Privacy Policy

Our privacy policy and how we use your data

Last updated: 9 July 2026

Thank you for your interest in Univents. Protecting your personal data matters to us. Below we inform you, in accordance with Art. 13 and 14 of the General Data Protection Regulation (GDPR), which personal data we process when you use our website univents.app and the application accessible through it, for which purposes and on which legal basis.

1. Controller

The controller responsible for the data processing within the meaning of the GDPR is:

Univents GmbH

Schillerstraße 10, 74395 Mundelsheim, Germany. Represented by the managing directors Andreas Köckeis and Markus Link. Commercial register: Amtsgericht Stuttgart, HRB 782148. VAT ID: DE 348 933 744.

For questions about data protection and to exercise your rights, you can reach us at the address above or by email at hello@univents.app.

This privacy policy covers the processing for which we ourselves are responsible. Where we process personal data on behalf of our customers (public booking pages and customer portals), Section 12 additionally applies.

2. Overview of the processing

We process personal data in particular for the following purposes:

  • Provision of our website and the application (hosting, delivery, security)
  • Analysis and reach measurement to improve our website and product
  • Advertising and measurement of advertising success on our marketing pages
  • Registration, management and operation of user accounts and workspaces
  • Payment processing and billing of paid services
  • Communication with prospects and customers (support chat, email, appointment booking)
  • AI-powered features within the application
  • Operation of public booking pages and customer portals on behalf of our customers

Categories of data subjects are website visitors, prospects, registered users and their team members, contact persons of our customers and suppliers as well as – within the scope of commissioned processing – end customers and guests of our customers.

3. Legal bases

We process personal data on the following legal bases of the GDPR:

  • Consent (Art. 6(1)(a) GDPR) – in particular for non-essential cookies, recurring-visitor analytics and marketing services. You may withdraw a consent you have given at any time with effect for the future.
  • Performance of a contract (Art. 6(1)(b) GDPR) – to provide the user account and the contractually agreed services.
  • Legal obligation (Art. 6(1)(c) GDPR) – in particular commercial and tax-law retention obligations.
  • Legitimate interest (Art. 6(1)(f) GDPR) – e.g. for security, data-minimising cookieless reach measurement and the improvement of our product.

We log the choice you make in the cookie banner on our server as evidence of consent (Art. 7(1) GDPR). You can adjust or withdraw your consent at any time via the “Cookie settings” link in the footer.

4. Hosting & infrastructure

Our application and website run on a cloud infrastructure within the EU. Database, authentication and file storage are provided by Supabase (EU region Frankfurt); the application is hosted and delivered via Vercel (EU region). An upstream content delivery network and protection against attacks (DDoS, web application firewall) are provided by Cloudflare.

Data is currently still being synchronised from our legacy system (Bubble) into the new application; Bubble is engaged as a processor until this migration is complete.

The legal basis is our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR) as well as the performance of a contract (Art. 6(1)(b) GDPR). Data processing agreements are in place with all infrastructure providers.

5. Visiting the website: server logs and cookies

Server log files

When you access our website, information is automatically transmitted to our servers and temporarily stored in log files: IP address, date and time of access, the page or file requested, the amount of data transferred, the referrer URL as well as browser and operating-system information. This is technically necessary to deliver the website and to ensure its stability and security. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Cookies and similar technologies

We use cookies and comparable technologies (e.g. localStorage). Essential cookies are required to operate the website and the application and are set without consent (§ 25(2) TTDSG, Art. 6(1)(f) GDPR). We set all non-essential cookies only with your consent via our cookie banner (§ 25(1) TTDSG, Art. 6(1)(a) GDPR). Our banner distinguishes three categories: Essential, Statistics and Marketing.

Details of the specific cookies we use, their storage periods and their providers can be found in our Cookie Policy. There, and via the “Cookie settings” link in the footer, you can adjust or withdraw your consent at any time.

6. Analytics & reach measurement

Reach and usage measurement (PostHog)

We use PostHog (EU hosting) for the statistical analysis of how our website is used. Before you give consent, no cookies are set and nothing is stored in your browser (localStorage). Insofar as reach measurement already takes place before consent, it does so exclusively in a cookieless mode without any persistent identifier and only in memory for the current session (e.g. pages viewed, approximate origin, browser/device, IP address). The legal basis is our legitimate interest in privacy-friendly reach measurement (Art. 6(1)(f) GDPR).

If you consent to analytics via our cookie banner, we additionally store cookies / localStorage entries to enable recurring-visitor analysis (lifetime up to 12 months). The legal basis is then your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.

You may object to the cookieless reach measurement at any time (Art. 21 GDPR) by choosing “Decline” in the cookie banner. We then stop collection immediately. Data is processed within the EU.

Session recordings in the logged-in area (PostHog Session Replay)

Within the logged-in area of the application we use PostHog Session Replay (EU hosting) to visually review individual usage sessions. Recording is limited to sessions during the setup onboarding and to sessions of accounts that have not yet sent their first quote or first invoice – the ongoing usage of active existing customers is not recorded. Captured are interactions such as mouse movements, clicks, scrolling and the rendered page content; input into form fields is masked by default and is not readable in the recording. On public booking pages, recording only takes place with consent.

The purpose of the recording is to improve the product’s onboarding: we analyse where new users run into obstacles while setting up and creating their first quote or invoice. The legal basis is our legitimate interest in analysing and improving our product (Art. 6(1)(f) GDPR). Recordings are processed within the EU and are automatically deleted after 30 days.

You may object to the recording at any time with effect for the future (Art. 21 GDPR) by contacting us via the contact address stated in the legal notice. Upon request, we delete recordings that have already been created ahead of schedule.

7. Advertising & conversion measurement

On our public marketing pages we use Google Consent Mode v2. Even before you give consent, the Google tag library is loaded with the default set to “denied”. In this state no cookies are set and no directly identifying data is sent to Google; only cookieless, aggregated signals (so-called consent pings without persistent identification) are transmitted to Google so that it can statistically model the effectiveness of our advertising. The legal basis is our legitimate interest in data-minimising advertising measurement (Art. 6(1)(f) GDPR).

If you consent to marketing via our cookie banner, we additionally enable Google Ads’ cookie-based conversion tracking as well as the Meta Pixel and the LinkedIn Insight Tag; these are only loaded after your consent. We also measure conversions server-side (Meta Conversions API, Google Ads) – likewise only after your marketing consent. The legal basis is then your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.

To attribute marketing campaigns, following your marketing consent we also set a first-party cookie (“attribution_id”, lifetime 12 months). It is never set on our customers’ public booking pages.

You may object to the cookieless advertising measurement at any time (Art. 21 GDPR) by choosing “Decline” in the cookie banner; we then stop transmitting to Google immediately. Meta and LinkedIn are not loaded at all without your consent. We use these marketing services solely on our public marketing pages – never in the logged-in application, on public booking pages or in customer portals.

Recipients are Google Ireland Ltd. / Google LLC, Meta Platforms Ireland Ltd. and LinkedIn Ireland U.C. This may involve a transfer to the USA, safeguarded by appropriate measures (EU Standard Contractual Clauses or the EU-US Data Privacy Framework adequacy decision).

Audience matching (Custom Audiences / Customer Match): Where a legal basis exists, we transmit a cryptographically hashed (SHA-256) version of the email address you provided at registration to Meta Platforms Ireland Ltd. and Google Ireland Ltd. in order to place you into defined advertising audiences there, to exclude you from certain ads, or to build statistically similar audiences. The plaintext of your email address is not transmitted; matching occurs solely via the hash value, which is deleted after matching where there is no match. Email addresses we obtain via a connected Google account (Gmail) are never used for this purpose. The legal basis is our legitimate interest in efficient direct marketing to our existing customers (Art. 6(1)(f) GDPR).

You may object to this audience matching at any time with effect for the future (Art. 21 GDPR) via the contact address stated in the legal notice; we then remove your address from the relevant audiences.

8. Registration & customer account

A user account is required to use the application. During registration we process the data you provide, in particular name, email address, password (stored only in encrypted form) as well as information about your company or workspace (e.g. company name, address, VAT ID). Authentication is handled via Supabase (EU).

Alternatively, you can sign in via single sign-on with a Google or Microsoft account. In that case we receive the profile data required to create the account (in particular name and email address) from the chosen provider.

Within a team workspace we additionally process the content that you and your team members enter (e.g. contacts, events, quotes, invoices). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) as well as our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

9. Payment processing

For paid subscriptions we use the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland). During a payment, Stripe processes your payment and invoicing data; full payment-instrument data (e.g. card number) is processed exclusively by Stripe and is not transmitted to us in plain text. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) as well as compliance with tax and commercial-law obligations (Art. 6(1)(c) GDPR). Where data is transferred to Stripe, Inc. (USA), EU Standard Contractual Clauses apply.

10. Communication

Support chat (Intercom)

We offer a support chat via Intercom. On our website the chat is loaded only after you have consented to statistics cookies. In the logged-in application there is no cookie banner; there, the Intercom messenger only starts once you actively open it. In this respect the legal basis is the performance of a contract or our legitimate interest in providing support (Art. 6(1)(b) and (f) GDPR). We process your messages as well as contact and usage data in order to answer your enquiries.

Email communication and transactional email (Resend)

We send transactional system emails (e.g. notifications, invitations, password resets) via Resend. If you contact us by email, we process the data you provide to handle your enquiry. The legal basis is the performance of a contract or our legitimate interest in communication (Art. 6(1)(b) and (f) GDPR).

Demo appointment booking and CRM (HubSpot)

On our demo page (/demo) we embed a HubSpot appointment-booking calendar, which is loaded when the page is opened. If you book an appointment, we process the data you provide (name, email, company where applicable) to prepare and hold the appointment. We also use HubSpot as a CRM to manage prospect and customer contacts. The legal basis is our legitimate interest in efficient communication or the initiation and performance of a contract (Art. 6(1)(f) and (b) GDPR).

Connected mailboxes and calendars (Nylas)

If you connect your own mailbox or calendar in the application, we synchronise emails, calendar and contact data via Nylas (EU data centre) in order to provide the features you enable (inbox, calendar sync). You can disconnect at any time.

Google API Services – Limited Use

When you connect a Google account (Gmail, Google Calendar or Google Contacts) to Univents, we access your data solely to provide the features you enable: showing and sending email, syncing your calendar, and syncing your contacts. We never sell this data, never use it for advertising, and never use it to train generalized AI/ML models. Access is per-connected-account and you can disconnect at any time, which revokes our access and deletes the mirrored data.

Univents’ use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

11. AI features

For AI features (chat assistant, onboarding assistant, knowledge base) the content you enter and related workspace data are sent to our AI providers. Responses are generated by Anthropic (Claude); we use OpenAI exclusively to create text embeddings for semantic search, not to generate responses. For quality assurance and sentiment analysis, the content of chat and onboarding conversations is also sent to PostHog. This content may contain personal data.

We use this content solely to provide and improve these features. Use for training generalized AI models by our providers is contractually excluded under the data processing agreements concluded with them. The legal basis is the performance of a contract or our legitimate interest in providing intelligent features (Art. 6(1)(b) and (f) GDPR).

12. Public booking pages & customer portals (commissioned processing)

Through Univents, our customers (organisers, caterers, event venues) operate public booking pages (e.g. at /book and as iframe embeds via /embed) and customer portals (EventHub). We process the booking, contact and guest data entered there solely on behalf of and on the instructions of the respective customer. For this data, the customer is the controller under data protection law; Univents is the processor (Art. 28 GDPR).

Our Data Processing Agreement (DPA) applies.

On these pages we use no marketing or advertising services. Our own processing is limited to anonymous, cookieless reach measurement; recurring-visitor statistics (PostHog) and sentiment analysis only take place with your consent. The attribution cookie (Section 7) is never set on these pages.

If a customer embeds its own tools on its booking page (e.g. its own Google Tag Manager), it is itself responsible for that processing. To exercise your data subject rights with respect to this data, please contact the respective customer as the controller.

13. Recipients & processors

To provide our services we share personal data with carefully selected service providers acting as processors (Art. 28 GDPR) exclusively on our instructions. Data processing agreements are in place with all of them. The overview below lists the providers we use, the purpose, the processing location and – for transfers to third countries – the respective transfer basis.

ProviderPurposeProcessing locationTransfer basis
Supabase Pte. Ltd.Database, authentication, file storageEU (Frankfurt)DPA (EU)
Vercel Inc.Application hosting and delivery (CDN)EU (Frankfurt); group HQ USADPA + SCC
Cloudflare, Inc.Edge/proxy infrastructure (incl. proxy for document rendering)Global edge network (HQ USA)SCC + DPA
Google LLCRendering of documents (quotes/invoices) via Google Apps ScriptUSASCC + DPA
Bubble Group, Inc.Legacy platform (ongoing data migration)USASCC + DPA
Anthropic, PBCAI text generation (Claude)USASCC + DPA
OpenAI, L.L.C.Semantic search and embeddingsUSASCC + DPA
PostHog, Inc.Product analytics, session replay, AI observabilityGermany (EU cloud)DPA (EU)
Stripe Payments Europe, Ltd.Payment processing and billingIreland (EU); transfer to Stripe, Inc. (USA)DPA + SCC
Resend, Inc.Sending transactional emailUSASCC + DPA
Nylas, Inc.Syncing of mailboxes and calendarsEU (Ireland)DPA + SCC
Intercom Inc.Support chat and customer communicationUSASCC + DPA
HubSpot, Inc.CRM, contact management, demo bookingEU (Frankfurt); group HQ USADPA + SCC
Google Ireland Ltd. (Maps)Address and distance features (e.g. travel-distance calculation)Ireland (EU); transfer to USA possibleDPA + SCC
Google Ireland Ltd. (Analytics / Google-Tag)Reach measurement with Google Analytics 4 and delivery of the Google tag (gtag.js); cookies only with statistics consentIreland (EU); transfer to USA possibleDPA + SCC
Google Ireland Ltd. (Ads)Conversion tracking (marketing consent only)Ireland (EU) / USASCC + EU-US DPF
Meta Platforms Ireland Ltd.Ad measurement and retargeting (marketing consent only)Ireland (EU); transfer to USASCC + EU-US DPF
LinkedIn Ireland U.C.Campaign measurement and B2B retargeting (marketing consent only)Ireland (EU); transfer to USASCC + EU-US DPF

14. Third-country transfers

Some of the providers named process data outside the EU or the EEA, in particular in the USA. Such third-country transfers only take place on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR: EU Standard Contractual Clauses (SCC) and – where the respective provider is certified (e.g. Google, Meta, LinkedIn) – on the basis of the adequacy decision for the EU-US Data Privacy Framework. Where necessary, we apply additional safeguards such as encryption. The specific processing locations are shown in the table in Section 13.

15. Storage period

We store personal data only for as long as is necessary for the respective purposes or as required by statutory retention obligations:

  • Account data: for the duration of the contractual relationship; deleted after termination unless retention obligations require otherwise.
  • Invoices and accounting records: 10 years (§ 147 AO, § 257 HGB).
  • Server log files: only briefly, then automatically deleted or anonymised.
  • Session recordings (PostHog Session Replay): automatically deleted after 30 days.
  • Pseudonymised analytics event data (PostHog): up to 84 months.
  • Records of consent: for as long as required as evidence.
  • AI content at our AI providers: under their data processing agreements only briefly (usually max. 30 days) for abuse detection, without training.

16. Your rights

Under the GDPR you have the following rights:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interest (Art. 21 GDPR)

You may withdraw a consent you have given at any time with effect for the future, without affecting the lawfulness of processing carried out until then – for cookies and tracking via the “Cookie settings” link in the footer, otherwise by contacting us.

To exercise your rights, an informal message to hello@univents.app is sufficient. If the data concerns a booking page or customer portal operated through Univents, please contact the respective customer as the controller (see Section 12).

Right to lodge a complaint: you have the right to lodge a complaint with a data protection supervisory authority, in particular with the authority responsible for us: the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg).

17. Obligation to provide data

Where necessary to conclude a contract or create an account, the provision of certain data (e.g. name, email address, billing data) is required. Without this data we cannot provide the application. Any information beyond this is voluntary.

18. Changes to this privacy policy

We adapt this privacy policy when the legal situation or our processing activities change. The version published on this page at the relevant time applies.