GDPR

GDPR-compliant webinar platform hosted in the EU

Webinars run on our servers in Germany and Finland under a public data processing agreement, and the company behind them is registered in Lithuania. Each point below links to the document or the setting it comes from.

  • Servers in the EU
  • Public DPA
  • Company in Lithuania
  • Signed DPA on request

Where the data is

Where your webinar data goes

EU hosting means different things on different sites. Here is what it means on ours.

Servers and storage in Germany and Finland

The servers that carry webinar traffic stand in Germany and Finland, and recordings, uploaded files and attendee lists are stored there and nowhere else. All of our data centres are in the European Union and follow the Tier III standard.

Source Why your speed to EU servers is slower than SpeedtestPrivacy policy, §8

Delivery networks carry it to your viewers

On their way to viewers, the broadcast, recordings and files pass through the delivery networks of Cloudflare, Bunny.net and Amazon CloudFront, which have servers around the world, so that people far from Europe get a smooth picture too.

Source About us

A company registered in Vilnius

MyOwnConference is operated by Akovana, UAB, registered at Didžioji Street 18 in Vilnius, Lithuania.

Source Privacy policy

Encrypted in transit and at rest

Everything you broadcast travels over TLS. Presentations, videos and other files you upload are stored encrypted with AES-128.

Source Privacy policy, §8

No cookies before you choose

This website sets no cookies until you answer the consent banner, and "Cookie settings" in the footer lets you change that answer at any time. Visitor statistics come from Plausible Analytics, which uses none, and the support chat loads only after you accept.

Source Privacy policy, §5

Data processing agreement

What our DPA commits us to

The agreement is published on this site and applies to every account from sign-up. These are the clauses compliance teams usually ask about first.

Your instructions only

We process attendee data only to run your webinars and only as you instruct, and that includes any transfer to another country.

Source DPA, §2

21 days' notice of a new sub-processor

Before a new sub-processor starts handling your attendees' data, we tell you at least 21 days in advance.

Source DPA, §1

Breach notice without delay

If a breach affects personal data, we notify you without undue delay and describe what happened, which data and how many people it touches, the likely consequences and what we are doing about it.

Source DPA, §2

Deletion when the contract ends

When the agreement ends, or earlier if you ask, we stop processing and delete or return the data, unless EU or member state law requires us to keep it.

Source DPA, §2

Audits and answers within days

You or an auditor you appoint can check how we meet Article 28 of GDPR. We answer questions about the agreement with evidence within 3 days and fix what an audit finds within 7 days.

Source DPA, §2 and §3

Lithuanian law

Anything the agreement leaves open is governed by Lithuanian law, including GDPR.

Source DPA, §7

Does your company need a signed copy? Write to us and we will sign the agreement with you. [email protected]

In your control panel

Settings that collect less and show less

Most of these live in the settings of a single webinar or room, so you decide event by event.

Ask only for what you need

A permanent room asks for "Full name" and nothing more, and a nickname will do. A scheduled webinar adds "Email", because reminders go there. Add other fields only when the event needs them. "Allow sign-up with social accounts" decides whether attendees can come in with a Google or Microsoft account.

Source Attendee registration not required

Hide attendees from each other

"Anonymize attendee names" shows attendees only each other's initials, "Hide attendees list" takes the list away, and turning off "Show host name" keeps the host's name off the broadcast. Your moderators still see everyone in full.

Source Anonymous webinar and participant data protection under GDPR

Record without names

Turn off "Including the moderators' names" and "Including a list of attendees", and the recording keeps the slides, screen sharing, speech and audience interaction without presenter name labels or a closing list of attendees.

Source Anonymous webinar and participant data protection under GDPR

Keep strangers out

"Invitation link login only" leaves personal invitation links as the only way in. Each link holds one seat, "Restrict access" emails a one-time code to the invited address, and the account itself can require a code from an authenticator app.

Source Platform security

Export it, delete it

"Export attendees" downloads the list as CSV or Excel with the columns you pick. Deleted files wait in "Trash" for seven days, and deleting your account in "Profile" removes it and everything stored in it for good.

Source Webinar statistics and reportsPrivacy policy, §4

Sub-processors

Companies that handle the data with us

Grouped by what they touch. The DPA commits us to tell you 21 days before a new one starts handling your attendees' data.

Running your webinars

CompanyWhat it does
HetznerServers for webinar traffic and storage in Germany and Finland
velia.net, OVHMail servers that send invitations and reminders, in the Netherlands and France
CloudflareDelivery network for the broadcast, recordings and files
Bunny.netDelivery network for the broadcast, recordings and files
Amazon CloudFrontDelivery network for the broadcast, recordings and files

Our website and billing

CompanyWhat it does
CrispSupport chat on this website, loaded only after you accept cookies
Plausible AnalyticsVisitor statistics for this website, without cookies
Paysera, Revolut, PayPalPayments for plans, with card details kept on their side

Only when you switch them on

CompanyWhat it does
Google, MicrosoftAttendee sign-up with a Google or Microsoft account
Google Tag ManagerTraffic analytics on your webinar pages once you add a GTM ID
PayPalTicket sales for paid webinars, paid into your own PayPal account
YouTubeYouTube videos and live streams you play in the room

Your part

What EU hosting leaves to you

As the organiser you decide which attendee data to collect and why. That makes you the controller, and a few duties stay with you on any platform.

Tell attendees what you collect

Your privacy notice and the legal basis for collecting attendee data are yours to provide. If an attendee writes to us instead of you, the DPA commits us to pass the request on and help you answer it.

Source DPA, §2

Say when you record

The webinar room shows attendees no recording indicator, so telling them that a session is recorded is up to you.

Source Webinar attendee guide

Check what you connect

A CRM you connect through the API, the PayPal account behind a paid webinar and a YouTube video played in the room each follow their own provider's terms.

Source MyOwnConference public API

FAQ

GDPR questions about MyOwnConference

Short answers for compliance checks and data protection officers

Still have questions? Contact us
On our side, yes. Attendee data is processed on servers in EU data centres under a public data processing agreement governed by Lithuanian law, and the company is registered in Vilnius. Whether a particular webinar complies also depends on you, because as the organiser you decide what data to collect and why.
Webinar traffic runs through our Hetzner servers in Germany and Finland, and recordings, files and attendee lists are stored there and nowhere else. Invitation emails are sent from mail servers in the Netherlands and France, run by velia.net and OVH. All of them are in Tier III data centres in the EU. On their way to viewers, the broadcast, recordings and files pass through the delivery networks of Cloudflare, Bunny.net and Amazon CloudFront.
Yes. The data processing agreement applies to every account from sign-up, and if your company needs a signed copy, write to [email protected] and we will sign it with you.
Yes, and the table on this page lists them by what they do. The agreement commits us to tell you at least 21 days before a new sub-processor starts handling your attendees' data.
As long as your account exists, unless you delete it sooner. Deleted files wait in Trash for seven days, deleting the account removes it and its content at once and for good, and a free account nobody signs in to for 180 days is deleted with everything in it.
Attendees can ask us directly at [email protected] to change or remove their data, as the privacy policy says. If the request reaches us, the data processing agreement commits us to pass it to you and help you answer it.
Yes. Everything you broadcast travels over TLS between you, our servers and the other participants, and the presentations, videos and other files you upload are stored encrypted with AES-128.
In a permanent room, yes. It asks for a full name only, and a nickname works. A scheduled webinar also asks for an email address, because reminders and the access link are sent there.

EU-hosted webinars

Run your next webinar on servers in the EU

Start on the free plan, try the settings above in your own control panel and read the DPA before your first event

EU-hosted • GDPR compliant • Free forever plan • No payment card