Privacy Policy
1. Who we are
The Ewento App is operated by JVF s.r.o. registration number: 55 627 510 with registered office at Moyzesova 2808/10, 058 01 Poprad, registered in the Commercial Register of District Court Prešov (hereinafter referred to as „Controller“). Contact person/contact point: e-mail support: ewento.contact@gmail.com, telephone: +421 910 655 611.
2. What data we process
We only process publicly available data about events, namely:
- name and brief description of the event,
- date and time of the event,
- the venue (address or GPS coordinates if the source contains them),
- cover image,
- categories and tags associated with the event (artistic genre, target group, theme, etc.).
We draw date from public sources (e.g. Facebook pages, official organizers websites, open-data platforms). No collection or processing of user’s personal data takes place. The only user footprint in the app is the list of categories, which the user saves themselves for personalization purpose.
Some organizers may insert personal data (e.g. phone contact of a person) in the event text. Ewento technically displays such data but does not store it outside the source and does not perform further operations on it. The user has the option to report inappropriate content, which we will remove in accordance with the Digital Services Act.
3. Purposes and legal basis of processing
- Aggregation and display of public events – we collect public event data and provide it in a transparent form. (Legal basis: Article 6 (1) (f) GDPR – the legitimate interest of the Controller in the operation of a service that contributes to the promotion of cultural and social life).
- Recommendation and personalization – based on the event categories/tag and categories that the user saves in the App, we display more relevant events in their vicinity. (Legal basis: legitimate interest according to Article 6 (1) (F) GDPR, the user can turn off personalization at any time).
The processing does not interfere in any way with the rights and freedoms of the data subjects, as we only work with publicly published content and without identifying visitors.
4. Data storage and security
We store all aggregated event data in an encrypted database, which is located exclusively in a cloud infrastructure on the territory of the European Union. This infrastructure is regularly audited and certified according to ISO 27001 and ISO 27017 standards, so that it meets strict information and cloud security requirements. In transmission between your device and our servers, data is protected by TLS 1.3 protocol, while we use AES-256 symmetric encryption when stored in the database, ensuring protection both „in motion“ and „at rest“.
Database accesses are subject to multi-factor authentication and are governed by the principle of least privilege. Every access and access attempt are logged in systems logs, which are archived for 365 days and continuously evaluated to detect anomalies or unauthorized activity.
We retain event data for a maximum of 12 months after the date of the event, after this period, it is automatically deleted or anonymized and archived for statistical purposes. We only keep a record of user preferences (saved interest categories) for as long as the user has an active account or until the user request to deactivate personalization.
To protect against data loss, we create daily incremental backups, each backup is encrypted, stored in an EU region and retained for 30 days. At least once a year, we commission an independent security team to perform a penetration test of the entire infrastructure. Critical vulnerabilities are remediated immediately, and no later than 30 days after identification.
5. User rights
Although we do not process your personal data, the GDPR grants you the following rights if the processing would affect on identifiable person (e.g. if you add your own content):
- Right of access – you can request confirmation of whether we are processing data about you and obtain a copy of that data.
- Right to erasure („forgetting“) – if you wish to delete stored categories of interest or if Ewento has accidentally stored personal data, you can request erasure.
- Right to object – you can object to personalization based on legitimate interest at any time, it will trigger a neutral display to you without recommendations.
- Right to restriction of processing – temporary „freezing“ of data while the objection is resolved.
- Right to lodge a complaint – Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk.
How to exercise rights:
Send a request from the e-mail address with which you are registered to ewento.contact@gmail.com or in writing to our registered office. In the interest of data protection, we may request additional verification. We will reply within 30 days; in justified cases we may extend the deadline by a further 30 days (we will inform you).
6. Transfer to third countries
The data is processed exclusively in the European Economic Area. Should a transfer outside the EEA occur in the future, it will only take place to countries with an adequacy decision or using standard contractual clauses under the GDPR.
7. Automated decision-making and profiling
The app uses simple profiling – sorting and filtering events according to the categories you have marked as proffered. The profiling does not have legal or other significant effects; it only serves to increase the relevance of the display.
8. Policy changes
You can always find an updated version of the Policy on the App and at www.ewento.eu. We will notify you or significant changes by e-mail at least 14 days before they take effect.
9. Contact
JVF s.r.o.
Moyzesova 2808/10 058 01 Poprad
IČO:55627510
DIČ: 2122259051
VAT: SK2122259051
ewento.contact@gmail.com
+421 910 655 611
Statement
The controller declares that it applies the privacy-by-design and privacy-by-default principles in the design and operation of Ewento, minimizes the volume of data processed and takes into account protentional risk in terms of the proportionally principle.