Data processing agreement
When you use the organiser tools, we process your attendees' data on your behalf. This agreement under Art. 28 GDPR sets the rules for that; it is part of the organiser terms, and the German version prevails.
1. Parties and scope
This agreement is made between the organiser that accepts the organiser terms of use ("controller", "you") and Alper ÇEVİK, Schnirchgasse 11/ 810 1030 Wien, Austria, operator of astrometrik.com ("Astrometrik", "processor", "we").
It is an annex to the organiser terms and part of that contract. It applies as soon as you accept the terms.
It covers the attendee data of your events that we process on your behalf. It does not cover data for which we are the controller ourselves, for example organiser accounts, server logs, the public calendar or the general daily game. For that data, see our privacy notice.
This agreement exists in German, English and Turkish. If the versions differ, the German version prevails.
2. Subject matter and duration
Subject matter: providing the organiser tools of astrometrik.com for your events, as described in the organiser terms.
Duration: this agreement runs as long as the organiser terms run. After that, section 14 applies.
3. Nature and purpose of the processing
We collect, store, organise, display, send and delete data (hosting and operation of the tools). The purposes are:
- registrations, with capacity and waiting list, and tickets;
- emails to registered guests: confirmation, reminders 24 hours and 3 hours before the event, notices about changes or cancellation, and your messages (at most 3 per day per event);
- check-in at the venue (QR code, or ticket plus a yes/no check that the guest is within 2 km);
- live announcements and push notifications for your events;
- SOS messages from guests to you;
- the moderated photo and comment wall and the event summary page;
- the sky-hunt game at your event and its ranking;
- showing you lists and statistics, and the CSV export.
4. Types of personal data
- Registration data: name, email address, number of people, language, time, status (registered, waiting, cancelled), arrival time and how, "paid" note.
- Check-in data, including the yes/no result of the distance check (no coordinates).
- Photos, comments, optional nicknames and reports on your event wall.
- SOS messages: optional text and optional location (rounded to about 1 metre). A guest may choose to include health information in the text.
- Hunt results at your event: optional nickname, score, found objects.
- Push subscriptions for your event: push address (endpoint), link to the event or ticket, language.
- Device pseudonyms (salted hash of a random device ID).
- Data of your staff and helpers, as far as it is contained in event data that you enter.
5. Categories of data subjects
- Attendees: people who register, are on the waiting list, check in, post, play the hunt, send SOS messages or subscribe to notifications for your events.
- Your staff and helpers.
6. Instructions
We process the data only on your documented instructions. Your instructions are the settings you choose and the actions you take in the organiser panel, for example switching registration on, approving a post, sending a message or downloading the CSV file. The organiser terms and this agreement are also instructions. Other instructions must be given in text form, for example by email.
We process the data for other purposes only if EU law or Austrian law requires it. In that case, we tell you before processing, unless that law forbids it.
If we think that an instruction infringes data protection law, we tell you without delay.
7. Your responsibilities as controller
- You are responsible for the lawfulness of the processing, including your own legal basis.
- You inform your attendees about the processing (Art. 13 and 14 GDPR). You may point to our privacy notice and add your own information.
- If you are located outside the EU/EEA, you are also responsible for complying with your local law, for example the Turkish Personal Data Protection Law (KVKK) in Turkey.
- You are responsible for data you download (for example CSV files) and keep yourself.
8. Confidentiality
The operator processes the data personally and keeps it confidential. If any other person is ever given access to the data, that person must first be bound to confidentiality.
9. Security
We take the technical and organisational measures described in Annex 1 (Art. 32 GDPR). We may adapt them to technical progress, as long as the level of protection does not fall.
10. Sub-processors
You give us general authorisation to use sub-processors. The current sub-processors are listed in Annex 2.
We inform you in the organiser panel at least 30 days before we add or replace a sub-processor. You can object. You can also end the contract at any time (see the organiser terms).
We impose on each sub-processor the data protection obligations required by Art. 28(4) GDPR.
Browser push services are listed separately in Annex 2. They are chosen by the visitor's browser and receive only an empty wake-up signal and the technical push address, no content.
11. Requests from data subjects
If a person contacts us about data of your event, we forward the request to you without delay and help you to answer it (Art. 12 to 22 GDPR).
Many requests can be handled with the existing tools: you can view and export the registrations of your events, and attendees can use My tickets & my data to see, download and delete their own data.
12. Assistance with your other duties
Taking into account the nature of the processing and the information available to us, we help you to meet your duties under Art. 32 to 36 GDPR: security of processing, notification of breaches, informing affected persons, data protection impact assessments and prior consultation of the supervisory authority. We do this mainly by providing the information in this agreement and its annexes and by answering your questions.
13. Personal data breaches
If we become aware of a personal data breach affecting your event data, we inform you without undue delay and, where possible, within 48 hours. We give you the information we have: what happened, which data and which people are likely affected, the likely consequences and the measures taken. We add further information as soon as we have it.
14. Deletion and return
You can export the registration data of your events as a CSV file at any time. In addition, event data is deleted automatically on the schedule in our privacy notice, in particular 30 days after an event ends.
When the contract ends, we delete your event data within 30 days, unless the law requires us to store it. If you want to keep the data, export it before the contract ends.
15. Information and audits
We give you the information you need to show that the duties in Art. 28 GDPR are met. We do this by providing information and documents, for example this agreement and Annex 1.
On-site audits are possible only with reasonable notice, at your cost and at most once a year.
16. Transfers outside the EU/EEA
We store the data in the EU/EEA, in Germany, Dusseldorf. If you are located outside the EU/EEA (for example in Turkey), we make the registration data of your events available to you there. This is necessary for attendees to take part in your event (Art. 49(1)(b) GDPR). Browser push services may process technical data in the USA; see Annex 2.
17. Final provisions
For liability, termination, applicable law and courts, the organiser terms apply. If this agreement and the organiser terms contradict each other on data protection, this agreement prevails.
Annex 1: Technical and organisational measures
Access and confidentiality
- Only the operator can access the admin area, with an individual password.
- Each organiser sees only the data of its own events.
- Passwords are stored only as hashes (PHP password_hash, bcrypt or Argon2).
- Login attempts are limited.
- Session cookies are httpOnly and Secure.
- Ticket and access links are HMAC-signed and cannot be guessed.
- The database and the data folder cannot be reached from the web.
- The operator keeps the data confidential.
Integrity
- HTTPS only.
- CSRF protection for forms.
- Every uploaded image is re-encoded; this removes metadata and hidden code. Scripts cannot run in the upload folder.
Availability
- Backups by the hosting provider.
- Rate limiting against abuse.
Data minimisation and pseudonymisation
- IP addresses are stored in our own tables only as salted hashes.
- Device IDs are stored only as salted hashes.
- For check-in by location, only the yes/no result is stored.
- Location and camera data are removed from uploaded images.
Deletion
- An automatic job runs hourly and daily.
- 30 days after an event ends: names and email addresses of registrations are erased (only anonymous counts remain), names at check-in removed, device pseudonyms in check-ins and hunt results replaced, SOS messages deleted, posts never approved deleted, push links to the event deleted.
- Internal notification log: 30 days. Queued push messages: 3 days. Rate-limit data: 2 days.
Annex 2: Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Hostinger International Ltd. | Hosting, database storage, sending emails | Germany, Dusseldorf |
Browser push services
These services are chosen by the visitor's browser. They receive only an empty wake-up signal and the technical push address, no content. They may process technical data (push address, IP address of the push request) in the USA under their own terms.
| Provider | Service | Browsers |
|---|---|---|
| Firebase Cloud Messaging | Chrome, Android | |
| Apple | Apple Push Notification service | Safari, iOS |
| Mozilla | autopush | Firefox |
| Microsoft | Push service for Edge | Edge |
Version 2026-10 · 2026-09-29