Privacy & security
Your guests’ data belongs to you — and stays in Europe. The first part of this page explains plainly how ticketYoo protects it; the second part gives IT and data protection officers the hard details.
At ticketYoo, data protection isn’t an add-on — it’s built in.
Storage and processing exclusively in Germany — no default transfer to third countries.
Sensitive data and file uploads — including guest photos — are encrypted with AES-256-GCM; transport via TLS.
Conclude the Art. 28 GDPR data processing agreement directly in ticketYoo — no paperwork.
Two-factor login (TOTP), role-based permissions and strict tenant isolation between teams. New passwords are checked against a local list of known leaked passwords — no external service involved.
Networking requires mutual consent, granular field sharing and per-scan revocation — privacy by design.
Rule-based retention: past guest and contact data is automatically anonymized or deleted.
Failed logins, probes and disruptions are detected and reported daily — with IP addresses only as a daily pseudonym. Revealing one requires a reason and is logged.
Login lockout per account with increasing wait times instead of blanket per-IP blocks, a check against leaked passwords — and large mailings require approval via a second factor.
Responsible disclosure per RFC 9116: security.txt and the address cybersec@codepiraten.com. We respond and fix — reports are welcome.
For IT & data protection officers
So your assessment is quick — open and without marketing fog.
Data-subject access · Art. 15 & 20
On a data subject's request, ticketYoo bundles everything stored about them team-scoped into an encrypted access package: a human-readable PDF, machine-readable daten.json (Art. 20) and related files. With identity verification (Art. 12(6)), secure handover by the team and automatic deletion of the package while keeping the audit record (Art. 5(2)).
The core operation — application, database and files — runs exclusively in Germany. Optional features involve additional services (some outside the EU) — only if you enable them:
The full, current list of processors is part of the DPA.
Anyone who finds a weakness can reach us directly: reporting channel per RFC 9116 in security.txt, contact cybersec@codepiraten.com, German or English. Please report responsibly — do not access third-party data, do not disrupt operations. We confirm receipt, fix and get back to you.
Questions about data processing or privacy are answered by our external data protection officer. We provide a DPA draft, TOM overview and privacy policy on request.
FAQ
Exclusively in a data center in Germany and therefore within the EU.
Yes, online directly in ticketYoo. On request we provide the draft in advance for review.
Not the core platform. Only optional services you enable (e.g. online payment via Stripe) then process their own data — listed transparently in the DPA. In professional-secrecy mode (§ 203 German Criminal Code), US services touching guest data are additionally blocked or tied to a logged consent.
Yes. We sign a service-provider agreement under § 203 StGB / § 43e BRAO and activate professional-secrecy mode: US services blocked, disclosures only with a logged confirmation, 2FA mandatory for all team members. All details on the page for professional secrecy.
Yes. Failed logins, probes and disruptions are detected and reported daily. IP addresses are stored only as a daily pseudonym; the real address is kept encrypted, gone after 7 days and revealed only with a logged reason. Reports contain figures only.
Via team-configurable retention periods: past guest and contact data is automatically anonymized or deleted, with exceptions by consent.
Yes. The sub-processor list and technical-organizational measures are part of the DPA and provided on request.
Patrick · Founder & CTO
Security isn’t an add-on for us. Hosting in Germany, encryption and ISO 27001 are standard — and because ticketYoo is a data processor, your guest data always stays yours. You sign the data processing agreement right online.