Trust Center

GDPR-compliant event softwareHosted in Germany, with a data processing agreement.

Invitations, registrations, guest lists: event management is processing personal data. AirLST is built for it, hosted on AWS in Germany, with a data processing agreement as the contractual basis.

01Roles

Who is the controller, and who processes on its behalf

As soon as you invite guests, you process personal data. The GDPR assigns the roles clearly.

01

You are the controller

The organizer decides on purpose and means: whom to invite, which data to collect, how long to keep it.

Source: GDPR Article 4(7)
02

AirLST processes on your behalf

AirLST processes attendee data on your instructions, governed by a data processing agreement with confidentiality and technical and organizational measures.

Source: GDPR Article 28
03

Data in Germany

The platform runs on Amazon Web Services in Germany; processing stays within the scope of the GDPR. More on data hosting.

Source: AWS compliance programs

For US companies: the GDPR can apply when you invite attendees from the EU (Article 3). Whether it applies to your event is a question for your privacy or legal team.

02Attendee rights

Your attendees' rights under the GDPR

You handle these rights as the controller; a guest list with one record per guest makes that simple.

  • AccessWhich data is stored about a person (Article 15).
  • RectificationCorrect inaccurate data (Article 16).
  • ErasureDelete data when the purpose ends (Article 17).
  • RestrictionLimit processing temporarily (Article 18).
  • PortabilityHand out data in a common format (Article 20).
  • ObjectionObject to processing (Article 21).

In the guest list, every guest is one record with a change log; marketing and event opt-ins are documented per guest.

03Contract

What you get for privacy approval

During contracting, your privacy team receives the usual documents.

  1. 01

    Data processing agreement

    Under GDPR Article 28: subject matter, duration, instructions, confidentiality, assistance.

  2. 02

    Technical and organizational measures

    The safeguards, as an annex to the DPA.

  3. 03

    Subprocessor list

    Who touches data in the processing chain, always current. More on the subprocessors page.

05FAQ

GDPR FAQ

Does the GDPR apply to US companies that host events?

It can. The GDPR applies to organizations outside the EU when they offer goods or services to people in the EU or monitor their behavior there (Article 3). A US company that invites attendees from Europe to a conference, a product launch or a customer event will often process their personal data within that scope. Whether it applies to your event is a question for your privacy or legal team; running the event on GDPR-compliant software hosted in Germany makes the answer easier either way.

What does GDPR compliance mean for event registration?

Every registration form collects personal data: names, email addresses, company, and often travel, hotel or dietary details. GDPR compliance means you process that data for a defined purpose, on a valid legal basis, with appropriate security, and that attendees can exercise their rights. Your event software carries a large share of that load, because it is where the data is collected, stored and eventually deleted.

Does AirLST sign a data processing agreement (DPA)?

A data processing agreement under Article 28 GDPR is the standard contract whenever a vendor processes personal data on your behalf, which is the case for attendee management. It is provided as part of the contracting process, together with the technical and organizational measures and the subprocessor list.

Is attendee data transferred outside the EU?

Attendee data is hosted on Amazon Web Services in Germany, within the scope of the GDPR. Whether individual subprocessors process data outside the EU is stated in the list that comes with the DPA. The subprocessors page explains how to get the current list of service providers.

How can attendees exercise their GDPR rights?

Attendees can ask the event organizer for access to, correction or deletion of their data, among other rights. The organizer is the controller and answers these requests; AirLST, as the processor, supports the organizer. Because every guest is one record with a change log, access, correction and deletion are handled at the record.

Who is the privacy contact at AirLST?

Send privacy questions to kontakt@airlst.com or use the contact form. The privacy policy of this website is available on the privacy policy page.
Events made easy

Privacy approval for your next event

In 15 minutes we answer your privacy team's questions and show how opt-ins, change log and roles work together in AirLST.