Venued

Privacy Policy

v1.3 · Effective 26.04.2026

VENUED PRIVACY POLICY
Version: 1.3

Effective Date: 26.04.2026

1. INFORMATION REGARDING THE CONTROLLER (ART. 13 GDPR)

The party responsible for the processing of personal data on this application is:

Name: Alara Özdenler
Email: alara.oezdenler@venued.eu
Contact Form: https://www.venued.eu/contact

Data Protection Contact: ata.keskin@venued.eu

No data protection officer has been appointed; this email serves as the contact for data protection.

2. SCOPE AND DEFINITIONS

This Privacy Policy applies to the "Venued" mobile application, its website, and all related services (the "Service"). "Personal Data" refers to any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).

3. CATEGORIES OF PERSONAL DATA COLLECTED

We process the following categories of data:

3.1 Account Data: Name, email address, date of birth, and internal User ID (UID).

3.2 Profile Data: Bio, interest tags, and uploaded profile photographs. Profile data is published as part of the social-network function of the Service and is therefore publicly visible — see Section 3.10 for details. Providing your gender identity is optional. If you choose to provide it, this data constitutes a special category of personal data under Art. 9 GDPR and is processed exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide during registration.

3.3 Verification Data: Phone number (processed via one-way cryptographic hash). The hashed values remain personal data and are used exclusively for account security and duplicate prevention.
Note: Venued does not store clear-text phone numbers. However, please be aware that our service provider Google/Firebase processes the phone number in clear text in order to send the verification SMS (see Section 7.1). Following verification, Venued retains only the cryptographic hash.

3.4 Event Interaction Data: Data regarding "liked," "saved," or "dismissed" events; event attendance history.

3.5 RSVP & Ticket Data: Transactional metadata related to event participation (excluding full financial card data).

3.6 Communication Data: Logs and content of in-app messages and match interactions.

3.7 Technical Device Data: Device model, OS version, anonymous Firebase Installation ID, and technical diagnostic data from the Firebase platform.

3.8 Support Communications: Records of correspondence between the user and our support team.

3.9 Contact Form Data: When you use the contact form on our website, we collect your name, email address, phone number (optional), and the content of your message.

3.10 Publicly Visible Content (Social-Network Function): Venued is a social-network service. The following data is, by design, publicly accessible — including via our website at www.venued.eu without sign-in — and may be cached or indexed by third parties:
- Display name, profile photograph, bio, interest tags, and "facts" you add to your profile
- Events you create, attend, or are listed on as an organizer, together with associated photographs, descriptions, and location
- Your participation status (RSVP) on a public event page

Data that remains non-public despite the social-network function:
- Email address, phone number (and its hash), date of birth, and internal User ID stored in private subcollections
- Direct messages and group chat content (only visible to chat participants)
- "Liked"/"saved"/"dismissed" event interactions and match-request history (only visible to you and, where applicable, the other party)
- Support communications and contact-form submissions (only visible to the operator)

By creating a profile or uploading content to a publicly visible field, you consent to its public display (Art. 6(1)(b) GDPR — performance of the contract for the social-network service). You may remove or edit publicly visible content at any time via the app; cached copies on third-party services may persist for some time after removal and are outside our control.

4. SOURCES OF DATA

4.1 Direct Collection: Data provided by the user during registration and profile creation.
4.2 Automated Collection: Technical data collected via SDKs and API interfaces during app usage.
4.3 Third-Party Integrations: Data received from SSO providers (e.g., Apple ID, Google Sign-In) upon user authorization.
4.4 Event Partners: Confirmation of ticket validity or attendance status from event organizers.

5. PURPOSES OF PROCESSING AND LEGAL BASES (ART. 6 GDPR)

We process your data for the following purposes:

5.1 Provision of Services (Art. 6(1)(b) GDPR): Account management, event discovery, matchmaking, and chat functionality.

5.2 Personalization:
a) Interest tags and interaction history (Art. 6(1)(f) GDPR): Our legitimate interest is to provide a relevant user experience by suggesting events and matches based on user interests.
b) Gender identity (Art. 9(2)(a) GDPR): Where you provide this optional data, it is processed exclusively on the basis of your explicit consent for the purpose of personalizing suggestions. Consent may be withdrawn at any time.

5.3 Communication (Art. 6(1)(b) GDPR): Sending service-related notifications and match updates.

5.4 Security & Fraud Prevention (Art. 6(1)(f) GDPR): Protecting the platform from bots, harassment, and unauthorized access.

5.5 Compliance (Art. 6(1)(c) GDPR): Fulfilling tax, accounting, and legal disclosure obligations.

5.6 Support Communications (Art. 6(1)(b) and (f) GDPR): Handling support requests and contact form messages in order to provide the Service and pursue our legitimate interest in service quality.

6. AUTOMATED DECISION-MAKING AND PROFILING

Venued uses algorithmic sorting to suggest potential matches and events.

6.1 Logic: The algorithm ranks content based on the overlap of user-selected interest tags and historical interaction data.

6.2 No Legal Effect: These automated processes do not produce legal effects or similarly significant impacts on the user (Art. 22 GDPR).

6.3 Right to Object: Users may object to personalized profiling by adjusting their profile settings.

6.4 AI Transparency (Art. 50 EU AI Act): Venued uses an AI system (a Heterogeneous Temporal Graph) to generate personalized event and profile recommendations within the feed and search. Direct match requests between users are not algorithmically filtered; they are initiated and accepted manually by users. Because the system has no legal or similarly significant effects on users (Art. 22 GDPR) and produces only recommendations, it qualifies as an AI system of minimal to limited risk under the EU AI Act (Art. 50 AI Act).

7. DATA SHARING AND RECIPIENTS

Personal data is only shared with the following recipients:

7.1 Cloud Service Providers: GOOGLE CLOUD for data hosting and Google/Firebase for authentication services. A data processing agreement under Art. 28 GDPR is in place with Google (https://cloud.google.com/terms/data-processing-addendum). During SMS-based phone number verification, Google/Firebase processes the phone number in clear text in order to send the verification SMS. This processing is additionally subject to Google's privacy policy (https://policies.google.com/privacy). Venued itself subsequently stores only the cryptographic hash value.

7.2 Push Notification Providers: Google (FCM) and Apple (APNs).

7.3 Event Organizers: Minimal data (name/RSVP status) shared only when a user interacts with a specific event.

7.4 Legal Authorities: Only when legally mandated by German or EU law to disclose personal data.

7.5 No Sale of Data: Venued does not sell, rent, or trade personal data to third parties for marketing purposes.

8. INTERNATIONAL DATA TRANSFERS

We process data primarily within the European Economic Area (EEA). Where data is transferred to a "third country" (e.g., USA), the transfer is based on Standard Contractual Clauses (Art. 46 GDPR), supplemented by a Transfer Impact Assessment in accordance with the CJEU "Schrems II" judgment (C-311/18) and EDPB Recommendations 01/2020. Where available, we additionally rely on adequacy decisions of the EU Commission (e.g., EU-U.S. Data Privacy Framework).

Currently we only operate in Germany.

9. DATA RETENTION AND ERASURE

9.1 Account Data: Retained for the duration of the active user relationship.

9.2 Account Deletion: You may request deletion of your account at any time via the app settings or by email to privacy@venued.eu. After a deletion request, a 7-day cancellation window applies during which you may revoke the deletion. Following this window, all personal data is erased within 30 days, unless statutory retention periods (e.g., 6–10 years for financial records under the HGB/AO) apply.

9.3 Retention by data category:
- Account data (§3.1): duration of the active user relationship
- Profile data (§3.2): duration of the active user relationship
- Verification data / phone number hash (§3.3): duration of the active user relationship
- Event interaction data (§3.4): until account deletion
- RSVP & ticket data (§3.5): until account deletion; statutory retention periods unaffected
- Communication data / messages (§3.6): until account deletion
- Technical diagnostic data (§3.7): max. 90 days (Firebase platform default retention)
- Support communications (§3.8): 24 months
- Contact form data (§3.9): 12 months

10. USER RIGHTS (ART. 15-21 GDPR)

You have the following rights:

Art. 15: Right of access to your stored data.

Art. 16: Right to rectify inaccurate data.

Art. 17: Right to erasure ("Right to be forgotten").

Art. 18: Right to restriction of processing.

Art. 20: Right to data portability. Data exports are provided in JSON format within 30 days of a request submitted by email to privacy@venued.eu.

Art. 21: Right to object to processing based on legitimate interests.

Art. 7(3): Right to withdraw consent at any time with future effect.

To exercise these rights, contact: privacy@venued.eu

11. COOKIES AND TRACKING

The app only uses technical identifiers that are strictly necessary for its core functionality, such as enabling account login and ensuring proper app operation. Currently, the app does not collect additional data for analytics or marketing purposes, so no additional consent is required.

If we introduce optional analytics or marketing tracking in the future, users will be asked to provide explicit consent before any such data is collected, and they will always be able to revoke it in the app settings.

We do not use "dark patterns" to influence your privacy decisions. Declining optional features will not result in any disadvantage in your use of the core app.

12. PUSH NOTIFICATIONS

If enabled, we use FCM (Google) or APNs (Apple) to send notifications. These services receive a device-bound push token that does not directly identify the user but can be linked to the account on our backend. Notifications can be disabled in the system settings of your mobile device.

13. DATA SECURITY

We implement state-of-the-art Technical and Organizational Measures (TOMs), including:

End-to-end encryption for data in transit (TLS/SSL).

Encryption at rest for databases (AES-256).

Strict access control and logging.

Regular security audits and vulnerability assessments.

We conduct regular reviews of our cloud infrastructure (Google Cloud DPA) to ensure that data processing meets European security standards for 2026.

14. CHILDREN'S PRIVACY

The Service is intended for users aged 18 and older. We do not intentionally collect data from minors. If we become aware of such collection, the data will be deleted immediately.

15. CHANGES TO THIS POLICY

We reserve the right to modify this policy. Users will be notified of material changes via in-app notification or email at least 14 days prior to the effective date.

16. COMPLAINTS AND SUPERVISORY AUTHORITY

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Venued is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany Website: www.lda.bayern.de