Last updated: May 28, 2026
EventOS Online is committed to complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page describes our approach to data protection and your rights as a data subject.
Processing necessary to deliver the service you signed up for — account management, ticket processing, event delivery.
Fraud prevention, security monitoring, and improving the Platform.
Marketing communications and non-essential analytics. You can withdraw consent at any time.
Retaining financial records as required by applicable law.
Right of Access
Request a full copy of all personal data we hold about you. We will respond within 30 days.
Right to Rectification
Request correction of inaccurate or incomplete personal data at any time via Settings or by contacting us.
Right to Erasure
Request deletion of your personal data ("right to be forgotten"). We will erase data not required by law within 30 days.
Right to Restrict Processing
Ask us to pause processing your data while a rectification or objection request is being resolved.
Right to Data Portability
Receive your personal data in a structured, machine-readable format (JSON / CSV) and transfer it to another service.
Right to Object
Object to processing based on legitimate interests, including direct marketing. We will stop immediately upon request.
Right to Withdraw Consent
Withdraw consent at any time for processing activities that rely on consent (e.g. marketing emails).
TLS 1.3 encryption for all data in transit
AES-256 encryption for sensitive data at rest
bcrypt password hashing (cost factor 12)
JWT access tokens with 15-minute expiry
Refresh token rotation on every use
Role-based access control (RBAC) on all API routes
Regular third-party security audits
Data processing agreements with all sub-processors
Breach notification within 72 hours as required by GDPR Art. 33
To exercise any of your GDPR rights, or to raise a data protection concern, contact our Data Protection Officer:
privacy@eventosonline.xyzWe will respond within 30 calendar days as required by GDPR Art. 12.