Privacy Policy
v1.5 · Effective 26.05.2026
VENUED PRIVACY POLICY
Version: 1.5
Effective Date: 26.05.2026
1. INFORMATION REGARDING THE CONTROLLER (ART. 13 GDPR)
The party responsible for the processing of personal data on this application is:
Name: Alara Özdenler
Email: alara.oezdenler@venued.eu
Contact Form: https://www.venued.eu/contact
Data Protection Contact: ata.keskin@venued.eu
No data protection officer has been appointed; this email serves as the contact for data protection.
2. SCOPE AND DEFINITIONS
This Privacy Policy applies to the "Venued" mobile application, its website, and all related services (the "Service"). "Personal Data" refers to any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).
3. CATEGORIES OF PERSONAL DATA COLLECTED
We process the following categories of data:
3.1 Account Data: Name, email address, date of birth, and internal User ID (UID).
3.2 Profile Data: Bio, interest tags, and uploaded profile photographs. Profile data is published as part of the social-network function of the Service and is therefore publicly visible — see Section 3.10 for details. Providing your gender identity is optional. If you choose to provide it, this data constitutes a special category of personal data under Art. 9 GDPR and is processed exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide during registration.
3.3 Verification Data: Phone number (processed via one-way cryptographic hash). The hashed values remain personal data and are used exclusively for account security and duplicate prevention.
Note: Venued does not store clear-text phone numbers. However, please be aware that our service provider Google/Firebase processes the phone number in clear text in order to send the verification SMS (see Section 7.1). Following verification, Venued retains only the cryptographic hash.
3.4 Event Interaction Data: Data regarding "liked," "saved," or "dismissed" events; event attendance history.
3.5 RSVP & Ticket Data: Transactional metadata related to event participation (excluding full financial card data).
3.6 Communication Data: Logs and content of in-app messages and match interactions.
3.7 Technical Device Data: Device model, OS version, anonymous Firebase Installation ID, and technical diagnostic data from the Firebase platform.
3.8 Support Communications: Records of correspondence between the user and our support team.
3.9 Contact Form Data: When you use the contact form on our website, we collect your name, email address, phone number (optional), and the content of your message.
3.10 Publicly Visible Content (Social-Network Function): Venued is a social-network service. The following data is, by design, publicly accessible — including via our website at www.venued.eu without sign-in — and may be cached or indexed by third parties:
- Display name, profile photograph, bio, interest tags, and "facts" you add to your profile
- Events you create, attend, or are listed on as an organizer, together with associated photographs, descriptions, and location
- Your participation status (RSVP) on a public event page
Data that remains non-public despite the social-network function:
- Email address, phone number (and its hash), date of birth, and internal User ID stored in private subcollections
- Direct messages and group chat content (only visible to chat participants)
- "Liked"/"saved"/"dismissed" event interactions and match-request history (only visible to you and, where applicable, the other party)
- Support communications and contact-form submissions (only visible to the operator)
By creating a profile or uploading content to a publicly visible field, you consent to its public display (Art. 6(1)(b) GDPR — performance of the contract for the social-network service). You may remove or edit publicly visible content at any time via the app; cached copies on third-party services may persist for some time after removal and are outside our control.
Aggregated audience analytics for organisers: Where you mark interest in an event ("interested"), the organiser of that event does NOT see your individual identity, profile, or any per-user list. Organisers see only privacy-safe aggregates (e.g., total interested count, age-bracket distribution, language skew) computed by Venued's server-side aggregation service. Every distribution bucket is k-anonymity floored at k ≥ 5 (and only computed at all when the underlying audience has ≥ 25 members), so individual users cannot be re-identified from any returned aggregate. The legal basis for this aggregation is our legitimate interest in providing organisers with the analytics necessary to plan future events (Art. 6(1)(f) GDPR), and our service-provision obligations to organisers under Art. 6(1)(b) GDPR.
3.11 Subscription and Billing Data: For users of paid tiers (e.g., Venued Plus), we process billing email, subscription status, payment method references (tokenised — full payment card data is processed exclusively by our payment service providers under PCI-DSS), and invoicing data required by §14 UStG and §147 AO.
4. SOURCES OF DATA
4.1 Direct Collection: Data provided by the user during registration and profile creation.
4.2 Automated Collection: Technical data collected via SDKs and API interfaces during app usage.
4.3 Third-Party Integrations: Data received from SSO providers (e.g., Apple ID, Google Sign-In) upon user authorization.
4.4 Event Partners: Confirmation of ticket validity or attendance status from event organizers.
5. PURPOSES OF PROCESSING AND LEGAL BASES (ART. 6 GDPR)
We process your data for the following purposes:
5.1 Provision of Services (Art. 6(1)(b) GDPR): Account management, event discovery, matchmaking, and chat functionality.
5.2 Personalization:
a) Interest tags and interaction history (Art. 6(1)(f) GDPR): Our legitimate interest is to provide a relevant user experience by suggesting events and matches based on user interests.
b) Gender identity (Art. 9(2)(a) GDPR): Where you provide this optional data, it is processed exclusively on the basis of your explicit consent for the purpose of personalizing suggestions. Consent may be withdrawn at any time.
5.3 Communication (Art. 6(1)(b) GDPR): Sending service-related notifications and match updates.
5.4 Security & Fraud Prevention (Art. 6(1)(f) GDPR): Protecting the platform from bots, harassment, and unauthorized access.
5.5 Compliance (Art. 6(1)(c) GDPR): Fulfilling tax, accounting, and legal disclosure obligations.
5.6 Support Communications (Art. 6(1)(b) and (f) GDPR): Handling support requests and contact form messages in order to provide the Service and pursue our legitimate interest in service quality.
5.7 Personalised Content and Sponsored Placements (Art. 6(1)(f) GDPR): We may display sponsored events, promoted venues, and branded content within the feed, search results, and event recommendations. Targeting of such content is performed exclusively by Venued based on interest tags, location, and interaction history; no personal data is transferred to advertisers or sponsoring brands, who receive only aggregated performance metrics (e.g., total impressions, total clicks per campaign). Our legitimate interest is the financial sustainability of the Service. You may object to personalised targeting at any time in the app settings (Art. 21 GDPR); non-personalised sponsored content may continue to be displayed.
5.8 Aggregated and Anonymised Insights (Art. 6(1)(f) GDPR; outside the scope of GDPR once anonymised): We may create aggregated, statistically anonymised datasets from user activity for the purposes of (a) market research and trend analysis, (b) publication of aggregated reports (e.g., event-category trends, regional demand patterns), and (c) provision of derived insights to event organisers via the organiser dashboard or to third parties as licensed reports or APIs. Anonymisation is performed in accordance with EDPB guidance, applying group-level aggregation (k-anonymity, k ≥ 25) and removal of all direct and indirect identifiers such that re-identification of an individual is not reasonably possible. Once so anonymised, the resulting data no longer constitutes personal data under Art. 4(1) GDPR (Recital 26).
5.9 Derived Model Outputs and Recommendation Services (Art. 6(1)(f) GDPR): We may use anonymised and aggregated behavioural data to train and operate machine learning models, including recommendation models. The outputs of these models (e.g., ranked recommendations, category-level similarity scores) may be provided to third parties as APIs or licensed services. No personal data, user identifiers, or individually-linked embedding vectors are shared with such third parties. Our legitimate interest is the commercialisation of derived analytical capabilities to support the Service.
6. AUTOMATED DECISION-MAKING AND PROFILING
Venued uses algorithmic sorting to suggest potential matches and events.
6.1 Logic: The algorithm ranks content based on the overlap of user-selected interest tags and historical interaction data.
6.2 No Legal Effect: These automated processes do not produce legal effects or similarly significant impacts on the user (Art. 22 GDPR).
6.3 Right to Object: Users may object to personalized profiling by adjusting their profile settings.
6.4 AI Transparency (Art. 50 EU AI Act): Venued uses an AI system (a Heterogeneous Graph Neural Network) to generate personalized event and profile recommendations within the feed and search. Direct match requests between users are not algorithmically filtered; they are initiated and accepted manually by users. Because the system has no legal or similarly significant effects on users (Art. 22 GDPR) and produces only recommendations, it qualifies as an AI system of minimal to limited risk under the EU AI Act (Art. 50 AI Act).
Additionally, certain event-template imagery displayed within the Service is generated by AI image-synthesis models. Such AI-generated imagery is used solely for the visual decoration of event-template categories and never depicts identifiable real persons. In line with Art. 50(2) AI Act, AI-generated content is marked as such where required by law.
7. DATA SHARING AND RECIPIENTS
Personal data is only shared with the following recipients:
7.1 Cloud Service Providers: GOOGLE CLOUD for data hosting and Google/Firebase for authentication services. A data processing agreement under Art. 28 GDPR is in place with Google (https://cloud.google.com/terms/data-processing-addendum). During SMS-based phone number verification, Google/Firebase processes the phone number in clear text in order to send the verification SMS. This processing is additionally subject to Google's privacy policy (https://policies.google.com/privacy). Venued itself subsequently stores only the cryptographic hash value.
7.2 Push Notification Providers: Google (FCM) and Apple (APNs).
7.3 Event Organizers: Minimal data (name/RSVP status) shared only when a user interacts with a specific event.
7.4 Legal Authorities: Only when legally mandated by German or EU law to disclose personal data.
7.5 No Sale of Personal Data: Venued does not sell or rent personal data to third parties. The sharing of aggregated and anonymised data (§5.8), the display of sponsored content targeted by Venued (§5.7), the provision of derived model outputs (§5.9), and the transfer of personal data in the context of a business transaction (§7.6) do not constitute a sale of personal data within the meaning of this section.
7.6 Business Transfers: In the event of a merger, acquisition, restructuring, reorganisation, insolvency, or sale of all or a substantial part of Venued's assets or business, your personal data may be transferred to the acquiring or successor entity as part of that transaction. Such a transfer is based on Venued's legitimate interest (Art. 6(1)(f) GDPR) in the continuity of the Service and the legitimate interest of the successor in continuing to provide the Service to existing users. The successor entity will be bound by the purpose limitations set out in this Privacy Policy at the time of transfer until and unless you are notified of changes and given the opportunity to object under Art. 21 GDPR or to request erasure under Art. 17 GDPR. We will notify you of any such transfer and the resulting change of controller via in-app notification or email at least 30 days before it takes effect, except where statutory or contractual confidentiality obligations require a shorter timeline.
7.7 Payment Service Providers: For processing of ticket purchases and paid subscriptions, we use Stripe Payments Europe Ltd. (Ireland) and PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). Full payment card data is processed exclusively by these providers under PCI-DSS; Venued itself receives only tokenised references and transaction metadata. These providers act as independent controllers for their own fraud-prevention and regulatory purposes; details are available in their respective privacy policies (https://stripe.com/privacy and https://www.paypal.com/de/legalhub/privacy-full).
8. INTERNATIONAL DATA TRANSFERS
We process data primarily within the European Economic Area (EEA). Where data is transferred to a "third country" (e.g., USA), the transfer is based on Standard Contractual Clauses (Art. 46 GDPR), supplemented by a Transfer Impact Assessment in accordance with the CJEU "Schrems II" judgment (C-311/18) and EDPB Recommendations 01/2020. Where available, we additionally rely on adequacy decisions of the EU Commission (e.g., EU-U.S. Data Privacy Framework).
Currently we only operate in Germany.
9. DATA RETENTION AND ERASURE
9.1 Account Data: Retained for the duration of the active user relationship.
9.2 Account Deletion: You may request deletion of your account at any time via the app settings or by email to privacy@venued.eu. After a deletion request, a 7-day cancellation window applies during which you may revoke the deletion. Following this window, all personal data is erased within 30 days, unless statutory retention periods (e.g., 6–10 years for financial records under the HGB/AO) apply.
9.3 Retention by data category:
- Account data (§3.1): duration of the active user relationship
- Profile data (§3.2): duration of the active user relationship
- Verification data / phone number hash (§3.3): duration of the active user relationship
- Event interaction data (§3.4): until account deletion
- RSVP & ticket data (§3.5): until account deletion; statutory retention periods unaffected
- Communication data / messages (§3.6): until account deletion
- Technical diagnostic data (§3.7): max. 90 days (Firebase platform default retention)
- Support communications (§3.8): 24 months
- Contact form data (§3.9): 12 months
10. USER RIGHTS (ART. 15-21 GDPR)
You have the following rights:
Art. 15: Right of access to your stored data.
Art. 16: Right to rectify inaccurate data.
Art. 17: Right to erasure ("Right to be forgotten").
Art. 18: Right to restriction of processing.
Art. 20: Right to data portability. Data exports are provided in JSON format within 30 days of a request submitted by email to privacy@venued.eu.
Art. 21: Right to object to processing based on legitimate interests.
Art. 7(3): Right to withdraw consent at any time with future effect.
To exercise these rights, contact: privacy@venued.eu
11. COOKIES AND TRACKING
The app and website use only technical identifiers strictly necessary for core functionality (account login, session continuity, security), as well as first-party diagnostic and performance telemetry from the Firebase platform (Crashlytics, Performance Monitoring) on the basis of our legitimate interest in service stability (Art. 6(1)(f) GDPR).
We do not currently use third-party advertising trackers, cross-site tracking pixels, or marketing cookies. If we introduce optional third-party analytics or marketing tracking in the future, users will be asked to provide explicit consent before any such data is collected and will retain the ability to withdraw consent at any time in the app settings.
We do not use "dark patterns" to influence your privacy decisions. Declining optional features will not result in any disadvantage in your use of the core app.
12. PUSH NOTIFICATIONS
If enabled, we use FCM (Google) or APNs (Apple) to send notifications. These services receive a device-bound push token that does not directly identify the user but can be linked to the account on our backend. Notifications can be disabled in the system settings of your mobile device.
13. DATA SECURITY
We implement state-of-the-art Technical and Organizational Measures (TOMs), including:
End-to-end encryption for data in transit (TLS/SSL).
Encryption at rest for databases (AES-256).
Strict access control and logging.
Regular security audits and vulnerability assessments.
We conduct regular reviews of our cloud infrastructure (Google Cloud DPA) to ensure that data processing meets European security standards for 2026.
14. CHILDREN'S PRIVACY
The Service is intended for users aged 18 and older. We do not intentionally collect data from minors. If we become aware of such collection, the data will be deleted immediately.
15. CHANGES TO THIS POLICY
We reserve the right to modify this policy. Users will be notified of material changes via in-app notification or email at least 14 days prior to the effective date.
16. COMPLAINTS AND SUPERVISORY AUTHORITY
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Venued is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany Website: www.lda.bayern.de
