Legal

Privacy Policy

This English version is provided for convenience. In the event of any discrepancy, the German version shall prevail.

1. General Information

Protecting personal data is important to us.

This Privacy Policy explains which personal data is processed when visiting our website, contacting EveLin, using an Organizer account, or participating in events where EveLin is used.

EveLin is a digital networking system for events. Organizers can create events and invite participants to use EveLin. Participants can create a profile via a QR code, provide information about their networking needs and offers, and receive matching suggestions based on that information.

Personal data means any information relating to an identified or identifiable natural person. Pseudonymous identifiers, event assignments, matching profiles, and combinations of professional information may also constitute personal data. Pseudonymized data is therefore not automatically anonymous.

2. Controllers and Allocation of Roles

The following persons are joint controllers for EveLin’s own processing activities described in this Privacy Policy:

Paul Martinez Lukasstraße 12A 50823 Cologne Germany

Maurice Guss Friesenwall 19 50672 Cologne Germany

Leonie Göbl Merheimer Str. 47 50733 Cologne Germany

Contact: info@evelin-ai.com

EveLin assumes different data protection roles depending on the specific processing activity.

EveLin acts as a controller for the operation of its website, prospect and waitlist data, Organizer accounts, support, system security, and the expressly described internal analysis and product improvement purposes.

When EveLin is used for a specific event, the respective Organizer generally determines the purpose of the event, the use of EveLin, and how event data is used. The Organizer is therefore generally the controller for event-related processing under the GDPR. EveLin generally processes such data as a processor on behalf of the Organizer when providing the core event service.

The respective Organizer is responsible in particular for informing participants about its identity, the purposes and legal bases of the event-related processing, and any specific event conditions. Information about the responsible Organizer may be provided in the event invitation, on the event page, or directly by the Organizer.

Where EveLin processes event-related data for its own expressly described purposes, particularly system security, quality assurance, internal analysis, or product improvement, EveLin acts as a controller for that processing. If EveLin and an Organizer act as joint controllers in a particular case, participants will be informed separately.

3. Website Visits and Technical Access Data

When our website or web applications are accessed, the following technical data may be processed:

This processing is carried out to provide the website, ensure its stability and security, detect misuse, and analyze technical errors.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, stable, and functional operation of our website and systems.

4. Local Storage, Cookies, and Similar Technologies

Our web applications may store technically necessary information in the user’s browser, including session or access tokens, language settings, event codes, and information required to continue an existing participant session.

Such storage is used to provide explicitly requested functions, authenticate users, and protect system security.

Where non-essential cookies, analytics technologies, or marketing technologies are used, this will take place only in accordance with the applicable legal requirements and, where required, after consent has been obtained.

5. Contact Requests, Waitlist, and Prospect Management

When you join our waitlist, contact us, or express an interest in EveLin, we may process the following data:

This processing is used to respond to your request, take steps prior to entering into a contract, manage the waitlist, and communicate about EveLin.

The legal basis is Article 6(1)(b) GDPR where the processing relates to pre-contractual measures. Where we obtain separate consent, the legal basis is Article 6(1)(a) GDPR. The structured handling of business inquiries and documentation of communications may also be based on Article 6(1)(f) GDPR.

We send promotional electronic communications only where we have obtained the necessary consent or another legal permission applies.

6. Organizer Accounts and Event Management

When an Organizer registers for or uses an EveLin account, the following data may be processed:

This processing is used to create and authenticate accounts, provide and manage the platform, conduct events, perform contracts, communicate with users, resolve errors, and maintain system security.

The legal basis is Article 6(1)(b) GDPR where the processing is necessary to establish or perform the user or contractual relationship. Security and misuse prevention measures may be based on Article 6(1)(f) GDPR. Legally required retention is based on Article 6(1)(c) GDPR.

7. Creating and Accessing Events

Organizers can create events in EveLin and provide information such as:

When a QR code is scanned, the event code and associated public event information are processed. The technical access data described in Section 3 may also be generated.

8. Participant Profiles

Participants can voluntarily create an event-related profile. Depending on the configuration of the respective event, the following data may be processed:

The data is used to enable participation in the event, provide the participant profile, create matching suggestions, display matching partners, collect feedback, and provide event-related reports to the Organizer.

Profile data may be displayed to the Organizer responsible for the event and, to the extent required for the relevant feature, to assigned matching partners.

Participation in EveLin is voluntary. The legal basis for event-related processing is determined by the respective Organizer. Where consent is obtained during the participant process, the processing is based on Article 6(1)(a) GDPR.

Consent can be withdrawn at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

9. AI-Assisted Matching

EveLin processes profile content and uses algorithmic systems and AI services to generate matching suggestions.

The current matching process may include the following information:

The participant’s full email address and profile photo are not included in the current matching payload. Pseudonymous participant identifiers are used for the processing. As assignment to a participant may remain possible within the EveLin system, the data is not anonymous.

The purpose of the processing is to suggest relevant conversation partners, support the selection of potential matches, and generate matching explanations and conversation starters.

Matching suggestions are recommendations only. They do not produce legal effects and do not similarly significantly affect participants. According to the current product design, no solely automated decision-making within the meaning of Article 22 GDPR takes place.

10. LINKsights, Reports, and Organizer Analytics

After an event, EveLin may create reports and LINKsights analytics for the Organizer.

The following information may be processed for this purpose:

Names, full email addresses, and profile photos are not transmitted to the AI service used to generate LINKsights.

However, the information used is not automatically anonymous. Event references, pseudonymous identifiers, free-text information, and combinations of professional information may enable indirect identification. The information is therefore still treated as personal data.

Authorized users of the respective Organizer may access event data, participant profiles, matches, feedback, reports, and CSV exports, depending on their permissions.

Authorized EveLin administrators may access event and report data where necessary for operation, support, troubleshooting, security, quality assurance, or the internal analysis described in Section 11.

11. Quality Assurance, Internal Analysis, and Product Improvement

EveLin may process pseudonymized event, matching, feedback, and report data for quality assurance, error analysis, evaluation of matching quality, improvement of existing features, and further development of the product.

The processing may pursue the following purposes:

The legal basis for these processing activities carried out by EveLin for its own purposes is Article 6(1)(f) GDPR. Our legitimate interests are improving the quality, security, reliability, and economic viability of our product.

When balancing these interests, we take into account in particular that the data was originally provided as part of voluntary event participation, that product improvements may benefit both Organizers and participants, and that names, full email addresses, and profile photos are not transmitted for AI-assisted LINKsights generation.

Where direct identifiers are not required for the respective analytical purpose, they are not included in the analysis. Access is restricted to authorized persons. Pseudonymized data nevertheless remains personal data.

Data subjects may object to this processing on grounds relating to their particular situation under Article 21 GDPR. Objections may be submitted to info@evelin-ai.com.

Personal participant data is not sold or otherwise commercially disclosed to third parties.

12. Optional Profile Photos

Uploading a profile photo is voluntary and requires separate consent.

Photos may be displayed to assigned matching partners and, depending on their permissions, to the Organizer or authorized EveLin administrators.

Profile photos are not used for AI-assisted matching or LINKsights and are not included in the corresponding AI payloads.

Consent can be withdrawn at any time with effect for the future. Withdrawal may be exercised in particular by deleting the photo or contacting the responsible Organizer or EveLin.

Technical records of consent and metadata relating to the deletion may be retained for longer than the image file itself where this is necessary to demonstrate consent, process the withdrawal, or maintain system security.

13. Feedback, Support, and Communications

Participants may provide feedback about matches or the event. Ratings, free-text responses, matching, participant and event assignments, and timestamps may be processed for this purpose.

Organizers and prospective customers may also submit support requests. Contact details, subject lines, messages, attachments, processing status, and internal support notes may be processed.

This processing is used to handle feedback, support Organizers and participants, resolve errors, and improve the service.

Depending on the context, the processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Where feedback is used for EveLin’s own product improvement purposes, the information in Section 11 also applies.

14. Recipients, Service Providers, and International Data Transfers

The following categories of recipients may be used to provide EveLin:

Where service providers process personal data on our behalf, they are engaged in accordance with the requirements of Article 28 GDPR.

Individual service providers may process data outside the European Union or the European Economic Area. Where no adequacy decision applies to the recipient country, transfers take place only in accordance with Articles 44 et seq. GDPR, particularly on the basis of appropriate safeguards such as the European Commission’s Standard Contractual Clauses and, where necessary, supplementary protective measures.

The specific list of service providers, their locations, roles, and transfer mechanisms is maintained in our provider and contract register and will be reflected in this Privacy Policy when changes are made.

Personal data may also be disclosed where we are legally required to do so or where disclosure is necessary to establish, exercise, or defend legal claims.

15. Retention and Deletion

Personal data is not retained for longer than required for the respective purpose. The relevant criteria include:

There is currently no general automatic deletion of event-related profile, matching, feedback, and LINKsights data 30 days after an event. Such data may also be retained after the event for as long as it is required to provide reports, handle support or legal matters, or pursue the transparently described quality assurance and product improvement purposes.

Event data may be deleted at the instruction of the responsible Organizer. Depending on the relevant deletion process, individual evidentiary, security, or pseudonymization records may remain where a continuing purpose or legal necessity exists.

The following specific rules currently apply to certain data:

Where no fixed retention period applies, the data is deleted or anonymized once the relevant purpose no longer applies and there are no statutory, contractual, or legal grounds requiring further retention.

16. Data Subject Rights

Data subjects have the following rights against the respective controller:

Requests concerning data processed in connection with a specific event should generally be directed first to the Organizer responsible for that event. EveLin supports the Organizer in handling such requests within the scope of the processing relationship.

For EveLin’s own processing activities and general data protection inquiries, you may contact info@evelin-ai.com.

We may require additional information to verify the identity of the requesting person and prevent personal data from being disclosed to unauthorized persons.

You also have the right to lodge a complaint with a data protection supervisory authority. The following authority is particularly responsible for our own processing activities:

State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia Kavalleriestraße 2–4 40213 Düsseldorf Germany https://www.ldi.nrw.de

17. Data Security

We implement technical and organizational measures to protect personal data against loss, manipulation, accidental disclosure, and unauthorized access.

Depending on the relevant system, these measures include access restrictions, authentication procedures, role-based permissions, encrypted data transmission, logging of security-relevant events, and technical measures to separate different Organizers and events.

Despite careful security measures, absolute security cannot be guaranteed for electronic data transmission and storage.

18. External Links

Our website and EveLin may contain links to external websites or platforms. When you follow such a link, you leave EveLin’s area of responsibility.

The respective operator of the external website or platform is generally responsible for the processing of personal data on that service.

19. Changes to this Privacy Policy

We update this Privacy Policy when our features, data processing activities, service providers, or legal requirements change.

The current version is published on our website. Where material changes affect Organizer accounts or event participants, we may also provide information through the application or by other appropriate means.

Last updated: August 2026