EventOps Privacy Policy

Version 1.0 — 21 September 2026

Rose Code SAS — [REGISTERED ADDRESS] — SIREN [SIREN] — privacy@eventops.fr

Introduction

This Privacy Policy describes how Rose Code SAS collects, uses, retains and protects personal data in the course of operating the EventOps platform, accessible via the web back-office and the mobile field application.

EventOps is intended exclusively for professional customers (organisations). This Policy is addressed to individual users of the platform, whether they are members of one or several organisations.

Data Controller Identity

The data controller for the processing activities described in this Policy is:

Rose Code SAS

[REGISTERED ADDRESS]

SIREN [SIREN]

Contact: privacy@eventops.fr

Rose Code SAS has not appointed a Data Protection Officer (DPO). For any questions relating to the protection of your personal data, you may contact our team at privacy@eventops.fr.

Allocation of Roles: Controller and Processor

Why This Distinction Matters

Depending on the data concerned and the entity that determines how it is processed, Rose Code SAS does not always act in the same legal capacity under the General Data Protection Regulation (GDPR). This section clearly explains how roles are allocated.

Rose Code SAS as Independent Data Controller

For certain processing activities, Rose Code SAS alone determines the purposes and means. These include:

  • managing user accounts (creation, authentication, security);
  • ensuring the security and stability of the platform;
  • handling support requests;
  • handling requests to exercise GDPR rights;
  • technical observability (logs, error diagnostics).

For these activities, Rose Code SAS acts as an independent data controller.

Client Organisation as Controller; Rose Code SAS as Processor

When a client organisation uses EventOps to manage its own operational data — members, events, operational logs, documents, messages, files — it is the organisation that determines the purposes and means of that processing. Rose Code SAS then acts solely as a data processor within the meaning of Article 28 GDPR, processing such data on behalf of and on the instructions of the client organisation.

A Data Processing Agreement (DPA), compliant with Article 28 GDPR, is incorporated into EventOps' general terms of use.

No Joint Controllership

Rose Code SAS and its clients do not exercise joint controllership within the meaning of Article 26 GDPR. The roles are distinct as described above.

Data Collected and Purposes

Account and Access

Data collected:

  • Name, email address, profile picture, preferred language
  • Hashed password
  • Email address verification proof
  • Encrypted MFA secrets, active sessions
  • Login attempts, account lockout

Purpose: account creation and security, authentication, user preference management.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Organisation Membership

Data collected:

  • Role within the organisation, active or inactive status
  • Local name and picture, membership type
  • Custom data fields defined by the organisation
  • Date of joining the organisation

Purpose: access and permissions management, internal organisational directory.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Event Activity

Data collected:

  • Events, teams, assignments, attendance records
  • Operational logs, corrections, contributions, comments

Purpose: event preparation, coordination and operational history.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Collaboration and Files

Data collected:

  • Messages and attachments
  • Documents and their versions, folders, shared links

Purpose: communication and resource sharing within the organisation.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Communications

Data collected:

  • Push notifications, notification preferences, subscriptions
  • Service emails

Purpose: alerts and information necessary for the operation of the service.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Note on future commercial communications: a commercial email feature is planned. It will be based on explicit, revocable opt-in consent and will be disabled by default. It will only be activated after this Policy has been updated and valid consent has been collected.

Security and Audit Trail

Data collected:

  • Audit log, security events
  • Technical identifiers, IP address and user agent (anonymised after 90 days)

Purpose: access control, incident investigation, operational traceability.

Legal basis: legitimate interests of Rose Code SAS (Article 6(1)(f) GDPR).

Support and Exercise of Rights

Data collected:

  • Email address, subject, description, attachments
  • Type of right exercised, scope, reference number, transmission status

Purpose: handling support requests and requests to exercise rights, record-keeping as evidence of processing.

Legal basis: performance of a contract and legal obligation (Articles 6(1)(b) and 6(1)(c) GDPR).

Mandatory and Optional Data

Some data are essential for the service to function:

  • Email address: mandatory. Without it, no account can be created.
  • Password or OAuth authentication: mandatory for logging in.
  • Organisation membership data (role, status): mandatory to access collaborative features.

The following data are optional:

  • Profile picture
  • Preferred language
  • Custom data fields defined by the organisation

Sensitive Data in Client Content

EventOps does not seek to collect special categories of personal data within the meaning of Article 9 GDPR (health data, data revealing racial or ethnic origin, political opinions, religious beliefs, etc.).

However, free-text fields and files uploaded by organisations may contain such data. Rose Code SAS does not systematically review this content. Client organisations remain responsible for the data they choose to process through the platform.

Rose Code SAS does not reuse organisational data to train artificial intelligence models, produce commercial statistics, or resell analyses.

Automated Decision-Making and Profiling

EventOps does not carry out any solely automated decision-making within the meaning of Article 22 GDPR, nor any profiling that produces legal effects or similarly significantly affects data subjects.

Sub-processors and Data Recipients

Rose Code SAS engages the following service providers to operate the platform. All are subject to contractual data protection obligations compliant with the GDPR.

ProviderRoleLocationTransfers and Safeguards
OVHcloudServer hosting, database, object storage, backupsFranceWithin the EEA — no transfers outside the EEA
ResendTransactional email deliveryUnited StatesEU–U.S. Data Privacy Framework (Resend is certified) and Standard Contractual Clauses, Commission Decision 2021/914, Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor) depending on the parties' roles. Both mechanisms operate independently and in a complementary manner.
Pusher (Bird)Real-time messaging (WebSocket)Ireland (EU cluster)Transfers outside the EEA possible via affiliates and sub-processors (Netherlands, United Kingdom, United States). Safeguards: adequacy decision or EU–U.S. DPF as applicable; failing that, Standard Contractual Clauses (sections 9.1 to 9.3 of the Bird DPA), Controller-to-Processor or Processor-to-Processor modules depending on the client's role.
PostHog EUTechnical error diagnostics (web and mobile)EEAWithin the EEA — no transfers outside the EEA. In-memory persistence only; no PostHog cookies are set.
Apple APNsiOS push notification deliveryApple global infrastructureNotification tokens are stored encrypted by EventOps (OVHcloud, France) and messages are transmitted directly to Apple for delivery. Apple announces Standard Contractual Clauses for its international transfers. The exact contractual scope of those clauses for the APNs flow should be confirmed with Apple or validated by legal counsel.
Google FCMAndroid push notification deliveryGoogle global infrastructureNotification tokens are stored encrypted by EventOps (OVHcloud, France) and messages are transmitted directly to Google for delivery. Firebase Data Processing and Security Terms (section 10): EU–U.S. DPF for relevant certified Google entities and Standard Contractual Clauses (Controller-to-Processor and Processor-to-Processor modules) for other transfers outside the EEA.

Rose Code SAS does not sell or rent personal data to third parties. Disclosures may occur in response to a court order or applicable legal obligation.

International Data Transfers

The majority of data processed by EventOps remains within the EEA, hosted by OVHcloud in France. Transfers outside the EEA may nonetheless occur in the following cases:

  • Resend (United States): transfer governed by the EU–U.S. Data Privacy Framework (Resend is certified) and by the Standard Contractual Clauses adopted under Commission Decision 2021/914, Module 2 or Module 3 depending on the parties' roles. Both mechanisms operate independently and in a complementary manner.
  • Pusher (Bird): the primary cluster is located in Ireland (EEA), but transfers to affiliates or sub-processors located in the Netherlands, the United Kingdom or the United States are possible. Applicable safeguards: adequacy decision or EU–U.S. DPF depending on the destination; failing that, Standard Contractual Clauses (sections 9.1 to 9.3 of the Bird DPA), Controller-to-Processor or Processor-to-Processor modules depending on the client's role.
  • Apple APNs: iOS notification messages transit through Apple's global infrastructure. Notification tokens are stored encrypted in France (OVHcloud). Apple announces Standard Contractual Clauses for its international transfers. The exact scope of those clauses for the specific APNs flow used by EventOps should be confirmed with Apple or validated by legal counsel.
  • Google FCM: Android notification messages transit through Google's global infrastructure. Tokens are stored encrypted in France (OVHcloud). The Firebase Data Processing and Security Terms (section 10) provide for the EU–U.S. DPF for certified Google entities and Standard Contractual Clauses for other transfers outside the EEA.
  • All other providers (OVHcloud, PostHog EU): processing exclusively within the EEA.

Cookies, Trackers and Local Storage

Strictly Necessary Cookies

The following trackers are strictly necessary for the service to function. They are exempt from the consent requirement under CNIL guidelines. No consent banner is required for these trackers.

Cookie / StoragePurposeMaximum Duration
Auth.js sessionMaintaining the authenticated session30 days
CSRF cookieProtection against Cross-Site Request Forgery attacksSession duration
Post-login redirect cookieRedirecting to the original page after authenticationSession duration
Temporary OAuth cookiesManaging the authentication flow via a third-party providerSession duration
Language preference (local storage)Remembering the user's chosen languagePersistent
Local storage (interface and offline)Interface settings and offline functionalityPersistent

No advertising cookies, audience measurement cookies or social media cookies are set at this time.

Technical Diagnostics Tool (PostHog)

PostHog is integrated into the platform for technical error diagnostics. Its persistence is configured to in-memory only: no PostHog cookies are set. Automatic capture of page views, interactions and sessions is disabled. Only technical errors are collected.

In the future, EventOps plans to use PostHog to measure feature usage. This tracking is not yet active. This Policy will be updated before it is enabled.

Mobile Application Permissions

The mobile application may request access to the device camera or photo library to upload an avatar or a support request attachment. Biometrics (fingerprint, facial recognition) may be used to unlock a session locally on the device. Biometric data never leaves the device and is not transmitted to Rose Code SAS.

Data Retention

DataRetention Period
Active accountFor the lifetime of the account
Operational data of an active organisationUntil no member holds an active EventOps account in that organisation
Archived organisation (restorable)12 months from the date of archiving, then permanent deletion with at least 30 days' prior notice
Scheduled organisation deletionImmediate closure; data destruction at D+30 (cancellable during that period)
Audit log1,095 days (~3 years) from the event
IP address and user agent in the audit logAnonymised after 90 days
Security events365 days
Notifications90 days
Revoked devices180 days
Synchronisation log30 days
Support (attachments then anonymised ticket)30 days after ticket closure
GDPR rights exercise requests3 years after the final response (limited to elements necessary to evidence the processing)
Auth.js session30 days maximum
CSRF and session cookiesDuration of the session

Technical note: the retention period for archived organisations is set at 12 months in this Policy. The default value currently applied in the codebase is 1,095 days. A technical update and a transition process for existing archives are under way. At least 30 days' prior notice will be given to affected users before any purge is carried out.

Account Deletion

Deleting an account results in:

  • anonymisation of the global profile;
  • removal from all organisation memberships;
  • revocation of all active sessions;
  • deletion of certain local data on the mobile application.

Past operational contributions (operational logs, documents, messages) remain accessible to authorised members of the relevant organisations, with the author profile anonymised and displayed as "deleted member." This retention serves the operational traceability purpose that is central to the service.

Special cases:

  • Sole member of an organisation: deleting the account simultaneously triggers the closure and immediate purge of the organisation.
  • Last administrator of an organisation with other active members: account deletion is blocked until another active administrator has been designated within the organisation.

Operational traceability does not prevent the exercise of rights of rectification or erasure: every request is examined on a case-by-case basis.

Rights of Data Subjects

Under the GDPR, you have the following rights over your personal data:

  • Right of access (Article 15 GDPR): obtain a copy of the data held about you.
  • Right to rectification (Article 16 GDPR): have inaccurate or incomplete data corrected.
  • Right to erasure (Article 17 GDPR): request deletion of your data in cases provided for by the GDPR.
  • Right to restriction of processing (Article 18 GDPR): request that processing be suspended in certain circumstances.
  • Right to object (Article 21 GDPR): object to processing based on legitimate interests.
  • Right to data portability (Article 20 GDPR): receive your data in a structured, machine-readable format.
  • Right to withdraw consent (Article 7(3) GDPR): withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

How to Exercise Your Rights

Via the EventOps application: navigate to the "Privacy and Data" centre. Each request is recorded, assigned a reference number and acknowledged.

By email: privacy@eventops.fr — this channel is accessible even without an active account or after leaving an organisation, including for individuals mentioned in operational content who have not created an account.

Response time: we are committed to responding within one month of receiving your request. This period may be extended by a further two months in cases of complexity or a high volume of requests, with prior notice to the requester.

Lodging a Complaint with a Supervisory Authority

If you consider that the processing of your personal data does not comply with the GDPR, you have the right to lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés — www.cnil.fr) or with the competent supervisory authority in the EU Member State in which you habitually reside.

Personal Data Breaches

In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, Rose Code SAS will notify the CNIL within 72 hours in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to data subjects, those individuals will also be notified without undue delay in accordance with Article 34 GDPR.

Data Security

Rose Code SAS implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure. These measures include in particular:

  • encryption of sensitive data at rest;
  • password hashing;
  • availability of multi-factor authentication (MFA);
  • role-based access control;
  • audit logging.

Updates to This Policy

This Policy may be updated to reflect changes to the product, the processing activities carried out, or the applicable regulatory framework.

In the event of a material change, users will be informed by email or by an in-app notification within a reasonable period before the changes take effect.

Version 1.0 — 21 September 2026

Rose Code SAS — [REGISTERED ADDRESS] — SIREN [SIREN] — privacy@eventops.fr

For a request about your personal data: privacy@eventops.fr