For data protection, procurement and tendering

Data protection and hosting

Where your data lives, which providers are involved, and what we can give you for a tender or an assessment.

This page answers the questions we receive from data protection teams and tendering bodies — briefly and without marketing.

Where the data lives

The application, database, authentication, file storage and the TLS edge all run in Frankfurt am Main (EU).

A content delivery network caches static files only — images, scripts, stylesheets — at locations outside the EU as well, so that pages load consistently worldwide. Database requests always travel physically to Frankfurt; database content is never held in that cache.

Email delivery runs through Google Workspace with the data region set to Europe. One point worth knowing if you connect your own mailbox to your event: that mailbox stays in your own Google Workspace. You set its data region; we access it over OAuth and do not relocate the data.

The AI assistant processes in AWS Bedrock in eu-central-1 (Frankfurt), using Claude as the model. Only the text a user gives the assistant is transmitted — not your data set.

What data is processed

Personal data belonging to organisers, speakers and guests — names, email addresses, phone numbers where provided — authentication data, and the content you create in the product: programmes, submissions, organisation profiles. Data is handled differently according to how sensitive it is; real personal data appears neither in test environments nor in documentation.

Usage analytics

The logged-in application collects its own, cookie-free usage analytics — which pages and features are used — to improve the product. There are no third-party analytics services and no cookies involved. Raw data is deleted automatically after 90 days, or immediately if the account is deleted.

Access, export and erasure

Data subject rights can be exercised directly in the product:

  • Access and portability: a self-service export produces a JSON file containing the requester’s own account data. The subject of the export is always the logged-in session itself — never a value a client could supply.
  • Erasure: a self-service flow removes the account, the associated personal data and the file storage, gated by an email confirmation.

So that no event is left without anyone responsible, erasure is blocked while someone is the sole administrator of an event. We never silently transfer an event to someone who has not agreed to take it on, and we never delete one other people are still working on without asking first.

Requests the self-service route cannot serve — for example from people who can no longer log in — we handle manually, following a documented internal procedure.

Accessibility

WCAG 2.1 AA is a shipping requirement for us, not an aspiration: an automated check runs on every change and turns red as soon as a new violation appears. We are deliberately precise about this — we do not claim unqualified certified WCAG 2.1 AA conformance, but we can show what is checked and how.

What you get for an assessment

On request we provide:

  • the full list of our service providers, with purpose, data categories and region,
  • our data processing agreement for the use of iveo in your organisation,
  • answers on individual points your assessment requires.

Write to us at hello@my-iveo.de — ideally quoting the reference of your tender or assessment.

Last updated: 9 September 2026

Still have questions?

Get in touch — we are happy to help.