Privacy Policy

Last updated: 25 Aug 2026

Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data Processing on This Website

Data processing on this website is carried out by the website operator:

FireVue UG (haftungsbeschränkt)
Thiedeweg 26
22047 Hamburg
E-Mail: contact@fvevents.com

Hosting and Content Delivery

Vercel

We host our website with Vercel. The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA.

Vercel is a tool for deploying and hosting websites. When you visit our website, your data is processed on Vercel servers. This may include IP addresses and server log files. Vercel is certified under the EU-US Data Privacy Framework.

For more details, see the Vercel privacy policy: https://vercel.com/legal/privacy-policy

Vercel Speed Insights

We use Vercel Speed Insights to measure the technical performance of our website (e.g., page load times and Core Web Vitals). The service collects anonymized technical data only and does not collect personally identifiable information. The data is processed solely to monitor and improve website performance.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analyzing and improving our website).

Cloudflare Web Analytics

We use Cloudflare Web Analytics, a privacy-focused, cookie-free analytics service provided by Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA), to measure the reach and performance of our website. The service does not use cookies, does not store or access any information on your device, and does not create persistent visitor profiles or fingerprints across websites. When you visit our site, a small measurement script loads and transmits data such as the page visited, the referrer, browser type and version, the approximate region, and performance metrics (e.g., page load times). Your IP address is processed transiently to deliver the request but is not stored or used to identify you. Cloudflare is certified under the EU-US Data Privacy Framework, and we have concluded a data processing agreement with Cloudflare.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the statistical analysis and improvement of our website). As no information is stored on or read from your device, no consent under Section 25 TDDDG is required.

Cloudflare R2 (Storage & CDN)

We use services from Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA) to store and deliver user-uploaded content (e.g., profile pictures, documents, form attachments). Storage takes place in a bucket within the European Union. Cloudflare also serves as a Content Delivery Network (CDN) to optimize load times of content worldwide. Cloudflare is certified under the EU-US Data Privacy Framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient delivery of our services).

Registration and Authentication

Supabase (Database & Auth)

For managing user accounts and storing data, we use Supabase. The database is hosted in the EU. The provider is Copple Software Inc. (Supabase), 970 Summer St, Stamford, CT 06905, USA. We have concluded Standard Contractual Clauses with the provider.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Social Login (Google & Apple)

You can register with us via Google or Apple.

  • Google: Provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
  • Apple: Provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland.

When you register, we receive your name, email address, and possibly your profile picture from these providers.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Chat and Push Notifications

Chat data

When you use chat, we process the information needed to provide and secure the feature. This includes your account identifier and display name, event and conversation membership, chat roles and permissions, messages and replies, timestamps, read and mute status, and moderation actions such as deleting messages or removing members. Depending on the type of conversation, this information is visible to the other person, the members of a group or community, or the participants and team members of an event channel.

FireVue processes event-related chat data on behalf of the event organizer. The organizer remains responsible for the lawfulness of using chat for their event and for informing participants where required. We process platform-wide direct messages to provide the communication feature requested by the account holders.

Legal basis: Art. 6(1)(b) GDPR (providing the requested platform and communication functions) and, for processing carried out on behalf of an event organizer, the legal basis determined by that organizer in accordance with the Data Processing Agreement.

Optional push notifications via Expo

If you allow notifications in the participants app, we store an Expo push token linked to your FireVue account together with the device platform (iOS or Android). When another person sends you a chat message, the notification request can contain the sender's display name or group title, up to the first 120 characters of the message, and technical conversation and event identifiers. Depending on your device settings, this preview may be visible on the lock screen or notification center.

We use the Expo Push Service provided by 650 Industries, Inc. (Expo), USA. Expo forwards notifications to Apple Push Notification Service (APNs) for iOS devices or Google Firebase Cloud Messaging (FCM) for Android devices. This means that the device token and notification payload are processed by Expo and the applicable operating-system provider. Processing may take place outside the EU/EEA. Appropriate safeguards for international transfers are provided by the applicable Data Privacy Framework certification and/or EU Standard Contractual Clauses.

Expo states that it does not store notification content in a database and retains it in memory or message queues only for delivery; content may be visible to Expo staff during active debugging. Apple or Google may temporarily retain undelivered notifications according to their own service rules. In particular, FCM may retain an undelivered notification for up to four weeks when no shorter lifetime is specified.

Push notifications are used only for service and chat messages, not for advertising. You can decline or withdraw notification permission in your device settings, mute individual conversations in the app, or sign out to remove the registered token from your account. Muting a conversation affects push delivery only and does not delete its messages. Invalid device tokens are removed when the delivery provider reports that the device is no longer registered; tokens are also deleted when the associated FireVue account is deleted.

Legal basis: Art. 6(1)(b) GDPR (providing the notification function requested by you) and, where consent is required, Art. 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future.

For more information, see Expo's privacy policy, Expo's push-notification privacy information, Google's Firebase privacy information, and Apple's privacy policy.

Payment Processing

Stripe

We use Stripe for payment processing. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.

  • For business customers: When you subscribe, your payment data is transmitted to Stripe.
  • For event participants: When you buy a ticket, payment is processed via Stripe Standard directly to the event organizer (business customer). FireVue only receives confirmation information (payment ID, amount, timestamp) but does not store credit card data.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

For more details, see the Stripe privacy policy: https://stripe.com/privacy

Email Communication

System emails (e.g., password reset, confirmations) are sent via Cloudflare Email Service. Your email address and message content are processed to ensure delivery.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Contact and demo request forms

When you submit a contact or demo request form, we process the information you provide, such as your name, email address, organization, role, event requirements, message content, IP address, and submission time. We use this data to respond to your request, arrange follow-up communication, and protect the form from misuse.

We retain these requests only as long as needed to handle the inquiry and any resulting business communication, unless legal retention obligations require a longer period.

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries and preventing misuse).

Cookies and Technically Necessary Data

We do not use marketing or tracking cookies. We only use technically necessary cookies to ensure the functionality of the platform (e.g., login session, language settings).

Legal basis: § 25(2) TDDDG (German Telecommunications-Digital Services Data Protection Act).

Data Processing Agreement (Important for Business Customers)

FireVue acts as a data processor for event participants. Business customers using our platform to collect participant data are "controllers" within the meaning of the GDPR.

We have created a specific Data Processing Agreement (DPA) for this purpose, which can be viewed at /dpa-contract and is an integral part of the contractual relationship.

Artificial Intelligence (AI) Features

We provide AI-assisted features within the administration area of our platform (in particular an in-app assistant) that help organizers manage events, analyze registrations, and edit content. Depending on the task, your requests are processed by different AI providers acting as our processors. We have concluded data processing agreements with these providers and, where personal data is transferred to a third country, rely on the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.

Processing of participant and other personal data (Mistral AI, EU)

Any AI feature that processes personal data — in particular questions about, and analysis of, event participants and their registrations — is handled exclusively by Mistral AI (Mistral AI SAS, Paris, France), a provider based in the European Union, on EU-hosted infrastructure. Mistral does not use this data to train its models. Inputs and outputs are retained for a maximum of 30 days solely for the purposes of abuse prevention and security, after which they are deleted. We have concluded a data processing agreement with Mistral.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in providing efficient event-management tools).

Other AI features (content and configuration assistance)

For tasks that are not intended to involve personal data — such as creating and editing landing-page content, drafting text and design suggestions, and configuring events — we may use additional AI providers (currently Google and Anthropic) via the Vercel AI Gateway. We have concluded a data processing agreement with Vercel, and these providers are certified under the EU-US Data Privacy Framework and/or bound by EU Standard Contractual Clauses.

Important: These features are not intended for personal data. You must not enter personal data of third parties (for example participant names, contact details, or any information about identifiable individuals) into free-text fields processed by these features, such as landing-page content, event descriptions, or configuration settings. As the controller for the content you enter, you are responsible for ensuring that no such personal data is provided to these features.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing efficient content and configuration tools).

No automated decision-making; no training on your data

Our AI features assist organizers and do not carry out automated decision-making that produces legal effects concerning, or similarly significantly affects, data subjects within the meaning of Art. 22 GDPR. Where the option is available, we have disabled the use of your data for training the providers’ models.

Your Rights

You have the right at any time to:

  • Access information about your stored data
  • Rectify or delete your data
  • Restrict processing
  • Data portability
  • Object to the processing of your data (Art. 21 GDPR)
  • Withdraw any consent you have given, with effect for the future (Art. 7(3) GDPR)
  • Lodge a complaint with a supervisory authority

To exercise these rights, please contact: contact@fvevents.com

Data Retention

We store your personal data only as long as necessary to fulfill the purposes described in this privacy policy or as required by law. Event data is retained for the duration of the event and for legal retention periods (typically 10 years for accounting purposes).

Data Security

We use appropriate technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security measures are continuously improved in line with technological developments.

© 2026 Events by FireVue. All rights reserved.