Privacy policy
Some details are pending final confirmation by the operator.
Controller
Leisure GmbH, Börsenplatz 1/1/7, 1010 Wien, Austria. Contact: [email protected].
What we process and why
Account: first name, last name, email address and date of birth (18+ eligibility, self-declared). Legal basis: performance of the contract (guest list access) and our legitimate interest in age-restricted events.
Authentication: we use passwordless sign-in links sent to your email. We store hashed one-time tokens and session identifiers, your IP address and browser type for security purposes.
Guest Pass: a random, revocable identifier linked to your account is encoded in your QR code. The QR contains no personal data.
Event access: your access requests, their status history, staff decisions and check-in records (time, event, staff member, method) for entrance operations and dispute resolution.
Newsletter: only with your separate, optional consent (double opt-in). We record consent state, timestamp, consent text version and unsubscribe events. You can unsubscribe at any time via the link in every newsletter.
Transactional emails (verification, sign-in links, access status, event changes) are necessary to provide the service and are sent regardless of newsletter preference.
Recipients and processors
Hetzner Online GmbH, Germany (hosting, EU data centre). Cloudflare, Inc. (DNS, TLS, DDoS protection, content delivery; EU/US with standard contractual clauses). Google Ireland Ltd. (Google Workspace — transactional email delivery). A2 Digital Works (technical operation on behalf of the controller).
Entrance staff of the respective event see your name and access status when scanning your Guest Pass. Door staff do not see your date of birth or your event history for other events.
Cookies and storage
We use only technically necessary cookies: a session cookie for your account, a language preference and a theme preference. No marketing tracking is used. For reach statistics we use Cloudflare Web Analytics, which works without cookies, without fingerprinting and without cross-site tracking; it is delivered by Cloudflare as part of hosting.
Retention
Unverified accounts are deleted after 14 days. Expired sign-in tokens are removed within 7 days. Check-in and registration records are retained for the operational history of the event. You may request deletion of your account; where records must be retained for legal reasons, we minimise or anonymise them.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection, and to lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at). Contact: [email protected].