Legal
Privacy notice
Updated 23 September 2026
Controller
Event AI Grupa d.o.o., Trampov breg 60b, 51000 Rijeka, Croatia, OIB 23337460184. For any personal data question: careventai@gmail.com.
What we process
- Account data: email, name, interface language, hashed password (managed by Supabase Auth).
- Organisation data: name, OIB, outlet addresses, website, alert emails.
- Catalogue and prices: products and services, prices, anchor prices, price history and audit trail. This is not personal data, except the name of the user who made a change.
- Payment data: processed by Stripe; we only see subscription status and invoices, never card numbers.
- Technical data: for abuse protection we use a hash of the IP address (the address itself is not stored). For public price lists we count daily downloads without any personal data.
- Full automation request: the name, company, email, phone, website and message you enter in the form. We store them and email them to our team to reply with a quote.
- Sidro assistant (chat on the website and in the dashboard): your question and a few previous messages are sent to an AI model provider to generate the answer. We do not store the chat — it stays only in your browser until you close the tab. We only count how many questions, recognised needs and requests there were per day, with no personal data.
- Request from the Sidro assistant: if you send the form in the chat and tick the consent box, we store what you entered — name, company or project, email and/or phone, description of your need, deadline, budget and preferred meeting time — and email it to the Event AI Group team so they can contact you. Apart from the form, do not enter personal data in the chat.
Purpose and legal basis
Performance of the contract (Art. 6(1)(b) GDPR), legal obligations such as accounting (c), and legitimate interest in security and abuse prevention (f). Submissions from the public price list check are stored only if you leave your email. Automation requests are processed to take steps before entering into a contract (b); requests from the Sidro assistant on the basis of your consent (a), which you can withdraw by writing to careventai@gmail.com.
Processors
- Supabase (database and sign-in) — servers in the EU (Frankfurt).
- Vercel (application hosting) — functions run in the EU (Frankfurt), static content via a global network.
- Stripe (payments) — own privacy terms and standard contractual clauses.
- Resend (email delivery).
- OpenRouter — AI category suggestions (only on request; product names are sent) and the fallback model of the Sidro assistant.
- Google (Gemini API) — Sidro assistant answers; only the chat text is sent.
Cookies
We only use essential cookies: sign-in session, selected organisation and language. No advertising or third-party analytics cookies, so no consent is required. The merchant widget sets no cookies.
Retention
Account and organisation data are kept while the account is active and deleted within 30 days of a deletion request. Invoices are kept as required by law. IP hashes used for rate limiting are deleted after 24 hours.
Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. Send requests to careventai@gmail.com. You can lodge a complaint with the Croatian Personal Data Protection Agency (azop.hr).
Security
Traffic is encrypted (HTTPS). Integration credentials (e.g. WooCommerce keys, Shopify tokens) are stored encrypted with AES-256-GCM. API keys are stored only as hashes. Only the service’s servers can access the database.