Privacy Policy
Information pursuant to Art. 13 GDPR on the processing of your personal data.
1. Controller
The controller for the processing of personal data pursuant to Art. 4 No. 7 GDPR is:
Stefan LatossekVon-Recklinghausen-Str. 9
33332 Gütersloh
Germany
E-mail: webmaster@meetandeat.events
The application is privately created and operated by this individual, not on behalf of any company.
2. Categories of Personal Data Processed
2.1 User Account (Registration & Login)
Data: e-mail address, first and last name, password hash (BCrypt; raw passwords are never stored), e-mail verification and password-reset tokens with expiry timestamps
Purpose: access to organiser functions, authentication, e-mail verification (double opt-in), password reset
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
Retention: until account deletion by the user; tokens deleted after use or expiry
2.2 Master Data – Households and People
Data: names, e-mail addresses, household addresses (street, house number, postal code, city), guest capacity, dietary restrictions, relations (avoid / together)
Purpose: planning and running cooking events
Legal basis: Art. 6(1)(b) GDPR (performance of contract with the organiser); obtaining consent from recorded participants is the organiser's responsibility
Retention: until manual deletion by the organiser or account deletion
2.3 Event Data and Invitations
Data: event title, date, time, course structure, cryptographically random invitation tokens, RSVP status and timestamps, participant messages (up to 500 characters)
Purpose: sending invitations, recording RSVPs, seating planning
Legal basis: Art. 6(1)(b) GDPR
Retention: until manual deletion by the organiser or account deletion
2.4 Dispatch Data (Route Plan Delivery)
Data: cryptographically random dispatch tokens, delivery status, delivery timestamps, token expiry date
Purpose: personalised route plan delivery to participants
Legal basis: Art. 6(1)(b) GDPR
Retention: tokens expire one day after the event; records remain until account deletion
2.5 Contact Form
Data: sender e-mail, subject, message content, timestamps; SHA-256-hashed IP addresses and e-mail addresses for rate-limiting (raw values are not stored)
Purpose: handling enquiries and feedback; abuse prevention (rate-limiting: max. 3 requests per 30 minutes)
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in communication and abuse protection)
Retention: rate-limiting hashes for 30 minutes; message content at the operator's end until processed
2.6 Server Log Files
Data: IP address, timestamp, requested URL, HTTP status code, browser/OS identifier (user agent)
Purpose: operational security, error analysis, security monitoring
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation)
Retention: 30 days (operator's Azure configuration)
2.7 Session Cookie and Browser Storage
Session Cookie: server-generated session identifier stored as an HttpOnly, Secure, SameSite=Strict cookie. No tracking, no cross-site access. Automatically deleted after 30 minutes of inactivity.
Browser Local Storage (cookieConsent): stores locally in the browser only whether the user has acknowledged the cookie notice. No server upload.
Legal basis: Art. 6(1)(f) GDPR (technically necessary for operation and security)
2.8 Login Protection (Rate-Limiting)
Data: SHA-256-hashed IP addresses (with salt); reverse-engineering to raw values is not possible
Purpose: protection against brute-force login attacks
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security)
Retention: 30 minutes
3. External Services and Data Processors
3.1 Microsoft Azure – Hosting and Database
Provider: Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Purpose: operating the web application (Azure App Service) and the database (Azure Database for PostgreSQL)
Data transferred: all personal data stored in the application
Hosting region: West Europe (Netherlands, EU/EEA)
Legal basis: Art. 6(1)(b)/(f) GDPR; data processing agreement (DPA) pursuant to Art. 28 GDPR with Microsoft
Privacy: https://privacy.microsoft.com
3.2 Azure Communication Services – E-mail Delivery
Provider: Microsoft Ireland Operations Ltd. (see above)
Purpose: transactional e-mail delivery (registration verification, password reset, system notifications)
Data transferred: recipient e-mail address, sender address, subject, e-mail content
Legal basis: Art. 6(1)(b) GDPR; DPA pursuant to Art. 28 GDPR
Privacy: https://privacy.microsoft.com
3.3 Cloudflare Turnstile – CAPTCHA
Provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA
Purpose: CAPTCHA protection on the registration, forgot-password and contact form pages to guard against automated access
Data transferred: CAPTCHA response token, user IP address
Third-country transfer: data is transferred to the USA. Cloudflare, Inc. participates in the EU-US Data Privacy Framework (DPF).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention)
Privacy: https://www.cloudflare.com/privacypolicy/
3.4 OpenRouteService (ORS) – Route Calculation
Provider: HeiGIT gGmbH, Im Neuenheimer Feld 368, 69120 Heidelberg, Germany
Purpose: calculating walking times and driving distances between households
Data transferred: geo-coordinates of household addresses
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing route information)
Privacy: https://openrouteservice.org/privacy-policy/
3.5 Nominatim / OpenStreetMap – Geocoding
Provider: OpenStreetMap Foundation (OSMF), St John's Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom
Purpose: converting household addresses into geo-coordinates (geocoding) for route calculation
Data transferred: household addresses (street, house number, postal code, city)
Legal basis: Art. 6(1)(f) GDPR
Privacy: https://osmfoundation.org/wiki/Privacy_Policy
3.6 Google Maps – Address Links and Map Preview
Provider: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: display of address links and optional map preview
Data is only transferred to Google when a user clicks a link or when a map preview loads. No Google Maps Platform API key is used.
Legal basis: Art. 6(1)(f) GDPR
Privacy: https://policies.google.com/privacy
3.7 Umami – Web Analytics
Provider: Umami Software, Inc. (Umami Cloud), USA
Purpose: anonymised web analytics (page views, clicks) to improve the service
Data collected: visited page, referrer, device category, browser language. No cookies are set, no IP addresses are stored, and no personal data is processed.
Third-country transfer: analytics data is processed on servers in the USA. As no personal data is transferred, no adequacy decision is required.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in anonymised usage statistics). No cookie banner required.
Privacy: https://umami.is/privacy
4. Legal Bases – Summary
Personal data are processed on the following GDPR legal bases: Art. 6(1)(b) (performance of contract) for user accounts, master data, event and dispatch data; Art. 6(1)(f) (legitimate interests) for server logs, session cookies, rate-limiting, CAPTCHA, geocoding, route calculation and address links. The legitimate interest in each case is the secure and functional operation of the platform.
5. Retention Periods
Personal data are retained only as long as necessary for the respective purpose. User account data and master data are retained until deleted by the user or operator. Session cookies and rate-limiting hashes expire automatically (30 minutes). Dispatch tokens become invalid after the event date. Server log files are deleted after 30 days. Verification and reset tokens are automatically removed after use or expiry (48 hours).
6. Recipients and Data Transfers
Data are transferred only to the following recipients to the extent necessary for operation: Microsoft (Azure hosting and e-mail), Cloudflare (CAPTCHA), HeiGIT/ORS (route calculation), OpenStreetMap Foundation (geocoding), Google (when clicking an address link or loading a map preview). A transfer to third countries outside the EU/EEA occurs only in the context of Cloudflare Turnstile (to the USA); Cloudflare participates in the EU-US Data Privacy Framework. No personal data are otherwise shared with third parties, no advertising networks are used, and no tracking pixels are deployed.
7. Your Rights as a Data Subject
You have the following rights under the GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). Users can manage account data in settings and permanently delete their account. To exercise your rights, please contact:
Stefan LatossekVon-Recklinghausen-Str. 9
33332 Gütersloh
E-mail: webmaster@meetandeat.events
Supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestrasse 2-4, 40213 Duesseldorf, Germany; poststelle@ldi.nrw.de; www.ldi.nrw.de
8. Data Security
The operator and Microsoft Azure implement appropriate technical and organisational measures: HTTPS/TLS transport encryption, BCrypt password hashing, cryptographically random tokens for invitations and dispatch, HttpOnly+Secure+SameSite session cookies, CSRF protection, and server-side access control (tenant-separated data storage per user account).
9. Changes to this Privacy Policy
This Privacy Policy may be updated when the application functionality, services used, or legal requirements change. Registered users will be notified of material changes.