This English version is provided for convenience. In the event of any discrepancy, the German version shall prevail.
1. General Information
Protecting personal data is important to us.
This Privacy Policy explains which personal data is processed when visiting our website, contacting EveLin, using an Organizer account, or participating in events where EveLin is used.
EveLin is a digital networking system for events. Organizers can create events and invite participants to use EveLin. Participants can create a profile via a QR code, provide information about their networking needs and offers, and receive matching suggestions based on that information.
Personal data means any information relating to an identified or identifiable natural person. Pseudonymous identifiers, event assignments, matching profiles, and combinations of professional information may also constitute personal data. Pseudonymized data is therefore not automatically anonymous.
2. Controllers and Allocation of Roles
The following persons are joint controllers for EveLin’s own processing activities described in this Privacy Policy:
Paul Martinez Lukasstraße 12A 50823 Cologne Germany
Maurice Guss Friesenwall 19 50672 Cologne Germany
Leonie Göbl Merheimer Str. 47 50733 Cologne Germany
Contact: info@evelin-ai.com
EveLin assumes different data protection roles depending on the specific processing activity.
EveLin acts as a controller for the operation of its website, prospect and waitlist data, Organizer accounts, support, system security, and the expressly described internal analysis and product improvement purposes.
When EveLin is used for a specific event, the respective Organizer generally determines the purpose of the event, the use of EveLin, and how event data is used. The Organizer is therefore generally the controller for event-related processing under the GDPR. EveLin generally processes such data as a processor on behalf of the Organizer when providing the core event service.
The respective Organizer is responsible in particular for informing participants about its identity, the purposes and legal bases of the event-related processing, and any specific event conditions. Information about the responsible Organizer may be provided in the event invitation, on the event page, or directly by the Organizer.
Where EveLin processes event-related data for its own expressly described purposes, particularly system security, quality assurance, internal analysis, or product improvement, EveLin acts as a controller for that processing. If EveLin and an Organizer act as joint controllers in a particular case, participants will be informed separately.
3. Website Visits and Technical Access Data
When our website or web applications are accessed, the following technical data may be processed:
- IP address
- date and time of access
- pages and resources accessed
- referrer URL
- browser type and browser version
- operating system and device information
- HTTP status and transferred data volume
- security, error, and diagnostic information
This processing is carried out to provide the website, ensure its stability and security, detect misuse, and analyze technical errors.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable, and functional operation of our website and systems.
4. Local Storage, Cookies, and Similar Technologies
Our web applications may store technically necessary information in the user’s browser, including session or access tokens, language settings, event codes, and information required to continue an existing participant session.
Such storage is used to provide explicitly requested functions, authenticate users, and protect system security.
Where non-essential cookies, analytics technologies, or marketing technologies are used, this will take place only in accordance with the applicable legal requirements and, where required, after consent has been obtained.
5. Contact Requests, Waitlist, and Prospect Management
When you join our waitlist, contact us, or express an interest in EveLin, we may process the following data:
- name
- email address
- company and professional role
- telephone number, where voluntarily provided
- content and time of the contact request
- status of the request or potential business relationship
- internal notes and communication history
This processing is used to respond to your request, take steps prior to entering into a contract, manage the waitlist, and communicate about EveLin.
The legal basis is Article 6(1)(b) GDPR where the processing relates to pre-contractual measures. Where we obtain separate consent, the legal basis is Article 6(1)(a) GDPR. The structured handling of business inquiries and documentation of communications may also be based on Article 6(1)(f) GDPR.
We send promotional electronic communications only where we have obtained the necessary consent or another legal permission applies.
6. Organizer Accounts and Event Management
When an Organizer registers for or uses an EveLin account, the following data may be processed:
- name and email address
- telephone number, where provided
- company, industry, and professional role
- password in hashed form
- registration and approval status
- login, security, and account information
- accepted versions of terms and privacy notices
- created events and event configurations
- company and event logos
- support and communication data
This processing is used to create and authenticate accounts, provide and manage the platform, conduct events, perform contracts, communicate with users, resolve errors, and maintain system security.
The legal basis is Article 6(1)(b) GDPR where the processing is necessary to establish or perform the user or contractual relationship. Security and misuse prevention measures may be based on Article 6(1)(f) GDPR. Legally required retention is based on Article 6(1)(c) GDPR.
7. Creating and Accessing Events
Organizers can create events in EveLin and provide information such as:
- event name and description
- date, time, and location
- Organizer and company assignment
- event logo
- event code and QR code
- questions and configurable registration fields
- settings for matching, reports, and participant access
When a QR code is scanned, the event code and associated public event information are processed. The technical access data described in Section 3 may also be generated.
8. Participant Profiles
Participants can voluntarily create an event-related profile. Depending on the configuration of the respective event, the following data may be processed:
- name or display name
- email address
- Need: what the participant is looking for
- Offer: what the participant can offer to others
- professional role or occupation
- company
- industry
- answers to event-related questions
- language
- voluntary identification hints or additional information
- optional profile photos
- event and participant identifiers
- time and version of consent provided
The data is used to enable participation in the event, provide the participant profile, create matching suggestions, display matching partners, collect feedback, and provide event-related reports to the Organizer.
Profile data may be displayed to the Organizer responsible for the event and, to the extent required for the relevant feature, to assigned matching partners.
Participation in EveLin is voluntary. The legal basis for event-related processing is determined by the respective Organizer. Where consent is obtained during the participant process, the processing is based on Article 6(1)(a) GDPR.
Consent can be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
9. AI-Assisted Matching
EveLin processes profile content and uses algorithmic systems and AI services to generate matching suggestions.
The current matching process may include the following information:
- pseudonymous participant identifier
- Need and Offer
- role or occupation
- industry and company
- answers to event-related questions
- organizational domain derived from the email address
- event-related contextual information
The participant’s full email address and profile photo are not included in the current matching payload. Pseudonymous participant identifiers are used for the processing. As assignment to a participant may remain possible within the EveLin system, the data is not anonymous.
The purpose of the processing is to suggest relevant conversation partners, support the selection of potential matches, and generate matching explanations and conversation starters.
Matching suggestions are recommendations only. They do not produce legal effects and do not similarly significantly affect participants. According to the current product design, no solely automated decision-making within the meaning of Article 22 GDPR takes place.
10. LINKsights, Reports, and Organizer Analytics
After an event, EveLin may create reports and LINKsights analytics for the Organizer.
The following information may be processed for this purpose:
- pseudonymous participant identifiers
- Needs and Offers
- roles, industries, and companies
- answers to event-related questions
- matching results
- matching explanations and icebreakers
- participant feedback
- event and matching metrics
- aggregated analytics and report content
Names, full email addresses, and profile photos are not transmitted to the AI service used to generate LINKsights.
However, the information used is not automatically anonymous. Event references, pseudonymous identifiers, free-text information, and combinations of professional information may enable indirect identification. The information is therefore still treated as personal data.
Authorized users of the respective Organizer may access event data, participant profiles, matches, feedback, reports, and CSV exports, depending on their permissions.
Authorized EveLin administrators may access event and report data where necessary for operation, support, troubleshooting, security, quality assurance, or the internal analysis described in Section 11.
11. Quality Assurance, Internal Analysis, and Product Improvement
EveLin may process pseudonymized event, matching, feedback, and report data for quality assurance, error analysis, evaluation of matching quality, improvement of existing features, and further development of the product.
The processing may pursue the following purposes:
- identifying and resolving technical or functional errors
- evaluating the quality of matching suggestions
- improving matching and reporting features
- assessing which product features function reliably
- developing and testing new matching and analytics methods
- ensuring stable and secure product operation
The legal basis for these processing activities carried out by EveLin for its own purposes is Article 6(1)(f) GDPR. Our legitimate interests are improving the quality, security, reliability, and economic viability of our product.
When balancing these interests, we take into account in particular that the data was originally provided as part of voluntary event participation, that product improvements may benefit both Organizers and participants, and that names, full email addresses, and profile photos are not transmitted for AI-assisted LINKsights generation.
Where direct identifiers are not required for the respective analytical purpose, they are not included in the analysis. Access is restricted to authorized persons. Pseudonymized data nevertheless remains personal data.
Data subjects may object to this processing on grounds relating to their particular situation under Article 21 GDPR. Objections may be submitted to info@evelin-ai.com.
Personal participant data is not sold or otherwise commercially disclosed to third parties.
12. Optional Profile Photos
Uploading a profile photo is voluntary and requires separate consent.
Photos may be displayed to assigned matching partners and, depending on their permissions, to the Organizer or authorized EveLin administrators.
Profile photos are not used for AI-assisted matching or LINKsights and are not included in the corresponding AI payloads.
Consent can be withdrawn at any time with effect for the future. Withdrawal may be exercised in particular by deleting the photo or contacting the responsible Organizer or EveLin.
Technical records of consent and metadata relating to the deletion may be retained for longer than the image file itself where this is necessary to demonstrate consent, process the withdrawal, or maintain system security.
13. Feedback, Support, and Communications
Participants may provide feedback about matches or the event. Ratings, free-text responses, matching, participant and event assignments, and timestamps may be processed for this purpose.
Organizers and prospective customers may also submit support requests. Contact details, subject lines, messages, attachments, processing status, and internal support notes may be processed.
This processing is used to handle feedback, support Organizers and participants, resolve errors, and improve the service.
Depending on the context, the processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Where feedback is used for EveLin’s own product improvement purposes, the information in Section 11 also applies.
14. Recipients, Service Providers, and International Data Transfers
The following categories of recipients may be used to provide EveLin:
- hosting, server, and database providers
- object or file storage providers
- email and communications providers
- AI and API providers
- error monitoring, logging, and system security providers
- technical development and support providers
- professional advisers where legally required
Where service providers process personal data on our behalf, they are engaged in accordance with the requirements of Article 28 GDPR.
Individual service providers may process data outside the European Union or the European Economic Area. Where no adequacy decision applies to the recipient country, transfers take place only in accordance with Articles 44 et seq. GDPR, particularly on the basis of appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where necessary, supplementary protective measures.
The specific list of service providers, their locations, roles, and transfer mechanisms is maintained in our provider and contract register and will be reflected in this Privacy Policy when changes are made.
Personal data may also be disclosed where we are legally required to do so or where disclosure is necessary to establish, exercise, or defend legal claims.
15. Retention and Deletion
Personal data is not retained for longer than required for the respective purpose. The relevant criteria include:
- the status and duration of the respective event
- the provision of matches, reports, and LINKsights
- the duration of the Organizer account or contractual relationship
- the necessity of the data for support, system security, or error analysis
- the necessity of the data for the product improvement purposes described in Section 11
- withdrawal of consent, objection, or a valid deletion request
- deletion instructions from the responsible Organizer
- statutory retention obligations
- the necessity of the data to establish or defend legal claims
- the possibility of legally effective anonymization
There is currently no general automatic deletion of event-related profile, matching, feedback, and LINKsights data 30 days after an event. Such data may also be retained after the event for as long as it is required to provide reports, handle support or legal matters, or pursue the transparently described quality assurance and product improvement purposes.
Event data may be deleted at the instruction of the responsible Organizer. Depending on the relevant deletion process, individual evidentiary, security, or pseudonymization records may remain where a continuing purpose or legal necessity exists.
The following specific rules currently apply to certain data:
- Organizer login tokens are generally valid for up to 24 hours.
- Participant tokens are generally valid for up to seven days.
- Password reset and account deletion confirmation tokens are generally valid for up to 30 minutes.
- Profile photo files are deleted based on a technically calculated expiration time, generally after the event or at least 24 hours after a later upload.
- AI call and cost records are deleted after twelve months under the current application logic.
- CSV exports are generated in server memory and are not stored as permanent export files.
- Temporary PDF files are deleted from the server after generation has been completed.
- Downloaded CSV or PDF files are subsequently stored within the respective Organizer’s area of responsibility.
- Technical logs, provider records, and backups are subject to the retention settings of the respective system or provider.
Where no fixed retention period applies, the data is deleted or anonymized once the relevant purpose no longer applies and there are no statutory, contractual, or legal grounds requiring further retention.
16. Data Subject Rights
Data subjects have the following rights against the respective controller:
- right of access under Article 15 GDPR
- right to rectification under Article 16 GDPR
- right to erasure under Article 17 GDPR
- right to restriction of processing under Article 18 GDPR
- right to data portability under Article 20 GDPR
- right to object under Article 21 GDPR
- right to withdraw consent with effect for the future
- right to lodge a complaint with a data protection supervisory authority
Requests concerning data processed in connection with a specific event should generally be directed first to the Organizer responsible for that event. EveLin supports the Organizer in handling such requests within the scope of the processing relationship.
For EveLin’s own processing activities and general data protection inquiries, you may contact info@evelin-ai.com.
We may require additional information to verify the identity of the requesting person and prevent personal data from being disclosed to unauthorized persons.
You also have the right to lodge a complaint with a data protection supervisory authority. The following authority is particularly responsible for our own processing activities:
State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia Kavalleriestraße 2–4 40213 Düsseldorf Germany https://www.ldi.nrw.de
17. Data Security
We implement technical and organizational measures to protect personal data against loss, manipulation, accidental disclosure, and unauthorized access.
Depending on the relevant system, these measures include access restrictions, authentication procedures, role-based permissions, encrypted data transmission, logging of security-relevant events, and technical measures to separate different Organizers and events.
Despite careful security measures, absolute security cannot be guaranteed for electronic data transmission and storage.
18. External Links
Our website and EveLin may contain links to external websites or platforms. When you follow such a link, you leave EveLin’s area of responsibility.
The respective operator of the external website or platform is generally responsible for the processing of personal data on that service.
19. Changes to this Privacy Policy
We update this Privacy Policy when our features, data processing activities, service providers, or legal requirements change.
The current version is published on our website. Where material changes affect Organizer accounts or event participants, we may also provide information through the application or by other appropriate means.
Last updated: August 2026