Security, GDPR & Compliance
Protecting your data is at the heart of our mission. Since 2013, Digitevent has supported more than 3,000 clients in managing their professional events. We know that trust is built on concrete commitments to security, compliance, and transparency.
GDPR & Data privacy
A dedicated DPO oversees our compliance. You remain the sole owner of your data, never used commercially.
A dedicated DPO at Digitevent oversees and guarantees Digitevent's compliance with the GDPR (General Data Protection Regulation) and answers your questions about data protection.
You remain the exclusive owner of all data you import or collect via Digitevent. We act as a data processor on your behalf to provide the service.
Your data is never sold, rented, or shared for commercial purposes. It is used only to provide the service you have subscribed to.
Digitevent makes it easy to respond to your attendees' requests to exercise their rights: right of access, right to rectification, right to erasure, and right to data portability.
Every data change is logged with its context, timestamp, and the user involved, ensuring full auditability of your event.
The platform includes granular consent controls: cookie management, opt-in/opt-out for communications.
The list of our sub-processors is available on request. A Data Processing Agreement (DPA) is available and can be incorporated into your contractual framework. All our sub-processors undergo regular security and data protection checks.
Access control & Authentication
SSO authentication via SAML2 (Azure AD, Google Workspace, Okta). Four permission levels and least privilege principle.
Digitevent supports SAML2 SSO (Single Sign-On) authentication for integration with your identity providers: Azure AD, Google Workspace, Okta, and others.
Access to data and features is strictly limited to what each role needs. Five permission levels are available: observer, manager, supervisor, administrator, and event owner
Password complexity requirements are enforced: minimum length, special characters, and secure renewal. We recommend using password managers and enabling two-factor authentication via SSO to strengthen security.
The back office can be accessed by passkey: your device's fingerprint, facial recognition, or passcode, or a physical security key (such as a YubiKey). An additional, phishing-resistant sign-in method that complements SSO and password login without replacing them.
Regular access reviews are carried out to ensure that each Digitevent team member has only the rights required for their role.
Hosting, infrastructure & Business continuity
Data hosted on AWS in France. Multi-node replication, anti-DDoS protection, and encrypted backups.
All our clients' data is hosted on Amazon Web Services (AWS), in data centers located in France with redundancy across the European Union. No sensitive data is transferred outside the EU. The AWS data centers are themselves certified ISO 27001, SOC 2, and PCI DSS.
Multi-node replication to ensure availability in the event of hardware failure. Automatic load balancing across multiple servers to maintain stability, including during traffic spikes. Built-in anti-DDoS protection and an availability commitment above 99.9% (SLA).
Data is backed up automatically. Backups are encrypted and stored in environments isolated from production. All environments are regularly tested to ensure fast data restoration whenever needed.
Digitevent has documented and tested business continuity plans (BCP) and disaster recovery plans (DRP). The redundant multi-node infrastructure enables automatic failover in the event of a failure.
Encryption & Data protection
Communications encrypted via HTTPS/TLS 1.2+ and data at rest protected by AES-256.
All communications between your browser and our servers are encrypted via HTTPS / TLS 1.2+. No data ever travels in plain text.
Stored data is protected with AES-256 encryption, the standard used by financial and government institutions.
Passwords are hashed server-side using robust cryptographic algorithms. They are never stored in plain text and are inaccessible to our teams.
Encryption keys are stored securely and rotated regularly. They are managed according to industry best practices.
Operational security
Regular penetration testing, annual ISO 27001 audits, continuous monitoring, and incident response procedures.
Penetration tests are performed regularly by independent auditors to identify and fix potential vulnerabilities before they can be exploited.
As part of our ISO 27001 certification, our information security management system is audited every year by an independent certification body.
Automated and manual security tests are built into our development process, allowing vulnerabilities to be detected as early as the design and coding phases.
Our infrastructure is continuously monitored to quickly detect and respond to any anomaly or intrusion attempt.
Digitevent has a documented and tested incident response procedure. In the event of a security incident affecting your data: detection by our monitoring systems, assessment by the security team, prompt notification (in line with GDPR requirements and those of the relevant data protection authority), immediate remediation, and a post-mortem to prevent recurrence.
All Digitevent employees sign a security charter committing them to comply with our data protection and information security policies. Security and data protection awareness sessions are held regularly for the whole team, covering everyday security best practices, personal data protection and GDPR, and secure development for technical teams.
Frequently asked questions
Every organizer must ensure attendee consent, data traceability, and compliance with the rights of access, rectification, and erasure. A Data Processing Agreement (DPA) with your event platform is essential. Digitevent has built these mechanisms in natively since 2017: granular consent management, a record of processing activities, a dedicated DPO, and an available DPA. You remain the exclusive owner of all data collected, which is never sold or shared with third parties.
The choice of hosting is a key compliance factor: attendees' personal data must remain in a jurisdiction offering an adequate level of protection. At Digitevent, all data is hosted on Amazon Web Services (AWS), in data centers located in France with redundancy across the European Union. No data is transferred outside the EU. The AWS data centers are themselves certified ISO 27001, SOC 2, and PCI DSS.
ISO 27001 certification is the international benchmark for information security: it guarantees that the vendor applies a security management system that is audited and continuously improved. Regular penetration testing by independent auditors and data encryption (TLS in transit, AES-256 at rest) are also essential. Digitevent holds ISO 27001 certification, audited every year, and submits its infrastructure to regular external penetration tests.
A secure event platform must encrypt data at every level: in transit (HTTPS / TLS 1.2+) and at rest (AES-256). Passwords must be hashed with robust algorithms and never stored in plain text. Digitevent applies all of these standards. Backups are also encrypted and kept in isolated environments, and encryption keys are rotated regularly.
The GDPR requires that any data breach be reported to the competent authority within 72 hours, and that affected individuals be informed as soon as possible. Your platform must therefore have a documented and tested incident response procedure. Digitevent continuously monitors its infrastructure, notifies clients within the regulatory timeframe, and conducts a post-mortem after every incident to prevent recurrence.
This is a major point of concern. Since the invalidation of the Privacy Shield (the Schrems II ruling), any data transfer to the United States requires additional safeguards (standard contractual clauses, a transfer impact assessment). Using European hosting considerably simplifies compliance. Digitevent hosts 100% of its data in France and the EU, eliminating the risks associated with transatlantic transfers.
Contact
For any questions regarding security or data protection:
+3000 event plannersuse Digitevent for their events!





