Legal
Sub-processors and external recipients
Only the German version is legally binding. Switch the site language to Deutsch to read it.
Translation for information purposes. Only the German version is legally binding.
This list is Annex 3 to the Data Processing Agreement and at the same time the named list referenced in clause 10 of the Privacy Policy. Changes are notified at least 30 days in advance under § 5.2 DPA.
1. In use
| Provider | Legal entity | Service | Data processed | Location | Transfer basis | Status |
|---|---|---|---|---|---|---|
| Amazon Web Services | Amazon Web Services EMEA SARL, Luxembourg (EU region) · Amazon Web Services, Inc., USA (US region) | hosting, object storage, database; delivery of images over a content delivery network (section 1.1) | all event and account data, image files | Storage and processing: EU: Frankfurt (eu-central-1) · US: Northern Virginia (us-east-1). Delivery: additionally edge locations in the United States, Canada, Europe and Israel | Storage, processing and deletion take place exclusively in the chosen data region. For delivery, images are cached transiently outside the EU as well (section 1.1); the basis is the AWS DPA with SCC and, where the USA is involved, the EU-US DPF adequacy decision. | ✅ |
| Google Ireland Limited / Google LLC, USA | AI photobooth: analysis of the shot, costume suggestions, image generation (Gemini API) | booth shot, guest's text input | mostly USA — including for data region EU | EU-US DPF adequacy decision (where certified) + SCC | ✅ | |
| Cloudflare | Cloudflare, Inc., USA · Cloudflare Germany GmbH | bot protection (Turnstile) on the photobooth and the email-sending forms | verification token, IP address, browser signals | USA / global | EU-US DPF adequacy decision + SCC | ✅ |
1.1 Delivery of images (content delivery network)
We deliver an event's images over Amazon's content delivery network (CloudFront). So that they arrive quickly and reliably everywhere, they are cached transiently at edge locations in the process — outside the EU as well. For the delivery of images the footprint is limited to the United States, Canada, Europe and Israel.
That caching exists only while the event is running. When the event ends we purge the cache; after that, nothing can be retrieved by this route.
The stored copy of an image does not leave the data region chosen at booking. The data region determines where an image is stored, processed and deleted — not every place a byte is briefly held for delivery.
For the marketing website and the applications' program files (JavaScript, stylesheets, website imagery) we use the same network with a larger footprint. Those files contain no personal data.
2. Planned
| Provider | Legal entity | Service | Data processed | Location | Transfer basis | Status |
|---|---|---|---|---|---|---|
| Stripe | Stripe Payments Europe, Ltd., Ireland (Stripe, Inc., USA as group company) | payment processing, tax determination, invoicing data; PayPal as a payment method inside Stripe | name, email, billing address, country, amount, payment method | EU / USA | Stripe DPA with SCC; EU-US DPF | ⏳ |
| Email delivery service | not yet selected | delivery of one-time codes, key recovery, booking confirmations, deletion notices | email address, message content | preferably EU | DPA with SCC where a third country is involved | ⏳ |
3. Removed
| Provider | Legal entity | Service | Location | Status |
|---|---|---|---|---|
| fal.ai | Features and Labels, Inc., USA | automatic image enhancement (denoise, sharpen, upscale) | USA | ❌ — removed on 30 July 2026 and no longer part of the system. This provider was never activated; no data was ever transmitted to it. |
4. Non-recipients
We use no:
- analytics, statistics or audience-measurement services
- advertising networks, retargeting, conversion pixels
- external font, icon or script services, third-party content delivery networks
- social-media plugins, embedded videos or maps
- customer data platforms, CRM tracking, session recording
- data brokers
The marketing website and all applications load files exclusively from our own servers and over our own delivery network (section 1.1). The sole exception is the bot-protection module in section 1; it is declared as such in the central storage registry.
5. Internal recipients
| Recipient | Access | Basis |
|---|---|---|
| Management and staff | internal console: business metrics, event and account master data, codes, redemptions, partner data | access only via an explicitly configured address list; confidentiality undertaking |
| Tax advisers | invoicing and booking data | legal obligation, professional secrecy |
| Legal advisers | as required | legitimate interest, professional secrecy |
Binding language version
Only the German version of this document is legally binding. Versions in other languages are provided for information purposes only. In the event of any discrepancy, the German version prevails.