1. Data Collected
Tov.events collects the following data:
- Account data: name, email, password (encrypted), language preferences, timezone.
- Event data: title, date, location, description, uploaded photos.
- Guest data: name, phone number, RSVP responses, preferred language.
- Technical data: IP address, browser, login timestamps.
- Google Data: If you use the contact import feature, we temporarily access your Google Contacts. No data is stored permanently without your explicit import action.
2. Purpose of Processing
Data is used to:
- Provide the online invitation service.
- Enable RSVP management and confirmation tracking.
- Send service-related notifications (confirmations, reminders).
- Improve the service and ensure account security.
3. Legal Basis
Data processing is based on the user's consent (account creation) and on the execution of the service contract.
4. Data Retention
- Account data: retained as long as the account is active, deleted within 30 days of a deletion request.
- Event data: retained for 12 months after the event date.
- Technical data: retained for a maximum of 12 months.
5. Data Sharing
Tov.events does not sell or share your personal data with third parties for commercial purposes. Data may be shared with:
- Our technical subcontractors (hosting, email delivery) strictly within the scope of the service.
- Competent authorities in case of legal obligation.
6. Cookies
Tov.events uses essential cookies for the service to function (session, language preference). No advertising or third-party tracking cookies are used.
7. Your Rights (GDPR)
In accordance with the GDPR, you have the following rights:
- Right of access: obtain a copy of your personal data.
- Right of rectification: correct your inaccurate data.
- Right of erasure: request the deletion of your data.
- Right of portability: receive your data in a structured format.
- Right to object: object to the processing of your data.
To exercise these rights, contact us at [email protected].
8. Security
We implement appropriate technical and organizational measures to protect your data: password encryption (bcrypt), secure sessions, CSRF protection, restricted data access.
Last updated: 26/05/2026