Privacy Policy
This Privacy Policy explains what personal data Kommunitea (“Kommunitea”, “we”, “us”) collects when you use the Kommunitea mobile app and website (together, the “Service”), why we collect it, who else can see it, and what rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR).
We have tried to describe what the Service actually does rather than what a privacy policy usually says. If you find something here that does not match your experience of the app, please tell us at privacy@kommunitea.app.
1. Who is responsible for your data
The data controller for the Service is:
- Harris Mubeen
- Erdingerstrasse 56a
- 85356 Freising, Germany
You can reach us about anything in this policy at privacy@kommunitea.app.
2. What Kommunitea is
Kommunitea is a platform for discovering and organising events and for running communities of all kinds — interest groups, neighbourhood groups, company teams, and university clubs and societies among them. Through the Service you can create or join communities, create and RSVP to events, manage who is attending, chat with other participants, share photos and “memories”, answer polls, and apply to opportunities that communities list.
3. Information we collect
We collect the following, and only what the feature you are using actually needs:
- Account information — your email address and display name. If you sign in with Apple or Google, we receive a unique identifier from them and, where you allow it, your name and email address. If you register with a password, we never store the password itself: we store a one-way hash of it, from which the password cannot be recovered.
- Usage information — a short, fixed list of actions you take in the app (for example that you joined a community or replied to an event), and that the app was installed, opened or updated. This is counted, never read: the contents of what you write are not included. Section 15 lists exactly what is collected and how to switch it off.
- Profile information — anything optional you choose to add: a profile photo, a short bio, a home location, and your interests.
- Content you create — the communities and events you create or join, messages you send in chats, photos and memories you upload, your poll responses, and your event RSVPs and attendance records.
- Event registration answers — if an organiser asks questions when you register for their event, your answers, together with the names of any guests you bring.
- Planning an event — hosts can keep a task list and notes for an event they are organising. If a task is assigned to you, or you comment on one, your name is attached to it. If a host runs a roll call on a trip, we record who responded and when.
- Shared costs and settling up: if the people at an event split what something cost, we store what the cost was called, the amount and currency, who put money in and how much, how it is divided between people, an optional note, and an optional photo of the receipt. We record who entered it. When someone says they have paid another person back, we store that claim, the amount, and whether the other person confirmed it, rejected it, or has not answered yet. See section 6.
- An event’s budget: the people organising an event can keep a private list of what it costs them, being a label, an amount, who paid, and an optional receipt photo. This is the organisers’ own record and is separate from the shared costs above.
- Feedback on an event you attended: a rating and an optional comment. Your name is attached to it unless you choose to leave it without your name. See section 5.
- Location — with your permission, an approximate location from your device, used to show you nearby events and communities. See section 7.
- Affiliation and verification data — if you ask to verify that you belong to a university, company or other organisation, the organisation email address you enter, which we use to send and check a one-time code. See section 8.
- Documents you upload — if you apply to an opportunity listed by a community, the contact email address, note, and any CV or document you attach. See section 9.
- Push notification token — a device identifier issued by Apple or Google, if you turn notifications on, so we can deliver them.
- Organisation portal sign-in — managers of an organisation sign in to our web portal with a one-time code instead of a password. We store the email address the code was sent to, the code itself, and whether it has been used, so that a code works once and cannot be replayed. Codes are short-lived and we limit how many can be requested in an hour.
- What you write when you ask to join a community: the people running a community can set one question that is asked of anyone requesting to join, and your answer is shown to them with your request. It is stored with your membership and stays visible to them if they let you in. Answering is optional unless they mark the question as required, and nothing is asked of you when you join a community that admits everyone.
- Organisation access lists: an organisation we work with may give us a list of email addresses of people who should be able to see that organisation inside the Service, and we store those addresses in order to recognise them. An address may be on such a list before the person holding it uses the Service at all. We use it for nothing except deciding what that person can see, we do not contact anyone because they appear on a list, and it stops being used once that organisation is open to everyone. The list is deleted with the organisation. If your address is on one and you would rather it were not, write to us at the address in section 20 and we will remove it.
- Technical data needed to run and secure the Service — your device’s IP address reaches our servers whenever you use the app, as it must for any internet service, and we use it to limit abusive request patterns. We do not keep a log of the ordinary requests you make.
- Failed sign-in records — when a sign-in, email verification, or password reset attempt fails, we write a line to our security log containing the IP address it came from and the email address that was tried. This is how we detect and stop someone guessing passwords, and we keep it for no longer than 30 days. Successful sign-ins are not logged this way.
- Crash reports — if the app crashes or hits an error, or if our servers hit an unexpected error while handling something you did, we receive a diagnostic report containing the error and a stack trace. We have configured our crash reporting so that it does not attach your IP address, and we do not send it your name or email address. We do not use it to track you and we do not collect performance or usage analytics through it.
4. Why we use it, and our legal basis
- To provide the Service — accounts, communities, events, RSVPs, attendance, chat, photos and polls. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To send transactional email — verification codes, password resets, and notices about your account. Legal basis: performance of our contract with you.
- To show nearby events, and to send push notifications — both only if you grant the relevant permission. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in your device settings.
- To verify an affiliation you have asked us to verify. Legal basis: your consent, given by starting the verification.
- To keep the Service secure, prevent abuse, handle reports, and keep the app reliable. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR) in a safe and functioning service.
- To comply with legal obligations where the law requires us to retain or disclose information. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
5. What other people can see
Kommunitea is a social product, so much of what you do is visible to other people by design. What follows depends on the settings of the community, event or chat in question:
- Your display name and profile — including your photo, bio and interests if you added them — can be seen by other users of the Service.
- Content you post in a community or event is visible to the people who can see that community or event. Some communities and events are open to anyone; others are restricted to members, to verified members, or to a committee.
- Chat messages are visible to the other participants of that chat.
- Whether you have read a message is shown to the person who sent it. On their own message, and only on their own, they can see how many of the people who were in the chat when they sent it have opened it, and the names of those who have and have not. It records whether, never when: no time is shown or stored against a particular message. You can switch this off at Settings → Privacy → Read receipts. It works both ways: with it off, nobody is told whether you read their message and you are left out of the count entirely, and you cannot see who has read yours.
- Memories and photos follow the visibility you choose when you upload them.
- Organisers and community administrators can see the information they need in order to run their event or community. For an event you have registered for, this includes your name, your RSVP and check-in status, your answers to any registration questions, and the names of guests you added. Where an organiser has recorded that you paid, they and their co-hosts see that too, as described in section 6.
- Organisers decide their own registration questions, and answer for them. We decide what the Service does with your registration — storing it, showing it on the door list, issuing your ticket. The organiser decides which questions to ask you, why, and what to do with your answers once they have them, including anything they export. For those decisions the organiser acts as a controller in their own right, not on our behalf. So if you want to know why an organiser asked something, or want your answers corrected or deleted from their records, ask them — we can help you reach them. Anything held on the Service itself remains ours to answer for, and section 18 explains how to exercise your rights with us. What organisers may and may not do with your data is set out in section 7 of our Terms of Service.
- An event’s hosts also see their own planning board — the tasks and notes for that event. A task assigned to you carries your name, as do any comments you leave on one, and a roll call records who responded. This is visible to the people organising that event, not to attendees generally.
- If you affiliate with an organisation — a university or company — your name, profile photo and whether you are verified appear in that organisation’s member list, which is visible to its managers and to other people affiliated with the same organisation. Your organisation email address is never shown (see section 8). Managers can additionally see who may create clubs, can remove your affiliation, and can see combined statistics about attendance across the organisation’s communities, which do not name individuals. The organisation decides these things, not us — who counts as affiliated with it, whose affiliation continues, and who may create a community in its name — and for those decisions it is a controller in its own right, not acting on our behalf. If you want to know why your affiliation was ended, or you disagree with a decision the organisation has taken about your membership, that is a question for the organisation; anything held on the Service itself remains ours to answer for. What an organisation agrees to is set out in section 7a of our Terms of Service. Affiliation is always your choice: you can leave an organisation at any time, and if you do, you no longer appear in its member list.
- A shared cost is visible to the people it charges. When someone adds a cost to an event, the people it is split between can see what it was, the amount, who paid, what each person’s share is, and who entered it. That last part is deliberate: anyone attending may add a cost, which is a wider permission than anything else in the Service gives, so the people being charged can always see who charged them. A cost can instead be narrowed to the people organising the event. Balances and records of settling up are visible to the two people involved. An event’s budget is a separate thing and is visible only to its hosts and co-hosts.
- Feedback you leave on an event is signed by default, so the host sees your name with your rating and comment. You can turn that off for an individual review before you send it, and the host then sees the rating and the comment without your name. Reviews written before 24 August 2026 were left under an earlier promise that the host saw them anonymously, and they stay that way.
- An event can be turned into a poster. Anyone who can see an event can generate an image of it to share outside the Service, on social media or on paper. The image contains the event’s own details: its title, date, place, the name of the community running it, its cover photo, and optionally a code linking back to it. Once shared it is an ordinary image, and we have no control over where it travels after that. A private event cannot be turned into a poster by anyone, including its host.
- A community may link to a group chat on another service, such as WhatsApp. Opening it takes you to that service, which is not ours, and what happens there is governed by that service’s own terms and privacy policy. Whoever runs the group there, not us, decides what it shows about you.
- Photos, profile pictures and event images you upload are served from public web addresses. The address is long and effectively unguessable, and the app only shows it to people entitled to see the content — but anyone who is given the address directly could open it. Please treat uploaded images as shareable rather than confidential. Documents uploaded to opportunity applications are handled differently and are described in section 9.
Other users may also be able to see you through features such as suggested invitees, which draws on events and communities you have in common with someone. Blocking a user prevents this in both directions.
6. Payments
Kommunitea does not process payments. There is no payment provider integrated into the Service. We do not collect, store, or process card details, bank details, or payment credentials, and no money passes through us.
Where an organiser has indicated that their event has a cost, that money is collected by the organiser directly and outside the Service — for example by bank transfer or in cash at the event. That arrangement is between you and the organiser, and any personal data you give them for it is handled by them, not by us.
We do record whether an organiser says you have paid. The app gives organisers a way to keep track of who has settled up. When an organiser marks your ticket as paid, we store:
- that the ticket is marked paid, and the amount and currency shown on that ticket;
- the date and time it was marked; and
- which organiser marked it.
This is a note made by a person, not a confirmation from a bank or payment provider. It records what the organiser told us, and we cannot verify that any money actually changed hands. We keep who marked it and when so that a disagreement about payment has something to refer back to.
This information is visible to the event’s organisers and co-hosts, and to you on your own ticket. It is included in the attendee list an organiser can export. We keep it for as long as the ticket exists, and it is deleted with the event or your account. If your ticket is marked unpaid again, the record of who marked it and when is deleted.
Splitting a cost between people is the same in this respect: no money moves through us. The Service lets the people at an event record what something cost, who put money in, and how it should be divided. From those entries it works out, by arithmetic, what each person’s share comes to and who is owed what. That is a running note kept by the people involved. It is not an account, we hold no funds, and nothing about it moves money between anybody.
When you tell the Service you have paid someone back, we record that you said so, the amount, and the date. The other person is asked to confirm it. Their answer, including a refusal, is kept alongside the claim, because a claim that quietly disappears looks to the person who made it as though it was never made. None of this is verified by us and none of it is evidence that money changed hands. If you disagree about a shared cost or about whether someone paid, that is between the two of you: we are not a party to it, and we cannot adjudicate it.
The Service can also offer to reduce a group’s debts to fewer payments, so that three people owing each other in a circle can settle with one transfer instead of three. It is arithmetic on the amounts already entered, it is off unless someone turns it on, and it changes who pays whom without changing what anyone owes in total.
Aside from this, event functionality in the app is limited to registration, RSVP, ticket issuance for entry, and attendance management.
7. Location
Location is optional. The Service asks for it only when you open a map or use the “use my location” control, and you can decline or revoke permission at any time in your device settings; the rest of the app continues to work without it.
- We request approximate location, not the most precise available.
- We request it only while the app is open. The Service does not track your location in the background and does not follow your movements over time.
- A reading is taken at the moment you use the feature, used to sort nearby results, and not stored as a location history.
- Separately, if you choose to set a home location on your profile, that place is stored on your profile until you change or remove it.
8. Verifying an affiliation
If you want to show that you belong to a university, company or other organisation, you can enter an email address at that organisation. We send a one-time code to it and check the code you enter back.
- We retain the verified email address alongside your affiliation record. We need it to evidence the verification, to re-check it if the organisation’s membership rules change, and to recognise organisation managers.
- Other users see only that you are verified with an organisation. They do not see your organisation email address.
- Managers of an organisation cannot see the verified email addresses of the people affiliated with it. The address is used inside our systems only to recognise who holds a manager permission; it is never shown in a member list or sent to another user.
- If verification fails, no affiliation is added. You can try again with a different address.
- Verification is optional. It unlocks access to communities and events that a community has restricted to verified members.
9. Documents you upload when applying to an opportunity
Communities can list opportunities, and you can apply in the app, optionally attaching a CV or similar document.
- The document is stored privately. It is not published at a public address and is not indexed. It is made available only through a short-lived download link.
- That link is issued only to the person who posted the opportunity and the administrators of the community that posted it. Those people can download and keep a copy — once they have, that copy is outside our control, and they act as an independent controller of it. What they may do with it is governed by their own obligations, not this policy.
- Your application also shows them the contact email address you supplied, your note, and your display name and profile photo.
- If you apply again to the same opportunity, your previous document is deleted and replaced.
- You can withdraw an application at any time. Withdrawing deletes the application and erases the attached document from our storage. Note that this cannot reach a copy someone has already downloaded.
- An application and its document are kept while the opportunity is live, and are deleted when the opportunity or the community that posted it is deleted, when you withdraw, or when you delete your account — whichever happens first.
- We do not scan uploaded documents for malware, and we do not process them with AI or any external service. They are stored and served, nothing more.
10. Who else processes your data
We do not sell your personal data and we do not share it for advertising. We use the following providers to run the Service:
- Amazon Web Services — server hosting, the database, file storage for uploaded images and documents, and outbound email (Amazon SES). Acts as our processor.
- Apple and Google — optional “Sign in with Apple” and “Sign in with Google”, and delivery of push notifications to your device. When they deliver a service on our behalf they act as our processor, but they also process data as independent controllers for their own purposes under their own privacy policies, over which we have no control.
- Google Maps — map display. Google acts as an independent controller for data collected through its mapping services.
- Photon (Komoot GmbH, Germany) and Nominatim (OpenStreetMap Foundation) — searching for a place. When you type a place into a search box, that text is sent to Photon to find matching addresses, and to Nominatim if Photon does not answer. Both are built on OpenStreetMap data. We send the text you typed and nothing that identifies you.
- Open-Meteo — the weather forecast shown on an event. We send the event’s coordinates and its time. Nothing about you is sent, and your own location is never sent.
- OpenRouteService — drawing the road route between the stops on a trip. We send the coordinates of those stops so a road-following line can be returned. As above, this describes the trip’s route, not you: nothing identifying you is sent, and your own location is never sent.
- Google Wallet — only if you choose to add a ticket to Google Wallet on Android. Doing so sends Google the name on the ticket, the event’s name, its date and time, its venue, and the ticket’s QR code, so that the pass can exist in your Wallet. Google then holds that pass under its own privacy policy. If you do not use the button, nothing is sent. Apple Wallet works differently: the pass is built on our own servers and handed straight to your device, so adding a ticket to Apple Wallet sends nothing to Apple.
- PostHog — product analytics, on PostHog’s European (EU) cloud region. Receives the usage events described in section 15, tied to your account’s internal ID number. Acts as our processor. You can switch this off in the app under Settings → Privacy.
- Sentry — receives crash and error reports as described in section 3, on Sentry’s European data region. Acts as our processor.
Organisations are different from everyone in that list. If you choose to affiliate with a university, company, or other organisation, that organisation receives your data as a controller in its own right — it is not our processor, and it does not act on our instructions. What it receives, and what it agrees to do with it, is described in section 5. Our basis for disclosing it to them is our legitimate interest, and yours, in an affiliation that means something (Art. 6(1)(f)), and the disclosure only happens because you asked to be affiliated. Ending the affiliation stops it.
We disclose personal data outside these arrangements only where we are legally required to, or where it is necessary to protect the rights or safety of users or the public.
11. Where your data is stored, and international transfers
Our servers, our database and its backups, and the storage holding uploaded images and documents are all located in the European Union, in Amazon Web Services’ Frankfurt (Germany) region. Crash reports are held by Sentry in its European data region.
Some processing necessarily takes place outside the EU/EEA and is outside our control: when you choose to sign in with Apple or Google, or when we hand a push notification to Apple’s or Google’s notification service for delivery to your device, those companies process data under their own privacy policies and their own transfer arrangements. The same applies to Google Maps when you view a map, and to Google Wallet if you choose to add a ticket to it — see section 10 for exactly what that sends.
The place-search and weather services described in section 10 are run by European providers, and we send them only a search term or an event’s coordinates — never anything identifying you. Each operates under its own privacy policy.
The Service is operated and administered from Germany. We do not use support or engineering staff outside the EU/EEA.
12. Security
The measures we have in place include:
- Encryption of all traffic between your device and our servers (HTTPS/TLS).
- Encryption of the database at rest, and of its automated backups.
- One-way hashing of passwords, so they are never stored in a readable form.
- Access controls throughout the Service, so that requests for a community, event, chat, attendee list or document are checked against your membership and role before anything is returned.
- Private storage for uploaded documents, reachable only through short-lived, individually issued links.
- Least-privilege access for administrators. Administrative permissions are re-checked against our database on every request rather than being carried in a token, uploaded files are stored under a location tied to the account that uploaded them so that one account cannot reach another’s, and direct access to the production database is limited to the operator named in section 1.
- Security logging of failed sign-in, verification and password-reset attempts, as described in section 3, so that we can detect and stop someone trying to guess their way into an account. These records are kept for no more than 30 days. We do not keep a log of the ordinary requests you make.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do commit to notifying you and the competent supervisory authority where a personal data breach requires it under Articles 33 and 34 GDPR.
13. How long we keep your data
We keep personal data for as long as your account is active, and then apply the rules below.
- Account and profile — until you delete your account. When you do, we erase or anonymise your personal data promptly: your email address, display name, profile photo, bio and any saved home location are removed, and your sign-in identifiers are released. Your memberships, tickets, RSVPs, poll votes, affiliations and notification tokens are deleted.
- Content you posted — messages and contributions to communities may remain, detached from your identity and shown as from a deleted user, so that conversations and community history remain coherent for the other people in them.
- Events and communities — events you created that belong to a community stay with that community. Events you created outside any community are deleted with your account, as are communities where you were the only remaining member.
- Attendance and registration answers — kept for as long as the event record exists, so that the organiser has a record of who attended. They are deleted when the event is deleted, and your own are deleted when you delete your account.
- Shared costs, balances and records of settling up: kept for as long as the event exists, and deleted with it. They are not deleted when you delete your account, because a shared cost is a record between several people and erasing one side of it would leave everybody else with a balance that no longer adds up. Your name is removed from it in the same way as your other content, so it shows as a deleted user. An event’s budget is deleted with the event.
- Feedback on an event: kept for as long as the event exists, and deleted with the event or with your account.
- Verification data — retained while the affiliation is active; deleted with your account.
- Join request answers: kept for as long as your membership of that community lasts, so the people running it keep the context they admitted you on. Deleted when you leave the community, when the community is deleted, and when you delete your account.
- Organisation access lists: kept until the organisation is removed or we are asked to remove an entry.
- Uploaded documents — see section 9.
- Reports and moderation records — retained for up to 2 years, including after an account is deleted. We need them to enforce our rules consistently, to prevent someone evading a ban by re-registering, and to respond to legal complaints about content on the Service.
- Content in a community we have taken down — retained rather than deleted for as long as the takedown stands. We keep it so that the community’s members can challenge the decision and have it reviewed on the evidence, and so that we can respond to the authorities where the takedown concerns illegal content. It is not visible to anyone in the app while the removal is in place. If we restore the community it becomes visible again; if you delete your account, your own content is handled as described above.
- Server and security logs — including the failed sign-in records described in section 3. Rotated automatically every day and retained no longer than 30 days. We do not keep a log of the ordinary requests people make to the Service.
- Crash reports — retained by our crash-reporting provider for 90 days, then deleted.
- Backups — automated database backups are kept for 7 days on a rolling basis. Deleted data may persist in a backup until that window passes, after which the backup containing it is destroyed. We do not restore deleted accounts from backups.
- Records we are legally required to keep — retained for the period the law requires.
14. Recommendations, automated decisions and AI
The Service suggests communities and events that may interest you, ranked using your stated interests, any organisation affiliation, your approximate location if you have shared it, and communities and events you already belong to. This is ordinary ranking of what to show you first. It does not produce legal effects, it does not decide anything about you, and it does not restrict what you can access.
Where the Service works out who owes what after a shared cost, or offers to reduce a group’s debts to fewer payments, that is arithmetic on figures people entered themselves. It decides nothing about you, it is visible to everyone it concerns, and anyone involved can correct the entries it is working from.
We do not make decisions about you by automated means within the meaning of Article 22 GDPR. We do not use AI or machine-learning services to analyse your messages, photos, CVs or other content, and we do not screen applications automatically. Reports and moderation decisions are reviewed by people.
15. Cookies, analytics and tracking
We do not use advertising SDKs. We do not track you across other apps or websites, we do not build advertising profiles, and we do not sell or share anything for advertising.
We do use one product-analytics tool inside the app, PostHog, to understand how the app is used and where people get stuck. It is hosted in the European Union and acts as our processor.
What it records is a short, fixed list of things you do, and nothing else:
- Steps you complete — starting and finishing sign-up, which setup step you reached, opening or completing the “finish your profile” steps, and whether a link you followed into the app reached the community or event it pointed at.
- Actions you take — that you joined, left or created a community; that you replied to an event, left one, or created one; that you added a memory, voted in a poll, sent a chat message, or shared a memory into a chat.
- App lifecycle — that the app was installed, opened or updated, together with the app version.
Each of these is recorded as a count, tied to your account’s internal ID number. The contents are never sent. We do not send the text of your messages, your search terms, captions, photos, names, email addresses or your location. For a chat message we record only that one was sent and whether it had a photo attached; for a memory, only that one was added and whether it was public or private; for sharing a memory into a chat, only that it happened — never which memory, which chat, or who could see it. There is no session recording, no screen recording, and no automatic capture of taps: only the events listed above are collected.
You can turn this off. Open Settings → Privacy in the app and switch off “Usage analytics”. It takes effect immediately, and your choice is remembered on that device. Turning it off does not affect anything else in the app.
Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in understanding how the Service is used so that we can improve it, balanced against the limited, non-content nature of what is collected and your ability to switch it off at any time.
The app stores a sign-in token and a small amount of preference data on your device so that you stay signed in. This is essential to the Service working.
The kommunitea.app website sets no cookies. It is a set of static pages, with no accounts, no analytics and no embedded trackers, which is why you are not asked for cookie consent when you visit it.
If we ever introduce a non-essential cookie or similar technology, we will ask for your consent before it is used, and update this section first.
16. Children
The Service is not directed at children. You must be at least 18 years old to create an account, and the app is rated accordingly in the App Store and on Google Play.
We do not ask for your date of birth, so we do not verify your age — the minimum age is a condition of using the Service rather than a check the app performs. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to someone under 18 we will disable it and delete the associated personal data. If you are a parent or guardian, or you believe a child has created an account, contact us at privacy@kommunitea.app and we will act on it.
17. People who are not users
In one situation we hold personal data about someone who has no account with us and has never agreed to anything: a guest brought to an event by someone else. Where an organiser asks registering attendees to name the guests they are bringing, we store those names. If that is you, this section is for you.
- What we hold. Your name, exactly as the person registering typed it, attached to their registration for one event. Nothing else — no contact details, no account, no profile.
- Why. So the organiser knows who to expect at the door and can admit you. Legal basis: our legitimate interests and those of the organiser in the event being able to run (Art. 6(1)(f) GDPR).
- Who sees it. The organisers and co-hosts of that one event, on their attendee list. It is not shown to other attendees, it is not published, and it is not used for anything else — not to build a profile of you, not for marketing, and not to create an account.
- How long. It is deleted when the event is deleted, or when the person who registered cancels their registration or deletes their account — whichever happens first. See section 13.
- Your rights are the same as anyone else’s. You can ask us what we hold about you, correct it, or have it erased, at privacy@kommunitea.app. Tell us the event and the name used, since that is all we have to find you by. You can also complain to the supervisory authority named in section 18.
The person who adds your name is required by our Terms of Service to have your permission first, and is asked to confirm this when they type it. A guest under 18 may only be added by their parent or guardian, who is responsible for them at the event. If your name was added without your agreement, contact us and we will remove it.
18. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct inaccurate data — you can edit most of it yourself in the app.
- Erase your data. You can delete your account yourself in the app under Settings → Delete account, which carries out the erasure described in section 13.
- Restrict our processing of your data in certain circumstances.
- Object to processing based on our legitimate interests, on grounds relating to your situation.
- Withdraw consent at any time, where we rely on it — for example location or notification permissions. Withdrawing consent does not affect processing carried out before you withdrew it.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As set out in section 14, we do not make such decisions.
To exercise any of these, email privacy@kommunitea.app. We will respond within one month, and will tell you if we need longer as the GDPR permits. We may need to confirm your identity first.
You also have the right to lodge a complaint with a data protection supervisory authority — in your country of residence, your place of work, or where you believe an infringement occurred. The authority competent for us is:
- Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
- Promenade 18, 91522 Ansbach, Germany
- Postal address: Postfach 1349, 91504 Ansbach, Germany
- www.lda.bayern.de
19. Changes to this policy
We may update this policy as the Service develops. When we do, we will post the updated version on this page and change the “Last updated” date at the top. If a change materially affects how we handle your data, we will tell you within the Service before it takes effect.
20. Contact
For any question about this policy, or to exercise your rights, contact us at privacy@kommunitea.app.