
For these pages the venue is the controller (section 2). To protect public forms against abuse, we record the IP address and time of submissions for rate limiting. These rate-limit records, including the IP address, are kept for 7 days. Some forms use Cloudflare Turnstile, which evaluates browser and request signals to tell people from bots. Legal basis for this protection: Art. 6(1)(f) GDPR. Product analytics is not loaded on personal link pages. It does run on the public intake form of a workspace and on the submission and help pages, as described in section 4.
6 · ai processing
Some functions send data to AI models: invoice checks read the uploaded invoice, including the payee's name, address, tax number and bank details, and compare it with the agreed booking; the invoice instructions a workspace writes are turned into the list of requirements the check applies; a scheduled second check re-reads stored invoice checks, and we, as the operator of eventflow, review its results to improve our prompts; briefing and message functions translate or draft text from the event data and templates; lineup import parses text the Customer pastes; and our support chat answers first with an AI model (section 4). When a workspace corrects an invoice check, the Service turns the correction into short guidance for future invoice checks. That guidance is stored in the Customer's own workspace and used only there; it is not used for other customers. The only guidance kept across customers is the support guidance described in section 4, which is visible only to us.
The models are provided by Cloudflare (Workers AI), OpenAI and Anthropic, as listed on the sub-processor page. We reach OpenAI through Cloudflare's AI Gateway, and Anthropic through our gateway or direct API calls. Requests through our AI gateway are sent with payload logging switched off and a zero data retention request. We do not use Customer Data to train AI models.
The Customer's team reviews invoice checks before it sets a status or pays, and reviews imported lineups; we review our outreach letter drafts before they are sent (section 7). Three outputs are shown without a person reviewing them first: the first reply in our support chat (section 4); the automatic pre-check an artist sees after uploading an invoice, which the Customer's team then reviews before deciding the invoice's status; and the translations of a workspace's briefing headlines, which are made when the headline is saved and shown to artists as they are. The Customer can change or remove a headline at any time, and it is translated again on save. More in the AI policy.
7 · our outreach to venues and promoters
We contact selected clubs, promoters and collectives by email to introduce eventflow. For this we use business contact data from public sources, such as the venue's website and published programme: the name of the venue, the name and business email address of a contact person, and public event information. Each letter links to a personal page that shows how eventflow would look with that public programme. To prepare the page and the letter, the public programme is structured and a first draft of the letter is written by an AI model from OpenAI, reached through Cloudflare; we review the letter before it is sent. On the page we store the time it was first opened. To limit abuse, the IP address of the visitor is kept only inside a rate-limit record, which is deleted after 7 days. The page loads no analytics and sets no tracking cookies. Links expire after 30 days.
We send such emails only where the law allows it, for example where there is an existing business relationship or the recipient has consented. Every letter and page contains a link to decline further contact. A decline is honoured permanently: we stop contacting you and keep your email address on a suppression list solely so that we do not contact you again. Legal basis for processing the business contact data for one personal letter with a decline link: Art. 6(1)(f) GDPR, our legitimate interest in presenting our service to businesses. You can object at any time (Art. 21(2) GDPR) by using the decline link or writing to hello@event-flow.ai. Outreach data is not yet deleted automatically. We delete it when you ask us to, except the suppression entry.
8 · cookies and local storage
The website stores only your analytics choice in local storage (section 3). The application uses cookies that are strictly necessary to keep you signed in and to protect forms; they are set under § 25(2) TDDDG and are not used for tracking. Product analytics (section 4) stores nothing on your device.
9 · recipients and sub-processors
We use service providers for hosting, database, email, payment, AI, analytics, error monitoring and backup. They process data only on our instructions under data processing agreements, concluded directly or, for OpenAI, through Cloudflare as the listed intermediary. Stripe also acts as an independent controller for payment processing. The current list with purpose, data and location is on the sub-processor page. We do not sell personal data and do not share it for advertising.
Google Ireland Limited (Google Fonts). The design studio and the HTML emails eventflow sends load font files from Google Fonts. When they load, the browser or email client of the viewer transmits its IP address to Google. Legal basis: Art. 6(1)(f) GDPR, a consistent display of designs and emails.
10 · international transfers
Our database, file storage, product analytics, error monitoring and backups are hosted in the EU. Some providers are based in the USA or process data there. The safeguard differs by provider:
- EU-U.S. Data Privacy Framework (Art. 45 GDPR), under which the provider is certified: Vercel, Twilio SendGrid, Stripe, PostHog, Sentry and Backblaze.
- Cloudflare: listed in the EU-U.S. Data Privacy Framework; we also rely on the EU Standard Contractual Clauses (Art. 46 GDPR).
- EU Standard Contractual Clauses only (Art. 46 GDPR): Supabase, OpenAI and Anthropic.
The sub-processor page states the safeguard for each provider. You can request a copy of the safeguards at hello@event-flow.ai.
11 · retention
We keep personal data only as long as needed for the purpose it was collected for. The periods below are our targets; where no automatic job enforces a period yet, we say so.
- Account data: while the account exists.
- Workspace data: deleted 30 days after the Customer's contract ends, as described in the terms, unless the Customer instructs otherwise or the law requires retention. This deletion is carried out by us, not by an automatic job.
- Invoices and accounting records: the periods required by German tax and commercial law (§ 147 AO and § 257 HGB, up to ten years).
- Rate-limit records, including IP addresses: 7 days.
- Access requests: on request, with a target of at the latest 24 months after the request is closed (section 3).
- Outreach data: on request (section 7). Suppression entries are kept so that a decline stays honoured.
- Backup copies: overwritten or expire in their regular backup cycle.
You can ask us at any time to delete data we hold about you; section 12 explains your rights.
12 · your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21), including at any time to processing for direct marketing. Where processing is based on consent, you can withdraw it at any time with effect for the future. To exercise these rights, write to hello@event-flow.ai. We answer within one month.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (www.datenschutz-berlin.de).
13 · automated decision-making
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). AI checks and drafts are proposals: an invoice's status, a payout, a send and a booking are always decided by a person. The automated outputs named in section 6 inform; they do not decide.
14 · is providing data required?
You are not legally obliged to provide personal data. Without an email address we cannot create an account or process an access request, and without billing data we cannot conclude a paid subscription.
15 · changes
We update this policy when the Service or the law changes. The date at the top shows the current version. We inform Customers of material changes by email.