Venued

Privacy Policy

v1.6 · Effective 28.05.2026

VENUED PRIVACY POLICY
Version: 1.6

Effective Date: 28.05.2026

1. INFORMATION REGARDING THE CONTROLLER (ART. 13 GDPR)

The party responsible for the processing of personal data on this application is:

Name: Alara Özdenler
Email: alara.oezdenler@venued.eu
Contact Form: https://www.venued.eu/contact

Data Protection Contact: ata.keskin@venued.eu

No data protection officer has been appointed; this email serves as the contact for data protection.

2. SCOPE AND DEFINITIONS

This Privacy Policy applies to the "Venued" mobile application, its website, and all related services (the "Service"). "Personal Data" refers to any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).

3. CATEGORIES OF PERSONAL DATA COLLECTED

We process the following categories of data:

3.1 Account Data: Name, email address, date of birth, and internal User ID (UID).

3.2 Profile Data: Display name, profile photograph, age, languages, interest tags, and "facts" you add to your profile. Profile data is processed as part of the matchmaking function of the Service. Each field has its own visibility tier (public / signed-in users / hidden) configurable at any time under "Privacy" in the Settings of the Venued mobile app — see Section 3.10 for the matchmaking-visibility model. Providing your gender identity is optional. If you choose to provide it, this data constitutes a special category of personal data under Art. 9 GDPR and is processed exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide during registration; the default visibility for gender is "signed-in users" only.

3.3 Verification Data: Phone number (processed via one-way cryptographic hash). The hashed values remain personal data and are used exclusively for account security and duplicate prevention.
Note: Venued does not store clear-text phone numbers. However, please be aware that our service provider Google/Firebase processes the phone number in clear text in order to send the verification SMS (see Section 7.1). Following verification, Venued retains only the cryptographic hash.

3.4 Event Interaction Data: Data regarding events you have marked as "interested" or "dismissed"; event attendance history. See Section 3.10 for the visibility model around "interested" markers.

3.5 RSVP & Ticket Data: Transactional metadata related to event participation (excluding full financial card data).

3.6 Communication Data: Logs and content of in-app messages and match interactions.

3.7 Technical Device Data: Device model, OS version, anonymous Firebase Installation ID, crash and error reports, in-app usage events (such as the screens you visit), and technical diagnostic data from the Firebase platform (see Section 11).

3.8 Support Communications: Records of correspondence between the user and our support team.

3.9 Contact Form Data: When you use the contact form on our website, we collect your name, email address, phone number (optional), and the content of your message.

3.10 Matchmaking Visibility (Social-Network Function): Venued is a matchmaking service. Your profile is processed under a three-tier per-field visibility model that you control through the "Privacy" section in the Settings of the Venued mobile app:

- "Public" fields are visible to anyone, including unauthenticated visitors browsing public event pages on www.venued.eu, and may be cached or indexed by third-party search engines (in which case removing the field will not immediately remove third-party caches).
- "Members" fields are visible only to signed-in Venued users. Unauthenticated visitors see a deterministic placeholder in their place (a bundled illustrated avatar paired with an anonymous handle such as "Curious Fox").
- "Hidden" fields are visible only to you.

The visibility tier you may choose, per field, is as follows. Defaults reflect the matchmaking purpose of the Service; you may opt up or down at any time in your Privacy settings.

- Display name: Public or Members. Default: Public. Cannot be set to "Hidden" because the matchmaking function requires a renderable identifier.
- Profile photograph: Public or Members. Default: Public. Cannot be set to "Hidden" for the same reason; Members-tier viewers without a session see the bundled placeholder image.
- Age (derived from your date of birth — the underlying date is never published): Public, Members, or Hidden. Default: Public.
- Gender: Public, Members, or Hidden. Default: Members. (You may opt up to Public; doing so makes the value visible to anonymous web visitors and to search engines.) Recall that gender itself is processed under Art. 9(2)(a) GDPR explicit consent.
- Languages: Public, Members, or Hidden. Default: Public.
- Interest tags: Public, Members, or Hidden. Default: Public.
- Profile "facts": Public, Members, or Hidden. Default: Public.

Where you mark interest in a public event ("interested"), the list of interested users (by user identifier only) is itself public; visitors then resolve each identifier to the corresponding user profile, which renders subject to that user's individual visibility tiers as described above. This is the matchmaking contract: it lets prospective match candidates see and reach you.

Data that remains non-public regardless of any tier setting (PII not used for matchmaking):
- Email address, phone number (and its hash), date of birth, and internal User ID stored in owner-only private subcollections
- Direct messages and group chat content (only visible to chat participants)
- "Dismissed" event interactions and match-request history (only visible to you and, where applicable, the other party)
- Support communications and contact-form submissions (only visible to the operator)

By creating a Venued account you accept the matchmaking contract (Art. 6(1)(b) GDPR — performance of contract). The granular per-field controls described above implement Art. 25 GDPR (data protection by design and by default). The default tiers above are presented to you at registration through a layered consent disclosure in the onboarding flow; your acceptance of these Terms and this Privacy Policy at that point constitutes your informed acceptance of those defaults. You may revisit and change any tier setting at any time in the Privacy settings of the app.

Aggregated audience analytics for organisers: Independent of the per-user visibility tiers above, organisers may see PRIVACY-SAFE AGGREGATES (e.g., total interested count, age-bracket distribution, language skew) about the audience of their own events. These aggregates are computed by Venued's server-side aggregation service. Every distribution bucket is k-anonymity floored at k ≥ 5 (and only computed at all when the underlying audience has ≥ 25 members), so individual users cannot be re-identified from any returned aggregate. The legal basis for this aggregation is our legitimate interest in providing organisers with the analytics necessary to plan future events (Art. 6(1)(f) GDPR), and our service-provision obligations to organisers under Art. 6(1)(b) GDPR.

Machine-learning personalisation: For the purposes of matchmaking recommendations and event personalisation, our internal models ingest the canonical profile data you have provided (regardless of your per-field visibility choices). Visibility tiers govern what other users / organisers / unauthenticated visitors see; they do not constrain Venued's own model training, which is necessary for the matchmaking function (Art. 6(1)(b) GDPR — performance of contract) and our legitimate interest in providing relevant recommendations (Art. 6(1)(f) GDPR). The trained model outputs are never published or shared with third parties.

3.11 Subscription and Billing Data: For users of paid tiers (e.g., Venued Plus), we process billing email, subscription status, payment method references (tokenised — full payment card data is processed exclusively by our payment service providers under PCI-DSS), and invoicing data required by §14 UStG and §147 AO.

4. SOURCES OF DATA

4.1 Direct Collection: Data provided by the user during registration and profile creation.
4.2 Automated Collection: Technical data collected via SDKs and API interfaces during app usage.
4.3 Third-Party Integrations: Data received from SSO providers (e.g., Apple ID, Google Sign-In) upon user authorization.
4.4 Event Partners: Confirmation of ticket validity or attendance status from event organizers.

5. PURPOSES OF PROCESSING AND LEGAL BASES (ART. 6 GDPR)

We process your data for the following purposes:

5.1 Provision of Services (Art. 6(1)(b) GDPR): Account management, event discovery, matchmaking, and chat functionality.

5.2 Personalization:
a) Interest tags and interaction history (Art. 6(1)(f) GDPR): Our legitimate interest is to provide a relevant user experience by suggesting events and matches based on user interests.
b) Gender identity (Art. 9(2)(a) GDPR): Where you provide this optional data, it is processed exclusively on the basis of your explicit consent for the purpose of personalizing suggestions. Consent may be withdrawn at any time.

5.3 Communication (Art. 6(1)(b) GDPR): Sending service-related notifications and match updates.

5.4 Security & Fraud Prevention (Art. 6(1)(f) GDPR): Protecting the platform from bots, harassment, and unauthorized access.

5.5 Compliance (Art. 6(1)(c) GDPR): Fulfilling tax, accounting, and legal disclosure obligations.

5.6 Support Communications (Art. 6(1)(b) and (f) GDPR): Handling support requests and contact form messages in order to provide the Service and pursue our legitimate interest in service quality.

5.7 Personalised Content and Sponsored Placements (Art. 6(1)(f) GDPR): We may display sponsored events, promoted venues, and branded content within the feed, search results, and event recommendations. Targeting of such content is performed exclusively by Venued based on interest tags, location, and interaction history; no personal data is transferred to advertisers or sponsoring brands, who receive only aggregated performance metrics (e.g., total impressions, total clicks per campaign). Our legitimate interest is the financial sustainability of the Service. You may object to personalised targeting at any time in the app settings (Art. 21 GDPR); non-personalised sponsored content may continue to be displayed.

5.8 Aggregated and Anonymised Insights (Art. 6(1)(f) GDPR; outside the scope of GDPR once anonymised): We may create aggregated, statistically anonymised datasets from user activity for the purposes of (a) market research and trend analysis, (b) publication of aggregated reports (e.g., event-category trends, regional demand patterns), and (c) provision of derived insights to event organisers via the organiser dashboard or to third parties as licensed reports or APIs. Anonymisation is performed in accordance with EDPB guidance, applying group-level aggregation (k-anonymity, k ≥ 25) and removal of all direct and indirect identifiers such that re-identification of an individual is not reasonably possible. Once so anonymised, the resulting data no longer constitutes personal data under Art. 4(1) GDPR (Recital 26).

5.9 Derived Model Outputs and Recommendation Services (Art. 6(1)(f) GDPR): We may use anonymised and aggregated behavioural data to train and operate machine learning models, including recommendation models. The outputs of these models (e.g., ranked recommendations, category-level similarity scores) may be provided to third parties as APIs or licensed services. No personal data, user identifiers, or individually-linked embedding vectors are shared with such third parties. Our legitimate interest is the commercialisation of derived analytical capabilities to support the Service.

6. AUTOMATED DECISION-MAKING AND PROFILING

Venued uses algorithmic sorting to suggest potential matches and events.

6.1 Logic: The algorithm ranks content based on the overlap of user-selected interest tags and historical interaction data.

6.2 No Legal Effect: These automated processes do not produce legal effects or similarly significant impacts on the user (Art. 22 GDPR).

6.3 Right to Object: Users may object to personalized profiling by adjusting their profile settings.

6.4 AI Transparency (Art. 50 EU AI Act): Venued uses an AI system (a Heterogeneous Graph Neural Network) to generate personalized event and profile recommendations within the feed and search. Direct match requests between users are not algorithmically filtered; they are initiated and accepted manually by users. Because the system has no legal or similarly significant effects on users (Art. 22 GDPR) and produces only recommendations, it qualifies as an AI system of minimal to limited risk under the EU AI Act (Art. 50 AI Act).

Additionally, certain event-template imagery displayed within the Service is generated by AI image-synthesis models. Such AI-generated imagery is used solely for the visual decoration of event-template categories and never depicts identifiable real persons. In line with Art. 50(2) AI Act, AI-generated content is marked as such where required by law.

7. DATA SHARING AND RECIPIENTS

Personal data is only shared with the following recipients:

7.1 Cloud Service Providers: GOOGLE CLOUD for data hosting and Google/Firebase for authentication services. A data processing agreement under Art. 28 GDPR is in place with Google (https://cloud.google.com/terms/data-processing-addendum). During SMS-based phone number verification, Google/Firebase processes the phone number in clear text in order to send the verification SMS. This processing is additionally subject to Google's privacy policy (https://policies.google.com/privacy). Venued itself subsequently stores only the cryptographic hash value.

7.2 Push Notification Providers: Google (FCM) and Apple (APNs).

7.3 Event Organizers: Minimal data (name/RSVP status) shared only when a user interacts with a specific event.

7.4 Legal Authorities: Only when legally mandated by German or EU law to disclose personal data.

7.5 No Sale of Personal Data: Venued does not sell or rent personal data to third parties. The sharing of aggregated and anonymised data (§5.8), the display of sponsored content targeted by Venued (§5.7), the provision of derived model outputs (§5.9), and the transfer of personal data in the context of a business transaction (§7.6) do not constitute a sale of personal data within the meaning of this section.

7.6 Business Transfers: In the event of a merger, acquisition, restructuring, reorganisation, insolvency, or sale of all or a substantial part of Venued's assets or business, your personal data may be transferred to the acquiring or successor entity as part of that transaction. Such a transfer is based on Venued's legitimate interest (Art. 6(1)(f) GDPR) in the continuity of the Service and the legitimate interest of the successor in continuing to provide the Service to existing users. The successor entity will be bound by the purpose limitations set out in this Privacy Policy at the time of transfer until and unless you are notified of changes and given the opportunity to object under Art. 21 GDPR or to request erasure under Art. 17 GDPR. We will notify you of any such transfer and the resulting change of controller via in-app notification or email at least 30 days before it takes effect, except where statutory or contractual confidentiality obligations require a shorter timeline.

7.7 Payment Service Providers: For processing of ticket purchases and paid subscriptions, we use Stripe Payments Europe Ltd. (Ireland) and PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). Full payment card data is processed exclusively by these providers under PCI-DSS; Venued itself receives only tokenised references and transaction metadata. These providers act as independent controllers for their own fraud-prevention and regulatory purposes; details are available in their respective privacy policies (https://stripe.com/privacy and https://www.paypal.com/de/legalhub/privacy-full).

8. INTERNATIONAL DATA TRANSFERS

We process data primarily within the European Economic Area (EEA). Where data is transferred to a "third country" (e.g., USA), the transfer is based on Standard Contractual Clauses (Art. 46 GDPR), supplemented by a Transfer Impact Assessment in accordance with the CJEU "Schrems II" judgment (C-311/18) and EDPB Recommendations 01/2020. Where available, we additionally rely on adequacy decisions of the EU Commission (e.g., EU-U.S. Data Privacy Framework).

Currently we only operate in Germany.

9. DATA RETENTION AND ERASURE

9.1 Account Data: Retained for the duration of the active user relationship.

9.2 Account Deletion: You may request deletion of your account at any time via the app settings or by email to privacy@venued.eu. After a deletion request, a 7-day cancellation window applies during which you may revoke the deletion. Following this window, all personal data is erased within 30 days, unless statutory retention periods (e.g., 6–10 years for financial records under the HGB/AO) apply.

9.3 Retention by data category:
- Account data (§3.1): duration of the active user relationship
- Profile data (§3.2): duration of the active user relationship
- Verification data / phone number hash (§3.3): duration of the active user relationship
- Event interaction data (§3.4): until account deletion
- RSVP & ticket data (§3.5): until account deletion; statutory retention periods unaffected
- Communication data / messages (§3.6): until account deletion
- Technical diagnostic data (§3.7): max. 90 days (Firebase platform default retention)
- Support communications (§3.8): 24 months
- Contact form data (§3.9): 12 months

10. USER RIGHTS (ART. 15-21 GDPR)

You have the following rights:

Art. 15: Right of access to your stored data.

Art. 16: Right to rectify inaccurate data.

Art. 17: Right to erasure ("Right to be forgotten").

Art. 18: Right to restriction of processing.

Art. 20: Right to data portability. Data exports are provided in JSON format within 30 days of a request submitted by email to privacy@venued.eu.

Art. 21: Right to object to processing based on legitimate interests.

Art. 7(3): Right to withdraw consent at any time with future effect.

To exercise these rights, contact: privacy@venued.eu

11. COOKIES AND TRACKING

The app and website use only technical identifiers strictly necessary for core functionality (account login, session continuity, security), as well as first-party diagnostic and usage telemetry from the Firebase platform on the basis of our legitimate interest in service stability and improvement (Art. 6(1)(f) GDPR). Specifically:

Firebase Crashlytics records crash and error reports (stack traces, device model, OS version, app version, and the app state at the time of the error) so that we can diagnose and fix faults.

Firebase Analytics records first-party usage events, principally the in-app screens you visit and basic interaction events. These events also form the breadcrumb trail attached to a crash report, showing the sequence of screens that preceded an error so that we can reproduce and fix it. This is first-party product analytics used solely to operate and improve Venued. It is not used for advertising, and the data is not shared with third parties for their own purposes.

This telemetry is collected only in released versions of the app and is associated with your account identifier so that we can investigate faults you personally encounter. Technical diagnostic data is retained for a maximum of 90 days (see Section 9).

We do not currently use third-party advertising trackers, cross-site tracking pixels, or marketing cookies. If we introduce optional third-party analytics or marketing tracking in the future, users will be asked to provide explicit consent before any such data is collected and will retain the ability to withdraw consent at any time in the app settings.

We do not use "dark patterns" to influence your privacy decisions. Declining optional features will not result in any disadvantage in your use of the core app.

12. PUSH NOTIFICATIONS

If enabled, we use FCM (Google) or APNs (Apple) to send notifications. These services receive a device-bound push token that does not directly identify the user but can be linked to the account on our backend. Notifications can be disabled in the system settings of your mobile device.

13. DATA SECURITY

We implement state-of-the-art Technical and Organizational Measures (TOMs), including:

End-to-end encryption for data in transit (TLS/SSL).

Encryption at rest for databases (AES-256).

Strict access control and logging.

Regular security audits and vulnerability assessments.

We conduct regular reviews of our cloud infrastructure (Google Cloud DPA) to ensure that data processing meets European security standards for 2026.

14. CHILDREN'S PRIVACY

The Service is intended for users aged 18 and older. We do not intentionally collect data from minors. If we become aware of such collection, the data will be deleted immediately.

15. CHANGES TO THIS POLICY

We reserve the right to modify this policy. Users will be notified of material changes via in-app notification or email at least 14 days prior to the effective date.

16. COMPLAINTS AND SUPERVISORY AUTHORITY

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Venued is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany Website: www.lda.bayern.de