GDPR-Compliant Event Marketing Software, Hosted in the EU

Speaker banners, attendee sharing and conversion tracking are personal-data processing, so here is exactly what DynaPictures stores, where, and what it never asks for. Frankfurt hosting, hashed IP addresses, no attendee email, a Data Processing Agreement on request.
GDPR-Compliant Event Marketing Software, Hosted in the EU
Ask for the DPA before you sign up if your review needs it first.

What Is Stored, What Is Not

Hosted in Frankfurt, Germany

The application, the database and the generated banners run on infrastructure in Frankfurt. Short links and the pixel endpoint run on the same stack.

IP Addresses Are Never Stored Raw

A visitor's IP address is hashed with SHA-256 for deduplication and used once, in memory, to resolve a country and city. The raw address is discarded. The same applies to the browser's user agent.

Attendees Are Never Asked for an Email

The attendee widget collects a name and, optionally, a job title, company and photo. There is no email field and no consent screen to design because nothing is collected that needs one.

Speaker Data Is What You Import

Name, job title, company, email and the columns you choose from your own spreadsheet, plus the photo they upload on their share page. Used to generate their banner and send their link; nothing else.

How Tracking Works Under GDPR

First-Party Tracking, Hashed Identifiers

First-Party Tracking, Hashed Identifiers

Every share mints a short link. A click on it records a hashed IP, a hashed user agent, a coarse browser family, a country and city, and the referrer. Bot traffic from crawlers and link scanners is classified and kept out of your reports. There is no third-party tracking on the share page or the widget.

SHA-256 hashes, raw values discarded
Country and city, not coordinates you can act on
Crawler traffic marked, never counted

The Conversion Pixel Is First-Party and Minimal

The Conversion Pixel Is First-Party and Minimal

The pixel on your ticket page stores one attribution id in the browser's local storage, with a cookie mirror so subdomains can read it, and reports the order id, value and currency you pass. It is not cookie-free, and we say so; it is first-party, single-purpose and does not build a profile.

One identifier, thirty-day window
No cross-site tracking
Debug mode that records nothing

Speakers and Attendees Keep Control

Speakers and Attendees Keep Control

A speaker's share page shows what you imported and lets them change the fields you mapped. A photo they upload replaces the one you had. Attendees using the widget store nothing until they generate and share; opening the widget alone records only an anonymous impression.

Names stored only on a deliberate share
Links can be revoked per person
Delete the campaign and its funnel rows go with it

For Your Data Protection Review

Data Processing Agreement

A DPA under Art. 28 GDPR is available on request. Ask before signing up if your process requires it first.

Processors You Should Know About

Payment through FastSpring; transactional email through a European email service; geo lookup with a locally hosted database, so no IP address leaves our servers for it. The full list comes with the DPA.

Retention Is Tied to the Campaign

Funnel rows (views, shares, clicks, conversions) live as long as the campaign. Deleting the campaign deletes them. There is no automatic purge schedule beyond that yet, which is why we say so here.

German-Speaking Support and Interface

The product interface, the share page and the widget are available in German, and so are we. The German version of this page speaks to DSGVO terms directly.

Privacy by Design, in Practice

A First-Party Pixel With One Purpose

Local storage plus a cookie mirror on your own domain, one attribution id, a thirty-day window. Documented so it goes straight into your cookie notice, and it loads after consent like any other tag.

Frame-Based Cropping, No Biometrics

Headshots are cropped to the frame you designed. No face recognition, no photo analysis, no avatars, nothing that would trigger a biometric assessment.

Minimal Attendee Data

A name and an optional photo, stored only when someone deliberately generates and shares. No email field exists, so there is nothing to ask consent for.

Every Decision Inspectable

The pixel has a debug mode that shows each step it takes and records nothing, so your developer or DPO can verify the behaviour instead of trusting a dashboard.

See It on Your Own Event

Twenty minutes with a demo campaign, or start free and import your first list today.

Related Pages

The hub with the full comparison, the other pages in this group, and the parts of the product they rely on.

Frequently Asked Questions

On infrastructure in Frankfurt, Germany: the application, the database, the generated images, the short links and the pixel endpoint.