Privacy Policy
This Privacy Policy explains how Fomomento OÜ Processes Personal Data as a Controller in connection with the Fomomento website and Platform.
-
Controller and scope of this Policy
-
The Controller for the Processing described as Fomomento's own Processing in this Policy is Fomomento OÜ, registry code 17490570, with its registered office at Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Estonia (Fomomento).
-
This Policy applies to the public website at fomomento.events, public Event pages and widgets, the organizer-facing Platform, Account administration, direct support interactions and technical Processing for which Fomomento determines its own purposes and essential means.
-
This Policy does not apply to Event-related Personal Data that Fomomento Processes solely on behalf of an Organizer. In that context, the Organizer is the Controller and provides the applicable privacy information. Requests concerning such data should be directed to the Organizer. If Fomomento receives such a request and can identify the relevant Organizer, it will forward the request without undue delay.
-
Capitalised terms that are not defined in this Policy have the meanings given to them in the Terms of Service.
-
-
Privacy contact
-
Questions, requests and complaints concerning Fomomento's Processing may be sent to privacy@fomomento.events or by post to Fomomento OÜ, Tartu mnt 67/1-13b, Kesklinna linnaosa, 10115 Tallinn, Estonia.
-
Fomomento has not appointed a Data Protection Officer. The contact above is the designated contact point for data protection matters.
-
-
Personal Data and sources
-
Depending on the interaction, Fomomento may Process the following Personal Data as Controller:
-
identity and contact information, including name, email address, telephone number where provided, organization, role and business contact details;
-
Account and authentication information, including Account identifier, login or magic-link records, Team membership, permissions, language and other Account preferences;
-
business, billing and payment-configuration information, including company and registration details, address, tax or VAT identifiers, connected Stripe-account status, Fomomento application-fee and payout references and limited metadata needed to administer Fomomento’s relationship with the Organizer; Organizer bank-account and payment-instruction details are covered by this Policy only to the extent that they constitute Personal Data and Fomomento determines the purposes and essential means of their Processing;
-
Platform configuration and usage information associated with an Account or Organization, including a pseudonymised analytics identifier, feature usage, navigation paths, allowlisted interaction events, funnels, drop-off information and limited technical error metadata, to the extent that Fomomento determines the purposes and essential means of the Processing;
-
communications and support information, including the content of enquiries, support requests, complaints and related attachments;
-
acceptance and compliance evidence for Fomomento's own relationship and legal obligations, including the version and time of acceptance of the Terms and DPA, evidence that privacy information was made available or acknowledged, and any consent or other affirmative action for which Fomomento determines the purposes and essential means; and
-
technical, device and security information, including IP address, device and browser information, timestamps, session and authentication events, error context, security signals and activity logs.
-
-
Fomomento obtains Personal Data directly from the Data Subject, from an Organizer or Organization administrator that invites or authorises the person, from Stripe or another integrated provider, and automatically from the person's device and use of the website or Platform.
-
Where Fomomento obtains Personal Data indirectly for its own purposes, it provides the information required by Article 14 GDPR within the applicable period, unless a legal exception applies. In particular, where an Organizer or Organization administrator supplies a person's email address to invite that person as a Team Member, the invitation email or the first invitation screen provides this Policy or concise Article 14 information and a link to this Policy no later than that first communication.
-
Where information is required to create an Account, authenticate access, connect a payment account or meet a legal requirement, the relevant field or flow will identify it as required. If required information is not provided, Fomomento may be unable to create or secure the Account, provide the requested function or complete the relevant legal or payment process. Other information is optional unless the interface clearly states otherwise.
-
Fomomento does not store full payment-card details or hold proceeds from ticket sales. Card credentials and regulated payment information are submitted to and processed by Stripe under the terms and privacy information applicable to the Organizer's connected Stripe account and the payment method used. Where bank transfer is offered, the Buyer pays the Organizer directly using payment instructions supplied by the Organizer. Event-specific Order, pro forma, payment-status and refund data are Processed by Fomomento on the Organizer's behalf under the DPA.
-
-
Purposes and legal bases
-
Fomomento Processes Personal Data as Controller for the purposes and on the legal bases set out below.
Purpose
Processing activity
Legal basis
Enquiries and steps before an Organizer relationship
Responding to enquiries, arranging demonstrations, evaluating access to the beta and taking steps requested before a contract is concluded.
Article 6(1)(b) GDPR where the Data Subject would be the contracting Organizer; otherwise Article 6(1)(f), based on Fomomento's legitimate interest in developing business relationships.
Website and public Event-page delivery
Serving the website, public Event pages and widgets, remembering a requested language, generating technical delivery logs and protecting public interfaces against abuse.
Article 6(1)(f) GDPR, based on Fomomento's legitimate interests in making the website and public Event functionality available, maintaining security and preventing abuse.
Account creation and Platform access
Creating and administering an Account, authenticating Users, managing an Organization and its Team Members, recording acceptance of the Terms and delivering the core Platform functionality.
Article 6(1)(b) for an Organizer who is a natural person; Article 6(1)(f) for representatives and Team Members, based on Fomomento's and the Organizer's legitimate interests in administering the business relationship and authorised access.
Product analytics and Platform improvement
Measuring how Organizer Account holders and Team Members use the authenticated Organizer portal, including feature usage, navigation paths, funnels, drop-off and technical errors, and using the results to develop and improve the Platform.
Article 6(1)(f) GDPR, based on Fomomento's legitimate interests in understanding use of the Platform and developing and improving its functionality, subject to data minimisation, pseudonymisation and an opt-out.
Service and transactional communications
Sending authentication links, invitations, security notices, service updates and other messages necessary for the relevant Account or Platform interaction.
Article 6(1)(b) GDPR where the communication is necessary for a contract with the Data Subject; otherwise Article 6(1)(f), based on Fomomento's legitimate interest in administering the Account, authorised access and operational communications.
Payment-account and bank-transfer configuration
Connecting and administering an Organizer’s Stripe account, administering any Fomomento application fee, and administering bank-transfer configuration to the extent that it contains Personal Data for which Fomomento acts as Controller.
Article 6(1)(b) GDPR where the Data Subject is the contracting Organizer; otherwise Article 6(1)(f), based on Fomomento's legitimate interest in operating the selected payment functionality and administering the Organizer relationship.
Accounting, tax and corporate compliance
Issuing and retaining accounting records, documenting transactions and complying with statutory obligations applicable to Fomomento OÜ.
Article 6(1)(c) GDPR, to the extent that Processing is necessary for compliance with obligations under applicable Estonian accounting and tax laws.
Support and correspondence
Responding to support requests, diagnosing a reported issue and retaining relevant correspondence where needed to document its handling.
Article 6(1)(b) GDPR where support is necessary for a contract with the Data Subject; otherwise Article 6(1)(f), based on Fomomento's legitimate interest in responding, diagnosing the issue and documenting its handling; Article 6(1)(c) only where law requires Fomomento to handle a particular request.
Security, service integrity and abuse prevention
Maintaining logs, authenticating access, detecting errors or abuse, protecting Accounts and investigating incidents.
Article 6(1)(f) GDPR, based on the legitimate interests of Fomomento, Organizers and Users in ensuring the security, integrity and proper operation of the Platform and preventing abuse; and Article 6(1)(c) GDPR where Processing is necessary to comply with a legal obligation, including obligations concerning the security of Personal Data.
Legal claims and enforcement
Establishing, exercising or defending claims, enforcing the Terms and responding to lawful requests from authorities.
Article 6(1)(f) and, where disclosure or retention is legally required, Article 6(1)(c) GDPR.
Data protection and regulatory compliance
Fulfilling Fomomento's legal obligations under data protection law, including responding to Data Subject requests and documenting compliance with the GDPR.
Article 6(1)(c) GDPR.
-
Where Fomomento relies on Article 6(1)(f) GDPR, the relevant legitimate interests include administering and improving the contractual relationship, enabling authorised business collaboration, securing the Platform, preventing fraud and abuse, maintaining evidence of actions and communications and protecting legal rights. Fomomento considers the nature of the data, the context of the relationship, reasonable expectations and available safeguards before relying on those interests.
-
-
Recipients and disclosures
-
Fomomento discloses Personal Data only where necessary for the purposes described in this Policy or where disclosure is required or permitted by law.
-
Recipients may include providers of hosting, databases, authentication, content delivery, security, email and business mailboxes, electronic signatures, error monitoring, product analytics, payments, venue-address or time-zone lookup, customer support and accounting; legal, tax and other professional advisers; an Organizer and authorised Team Members; courts, regulators and public authorities; and a successor in connection with a lawful corporate transaction.
-
Annex I identifies providers used in connection with Fomomento's own Processing as Controller.
-
Stripe Connect direct charges are created on the Organizer's Standard connected Stripe account. Stripe and the Organizer have a direct relationship, and Stripe may act as an independent Controller for payment, identity-verification, fraud-prevention and legal-compliance purposes. For Fomomento's own Processing, Fomomento receives only information necessary to administer the connected integration, its application fee and its legal obligations. Fomomento does not hold ticket-sale funds. Event-specific Order, payment-status and refund data, including equivalent records for bank-transfer Orders, are Processed for the Organizer under the DPA rather than for Fomomento's own purposes.
-
-
International transfers
-
Core application and database services are configured in the European Economic Area. Some providers operate globally or are established outside the European Economic Area, and remote access or onward Processing may therefore constitute a transfer to a third country.
-
Where a recipient is not covered by an applicable adequacy decision, Fomomento relies on appropriate safeguards, such as the relevant European Commission standard contractual clauses, and adopts supplementary measures where required by the circumstances of the transfer. Where a recipient validly participates in the EU-US Data Privacy Framework and the relevant transfer falls within that certification, the transfer may be based on the applicable adequacy decision.
-
Fomomento assesses the recipient's identity, role, location and transfer mechanism and reviews available supplier documentation proportionately to risk. A copy of the relevant safeguard or information about how to obtain it may be requested using the contact details in section 2, subject to permitted redactions.
-
-
Retention
-
Fomomento retains Personal Data only for as long as necessary for the purpose for which it was collected, including the period required to provide the Platform, comply with law, resolve disputes and establish, exercise or defend claims. Different records are subject to the following periods or criteria.
Category
Retention period or criterion
Prospective-Organizer enquiries
For the period needed to handle the enquiry and, where necessary, for a subsequent period determined by the applicable limitation period or the need to document the response.
Account and Organization administration data
For the duration of the Account and ordinarily for up to 30 days after closure in active systems, except for records retained under another row. A protected backup copy may remain for up to the additional rolling backup period described in section 7.
Terms, consent and compliance records
For the duration of the relevant relationship and afterwards for the applicable limitation period or another shorter documented period appropriate to the purpose and risk. Records are deleted earlier where they are no longer necessary to demonstrate the relevant acceptance, consent or compliance decision.
Accounting and tax records
For the period required under applicable Estonian accounting or tax laws, depending on the type of record.
Payment and Stripe Connect metadata
For the Account relationship and, where the metadata forms part of an accounting, tax, dispute or claim record, for the period applicable to that record.
Support and correspondence
Until the matter is closed and afterwards only for as long as reasonably necessary to document the response or establish, exercise or defend a claim.
Product analytics data
For up to 12 months from collection, after which identifiers are deleted and the remaining information is deleted or irreversibly aggregated, unless a shorter period is selected or retention is required to investigate a documented security or legal issue.
Server, security and diagnostic logs
Ordinarily approximately 90 days, unless a particular record is required for an active security investigation, legal obligation or claim.
-
When a retention period expires, Fomomento deletes or anonymises the relevant Personal Data unless a longer period is required by law. Where active-system deletion is completed within a stated period, a protected copy may remain in routine backups until it is overwritten in the ordinary rolling backup cycle. Routine database and object-storage backups are currently created daily and retained for up to seven days; they are not available for ordinary use and may be restored only for recovery or legal-compliance purposes.
-
-
Security
-
Fomomento applies technical and organisational measures appropriate to the risk, including access restrictions, authentication and session controls, encryption in transit and, where appropriate to the risk and relevant functionality, encryption at rest, logical segregation, backups, logging, incident response and supplier management.
-
No method of transmission or storage is completely secure. Fomomento reviews and updates its measures in light of risk and will notify affected Data Subjects and the competent authority where required by Data Protection Law.
-
-
Data Subject rights and complaints
-
Subject to the conditions and exceptions in the GDPR, a Data Subject may request access to and a copy of Personal Data, rectification, erasure, restriction of Processing and data portability.
-
A Data Subject may object at any time, on grounds relating to that person's particular situation, to Processing based on Article 6(1)(f) GDPR. Fomomento will stop the Processing unless it demonstrates compelling legitimate grounds that override the person's interests, rights and freedoms or the Processing is needed to establish, exercise or defend legal claims.
-
Where Fomomento relies on consent, the Data Subject may withdraw it at any time without affecting the lawfulness of Processing before withdrawal.
-
Where Fomomento has reasonable doubts concerning the identity of the person making a request, it may request additional information necessary to confirm that person's identity. Fomomento will provide information on the action taken without undue delay and in any event within one month of receiving the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. Fomomento will inform the person of the extension and the reasons for it within one month of receiving the request.
-
A rights request may be sent to privacy@fomomento.events.
-
A Data Subject has the right to lodge a complaint with a competent supervisory authority if that person considers that the Processing of their Personal Data infringes the GDPR or other applicable Data Protection Law.
-
-
Cookies and similar technologies
-
The website and Platform may store information on or access information from a User's device only in accordance with applicable law.
-
At the date of this Policy, Fomomento uses only technologies necessary to authenticate Users, maintain security, provide a language choice and deliver functionality expressly requested by the User. The current categories are described below.
Category
Provider
Purpose
Duration
Authentication and session storage
Fomomento / Supabase
Authenticating the User, maintaining an authorised session and protecting access
Session or the configured session lifetime
Language preference
Fomomento
Remembering the language selected by the User
Until changed or cleared by the User, subject to the configured expiry
Security and anti-bot storage or signals
Fomomento / Cloudflare
Detecting abuse, protecting forms and maintaining Platform security
For the period technically necessary for the relevant security function
-
Consent is not required to the extent that storing or accessing information is strictly necessary to transmit a communication or provide a function expressly requested by the User and applicable law permits its use without consent. Fomomento nevertheless provides the information required by law. Other technologies will be activated only after any required consent has been obtained.
-
A User may clear or block cookies and local storage through browser settings, but doing so may prevent authentication, language preferences or other requested functions from operating correctly.
-
-
Analytics and automated decision-making
-
Fomomento uses PostHog in the authenticated Organizer portal to analyse how Organizer Account holders and Team Members use Platform features, including allowlisted interaction events, navigation paths, funnels, drop-off and limited technical errors, for the purpose of developing and improving the Platform. The subsequent Processing of Personal Data for this purpose is based on Fomomento's legitimate interests after an assessment of the purpose, necessity, reasonable expectations, impact and safeguards. Where the implementation stores information on, or accesses information from, a User's device, it is activated only after any consent required by applicable electronic-communications law has been obtained.
-
Organizer-portal analytics uses pseudonymised identifiers and is configured not to collect names, email addresses, registration answers, special-category data, Organizer Content, full URLs or query strings containing tokens, or Personal Data relating to Buyers, Attendees, Orders or tickets. Session replay, form-content capture and advertising profiling are not used. An Organizer Account holder or Team Member may withdraw any device-access consent through the available preference control and may opt out of the analytics or object to the subsequent Processing using the contact details in section 2.
-
On public Buyer surfaces, Fomomento uses only server-side aggregate operational measurement. No PostHog browser software or other analytics technology is loaded on the User's device for this purpose, no persistent or daily user identifier is assigned, and the measurement is not linked to a Buyer, Attendee, Order or ticket.
-
Fomomento does not make decisions based solely on automated Processing that produce legal effects concerning a person or similarly significantly affect that person within the meaning of Article 22 GDPR.
-
-
Children
-
Organizer Accounts and Team access are intended for persons acting in a business or professional capacity and are not intended for children. If an Organizer offers an Event to children or collects their Event-related Personal Data, the Organizer remains responsible for the applicable privacy information and lawful basis, and Fomomento Processes that Event-related Personal Data on the Organizer's behalf.
-
-
Changes to this Policy
-
Fomomento may update this Policy to reflect changes in Processing, the Platform, providers or law. The current version and last-updated date will be published with the Policy.
-
Where a change materially affects Processing connected with an Account or requires fresh consent, Fomomento will provide appropriate advance information by email, through the Platform or another Durable Medium and will obtain any consent required before the changed Processing begins.
-
Before further Processing Personal Data for a purpose other than the purpose for which it was obtained, Fomomento will provide the Data Subject with information about the new purpose and any other relevant information required by Article 13(3) or Article 14(4) GDPR and will establish the applicable lawful basis before the further Processing begins.
-
Annex I. Providers
This Annex identifies providers relevant to the Processing of Personal Data for which Fomomento acts as Controller. Each provider name links to its privacy policy. A provider may also support Processing carried out by Fomomento on an Organizer's behalf under the DPA. The scope of a provider's involvement depends on the specific service and data flow.
|
Provider |
Function |
Processing location |
|
Database, authentication and file storage |
Primary data stored in Ireland; support or administration may occur globally |
|
|
Server and application hosting |
Production deployment in Amsterdam; provider documentation also identifies processing operations in the United States |
|
|
CDN, WAF, Turnstile, Workers and R2 object-storage backup |
Global network; R2 backup bucket configured in the European Union |
|
|
Account and transactional email delivery |
EU sending infrastructure in Ireland; metadata or logs may be processed in the United States and authorised provider locations |
|
|
Electronic signatures and contract workflow |
United States and other locations described by the provider |
|
|
Error monitoring and crash diagnostics |
Configured EU region in Germany; support or administration may occur elsewhere |
|
|
Product analytics for the authenticated Organizer portal |
European Union hosting selected; PostHog, Inc. is established in the United States and authorised support or Sub-processors may operate elsewhere |
|
|
Connected-account, payment, payout and payment-status functionality |
EEA and other locations described by Stripe |
|
|
Server-side venue-address formatting, search and time-zone lookup |
EEA and other locations described by Google |
|
|
Business email used for privacy, support and legal communications |
Switzerland and authorised provider locations |