Legal

GDPR Compliance

Last updated: May 28, 2026

EventOS Online is committed to complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page describes our approach to data protection and your rights as a data subject.

Legal Basis for Processing

Contract

Processing necessary to deliver the service you signed up for — account management, ticket processing, event delivery.

Legitimate Interest

Fraud prevention, security monitoring, and improving the Platform.

Consent

Marketing communications and non-essential analytics. You can withdraw consent at any time.

Legal Obligation

Retaining financial records as required by applicable law.

Your Rights Under GDPR

Right of Access

Request a full copy of all personal data we hold about you. We will respond within 30 days.

Right to Rectification

Request correction of inaccurate or incomplete personal data at any time via Settings or by contacting us.

Right to Erasure

Request deletion of your personal data ("right to be forgotten"). We will erase data not required by law within 30 days.

Right to Restrict Processing

Ask us to pause processing your data while a rectification or objection request is being resolved.

Right to Data Portability

Receive your personal data in a structured, machine-readable format (JSON / CSV) and transfer it to another service.

Right to Object

Object to processing based on legitimate interests, including direct marketing. We will stop immediately upon request.

Right to Withdraw Consent

Withdraw consent at any time for processing activities that rely on consent (e.g. marketing emails).

Technical & Organisational Measures

TLS 1.3 encryption for all data in transit

AES-256 encryption for sensitive data at rest

bcrypt password hashing (cost factor 12)

JWT access tokens with 15-minute expiry

Refresh token rotation on every use

Role-based access control (RBAC) on all API routes

Regular third-party security audits

Data processing agreements with all sub-processors

Breach notification within 72 hours as required by GDPR Art. 33

Data Protection Contact

To exercise any of your GDPR rights, or to raise a data protection concern, contact our Data Protection Officer:

privacy@eventosonline.xyz

We will respond within 30 calendar days as required by GDPR Art. 12.