Why Happenee

Security & Privacy

Event data,handled like enterprise data

Happenee runs events for banks, telcos, public institutions and media, where how data is stored, processed and proven matters as much as what the software does. Here’s how we protect it.

Book a demo 30-minute call.
Tailored to your events.

Certifications & data protection

Compliant by design, not by exception

ISO/IEC 27001 certified

Information security managed under a certified information security management system.

More information

GDPR compliant

Built and operated to meet EU data protection requirements as a data processor.

EU data residency

All data is stored and operated within EU territory.

We don’t sell your data

We never sell the personal information of customers or their attendees to third parties.

DPA available

A Data Processing Agreement sets out roles, obligations and processing terms for customers.

Sub-processor transparency

We maintain a list of sub-processors (including Microsoft Azure), available to customers on request.

Infrastructure & encryption

Encrypted in transit, encrypted at rest, hosted in the EU

AES encryption at rest

All stored data is encrypted using AES. Access to encryption keys is restricted to minimal staff.

256-bit TLS in transit

All traffic to the website and APIs is served over TLS with a 256-bit SSL certificate.

Microsoft Azure, EU

Cloud service hosted on Microsoft Azure, with infrastructure operated within the EU.

More on Azure security and Azure compliance.

Application security & operations

Tested, monitored and built to keep running

Built and maintained in-house

Web and mobile apps are developed, tested, deployed and maintained in-house, not outsourced.

Penetration testing

OWASP Top Ten scans, automated pentesting via Indusface Apptrana, plus independent manual penetration testing.

Backups & disaster recovery

Daily full and incremental backups, with a documented, step-by-step disaster recovery plan.

99.5% uptime commitment

A defined availability commitment, with routine vulnerability scans against production servers.

Current service status on status.happenee.com.

Access control & logging

Access to systems, data and keys is restricted on a need-to-know basis. System and infrastructure access is logged.

For financial-sector customers

Supporting your DORA obligations

For regulated financial customers, Happenee acts as an ICT third-party service provider. The obligation under DORA is yours, but where our service is in scope, our posture is built to support it.

EU data residencyData stored and operated within the EU.
Availability & SLAA defined 99.5% uptime commitment.
Incident notificationWe notify affected customers of relevant security incidents.
Audit & access rightsContractual provisions for information and audit access.
Operational continuityDocumented backups and disaster recovery.
Sub-processor transparencyA maintained, available sub-processor list.
Exit provisionsDefined terms for return and deletion of data on exit.

Responsible disclosure

Found a vulnerability? We’d like to hear from you. We don’t currently run a public bug bounty program, but we review every report.

E-mail security [at] happenee.com See also our Privacy policy, Terms of use and DPA.

Run your events on a platform you can trust

ISO/IEC 27001 certificate

The certificate exists in two language versions. They carry the same number and validity, and each states the certified scope in its own wording.

Certified organization
Happenee s.r.o., company ID 042 16 202
Certificate number
1046/2024/SC/BI
Issued by
Systémové certifikace s.r.o., accredited certification body No. 3209
Validity
10 June 2024 to 9 June 2027 (issued 10 June 2024)
Statement of Applicability
1 April 2024, version 1
Scope, English certificate
“Event platform, organization and realization” (ISO/IEC 27001:2022)
Scope, Czech certificate
„Zajištění nástrojů, organizace a realizace eventů“ (ČSN EN ISO/IEC 27001:2023)