Privacy Policy

Last updated 12 September 2026

Two roles, one policy

Chynora is a platform organisations use to run events: creating an event, inviting guests through single-use links that can be passed forward, and messaging the people who register. Depending on who you are, we relate to your personal data differently:

  • If you have a Chynora account — you organise or help run events — Part A applies to you. We decide why and how your account data is processed, so we are the data controller.
  • If someone invited you to an event and you registered — you have never signed up for Chynora yourself — Part B applies to you. The organisation running the event decides what is asked and who is contacted; we process it on their behalf as a data processor.

Sections after Part B apply to both.

Part A — organisers and members

1. Who is responsible for this policy

For the data covered by this Part, the controller is David Bešter, an individual established in Slovenia. You can reach us at contact@chynora.com. We have not appointed a data protection officer — our processing does not reach the scale or nature (large-scale monitoring, or large-scale special-category data) that would require one.

2. Information we collect about organisers and members

Chynora’s only sign-in method is Google. When you sign in, we receive your name, email address, Google account identifier and profile picture from Google — we never ask for or store a password. We keep a profile, your organisation memberships and role, and basic usage information needed to run the Service.

3. Information we collect about invitations you send

When you invite someone to join your organisation, we store the invitee’s email address and the state of that invitation (sent, accepted, revoked) as a record of who invited whom into the organisation.

4. Why we process this information

  • To provide the Service and authenticate you — necessary to perform our contract with you (GDPR Article 6(1)(b)).
  • To keep the Service secure and working — preventing abuse, debugging problems, and enforcing the Terms of Use — on the basis of our legitimate interest in operating a secure and reliable service (Article 6(1)(f)); we have considered this against your interests and consider it justified given the limited data involved.
  • To send you service-related email about your account or organisation — necessary to perform our contract with you (Article 6(1)(b)).

5. Your rights

Subject to the conditions in applicable law, you can ask us to: give you access to your personal data, correct it, delete it, restrict how we use it, receive a portable copy of it, or object to processing based on our legitimate interests. To exercise any of these, email contact@chynora.com; we will respond within one month as required by GDPR Article 12(3). You can also complain to Slovenia’s supervisory authority, the Informacijski pooblaščenec, Dunajska cesta 22, 1000 Ljubljana, Slovenia (gp.ip@ip-rs.si), or to the supervisory authority in your own EU country of residence.

Part B — event guests

6. If you were invited to someone’s event

You did not sign up for Chynora — someone running an event sent you (or someone in your chain of invitations) a link, and you registered. That organisation decides what its registration form asks, who it invites, and what it sends you; we process the data it collects only on its instructions, as a processor. If you want to know what an organisation holds about you, correct it, or have it deleted, please contact that organisation directly — they are best placed to act quickly and are the ones who decide. If you contact us instead at contact@chynora.com, we will forward your request to the relevant organisation and assist as required by law.

7. What we collect when you register

When you complete a registration form, we store your email address, first and last name, and — if the organiser’s form asks for it — your date of birth and answers to whatever other questions the organiser chose to include. We also store the review status the organiser gives your registration, its attendance status, and any comments an organiser leaves internally about it.

8. The invite chain

Chynora records which invitation link your registration came from, and which onward invitation links were minted from it. This “invite chain” lets the organisation see how its guest list grew, apply limits on how far a chain can spread, and revoke a branch of it if needed. We keep this graph intact even if a guest asks to have their personal details removed, so that other guests’ links keep working — see “Security” below for how we handle that.

9. Emails and delivery records

Registering for an event triggers automated emails (such as a confirmation), and the organisation may separately send broadcasts to some or all of its guests. For each message we keep a delivery record: your email address, the subject line, delivery status, and a copy of the message content that was sent, so the organisation can see what was communicated and we can diagnose delivery problems.

10. Sensitive information

Chynora does not ask any organisation to collect health, dietary, religious, disability, biometric or similarly sensitive information, and does not need it to provide the Service. If an organisation’s form asks for this kind of information anyway (for example, a dietary requirement field), that is the organisation’s choice and its responsibility to have your explicit consent to ask for it — our Terms of Use require this of every organisation.

11. Children

Chynora accounts are for adults running events. Event guests can be of any age where the event itself is appropriate for them; where an organisation’s registration form is directed at, or likely to be completed by, someone under 15 (the digital age of consent under Slovenian law), the organisation is responsible for ensuring a parent or guardian has given or authorised the necessary consent before the data is submitted.

12. Who processes this data, and where

We use a small number of infrastructure providers to run Chynora, each acting under a contract that limits what they may do with the data:

  • Vercel Inc. (United States) — hosts the Chynora application.
  • Supabase Inc. — provides our database, authentication and file storage.
  • Plus Five Five, Inc. (Resend) — delivers the emails Chynora sends, using the chynora.com sending domain.
  • Cloudflare, Inc. — provides DNS for our domains.

Google LLC is not one of our processors — when you sign in with Google, or when we send email through a Google-hosted inbox, Google acts as an independent controller under its own privacy policy for the parts of that exchange it controls.

13. International transfers

Some of the providers above may process data outside the European Economic Area, including in the United States. Where that happens, we rely on the European Commission’s adequacy decision for the EU–U.S. Data Privacy Framework and/or the Commission’s Standard Contractual Clauses, as applicable to each provider, to ensure your data continues to receive an equivalent level of protection.

14. Retention

We keep organiser account data for as long as the account is active, and for a limited period afterwards where needed for security, accounting or legal reasons. We keep Guest Data for as long as the organisation running the relevant event needs it, or as required to comply with a legal obligation, resolve a dispute, or enforce our agreements — after which it is deleted or anonymised. An organisation can ask us to delete an event’s Guest Data at any time.

15. Security

Data in transit to and from Chynora is encrypted, and our database applies row-level security so that a query can only return the organisations, events and guest records the requester is actually authorised to see. Invitation links are stored as one-way hashes rather than in plain, readable form, so a database copy alone cannot be used to reconstruct a working invite link.

One limitation worth stating plainly: images an organisation uploads (for event branding, for example) are currently served from a location that anyone with the file’s address can view, without needing to sign in, so that they can be shown on public invitation pages and in emails. Do not upload an image you would not want to be publicly reachable by its direct link.

16. Cookies

Chynora sets no advertising, analytics or third-party tracking cookies anywhere on the Service. The only cookies we use are:

  • An authentication session cookie, set by our sign-in provider, which keeps you signed in. Strictly necessary — without it you would have to sign in on every page.
  • A short-lived sign-in cookie used only while completing a Google sign-in, and deleted once sign-in finishes.
  • A sidebar-preference cookie, remembering for up to seven days whether you last collapsed or expanded the app’s sidebar. Purely a display preference.

Every cookie above is either strictly necessary to provide the Service you asked for, or remembers a choice you made about how it looks — both are exempt from cookie-consent requirements under applicable law, which is why the Service does not show a cookie-consent banner.

17. Changes to this policy

We may update this policy from time to time; we will post the revised version here with a new “Last updated” date. If a change is material, we will make a reasonable effort to let organisation members know directly.