Privacy & Data Protection Policy

This policy explains how Bloomsy processes personal data in compliance with Regulation (EU) 2016/679 (GDPR) and applicable laws of the Slovak Republic and the European Union.

1. Introductory provisions

The controller of personal data is Codexio s.r.o. (the “Controller”).

The Bloomsy service is an online platform intended for creating digital events, generating QR codes, and temporarily collecting photos and videos from event participants.

The Controller processes personal data in accordance with Regulation (EU) 2016/679 (GDPR), Act No. 18/2018 Coll. on Personal Data Protection, and other generally binding legal regulations of the Slovak Republic and the European Union.

2. Definitions

„Controller“ - Codexio s.r.o..

„Data subject“ - a natural person whose personal data are processed.

„Event owner“ - an individual or legal entity that orders the Bloomsy service.

„Guest“ - a person uploading content through a QR code, link, or password.

„Personal data“ - data as defined in Article 4(1) GDPR.

„Content“ - photographs, videos, and other audiovisual files uploaded to the system.

„Processing“ - any operation performed on personal data as described in Article 4(2) GDPR.

„Web“ - the public website available at https://bloomsy.eu.

3. Controller identification

Controller:
Codexio s.r.o.
Lachova 1602/9
851 03 Bratislava V
Company ID: 55761631
VAT ID: SK2122079135

Contact for data protection matters: privacy@bloomsy.eu

The Controller is not required to appoint a data protection officer under Article 37 GDPR, as the legal thresholds for such appointment are not met.

4. Data subjects and scope

The Controller processes personal data mainly of:

  • event owners,
  • event guests,
  • website visitors.

The categories of personal data include:

  • identity data (name, surname, company name),
  • contact data (email address, phone number),
  • billing and contractual data including registered office address, company ID, tax ID, VAT ID, order identification, amount, and currency,
  • technical data (IP address, user-agent, system logs),
  • uploaded audiovisual content (photos, videos).

The Controller does not intentionally process special categories of data under Article 9 GDPR; however, such data may appear in content uploaded by data subjects, and the event owner is responsible for their inclusion.

5. Processing principles and purposes

The Controller processes personal data lawfully, fairly, and transparently in line with the principles outlined in Article 5 GDPR, especially purpose limitation, data minimization, storage limitation, integrity, and confidentiality.

Data are processed solely for predefined and legitimate purposes related to providing the Bloomsy service, its operation, technical prevention, communication with users, fulfilling legal obligations, and protecting the Controller’s legitimate interests.

The Controller only handles data that are adequate, relevant, and necessary and does not process them in ways incompatible with the stated purposes.

When the relevant legal basis is met, data subjects are informed about news, service changes, or marketing notices on the basis of consent or legitimate interest, and they may refuse such sending.

5a. Roles of the Event owner and Guests

When processing Event owner data for order, payment, invoicing, and account management purposes, Codexio s.r.o. acts as the controller.

When storing and making available content uploaded by Guests within a specific event, the Event owner may determine the purpose and scope of processing. In such cases, Codexio s.r.o. provides the technical platform and processes content to the extent necessary to provide the service, and may act as a processor in relation to the Event owner. Where the Event owner is a business, this processing is governed by the Data Processing Agreement, which the Event owner accepts at checkout.

The Event owner is the person deciding the purpose of the specific event and inviting guests to it; guests upload content based on settings chosen by the Event owner.

6. Purposes and retention

The Controller ensures that personal data are not stored longer than necessary for the purposes for which they are processed, in accordance with the GDPR’s storage limitation principle.

Data processed for providing the service, managing events, and enabling content uploads are retained for the duration of the relevant event or for the duration of the contractual or similar relationship established by ordering the service.

Billing and accounting data are stored for the periods required by specific laws, in particular accounting and tax legislation, typically at least 10 years.

Technical and security-related records (logs, abuse protection data) are kept only as long as needed to ensure system security and reliable operation.

Audiovisual content is removed from active storage within 14 days after the event is archived. Once deleted, the content cannot be restored.

Once the retention periods expire, personal data are securely deleted or anonymized, unless further storage is required by law or the Controller’s legitimate interest.

7. Legal basis and recipients

Processing is based on contract performance, consent, legitimate interest, or legal obligation.

We share data only with authorized processors necessary to operate the service.

  • Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) - infrastructure & hosting.
  • Cloudflare (Inc., 101 Townsend St, San Francisco, CA 94107, USA) - Cloudflare R2 object storage. We prioritize processing and storage within the EU where the selected service and technical setup allow it. If transfers to third countries occur, appropriate safeguards under GDPR are applied.
  • Mailgun Technologies (Inc., 112 E Pecan St #1135, San Antonio, TX 78205, USA) - transactional email delivery (EU endpoint).
  • Zoho Corporation B.V. (Beneluxlaan 4B, 3527 HT Utrecht, The Netherlands) - customer support mailbox/email communication.
  • Stripe Ireland Ltd (1 Grand Canal Street Lower, Dublin 2, Ireland) - payment processing. Payment card data is processed by Stripe. We do not have access to full payment card details.
  • Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) - traffic analytics via Google Analytics. Processed only after the user gives consent.
  • Chatwoot Inc. - customer support via live chat widget. Processed only after the user gives consent.

For the Meta Pixel, Meta Platforms Ireland Ltd is not a processor but a joint controller - see section 7b.

7a. Purpose, legal basis and retention

The following overview maps each processing purpose to the data used, the legal basis under Article 6(1) GDPR, and the retention period. It supplements, and does not replace, sections 6 and 7.

Purpose Data used Legal basis Retention
Providing the service, managing events and the user account identity, contact, uploaded content, technical data Art. 6(1)(b) - performance of the contract for the duration of the event and the contractual relationship
Billing, accounting and tax compliance identity, billing and order data Art. 6(1)(c) - legal obligation typically at least 10 years (Slovak accounting and tax law)
Security, abuse prevention and service stability technical data, system logs Art. 6(1)(f) - legitimate interest in the security of our network and information systems and in preventing misuse only as long as needed for security and reliable operation
Handling support requests identity, contact, message content Art. 6(1)(b) or Art. 6(1)(f) - legitimate interest in answering enquiries until the request is resolved and a short follow-up period
Sending service and product news to existing customers contact data Art. 6(1)(f) - legitimate interest in direct marketing to existing customers (with a right to object at any time), or Art. 6(1)(a) - consent where required until you object or unsubscribe, or the customer relationship ends
Traffic analytics and advertising measurement (Google Analytics, Meta Pixel) usage data, online identifiers Art. 6(1)(a) - consent (withdrawable at any time) as set out in the cookie policy, up to 24 months
Establishing, exercising or defending legal claims relevant data from the purposes above Art. 6(1)(f) - legitimate interest in the defence of legal claims until the applicable limitation periods expire

Where the legal basis is legitimate interest (Art. 6(1)(f)), we have assessed that our interest is not overridden by your interests or fundamental rights. You may ask for details of that assessment and object at any time (see section 12).

7b. Meta Pixel - joint controllership

For the collection and transmission of data through the Meta Pixel, Codexio s.r.o. and Meta Platforms Ireland Ltd (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) act as joint controllers within the meaning of Article 26 GDPR, on the basis of the Meta Controller Addendum. We are jointly responsible for informing you and for obtaining your consent; Meta is solely responsible for the further processing of the data on its own systems. You can exercise your data-subject rights against either party - requests concerning Meta's own processing are handled by Meta. This processing only takes place after you consent via the cookie banner.

8. International transfers

The service is accessible globally, while personal data are processed in compliance with the GDPR and typically kept within the EU.

Some recipients are based in or process data in the United States (Cloudflare, Mailgun, Google, Meta). Transfers to them are based on:

  • the European Commission's adequacy decision for the EU-US Data Privacy Framework, where the recipient is certified under that framework; or
  • the European Commission's Standard Contractual Clauses together with supplementary technical and organizational measures, where it is not.

You can request a copy of the safeguards applied to a specific transfer at privacy@bloomsy.eu.

When data are otherwise accessed from third countries, the Controller implements appropriate safeguards in line with Chapter V GDPR.

9. Security incidents

The Controller has procedures for detecting, assessing, and reporting data breaches in accordance with Articles 33 and 34 GDPR.

Affected individuals and the supervisory authority are notified without undue delay when GDPR requires it.

10. Content visibility and responsibility

Content is private and available exclusively to persons designated by the event owner.

The event owner must obtain the necessary consents from individuals depicted in photos, videos, or other audiovisual recordings; the Controller is not liable for any omissions.

11. Artificial intelligence and minors

Content is not used for training artificial intelligence or for marketing purposes; any future use would require a separate explicit consent.

The ordering and management of an event is intended for persons aged 18 and above; this concerns the capacity to enter into the contract.

The age at which a child can validly consent to an information-society service under Article 8 GDPR varies by country - 16 in Germany, Hungary, Poland and Slovakia, 15 in the Czech Republic, 14 in Austria. Guests may use the upload functionality only where they have the legal capacity or the appropriate consent required under applicable law. Where a guest is below the applicable Article 8 age, or where minors appear in uploaded content, the event owner is responsible for securing a lawful basis other than the child's own consent.

12. Data subject rights

We do not carry out automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects them within the meaning of Article 22 GDPR.

Under the GDPR, individuals have the following rights:

  • the right of access to personal data processed about them,
  • the right to correct inaccurate or supplement incomplete data,
  • the right to erasure (“right to be forgotten”) when the GDPR conditions are met; this does not affect obligations to retain data under specific laws,
  • the right to restrict processing in legally defined cases,
  • the right to data portability when statutory conditions are satisfied,
  • the right to object to processing carried out on the basis of the Controller’s legitimate interest,
  • the right to information about automated decision-making, including profiling, if such processing occurs,
  • the right to withdraw consent at any time when processing is based on consent; withdrawal does not affect the lawfulness of prior processing.

These rights apply even when personal data were not obtained directly from the data subject.

Exercising these rights may be limited to the extent permitted or required by specific laws (e.g., the obligation to keep accounting records for at least 10 years).

Submit requests to privacy@bloomsy.eu; we respond within 30 calendar days.

13. Supervisory authority

Individuals may lodge complaints with the supervisory authority:

Office for Personal Data Protection of the Slovak Republic
Galvaniho Business Centrum II, Galvaniho 7/B
821 04 Bratislava
Slovak Republic
Phone: +421 2 3231 3214
Website: dataprotection.gov.sk/uoou

You may also lodge a complaint with the supervisory authority of the EU Member State of your habitual residence or place of work, in particular: the Federal or competent State Data Protection Authority (Germany), the Datenschutzbehörde (Austria), the Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH (Hungary), the Prezes Urzędu Ochrony Danych Osobowych – UODO (Poland), or the Úřad pro ochranu osobních údajů (Czech Republic).

14. Final provisions

This Privacy Policy is effective from the date of publication. The Controller reserves the right to update or change this Policy at any time, especially due to changes in legal regulations, the scope of data processing, or service functionality.

The current version is always available on the Bloomsy service website.

Last updated: May 26, 2026