Privacy Policy
At Espace Event, we take the protection of your personal data very seriously. Find out how we collect, use and protect it.
1. Data Controller
We commit to responding to any personal data request within a maximum of 30 calendar days.
2. Data Collected
When using the Platform, we collect the following categories of data:
| Category | Data collected | Main purpose |
|---|---|---|
| Identity | First name, last name, email address, phone number | Account creation & management |
| Profile | Account type, profile photo, professional information | Service personalisation |
| Events | Dates, types, locations, guest lists | Event management service |
| Financial | Subscriptions, quotes, invoices (no card data stored) | Billing & accounting |
| Navigation | IP address, browser, pages visited, timestamps | Security & service improvement |
3. Purposes of Processing
Your data is collected and processed for the following purposes:
- Account creation and management.
- Provision of Platform features (event management, messaging, quotes, invoicing).
- Processing of subscription payments.
- Sending notifications and communications relating to your account and events.
- Fraud prevention and security improvement.
- Continuous improvement of the Platform (anonymised statistical analysis).
- Compliance with legal obligations.
4. Legal Basis
Processing of your data rests on the following legal grounds:
- Contract performance: to provide the service you have subscribed to.
- Consent: for marketing communications (if applicable).
- Legitimate interest: to improve our services and ensure Platform security.
- Legal obligation: to comply with regulatory requirements.
5. Data Retention
Your data is kept only as long as necessary for the purposes for which it was collected:
| Data type | Retention period | Legal basis |
|---|---|---|
| Active account data | Duration of account + 3 years after closure | Contract performance |
| Quotes & invoices | 10 years | Legal obligation (accounting) |
| Access & security logs | 12 months maximum | Legitimate interest (security) |
| Session cookies | Session duration (deleted on browser close) | Service operation |
6. Data Sharing
Espace Event does not sell your personal data. It may be shared only in the following cases:
- With other users in the normal course of the service (e.g. a provider receives an organizer's contact details after a quote is accepted).
- With our technical sub-processors acting as data processors, bound by GDPR-compliant data processing agreements:
| Sub-processor | Role | Country | Safeguard |
|---|---|---|---|
| o2switch SARL | Web hosting & file storage | France 🇫🇷 | EU GDPR compliant |
| Stripe Inc. | Payment processing | USA 🇺🇸 | Standard Contractual Clauses (SCC) |
| SMTP email provider | Transactional email delivery | EU 🇪🇺 | EU GDPR compliant |
- With competent authorities when duly justified by law.
7. Cookies
The Platform uses only cookies strictly necessary for its operation. No third-party advertising cookies are placed without your prior consent.
| Cookie | Purpose | Duration | Can be disabled |
|---|---|---|---|
PHPSESSID |
Authentication session (keeps you logged in) | Session (browser close) | No |
csrf_token |
CSRF protection on forms | Session | No |
lang |
Language display preference | 30 days | Yes |
cookie_notice_dismissed |
Records that the cookie notice was dismissed (localStorage — not a server cookie) | Permanent (until browser data cleared) | Yes |
8. Your Rights
In accordance with applicable data protection regulations, you have the following rights:
To exercise these rights, contact us via the Contact page (type: "Legal / GDPR Request"). We will respond within a maximum of 30 days.
9. Security
Espace Event implements appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss or disclosure:
- All communications are transmitted over an encrypted HTTPS / TLS connection.
- Passwords are stored in hashed form using bcrypt (no plain-text passwords are kept).
- Each form is protected by a unique single-use CSRF token.
- Login attempts are rate-limited to prevent brute-force attacks.
- All access to sensitive data is logged with timestamps.
Despite these measures, no system is infallible. In the event of a data breach likely to pose a risk to your rights, we will notify you within the timeframes required by applicable regulations.
10. International Transfers
Your data is hosted primarily on servers located in France (o2switch SARL, Clermont-Ferrand). If a transfer to a country outside the European Economic Area (EEA) were to become necessary, Espace Event would ensure that such transfer is governed by appropriate safeguards (standard contractual clauses, European Commission adequacy decision, or other recognised mechanism).
11. Changes to this Policy
This privacy policy may be updated at any time. In the event of a material change, you will be notified by email or by a notice displayed upon your next login.
We encourage you to review this page regularly to stay informed of any updates.
12. Contact & Complaints
For any query relating to this policy or to exercise your rights, contact us via the Contact page (request type: "Legal / GDPR Request").
If you believe, after contacting us, that your rights have not been respected, you may lodge a complaint with the supervisory authority in your country of residence. In France: CNIL — Commission Nationale de l'Informatique et des Libertés · 3 Place de Fontenoy, 75007 Paris.