Privacy Policy (EU)
Effective Date: 13 AUGUST 2026
We at Better Faster Oy (Business ID: 3483750-3) with its place of business at Pitkäjärventie 5 B, 02720, Espoo, Finland (“Service Provider”, “us” or “we”) understand the importance of data protection and are committed to keeping personal data secure and adhering to the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and all applicable data protection regulation. This privacy policy ("Policy") explains how we collect, process, and use user (“User” or “you”) data, when Users use the Eventplanner.ai tools and services ("Service").
To ensure that you are informed about how we process your personal data, please read the following Policy. By accessing or using the Service, you acknowledge and accept this Policy.
NOTE. This Policy only applies to User personal data that we process as a data controller, according to the GDPR, and it does not apply to User personal data or any other content which we process as a data processor on behalf of our customers, who act as data controllers, or to the any of our employment-related personal information.
Service Provider contact information:
Registered address: Pitkäjärventie 5 B, 02720, Espoo, Finland
Email: hello@eventplanner.ai
1. Data Controller
1.1
The Service Provider is the data controller (as described by the GDPR) of your personal data and responsible for determining the purpose and means of processing such data.
2. The Personal Data We Collect
2.1
We collect personal data that is necessary for providing, maintaining, securing, developing, and billing for the Service, generating the AI-powered content you request, providing support, sending service and (where consented) marketing communications, and fulfilling our legal obligations under applicable laws. We do not collect data belonging to special categories of personal data (such as health information), and users should not enter such data into the Service.
2.2
We may collect personal data belonging to the following categories:
Account data: Including name, email, username, and affiliated company.
Usage data: Including IP address, approximate location (country), browser and device information, time zone, language, service log records, and AI usage metering (token counts — not the content of your prompts).
Payment data: Including subscription plan, billing address, VAT/tax ID where applicable, and payment method details. Card details are provided directly to and held by our payment processor (Stripe); we never store card numbers.
Communication data: Including communications between you and the Service Provider, such as support requests or feedback that you provide to us.
AI features and your Input: The Service’s content-generating features are powered by third-party AI model providers (currently OpenAI, Anthropic, xAI, and Google; presentation rendering by Gamma). When you use these features, the event context you provide (“Input”) is transmitted to the applicable provider to generate output. We do not train AI models on your data, and our AI providers are contractually restricted from using your Input to train theirs. AI usage metering (token counts) is kept for billing; excerpts of failed generations are kept at most 30 days for debugging, with contact-detail redaction. We do not use your personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Article 22); AI features generate editable planning drafts under your control.
Cookies and tracking data: On first visit you can choose Essential only or Accept all. Analytics and marketing technologies run only if you accept: product analytics and session replay (PostHog, with input masking), and the Meta (Facebook) Pixel, used to measure our advertising. Strictly necessary technologies (login/session, in-app support messenger, security and region routing) do not require consent. You can change your choice at any time via the cookie settings in the Service, or by clearing your browser data for the site or contacting us.
3. How Personal Data Is Collected by Us
3.1
Where the Service Provider may collect personal data from:
Directly from You: As you directly provide data to the Service Provider (like when creating an account).
Your use of the Service: When you use the Service the Service provider may collect your usage and other data.
Company that hosts your use of the Service: When a company signs up for the Service, they may provide your personal data to the Service Provider, to invite you to the Service.
From Google: If you choose Google sign-in, we receive your email address and Google account identifier only.
4. Purpose And the Legal Basis for Processing (GDPR article 6)
Purpose of Processing:
Provide and maintain the Service
Legal basis:
Legitimate interest
Performance of a contract
***
Purpose of Processing:
Improve and develop the Service
Legal basis:
Legitimate interest
***
Purpose of Processing:
Provide and maintain the Service
Legal basis:
Performance of a contract
***
Purpose of Processing:
Non-marketing communications
Legal basis:
Legitimate interest
***
Purpose of Processing:
Marketing communications
Legal basis:
Consent
***
Purpose of Processing:
Comply with legal and contractual obligations
Legal basis:
Compliance with legal obligations
Performance of a contract
5. Who We May Disclose Personal Data To
5.1
In connection with our Service, we may disclose your personal data with third parties, as outlined below. We do not sell personal data. Our current subprocessor list, including processing locations, is available at eventplanner.ai/dpa#sub-processors and on request.
Affiliates: our affiliated US operating company (EventPlanner.ai Inc) for group administration; US users are served by that entity under the separate US Privacy Policy.
Business transfer: We may disclose personal data in connection to a merger, acquisition, asset sale, reorganization, or other business transaction or investment that involves the Service Provider or its affiliates.
Public authorities: We may disclose personal data to public authorities’, law enforcement, and others to comply with legal obligations, requests and demands from public authorities, or to protect our rights and the rights of others.
Professional advisors: We may disclose personal data to provisions advisors when necessary for them to provide services to us, including accounting, audit, legal, and other services.
Service providers: We may disclose personal data to third-party service providers for us to provide, maintain, and develop the Service. These service providers include, but are not limited to:
Amazon Web Services (hosting, EU region for EU users)
Intercom (support messaging)
Stripe (payment processing)
PostHog (product analytics, only with your cookie consent)
AI model providers (OpenAI, Anthropic, xAI, Google) and Gamma when you use AI features, and network/CDN services (Cloudflare)
6. Data Transfers
6.1
Due to the nature of our operations and the operations of our third-party service providers, your personal data may be processed between difference countries within the European Union (“EU”), when we carry out activities related to our Service and business. We host and process EU users’ service data in the European Union (AWS region Stockholm, Sweden). Some of our service providers — including the AI model providers, Gamma, Stripe, Intercom, and PostHog — process data in the United States or other countries outside the EU/EEA.
6.2
Where personal data is transferred outside the EU/EEA, we rely on: the EU–US Data Privacy Framework for providers certified under it, and EU Standard Contractual Clauses (Commission Decision 2021/914), with supplementary measures where appropriate. We maintain SCCs as a fallback even where DPF certification exists. You may request details of the safeguards for any specific transfer via the contact information outlined in the beginning of this Policy.
7. Security Measures
7.1
Keeping personal data secure is of utmost importance to us, and as such we employ commercially reasonable and industry-standard measures to safeguard your data. However, no method is entirely secure and accordingly, although we seek to protect your personal data that we hold, we cannot guarantee its absolute security.
7.2
Be aware that you are responsible for storing and protecting your log-in credentials and keeping access to your devices and account limited.
8. Data Retention
8.1
We retain personal data only as long as necessary for the purposes above, or as required by law (e.g. transaction records for accounting). You may delete your account at any time in the Service — it is deactivated immediately and no longer accessible. Deactivated accounts and deleted workspaces are archived for a maximum of 24 months (during which they can be restored on request), after which the personal data is permanently erased or irreversibly anonymized, except where retention is legally required. You may request erasure of your personal data at any time (see Your Rights below); we will erase it without undue delay and at the latest within 30 days of a verified request, except where retention is legally required.
9. Your Rights
9.1
You may exercise the following rights granted to you under the GDPR:
Right to Access: You may request to access a copy of your personal data.
Right to Data Portability: You may request to receive your personal data that we have collected, in a structured, commonly used, and machine-readable format. Also, you may request the transfer of this personal data to another controller.
Right to Erasure: You may request us to erase your personal data from our servers. Please remember that you may delete your account at any time.
Right to Object to Processing: You may request us to not process your personal data.
Right to Rectification: You may request the correction of inaccurate or incomplete personal data. Please remember that you may edit some of the personal data within your account after your account has been created.
Right to Restrict Processing: You may request to restrict the processing of your personal data.
Right to file a complaint: If you wish to report a complaint or contact a supervisory authority in relation to personal data processing, the competent supervisory authority in Finland is the Data Protection Ombudsman. Its contact details can be found at https://tietosuoja.fi/en/home.
9.2
To exercise your rights, contact us at hello@eventplanner.ai or using the contact information provided in the beginning of this Policy.
9.3
You may choose not to disclose personal data to us. Please be aware that if you choose to limit your disclosure of personal data to us, this may limit your use and access to the Service.
10. Children’s Personal Data
10.1
As described in our Terms of Service, our Service is not directed to children under the age of 18, and we do not knowingly collect or solicit personal data from them. Children under the age of 18 may not use the Services or send any personal data to us.
10.2
If you are a parent or legal guardian and you are aware that your child (under the applicable age of consent to data sharing) has provided us with personal data, please contact us at the contact information in the beginning of this Policy. If we learn we have collected personal data, from anyone under the age of consent to data sharing, without parental consent, we will take measures to remove such data from our files promptly.
11. Changes to the Policy
11.1
From time to time, we may update and make changes to the Policy. We will notify you of such update by email, to the email used to register for the Service, or by posting a notice on our Service, prior to the update becoming effective. By using our Service after updates to this Policy have been made, you agree to all the changes in the updated policy. We will post the updated version of this Policy on to our website with a revised “Effective Date”.