Privacy & security

Security & data protection

Your guests’ data belongs to you — and stays in Europe. The first part of this page explains plainly how ticketYoo protects it; the second part gives IT and data protection officers the hard details.

Jump to IT details Privacy policy

Trust that rests on technology

At ticketYoo, data protection isn’t an add-on — it’s built in.

🇩🇪Hosted in Germany
🏅ISO 27001
📋GDPR-compliant
🔒AES-256 & TLS

Data stays in the EU

Storage and processing exclusively in Germany — no default transfer to third countries.

Strong encryption

Sensitive data and file uploads — including guest photos — are encrypted with AES-256-GCM; transport via TLS.

Sign the DPA online

Conclude the Art. 28 GDPR data processing agreement directly in ticketYoo — no paperwork.

2FA & access control

Two-factor login (TOTP), role-based permissions and strict tenant isolation between teams. New passwords are checked against a local list of known leaked passwords — no external service involved.

Mutual consent

Networking requires mutual consent, granular field sharing and per-scan revocation — privacy by design.

Delete & anonymize

Rule-based retention: past guest and contact data is automatically anonymized or deleted.

Attack detection without personal data

Failed logins, probes and disruptions are detected and reported daily — with IP addresses only as a daily pseudonym. Revealing one requires a reason and is logged.

Protection against account takeover & sending abuse

Login lockout per account with increasing wait times instead of blanket per-IP blocks, a check against leaked passwords — and large mailings require approval via a second factor.

Report a vulnerability

Responsible disclosure per RFC 9116: security.txt and the address cybersec@codepiraten.com. We respond and fix — reports are welcome.

For IT & data protection officers

The details you need

So your assessment is quick — open and without marketing fog.

Data-subject access · Art. 15 & 20

Access at the push of a button — with docs for your DPO

On a data subject's request, ticketYoo bundles everything stored about them team-scoped into an encrypted access package: a human-readable PDF, machine-readable daten.json (Art. 20) and related files. With identity verification (Art. 12(6)), secure handover by the team and automatic deletion of the package while keeping the audit record (Art. 5(2)).

Data-subject rights doc (PDF)

1. Hosting & infrastructure

  • Data center in Germany; application and database (PostgreSQL) are operated exclusively in the EU.
  • End-to-end transport encryption via TLS/HTTPS; cookie only technically necessary and with the secure flag.
  • Daily, encrypted backups; recovery process documented.
  • ISO 27001-certified information security management.
  • Round-the-clock availability monitoring: deep health check (database, cache, mail queue, storage) and mutual checks between environments with alerting.

2. Encryption

  • File uploads and sensitive fields (incl. guest photos, signatures) encrypted with AES-256-GCM.
  • Key derivation via PBKDF2; secrets (e.g. SMTP passwords, API keys) stored encrypted, never returned in plain text.
  • Upload hardening: extension whitelist + magic-byte check; executable/HTML files are blocked (protection against stored XSS).
  • Documented and rehearsed key-rotation procedure for the encryption key — with a transition phase in which existing data is re-encrypted.

3. Access & authentication

  • Two-factor authentication (TOTP) for operator accounts.
  • Role-based permissions, event-specific roles (check-in only, guest list or full editing).
  • Strict tenant isolation between teams; cross-tenant access blocked server-side.
  • Optional single sign-on via Microsoft Entra ID (Azure AD).
  • Login protection per account with exponentially increasing lockout — a typo behind a company IP does not lock out colleagues.
  • Approval via a second factor (TOTP or email link) before large mailings; new passwords are checked locally against known password leaks, without an external service.

4. Data-subject rights & minimization

  • Access & data portability (Art. 15/20): a dedicated data-subject access bundles everything about a person team-scoped into an encrypted package (PDF + machine-readable JSON + files); plus structured exports (CSV/Excel).
  • Deletion & anonymization: team-configurable retention periods, automatic cron, exceptions by consent/tag.
  • Consent: documented per consent, with an optional legally valid signature (encrypted) at registration or check-in.
  • Networking/lead scan: mutual consent, granular field sharing, per-scan revocation.

5. Sub-processors (transparent)

The core operation — application, database and files — runs exclusively in Germany. Optional features involve additional services (some outside the EU) — only if you enable them:

  • Hosting/database: provider in Germany (EU).
  • Email delivery: mail-server infrastructure in the EU (DKIM/SPF); own sender per team possible.
  • Online payment (optional): Stripe — only active if you enable online payments; payment data then runs through Stripe.
  • SMS/WhatsApp (optional): via the provider you choose, only when enabled.
  • Push notifications (optional): Apple (APNs, USA) and Google (FCM, USA) — technically required to deliver to iOS/Android devices, only when push is used.

The full, current list of processors is part of the DPA.

6. Technical & organizational measures (TOM)

  • Physical/system/data access: data-center security, 2FA, role-based permissions, tenant separation.
  • Input/transfer: TLS, encrypted storage, logging of security-relevant actions.
  • Availability: daily encrypted backups, rate limiting/quota against abuse, virus scanning for uploads.
  • Resilience: regular penetration tests and targeted hardening of public endpoints.

7. Attack detection without personal data

  • Security-relevant responses — failed logins, denied access, probes for third-party software paths, throttling — are collected and evaluated centrally.
  • IP addresses exist only as a day-bound pseudonym; the mapping to the real address is encrypted, deleted after 7 days and revealed only with a stated reason — every reveal is logged.
  • Daily, weekly and alert reports to the platform owners; the reports contain only figures and findings, no addresses.
  • Retention: events 30 days, reports 365 days. Deliberately no automatic IP blocking — behind trade-fair Wi-Fi and company networks, hundreds of real guests share one address.
  • Description for security officers (German and English) with a runbook per finding — on request, like the TOM annex.

8. Report a vulnerability (responsible disclosure)

Anyone who finds a weakness can reach us directly: reporting channel per RFC 9116 in security.txt, contact cybersec@codepiraten.com, German or English. Please report responsibly — do not access third-party data, do not disrupt operations. We confirm receipt, fix and get back to you.

cybersec@codepiraten.com security.txt

Contact for privacy questions

Questions about data processing or privacy are answered by our external data protection officer. We provide a DPA draft, TOM overview and privacy policy on request.

info@dsb-r.de Sample DPA (PDF) Data-subject rights (PDF) Privacy policy Contact

FAQ

Common privacy questions

Where is the data stored?

Exclusively in a data center in Germany and therefore within the EU.

Do you sign an Art. 28 GDPR DPA?

Yes, online directly in ticketYoo. On request we provide the draft in advance for review.

Is data transferred to the US?

Not the core platform. Only optional services you enable (e.g. online payment via Stripe) then process their own data — listed transparently in the DPA. In professional-secrecy mode (§ 203 German Criminal Code), US services touching guest data are additionally blocked or tied to a logged consent.

Can professionals bound to secrecy (lawyers, doctors, tax advisors, notaries) use ticketYoo?

Yes. We sign a service-provider agreement under § 203 StGB / § 43e BRAO and activate professional-secrecy mode: US services blocked, disclosures only with a logged confirmation, 2FA mandatory for all team members. All details on the page for professional secrecy.

Do you monitor attacks — and what happens to IP addresses?

Yes. Failed logins, probes and disruptions are detected and reported daily. IP addresses are stored only as a daily pseudonym; the real address is kept encrypted, gone after 7 days and revealed only with a logged reason. Reports contain figures only.

How is old guest data deleted?

Via team-configurable retention periods: past guest and contact data is automatically anonymized or deleted, with exceptions by consent.

Can I get a list of sub-processors and TOM?

Yes. The sub-processor list and technical-organizational measures are part of the DPA and provided on request.

Patrick

Patrick · Founder & CTO

Security isn’t an add-on for us. Hosting in Germany, encryption and ISO 27001 are standard — and because ticketYoo is a data processor, your guest data always stays yours. You sign the data processing agreement right online.

Data protection you can trust