avond.

Privacy policy

Esta es una traducción de cortesía — la versión alemana es la jurídicamente vinculante.

1. Controller

Dialogine GmbH, c/o Gateway Workspace, Weyertal 109, 50931 Köln, Germany
Privacy contact: privacy@avond.de

2. Principles

avond is a ticketing platform built on data minimisation: all platform data is stored in the EU (Cloudflare with EU data residency), there are no advertising trackers (no Google Ads, no Meta pixel), and tickets can be bought without an account. Optional analytics only ever starts after your consent.

3. Processing in detail

3.1 Visiting the site

When you open our pages, our host Cloudflare (Cloudflare Workers, EU data residency) processes technically necessary data such as IP address, user agent and timestamp in short-lived server logs. Legal basis: Art. 6 (1)(f) GDPR (secure, stable operation).

3.2 Organizer account

Sign-in is passwordless via magic link: we store your email address, name and a session (essential cookie). Cloudflare Turnstile protects the login against bots (Art. 6 (1)(f) GDPR). Legal basis otherwise: Art. 6 (1)(b) GDPR.

3.3 Ticket purchase & delivery

When you buy tickets we process the buyer name, email address and order data (Cloudflare D1, EU) as well as the generated ticket PDFs (Cloudflare R2, EU). Tickets are emailed via our processor (Resend or Cloudflare Email Service). Legal basis: Art. 6 (1)(b) GDPR; statutory retention of order and invoice data (§ 147 AO): Art. 6 (1)(c) GDPR.

3.4 Payments (Stripe)

Paid tickets are processed as direct charges through the organizer's own Stripe account (Stripe Connect Standard). Your payment data goes to Stripe and to the organizer (each their own controller); avond never receives your card details — only transaction metadata and the platform fee. Stripe may transfer data to the USA (Standard Contractual Clauses, EU-US Data Privacy Framework). Legal basis: Art. 6 (1)(b) GDPR.

3.5 Entry / check-in

At the door, your ticket's QR code is scanned and the check-in time stored so a ticket can only be used once. Legal basis: Art. 6 (1)(b) and (f) GDPR.

4. Consent-based analytics: PostHog (EU)

Only if you accept in the cookie banner do we load PostHog (PostHog EU cloud, hosted in the EU) and capture page views, clicks (autocapture) and session recordings in which input fields (e.g. name and email at checkout) are masked. For logged-in organizers we link usage to account ID and email; ticket buyers stay anonymous. Legal basis: Art. 6 (1)(a) GDPR, § 25 (1) TDDDG.

You can withdraw your consent at any time with effect for the future via . On withdrawal, the PostHog cookies are deleted.

5. Cookies

CookiePurposeDurationLegal basis
better-auth.*Organizer login session (essential)session§ 25 (2) TDDDG
avond-consentStores your cookie decision (essential)6 months§ 25 (2) TDDDG
NEXT_LOCALERemembers your language choice (essential)12 months§ 25 (2) TDDDG
ph_*PostHog analytics & session recordinguntil withdrawnArt. 6 (1)(a) GDPR

6. Recipients and processors

Cloudflare (hosting, D1 database, R2 storage, Turnstile — EU data residency, data processing agreement per Art. 28 GDPR), Stripe (payments), Resend or Cloudflare Email Service (transactional email), PostHog (analytics, EU cloud). Where US parent companies are involved, transfers rely on Standard Contractual Clauses and the EU-US Data Privacy Framework.

7. Retention

Account data until you delete your account; order and invoice data for the statutory retention periods; analytics data per the PostHog retention settings. Server logs are short-lived.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and to withdraw consent (Art. 7 (3) GDPR) — contact privacy@avond.de. Complaints: your supervisory authority; for us, the Data Protection Commissioner of North Rhine-Westphalia (Art. 77 GDPR).

9. Roles: avond and organizers

The organizer is (jointly) responsible for running their event (guest list, entry, their own communication); avond operates the platform. You can find the organizer's imprint on their page.

10. Security

All connections are TLS-encrypted, tickets are HMAC-signed (forgery-proof), and all platform data lives in the EU.

11. Changes

We update this policy as the platform evolves. Last updated: July 2026.