Privacy Policy
v1.7 · Effective 13.06.2026
VENUED PRIVACY POLICY
Version: 1.7
Effective Date: 13.06.2026
Changelog (v1.7): Added Art. 14 / Art. 6(1)(f) basis and source disclosure for Curated (aggregated) event listings containing non-user personal data (§ 4.5, § 5.10); named the legal basis for subscription billing data (§ 3.11); added SMS-verification, error-monitoring (Sentry), and CDN/network-security (Cloudflare) recipients to align with Terms § 25.1 (§ 7.2a–7.2c); hardened the derived-model-output offering with an aggregate-only guarantee, documented balancing test, and an opt-out from training for third-party offerings (§ 5.9).
1. INFORMATION REGARDING THE CONTROLLER (ART. 13 GDPR)
The party responsible for the processing of personal data on this application is:
Name: Alara Özdenler
Email: alara.oezdenler@venued.eu
Contact Form: https://www.venued.eu/contact
Data Protection Contact: ata.keskin@venued.eu
No data protection officer has been appointed; this email serves as the contact for data protection.
2. SCOPE AND DEFINITIONS
This Privacy Policy applies to the "Venued" mobile application, its website, and all related services (the "Service"). "Personal Data" refers to any information relating to an identified or identifiable natural person (Art. 4 No. 1 GDPR).
3. CATEGORIES OF PERSONAL DATA COLLECTED
We process the following categories of data:
3.1 Account Data: Name, email address, date of birth, and internal User ID (UID).
3.2 Profile Data: Display name, profile photograph, age, languages, interest tags, and "facts" you add to your profile. Profile data is processed as part of the matchmaking function of the Service. Each field has its own visibility tier (public / signed-in users / hidden) configurable at any time under "Privacy" in the Settings of the Venued mobile app — see Section 3.10 for the matchmaking-visibility model. Providing your gender identity is optional. If you choose to provide it, this data constitutes a special category of personal data under Art. 9 GDPR and is processed exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you provide during registration; the default visibility for gender is "signed-in users" only.
3.3 Verification and Contact Data: Phone number. We collect your phone number for three purposes: (a) account security, identity verification, and duplicate prevention; (b) sending you updates about events you have marked as "interested", including notifications conveyed on behalf of event organisers; and (c) enabling the optional "find your contacts on Venued" feature so you can discover people you know who already use the Service.
For account security and duplicate prevention, your phone number is processed via a one-way cryptographic hash; the hashed values remain personal data. For the contacts feature, matching is performed by comparing one-way hashes, and the phone numbers in your address book are hashed on your device before any comparison takes place. Venued does not store clear-text phone numbers. However, please be aware that our service provider Google/Firebase processes the phone number in clear text in order to send the verification SMS and any event update messages delivered by SMS (see Section 7.1). Following verification, Venued retains only the cryptographic hash.
3.4 Event Interaction Data: Data regarding events you have marked as "interested" or "dismissed"; event attendance history. See Section 3.10 for the visibility model around "interested" markers.
3.5 RSVP & Ticket Data: Transactional metadata related to event participation (excluding full financial card data).
3.6 Communication Data: Logs and content of in-app messages and match interactions.
3.7 Technical Device Data: Device model, OS version, anonymous Firebase Installation ID, crash and error reports, in-app usage events (such as the screens you visit), and technical diagnostic data from the Firebase platform (see Section 11).
3.8 Support Communications: Records of correspondence between the user and our support team.
3.9 Contact Form Data: When you use the contact form on our website, we collect your name, email address, phone number (optional), and the content of your message.
3.10 Matchmaking Visibility (Social-Network Function): Venued is a matchmaking service. Your profile is processed under a three-tier per-field visibility model that you control through the "Privacy" section in the Settings of the Venued mobile app:
- "Public" fields are visible to anyone, including unauthenticated visitors browsing public event pages on www.venued.eu, and may be cached or indexed by third-party search engines (in which case removing the field will not immediately remove third-party caches).
- "Members" fields are visible only to signed-in Venued users. Unauthenticated visitors see a deterministic placeholder in their place (a bundled illustrated avatar paired with an anonymous handle such as "Curious Fox").
- "Hidden" fields are visible only to you.
The visibility tier you may choose, per field, is as follows. Defaults reflect the matchmaking purpose of the Service; you may opt up or down at any time in your Privacy settings.
- Display name: Public or Members. Default: Public. Cannot be set to "Hidden" because the matchmaking function requires a renderable identifier.
- Profile photograph: Public or Members. Default: Public. Cannot be set to "Hidden" for the same reason; Members-tier viewers without a session see the bundled placeholder image.
- Age (derived from your date of birth — the underlying date is never published): Public, Members, or Hidden. Default: Public.
- Gender: Public, Members, or Hidden. Default: Members. (You may opt up to Public; doing so makes the value visible to anonymous web visitors and to search engines.) Recall that gender itself is processed under Art. 9(2)(a) GDPR explicit consent.
- Languages: Public, Members, or Hidden. Default: Public.
- Interest tags: Public, Members, or Hidden. Default: Public.
- Profile "facts": Public, Members, or Hidden. Default: Public.
Where you mark interest in a public event ("interested"), the list of interested users (by user identifier only) is itself public; visitors then resolve each identifier to the corresponding user profile, which renders subject to that user's individual visibility tiers as described above. This is the matchmaking contract: it lets prospective match candidates see and reach you.
Data that remains non-public regardless of any tier setting (PII not used for matchmaking):
- Email address, phone number (and its hash), date of birth, and internal User ID stored in owner-only private subcollections
- Direct messages and group chat content (only visible to chat participants)
- "Dismissed" event interactions and match-request history (only visible to you and, where applicable, the other party)
- Support communications and contact-form submissions (only visible to the operator)
By creating a Venued account you accept the matchmaking contract (Art. 6(1)(b) GDPR — performance of contract). The granular per-field controls described above implement Art. 25 GDPR (data protection by design and by default). The default tiers above are presented to you at registration through a layered consent disclosure in the onboarding flow; your acceptance of these Terms and this Privacy Policy at that point constitutes your informed acceptance of those defaults. You may revisit and change any tier setting at any time in the Privacy settings of the app.
Aggregated audience analytics for organisers: Independent of the per-user visibility tiers above, organisers may see PRIVACY-SAFE AGGREGATES (e.g., total interested count, age-bracket distribution, language skew) about the audience of their own events. These aggregates are computed by Venued's server-side aggregation service. Every distribution bucket is k-anonymity floored at k ≥ 5 (and only computed at all when the underlying audience has ≥ 25 members), so individual users cannot be re-identified from any returned aggregate. The legal basis for this aggregation is our legitimate interest in providing organisers with the analytics necessary to plan future events (Art. 6(1)(f) GDPR), and our service-provision obligations to organisers under Art. 6(1)(b) GDPR.
Machine-learning personalisation: For the purposes of matchmaking recommendations and event personalisation, our internal models ingest the canonical profile data you have provided (regardless of your per-field visibility choices). Visibility tiers govern what other users / organisers / unauthenticated visitors see; they do not constrain Venued's own model training, which is necessary for the matchmaking function (Art. 6(1)(b) GDPR — performance of contract) and our legitimate interest in providing relevant recommendations (Art. 6(1)(f) GDPR). The trained model outputs are never published or shared with third parties.
3.11 Subscription and Billing Data: For users of the paid tier (Venued Plus, see Terms § 24), we process billing email, subscription status and renewal dates, payment method references (tokenised — full payment card data is processed exclusively by our payment service providers under PCI-DSS), and invoicing data. This data is processed to perform the subscription contract (Art. 6(1)(b) GDPR) and to meet statutory invoicing and retention obligations (Art. 6(1)(c) GDPR; § 14 UStG, § 147 AO).
4. SOURCES OF DATA
4.1 Direct Collection: Data provided by the user during registration and profile creation.
4.2 Automated Collection: Technical data collected via SDKs and API interfaces during app usage.
4.3 Third-Party Integrations: Data received from SSO providers (e.g., Apple ID, Google Sign-In) upon user authorization.
4.4 Event Partners: Confirmation of ticket validity or attendance status from event organizers.
4.5 Public Event Sources (Curated Listings): For events that have not yet been claimed by an organiser, we compile factual event information from publicly available sources — including official interfaces and data feeds (public APIs, RSS, calendar/ICS feeds, structured event data), public web sources, and our own editorial entry. This compiled information may include limited personal data of organisers or performers that is already public in those sources (for example, an organiser's or act's name, or a publicly listed contact). We do not collect this data from you directly; the disclosures required by Art. 14 GDPR are set out in Section 5.10.
5. PURPOSES OF PROCESSING AND LEGAL BASES (ART. 6 GDPR)
We process your data for the following purposes:
5.1 Provision of Services (Art. 6(1)(b) GDPR): Account management, event discovery, matchmaking, and chat functionality.
5.2 Personalization:
a) Interest tags and interaction history (Art. 6(1)(f) GDPR): Our legitimate interest is to provide a relevant user experience by suggesting events and matches based on user interests.
b) Gender identity (Art. 9(2)(a) GDPR): Where you provide this optional data, it is processed exclusively on the basis of your explicit consent for the purpose of personalizing suggestions. Consent may be withdrawn at any time.
5.3 Communication (Art. 6(1)(b) GDPR): Sending service-related notifications and match updates.
5.4 Security & Fraud Prevention (Art. 6(1)(f) GDPR): Protecting the platform from bots, harassment, and unauthorized access.
5.5 Compliance (Art. 6(1)(c) GDPR): Fulfilling tax, accounting, and legal disclosure obligations.
5.6 Support Communications (Art. 6(1)(b) and (f) GDPR): Handling support requests and contact form messages in order to provide the Service and pursue our legitimate interest in service quality.
5.7 Personalised Content and Sponsored Placements (Art. 6(1)(f) GDPR): We may display sponsored events, promoted venues, and branded content within the feed, search results, and event recommendations. Targeting of such content is performed exclusively by Venued based on interest tags, location, and interaction history; no personal data is transferred to advertisers or sponsoring brands, who receive only aggregated performance metrics (e.g., total impressions, total clicks per campaign). Our legitimate interest is the financial sustainability of the Service. You may object to personalised targeting at any time in the app settings (Art. 21 GDPR); non-personalised sponsored content may continue to be displayed.
5.8 Aggregated and Anonymised Insights (Art. 6(1)(f) GDPR; outside the scope of GDPR once anonymised): We may create aggregated, statistically anonymised datasets from user activity for the purposes of (a) market research and trend analysis, (b) publication of aggregated reports (e.g., event-category trends, regional demand patterns), and (c) provision of derived insights to event organisers via the organiser dashboard or to third parties as licensed reports or APIs. Anonymisation is performed in accordance with EDPB guidance, applying group-level aggregation (k-anonymity, k ≥ 25) and removal of all direct and indirect identifiers such that re-identification of an individual is not reasonably possible. Once so anonymised, the resulting data no longer constitutes personal data under Art. 4(1) GDPR (Recital 26).
5.9 Derived Model Outputs and Recommendation Services (Art. 6(1)(f) GDPR): We train and operate machine-learning models, including recommendation models, to provide and improve the Service. We may also offer the outputs of these models to third parties as APIs or licensed services. The following safeguards apply to that offering:
a) Aggregate / category level only. Anything provided to a third party is limited to aggregate or category-level outputs (for example, category-level similarity scores, area-level demand patterns, ranked recommendations for a defined audience segment). We never provide, and a third party can never derive, information about an identified or identifiable individual. No personal data, user identifiers, profile fields, raw interaction logs, or individually-linked embedding vectors are shared with any third party under this Section.
b) Anonymisation standard. Inputs underlying any third-party output are anonymised in accordance with EDPB guidance, applying group-level aggregation (k-anonymity, k ≥ 25) and removal of direct and indirect identifiers, such that re-identification of an individual is not reasonably possible. Once so anonymised, the resulting outputs no longer constitute personal data under Art. 4(1) GDPR (Recital 26).
c) Legal basis and balancing test. The training and operation of models to provide and improve the Service rests on the performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in relevant recommendations (Art. 6(1)(f) GDPR). The provision of anonymised, aggregate outputs to third parties rests on our legitimate interest in the financial sustainability and continued development of the Service (Art. 6(1)(f) GDPR). We have carried out and documented a balancing test (legitimate-interests assessment) for this purpose, taking into account that no personal data leaves Venued, that outputs are aggregate-only, and that you can object as set out below; the documented assessment is available on request to privacy@venued.eu.
d) Right to object. You may object at any time, with future effect, to the use of your data for training models whose outputs are offered to third parties under this Section, by adjusting the relevant setting in the app or by writing to privacy@venued.eu (Art. 21 GDPR). Following an objection, your data is excluded from training pipelines used for third-party offerings; this does not affect models used solely to operate the Service for you, or outputs already anonymised before the objection.
5.10 Curated (Aggregated) Event Listings and Information for Non-Users (Art. 6(1)(f) and Art. 14 GDPR): To provide a useful event-discovery and matchmaking experience from the outset, we compile factual listings for events that have not yet been claimed by an organiser, as described in Section 4.5 and in our Terms § 12A. Where such a listing contains limited personal data of an organiser or performer (such as a name or a publicly listed contact), the following applies:
a) Categories of data: name and, where publicly listed, contact or role information of the organiser, host, or performer associated with a public event; factual event metadata (title, date, time, venue, price, category).
b) Source: the public sources described in Section 4.5. We do not obtain this data from the data subject directly. This Section serves as the information notice required by Art. 14 GDPR.
c) Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in operating an event-discovery directory and informing users about public events in their area, comparable to a public event calendar. We have assessed that this interest is not overridden by the interests of the data subjects, because the data is already public, is limited to what is necessary to identify and describe a public event, and is not used to profile the organiser or performer or for advertising directed at them.
d) Recipients and transfers: the same processors used to host and operate the Service (Section 7); the data is displayed publicly within Curated Listings as factual event information. It is not sold (Section 7.5).
e) Retention: a Curated Listing is retained while the underlying event is current or of discovery value, and is removed or anonymised thereafter; it is also removed on a valid request under (f).
f) Your rights and objection / removal: any organiser, venue, performer, or other rights holder, or any person whose personal data appears in a Curated Listing, may object to the processing (Art. 21 GDPR) and request correction or removal at any time by contacting privacy@venued.eu or legal@venued.eu. We act on a valid request without undue delay and, in the ordinary case, within five (5) business days. Where an organiser claims their event (Terms § 12A.3), the listing's content thereafter is governed by the organiser-content provisions and the organiser becomes responsible for it.
6. AUTOMATED DECISION-MAKING AND PROFILING
Venued uses algorithmic sorting to suggest potential matches and events.
6.1 Logic: The algorithm ranks content based on the overlap of user-selected interest tags and historical interaction data.
6.2 No Legal Effect: These automated processes do not produce legal effects or similarly significant impacts on the user (Art. 22 GDPR).
6.3 Right to Object: Users may object to personalized profiling by adjusting their profile settings.
6.4 AI Transparency (Art. 50 EU AI Act): Venued uses an AI system (a Heterogeneous Graph Neural Network) to generate personalized event and profile recommendations within the feed and search. Direct match requests between users are not algorithmically filtered; they are initiated and accepted manually by users. Because the system has no legal or similarly significant effects on users (Art. 22 GDPR) and produces only recommendations, it qualifies as an AI system of minimal to limited risk under the EU AI Act (Art. 50 AI Act).
Additionally, certain event-template imagery displayed within the Service is generated by AI image-synthesis models. Such AI-generated imagery is used solely for the visual decoration of event-template categories and never depicts identifiable real persons. In line with Art. 50(2) AI Act, AI-generated content is marked as such where required by law.
7. DATA SHARING AND RECIPIENTS
Personal data is only shared with the following recipients:
7.1 Cloud Service Providers: GOOGLE CLOUD for data hosting and Google/Firebase for authentication services. A data processing agreement under Art. 28 GDPR is in place with Google (https://cloud.google.com/terms/data-processing-addendum). During SMS-based phone number verification, and when sending you SMS updates about events you have marked as "interested" (including messages conveyed on behalf of event organisers), Google/Firebase processes the phone number in clear text in order to send the relevant SMS. This processing is additionally subject to Google's privacy policy (https://policies.google.com/privacy). Venued itself subsequently stores only the cryptographic hash value.
7.2 Push Notification Providers: Google (FCM) and Apple (APNs).
7.2a SMS Provider: During phone-number verification, the one-time password is delivered via Google/Firebase's SMS infrastructure, which processes the phone number in clear text solely to send the message (see Section 3.3 and Section 7.1). The same infrastructure is used to deliver SMS updates about events you have marked as "interested", including messages conveyed on behalf of event organisers. Venued retains only the cryptographic hash.
7.2b Error Monitoring: We use an error-monitoring provider (Sentry or an equivalent) to receive crash and error reports for diagnosing faults. Reports may include technical device data and the application state at the time of the error; a data processing agreement under Art. 28 GDPR is in place. (See also Section 11.)
7.2c Content Delivery / Network Security: Where enabled, we use a content-delivery and network-security provider (Cloudflare) in front of parts of the Service to deliver content efficiently and protect against abuse. Such a provider processes connection metadata (e.g., IP address, request headers) as a processor on our behalf under Art. 28 GDPR.
7.3 Event Organizers: Minimal data (name/RSVP status) shared only when a user interacts with a specific event.
7.4 Legal Authorities: Only when legally mandated by German or EU law to disclose personal data.
7.5 No Sale of Personal Data: Venued does not sell or rent personal data to third parties. The sharing of aggregated and anonymised data (§5.8), the display of sponsored content targeted by Venued (§5.7), the provision of derived model outputs (§5.9), and the transfer of personal data in the context of a business transaction (§7.6) do not constitute a sale of personal data within the meaning of this section.
7.6 Business Transfers: In the event of a merger, acquisition, restructuring, reorganisation, insolvency, or sale of all or a substantial part of Venued's assets or business, your personal data may be transferred to the acquiring or successor entity as part of that transaction. Such a transfer is based on Venued's legitimate interest (Art. 6(1)(f) GDPR) in the continuity of the Service and the legitimate interest of the successor in continuing to provide the Service to existing users. The successor entity will be bound by the purpose limitations set out in this Privacy Policy at the time of transfer until and unless you are notified of changes and given the opportunity to object under Art. 21 GDPR or to request erasure under Art. 17 GDPR. We will notify you of any such transfer and the resulting change of controller via in-app notification or email at least 30 days before it takes effect, except where statutory or contractual confidentiality obligations require a shorter timeline.
7.7 Payment Service Providers: For processing of ticket purchases and paid subscriptions, we use Stripe Payments Europe Ltd. (Ireland) and PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). Full payment card data is processed exclusively by these providers under PCI-DSS; Venued itself receives only tokenised references and transaction metadata. These providers act as independent controllers for their own fraud-prevention and regulatory purposes; details are available in their respective privacy policies (https://stripe.com/privacy and https://www.paypal.com/de/legalhub/privacy-full).
8. INTERNATIONAL DATA TRANSFERS
We process data primarily within the European Economic Area (EEA). Where data is transferred to a "third country" (e.g., USA), the transfer is based on Standard Contractual Clauses (Art. 46 GDPR), supplemented by a Transfer Impact Assessment in accordance with the CJEU "Schrems II" judgment (C-311/18) and EDPB Recommendations 01/2020. Where available, we additionally rely on adequacy decisions of the EU Commission (e.g., EU-U.S. Data Privacy Framework).
Currently we only operate in Germany.
9. DATA RETENTION AND ERASURE
9.1 Account Data: Retained for the duration of the active user relationship.
9.2 Account Deletion: You may request deletion of your account at any time via the app settings or by email to privacy@venued.eu. After a deletion request, a 7-day cancellation window applies during which you may revoke the deletion. Following this window, all personal data is erased within 30 days, unless statutory retention periods (e.g., 6–10 years for financial records under the HGB/AO) apply.
9.3 Retention by data category:
- Account data (§3.1): duration of the active user relationship
- Profile data (§3.2): duration of the active user relationship
- Verification data / phone number hash (§3.3): duration of the active user relationship
- Event interaction data (§3.4): until account deletion
- RSVP & ticket data (§3.5): until account deletion; statutory retention periods unaffected
- Communication data / messages (§3.6): until account deletion
- Technical diagnostic data (§3.7): max. 90 days (Firebase platform default retention)
- Support communications (§3.8): 24 months
- Contact form data (§3.9): 12 months
10. USER RIGHTS (ART. 15-21 GDPR)
You have the following rights:
Art. 15: Right of access to your stored data.
Art. 16: Right to rectify inaccurate data.
Art. 17: Right to erasure ("Right to be forgotten").
Art. 18: Right to restriction of processing.
Art. 20: Right to data portability. Data exports are provided in JSON format within 30 days of a request submitted by email to privacy@venued.eu.
Art. 21: Right to object to processing based on legitimate interests.
Art. 7(3): Right to withdraw consent at any time with future effect.
To exercise these rights, contact: privacy@venued.eu
11. COOKIES AND TRACKING
The app and website use only technical identifiers strictly necessary for core functionality (account login, session continuity, security), as well as first-party diagnostic and usage telemetry from the Firebase platform on the basis of our legitimate interest in service stability and improvement (Art. 6(1)(f) GDPR). Specifically:
Firebase Crashlytics records crash and error reports (stack traces, device model, OS version, app version, and the app state at the time of the error) so that we can diagnose and fix faults.
Firebase Analytics records first-party usage events, principally the in-app screens you visit and basic interaction events. These events also form the breadcrumb trail attached to a crash report, showing the sequence of screens that preceded an error so that we can reproduce and fix it. This is first-party product analytics used solely to operate and improve Venued. It is not used for advertising, and the data is not shared with third parties for their own purposes.
This telemetry is collected only in released versions of the app and is associated with your account identifier so that we can investigate faults you personally encounter. Technical diagnostic data is retained for a maximum of 90 days (see Section 9).
We do not currently use third-party advertising trackers, cross-site tracking pixels, or marketing cookies. If we introduce optional third-party analytics or marketing tracking in the future, users will be asked to provide explicit consent before any such data is collected and will retain the ability to withdraw consent at any time in the app settings.
We do not use "dark patterns" to influence your privacy decisions. Declining optional features will not result in any disadvantage in your use of the core app.
12. PUSH NOTIFICATIONS
If enabled, we use FCM (Google) or APNs (Apple) to send notifications. These services receive a device-bound push token that does not directly identify the user but can be linked to the account on our backend. Notifications can be disabled in the system settings of your mobile device.
13. DATA SECURITY
We implement state-of-the-art Technical and Organizational Measures (TOMs), including:
End-to-end encryption for data in transit (TLS/SSL).
Encryption at rest for databases (AES-256).
Strict access control and logging.
Regular security audits and vulnerability assessments.
We conduct regular reviews of our cloud infrastructure (Google Cloud DPA) to ensure that data processing meets European security standards for 2026.
14. CHILDREN'S PRIVACY
The Service is intended for users aged 18 and older. We do not intentionally collect data from minors. If we become aware of such collection, the data will be deleted immediately.
15. CHANGES TO THIS POLICY
We reserve the right to modify this policy. Users will be notified of material changes via in-app notification or email at least 14 days prior to the effective date.
16. COMPLAINTS AND SUPERVISORY AUTHORITY
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Venued is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany Website: www.lda.bayern.de
