This Policy is available in Italian and in English. If the two versions differ, the Italian version prevails.
This Policy explains which personal data we process when you use Play the Event (the playtheevent.com website, the web application and the app), why we process it, how long we keep it, who we share it with and what rights you have, under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003 (Privacy Code). It is not a contract and we do not ask you to accept it: it informs you. The Terms and Conditions of Use are a separate document (playtheevent.com/en/legal/terms-of-service).
In short
- Who processes your data: Federico Calò, a natural person, the controller of Play the Event. For any request: info@playtheevent.com (Section 1).
- What we process: your account data, the events you create with the people you invite, the technical data needed to run the site, the measurement of how you use the service, which you can object to in one step from your profile, the count of how many times the pages of the site are viewed - with no cookies and no code that concerns you (Section 3.19) - and, only if you choose to, Google Analytics statistics and the measurement of our ad conversions with Google Ads (Section 3).
- Where: on a server in Germany. The server provider, OVHcloud US, is based in the United States: this is why we treat the relationship as a transfer of data to the United States (Section 6.1).
- Artificial intelligence: the assistant runs on our server; no external artificial intelligence provider receives your conversations, your documents or your events (Section 6.3).
- Cookies: technical cookies are always needed; Google statistics and advertising are off until you turn them on from the banner, and you can change your mind at any time (Section 11).
- Advertising: we show no ads on the site and we do not sell your data, but we do advertise on Google. Every page carries the Google Ads conversion tag, which with your consent measures which clicks on our ads lead to a sign-up; if you turn on the "Advertising" category you also allow Google to use data about your visits for its advertising services (Section 11).
- Security: at sign-up we use Google's reCAPTCHA anti-bot check; on the other public forms only if you turn it on from the banner (Section 3.14).
- Deleting your account: it is immediate and final; before you confirm, we offer you a copy of your data to download (Section 8.3).
- Your rights: access, rectification, erasure, restriction, portability, objection and withdrawal of consent (Section 8); complaint to the Italian Data Protection Authority (Section 14).
- Outside the European Union: the GDPR protects your data wherever you live; United Kingdom, Switzerland, California, Brazil and Canada in Section 15.
Contents
- 1. Data Controller
- 2. Data Protection Contact
- 3. Data We Process
- 4. Legal Bases and Purposes
- 5. Recipients of Data
- 6. Transfers outside the European Union
- 7. How Long We Keep Data
- 8. Your Rights
- 9. Profiling and Automated Decisions
- 10. Security Measures
- 11. Cookies and Similar Technologies
- 12. Minors
- 13. Changes to this Policy
- 14. Complaint to the Supervisory Authority
- 15. If You Live outside the European Union
1. Data Controller
The data controller is a natural person:
Federico Calò, Viale Italia 292, 73010 Soleto (LE), Italy
Email: info@playtheevent.com
Phone: +39 333 267 3965
The Controller decides the purposes and means of processing the data of Users and of the people who take part in events managed with the Platform.
Business Customers with a data processing agreement. When a Business Customer uses the Platform to process the data of its own attendees, employees or customers and has concluded the data processing agreement (DPA) with the Controller, the Business Customer is the controller of that data and the Controller processes it on its behalf, as processor under Article 28 GDPR. In that case the information on the processing is given by the Business Customer.
2. Data Protection Contact
We have not appointed a Data Protection Officer (DPO): the conditions of Article 37(1) GDPR are not met, because our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data or of data relating to criminal convictions and offences.
For any question about the processing of your data and to exercise your rights, write to the Controller: info@playtheevent.com. If the conditions of Article 37 GDPR are met in the future, the appointment of a DPO will be notified to the supervisory authority and stated in this Policy.
3. Data We Process
3.1 Account data
When you sign up and use your account we process:
- first name and surname and email address, which is also the name you sign in with;
- your password, which we keep only in encrypted form with a one-way algorithm (BCrypt): nobody, not even us, can read it;
- if you enter them: phone number and profile picture;
- the age band you declare, if you indicate it (under 14, 14 to 17, adult): it is used to apply the rules for minors in Section 12;
- the account type (private, company, association) and, for Business plans, the organisation's details (company name, tax code or VAT number, registered office);
- the language you use on the site (Italian or English).
3.2 Technical and browsing data
To run the site and protect it we automatically process:
- your IP address, which the web server records in full in the access logs for every request, including from people who are not signed up, and in the security logs. We keep the access logs for 90 days and the other technical records for 12 months (Section 7);
- browser and operating system type and version, for compatibility and to fix errors (in the same records, and for the same time);
- date and time of requests and operations, for security (in the same records, and for the same time);
- the technical cookies used for signing in (Section 11);
- the full address requested, including any parameters it contains. If you arrive from one of our ads on Google, the address contains the `gclid` click identifier added by Google (Section 11): it stays in the access logs along with everything else, for 90 days, and we process it only for security and diagnostics, never for advertising and never to link you to an account.
3.3 Event data
For each event you create we process title and description, dates and times, place (address, coordinates, floor plans), tasks and deadlines, images and attachments, and the settings and templates you choose.
Organisation webhooks. A company or association account can connect a system of its own with a webhook: when it creates, edits, publishes or cancels an event, the Platform sends to the address chosen by the organisation (https only, with a signature that lets it check where the message comes from) the identifier, the title, the status and the dates of the event. We never send the description, the place, the reason for a cancellation or attendee data. The title is free text: if it contains a person's name, that name also reaches the organisation's system, so it is better not to write in the title personal details that are not needed. The receiving system belongs to the organisation, which is responsible for it. We record each delivery (the content sent and the response of the receiving system) so that we can retry it and show the organisation its outcome, until the organisation deletes the address or the account.
3.4 Attendee and guest data
When an Organiser adds attendees or guests to one of their events we process: first name, surname, email and phone; the reply to the invitation; arrival time and check with the QR code; food preferences and allergies, if entered; the notes and custom fields the Organiser adds.
If an Organiser added you without you being signed up, your data was provided by them (Article 14 GDPR): the source is the Organiser of the event you are invited to. You can exercise your rights by writing to info@playtheevent.com, even without an account.
3.5 Relationships between people
The "Relationship graph" feature lets you link people with a type of relationship chosen from 65 (for example spouse, partner, parent, child, sibling, colleague, friend), with dates and notes if any. From this data the Platform works out degrees of separation and possible conflicts; at the Organiser's request it also proposes likely relationships and flags possible duplicates (Section 9.1).
Family ties, on their own, are not special categories of data under Article 9 GDPR. Some relationship types can however reveal special categories of data: for example "partner" between two people of the same sex reveals sexual orientation, and a godparent relationship can reveal religious beliefs. This is why we handle them with the care required for special categories: no use outside the feature, no family ties ever proposed, no relationship created without the person concerned accepting it.
The controller of this data is the Controller named in Section 1. Anyone who adds a relationship must only enter data they may lawfully use and must not record information the other person does not want disclosed. People linked in the graph can exercise the rights in Section 8 by writing to info@playtheevent.com, even if they are not signed up.
3.6 Financial data
Expense management processes budgets, expenses (amount, category, description, date), shares assigned to each attendee, uploaded receipts and the currencies used. Card data for payments is received only by Stripe: we only receive the payment references.
If you buy a subscription or a pass for a single event (General Terms and Conditions of Sale), we record the plan or pass chosen, the event the pass refers to, the validity dates, the amount and the payment references at Stripe.
3.7 Uploaded documents and text recognition
If you upload documents (PDFs, images, texts, spreadsheets), we process their content, name, type, date and versions. The text of documents is extracted automatically, on our server, to make it searchable. Documents may contain other people's data: upload them only if you are allowed to.
3.8 Statistics and analysis features for Organisers
To offer the Organiser statistics and forecasts on their events (attendance, expenses, check-ins, risk of no-shows, anomalous values), the Platform processes event data on our server, with the safeguards in Section 9.3. Details of each feature are in Section 9.1.
3.9 Support and communications
We process the content of support requests, correspondence with the Controller and the feedback you send us about the Platform.
3.10 App diagnostic errors
When the app runs into a failure (a failed request to the server, an unhandled error, an interrupted operation) it automatically sends the Controller a technical error with only these fields: time, origin of the error, technical description (filtered of passwords and tokens and at most 500 characters long), app version, method, address and status of the request involved, error code, the app page where the error happened.
For the page we record only the path (for example "/en/events/:id/expenses"): we remove the parameters after the question mark and any session identifier, and we replace emails, codes and tokens and the numbers that identify an event or another resource with a placeholder. It is used to understand on which screen the failure happened, not who was using it or which event they had open.
The app adds no name, email or identifiers. If you have an active session, the session cookie makes it possible to link the error to your account: we use this only to delete these errors when you delete your account (Section 8.3). You can turn the sending off at any time from the app's "Diagnostics" screen (Section 8.6).
3.11 Country derived from the IP address to choose the language
When you open the site's main address (playtheevent.com, without /it or /en), the server chooses whether to show you the Italian or the English version. First comes the language you chose in the language selector, then the browser language. The country, derived from your IP address, decides only if the browser indicates neither Italian nor English: from Italy you go to the Italian version, from any other country to the English one. Pages starting with /it or /en are never redirected based on the country.
- How: the server looks up a copy of the DB-IP Lite database kept on the server itself; your IP address is not sent to DB-IP or anyone else. Like every request to the site, it passes through the infrastructure of the server provider (Section 6.1).
- What does not happen: this feature does not save the address or the country and creates no cookies.
- What happens anyway: the web server records the IP address of every request in the access logs, for security, and keeps them for 90 days (Sections 3.2 and 7).
- Legal basis: legitimate interest in showing you the site in a language you understand (Section 4.3).
- How to avoid it: open pages starting with /it or /en directly.
- Attribution: IP Geolocation by DB-IP (https://db-ip.com), data released under the Creative Commons Attribution 4.0 licence (https://creativecommons.org/licenses/by/4.0/).
3.12 Ticket buyers
When you buy a ticket for an event published on the Platform we process the name and email entered at payment (the email is needed to receive the ticket), the ticket's QR code, type and number of tickets, amount, status and dates of purchase and entry, any notes and the payment references at Stripe. You need an account to buy (Section 3.1). Card data is received only by Stripe: we neither see nor keep it.
- Who decides what: the Controller is an independent controller for payment and collection through Stripe, transfer of the amount to the Organiser, refunds it orders under Section 5.10.6 of the Terms and Conditions of Use, order reconciliation, fraud prevention, payment disputes and its own accounting obligations. The Organiser is the controller for the sale of the ticket, issuing and sending it, the list of buyers, entry checks and refunds for cancellation or postponement: for these activities the Controller processes the data on its behalf, as processor under Article 28 GDPR, according to Section 5.10.12 of the Terms and Conditions of Use, and the Organiser's privacy notice applies.
- Legal bases: performance of the contract for purchase, collection, ticket, entry and refunds; legal obligation for accounting; legitimate interest in preventing fraud and defending payment disputes, with the right to object (Section 8.6).
- Recipients: the Organiser and the staff they authorise for entry checks (name, email, ticket status, never card data); Stripe, Inc. (Section 6.2), which for some of its own purposes, such as fraud prevention, processes the data as an independent controller under its own privacy notice (https://stripe.com/privacy); our mail server (Section 6.6); the server provider (Section 6.1).
- Refunds after a cancellation: if the Organiser cancels the event, the Platform asks Stripe to refund the paid tickets and keeps a refund record: order, amount, payment and refund references at Stripe, status, number of attempts and only the code of any error. In the record we also save the email address of the person who paid, which Stripe returns to us with its answer to the refund (from the payment details or the receipt), and we use it only to tell you how the refund went, with a single email. The same record is used for supplier bookings paid through the Platform and refunded, with the email of the account that made the booking. Basis: performance of the contract for the refund and the outcome message; legal obligation for the accounting part.
- How long: the buyer's name, email, code and notes are made anonymous 12 months after the end of the event (or after the start, if the end is missing) by an automatic nightly procedure. The order, without name or email but with the payment references, is kept for 10 years for accounting and tax obligations, together with the refund record. The email address in the refund record is not deleted automatically today, not even when you delete your account: you can ask us to delete it at info@playtheevent.com and we do it at once; automatic deletion together with the other ticket data, 12 months after the end of the event, is not active yet.
- Rights: for the Controller's processing write to info@playtheevent.com; for the Organiser's processing contact the Organiser, or write to info@playtheevent.com and we will forward the request.
3.13 Data we ask for when you sign up during the Beta
When you sign up during the Beta, in addition to the data in Section 3.1, we save:
- which link brought you here: the campaign parameters we wrote in the link you opened (for example "linkedin", "post", the campaign name) and only the domain of the site you came from (for example linkedin.com), never the full page address. We do not receive your profile data on those sites nor click identifiers of advertising platforms, and we use no cookies or other browser storage for this: the parameters travel from the link to the form and are saved only when you complete the sign-up;
- the country you indicate, your type of user (for example private person, association, supplier, professional organiser) and what you want to organise: a single optional free line, up to 300 characters, in which we ask you not to write data about health, religion or other sensitive information;
- if you choose to, your availability to be contacted for an interview about the Beta (optional box, not ticked, which we do not show to anyone who declares they are under 14).
Why and on what basis: country, type of user and what you want to organise are used to tailor the service to you (performance of the contract). Which link brought you is used to understand which channels bring people who really use Play the Event, to decide where to publish and where to spend (legitimate interest, Section 4.3). We read this data only in aggregate form, with at least 10 people behind each figure and excluding our internal accounts. Availability for an interview is based on your consent, which you can withdraw at any time by writing to info@playtheevent.com.
How long: source data and the free line for 25 months from sign-up, or until the account is closed if earlier; country and type of user for as long as the account exists; interview availability until you withdraw it, and at the latest 30 days after the end of the Beta.
How to object: write to info@playtheevent.com and we delete the source data and the free line of your account (Section 8.6).
3.14 Anti-bot check with Google reCAPTCHA
To stop automated programs from creating accounts or sending forms in bulk we use Google reCAPTCHA v3. Google's script reads information about the browser and how you use the page (for example browser type and language, screen resolution, movements and interaction times) and your IP address, may set the technical cookie `_GRECAPTCHA` and returns a score showing how likely it is that a person is on the other side. We do not save the score or the data collected: we only record whether the check succeeded, in the technical records (12 months, Section 7).
- At sign-up the check is always on, and without it it is not possible to sign up. It is based on our legitimate interest in the security of the Platform and its users (Article 6(1)(f) GDPR); reading browser data is strictly necessary for the service you ask for, signing up (Article 122(1) of the Italian Privacy Code), so we do not ask for your consent.
- On the other public forms (contact form, vote in a public poll, booking an activity, request to join an association) the check runs only if you turn on the "Form protection" category in the cookie banner, that is with your consent (Article 6(1)(a) GDPR and Article 122 of the Italian Privacy Code), which you can withdraw at any time with the "Cookie settings" button at the bottom of every page. Without consent the form works anyway, with the limits on the number of submissions that apply to everyone.
- Who processes the data: Google, on our behalf, as processor, with the data also processed in the United States (Section 6.9). Next to the protected forms you will find the reference to the Google Privacy Policy (https://policies.google.com/privacy) and the Google Terms of Service (https://policies.google.com/terms).
- If the check fails: you can try again; if a script blocker stops Google, allow www.google.com and www.gstatic.com for this site. If that does not help, or if you object to the check at sign-up (Section 8.6), write to info@playtheevent.com and we will verify your sign-up another way, with a person. No sign-up is refused for good solely because of the score.
3.15 Answers to questionnaires and polls filled in without an account
Anyone with an account can create a questionnaire or a poll and share its link, for example on social media. People who answer do not need an account.
- Who decides: the questionnaire belongs to the person who created it, who decides what to ask and how to use the answers and is the controller; Play the Event hosts it and stores the data on their behalf. If the questionnaire is created by Play the Event (the questionnaire page says so), the controller is the Controller of this Policy and we use it for research on the product, that is to understand the needs of people who organise events (legitimate interest, Section 4.3).
- What we save: the answers and, only if the questionnaire asks for them, name and email. So that the same answer is not counted twice, your browser keeps a random code (Cookie Policy, section 2.1) that describes neither you nor your device; we receive it with the answers.
- Who sees answers with name and email: only the creator and the organisers of the event it is linked to.
- How long: until the creator deletes the answers or the questionnaire.
- Rights: write to the creator or to info@playtheevent.com; if the questionnaire is not ours, we forward the request to the creator and help them answer.
3.16 Quick questions in the app
Every now and then, after you have done something in the service (for example created an event), we ask you one or two quick questions: how easy it was to get the result and how you would feel if you could no longer use Play the Event.
- What we save: the answer you choose, your comment if you decide to write one (at most 500 characters: do not write personal data about yourself or others), when we asked you, the language and the time. No device or browser data. If you declared that you are under 14 we do not ask for a comment: you answer only by choosing among the suggested answers.
- Why and on what basis: to understand whether the service is useful and easy and where to improve it (legitimate interest, Section 4.3). We read answers only in aggregate form, with at least 10 people behind each figure; comments are read by the Controller to improve the service.
- How to say no: you can simply not answer, and with "Don't ask me again" we stop asking. If you want us to delete the answers you have already given, write to info@playtheevent.com.
- How long: 25 months from the answer, and in any case until your account is deleted if that happens earlier. Your answers are included in the copy of your data you can download (Section 8.5).
3.17 Measuring product use
To understand which features are really useful and where the service gets stuck, we measure the use of the product with a system of our own, which runs on our server (product telemetry). It uses no cookies or other browser storage and does not go through Google Analytics or any other provider. It has two levels, both active.
- Level 0: daily counters without people. When you perform one of the actions on a closed list (for example creating an event, generating a document with the assistant or downloading it; the list also includes sign-up, login, invitations and payments), we add one to a counter that only says which action, on which day (Rome time), from which part of the service (server, website, app) and whether one of the Controller's internal accounts did it, which we keep apart from the figures of real people. The counter does not contain your name, your email, your account identifier, your IP address, your browser or the content of what you did. To decide whether to count the action we read, at that moment, only whether you have objected and whether your account is internal; the counter does not record who performed the action.
- Level 1: one row per action, linked to your account. To measure, for example, how many people come back to the service after the first week, for each action on the same closed list we record a row with your account identifier, the type of action, the time, the part of the service you used and the object involved shown only as a number (for example the number of the event). We never record free text, the content of what you did, your IP address or your browser. From these rows we derive, every night, your usage sessions and the days on which you used the service. The actions of the Controller's internal accounts are kept apart from the figures of real people.
- Why and on what basis: improving the service by deciding what to fix and build, on the basis of our legitimate interest (Article 6(1)(f) GDPR), with a data protection impact assessment approved before starting. It is not consent: the measurement is on and you can object. Only the Controller reads the figures; level 1 figures only in aggregate form, with at least 10 people behind each figure. We do not use them for advertising, prices or offers, or for decisions about you, and we do not share them with anyone.
- How to object: at any time and without having to give reasons, with a single control on the "Privacy" page of your profile, or by writing to info@playtheevent.com. From that moment your actions no longer enter either the level 1 rows or the level 0 counters, and the rows already collected about you are deleted at once. You can withdraw the objection from the same page: the measurement starts again from that moment, and the deleted rows do not come back.
- How long: level 0 counters are kept with no expiry, because they contain no data about you. Level 1 rows: actions and sessions 400 days, days of activity 760 days, then an automatic nightly procedure deletes them; they are deleted at once when you delete your account or object. They remain only in the encrypted backup copies, until these expire (30 days, plus at most 30 days in the Gmail Trash for the copy in the Controller's mailbox, Section 8.3). Level 1 rows are included in the copy of your data you can download (Section 8.5).
- Visitors of the free tools without an account: the measurement of the tools used without an account is not active. If we turn it on, it will start only with consent to a dedicated category of the cookie banner, and we will say so first in the Cookie Policy. That is a different thing from simply counting how many times a page is viewed, which concerns no one in particular and which we explain in Section 3.19.
3.18 How you use Play the Event
In your profile you can tell us, if you wish, how you use Play the Event: for yourself, for your work as a professional organiser, or for an organisation (company, association, public body). We do not ask when you sign up.
- What we save: only your choice among the three suggested answers. No free text.
- What it is for: only to show you first, on an event page, the sections that suit how you use the service. The others always remain available under "Show more sections". If you do not answer, we choose the sections from your account type and, if you have one, your public professional profile as an event or wedding planner: this is worked out in your browser and nothing is saved. Your answer is not used for advertising, prices or plans, it is not seen by other users or by the organisers of events you attend, and it does not appear in your public profile.
- On what basis: it is a setting of the service that you choose, to get an event page that fits you better (performance of the contract, Article 6(1)(b) GDPR). Not answering does not take away any feature.
- How to change or remove it: from your profile, at any time; when you remove the answer we delete it.
- How long: until you remove it or delete your account (Section 7). Your answer is included in the copy of your data you can download (Section 8.5).
3.19 How many times the pages of the site are viewed
We publish hundreds of pages (articles, free tools, presentation pages) and we want to know which ones are read, so we can rewrite or remove the ones that are of no use to anyone. To find out, we count, on our own server, how many times each public page was viewed on a given day.
- What we save: one row that says only the day (Rome time), which page and in which language it was, with one number: how many times it was viewed. A real example of a row is "9 October 2026, the article 'Types of events' in Italian, 37 times". That row contains nothing about you: no name, no email, no identifier of your account, no IP address not even shortened, no browser, no time of day, no country.
- What we do not do, and this is the important part: we use no cookies and we write nothing and read nothing on your device; we do not assign you a visitor or session code, so we do not know and cannot know which pages the same person viewed, how long they stayed, where they came from or where they went next. Two pages viewed by you are indistinguishable, for us, from two pages viewed by two different people: it is information we have chosen not to have. We do not count at all the pages that open from a personal link (for example an invitation to an event or a questionnaire received by link), and we do not count the pages inside your account.
- Why and on what basis: to decide which pages to rewrite or remove, and to have a figure of our own against which to check Google Analytics statistics, which only measure those who accept cookies. It is a legitimate interest of ours (Article 6(1)(f) GDPR) and we do not ask you for consent, because we place nothing on your device and process nothing that identifies you: the measurement stays a statistical count, never a decision about you.
- We do not use it for anything else: not for advertising, not for prices or offers, not to recommend content to you, not for predictions about you; we do not combine it with any other data, not even with the measurement of product use in Section 3.17 or with Google Analytics; we do not share it with anyone. Only the Controller reads these figures.
- Objection, said as it is: you may object by writing to info@playtheevent.com, but there is nothing about you to remove or to stop, because we record nothing that concerns you and we have no way of telling your visits apart from the others. To exclude you we would first have to assign you a code, that is, do exactly the thing this measurement avoids. We prefer not to know who you are.
- How long: the daily counts for 25 months, after which only the monthly totals per page remain. They are not personal data, and they are not included in the copy of your data you can download, because there is nothing of yours to put in it.
- What these figures do not say: they do not say how many people visited the site. They say how many times the pages were viewed, and that is what we call them.
4. Legal Bases and Purposes
4.1 Performance of the contract (Article 6(1)(b) GDPR)
We process data because it is needed to provide the service you asked for under the Terms and Conditions of Use, or to take pre-contractual steps at your request:
- signing up and managing the account;
- the features of the plan you use, including events, invitations, expenses, documents, relationships and the assistant;
- payments through Stripe;
- service communications (event notifications, account and security notices);
- support;
- country, type of user and what you want to organise, asked at sign-up during the Beta (Section 3.13);
- the optional answer to "How do you use Play the Event?" (Section 3.18).
4.2 Consent (Article 6(1)(a) GDPR)
This processing happens only with your consent, which you can withdraw at any time; withdrawal does not make earlier processing unlawful and does not take the service away from you:
- Google Analytics statistics: Google Analytics cookies, "Statistics" category of the banner (Section 11);
- Google Ads conversion tag and Google advertising signals: "Advertising" category of the banner (Section 11);
- anti-bot check on public forms other than sign-up: "Form protection" category of the banner (Section 3.14);
- marketing communications: newsletters and offers, only if you ask for them;
- availability for an interview about the Beta (Section 3.13);
- allergy and diet data you enter about yourself, and accepting a relationship in the graph (Section 3.5).
4.3 Legitimate interest (Article 6(1)(f) GDPR)
We process this data for a legitimate interest of ours, after checking that your rights and freedoms do not override it. You can always object (Section 8.6):
- security of the Platform: access logs with IP address (90 days) and other technical records (12 months), limits on the number of requests, detection of anomalous access, to prevent unauthorised access, fraud and attacks;
- anti-bot check at sign-up (Section 3.14): one check per sign-up, Google processes the data on our behalf, no score kept by us, no sign-up refused for good without being able to talk to a person;
- choosing the language at the site's main address (Section 3.11): momentary reading of the IP address, never saved and never shared with third parties, only when the browser indicates neither Italian nor English;
- relationship suggestions and matches between attendees (Section 9.1): only numeric identifiers and relationships already accepted, no names or contacts, no family ties proposed, only a suggestion for the Organiser who asks for it;
- fixing app malfunctions (Section 3.10): sending errors is used to repair failures, not to reconstruct how you use the app;
- which link brought you when you sign up (Section 3.13): only campaign parameters written by us and the referring domain, no cookies, aggregate reading with at least 10 people per figure, deletion after 25 months;
- Play the Event questionnaires filled in without an account (Section 3.15): understanding the needs of people who organise events from answers given voluntarily;
- quick questions in the app (Section 3.16): closed answers, aggregate reading with at least 10 people per figure, "Don't ask me again" always visible;
- measuring product use (Section 3.17): daily counters with no data about you and one row per action linked to the account, read only in aggregate form with at least 10 people behind each figure; objection in one step from your profile, without reasons, which stops the collection, deletes the rows already collected and also stops the counters;
- how many times the pages of the site are viewed (Section 3.19): a count per day, page and language, with no cookies, nothing written on your device and no code that concerns you, to decide which pages to rewrite or remove;
- statistics and analysis for Organisers (Section 3.8): advanced features offered to Organisers on the data of their events, with the safeguards in Section 9.3;
- defence in complaints and disputes: keeping the relevant communications.
4.4 Legal obligation (Article 6(1)(c) GDPR)
We process data to comply with legal obligations: keeping accounting and tax records, answering requests from authorities, handling data subjects' rights and personal data breaches.
5. Recipients of Data
We do not sell your personal data and we do not give it to other companies to use for their own purposes. The only exception concerns advertising and is under your control: if you turn on the "Advertising" category in the cookie banner, Google may use data about your visits for its own advertising services (Section 11). Without that consent no data goes to Google for advertising.
5.1 Providers processing data on our behalf
| Provider | Service | Where | Transfer outside the EU |
|---|---|---|---|
| OVHcloud US | Server running the site, application, database, backups, mail and artificial intelligence models | Server in Germany; provider based in the United States | Yes (Section 6.1) |
| Stripe, Inc. | Payments, transfer of ticket revenue to Organisers, refunds | United States | Yes (Section 6.2) |
| Google (Google Cloud, reCAPTCHA service) | Anti-bot check (Section 3.14) | United States | Yes (Section 6.9) |
| Google (Google Analytics) | Statistics on site use, with cookies only with your consent (Section 11) | United States | Yes (Section 6.10) |
For ticket buyers' data processed on behalf of the Organiser (Section 3.12), OVHcloud US and Stripe are the sub-processors referred to in Section 5.10.12 of the Terms and Conditions of Use.
No third-party artificial intelligence provider receives your data (Section 6.3).
5.2 Other recipients
- Google, as an independent controller, for advertising (Google Ads and advertising signals): only if you turn on the "Advertising" category (Section 11). This covers the Google Ads conversion tag `AW-17872801987`, present on every page of the site, with the cookies `_gcl_aw`, `_gcl_gb`, `_gcl_dc` and `_gcl_au` (90 days) and the `gclid` click identifier, and Google's use of data about your visits to measure and personalise ads. The provider is Google Ireland Limited; the data may be processed in the United States by Google LLC (Section 6.10).
- Google, for the Controller's mailbox: every night it receives the encrypted backup copy of the database, which Google keeps without being able to read it (Section 6.7). It is not a provider with an agreement under Article 28 GDPR, but the mail service used by the Controller.
- Telegram: only if you use the community bot (Section 6.5).
- Other users: co-organisers and team members authorised by the Organiser see the event data within their permissions; the Organiser sees the data of the buyers of their tickets (Section 3.12).
- Systems connected by an organisation: identifier, title, status and dates of the organisation's events, sent to the webhook the organisation itself has set (Section 3.3).
- Authorities: judicial, police or administrative authorities, when the law requires it.
- Whoever takes over the business: if the business is transferred, the acquirer, with the same obligations as this Policy.
- People authorised by the Controller, bound to confidentiality, only for the data needed for their task.
6. Transfers outside the European Union
6.1 Server in Germany, provider based in the United States (OVHcloud US)
The Platform runs on a virtual server in a data centre in Germany. The server contract is with OVHcloud US, the OVHcloud group company based in the United States that manages the account and invoices the service.
- Your data (account, events, documents, database, backups, logs, conversations with the assistant) is stored in Germany, except for the encrypted backup copy sent to the Controller's mailbox (Section 6.7).
- The provider, however, is based in the United States and can access the infrastructure, for example for support and maintenance, or receive requests from US authorities. This is why we treat the relationship as a transfer to the United States and do not say that "data stays in Europe" except for where it is stored.
- The safeguard for the transfer is to be verified in the contract: it will be the provider's participation in the EU-US Data Privacy Framework, if it is certified, or the European Commission's standard contractual clauses. To date we have not yet verified it and we do not declare it established. Once it is verified you can ask for a copy (Section 6.8).
6.2 Stripe (United States)
Payment data is processed by Stripe, Inc., United States. The transfer relies on the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914); Stripe also participates in the EU-US Data Privacy Framework.
6.3 Artificial intelligence: no transfer
The assistant and the other features based on language models run on models hosted on our server in Germany. We do not call third-party artificial intelligence services: conversations, documents and event data do not leave our infrastructure and no external provider uses them, not even to train its own models.
6.3.1 How to recognise content produced by artificial intelligence
The assistant's answers and the drafts proposed by artificial intelligence are marked as such on the page and also carry a machine-readable marker, with the name of the model that produced them. Documents generated by the assistant (PDFs, Excel sheets, Gantt charts and texts) carry the same indication in their metadata. This is required by the transparency obligation in Article 50 of Regulation (EU) 2024/1689 on artificial intelligence.
6.4 Phone notifications (Firebase Cloud Messaging, Google)
Phone notifications in the Android app are not active yet, and today the app sends no data to Google for notifications. Before turning them on we will update this Policy with the data sent and the safeguard for the transfer.
6.5 Telegram
The community Telegram bot processes the Telegram identifier and username and the messages exchanged with the bot, for people who choose to use it. Telegram FZ-LLC is based outside the European Union, in Dubai. We have no documented safeguard for this transfer: Telegram does not make a verifiable data processing agreement available. If you do not want your data to go to Telegram, do not use the bot: the rest of the Platform works anyway.
6.6 Email
The Platform's emails (notifications, invitations, tickets) are sent from our mail server, which runs on the same server in Germany (Section 6.1): no third-party mail provider receives the messages.
6.7 Backup copy in the Controller's mailbox (Google)
Every night the server makes a backup copy of the whole database, encrypts it (GPG, 256-bit AES) and sends it to the Controller's mailbox at Google (Gmail). It is used only to restore the service after a failure.
- The copy contains all the data in the database, including any special categories such as allergies and intolerances, but it is encrypted before leaving the server: Google keeps it without being able to read it, because it does not have the key.
- The mailbox provider is Google Ireland Limited; Google may also process data in the United States through Google LLC, which participates in the EU-US Data Privacy Framework. Encryption with a key the provider does not have is the supplementary measure that Recommendations 01/2020 of the European Data Protection Board indicate for the mere storage of copies.
- Each copy stays in the mailbox for 30 days; it then moves to the Gmail Trash, which deletes it within another 30 days.
6.8 Copy of the safeguards
You can ask for a copy of the safeguards adopted for transfers outside the European Union by writing to info@playtheevent.com.
6.9 Google reCAPTCHA (United States)
The anti-bot check in Section 3.14 is a Google Cloud service. Google processes reCAPTCHA data on our behalf, as processor, under the Cloud Data Processing Addendum, which includes the Commission's standard contractual clauses (Implementing Decision (EU) 2021/914); Google LLC also participates in the EU-US Data Privacy Framework. Data may be processed in the United States.
6.10 Google Analytics, Google Ads and advertising signals (United States)
Google Analytics is provided by Google Ireland Limited and by Google LLC, which may process data in the United States. The transfer relies on Google LLC's participation in the EU-US Data Privacy Framework (Commission adequacy decision of 10 July 2023) and, as a fallback, on the standard contractual clauses included in Google's data processing terms. For the advertising use described in Section 11 Google processes the data as an independent controller, under its own privacy policy (https://policies.google.com/privacy).
The same applies to Google Ads: the conversion tag `AW-17872801987`, present on every page of the site, is provided by Google Ireland Limited, and the conversion data (the `_gcl_*` cookies, the `gclid` click identifier, the page address and the IP address) may be processed in the United States by Google LLC, under the same transfer safeguard. Without your consent to the "Advertising" category no cookie is set and no click identifier is kept; the tag's script loads anyway and sends Google cookieless technical signals that include your IP address, as described for Google Analytics in Section 11.
7. How Long We Keep Data
We keep data only for as long as needed for the purposes for which we process it (Article 5(1)(e) GDPR).
| Data | How long | Why |
|---|---|---|
| Account and events | For as long as the account exists. When you delete it, deletion is immediate: afterwards we keep none of your events, participants, shared expenses, dietary preferences or other relationships. Only accounting and tax data remains, with its own period, and the full list is in Section 8.3 | Performance of the contract |
| Accounts without a paid plan at the end of the Beta | Viewing and export for at least 90 days from the end of the Beta; then deletion of the account and content, with an email notice 30 days before and reminders at 7 days and 1 day | Performance of the contract |
| Inactive account (this is not the same as a deleted account: here the account still exists and is not being used) | Deletion after 24 months of inactivity, with an email notice beforehand. The rule is adopted but not yet applied automatically: until then inactive accounts are not deleted for this reason | Storage limitation |
| Web server access logs (IP address, full address requested, browser, date and time of every request) | 90 days | Security |
| Other technical records (application and diagnostics logs, web server error log, sign-in outcomes) | 12 months | Security |
| Accounting and tax records, ticket orders without name or email | 10 years | Legal obligation |
| Tickets: buyer's name, email, code and notes | Made anonymous 12 months after the end of the event | Performance of the contract, disputes |
| Support requests | 3 years from closure | Legitimate interest, complaints |
| Sign-in cookies (`accessToken`, `refreshToken`) | 30 minutes and 45 minutes | Performance of the contract |
| Google Analytics cookies (`_ga`, `_ga_R1K4DVSC5Y`) | 13 months, only with your consent | Consent |
| Visit data in Google Analytics | 14 months, then deleted by Google | Consent |
| Google Ads conversion cookies (`_gcl_aw`, `_gcl_gb`, `_gcl_dc`, `_gcl_au`), which contain the `gclid` click identifier | 90 days, only with your consent | Consent |
| The `gclid` click identifier in the server access logs | 90 days, like any other access log data | Legitimate interest (security) |
| Encrypted backup copies | 30 days, on rotation; the copy in the Controller's mailbox moves to the Trash after 30 days and is deleted within another 30 days | Service continuity |
| App diagnostic errors | 30 days, then automatic deletion | Legitimate interest |
| Source data and free line from sign-up during the Beta | 25 months from sign-up, or until the account is closed if earlier | Legitimate interest |
| Country and type of user given at sign-up | For as long as the account exists | Performance of the contract |
| Availability for an interview | Until withdrawn, and at the latest 30 days after the end of the Beta | Consent |
| reCAPTCHA anti-bot check | We keep no score or data collected; only the outcome stays in the technical records (12 months) | Legitimate interest or consent (Section 3.14) |
| Answers to questionnaires filled in without an account | Until the creator deletes them | Creator's choice; for Play the Event questionnaires legitimate interest |
| Quick questions in the app | 25 months from the answer, or until the account is deleted if earlier | Legitimate interest |
| Product telemetry, level 1: one row per action, linked to the account | Actions and sessions 400 days, days of activity 760 days; deleted at once with the account or with the objection; they remain in the encrypted backup copies until these expire (30 days, plus at most 30 days in the Gmail Trash for the copy in the Controller's mailbox) | Legitimate interest |
| Product telemetry, level 0: daily counters without people | No expiry: they contain no data about you | Not personal data |
| How many times the pages of the site are viewed (Section 3.19) | Daily counts 25 months; afterwards only the monthly totals per page | Not personal data; legitimate interest for the momentary reading of the request |
| Refund record | With the order, 10 years. The email of the person who paid is not deleted automatically today: we delete it on request (Section 3.12) | Performance of the contract, legal obligation |
| Deliveries of organisation webhooks (content sent and response) | Until the organisation deletes the webhook address or the account | Performance of the contract |
| Answer to "How do you use Play the Event?" | Until you remove it from your profile or delete your account | Performance of the contract |
| Marketing communications | Until consent is withdrawn | Consent |
| Personal data breaches notified to the supervisory authority | 5 years | Legal obligation |
When the period ends the data is deleted or made anonymous irreversibly.
8. Your Rights
You have the rights in Articles 15-22 GDPR. You exercise them as described in Section 8.8.
8.1 Access
You can find out whether we process data about you and receive a copy, with the purposes, the categories of data, the recipients, the retention period, the source and your rights.
8.2 Rectification
You can correct inaccurate data and complete incomplete data; you can correct most of it yourself from your profile.
8.3 Erasure
You can ask for your data to be deleted when it is no longer needed, when you withdraw the consent it is based on, when you object and there are no overriding legitimate grounds, or when it is processed unlawfully.
Deleting your account. You can delete your account from your profile. Before you confirm, the page offers you to download a copy of your data (Section 8.5). Deletion is immediate and final: the account, the events you created and the related data, including app diagnostic errors, are deleted at once, and afterwards they can no longer be downloaded. Only the following remain:
- accounting and tax records and ticket orders, for 10 years (Section 7);
- the email address in the refund record, if you received a refund, until automatic deletion is active: ask us to delete it at info@playtheevent.com (Section 3.12);
- backup copies, until they expire (30 days, plus at most 30 days in the Gmail Trash for the copy in the Controller's mailbox): if we ever had to restore a copy, we would delete your account again before reopening the service, and for this reason we keep the numeric identifier of the deleted account outside the database, for as long as a copy may still contain it.
And nothing else remains. A list of what survives does not say enough, so we also say what we do not keep after deletion, not even briefly: the events you created, with their activities, deadlines and locations; the participants and invitations of your events; the shared expenses, budgets and splits, in the part that has no tax relevance; the dietary preferences, allergies and special diets; the relationships between people you had entered; the documents you uploaded and the text recognised inside them; the rows of the product usage measurement (Section 3.17); the app diagnostic errors. The law requires us to keep accounting and tax records: it does not authorise us to keep the rest, and we do not keep it.
8.4 Restriction
You can ask us to restrict processing when you contest the accuracy of the data, when the processing is unlawful but you do not want erasure, or when you need the data to defend a right in court.
8.5 Portability
You can receive the data you provided to us in a structured, machine-readable format. From your profile, in the "Export your data" box, you immediately download an Excel file with your profile, events, collaborators, expenses, relationships, subscriptions, your answers to the quick questions and your answer to "How do you use Play the Event?". For data the file does not contain, write to info@playtheevent.com.
8.6 Objection
You can object at any time to processing based on legitimate interest (Section 4.3), including profiling: we stop, unless there are compelling legitimate grounds that override your interests or we need the data to defend a right in court. You can always object to the use of data for advertising and marketing communications, without giving reasons.
Some objections you make yourself: sending app errors from the "Diagnostics" screen, with immediate effect; relationship suggestions from the "Suggestions about people" page of your profile (Section 9.4); quick questions with "Don't ask me again"; the measurement of product use from the "Privacy" page of your profile (Section 3.17), without giving reasons, with the immediate deletion of the rows already collected about you. For all the others write to info@playtheevent.com.
8.7 Automated decisions
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. The Platform takes no decisions of this kind (Section 9.2).
8.8 How to exercise your rights
You can use the profile features mentioned above or write to info@playtheevent.com. We answer within one month of the request; for complex requests the period can be extended by two further months, and in that case we tell you within the first month. It is free of charge, except for manifestly unfounded or excessive requests. We may ask you to confirm your identity before answering, so as not to hand your data to someone else.
9. Profiling and Automated Decisions
9.1 Analysis features for Organisers
At the Organiser's request the Platform processes the data of their events to offer them:
- an estimate of the risk of no-shows among guests, as a rough indication;
- groups of attendees with similar attendance habits;
- forecasts of attendance;
- flagging of anomalous values in expenses or check-ins.
Relationship suggestions and matches between attendees. If the Organiser asks the assistant, the Platform works out with fixed rules, not with an artificial intelligence model (the assistant only presents the result): likely relationships between people in their network (based on the events they organised that you attended together, and on both of you being their colleagues or members), possible duplicate accounts, and people who might get to know each other at one of their events. Attendance at all events of the same Organiser is considered, of any kind; events of other Organisers are not used. Possible duplicate accounts are only flagged: accounts are never merged. Family ties are never proposed. The Organiser only sees a suggestion, with the reason: no relationship is created without the person concerned accepting it. No names or contacts are used for these calculations.
9.2 No binding automated decisions
No decision with legal effects or similarly significant effects (refusing access, penalties) is based solely on automated processing. Analysis results support the Organiser, who decides.
9.3 Safeguards
Analyses run on our server; they receive only the data needed for each feature, with numeric identifiers instead of names; results about groups of people are not shown if the group is too small to keep someone from being recognised.
9.4 Objection
You can object to the analysis features that concern you by writing to info@playtheevent.com; you do not lose access to the basic features. For relationship suggestions and matches, objection is a separate choice, from the "Suggestions about people" page of your profile, where you can also withdraw it, or by email: no reason is needed, it applies to all Organisers and from then on you will no longer appear in these calculations. Relationships you have already accepted remain.
10. Security Measures
We adopt technical and organisational measures appropriate to the risk (Article 32 GDPR):
- encrypted communications only (HTTPS) and HSTS;
- passwords stored with BCrypt; sign-in with signed tokens in cookies that page code cannot read (HttpOnly), with the SameSite attribute, which the browser does not send with change requests coming from other sites;
- limits on the number of requests on all services, against repeated attempts and abuse;
- database reachable only from the server itself, with restricted access; encrypted backup copies on a 30-day rotation, with restore tests;
- prepared queries against code injection, input validation, security headers on pages (Content Security Policy);
- web server access logs kept for 90 days and other technical records kept for 12 months (Section 7);
- access to systems limited to the Controller and the people he authorises, bound to confidentiality;
- a register of personal data breaches: if a breach poses a risk to your rights we notify the supervisory authority within 72 hours of discovering it and, if the risk is high, we inform you without undue delay.
11. Cookies and Similar Technologies
The details of each cookie, with duration and provider, are in the Cookie Policy (playtheevent.com/en/legal/cookie-policy). In short, the cookie banner has four categories:
- Necessary, always on and without consent: the sign-in cookies `accessToken` and `refreshToken` (30 and 45 minutes) and the `lingua_preferita` cookie (one year, created only when you choose the language in the selector). We keep your cookie choice in the browser (`localStorage`, entry `pte_cookie_consent`), not in a cookie.
- Statistics, off until you turn them on: Google Analytics cookies (`_ga`, `_ga_R1K4DVSC5Y`), which last 13 months; Google keeps the visit data linked to those cookies for 14 months. Even without consent the Google Analytics script loads and sends Google technical signals without cookies, which include your IP address, used by Google for aggregate estimates of visits.
- Advertising, off until you turn it on: this covers the Google Ads conversion tag `AW-17872801987`, which the site loads on every page. We show no ads on our site, but we do advertise on Google, and the tag tells us which clicks on our ads lead to a sign-up. With this consent: Google sets the conversion cookies `_gcl_aw`, `_gcl_gb`, `_gcl_dc` and `_gcl_au` on the site's domain, lasting 90 days; if you arrive from one of our ads, the address you open contains the `gclid` click identifier ("Google Click Identifier"), which Google adds to recognise that single click and, with your consent, keeps in the `_gcl_aw` cookie for 90 days (we do not store it in our database: Sections 3.2 and 3.13); and Google may use data about your visits for its advertising services, that is to measure and personalise ads, including on other sites and apps. For this use Google is an independent controller, under its own privacy policy (https://policies.google.com/privacy) and its rules on the use of data from partner sites (https://policies.google.com/technologies/partner-sites). Without your consent no advertising cookie is set and no `gclid` is kept; the tag's script loads anyway and sends Google cookieless technical signals that include your IP address.
- Form protection, off until you turn it on: Google's reCAPTCHA anti-bot check on public forms other than sign-up (Section 3.14). At sign-up the check is always on and does not depend on this choice.
"Accept all" turns on the three optional categories; "Reject all" leaves them off. You can change your choice at any time with the "Cookie settings" button at the bottom of every page or from the "Cookie preferences" section of your profile. If you declared that you are under 14, the banner does not offer you the optional categories (Section 12).
Without consent, because they serve features you ask for, we also use some entries in the browser's storage, such as the interface language and the random code that avoids counting the same answer to a questionnaire or public poll twice (Cookie Policy, section 2.1).
12. Minors
Opening an account requires being at least 16 years old (Terms and Conditions of Use, Section 3.1). We do not ask you for an identity document: we rely on what you declare, and a declaration is not a verification. If we learn that someone with an account is under 16 we delete nothing by surprise: we write to the account's email address and give you at least 30 days to export your data, following the procedure written in Section 3.1 of the Terms.
The public parts of the site remain open at any age: the free tools, the blog, the public questionnaires and surveys, the waiting-list sign-up. There we do not know how old you are, and for those parts the statutory threshold explained below applies, not the 16-year requirement.
At sign-up we ask, optionally, for your age band. The bands we offer today are three - under 14, 14 to 17, adult - and they do not distinguish 16 years: they serve the statutory threshold of 14 years, not the enforcement of the 16-year requirement. We say so because you should know what we measure and what we do not.
If you are under 14, the processing based on consent listed in Section 4.2 requires the consent of the holder of parental responsibility (Article 8 GDPR and Art. 2-quinquies of Italian Legislative Decree 196/2003, which for Italy sets that threshold at fourteen years), and access to artificial intelligence requires the same consent (Article 4 of Italian Law No. 132 of 23 September 2025). For this reason, if you declare you are under 14: the banner does not offer you statistics, advertising or form protection; we do not show you the interview box or the free comment of the quick questions; you cannot use the chat with artificial intelligence. That threshold is set by law and does not change because the Terms require 16 years: it applies to everyone, with or without an account.
If you believe we have processed data of a child under 14 without the required consent, write to info@playtheevent.com: we will delete that data.
13. Changes to this Policy
We may update this Policy when the processing, the law or the Platform changes. The version and date are at the top of the page. If a change reduces your rights, we tell you about it before it comes into force, by email to your account address and with a notice in the Platform the first time you sign in. Other important changes apply from the day we publish them and we tell you about them on the same day, in the same way; new processing that requires your choice stays off until you turn it on. If a change requires your consent, we ask for it: we do not infer it from the fact that you keep using the Platform.
Previous versions of this Policy are available on request at info@playtheevent.com.
14. Complaint to the Supervisory Authority
If you believe that the processing of your data infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Article 77 GDPR), Piazza Venezia 11, 00187 Rome, website https://www.garanteprivacy.it, email protocollo@gpdp.it, or with the supervisory authority of the country where you live or work. You can also go to court (Article 79 GDPR). If you wish, write to us first at info@playtheevent.com: we will try to settle the matter directly.
15. If You Live outside the European Union
Play the Event is run by a natural person established in Italy: this is why the GDPR applies to your data wherever you live, and the rights in Section 8 and the complaint in Section 14 apply to you too, in the same way and within the same time limits. The site is in Italian and English and is not aimed at any particular country outside the European Union. This Section explains how the laws of some countries relate to this Policy: it adds no rights beyond those the law gives you. If a law of your country applies to our case, we comply with its obligations; if it is not clear that it applies, we still answer your request with the rights in Section 8. Write to info@playtheevent.com and tell us the country where you live.
15.1 United Kingdom (UK GDPR)
If you live in the United Kingdom, the UK GDPR and the Data Protection Act 2018 may also apply to the processing; they give you rights similar to those in Section 8, which you exercise in the same way. Besides the complaint in Section 14, you can contact the Information Commissioner's Office (ICO): https://ico.org.uk/make-a-complaint/. Where data is stored and which transfers take place is described in Section 6.
15.2 Switzerland (nFADP)
If you live in Switzerland, the Federal Act on Data Protection (nFADP), in force since 1 September 2023, may also apply to the processing; among other things it gives you the right of access and the right to receive your data in a commonly used electronic format, which you exercise as described in Section 8. You can contact the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch/.
15.3 California (CCPA/CPRA)
The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to businesses above certain thresholds: among them, annual gross revenue above 25 million dollars (an amount adjusted periodically) or buying, selling or sharing the personal information of 100,000 or more California consumers or households a year (https://oag.ca.gov/privacy/ccpa). Play the Event currently meets none of these thresholds, so it is not subject to that law. We still tell you, in its terms, what we do: we do not sell your personal information for money. If you turn on the "Advertising" category in the banner (Section 11), you allow Google to use data about your visits for advertising based on browsing across sites, which Californian law calls "sharing": the category is off until you turn it on and you can turn it off at any time with the "Cookie settings" button. You can exercise the rights in Section 8 from California too, and we do not treat you differently for exercising them.
15.4 Brazil (LGPD)
If you use Play the Event while you are in Brazil, the Lei Geral de Proteção de Dados (Law No. 13,709/2018, LGPD) also applies to the processing; it gives you rights similar to those in Section 8: confirmation that we process data about you, access, correction, deletion of unnecessary data, portability, information about the parties we share it with and withdrawal of consent. You exercise them by writing to info@playtheevent.com, our channel for requests. You can also contact the Autoridade Nacional de Proteção de Dados (ANPD): https://www.gov.br/anpd/pt-br. Data transfers are described in Section 6.
15.5 Canada (PIPEDA)
If you live in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) may apply to the processing; it gives you the right to access your data, to ask for it to be corrected and to challenge how we handle it. You exercise these rights as described in Section 8. You can complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca/. Some provinces, such as Quebec, have their own laws.