Skip to main content
eBrainGo
  • Home
  • Features
  • Pricing
  • Video Guides
  • Contact
Get Started

eBrainGo Privacy Policy

Effective date

Effective date: July 2026 · Last updated: July 24, 2026

1. Overview & Data Protection Roles

This Privacy Policy describes how eBrainGo ("we", "us", "our", platform accessible via ebraingo.com), operated by eBrain Technology Group GmbH, collects, processes, and protects personal data in compliance with the EU General Data Protection Regulation (GDPR / DSGVO) and applicable German data protection laws (BDSG).

Data Roles

Event Attendee Data: When you register for or attend an event managed via eBrainGo, the Event Organizer (our client) acts as the Data Controller. eBrainGo operates as the Data Processor acting strictly under the Controller’s instructions and Data Processing Agreements (DPA).

Organizer Account & Website Data: For tenant administrators, client business contacts, billing profiles, and visitors to our public website, eBrainGo acts as the Data Controller.

Contact for Data Protection

  • Provider — eBrain Technology Group GmbH, Gesellschaft mit beschränkter Haftung (GmbH / Limited Liability Company), HRB 271443 B (Registered at the Local Court / Amtsgericht Charlottenburg, Berlin)
  • Email — info@ebraingo.com
  • Address — Wilmersdorfer Straße 138-140, 10585 Berlin, Germany

2. Data We Collect

We process personal data only to the extent necessary to deliver high-quality event experiences, mobile application features, and platform services.

A. Account & Profile Data

Identity and professional details: Full name, professional email address, job title, and company or organization name.

Optional profile details: Profile biography, headshot photo, contact details, and social media handles, if provided by the user.

B. Event Activity & Engagement Data

Agenda & Bookmarks: Saved sessions, personal schedules, and session attendance.

Networking & Matchmaking: Profile interests, connection requests, meeting schedules, and Smart Matchmaking AI recommendations.

Interactions: Live poll responses, Q&A submissions, and message content in community feeds or one-to-one attendee chats.

Badge & Check-in Data: QR code scans at check-in desks, session entry gates, or exhibitor booths.

C. Technical & Telemetry Data

  • IP address, device type, operating system version, app version, unique device identifiers.
  • Push notification tokens (for event announcements and schedule reminders).
  • System logs, timestamped activity, and crash reports.

D. Billing & Payment Data

Payment cards, billing contact details, and transaction history.

Note: All payment processing is securely handled by Stripe. eBrainGo does not store or process raw PCI credit card numbers directly.

3. Legal Basis for Data Processing (Art. 6 GDPR)

We process personal data based on the following legal grounds under Article 6(1) GDPR:

  • Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill contract obligations, activate tenant accounts, issue tickets, deliver app functionality, and process payments.
  • Legitimate Interests (Art. 6(1)(f)): Processing necessary for platform security, fraud prevention, service reliability, user analytics, and system optimization.
  • Consent (Art. 6(1)(a)): Processing based on explicit user consent for push notifications, location/camera access for QR scanning, marketing communications, and optional exhibitor lead retrieval scanning.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with statutory tax, commercial, and financial record retention laws (e.g., German HGB / AO).

4. Data Sharing & Sub-Processors

eBrainGo does not sell, rent, or trade personal data to third parties. We share data only with vetted sub-processors necessary to run the platform under strict Data Processing Agreements:

  • Cloud Infrastructure — AWS: Application hosting, database storage, and tenant isolation in the EU Region (Germany/Frankfurt).
  • Payment Gateway — Stripe Payments Europe Ltd.: Automated billing, invoicing, and subscription management in the EU and globally (PCI-DSS Level 1).
  • Push Notifications — Apple APNs / Google FCM: Mobile push alerts for session reminders and event updates in the EU and USA (EU Standard Contractual Clauses).
  • AI Features — IONOS AI Models / IONOS AI Processing Services: Smart Matchmaking, AI Concierge, content recommendations, and AI-assisted event discovery in the EU Region; customer personal data is not used for AI model training unless expressly agreed.

AI Processing with IONOS Models

eBrainGo uses IONOS AI Models and IONOS AI Processing Services to support optional AI-powered platform features, including Smart Matchmaking, AI Concierge responses, content recommendations, and AI-assisted event discovery. Where these features process personal data, eBrainGo limits processing to the minimum data necessary to provide the requested functionality and applies contractual, technical, and organizational safeguards consistent with GDPR requirements.

Customer event data, attendee profiles, prompts, messages, and interaction data processed through IONOS-powered AI features are used only to deliver the relevant eBrainGo service and are not used by eBrainGo or IONOS to train or improve general-purpose AI models unless the Event Organizer has expressly agreed to such use in writing. AI processing is performed in the EU region where available, and any international transfer, if required, is protected through appropriate safeguards such as Data Processing Agreements and EU Standard Contractual Clauses.

5. Attendee Privacy & Networking Visibility

Attendee Directory: By default, attendees participating in event networking are visible in the event’s attendee directory. Attendees can toggle their directory visibility or adjust privacy settings at any time within their app profile.

Exhibitor Lead Scanning: When an attendee permits an exhibitor or sponsor to scan their physical or digital badge QR code, the attendee explicitly consents to sharing their profile contact details directly with that exhibitor.

6. Data Retention & Erasure

Event Data: Event attendee data is retained for the duration specified by the Event Organizer (Data Controller) or until the conclusion of the contract term.

Account Data: Organizer account details are stored for the duration of the subscription agreement.

Statutory Retention: Financial records, tax invoices, and transaction logs are retained for up to 10 years in compliance with statutory commercial and tax retention requirements (HGB/AO).

Data Deletion: Following contract termination or an organizer’s request, tenant data is securely deleted or anonymized within 30 days, unless statutory preservation duties apply.

AI Processing Data: Personal data processed through IONOS-powered AI features is retained only for as long as necessary to provide the requested AI functionality, maintain security and audit logs, or comply with contractual and legal obligations. AI prompts, outputs, and related processing logs are deleted or anonymized according to the applicable event retention configuration and are not retained for general AI model training unless separately agreed.

7. Data Subject Rights (EU / GDPR)

Under GDPR Articles 15–22, users have the following rights regarding their personal data:

  • Right to Access (Art. 15): Request a copy of personal data processed by eBrainGo. Attendees can use the in-app "Download My Data" tool to export their profile and activity data instantly.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request permanent deletion of personal data using the in-app "Forget Me" self-service button or by contacting support.
  • Right to Rectification (Art. 16): Update or correct inaccurate personal information.
  • Right to Restrict or Object (Art. 18/21): Restrict processing or object to legitimate-interest processing.
  • Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format (JSON/CSV).
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a competent Data Protection Supervisory Authority (e.g., Berliner Beauftragte für Datenschutz und Informationsfreiheit).

8. Security Measures (Art. 32 GDPR)

eBrainGo employs state-of-the-art technical and organizational security measures (TOMs):

  • Full TLS/HTTPS encryption for all data in transit.
  • AES-256-bit encryption for data at rest.
  • Multi-tenant architecture with strict database and storage isolation for each event client.
  • Role-Based Access Control (RBAC) and strict employee access auditing.
  • Regular security vulnerability scans and automated backup routines.

9. Cookies & Local Storage

Essential Cookies: Required for user authentication, session security, and basic web application functions.

Performance & Functional Storage: Used to store user preferences, such as language choice and dark or light theme.

No Third-Party Ad Trackers: eBrainGo does not deploy third-party advertising or cross-site tracking cookies.

10. Changes to This Privacy Policy & Contact

We may update this Privacy Policy from time to time to reflect operational changes or statutory updates. The current version will always be published within the app and website.

For questions, DPA requests, or privacy inquiries:

  • General Support — info@ebraingo.com
  • Address — eBrain Technology Group GmbH, Wilmersdorfer Straße 138-140, 10585 Berlin, Germany

eBrainGo

  • Features
  • Pricing
  • Video Guides
  • About Us
  • Contact
  • Support
  • FAQs
  • Privacy Policy
  • Terms of Service

© 2026 eBrainGo. All rights reserved.