Privacy Policy
Last updated 2026-07-19
This policy explains what 2u.events collects, why, and what we do with it. It describes how the service actually works — we run no advertising, no analytics and no tracking cookies, and we do not sell or share personal data with advertisers.
Who we are
2u.events is operated by Behind Software Group S.R.L., a company registered in the Republic of Moldova ("we", "us").
For questions about this policy or your data, contact us at privacy@2u.events.
What we collect, and why
We keep the set of data deliberately small. Each item below exists for a stated purpose; nothing is collected "just in case".
- Organizer account — your email address, organization name, interface language, and a cryptographic hash of your password (we never store the password itself). Purpose: to create and operate your account. Basis: performance of our contract with you.
- Sign-in sessions — a random token is placed in your browser; we store only its hash and its expiry. Purpose: to keep you signed in. Basis: performance of our contract.
- Email confirmation — a single-use token, stored hashed, valid for 48 hours. Purpose: to confirm you control the address. Basis: contract and security.
- Events you create — the name, description, dates, type and other details you enter. Purpose: to run your event. Basis: performance of our contract.
- Assistant conversations — what you type into the AI event-setup assistant, and the drafts it produces. Purpose: to generate your event setup. Basis: performance of our contract at your request.
- Anti-abuse signals — your IP address, browser user-agent, browser language and a short technical signal derived from your browser, combined and stored only as an irreversible hash for a brief period. Purpose: to stop automated abuse of the assistant, which costs us money to run. Basis: our legitimate interest in keeping the service available and affordable.
Drafts stay in your browser
Before you register, the event draft you build with the assistant is stored in your own browser (local storage), for up to 120 days. It is not kept on our servers.
It becomes data on our side only when you create an account, at which point the draft is turned into a real event in your workspace. You can discard it at any time with "Start over", or by clearing your browser storage.
Who else processes your data
We use a small number of service providers. They act on our instructions and are not permitted to use your data for their own purposes.
- DigitalOcean — hosting. Our server is located in Frankfurt, Germany (EU).
- Brevo — sending transactional email, such as your confirmation message.
- Cloudflare — Turnstile, the invisible check that protects the assistant from automated abuse.
- Anthropic — the AI model that generates the assistant's replies. What you type into the assistant is sent to it in order to produce a response.
- DevTeam.Games — the event engine operated within our own group, where your events, registrations and results are stored.
International transfers
Our servers are in the EU. Some providers above may process data outside the European Economic Area. Where that happens, the transfer is covered by appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
How long we keep things
- Account data — until you ask us to delete your account.
- Sign-in sessions — 30 days, or until you sign out.
- Email confirmation links — 48 hours, and they are destroyed once used.
- Anti-abuse hashes — minutes to hours; they expire with the rate-limiting window and are not retained afterwards.
- Unregistered drafts — up to 120 days, in your browser, under your control.
Your rights
If you are in the EU or UK, you have the right to access your data, correct it, delete it, receive a copy in a portable format, restrict or object to processing, and to withdraw consent where processing is based on it.
Write to privacy@2u.events and we will respond within one month. You also have the right to complain to your national data protection authority.
Events you organize
When you run an event and collect data about your participants, you decide what to collect and why — you are the controller of that data, and we process it on your behalf as your provider. You are responsible for having a lawful basis and for telling your participants how you use their information.
Security
Passwords are stored using PBKDF2 with a per-account random salt. Session and confirmation tokens are stored only as hashes, so the stored values cannot be replayed. Traffic is encrypted in transit with TLS.
No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authority as required by law.
Changes
If we change this policy in a way that materially affects you, we will tell you before the change takes effect. The date at the top always reflects the current version.