Privacy Policy
Last updated: 27 Jun 2026
Data Protection at a Glance
General Information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.
Data Processing on This Website
Data processing on this website is carried out by the website operator:
FireVue UG (haftungsbeschränkt)
Thiedeweg 26
22047 Hamburg
E-Mail: contact@fvevents.com
Hosting and Content Delivery
Vercel
We host our website with Vercel. The provider is Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA.
Vercel is a tool for deploying and hosting websites. When you visit our website, your data is processed on Vercel servers. This may include IP addresses and server log files. Vercel is certified under the EU-US Data Privacy Framework.
For more details, see the Vercel privacy policy: https://vercel.com/legal/privacy-policy
Vercel Speed Insights
We use Vercel Speed Insights to measure the technical performance of our website (e.g., page load times and Core Web Vitals). The service collects anonymized technical data only and does not collect personally identifiable information. The data is processed solely to monitor and improve website performance.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in analyzing and improving our website).
Cloudflare Web Analytics
We use Cloudflare Web Analytics, a privacy-focused, cookie-free analytics service provided by Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA), to measure the reach and performance of our website. The service does not use cookies, does not store or access any information on your device, and does not create persistent visitor profiles or fingerprints across websites. When you visit our site, a small measurement script loads and transmits data such as the page visited, the referrer, browser type and version, the approximate region, and performance metrics (e.g., page load times). Your IP address is processed transiently to deliver the request but is not stored or used to identify you. Cloudflare is certified under the EU-US Data Privacy Framework, and we have concluded a data processing agreement with Cloudflare.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the statistical analysis and improvement of our website). As no information is stored on or read from your device, no consent under Section 25 TDDDG is required.
Cloudflare R2 (Storage & CDN)
We use services from Cloudflare Inc. (101 Townsend St., San Francisco, CA 94107, USA) to store and deliver user-uploaded content (e.g., profile pictures, documents, form attachments). Storage takes place in a bucket within the European Union. Cloudflare also serves as a Content Delivery Network (CDN) to optimize load times of content worldwide. Cloudflare is certified under the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient delivery of our services).
Registration and Authentication
Supabase (Database & Auth)
For managing user accounts and storing data, we use Supabase. The database is hosted in the EU. The provider is Copple Software Inc. (Supabase), 970 Summer St, Stamford, CT 06905, USA. We have concluded Standard Contractual Clauses with the provider.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Social Login (Google & Apple)
You can register with us via Google or Apple.
- Google: Provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
- Apple: Provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland.
When you register, we receive your name, email address, and possibly your profile picture from these providers.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Payment Processing
Stripe
We use Stripe for payment processing. The provider is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland.
- For business customers: When you subscribe, your payment data is transmitted to Stripe.
- For event participants: When you buy a ticket, payment is processed via Stripe Standard directly to the event organizer (business customer). FireVue only receives confirmation information (payment ID, amount, timestamp) but does not store credit card data.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
For more details, see the Stripe privacy policy: https://stripe.com/privacy
Email Communication
System emails (e.g., password reset, confirmations) are sent via Cloudflare Email Service. Your email address and message content are processed to ensure delivery.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Contact and demo request forms
When you submit a contact or demo request form, we process the information you provide, such as your name, email address, organization, role, event requirements, message content, IP address, and submission time. We use this data to respond to your request, arrange follow-up communication, and protect the form from misuse.
We retain these requests only as long as needed to handle the inquiry and any resulting business communication, unless legal retention obligations require a longer period.
Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries and preventing misuse).
Cookies and Technically Necessary Data
We do not use marketing or tracking cookies. We only use technically necessary cookies to ensure the functionality of the platform (e.g., login session, language settings).
Legal basis: § 25(2) TDDDG (German Telecommunications-Digital Services Data Protection Act).
Data Processing Agreement (Important for Business Customers)
FireVue acts as a data processor for event participants. Business customers using our platform to collect participant data are "controllers" within the meaning of the GDPR.
We have created a specific Data Processing Agreement (DPA) for this purpose, which can be viewed at /dpa-contract and is an integral part of the contractual relationship.
Artificial Intelligence (AI) Features
We provide AI-assisted features within the administration area of our platform (in particular an in-app assistant) that help organizers manage events, analyze registrations, and edit content. Depending on the task, your requests are processed by different AI providers acting as our processors. We have concluded data processing agreements with these providers and, where personal data is transferred to a third country, rely on the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses.
Processing of participant and other personal data (Mistral AI, EU)
Any AI feature that processes personal data — in particular questions about, and analysis of, event participants and their registrations — is handled exclusively by Mistral AI (Mistral AI SAS, Paris, France), a provider based in the European Union, on EU-hosted infrastructure. Mistral does not use this data to train its models. Inputs and outputs are retained for a maximum of 30 days solely for the purposes of abuse prevention and security, after which they are deleted. We have concluded a data processing agreement with Mistral.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in providing efficient event-management tools).
Other AI features (content and configuration assistance)
For tasks that are not intended to involve personal data — such as creating and editing landing-page content, drafting text and design suggestions, and configuring events — we may use additional AI providers (currently Google and Anthropic) via the Vercel AI Gateway. We have concluded a data processing agreement with Vercel, and these providers are certified under the EU-US Data Privacy Framework and/or bound by EU Standard Contractual Clauses.
Important: These features are not intended for personal data. You must not enter personal data of third parties (for example participant names, contact details, or any information about identifiable individuals) into free-text fields processed by these features, such as landing-page content, event descriptions, or configuration settings. As the controller for the content you enter, you are responsible for ensuring that no such personal data is provided to these features.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing efficient content and configuration tools).
No automated decision-making; no training on your data
Our AI features assist organizers and do not carry out automated decision-making that produces legal effects concerning, or similarly significantly affects, data subjects within the meaning of Art. 22 GDPR. Where the option is available, we have disabled the use of your data for training the providers’ models.
Your Rights
You have the right at any time to:
- Access information about your stored data
- Rectify or delete your data
- Restrict processing
- Data portability
- Object to the processing of your data (Art. 21 GDPR)
- Withdraw any consent you have given, with effect for the future (Art. 7(3) GDPR)
- Lodge a complaint with a supervisory authority
To exercise these rights, please contact: contact@fvevents.com
Data Retention
We store your personal data only as long as necessary to fulfill the purposes described in this privacy policy or as required by law. Event data is retained for the duration of the event and for legal retention periods (typically 10 years for accounting purposes).
Data Security
We use appropriate technical and organizational measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. Our security measures are continuously improved in line with technological developments.