Version: PP-APP-1.5 dated 27.07.2026

Privacy Policy of the Party Sharing App

This English version is an automated translation of the German original. The German version is the authoritative version of this Privacy Policy; in case of discrepancies, Section 27 applies.

1. General information

We, Party Sharing App UG (haftungsbeschränkt), provide the mobile application “Party Sharing App” (“App”).

With this Privacy Policy, we inform you about which personal data is processed when using the App, for which purposes this is done, on which legal basis the processing takes place, to whom data may be disclosed, how long data is stored and which rights data subjects have.

This Privacy Policy applies to the processing of personal data in connection with the use of the App by private user accounts and Business Accounts. Private user accounts include, in particular, Users as well as Users who apply for or use an upgrade to Host. Business Accounts include, in particular, Promoters, for example event organizers, artists, associations, photographers, influencers, bloggers, organizations, self-employed persons and other commercial or professional account holders. This Privacy Policy also applies to other persons who use functions of the App, interact with the App or whose data is processed in connection with Events, @Rooms, media, communication, payments, support, access functions or other functions provided within the App.

Depending on which functions of the App are used, different data may be processed. Not every processing operation described in this Privacy Policy applies to every User.

2. Controller and privacy contact

The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:

Party Sharing App UG (haftungsbeschränkt)

Ravensberger Str. 55

32312 Lübbecke

Germany

E-mail: support@partysharingapp.com

For privacy-related inquiries, the Platform Provider can be contacted via the above e-mail address and via the contact channels stated in the legal notice.

A data protection officer will only be named where there is a legal obligation to do so or where the Platform Provider voluntarily appoints a data protection officer. If no data protection officer has been appointed, the above e-mail address serves as the privacy contact.

3. Scope of this Privacy Policy

This Privacy Policy applies to the processing of personal data in connection with the use of the App, in particular in relation to:

  • registration, login and management of the user account,

  • verification of e-mail address, mobile number and, where applicable, further information,

  • participation in Events and @Rooms,

  • use of QR codes, QR links, invitations and other access functions,

  • use of location and attendance checks,

  • displaying, uploading, storing, processing and downloading media,

  • use of chats, messages, announcements, support and dispute functions,

  • purchase of paid gallery or album access,

  • voluntary support amounts or thank-you contributions,

  • payment processing,

  • use of external ticket providers or online platforms,

  • push notifications and e-mail notifications,

  • security, abuse and fraud prevention,

  • technical error analysis, diagnostics, app optimization and analytics functions.

For the Platform Provider’s website, supplementary or separate privacy notices may apply.

4. Download of the App via app stores

When the App is downloaded via an app store, in particular the Apple App Store or the Google Play Store, personal data may be processed by the respective app store operator.

This may include, in particular, data from the app store user account, the e-mail address or user identifier of the app store account, the time of download, device information, the IP address and technical download and installation data. Where payments or in-app purchases are processed via the respective app store, payment and transaction data may additionally be processed by the respective app store operator. Details are governed by the privacy information of the respective app store operator.

The Platform Provider generally has no influence over this data processing by the respective app store operator. The respective app store operator is responsible for this processing in accordance with its own privacy terms.

The Platform Provider processes data in connection with the download only to the extent necessary for the provision, installation, update or use of the App.

5. Registration, login and user account

Use of the App generally requires registration of a user account. Different personal data may be processed depending on the type of account, role and function used.

5.1 Private user accounts

When registering a private user account, in particular the following data may be processed:

  • e-mail address,

  • password or technical login data,

  • first name and last name, where provided or required for registration,

  • automatically generated nickname or nickname selected by the User,

  • mobile number,

  • User ID,

  • verification status,

  • language settings,

  • App version,

  • time of registration,

  • login times,

  • time of last activity,

  • status of the user account, for example active, deactivated, suspended or deleted.

The nickname may be displayed within the App to other Users, Hosts, Promoters or other authorized persons. First name, last name, e-mail address and mobile number are generally not visible to other Users unless otherwise expressly displayed or enabled within the App.

5.2 Registration of private user accounts via Apple or Google

Private user accounts may also be registered or logged in via third-party login functions, in particular Apple or Google. In this case, depending on the User’s settings and the respective third-party provider, in particular the following data may be transmitted to the Platform Provider:

  • unique third-party provider ID,

  • e-mail address,

  • first name and last name, where provided by the third-party provider,

  • profile picture, where provided by the third-party provider,

  • technical login and authentication data.

If Apple, Google or another third-party provider does not provide a permanently reachable e-mail address or an e-mail address usable for the App, the Platform Provider may require the provision and verification of a separate e-mail address.

5.3 Host upgrade

A private user account may apply for an upgrade to Host, provided that this function is available within the App.

For the review and activation as Host, in particular the following additional data may be processed:

  • full first name and last name,

  • address,

  • date of birth, where required,

  • e-mail address already stored in the user account or confirmed as part of the upgrade,

  • mobile number already stored in the user account or confirmed as part of the upgrade,

  • identity or address proofs,

  • uploaded documents or proofs,

  • review status,

  • time of review,

  • internal review notes,

  • User ID and account status.

This data is processed in order to verify the identity and reachability of the Host, prevent abuse, secure the creation of private Events and be able to trace responsibility for Events created by the Host.

5.4 Business Accounts

For Business Accounts, in particular Promoters, for example event organizers, artists, associations, photographers, influencers, bloggers, organizations, self-employed persons or other commercial or professional account holders, the following data may be processed depending on account type, verification and function used:

  • company name, artist name, association name, organization name or business designation,

  • publicly visible name, display name or nickname of the Business Account,

  • full business or contact address,

  • field of activity,

  • e-mail address for the account,

  • publicly visible contact e-mail address,

  • mobile number,

  • VAT identification number, tax number or other trade or identification number,

  • bank details or payout data, where payments or payouts are made,

  • legal notice details and other legal mandatory information provided by the Business Account,

  • publicly visible profile information,

  • logos, images, descriptions or other profile data,

  • evidence of identity, activity or authorization,

  • review status,

  • approval status,

  • internal review notes,

  • User ID, Account ID and account status.

Certain information of a Business Account may be displayed within the App or in publicly accessible areas, in particular the name or designation of the account holder, publicly visible contact details, legal notice details, profile information, logos, Event information or @Room information. Other information is processed only internally for review, contract performance, payment processing, security and abuse prevention.

5.5 Account logs and activity data

In connection with registration, login, use and management of the user account, technical and organizational log data may be processed.

This may include in particular:

  • time of registration,

  • login and logout times,

  • time of last activity,

  • device used or technical device identifier,

  • IP address, insofar as it is technically processed or logged,

  • App version,

  • operating system,

  • language settings,

  • joining Events or @Rooms,

  • QR code or link use,

  • uploads, downloads and media access,

  • purchases, voluntary support amounts, thank-you contributions and payment status,

  • support and dispute processes,

  • security events,

  • suspensions, deactivations or deletion processes.

This data is processed insofar as this is necessary for providing the App, contract performance, security, abuse prevention, error analysis, traceability of processes, payment processing or handling support and disputes.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for registration, management and provision of the user account as well as for contract performance.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, traceability, error analysis and management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

6. Verification of e-mail address, mobile number and device

To ensure the identity of the User, prevent abuse, multiple registrations and unauthorized access, and secure Event and @Room access, the Platform Provider uses verification procedures.

In particular, the following data may be processed for this purpose:

  • e-mail address,

  • mobile number,

  • one-time code by e-mail for verification of the e-mail address (OTP),

  • SMS code for verification of the mobile number (OTP),

  • time of verification,

  • verification status,

  • User ID,

  • IP address,

  • login and security logs,

  • technical device identifier,

  • device ID or app-related device identifier,

  • on Android devices, in particular Android Secure ID or an app- or device-related identifier derived from it,

  • on iOS devices, in particular Identifier for Vendor (IDFV) or an app- or vendor-related identifier derived from it,

  • App Instance ID or installation identifier,

  • push token,

  • Firebase Installation ID, Firebase App Instance ID or comparable Firebase identifiers, where Firebase services are used,

  • other technical identifiers required for device assignment, security, verification or abuse prevention.

According to the current technical status, the Platform Provider does not collect or store IMEI numbers. The device identifiers used serve in particular for authentication, verification, session management, device assignment, security and abuse prevention. According to the current status, they are not used for advertising, remarketing or marketing tracking.

A user account is not permanently restricted to a single device. If a User logs in on a new device, reinstalls the App, changes device or the device identifier changes, additional verification may be required, in particular by e-mail OTP or by another security procedure provided within the App, before the new device is authorized or linked to the user account.

The App may use technical device or app identifiers in order to assign a user account to a device or installation, avoid multiple registrations, check access authorizations, prevent abusive use and ensure the security of the App.

Where a user account is already linked to a device, use on another device may be restricted or made dependent on additional verification, approval, logout on the previous device or another security procedure.

In the event of a device change, reinstallation, change of mobile number, change of SIM card or other security-relevant changes, the Platform Provider may require renewed verification.

The User is responsible for updating changes to the User’s e-mail address, mobile number, device or other information relevant to verification, security or communication within the App or notifying the Platform Provider, insofar as this is necessary for the use, security, recovery or management of the user account.

If no update is made, individual functions, verifications, security approvals, device changes, access, notifications or contract- and security-related communications may be wholly or partially restricted or misdirected. This may in particular result in verification information, security codes, notices, support replies or other account-related communications being sent to an e-mail address or mobile number that is no longer current or no longer controlled by the User.

Where a device or app identifier is linked to a user account, an e-mail address, a mobile number or a User ID, this is done to secure the user account, prevent abuse, verify access authorizations, prevent unauthorized use and technically provide the App.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for registration, verification and use of the user account.

Art. 6(1)(f) GDPR, insofar as processing is necessary for the security of the App, prevention of abuse, fraud prevention, control of access authorizations and protection against unauthorized use.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

7. Roles, permissions and additional verifications

Depending on use of the App, different roles, permissions or account types may be assigned to a user account.

These include in particular:

  • private user accounts,

  • Hosts,

  • Business Accounts,

  • persons authorized or commissioned by Hosts or Business Accounts,

  • role-related additional permissions,

  • and further roles, permissions or function activations provided within the App.

These may in particular include Assistants, Sub-Promoters, Sub-Accounts, Access Contact or comparable roles, insofar as these are provided or activated within the App.

Business Accounts include commercial, professional or organizational account holders as described in this Privacy Policy. A repeated listing of individual Business Account types is not made in this section.

For certain roles, permissions or function activations, an additional review or verification may be required. This applies in particular to:

  • activation as Host,

  • creation and management of private Events by Hosts,

  • activation and use of Business Accounts,

  • creation, management and publication of Events or @Rooms by Business Accounts,

  • activation of Assistants, Sub-Accounts, Sub-Promoters, Access Contact functions or comparable permissions,

  • provision of paid content,

  • and other functions with increased responsibility, visibility or risk of abuse.

As part of such reviews, data, proofs, review status information, approval status information, internal review notes and times of application, review and approval already stored in the user account or Business Account may be processed.

If additional data is required for a role or function, it will be requested and processed in the respective registration, upgrade, approval or verification process.

The processing is carried out in order to review roles and permissions, prevent abuse, make responsibilities traceable, comply with legal requirements and enable secure use of the respective functions.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for performance of the user agreement, role activation or provision of the respective function.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, verification of authorization, traceability and proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

8. Events, @Rooms and access functions

The App enables Users to access Events and @Rooms. Depending on the Event, @Room, role, permission and settings of the respective Host or Business Account, different access functions may be used.

Access to Events and @Rooms may take place in particular via QR codes, QR links or other access functions provided within the App.

For private Events created by Hosts, access is generally granted only via a targeted invitation, a QR code or a QR link provided by the Host or an authorized person. Private Events are generally not publicly searchable via the App search.

For Events of Business Accounts, subsequent access requests may be possible after the end of the Event during the respective intended availability period or Open Door Phase, provided that this function is made available within the App. In this case, the User may submit a request and provide evidence for this purpose, in particular a ticket or a comparable proof of entitlement. The request may be reviewed, approved or rejected by the responsible Business Account or by persons authorized for this purpose.

Where provided within the App, a person already assigned to the Event may be appointed as Access Contact for non-public Events of Business Accounts or for private Host Events. In this context, in particular User ID, user account, nickname, Event ID, time of appointment, confirmation status, time of confirmation, activation, rejection or deactivation status of the Access Contact function, provided AC links, AC QR codes or other access means provided for this purpose as well as dispatch and delivery information regarding corresponding notifications may be processed.

This data is processed in order to provide the Access Contact function, document the appointment and confirmation in a verifiable manner, enable persons actually entitled to participate to obtain subsequent access, prevent abuse and ensure the security of the access functions.

The e-mail address, mobile number or other direct contact details of the Access Contact are generally not disclosed to the respective Business Account, Primary Promoter or Host, unless this is expressly provided within the App, required for a specific function and legally permissible.

In addition, technical links with external online platforms, ticket providers, online shops or other third-party providers may exist where such functions are available.

QR codes and QR links may have different technical requirements depending on their configuration. These may include in particular an active internet connection, an existing user account, login in the App, a technical check of the verification status of the user account in the background, a location or attendance check or other security checks. Renewed manual verification of the user account is not necessarily required if the user account is already sufficiently verified and the check can be carried out technically in the background.

In connection with Events, @Rooms and access functions, in particular the following data may be processed:

  • User ID,

  • user account,

  • nickname,

  • Event ID,

  • @Room ID,

  • role or permission of the User,

  • time of joining,

  • time of leaving,

  • access status,

  • QR code or QR link used,

  • scan or access time,

  • subsequent access requests for Events of Business Accounts and proofs submitted for this purpose, in particular tickets or comparable proofs of entitlement,

  • review, approval or rejection status of such subsequent access requests by the respective Business Account or by persons authorized for this purpose,

  • appointment as Access Contact,

  • confirmation status and time of confirmation of the Access Contact function,

  • activation, rejection or deactivation status of the Access Contact function,

  • provided AC links, AC QR codes or other access means provided for this purpose as well as dispatch and delivery information regarding corresponding notifications,

  • QR codes, QR links or other invitations provided or subsequently transmitted for private Events by the Host or persons authorized for this purpose,

  • technical verification and security data,

  • device data or app identifiers,

  • verification status,

  • location verification result, insofar as a location check is required,

  • access and security logs.

This data is processed in order to enable access to Events and @Rooms, check access authorizations, prevent unauthorized access, detect abuse, provide invitations or access means, process subsequent access requests for Events of Business Accounts and ensure the security of the App.

Where Events or @Rooms are managed by Hosts or Business Accounts, they may view certain information within the App, insofar as this is provided and necessary for the respective function. This may include in particular information about participants, access, permissions, media, purchases, voluntary support amounts, thank-you contributions, interactions or statistical evaluations.

Statistical evaluations may in particular include:

  • number of likes,

  • number of downloads,

  • number of purchases,

  • number of voluntary support payments and total amount of support amounts,

  • technical status information,

  • and aggregated or function-related evaluations for Events, @Rooms, galleries, albums or media.

Internal technical logs for security, error analysis, abuse prevention or system optimization remain unaffected and may be processed in accordance with this Privacy Policy.

A personalized display of individual user activities to Hosts or Business Accounts only occurs insofar as this is necessary for the respective function, provided accordingly within the App or based on a legal basis. Where a personalized display is not necessary, evaluations may be anonymized, aggregated or provided without directly displaying individual Users.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for participation in Events, joining @Rooms and provision of the respective App functions.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, access control, traceability, statistical evaluation and proper management of Events and @Rooms.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

9. Location data and attendance verification

Certain functions of the App may require a location check, attendance check or location-related display. This applies in particular to location-bound Event access, QR code functions, entitlement checks, security checks, functions for displaying Events in the vicinity, map views or regional Event search functions as well as functions intended to ensure that the User is at the venue or within a specified area.

For location and attendance verification, the App may use in particular the following data depending on device, operating system and permission:

  • GPS location data,

  • Wi-Fi or network-based location information,

  • IP-based location information, insofar as technically processed,

  • places, regions, countries or search parameters entered or selected by the User, insofar as the User uses map, surrounding-area or regional search functions,

  • time of the location check,

  • Event ID or @Room ID,

  • User ID,

  • device used or technical device identifier,

  • result of the location check, for example inside or outside a defined area,

  • technical verification and security logs.

According to the current technical status, exact GPS coordinates are used only temporarily for the respective location or attendance check and are not permanently stored in the Platform Provider’s backend databases. However, the result of the check, in particular inside or outside a defined area, the time of the check, the Event ID, the User ID, device or security metadata and technical verification logs may be stored insofar as this is necessary for access control, security, abuse prevention, traceability, support or disputes.

The location check is generally carried out only insofar as it is required for a specific function, in particular when joining an Event, scanning a QR code, during an access control or during another attendance check provided within the App.

Permanent background monitoring of the location does not take place unless expressly stated otherwise within the App and the required permission or consent has been obtained for this purpose.

The processing is carried out in order to check location-bound access, prevent unauthorized access, detect access abuse, verify participation entitlement, display Events in the vicinity, on a map view or according to selected regions, places or countries, and ensure the security of Events, @Rooms and media access.

Legal bases:

Art. 6(1)(b) GDPR, insofar as the location check is necessary for providing a function requested by the User, for participation in an Event or for checking an access authorization.

Art. 6(1)(f) GDPR, insofar as processing is necessary for abuse prevention, security, fraud prevention, traceability and access control.

Art. 6(1)(a) GDPR, insofar as location processing is based on consent or a device permission.

10. Media, uploads, downloads, watermarks and processing of content

Within the App, media, in particular photos and videos, may be provided, displayed, streamed, uploaded, processed, marked with watermarks or other identifiers, downloaded or stored.

Media may in particular be provided by:

  • Business Accounts,

  • Hosts,

  • persons authorized or commissioned by Business Accounts or Hosts,

  • Users, insofar as the respective upload function has been activated for them within the App,

  • and other authorized content providers or function-authorized persons within the App.

In connection with media, in particular the following data may be processed:

  • User ID,

  • user account,

  • nickname,

  • role or permission of the User,

  • Event ID,

  • @Room ID,

  • gallery ID,

  • album ID,

  • media files,

  • file name,

  • file format,

  • file size,

  • technically available metadata of the original file, in particular creation time, insofar as this is technically provided by the device, operating system or file,

  • upload time,

  • server-side processing or storage time, insofar as an original creation time is not technically available, not clear or not transferable,

  • activation status,

  • watermark or marking information,

  • technical processing data,

  • preview images, thumbnails, compressed versions, streaming versions or download versions,

  • likes and like status,

  • download status, download times and number of downloads,

  • technical display, streaming, access or retrieval events, insofar as these are required for technical provision, error analysis, abuse prevention, system optimization or internal evaluation,

  • technical error or verification logs,

  • reports, complaints or dispute data in connection with media.

Where technically possible, the Platform Provider adopts the creation time or other relevant metadata contained in the original file. However, the Platform Provider cannot guarantee that such metadata is fully, correctly or readably available for every file, every device, every operating system or every transmission. Where such metadata is not available or is not technically unambiguous, server-side times, in particular upload, processing or storage times, may be used.

The processing is carried out in order to provide, display, stream, download, technically process and mark media within the App with watermarks or identifiers, enable uploads and downloads, implement rights and access restrictions, prevent abuse, analyze technical errors and review disputes or rights infringements.

Media uploaded by Business Accounts, Hosts, persons authorized or commissioned by them and Users, insofar as the respective upload function has been activated for them within the App, may be technically processed, compressed, converted into other formats, marked with watermarks, source identifiers, date identifiers or other notices, and provided in suitable versions for preview, streaming, display or download.

This includes in particular media provided within Events, @Rooms, galleries, albums or other media functions provided within the App.

Uploads by Users are permitted only insofar as the upload function has been activated for the respective User, the respective Event, the respective @Room or the respective upload mode within the App.

Where media within an Event or @Room is liked, downloaded, activated as paid content or used in connection with voluntary support amounts, technical and statistical information may be processed in this context. Personalized evaluation or display of individual user activities to Hosts or Business Accounts occurs only insofar as this is provided, necessary or legally permissible for the respective function.

Media may be deleted or made inaccessible after expiry of the respective availability period, Open Door Phase or other defined access period. Longer storage may take place insofar as this is necessary for handling disputes, rights infringements, abuse reports, payment cases, technical evidence, legal obligations or legal defense.

The Platform Provider may create and use screenshots, screen recordings or other representations of the App, platform areas, Event overviews, public Event data, public title images, public preview displays, demo content, the Platform Provider’s own content or content released by the respective authorized person for documentation, training, support, demonstration, presentation or instruction purposes.

Non-public Events, internal Event Rooms, Event galleries, galleries, albums, media, participant content or other restricted-access content are generally used for this purpose only if there is a separate release, consent or other legal basis.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing, displaying, using, activating, uploading or downloading media and for contract performance.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, technical processing, error analysis, traceability, legal defense or proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

11. Chats, messages, support and disputes

The App may provide communication and interaction functions, in particular Event chats, @Room chats, announcements, push or e-mail notifications, support functions, dispute functions and reporting, question, survey, interview or livestream interaction functions, insofar as such functions are available within the App.

In connection with such functions, in particular the following data may be processed:

  • User ID,

  • user account,

  • nickname,

  • role or permission,

  • Event ID,

  • @Room ID,

  • chat or message content,

  • attachments or file types permitted within the App, in particular images, videos, GIFs, PDFs or comparable permitted content,

  • times of sending, receiving or retrieval,

  • read status or technical delivery status, insofar as provided within the App,

  • reports or complaints,

  • support requests,

  • dispute information,

  • purchase, payment, gallery, album or media reference in support or dispute cases,

  • technical verification and processing logs,

  • communication history in connection with the respective matter.

The processing is carried out in order to enable communication within the App, provide announcements, handle support requests, review disputes, clarify technical problems, investigate rights infringements or abuse and ensure the security of the App.

Where support or dispute functions are used, information, evidence and files provided by the User may be processed in order to review and handle the respective matter. For this purpose, assignment to a user account, Event, @Room, album, gallery, medium, purchase transaction, payment or technical process may also be required.

Where a dispute, complaint, rights infringement or suspected abuse concerns other Users, Hosts, Business Accounts, payment service providers or other parties involved, information required for the review may be passed on to the respectively affected or responsible bodies within the App or within the platform organization, insofar as this is necessary and legally permissible.

Communication content may be deleted or restricted if it violates statutory provisions, this Privacy Policy, Terms of Use, third-party rights or security requirements, or if other legitimate reasons exist.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing communication, support or dispute functions as well as for contract performance.

Art. 6(1)(f) GDPR, insofar as processing is necessary for handling inquiries, security, abuse prevention, legal defense, traceability or proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

12. Paid content, voluntary support amounts and payment processing

Paid content or functions may be provided within the App. This concerns in particular paid access to galleries or albums including the media contained therein as well as other digital content or functions expressly marked as paid within the App.

Within the App, Business Accounts may provide a function for voluntary support amounts or thank-you contributions, insofar as this function has been activated for the respective account. This function may be used in particular in connection with Events or @Rooms.

Users may voluntarily select and pay a support amount in order to support the respective authorized Business Account. Such a support amount is voluntary and, unless expressly stated otherwise within the App, does not establish any claim to additional content, services or other consideration.

Hosts cannot provide such support amounts as their own function for private Events created by them, unless a deviating function has been expressly activated and legally regulated within the App.

In connection with paid content, voluntary support amounts and payment processing, in particular the following data may be processed:

  • User ID,

  • user account,

  • Event ID,

  • @Room ID,

  • gallery ID,

  • album ID,

  • medium or digital content,

  • type of transaction, in particular paid gallery or album access or voluntary support amount,

  • selected support amount,

  • price or payment amount,

  • currency,

  • payment status,

  • activation status,

  • time of purchase, activation or payment of the support amount,

  • transaction number,

  • payment reference,

  • product ID or in-app purchase ID,

  • payment provider,

  • app store operator,

  • refund, chargeback or dispute status,

  • technical payment and verification logs,

  • support or dispute data in connection with payments.

Payment processing may take place in particular via app store operators or payment providers, insofar as these are offered within the App. Currently, payments may in particular be processed via in-app purchases in the Apple App Store or Google Play Store. Additional payment methods, payment service providers or payment processors may be added insofar as they are offered within the App.

When payments are made via app store operators or external payment providers, the respective provider processes personal data in accordance with its own privacy information. The Platform Provider regularly receives only such information as is necessary for assignment, activation, verification, accounting, reversal, fraud prevention or handling disputes.

Where paid gallery or album access is purchased, the Platform Provider processes the data required for this purpose in order to activate access, provide download options, prove the purchase and handle any support, dispute, refund or abuse cases.

Where a voluntary support amount or thank-you contribution is paid, the Platform Provider processes the data required for this purpose in order to technically, accounting-wise and organizationally assign the payment transaction, check the payment status, assign the amount to the respective Business Account, prepare settlements or payouts, enable internal or aggregated evaluations and handle support, dispute, refund, abuse or review processes.

Information about payments, purchases or voluntary support amounts is generally provided to the respective Business Account only to the extent necessary for the respective function, settlement, payout, traceability, support handling, dispute review or legal obligations.

Where personalized display of individual Users is not necessary, information is generally provided to Business Accounts in anonymized or aggregated form or without directly displaying individual Users. Personalized display of individual Users occurs only where expressly provided within the App, required for the respective function or legally permissible.

Payment, accounting and transaction data may be stored for longer periods due to statutory commercial, tax or other retention obligations.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for carrying out paid purchase transactions, activating digital content, processing voluntary support amounts or thank-you contributions or for contract performance.

Art. 6(1)(c) GDPR, insofar as statutory retention, tax, bookkeeping or evidence obligations exist.

Art. 6(1)(f) GDPR, insofar as processing is necessary for payment verification, fraud prevention, security, accounting, dispute handling, legal defense or proper management of the App.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

13. External ticket providers, online platforms and technical links

Within the App, notices, links, redirects or technical links to external online platforms, ticket providers, online shops, websites or profile pages of Promoters, data providers, map, geocoding, location or surrounding-area services or other third-party providers may be provided where such functions are available within the App.

For certain technical redirects, invitation links, QR links, deep links, App Links, Universal Links or comparable links within or outside the App, the Platform Provider may use its own technical deep-link or linking functions. According to the current technical status, Firebase Dynamic Links are not used for this purpose.

According to the current technical status, no personal user account data, device data, App Instance IDs, IP addresses or tracking parameters are permanently stored via these own deep-link or linking functions. Technically required access, redirect, security or server logs remain unaffected, insofar as these are necessary for technical provision, security, error analysis, abuse prevention or traceability and are processed in accordance with this Privacy Policy.

Unless expressly stated otherwise, the Platform Provider itself does not sell event tickets, vouchers, reservations or other services of external third-party providers. The purchase of such services generally takes place via the respective external provider in accordance with that provider’s own contractual and privacy terms.

Where the User is redirected via the App to external online platforms, ticket providers, online shops or other third-party providers, personal data may be processed by the respective third-party provider. The Platform Provider generally has no influence over this where the processing takes place outside the Platform Provider’s technical systems.

Where technical links exist between external online platforms, ticket providers, online shops or other third-party providers and the Platform Provider’s technical systems, in particular the following data may be processed:

  • User ID,

  • e-mail address or other identifier required for assignment,

  • Event ID,

  • @Room ID, where affected,

  • ticket, order, booking or transaction reference,

  • status of an external booking, order or entitlement,

  • time of transmission or linking,

  • confirmation or verification status,

  • technical interface and verification logs,

  • error, status or security information in connection with the technical link.

Such processing may in particular take place in order to assign externally purchased access to an Event, @Room, user account or specific function within the App, check participation entitlement, enable automatic or manual activation, prevent abuse or handle support and disputes.

Where the User consents with an external provider to data being transmitted to the Platform Provider, the Platform Provider processes the transmitted data only to the extent required for this purpose, in particular to assign the user account, activate the respective Event or @Room, check entitlement and technically provide the respective function.

Where external providers process personal data independently, their own privacy information additionally applies. The Platform Provider is responsible for such independent data processing by external providers only insofar as this is provided by law or the Platform Provider itself determines the purposes and means of processing.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing a function requested by the User, assigning external access or for contract performance.

Art. 6(1)(f) GDPR, insofar as processing is necessary for access control, abuse prevention, technical verification, error analysis, traceability or proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

14. Push notifications, e-mail and SMS messages

The App may use push notifications, e-mail messages, SMS messages or other messages provided within the App in order to inform the User about app-, account-, security-, contract-, event- or function-related processes.

For push notifications, the Platform Provider may use Firebase Cloud Messaging (FCM), a Google service, or comparable push services. In this context, in particular push tokens, device or app identifiers, App version, operating system, language settings, time of dispatch, delivery status, technical log data and the content or technical reference of the respective notification may be processed insofar as this is necessary for delivery, management, security, error analysis or traceability of push notifications.

Push notifications may in particular concern account-, security-, verification-, event-, @Room-, access-, media-, support-, disruption- or function-related information. Non-essential advertising, marketing or campaign messages are sent only where consent exists or another legal basis applies.

These may include in particular the following messages:

  • verification and security messages,

  • OTP codes or other one-time codes,

  • notices regarding registration, login, device change or account recovery,

  • notices regarding Events, @Rooms, invitations or access functions,

  • announcements within Events or @Rooms,

  • notices regarding uploads, downloads, media, galleries or albums,

  • purchase, payment, activation or refund information,

  • information regarding voluntary support amounts or thank-you contributions,

  • support replies,

  • dispute information,

  • technical notices,

  • changes to legal documents,

  • security warnings,

  • and other messages required for use of the App or activated by the User.

In connection with push notifications and e-mail messages, in particular the following data may be processed:

  • User ID,

  • user account,

  • e-mail address,

  • mobile number, insofar as required for OTP, security, account, support, disruption, recovery, Event, @Room or other app-, contract- or function-related messages,

  • push token,

  • device identifier or app identifier,

  • language settings,

  • notification settings,

  • delivery status,

  • opening or interaction status, insofar as technically processed and legally permissible

  • time of dispatch,

  • content or subject of the message,

  • technical delivery and error logs.

Contract-related, security-relevant, technically necessary or function-related messages may also be sent without separate advertising consent, insofar as they are necessary for providing the App, for security, contract performance, compliance with legal obligations or safeguarding legitimate interests. In justified exceptional cases, this may also include SMS messages, in particular in the event of technical disruptions, account or login problems, security-relevant processes or important notices regarding Events or @Rooms that the User has already joined or uses within the App.

Messages relating to advertising, marketing, general recommendations, campaigns or non-essential information are sent only where consent exists or another legal basis applies. This applies in particular to promotional SMS messages.

The User may change notification settings within the App or via the settings of the User’s device, insofar as this is technically provided. If push notifications are deactivated or contact details, in particular e-mail address or mobile number, are not kept up to date, individual functions, notices, security information, support information or contract-related messages may be restricted, delayed or misdirected.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing the App, performing the user agreement or transmitting contract-related messages.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, technical communication, traceability or proper management of the App.

Art. 6(1)(c) GDPR, insofar as statutory information obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent, in particular for optional push notifications, marketing or comparable non-essential messages.

15. Security, abuse control and logging

The Platform Provider processes personal data and technical log data in order to ensure the security of the App, user accounts, Events, @Rooms, media, payment transactions, access functions and technical systems.

According to the current technical status, the mobile App does not use dedicated client-side logging systems for analytics or behavioral tracking. This does not affect technically required operational, security, access, authentication, API, error and abuse logs in backend systems or other technical systems of the Platform Provider, insofar as these are necessary for provision, security, error analysis, abuse prevention, support or legal defense.

The processing serves in particular to:

  • detect and prevent unauthorized access,

  • prevent abuse of user accounts, QR codes, QR links, invitations or other access functions,

  • detect multiple registrations, spam, fraud attempts or manipulations,

  • check device changes, suspicious logins or unusual activities,

  • detect GPS, location, IP or device manipulations,

  • detect VPN, proxy, emulator, bot, scraping or other technical circumvention attempts,

  • enforce technical protective measures,

  • review unlawful content, rights infringements or violations of Terms of Use,

  • be able to trace payment, purchase, activation, refund or dispute processes,

  • analyze errors, crashes, security events or technical disruptions,

  • protect the integrity, stability and availability of the App,

  • fulfill legal obligations,

  • assert, defend against or prove claims.

As part of security, abuse and logging functions, in particular the following data may be processed:

  • User ID,

  • user account,

  • role or permission,

  • e-mail address,

  • mobile number,

  • IP address, insofar as technically processed or logged,

  • device identifier, app identifier or installation identifier,

  • push token,

  • App version,

  • operating system,

  • device type,

  • login and logout times,

  • time of last activity,

  • QR code, QR link or access use,

  • Event ID,

  • @Room ID,

  • gallery ID,

  • album ID,

  • purchase, payment or activation status,

  • upload, download, streaming or media access,

  • location verification results, insofar as location checks are required,

  • technical error, security and system logs,

  • suspension, review, approval, rejection, deactivation or deletion processes,

  • support, dispute, complaint or abuse reports,

  • technical indications of manipulations, circumvention attempts or unusual usage patterns.

Security and log data is processed only insofar as this is necessary for provision, security, abuse prevention, error analysis, traceability, legal defense or proper management of the App.

Where there is suspicion of abuse, fraud, rights infringements, security incidents or other impermissible use, the affected data may be stored and evaluated for the duration of the review, handling and legal clarification.

Where required or permitted by law, security-relevant information may be transmitted to authorities, courts, legal advisers, payment service providers, app store operators or other competent bodies.

The specific storage periods for security, access, dispute, payment and log data are described in Section 22 of this Privacy Policy.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for secure provision of the App, performance of the user agreement or review of contractual claims.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, abuse prevention, fraud prevention, error analysis, traceability, legal defense and proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

16. Technical permissions of the end device

For certain functions of the App, technical permissions, access rights or settings of the mobile end device may be required. Which permissions are specifically required depends in particular on the operating system, the end device, the App version, the activated functions and the respective Event, @Room, upload, download, communication or access functions.

These may include in particular:

  • camera,

  • microphone,

  • media library of the end device, in particular photo and video gallery or file selection,

  • storage or download functions,

  • location services,

  • map and surrounding-area functions, insofar as these are used within the App,

  • push notifications,

  • internet and network access,

  • background activity or background services,

  • battery or energy optimization settings,

  • QR code scanning,

  • audio and media playback,

  • contact access, insofar as a contact or invitation function is provided within the App and activated by the User,

  • and other technical permissions, insofar as they are required for the respective function.

The permissions may in particular be required in order to:

  • scan QR codes,

  • take photos or videos,

  • select media from the gallery or media library,

  • upload media,

  • download media and store it on the end device,

  • play media, videos, livestreams or other content,

  • use chat, support, dispute or interaction functions,

  • carry out location or attendance checks and display Events in the vicinity, on a map view or according to selected regions, places or countries,

  • receive push notifications,

  • enable automatic uploads or background processes, insofar as such functions are available,

  • use invitations or contact functions, insofar as such functions are available,

  • and ensure the security, functionality and technical provision of the App.

The User may grant, restrict or withdraw individual permissions via the settings of the User’s end device or, where provided, within the App. If required permissions are not granted or are subsequently deactivated, individual functions of the App may be wholly or partially unusable.

The App processes data from such permissions only insofar as this is required for the respective function, consent exists, processing is required for performance of the user agreement or another legal basis exists.

Where the App stores information on the end device or accesses information stored there, this occurs only insofar as this is technically required or required consent exists.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing the App function requested by the User or for performing the user agreement.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, technical functionality, error prevention, abuse prevention or proper management of the App.

Art. 6(1)(a) GDPR, insofar as processing is based on consent or a device permission granted by the User.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

17. Analytics, diagnostics and improvement of the App

The Platform Provider may process technical usage, diagnostic, error, crash, performance and analytics data in order to provide the App, ensure its security, stability and functionality, detect technical errors, prevent abuse, improve the user experience and further develop the App.

In this context, in particular the following data may be processed:

  • User ID or pseudonymous identifier,

  • App Instance ID or installation identifier,

  • device identifier or app identifier,

  • App version,

  • operating system and operating system version,

  • device type and device model,

  • language settings,

  • country or approximate region, insofar as technically processed,

  • IP address, insofar as technically processed or logged,

  • times of use,

  • session data,

  • technical events within the App,

  • function calls,

  • error reports,

  • crash reports,

  • performance data,

  • loading times,

  • network or connection information,

  • technical status information,

  • security events,

  • diagnostic and system logs.

The processing may in particular take place in order to:

  • detect and remedy technical errors,

  • analyze crashes and malfunctions,

  • improve the stability and security of the App,

  • optimize technical performance and loading times,

  • detect abuse, manipulations or unusual usage patterns,

  • improve functions and user guidance,

  • statistically evaluate the use of certain functions,

  • plan, test or optimize new functions,

  • adapt the App to operating systems, end devices or technical requirements.

Where data is required for security, technical stability, error analysis, abuse prevention or technical provision of functions that the User actively calls up or uses within the App, processing may take place on the basis of contract performance or legitimate interests.

Where analytics, tracking, product analytics, user behavior or marketing functions are used that are not technically necessary, processing takes place only where consent exists or another legal basis applies. This applies in particular where information is stored on or read from the end device and consent is legally required.

The Platform Provider generally does not use analytics and diagnostic data to evaluate private chat content, private media content or payment data in terms of content, unless this is required for support, disputes, security checks, rights infringements, abuse review or legal obligations.

Specific information regarding analytics or diagnostic services used, in particular Firebase Crashlytics as well as any further services such as Google Firebase Analytics or Mixpanel that may be used, is described in the following sections of this Privacy Policy.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing the App, technical troubleshooting or performance of the user agreement.

Art. 6(1)(f) GDPR, insofar as processing is necessary for security, stability, error analysis, abuse prevention, system optimization, statistical evaluation or further development of the App.

Art. 6(1)(a) GDPR, insofar as processing is based on consent, in particular for optional analytics, tracking, product analytics, user behavior or marketing functions.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

18. Google Firebase services

According to the current technical status, the Platform Provider uses Firebase Cloud Messaging (FCM) for push notifications and Firebase Crashlytics for crash reports and technical diagnostic information. According to the current technical status, Firebase Dynamic Links are not used for deep-link or linking functions.

Depending on the function, in particular push tokens, device or app identifiers, App Instance or installation identifiers, operating system, App version, language settings, technical delivery, opening, error, crash, diagnostic or log data and times of the respective technical processes may be processed.

Firebase Crashlytics is used to collect crash reports and technical diagnostic information. The processing is carried out on the basis of the Platform Provider’s legitimate interests pursuant to Art. 6(1)(f) GDPR. The legitimate interest consists of identifying technical errors, analyzing crashes, improving the stability, security and functionality of the App and technically developing the App.

Crashlytics reports may include, in particular, technical information such as device type or device model, operating system and operating system version, App version, time of the crash, technical error data, stack traces, diagnostic information, App Instance or installation identifiers and comparable technical log data. Firebase Crashlytics is not used for advertising, remarketing, marketing purposes, personalized advertising, user profiling or campaign measurement.

According to the current technical status, the Platform Provider does not actively transmit plain-text e-mail addresses, mobile numbers, names, payment data, private chat content, uploaded media content, document content, precise GPS coordinates or comparable personal content data to Firebase Crashlytics. The User may disable the collection of Crashlytics crash reports for the future within the App settings. After deactivation, no further Crashlytics crash reports will be collected. Technically required operational, security or backend logs remain unaffected, insofar as they are processed in accordance with this Privacy Policy.

Additional Firebase or Google services outside Firebase Cloud Messaging and Firebase Crashlytics, in particular Firebase Analytics, Google Analytics for Firebase, Performance Monitoring, Remote Config, App Check as well as advertising, marketing or tracking functions such as Google Signals, ad personalization, remarketing, advertising attribution or comparable functions, are not actively used according to the current technical status, unless expressly stated otherwise. If such additional services are activated in the future, the information regarding provider, purpose, data categories, legal bases, storage period, possible transfers to third countries and any required consents will be supplemented before the respective processing begins. Where consent is legally required for this, it will be obtained before the processing begins.

19. Mixpanel

According to the current technical status, Mixpanel is not used in the production version of the App.

If Mixpanel or a comparable analytics or product analytics service is used within the App in the future, this Privacy Policy will be supplemented before the respective processing begins. In particular, the provider, purposes, data categories, identifiers used, storage period, server location, EU Data Residency, endpoints used, transfers to third countries, legal bases and consent and withdrawal options will be described.

If consent is required for this, Mixpanel or a comparable optional analytics service will be activated only after the required consent has been given. The User should be able to reject such consent within the App or withdraw it later, insofar as this is legally required.

20. Recipients, processors and third-party providers

The Platform Provider discloses personal data only insofar as this is necessary for providing the App, performing the user agreement, processing functions, payment processing, security, abuse prevention, handling support or disputes, fulfilling legal obligations or on the basis of consent.

Recipients of personal data may in particular be:

  • technical service providers and hosting providers,

  • IT, maintenance, security and support service providers,

  • app store operators, in particular Apple and Google,

  • payment providers, payment service providers or payment processors,

  • providers of analytics, diagnostic, error or crash reports, insofar as such services are used,

  • providers of push notifications, e-mail dispatch, SMS/OTP dispatch, verification services or communication services,

  • providers of map, geocoding, location or surrounding-area services, insofar as such services are used within the App,

  • external ticket providers, online platforms, online shops, data providers or other third-party providers, insofar as technical links, redirects, affiliate or assignment functions exist or are provided within the App in the future,

  • Hosts or Business Accounts, insofar as they receive information within the App about Events, @Rooms, access, media, purchases, voluntary support amounts, support or disputes and this is necessary for the respective function or legally permissible,

  • persons authorized or commissioned by Hosts or Business Accounts, insofar as they receive corresponding permissions within the App on behalf of the respective Host or Business Account and need to view or process information for this purpose,

  • legal advisers, tax advisers, auditors or other professional advisers,

  • authorities, courts, law enforcement authorities or other public bodies, insofar as there is a legal obligation or the disclosure is necessary for prosecution, legal defense or averting danger.

In the case of a mere redirection to external ticket providers, online shops, websites or profile pages of Promoters or other third-party providers, the Platform Provider generally does not transmit user account data to the respective third-party provider unless this is required for the respective function, the User enters the corresponding information with the third-party provider or transmission is expressly provided within the App and legally permissible.

Where technical identifiers, parameters, cookies, tracking links or comparable information are used for redirects, affiliate, assignment or commission functions, this occurs only in accordance with this Privacy Policy and, where required, on the basis of consent.

Where service providers process personal data on behalf of the Platform Provider as processors, this is done on the basis of a processing agreement or another data-protection instrument required under data protection law pursuant to Art. 28 GDPR, insofar as such an instrument is required. This may also be based on the contractual terms or data protection agreements provided by the respective service provider.

Where third-party providers process personal data under their own responsibility, their own privacy information additionally applies. This applies in particular to app store operators, payment providers, external ticket providers, online shops or other external platforms, insofar as they themselves determine the purposes and means of processing.

Personal data is disclosed to Hosts, Business Accounts or persons authorized by them only insofar as this is provided within the App, necessary for the respective function or legally permissible. Where possible, information may be provided anonymized, aggregated or without directly displaying individual Users.

The Platform Provider does not sell personal data to third parties.

Legal bases:

Art. 6(1)(b) GDPR, insofar as disclosure is necessary for performance of the user agreement, provision of the App or processing of individual functions.

Art. 6(1)(c) GDPR, insofar as there is a legal obligation to disclose.

Art. 6(1)(f) GDPR, insofar as disclosure is necessary for security, abuse prevention, legal defense, enforcement of claims, technical provision and proper management of the App.

Art. 6(1)(a) GDPR, insofar as disclosure is based on consent.

21. Transfers to third countries

The Platform Provider intends to process central platform data and user account data, as far as possible, within the European Union or the European Economic Area, in particular in Germany. Depending on the function used, service provider used, app store operator, payment provider, analytics or diagnostic service, technical location, regional App availability, media provision or international provision of the App, however, processing or transfers of personal data outside the European Union or the European Economic Area may occur.

Where the App is provided in countries outside the European Union or the European Economic Area, additional regional technical infrastructures, servers, hosting providers, payment providers, communication providers or other service providers may be used for Users, media content, technical delivery, performance, availability or regional functions there.

The Platform Provider intends not to transfer personal data of Users from the European Union or the European Economic Area to regional servers outside the European Union or the European Economic Area without an appropriate data protection basis. However, data exchange between regional systems and central systems of the Platform Provider may be necessary, in particular for account management, security, abuse prevention, payment processing, support, dispute handling, technical synchronization, media provision or proper provision of the App.

Such processing or transfers outside the European Union or the European Economic Area may in particular become relevant for internationally active service providers, app store operators, payment providers, analytics, diagnostic, security, support, communication or cloud services.

Personal data is transferred to a third country only where the data protection requirements for this are met. This may in particular be the case if:

  • an adequacy decision of the European Commission exists for the country concerned,

  • appropriate safeguards exist, in particular through the conclusion or incorporation of the EU Standard Contractual Clauses or comparable data protection mechanisms,

  • additional technical or organizational safeguards are used,

  • the transfer is necessary for contract performance,

  • the transfer is necessary for the establishment, exercise or defense of legal claims,

  • there is a legal obligation,

  • or the User has expressly consented after being provided with corresponding information.

Where individual providers, in particular app store operators, payment providers, analytics or diagnostic services, process personal data in third countries, the details are described in the respective sections of this Privacy Policy or in the privacy information of the respective providers.

For currently used Firebase services, in particular Firebase Cloud Messaging and Firebase Crashlytics, depending on technical provision, device, operating system, app store environment, Google infrastructure or regional availability, processing or transfers outside the European Union or the European Economic Area cannot be completely ruled out. Details are additionally governed by the privacy information and technical terms of the respective provider. According to the current technical status, Firebase Dynamic Links are not used.

Firebase Crashlytics may be used in accordance with this Privacy Policy for technical error analysis and stability improvement on the basis of legitimate interests. Google Firebase Analytics and Mixpanel are not used according to the current technical status, unless expressly stated otherwise. If further optional analytics, tracking, product analytics, marketing or non-technically required diagnostic services are activated in the future, information regarding server location, EU Data Residency, endpoints used, data categories, legal bases, any required consents and possible transfers to third countries will be supplemented before processing begins.

When selecting and integrating service providers used, the Platform Provider takes into account the available data protection, security and transfer bases insofar as this is required for the respective service. This may include in particular reviewing provider information, privacy terms, processing agreements, Standard Contractual Clauses, certifications or comparable evidence.

The legal bases named below relate to the processing of personal data pursuant to Art. 6 GDPR. Insofar as personal data is transferred to third countries, the requirements for transfers to third countries under Chapter V GDPR must additionally be observed.

Legal bases:

Art. 6(1)(b) GDPR, insofar as processing or transfer is necessary for performing the user agreement or providing the respective function.

Art. 6(1)(f) GDPR, insofar as transfer is necessary for technical provision, security, error analysis, abuse prevention, legal defense or proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

Art. 6(1)(a) GDPR, insofar as the transfer is based on consent.

22. Storage period and deletion

The Platform Provider stores personal data only for as long as this is necessary for the respective processing purposes, a statutory retention obligation exists, storage is necessary for the establishment, exercise or defense of legal claims or another legal basis permits storage. The specific implementation of deletion and retention periods is carried out according to internal deletion rules and a deletion concept that takes into account the respective data categories, purposes, systems, periods and technical deletion processes.

The specific storage period depends in particular on:

  • type of data,

  • purpose of processing,

  • function used,

  • role or permission of the User,

  • contract term,

  • statutory retention obligations,

  • security and abuse risks,

  • open support, dispute, payment, legal or review processes,

  • technical deletion, backup and retention cycles.

22.1 User account and account data

User account data is generally stored for the duration of the existence of the user account.

If a user account is deleted, the personal data of the user account is deleted or anonymized, unless statutory retention obligations, security reasons, open disputes, payment or accounting processes, abuse reviews, legal claims or other legitimate reasons prevent immediate deletion.

Logs regarding deletion, deactivation, suspension or restoration processes may be stored for an appropriate period insofar as this is necessary for traceability, security, abuse prevention or legal defense.

22.2 Verification, security and device data

Verification data, security logs, device identifiers, app identifiers, login logs and comparable technical data are stored for as long as this is necessary for the security of the user account, verification, abuse prevention, prevention of unauthorized access, review of device changes or technical provision of the App.

Where such data is no longer necessary for the original purpose, it is deleted, anonymized or restricted in its processing unless legal obligations, disputes, security incidents or legal claims prevent this.

22.3 Events, @Rooms, access and log data

Data in connection with Events, @Rooms, access functions, QR codes, QR links, location checks, joins, approvals, access requests and security logs is stored for as long as this is necessary for providing the respective function, access control, abuse prevention, traceability, handling support or disputes or legal defense.

Regular access, security and event logs may be stored for an appropriate period. In the event of suspected abuse, security incidents, disputes, payment relevance, suspensions, rights infringements or other review processes, longer storage may take place until completion of the respective process and beyond within the framework of statutory limitation or retention periods.

22.4 Media, galleries, albums and event-related content

Media, galleries, albums, preview images, thumbnails, streaming versions, download versions, watermarked media versions, chat content and other event-related content are generally provided only for the respective availability period, Open Door Phase or other defined access period.

Watermarks, logos, markings or other profile data stored in the user account, Host account or Business Account may remain stored independently thereof for the duration of the respective account or respective function unless deleted by the account holder or another reason for deletion exists.

After expiry of the respective availability period, Open Door Phase or other defined access period, content may be deleted, blocked, archived or made inaccessible.

After expiry of the respective availability period, Open Door Phase or other defined access period, an additional technical follow-up, review or backup period may exist, in particular in order to implement deletion processes, update backups, review disputes, prevent abuse, handle rights infringements, clarify payment or support processes or remedy technical errors.

Event-related media content is generally deleted or made inaccessible after expiry of the respective availability period, unless disputes, complaints, suspected abuse, payment or accounting questions, authority requests, rights infringements, legal obligations, legal claims or other legitimate reasons require longer storage.

22.5 Purchases, payments, support amounts and accounting

Purchase, payment, activation, refund, chargeback, accounting and transaction data is stored for as long as this is necessary for payment processing, activation of digital content, handling support or disputes, settlement with Business Accounts, fraud prevention, traceability, bookkeeping, tax obligations or legal defense.

Where statutory commercial, tax or other retention obligations exist, the affected data is stored for the respective legally prescribed period.

22.6 Support, disputes, complaints and legal enforcement

Data in connection with support requests, disputes, complaints, reports, rights infringements, suspected abuse, suspensions or other review processes is stored for the duration of handling.

After completion of the respective process, the data may be stored for an appropriate follow-up period insofar as this is necessary for traceability, abuse prevention, quality assurance, legal defense or for the establishment, exercise or defense of claims.

Where statutory retention periods, limitation periods, authority requests or ongoing legal proceedings are affected, longer storage may be required.

22.7 Analytics, diagnostics and log data

Analytics, diagnostic, error, crash, performance, security and system log data is stored for as long as this is necessary for technical error analysis, security, stability, abuse prevention, system optimization, statistical evaluation or further development of the App.

The specific storage period may vary depending on the service used, technical configuration, purpose and legal basis. Details regarding analytics, diagnostic and logging services used or to be used in the future can be found in the respective sections of this Privacy Policy. Firebase Crashlytics may be used for technical error analysis and stability improvement on the basis of legitimate interests. If optional analytics, tracking or product analytics services such as Firebase Analytics, Mixpanel or comparable services are activated in the future, the information will be supplemented before the corresponding processing begins and, where legally required, consent will be obtained.

22.8 Backups and technical deletion periods

Data may temporarily be contained in backups, backup copies, logs or technical caches.

Backups are not used for active use of the data but serve system security, recovery, integrity and fail-safety of the App. Data in backups is deleted or overwritten as part of the technical backup and deletion cycles unless a legal obligation or a special security, dispute or legal reason makes longer storage necessary.

22.9 Anonymization and statistical evaluations

Where personal data is no longer required for the original purpose, it may be deleted, anonymized or aggregated.

Anonymized data or aggregated statistical evaluations that no longer allow conclusions to be drawn about an identified or identifiable person may continue to be used for statistical evaluations, technical analyses, product improvement, security analyses or business evaluations.

Legal bases:

Art. 6(1)(b) GDPR, insofar as storage is necessary for performing the user agreement or providing the respective function.

Art. 6(1)(c) GDPR, insofar as statutory retention or evidence obligations exist.

Art. 6(1)(f) GDPR, insofar as storage is necessary for security, abuse prevention, error analysis, traceability, legal defense, establishment or defense of claims or proper management of the App.

Art. 6(1)(a) GDPR, insofar as storage is based on consent.

23. Consents and withdrawal

Where the processing of personal data is based on consent, the Platform Provider obtains the User’s consent before the respective processing begins, insofar as this is legally required.

Consents may be required in particular for:

  • optional analytics, tracking or product analytics functions,

  • optional push notifications or non-essential messages,

  • marketing or campaign functions, insofar as such functions are available,

  • certain location functions, insofar as these are not required for a function requested by the User,

  • access to certain functions or data of the end device, insofar as consent is legally required for this,

  • storing information on the end device or accessing information on the end device, insofar as this is not technically required,

  • and other optional functions for which consent is legally required.

The User may withdraw consent given at any time with effect for the future. The withdrawal does not affect the lawfulness of processing carried out on the basis of consent before the withdrawal.

The withdrawal may take place in particular within the App, via the settings of the end device or via the contact channels provided by the Platform Provider, insofar as this is provided for the respective consent.

Where consent management is provided within the App, in particular for optional analytics, tracking, product analytics or marketing functions, the Platform Provider may process in particular User ID, consent status, time of granting, time of withdrawal, consent version, App version, language setting, country or region and technical consent log data for evidence and management purposes.

According to the current technical status, there is currently no separate analytics consent screen because Firebase Analytics, Google Analytics for Firebase, Firebase Performance Monitoring, Firebase Remote Config, Firebase App Check, Google Signals, ad personalization, remarketing, advertising attribution and Mixpanel are not actively used. Firebase Crashlytics is not treated as an optional analytics or tracking service in this context, insofar as it is used exclusively for technical error analysis, crash diagnostics, stability, security and troubleshooting on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR. If optional analytics, tracking, product analytics, marketing or comparable services are activated in the future, the required consents should be obtained before processing begins and designed to be withdrawable within the App, insofar as this is legally required.

If consent is withdrawn or a required permission is deactivated, this may result in individual functions of the App no longer being usable in whole or in part. This applies in particular where the respective processing or permission is technically or legally required for the requested function.

Where consent for optional analytics, tracking, marketing, campaign or comparable non-essential functions is withdrawn, the relevant processing will be terminated for the future unless another legal basis for the processing exists.

Where the App stores information on the end device or accesses information in the end device, this occurs only insofar as this is technically required or required consent exists. This applies in particular in accordance with the respectively applicable provisions for the protection of privacy in terminal equipment.

The Platform Provider may process evidence of granted, changed or withdrawn consents insofar as this is necessary for traceability, management of consents, fulfillment of legal obligations or legal defense.

Legal bases:

Art. 6(1)(a) GDPR, insofar as processing is based on consent.

Art. 6(1)(b) GDPR, insofar as processing is necessary for providing a function requested by the User.

Art. 6(1)(f) GDPR, insofar as processing is necessary for traceability, management of consents, security, legal defense or proper management of the App.

Art. 6(1)(c) GDPR, insofar as legal obligations exist.

24. Rights of data subjects

Data subjects have rights in relation to personal data concerning them in accordance with the statutory provisions.

These include in particular:

  • the right of access to the personal data processed pursuant to Art. 15 GDPR,

  • the right to rectification of inaccurate personal data pursuant to Art. 16 GDPR,

  • the right to erasure of personal data pursuant to Art. 17 GDPR,

  • the right to restriction of processing pursuant to Art. 18 GDPR,

  • the right to data portability pursuant to Art. 20 GDPR,

  • the right to object to certain processing pursuant to Art. 21 GDPR,

  • the right to withdraw consent given at any time with effect for the future,

  • and, where applicable, rights in connection with automated decision-making in individual cases including profiling pursuant to Art. 22 GDPR.

To exercise these rights, the data subject may contact the Platform Provider using the contact details stated in this Privacy Policy.

The Platform Provider may require an appropriate identity check in order to handle a request, insofar as this is necessary to ensure that personal data is not disclosed, changed or deleted without authorization to third parties.

Exercising the rights is generally free of charge. In the case of manifestly unfounded or excessive requests, the Platform Provider may charge a reasonable fee or refuse to act on the request in accordance with the statutory provisions.

Where statutory retention obligations, legal claims, security reasons, disputes, abuse reviews, payment or accounting processes or other legally permissible reasons prevent this, deletion or restriction of processing may be wholly or partially excluded or delayed.

The Platform Provider responds to requests from data subjects within the statutory periods. As a rule, a response is provided within one month of receipt of the request. This period may be extended in accordance with the statutory provisions if this is necessary due to the complexity or number of requests.

Where a request is submitted electronically, the response will also be provided electronically where possible, unless the data subject requests otherwise and no legal or technical reasons prevent this.

25. Right to lodge a complaint with a supervisory authority

Data subjects have the right to lodge a complaint with a data protection supervisory authority if they consider that the processing of their personal data violates data protection regulations.

The complaint may in particular be lodged with the data protection supervisory authority of the Member State in which the data subject has their habitual residence, place of work or the place of the alleged infringement.

The data protection supervisory authority of the federal state in which the Platform Provider has its respective registered office is generally responsible for the Platform Provider unless another supervisory authority is competent.

The exercise of other administrative or judicial remedies remains unaffected.

26. Amendments to this Privacy Policy

The Platform Provider may amend this Privacy Policy with effect for the future insofar as this becomes necessary due to technical, functional, organizational, legal or factual changes.

Amendments may become necessary in particular in the event of:

  • changes to the App or individual functions,

  • introduction of new functions, services or roles,

  • changes to service providers, processors or third-party providers used,

  • changes to analytics, diagnostic, payment, communication or security services,

  • changes to the technical infrastructure or regional provision of the App,

  • changes to statutory requirements, regulatory requirements or case law,

  • adjustments to storage, deletion, security or verification processes.

The current version of the Privacy Policy is available via the “Legal” section within the App and on the Platform Provider’s website. The App may refer for this purpose to the Platform Provider’s website or to a current version of the Privacy Policy provided there.

Where amendments have significant effects on the processing of personal data, the Platform Provider informs the data subjects in an appropriate manner, in particular within the App, by push notification, by e-mail or by another suitable means.

Where consent is required for certain new or changed processing, the Platform Provider will obtain this consent before the respective processing begins, insofar as this is legally required.

27. Status and version

This Privacy Policy applies in its current version.

The authoritative version of this Privacy Policy is the German version. Where this Privacy Policy is translated into other languages, those translations serve better comprehensibility. In the event of deviations, ambiguities or contradictions between the German version and a translation, the German version shall prevail, to the extent legally permissible. Mandatory statutory requirements regarding language, transparency or privacy information in other countries remain unaffected.

The current version may be clearly identified by version numbers, dates, document abbreviations or comparable identifiers. Such information may in particular be displayed in the footer, in the document title, within the App, on the Platform Provider’s website or in the Platform Provider’s technical administration systems.

The Platform Provider may store, for evidence purposes, which version of the Privacy Policy was displayed to a User and at what time acknowledgement, confirmation, consent or another required action took place.

Where a new or amended version of the Privacy Policy requires renewed confirmation, acknowledgement or consent, continued use of the App or individual functions may be made dependent on the User confirming the respective current version within the App.

The Platform Provider may assign this information to the respective user account and document it within technical administration systems in order to be able to prove which version was authoritative for the respective User.

 

Kontakt aufnehmen

Du kannst uns auch gerne per Email oder direkt in der App kontaktieren.