Security & trust

Procurement-grade trust, built in

When the guest experience carries your brand, it carries your standards. Gathmo is EU-hosted, GDPR-first and AI-moderated — with the controls your clients' security and legal teams ask for.

How we protect event media

Trust as a foundation, not an add-on

The same controls protect every event — whether it's on our domain or fully white-labelled on yours.

EU data residency

Media and personal data are hosted in the EU (Frankfurt, Germany) and are not transferred to the US.

Encrypted in transit & at rest

All traffic runs over HTTPS/TLS, and stored media is encrypted at rest by our EU infrastructure.

AI + host moderation

Uploads are AI-moderated, and hosts can review before publishing, hide anything, and keep galleries invite-only.

Consent & retention

Consent is recorded at upload, retention windows are enforced per plan, and data is removed when the window ends.

Access control & SSO

Role-based team seats on every business plan, with SAML/OIDC single sign-on available on Enterprise.

GDPR & a signed DPA

GDPR-first by design, with a Data Processing Agreement under Art. 28 available to business customers.

DATA RESIDENCY

Hosted in the EU, never sent to the US

Event media and guest data are stored in Frankfurt, Germany. Consent, export and erasure are built in, so you stay GDPR-compliant by default — and so do the clients whose brand sits on top.

Data-subject rights

Consent, export and erasure — handled

Consent at upload
Every guest sees and accepts the terms before contributing — and that consent is recorded.
Export anytime
Download all originals as a ZIP per event, at any time, for you or your client.
Erasure on request
Delete an event or specific media and it's removed — GDPR right-to-erasure built in.
FAQ

Security questions

In the EU — Frankfurt, Germany. Media and personal data are not transferred to the US.

Yes. A Data Processing Agreement under GDPR Art. 28 is available to business customers — you can read it on our DPA page.

Yes, on Enterprise. SAML/OIDC SSO lets your team sign in with your identity provider; role-based seats are available on every business plan.

Uploads are AI-moderated, and hosts get moderation tools to review before publishing, hide content and keep galleries invite-only — so the experience under your brand stays clean.

Take it through procurement

Talk to sales about SSO, the DPA and data residency for your events.