Unlike other geographical areas, Europe has legislated to protect the personal data of European citizens.
The security of our customers' data is therefore a top priority at AppCraft Events.
Your data is therefore stored in France, protected by French and European legislation.
We also conduct an annual security audit to ensure the security of our systems.
In addition, we are open to penetration testing by our clients' IT departments.
For example, we took early steps to ensure the security of your data by migrating our data, initially hosted by AWS (an American hosting provider), to OVH (a French hosting provider) for reasons of digital sovereignty.
To guarantee sovereignty and GDPR compliance, we have opted for 100% French hosting, on OVHcloud's secure data centers in Gravelines and Roubaix.
With OVH, our customers are not subject to the US Cloud Act , unlike event management solutions hosted in France but by American companies such as AWS (Amazon Web Services) or Microsoft Azure (even though these companies have data centers in France, they cannot escape US legislation).
Be wary of false promises regarding GDPR compliance—and choose sovereign solutions instead!

The GDPR requires complete transparency regarding the use of personal data.
Your guests must be clearly informed of the purpose of the data collection (registration, personalization, post-event communication, etc.) and give their explicit consent (opt-in) before their data can be used.
AppCraft offers very clear, unambiguous registration forms that allow your participants to easily withdraw their consent.
All the tools that AppCraft provides to event organizers to facilitate opt-ins are powerful levers for increasing participant trust and loyalty.
• GDPR compliance is now integrated into corporate governance, just like security and risk management.
AppCraft keeps a daily record of data processing and trains its teams in best practices.
Ask your AppCraft project manager or our DPO for advice dpo [at] appcraft.fr
• The GDPR has transformed data collection into a relationship of trust with participants. Organizers must prioritize relationships and avoid profiling or data resale practices
For your event project, put us in touch with your DPO Data Protection Officer
• Modern event tools such as AppCraft include dedicated features
– activity log,
– highly granular rights management by profile,
– access measurement and traceability,
– reports available in https,
– data purging 2 months after the event
– right to be forgotten, etc.
to facilitate compliance while enabling a smooth user experience.
In a strict regulatory environment, we make data protection a strategic asset, not a constraint:
• Granular Consent & Invisible Mode: Respect everyone's privacy. Your participants decide what information they share (email, phone number) and can activate "Invisible Mode" to browse the app without being solicited, giving them back full control over their visibility.
• Right to be forgotten: Simple tools allow users to manage their data, ensuring GDPR compliance "by design" and strengthening trust in your organizing brand.




