1. Data Controller
- Company name: WE EVENT — SAS, mission-driven company
- Share capital : 10,000 €
- Head office : 93 avenue du Général Charles de Gaulle, 83300 Draguignan, France
- Registration: RCS Draguignan 107 466 526 — SIRET 107 466 526 00012
- GDPR Contact: support@we-event.eu
2. Data Collected
2.1 Data you provide us
- Account: last name, first name, email, password (encrypted), phone (optional)
- Providers: SIRET, SIREN, company name, VAT, Professional Liability Insurance
- Quote requests: event type, date, number of guests, budget, message
- Content: photos, videos, published descriptions
2.2 Automatically collected data
- Technical: IP address, browser type, pages visited, session duration
- Cookies: see Cookie Policy
3. Purposes and Legal Bases
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Account creation and management | Contract execution (Art. 6.1.b) |
| Client / Vendor Connection | Contract execution (Art. 6.1.b) |
| Provider Subscription Billing | Legal obligation (art. 6.1.c) |
| Commercial communications | Consent (Art. 6.1.a) |
| Fraud prevention and security | Legitimate interest (art. 6.1.f) |
| Anonymized statistical analysis | Legitimate interest (art. 6.1.f) |
| Response to GDPR requests (Art. 15-22) | Legal obligation (art. 6.1.c) |
4. Retention Periods
| Data | Duration |
|---|---|
| Active account | For the entire duration of use + 3 years after last login |
| Unsuccessful quote request | 24 months from the request |
| Invoices and Accounting Documents | 10 years (French legal obligation) |
| Analytical cookies | 13 months maximum |
| Security Logs | 12 months |
5. Recipients
Your data may be shared with:
- Providers relevant to your quote requests (only pertinent info)
- Our technical subcontractors (hosting, emailing, Stripe payment, analytics), governed by contracts compliant with Art. 28 GDPR
- Enable Banking Oy (Finland, European Union), authorized account information service provider, when you choose to connect a bank account — see section 7
- Authorities in case of legal judicial request
We never sell your data to third parties.
6. Data transfers outside the European Union
As WE EVENT is established in France, some data may be processed outside the EU (in particular by our teams). These transfers are governed by:
- The standard contractual clauses (SCCs) adopted by the European Commission (Implementing Decision EU 2021/914 of 4 June 2021)
- Additional technical measures: encryption in transit (TLS 1.3) and at rest (AES-256), strict access controls, pseudonymization when relevant
US subcontractors benefit, where applicable, from Data Privacy Framework certification between the EU and the USA.
A copy of the applicable guarantees is available upon request at support@we-event.eu.
7. Bank Account Aggregation (account information service)
If you are a Provider and choose to connect a bank account to your space, WE EVENT implements a processing ofaccount aggregation intended for monitoring your cash flow and reconciling your invoices.
This service relies on the European Payment Services Directive (PSD2). It is technically provided by Enable Banking Oy, a Finnish company (registration number 2988499-7, Otakaari 5, 02150 Espoo, Finland), authorized as an account information service provider and acting as a sub-processor in the sense of Article 28 of the GDPR.
Data Processed
- Theidentity of the bank you select
- The references and names of the accounts you grant access to (IBAN, account name, currency)
- The balance of these accounts
- Thetransaction history : date, amount, description, third-party name
WE EVENT does not have access to your bank credentials. You authenticate directly with your bank, on its own website.
Legal Basis
Your explicit consent (Art. 6.1.a of the GDPR), collected by your bank at the time of connection, as well as the performance of the contract binding us (Art. 6.1.b) for the treasury functions of your subscription.
Duration
Consent is valid for 180 days maximum and must be renewed thereafter. WE EVENT revokes consent with the institution as soon as you disconnect the account, your subscription ends, or the connection remains inactive for more than 90 days. Already imported transactions are retained according to the durations in section 4.
Withdraw your consent
You can disconnect an account at any time, without cause, since Cash Flow → Bank and Reconciliation. Disconnecting immediately revokes access to your bank. You can also do this directly with your bank, or by writing to support@we-event.eu.
Location
This data is processed within the European Union. No transfer to a third country is made as part of this processing.
8. Your GDPR Rights
You have the following rights (Art. 15 to 22 GDPR):
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to object, notably to direct marketing
- Right to data portability in a structured format
- Right to withdraw your consent at any time
- Right to define post-mortem directives regarding your data
To exercise these rights, write to support@we-event.eu attaching an ID if necessary to verify your identity.
We respond within a maximum of 30 days in accordance with Art. 12 GDPR (extendable by 2 months in case of complex request).
9. Security
Technical and organizational measures implemented:
- Password encryption (bcrypt)
- HTTPS required (TLS 1.3)
- Database encryption at rest (AES-256)
- Restricted internal access (principle of least privilege)
- Regular encrypted backups
- Periodic Security Audits
In case of a data breach likely to result in a high risk to your rights, we will notify you without undue delay in accordance with Art. 34 GDPR.
10. Cookies and trackers
Details of cookies used, their duration, and management procedures are specified in our Cookie Policy.
11. Minors
The Platform is not intended for individuals under 15 years of age. We do not knowingly collect data concerning minors. If you believe a minor has provided us with information, please contact us so we can delete this data.
12. Connecting to your Google services
If you choose to link your Google Calendar to We Event, we access certain data from your Google account. This connection is optional: the Platform functions without it.
12.1 What we access
- Your main calendar events (title, dates, location, description, status) within a window ranging from 7 days in the past to 90 days in the future
- The email address associated with your calendar, only to show you which account is connected
We do not access your other calendars, contacts, files, or any other data from your Google account.
12.2 What we do with it
- Show your Google events in your We Event calendar, alongside your appointments and services
- Add to your Google Calendar the appointments and events you create in We Event, so that both calendars remain a mirror of each other
- Detect conflicts in slots between your different appointment sources
This data is used for no other purpose. It is not resold, not used for advertising, not exploited to train artificial intelligence models, nor transmitted to third parties other than the technical hosting subcontractors mentioned in article 5.
12.3 Where this data is stored
Imported events are stored in our database hosted in the European Union, associated with your account only. Access tokens issued by Google are securely stored and are never transmitted to a third party or exposed in the interface.
12.4 How to revoke this access
You can disconnect your Google account at any time from your We Event calendar: the disconnect button immediately and permanently deletes access tokens from our servers, and synchronization stops. You can also revoke access directly from your Google account permissions. Already imported events can be deleted upon simple request to contact@we-event.eu, in accordance with article 7.
12.5 Compliance with Google's policies
We Event's use and transfer of information received from Google APIs comply with the Google API Services User Data Policy, including its Limited Use requirements (Limited Use).
13. Appeal to the CNIL
If you believe, after contacting us, that your GDPR rights are not respected, you can file a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) :
- Website: www.cnil.fr
- Address: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07