Skip to main content

Privacy Policy

Information pursuant to Art. 13 GDPR on the processing of your personal data.

1. Controller

The controller for the processing of personal data pursuant to Art. 4 No. 7 GDPR is:

Stefan Latossek
Von-Recklinghausen-Str. 9
33332 Gütersloh
Germany

E-mail: webmaster@meetandeat.events

The application is privately created and operated by this individual, not on behalf of any company.

2. Categories of Personal Data Processed

2.1 User Account (Registration & Login)

Data: e-mail address, first and last name, password hash (BCrypt; raw passwords are never stored), e-mail verification and password-reset tokens with expiry timestamps

Purpose: access to organiser functions, authentication, e-mail verification (double opt-in), password reset

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

Retention: until account deletion by the user; tokens deleted after use or expiry

2.2 Master Data – Households and People

Data: names, e-mail addresses, household addresses (street, house number, postal code, city), guest capacity, dietary restrictions, relations (avoid / together)

Purpose: planning and running cooking events

Legal basis: Art. 6(1)(b) GDPR (performance of contract with the organiser); obtaining consent from recorded participants is the organiser's responsibility

Retention: until manual deletion by the organiser or account deletion

2.3 Event Data and Invitations

Data: event title, date, time, course structure, cryptographically random invitation tokens, RSVP status and timestamps, participant messages (up to 500 characters)

Purpose: sending invitations, recording RSVPs, seating planning

Legal basis: Art. 6(1)(b) GDPR

Retention: until manual deletion by the organiser or account deletion

2.4 Dispatch Data (Route Plan Delivery)

Data: cryptographically random dispatch tokens, delivery status, delivery timestamps, token expiry date

Purpose: personalised route plan delivery to participants

Legal basis: Art. 6(1)(b) GDPR

Retention: tokens expire one day after the event; records remain until account deletion

2.5 Contact Form

Data: sender e-mail, subject, message content, timestamps; SHA-256-hashed IP addresses and e-mail addresses for rate-limiting (raw values are not stored)

Purpose: handling enquiries and feedback; abuse prevention (rate-limiting: max. 3 requests per 30 minutes)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communication and abuse protection)

Retention: rate-limiting hashes for 30 minutes; message content at the operator's end until processed

2.6 Server Log Files

Data: IP address, timestamp, requested URL, HTTP status code, browser/OS identifier (user agent)

Purpose: operational security, error analysis, security monitoring

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)

Retention: 30 days (operator's Azure configuration)

2.7 Session Cookie and Browser Storage

Session Cookie: server-generated session identifier stored as an HttpOnly, Secure, SameSite=Strict cookie. No tracking, no cross-site access. Automatically deleted after 30 minutes of inactivity.

Browser Local Storage (cookieConsent): stores locally in the browser only whether the user has acknowledged the cookie notice. No server upload.

Legal basis: Art. 6(1)(f) GDPR (technically necessary for operation and security)

2.8 Login Protection (Rate-Limiting)

Data: SHA-256-hashed IP addresses (with salt); reverse-engineering to raw values is not possible

Purpose: protection against brute-force login attacks

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security)

Retention: 30 minutes

3. External Services and Data Processors

3.1 Microsoft Azure – Hosting and Database

Provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland

Purpose: operating the web application (Azure App Service) and the database (Azure Database for PostgreSQL)

Data transferred: all personal data stored in the application

Hosting region: West Europe (Netherlands, EU/EEA)

Legal basis: Art. 6(1)(b)/(f) GDPR; data processing agreement (DPA) pursuant to Art. 28 GDPR with Microsoft

Privacy: https://privacy.microsoft.com

3.2 Azure Communication Services – E-mail Delivery

Provider: Microsoft Ireland Operations Ltd. (see above)

Purpose: transactional e-mail delivery (registration verification, password reset, system notifications)

Data transferred: recipient e-mail address, sender address, subject, e-mail content

Legal basis: Art. 6(1)(b) GDPR; DPA pursuant to Art. 28 GDPR

Privacy: https://privacy.microsoft.com

3.3 Cloudflare Turnstile – CAPTCHA

Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA

Purpose: CAPTCHA protection on the registration, forgot-password and contact form pages to guard against automated access

Data transferred: CAPTCHA response token, user IP address

Third-country transfer: data is transferred to the USA. Cloudflare, Inc. participates in the EU-US Data Privacy Framework (DPF).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention)

Privacy: https://www.cloudflare.com/privacypolicy/

3.4 OpenRouteService (ORS) – Route Calculation

Provider: HeiGIT gGmbH, Im Neuenheimer Feld 368, 69120 Heidelberg, Germany

Purpose: calculating walking times and driving distances between households

Data transferred: geo-coordinates of household addresses

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing route information)

Privacy: https://openrouteservice.org/privacy-policy/

3.5 Nominatim / OpenStreetMap – Geocoding

Provider: OpenStreetMap Foundation (OSMF), St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom

Purpose: converting household addresses into geo-coordinates (geocoding) for route calculation

Data transferred: household addresses (street, house number, postal code, city)

Legal basis: Art. 6(1)(f) GDPR

Privacy: https://osmfoundation.org/wiki/Privacy_Policy

3.6 Google Maps – Address Links and Map Preview

Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland

Purpose: display of address links and optional map preview

Data is only transferred to Google when a user clicks a link or when a map preview loads. No Google Maps Platform API key is used.

Legal basis: Art. 6(1)(f) GDPR

Privacy: https://policies.google.com/privacy

3.7 Umami – Web Analytics

Provider: Umami Software, Inc. (Umami Cloud), USA

Purpose: anonymised web analytics (page views, clicks) to improve the service

Data collected: visited page, referrer, device category, browser language. No cookies are set, no IP addresses are stored, and no personal data is processed.

Third-country transfer: analytics data is processed on servers in the USA. As no personal data is transferred, no adequacy decision is required.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in anonymised usage statistics). No cookie banner required.

Privacy: https://umami.is/privacy

4. Legal Bases – Summary

Personal data are processed on the following GDPR legal bases: Art. 6(1)(b) (performance of contract) for user accounts, master data, event and dispatch data; Art. 6(1)(f) (legitimate interests) for server logs, session cookies, rate-limiting, CAPTCHA, geocoding, route calculation and address links. The legitimate interest in each case is the secure and functional operation of the platform.

5. Retention Periods

Personal data are retained only as long as necessary for the respective purpose. User account data and master data are retained until deleted by the user or operator. Session cookies and rate-limiting hashes expire automatically (30 minutes). Dispatch tokens become invalid after the event date. Server log files are deleted after 30 days. Verification and reset tokens are automatically removed after use or expiry (48 hours).

6. Recipients and Data Transfers

Data are transferred only to the following recipients to the extent necessary for operation: Microsoft (Azure hosting and e-mail), Cloudflare (CAPTCHA), HeiGIT/ORS (route calculation), OpenStreetMap Foundation (geocoding), Google (when clicking an address link or loading a map preview). A transfer to third countries outside the EU/EEA occurs only in the context of Cloudflare Turnstile (to the USA); Cloudflare participates in the EU-US Data Privacy Framework. No personal data are otherwise shared with third parties, no advertising networks are used, and no tracking pixels are deployed.

7. Your Rights as a Data Subject

You have the following rights under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). Users can manage account data in settings and permanently delete their account. To exercise your rights, please contact:

Stefan Latossek
Von-Recklinghausen-Str. 9
33332 Gütersloh
E-mail: webmaster@meetandeat.events

Supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestrasse 2-4, 40213 Duesseldorf, Germany; poststelle@ldi.nrw.de; www.ldi.nrw.de

8. Data Security

The operator and Microsoft Azure implement appropriate technical and organisational measures: HTTPS/TLS transport encryption, BCrypt password hashing, cryptographically random tokens for invitations and dispatch, HttpOnly+Secure+SameSite session cookies, CSRF protection, and server-side access control (tenant-separated data storage per user account).

9. Changes to this Privacy Policy

This Privacy Policy may be updated when the application functionality, services used, or legal requirements change. Registered users will be notified of material changes.