← To the start page

Privacy policy

This is a translation. Where it differs from the original, the German version prevails.

Last updated: September 2026

This privacy policy applies to the website gateheroes.events — the public information site of GateHeroes — and to the application admin.gateheroes.events, in which you manage your account, conclude contracts, pay and use the platform. Sections 1 to 6 mainly concern the website, sections 7 to 11 the application; everything else applies to both.

Guest data — that is, the data of the people who register for your events — is processed by us on your behalf: for this data you are the controller and we are the processor. It is governed not by this policy but by the data processing agreement that you conclude in the application.

1. Controller

Einlasshelden.de
Owner: Sebastian Reinhardt
Peperkamp 2, 25451 Quickborn, Germany
Email: hallo@einlasshelden.de
Phone: +49 (0)4106 122744

2. General

We take the protection of your personal data seriously. The website is a pure information site: it sets no cookies, integrates no analytics or tracking services and does not load any content from third parties. The application itself only sets the cookies that are technically necessary for your sign-in (section 8), and likewise integrates no analytics or tracking services. No user profiles are created.

3. Hosting and server logs

The website and the application are operated on a server of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in a data centre in Falkenstein/Vogtland, Germany. Files that are uploaded in the application or generated for it (such as uploads in forms and invoice receipts) are kept in the object storage of the same provider in a data centre in Nuremberg, Germany. Encrypted backup copies (backups) are kept, also at Hetzner, in a data centre in Helsinki, Finland (European Union). The data does not leave the EU.

Our servers do not keep an access log that records every page view with address, time and browser. The server's technical logs (error and protection messages) may contain your IP address — in particular when one of the protection mechanisms is triggered with which we throttle sign-in, registration, forgotten password and the waiting list form on einlasshelden.de against automated access. These entries serve solely to ensure trouble-free operation and to defend against attacks; the legal basis is our legitimate interest in a secure and functional service pursuant to Art. 6(1)(f) GDPR. We delete them after 30 days. They are not combined with other data sources or analysed for marketing purposes.

4. Fonts

The fonts used on the website and in the application are loaded locally from our own server. No connection to third-party servers (such as Google Fonts) is established in the process, and no data is transmitted to third parties.

5. Contacting us

If you contact us by email, we process the data you send us (your email address and the content of your message) in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR if your enquiry is aimed at concluding or performing a contract, and otherwise our legitimate interest in answering enquiries pursuant to Art. 6(1)(f) GDPR. We delete this data as soon as your enquiry has been dealt with and no statutory retention obligations prevent this.

6. Waiting list on einlasshelden.de

On the website einlasshelden.de you can put yourself on a waiting list to be notified as soon as the platform launches. For this we store your email address, the wording of the consent you gave when doing so, and the language and time — nothing else, in particular no name. After signing up you receive a confirmation email with a link that is valid for seven days; your entry only becomes active when you click it (double opt-in). An unconfirmed entry is not used. The form is throttled per network address against automated sign-ups; if the throttle responds, a log entry with the IP address is created (section 3).

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future — via the unsubscribe link in every email or by sending us a message. We send the waiting list confirmation email via the email service provider Mailjet (Mailjet SAS, France), which processes the message on our behalf and bound by our instructions within the EU (section 12).

7. Account and contract in the application

When you register in the application, we create your account. For this we process the account name, your email address and your password (only as a hash, section 8) and assign a customer number. You confirm your email address via a link in the welcome email.

Before the platform processes guest data for you or you buy paid services, we record your account's contract and billing details: company (optional), VAT ID (optional, companies only), contact person, address including country, contact email address and phone number. These details are the contracting party of the data processing agreement, appear on your invoices and determine the available payment methods and the VAT.

When you accept the data processing agreement or agree to the order terms (at checkout or under “Account”), we record as proof who agreed to which version and when, including the IP address from which this was done. Invoices cannot be changed once issued. For every purchase in the application we record which person in your account triggered it; the account admins see this on the invoice.

If you invite further people to your account, we store their email address and the invitation link (valid for seven days). If an account admin removes an access, it is deleted as soon as it no longer belongs to any account; where an action by this person must remain documented (such as who triggered a purchase or stored a payment method), the entry remains and then states that the access was deleted.

The legal basis is the performance of the contract with you (Art. 6(1)(b) GDPR). We keep account and contract data for the duration of the contractual relationship, and billing data beyond that for as long as commercial and tax retention periods require (Art. 6(1)(c) GDPR). We back up the database daily and keep these backups on the server for up to eight weeks. Backup copies stored elsewhere are encrypted; their keys are renewed at regular intervals and old keys are destroyed.

8. Sign-in and session

We store your password exclusively as a hash (scrypt with a random salt); it cannot be recovered from it. After you sign in, the application sets the technically necessary cookie eh_session: it carries a random session identifier whose session expires on our server after seven days. As soon as you choose an account or workspace, eh_account and eh_workspace are added; they remember where you are currently working. All three are inaccessible to scripts (HttpOnly), are only transmitted over encrypted connections and are not sent to third parties. They are deleted when you sign out.

Optionally, you can set up two-factor sign-in. We store the secret required for this in encrypted form (AES-256-GCM); we store the recovery codes only as a hash, and each can be used once.

To protect sign-in, registration and forgotten password against automated attacks, the application counts attempts per network address and target address in its working memory and slows down when something looks suspicious; these counters are not stored in the database. If a protection mechanism responds, a log entry with the IP address is created (section 3). How many invitations, delivery tests and confirmations for test addresses an access can trigger per hour is also limited; this counter is tied to the access, not to your network address. The legal basis is Art. 6(1)(b) GDPR (session, two-factor) and our legitimate interest in secure operation pursuant to Art. 6(1)(f) GDPR (defence against attacks).

9. Emails to account holders

The application sends you emails that are part of running your account: the welcome and confirmation email, invitations, messages about forgotten passwords and password changes, invoice receipts and notices when something needs your attention (such as an upcoming deletion after a deadline expires, storage running low or an expiring domain). We send these emails via our own email mailbox with a provider in the European Union — not via the waiting list's email service provider. Only when you have the application check whether your guest emails arrive (delivery test to your own address) does this one email — like every guest email — go via Mailjet (section 12); a template's preview email, by contrast, goes via our mailbox. The legal basis is Art. 6(1)(b) GDPR. There are no promotional emails to account holders.

10. Support access

So that we can help you with a problem, a platform supporter of ours can look into your account — read-only, never acting, always with a reason that they must state, and only for one hour; after that the access expires by itself. Particularly sensitive details of your guests (Art. 9 GDPR) remain masked during this access. Every look is logged, and you can see in your account when a platform supporter looked into it and for what reason. The legal basis is the performance of the contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in trouble-free operation (Art. 6(1)(f) GDPR).

11. Payment processing

When you buy paid services in the application and pay online (for example by card), we process the payment via the payment service provider Stripe Payments Europe, Limited, Dublin, Ireland (“Stripe”). You enter your payment details directly into the payment form provided by Stripe. Full card numbers, account numbers or security codes never reach our servers and are never stored by us.

On your first purchase we create a customer record for your account at Stripe that carries only your account's identifier and your customer number. In connection with a payment, Stripe also receives from us:

Stripe tells us whether a payment was successful and sends us an identifier of the payment and — if you save your payment method — an identifier of the saved payment method. We hold only this identifier, no card data. We retrieve its type and a shortened display (for example “Visa •••• 4242”) from Stripe when we show it to you in your account, and do not store them.

As soon as you trigger a purchase and the payment form appears, your browser loads it from Stripe's servers. In the process Stripe receives your IP address and technical details about your device and browser, which Stripe also uses to detect and prevent fraud; Stripe may set cookies for this. This concerns only the payment page in the application — nothing from Stripe is loaded on the website.

Saving a payment method: When paying, you can choose to have Stripe save your payment method for future purchases. This only happens if you tick the corresponding box; it is only charged when someone triggers a purchase themselves — never automatically. A saved payment method belongs to your account, not to you alone: every account admin can pay with it. We record who stored it and who triggered a payment, and show both to the account admins of your account with email address and date. You can remove saved payment methods in your account at any time; they are then detached from your account at Stripe.

The legal basis is the performance of the contract with you (Art. 6(1)(b) GDPR); for fraud prevention it is additionally our legitimate interest in secure payments (Art. 6(1)(f) GDPR). Stripe processes the payment data as a payment service provider under its own responsibility, insofar as this is necessary to execute the payment, prevent fraud and fulfil its own legal obligations. In doing so, Stripe may transfer data to affiliated companies in the USA, in particular to Stripe, Inc. According to its own information, Stripe bases this transfer on the EU-U.S. Data Privacy Framework and additionally on the standard contractual clauses of the European Commission. You can find details in Stripe's privacy policy.

We keep the data belonging to an invoice (amount, invoice number, billing address with contact person and VAT ID, payment status, time, payment identifier and who triggered the purchase) on our servers (section 3) for as long as commercial and tax retention periods require. A saved payment method remains stored at Stripe until you remove it or your account ends; the customer record at Stripe exists until your account ends.

12. Disclosure of data

Your data is not transferred to third parties — with the exception of the service providers who process data on our behalf and bound by our instructions on the basis of a data processing agreement pursuant to Art. 28 GDPR: the hosting provider named above, the provider of our email mailbox for account emails (section 9) and the email service provider Mailjet for the waiting list (section 6) and for the delivery test of your guest emails to yourself (section 9) — as well as the payment service provider Stripe for a payment in the application (section 11), which processes the payment data under its own responsibility.

13. Your rights

Under the GDPR you have the following rights:

An informal message to the contact details given above is sufficient to exercise your rights.

14. Right to lodge a complaint with the supervisory authority

Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:

Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany
www.datenschutzzentrum.de