Privacy notice
What davetti knows about you, why we hold it, and how you get it back or get rid of it. Written to be read, not to be survived.
Last updated August 9, 2026
Who is responsible for your data
The controller is Yeppler Gastronomy und Imports GbR, Tegelbergweg 4, 89231 Neu-Ulm, Germany. You can reach us about anything on this page at hello@davetti.de.
We have not appointed a data protection officer — we are not required to. Your request reaches us just as reliably at the address above.
One split worth knowing: when you are a guest at someone's party, the host decides what to ask you and why, so for that part they are the controller and we act for them. Everything else on this page is us.
What we collect
Only what the thing you are doing actually needs.
- Account — your name, phone number or email, your language, and the sign-in codes we send you.
- Parties — what you write on a party page: the date, the place, the theme, the child's first name and age if you add them, and any photos you upload.
- Guests and replies — a guest's name and contact details as the host entered them, plus the reply, headcount and any note about allergies or access needs.
- Gifts and orders — what was claimed or contributed to, the amount, and the delivery address when there is a physical gift.
- Bookings — which vendor, which slot, the price, and the messages you exchange about it.
- Payments — the amount, currency, status and a reference from our payment provider. We never receive your full card number.
- Technical — IP address, device and browser, and error logs, kept short and used to keep the service up and to stop abuse.
Why we use it, and on what basis
Every use below sits on one of three bases in Article 6(1) GDPR.
- To provide davetti — creating a party, sending invitations, taking replies, running gift pools, handling bookings and payments. Basis: performance of a contract, Art. 6(1)(b).
- To keep it safe and working — abuse prevention, rate limiting, error diagnosis, backups. Basis: our legitimate interest in a service that stays up and isn't abused, Art. 6(1)(f).
- To meet legal duties — accounting and tax records for anything paid. Basis: legal obligation, Art. 6(1)(c).
- Anything optional — non-essential cookies, and any marketing message. Basis: your consent, Art. 6(1)(a), and you can withdraw it at any time with effect for the future.
We do not profile you, and we make no automated decision that has a legal or similarly significant effect on you.
If you are a guest
You can be in davetti without ever having signed up, because a host added you to their guest list. That is allowed — it is how an invitation works — but it means you did not choose us, so here is what you can do.
You can see exactly what was stored about you on the party page you were sent. You can correct it in your reply. And you can ask the host, or us, to delete it. We will always tell you which host holds your details if you ask.
Transfers outside the EU
We keep data in the EU wherever we can. Where a provider processes data outside it, we rely on the European Commission's standard contractual clauses or an adequacy decision, and we check that the safeguards actually apply.
Ask us and we will tell you which providers are involved and where they sit.
How long we keep it
- Your account — until you close it.
- A party and its guest list — until you delete the party, or 24 months after the party date, whichever comes first.
- Payment and invoice records — 10 years, because German tax law says so.
- Cookie consent records — 3 years, as evidence that consent was given.
- Technical logs — 30 days, then deleted.
- Staff access records — kept for as long as your account exists, so you can always see when your activity was opened and why.
When a retention period ends we delete the data or anonymise it beyond re-identification.
Staff access to your activity
When you are signed in, our own team can open a 90-day view of how you have used the site — the kinds of page you opened, your bookings and your orders. It exists so somebody can help you when something goes wrong, and it never leaves our team: no vendor, and nobody outside the company, can see it.
We record every single time a member of the team opens it — when they looked and the reason they gave — and that record is in the data export in your account settings, so you can always check for yourself. This view is only ever built for accounts: visitors who are not signed in are counted anonymously and cannot be recognised from one day to the next.
Your rights
Under the GDPR you can ask us for any of the following, free of charge, and we will answer within a month.
- Access (Art. 15) — a copy of what we hold. Your account has a one-click export.
- Rectification (Art. 16) — fix anything wrong.
- Erasure (Art. 17) — delete it, unless we must keep it.
- Restriction (Art. 18) — freeze it while something is disputed.
- Portability (Art. 20) — your data in a machine-readable file.
- Objection (Art. 21) — object to anything we do on a legitimate-interest basis.
Write to hello@davetti.de. We may ask you to confirm who you are before we hand over a copy — that protection cuts both ways.
Children's data
A children's birthday platform holds children's details by design — a first name, an age, sometimes an allergy. We ask hosts for the least that makes the party work, and we never use a child's data for anything but the party it belongs to.
Accounts are for adults aged 16 and over. A parent or guardian decides about their child's data and can ask us to remove it at any time.
How we protect it
Everything travels over TLS. Passwords are not stored at all — we sign you in with a one-time code. Access to production data is limited to the people who need it, and backups are encrypted.
No system is perfect. If a breach ever puts your rights at risk, we will tell the supervisory authority within 72 hours and tell you without undue delay.
Changes to this notice
When the product changes, this page changes with it. The date at the top always reflects the current version, and we will tell you directly before any change that materially affects you takes effect.
If you want to complain
Please come to us first — most things are a misunderstanding we can fix the same day.
You also have the right to complain to a supervisory authority, in the EU country you live or work in or where the issue arose. Ours is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Everything on this page in one sentence: we hold what the party needs, for as long as it needs it, and you can have it back or have it gone at hello@davetti.de.