Privacy Policy
This Privacy Policy explains how we — MYFAMBLISS GROUP LTD, the operator of EventBliss — collect, use, share and protect your personal data when you use our app (iOS and Android), our website event-bliss.com and the EventBliss marketplace. It also explains your rights under the EU General Data Protection Regulation (GDPR). EventBliss is built to be privacy-friendly: we process only what is needed to run the service, we do not sell your data and we do not show third-party advertising.
1. At a Glance
- We only process the data needed to run EventBliss — your account, your events and, if you buy Premium, your purchase data.
- Our database, authentication and file storage run on Supabase in the EU (Frankfurt, Germany).
- Payments are handled by Apple, Google and Stripe — we never see or store your full card details.
- AI features (receipt scanner, planning assistant, read-aloud) only transmit data while you actively use them — and never for advertising purposes.
- We do not sell personal data and we do not use third-party advertising or tracking networks.
- You can delete your account at any time in the app (Profile → Settings → Delete account) — see 'Account Deletion'.
2. Controller
Controller within the meaning of Art. 4(7) GDPR for all processing described in this policy is: MYFAMBLISS GROUP LTD is a company registered in the Republic of Cyprus. "EventBliss" is a brand and product of MYFAMBLISS GROUP LTD. We have not appointed a data protection officer, as we are not legally required to do so; for all privacy matters you can reach our team directly using the contact details below.
MYFAMBLISS GROUP LTD
Gladstonos 12-14, 8046 Paphos, Cyprus
Reg. No. HE 473088 · VAT ID CY60165018Q
3. What Data We Process
Depending on how you use EventBliss, we process the following categories of personal data. We collect them directly from you, from your device, or they arise from your use of the service:
- Account data
- Display name, email address, password (stored only as a salted cryptographic hash by our authentication provider), profile picture, language and notification preferences. If you sign in with Apple or Google, we receive your name (or a pseudonym), your (relay) email address and a technical account identifier from that provider.
- Event content
- Everything you and your guests create inside an event: event name, type, dates, location, guest list, tasks, schedules, polls and votes, chat messages, photo gallery uploads, expense entries and game results. Event content is visible to the other participants of that event.
- Purchase and payment data
- Your subscription status (Free, Premium, Lifetime), product identifiers, transaction and purchase tokens from Apple or Google, and — for web purchases — the data processed via Stripe (amount, currency, payment method type, last four card digits). Full card numbers are processed exclusively by the payment providers and never reach our servers.
- Receipt photos (expense scanner)
- If you use the receipt scanner in the expense feature, the photo you take and the recognised data (merchant, amount, date) are processed to pre-fill the expense entry. See 'Recipients and Processors' for the OCR provider involved.
- Usage data
- Which features you use and basic interaction events (e.g. event created, game started), crash reports and performance diagnostics. We use this to keep the app stable and to improve it — not to build advertising profiles.
- Device and log data
- IP address, device model, operating system and version, app version, browser type, time stamps of requests and — if you enable notifications — your push token. Server logs are kept for security and troubleshooting.
- Location data (optional)
- Only when you use map features (e.g. picking an event location): the map section you view and, if you grant the system permission, your approximate device location for centring the map. We do not create movement profiles and we do not track your location in the background.
- Read-aloud / audio (optional)
- When you use the read-aloud (text-to-speech) feature, the text to be spoken is transmitted to our speech provider to generate the audio. We do not access or record your microphone for this feature.
4. Purposes and Legal Bases (Art. 6 GDPR)
We process your data only for the following purposes and only on these legal bases:
Providing the EventBliss service: your account, event planning and collaboration, synchronisation across devices, marketplace bookings and customer support.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract (our Terms of Service).
Processing purchases and subscriptions (Premium, Lifetime, marketplace bookings), issuing receipts and preventing payment fraud.
Legal basis: Art. 6(1)(b) GDPR; for tax and commercial record-keeping additionally Art. 6(1)(c) GDPR.
AI-supported features: receipt text recognition (OCR), the AI planning assistant and text-to-speech output. Data is transmitted to the providers listed under 'Recipients and Processors' only at the moment you actively use the feature.
Legal basis: Art. 6(1)(b) GDPR — the feature is part of the service you request. Where required, we additionally ask for your consent (Art. 6(1)(a) GDPR).
Push notifications about your events (e.g. new messages, tasks or schedule changes).
Legal basis: Art. 6(1)(a) GDPR — your consent via the system permission dialog; revocable at any time in your device settings.
Security and abuse prevention: server logs, rate limiting, fraud detection, defence against attacks and enforcement of our Terms.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, trustworthy platform.
Compliance with legal obligations, in particular statutory retention periods for transaction and accounting records.
Legal basis: Art. 6(1)(c) GDPR.
5. Recipients and Processors
We share personal data only with the following recipients, only to the extent necessary, and — where they act as our processors — on the basis of data processing agreements pursuant to Art. 28 GDPR. Apple, Google, Stripe and Spotify act (partly) as independent controllers for their own services.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database, authentication and file storage — the technical backbone of the app | EU (Frankfurt, Germany) | Processor; DPA pursuant to Art. 28 GDPR; data hosted in the EU |
| Vercel | Hosting and content delivery of the website event-bliss.com | USA / global edge network | DPA with EU Standard Contractual Clauses (SCCs); EU-U.S. Data Privacy Framework |
| Stripe | Payment processing for purchases on the website (cards, Apple Pay, Google Pay, SEPA) | EU / USA | DPA with SCCs; certified under the EU-U.S. Data Privacy Framework |
| Apple | In-app purchases on iOS, Sign in with Apple, push notifications (APNs) | USA | Independent controller for purchases; EU-U.S. Data Privacy Framework |
| In-app purchases on Android (Play Billing), Google Sign-In, push notifications (FCM), Google Maps | USA | Independent controller for purchases; SCCs; EU-U.S. Data Privacy Framework | |
| RevenueCat | Subscription management and validation of in-app purchases (receives a pseudonymous user ID and purchase tokens) | USA | Processor; DPA with SCCs |
| OpenAI | Receipt OCR — receipt photos are transmitted for text recognition when you use the expense scanner | USA | Processor; DPA with SCCs; API data is not used to train models |
| OpenRouter | AI assistant — your input text is transmitted to generate planning suggestions | USA | Processor; DPA with SCCs |
| Mistral AI | Text-to-speech — generates the audio for the read-aloud feature | EU (France) | Processor; DPA pursuant to Art. 28 GDPR |
| Spotify | Music playback SDK — only if you use the OHRWURM music game and connect your own Spotify account | EU (Sweden) | Independent controller; Spotify's own privacy policy applies |
| Mapbox / Google Maps | Map display — your IP address and the requested map tiles are transmitted when a map loads | USA | DPA with SCCs; EU-U.S. Data Privacy Framework (Google) |
| Chatbase | Support chatbot on the website; processes the messages you enter in the chat | USA | DPA, SCCs |
| ALL-INKL.COM (SMTP) | Delivery of transactional and notification emails (e.g. booking confirmations, newsletter confirmation) | EU (Germany) | DPA (Art. 28 GDPR) |
Supabase
Database, authentication and file storage — the technical backbone of the app
Vercel
Hosting and content delivery of the website event-bliss.com
Stripe
Payment processing for purchases on the website (cards, Apple Pay, Google Pay, SEPA)
Apple
In-app purchases on iOS, Sign in with Apple, push notifications (APNs)
In-app purchases on Android (Play Billing), Google Sign-In, push notifications (FCM), Google Maps
RevenueCat
Subscription management and validation of in-app purchases (receives a pseudonymous user ID and purchase tokens)
OpenAI
Receipt OCR — receipt photos are transmitted for text recognition when you use the expense scanner
OpenRouter
AI assistant — your input text is transmitted to generate planning suggestions
Mistral AI
Text-to-speech — generates the audio for the read-aloud feature
Spotify
Music playback SDK — only if you use the OHRWURM music game and connect your own Spotify account
Mapbox / Google Maps
Map display — your IP address and the requested map tiles are transmitted when a map loads
Chatbase
Support chatbot on the website; processes the messages you enter in the chat
ALL-INKL.COM (SMTP)
Delivery of transactional and notification emails (e.g. booking confirmations, newsletter confirmation)
6. International Data Transfers
Where recipients are located outside the European Economic Area (in particular in the USA), we ensure an adequate level of data protection through: (a) the EU Commission's adequacy decision for the EU-U.S. Data Privacy Framework (Art. 45 GDPR) for certified providers, and (b) the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) including supplementary measures where required. Copies of the relevant safeguards are available on request via the contact details below.
7. Storage Periods
We store personal data only for as long as necessary for the respective purpose or as required by law:
- Account data
- Stored for as long as your account exists and deleted when you delete your account.
- Event content
- Deleted when you delete the event or your account; residual copies are removed from encrypted backups within 30 days.
- Payment and transaction records
- Retained for 6 years after the end of the relevant financial year, as required by the Cyprus Companies Law and tax legislation.
- Server and security logs
- Automatically deleted or anonymised after 30 days, unless a specific security incident requires longer retention.
9. Push Notifications
We send push notifications (e.g. new chat messages, tasks or schedule changes in your events) only if you allow them in the system permission dialog. Delivery is handled by Apple (APNs) on iOS and Google (FCM) on Android, which receive a technical push token for your device. You can revoke your consent at any time: on iOS under Settings → Notifications → EventBliss, on Android under Settings → Apps → EventBliss → Notifications — or simply disable individual notification types directly in the app.
10. Purchases, Subscriptions and Payment Data
In-app purchases (iOS/Android): Premium subscriptions and the Lifetime purchase are processed by Apple (App Store) or Google (Google Play) as independent controllers. We receive confirmation of the purchase and pseudonymous transaction data, but no payment details. RevenueCat validates purchases and manages the subscription status on our behalf. Web purchases: On event-bliss.com payments are processed by Stripe. Stripe processes your payment details in accordance with payment regulation; we only receive the result, the amount and a reference. We never store full card numbers; statutory retention duties apply to transaction records (see 'Storage Periods').
11. Account Deletion
You can delete your account directly in the app at any time: Profile → Settings → Delete account. This permanently deletes your account data and the events you own; copies in encrypted backups are purged within 30 days. Data subject to statutory retention duties (e.g. payment records, see 'Storage Periods') is blocked from any other use and deleted once the retention period expires. Alternatively, you can request deletion by emailing support@event-bliss.com from your account email address. Note: subscriptions purchased via Apple or Google must be cancelled separately in your App Store / Google Play subscription settings — deleting your account does not cancel them automatically.
12. Your Rights (Art. 15–21 GDPR)
You have the following rights regarding your personal data. To exercise them, an informal email is sufficient — we respond within one month at the latest (Art. 12(3) GDPR):
- Right of access (Art. 15 GDPR)
- You can request confirmation of whether and which data we process about you, and obtain a copy of that data together with the information listed in Art. 15.
- Right to rectification (Art. 16 GDPR)
- You can have inaccurate data corrected and incomplete data completed — most account data can be edited directly in the app.
- Right to erasure (Art. 17 GDPR)
- You can request the deletion of your data; the easiest way is the in-app account deletion (see 'Account Deletion').
- Right to restriction of processing (Art. 18 GDPR)
- In the cases listed in Art. 18 (e.g. while the accuracy of contested data is being verified), you can require us to restrict processing.
- Right to data portability (Art. 20 GDPR)
- You can receive the data you provided in a structured, commonly used, machine-readable format. Download it directly in the app under Profile → Settings → “Export my data”, or request the export by email to support@event-bliss.com.
- Right to object (Art. 21 GDPR)
- You can object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR. We will then stop processing unless compelling legitimate grounds prevail.
- Right to withdraw consent (Art. 7(3) GDPR)
- Where processing is based on your consent (e.g. push notifications), you can withdraw it at any time with effect for the future.
Right to lodge a complaint (Art. 77 GDPR): You may complain to a data protection supervisory authority, in particular in the EU member state of your habitual residence or place of work. The authority responsible for us is the Commissioner for Personal Data Protection of the Republic of Cyprus, 1 Iasonos Street, 1082 Nicosia, Cyprus — dataprotection.gov.cy.
13. Children and Minors
EventBliss is not directed at children. Creating an account requires a minimum age of 16 (or the lower age your member state has set for information society services, but never below 13). We do not knowingly collect personal data from children below this age. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
14. Data Security
We protect your data with technical and organisational measures pursuant to Art. 32 GDPR: TLS encryption for all data in transit, encryption at rest for the database and file storage, row-level security so that every user can only access their own events, role-based access controls for our team, the principle of least privilege for service keys, and regular review of our security measures. No system is 100% secure, but we work continuously to keep the risk as low as possible.
15. Changes to this Privacy Policy
We update this policy when our service, our providers or the legal situation change. The current version with the date stated above always applies; material changes will be announced in the app or by email. Earlier versions are available on request.
16. Contact
For any privacy questions or to exercise your rights, contact us at:
info@event-bliss.com