Privacy Policy
This Privacy Policy explains what personal data KommUnitea (“KommUnitea”, “we”, “us”) collects when you use the KommUnitea mobile app and website (together, the “Service”), why we collect it, who else can see it, and what rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR).
We have tried to describe what the Service actually does rather than what a privacy policy usually says. If you find something here that does not match your experience of the app, please tell us at privacy@kommunitea.app.
1. Who is responsible for your data
The data controller for the Service is:
- Harris Mubeen
- Erdingerstrasse 56a
- 85356 Freising, Germany
You can reach us about anything in this policy at privacy@kommunitea.app.
2. What KommUnitea is
KommUnitea is a platform for discovering and organising events and for running communities of all kinds — interest groups, neighbourhood groups, company teams, and university clubs and societies among them. Through the Service you can create or join communities, create and RSVP to events, manage who is attending, chat with other participants, share photos and “memories”, answer polls, and apply to opportunities that communities list.
3. Information we collect
We collect the following, and only what the feature you are using actually needs:
- Account information — your email address and display name. If you sign in with Apple or Google, we receive a unique identifier from them and, where you allow it, your name and email address. If you register with a password, we never store the password itself: we store a one-way hash of it, from which the password cannot be recovered.
- Profile information — anything optional you choose to add: a profile photo, a short bio, a home location, and your interests.
- Content you create — the communities and events you create or join, messages you send in chats, photos and memories you upload, your poll responses, and your event RSVPs and attendance records.
- Event registration answers — if an organiser asks questions when you register for their event, your answers, together with the names of any guests you bring.
- Location — with your permission, an approximate location from your device, used to show you nearby events and communities. See section 7.
- Affiliation and verification data — if you ask to verify that you belong to a university, company or other organisation, the organisation email address you enter, which we use to send and check a one-time code. See section 8.
- Documents you upload — if you apply to an opportunity listed by a community, the contact email address, note, and any CV or document you attach. See section 9.
- Push notification token — a device identifier issued by Apple or Google, if you turn notifications on, so we can deliver them.
- Technical data needed to run and secure the Service — your device’s IP address reaches our servers whenever you use the app, as it must for any internet service, and we use it to limit abusive request patterns. We do not keep a log of the ordinary requests you make.
- Failed sign-in records — when a sign-in, email verification, or password reset attempt fails, we write a line to our security log containing the IP address it came from and the email address that was tried. This is how we detect and stop someone guessing passwords, and we keep it for no longer than 30 days. Successful sign-ins are not logged this way.
- Crash reports — if the app crashes or hits an error, we receive a diagnostic report containing the error and a stack trace. We have configured our crash reporting so that it does not attach your IP address, and we do not send it your name or email address. We do not use it to track you and we do not collect performance or usage analytics through it.
4. Why we use it, and our legal basis
- To provide the Service — accounts, communities, events, RSVPs, attendance, chat, photos and polls. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- To send transactional email — verification codes, password resets, and notices about your account. Legal basis: performance of our contract with you.
- To show nearby events, and to send push notifications — both only if you grant the relevant permission. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time in your device settings.
- To verify an affiliation you have asked us to verify. Legal basis: your consent, given by starting the verification.
- To keep the Service secure, prevent abuse, handle reports, and keep the app reliable. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR) in a safe and functioning service.
- To comply with legal obligations where the law requires us to retain or disclose information. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
5. What other people can see
KommUnitea is a social product, so much of what you do is visible to other people by design. What follows depends on the settings of the community, event or chat in question:
- Your display name and profile — including your photo, bio and interests if you added them — can be seen by other users of the Service.
- Content you post in a community or event is visible to the people who can see that community or event. Some communities and events are open to anyone; others are restricted to members, to verified members, or to a committee.
- Chat messages are visible to the other participants of that chat.
- Memories and photos follow the visibility you choose when you upload them.
- Organisers and community administrators can see the information they need in order to run their event or community. For an event you have registered for, this includes your name, your RSVP and check-in status, your answers to any registration questions, and the names of guests you added.
- Photos, profile pictures and event images you upload are served from public web addresses. The address is long and effectively unguessable, and the app only shows it to people entitled to see the content — but anyone who is given the address directly could open it. Please treat uploaded images as shareable rather than confidential. Documents uploaded to opportunity applications are handled differently and are described in section 9.
Other users may also be able to see you through features such as suggested invitees, which draws on events and communities you have in common with someone. Blocking a user prevents this in both directions.
6. Payments
KommUnitea does not process payments. There is no payment provider integrated into the Service. We do not collect, store, or process card details, bank details, or payment credentials, and no money passes through us.
Where an organiser has indicated that their event has a cost, that money is collected by the organiser directly and outside the Service — for example by bank transfer or in cash at the event. That arrangement is between you and the organiser, and any personal data you give them for it is handled by them, not by us.
We do record whether an organiser says you have paid. The app gives organisers a way to keep track of who has settled up. When an organiser marks your ticket as paid, we store:
- that the ticket is marked paid, and the amount and currency shown on that ticket;
- the date and time it was marked; and
- which organiser marked it.
This is a note made by a person, not a confirmation from a bank or payment provider. It records what the organiser told us, and we cannot verify that any money actually changed hands. We keep who marked it and when so that a disagreement about payment has something to refer back to.
This information is visible to the event’s organisers and co-hosts, and to you on your own ticket. It is included in the attendee list an organiser can export. We keep it for as long as the ticket exists, and it is deleted with the event or your account. If your ticket is marked unpaid again, the record of who marked it and when is deleted.
Aside from this, event functionality in the app is limited to registration, RSVP, ticket issuance for entry, and attendance management.
7. Location
Location is optional. The Service asks for it only when you open a map or use the “use my location” control, and you can decline or revoke permission at any time in your device settings; the rest of the app continues to work without it.
- We request approximate location, not the most precise available.
- We request it only while the app is open. The Service does not track your location in the background and does not follow your movements over time.
- A reading is taken at the moment you use the feature, used to sort nearby results, and not stored as a location history.
- Separately, if you choose to set a home location on your profile, that place is stored on your profile until you change or remove it.
8. Verifying an affiliation
If you want to show that you belong to a university, company or other organisation, you can enter an email address at that organisation. We send a one-time code to it and check the code you enter back.
- We retain the verified email address alongside your affiliation record. We need it to evidence the verification, to re-check it if the organisation’s membership rules change, and to recognise organisation managers.
- Other users see only that you are verified with an organisation. They do not see your organisation email address.
- Managers of an organisation cannot see the verified email addresses of the people affiliated with it. The address is used inside our systems only to recognise who holds a manager permission; it is never shown in a member list or sent to another user.
- If verification fails, no affiliation is added. You can try again with a different address.
- Verification is optional. It unlocks access to communities and events that a community has restricted to verified members.
9. Documents you upload when applying to an opportunity
Communities can list opportunities, and you can apply in the app, optionally attaching a CV or similar document.
- The document is stored privately. It is not published at a public address and is not indexed. It is made available only through a short-lived download link.
- That link is issued only to the person who posted the opportunity and the administrators of the community that posted it. Those people can download and keep a copy — once they have, that copy is outside our control, and they act as an independent controller of it. What they may do with it is governed by their own obligations, not this policy.
- Your application also shows them the contact email address you supplied, your note, and your display name and profile photo.
- If you apply again to the same opportunity, your previous document is deleted and replaced.
- You can withdraw an application at any time. Withdrawing deletes the application and erases the attached document from our storage. Note that this cannot reach a copy someone has already downloaded.
- An application and its document are kept while the opportunity is live, and are deleted when the opportunity or the community that posted it is deleted, when you withdraw, or when you delete your account — whichever happens first.
- We do not scan uploaded documents for malware, and we do not process them with AI or any external service. They are stored and served, nothing more.
10. Who else processes your data
We do not sell your personal data and we do not share it for advertising. We use the following providers to run the Service:
- Amazon Web Services — server hosting, the database, file storage for uploaded images and documents, and outbound email (Amazon SES). Acts as our processor.
- Apple and Google — optional “Sign in with Apple” and “Sign in with Google”, and delivery of push notifications to your device. When they deliver a service on our behalf they act as our processor, but they also process data as independent controllers for their own purposes under their own privacy policies, over which we have no control.
- Google Maps — map display and place lookup. Google acts as an independent controller for data collected through its mapping services.
- Sentry — receives crash and error reports as described in section 3, on Sentry’s European data region. Acts as our processor.
We disclose personal data outside these arrangements only where we are legally required to, or where it is necessary to protect the rights or safety of users or the public.
11. Where your data is stored, and international transfers
Our servers, our database and its backups, and the storage holding uploaded images and documents are all located in the European Union, in Amazon Web Services’ Frankfurt (Germany) region. Crash reports are held by Sentry in its European data region.
Some processing necessarily takes place outside the EU/EEA and is outside our control: when you choose to sign in with Apple or Google, or when we hand a push notification to Apple’s or Google’s notification service for delivery to your device, those companies process data under their own privacy policies and their own transfer arrangements. The same applies to Google Maps when you view a map.
The Service is operated and administered from Germany. We do not use support or engineering staff outside the EU/EEA.
12. Security
The measures we have in place include:
- Encryption of all traffic between your device and our servers (HTTPS/TLS).
- Encryption of the database at rest, and of its automated backups.
- One-way hashing of passwords, so they are never stored in a readable form.
- Access controls throughout the Service, so that requests for a community, event, chat, attendee list or document are checked against your membership and role before anything is returned.
- Private storage for uploaded documents, reachable only through short-lived, individually issued links.
[CONFIRM AND THEN STATE, OR REMOVE: logging and monitoring, vulnerability management, least-privilege access for administrators, and a documented incident-response process. Do not list a measure here that is not actually in place.]
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do commit to notifying you and the competent supervisory authority where a personal data breach requires it under Articles 33 and 34 GDPR.
13. How long we keep your data
We keep personal data for as long as your account is active, and then apply the rules below.
- Account and profile — until you delete your account. When you do, we erase or anonymise your personal data promptly: your email address, display name, profile photo, bio and any saved home location are removed, and your sign-in identifiers are released. Your memberships, tickets, RSVPs, poll votes, affiliations and notification tokens are deleted.
- Content you posted — messages and contributions to communities may remain, detached from your identity and shown as from a deleted user, so that conversations and community history remain coherent for the other people in them.
- Events and communities — events you created that belong to a community stay with that community. Events you created outside any community are deleted with your account, as are communities where you were the only remaining member.
- Attendance and registration answers — kept for as long as the event record exists, so that the organiser has a record of who attended. They are deleted when the event is deleted, and your own are deleted when you delete your account.
- Verification data — retained while the affiliation is active; deleted with your account.
- Uploaded documents — see section 9.
- Reports and moderation records — retained for up to 2 years, including after an account is deleted. We need them to enforce our rules consistently, to prevent someone evading a ban by re-registering, and to respond to legal complaints about content on the Service.
- Server and security logs — including the failed sign-in records described in section 3. Rotated automatically every day and retained no longer than 30 days. We do not keep a log of the ordinary requests people make to the Service.
- Crash reports — retained by our crash-reporting provider for 90 days, then deleted.
- Backups — automated database backups are kept for 7 days on a rolling basis. Deleted data may persist in a backup until that window passes, after which the backup containing it is destroyed. We do not restore deleted accounts from backups.
- Records we are legally required to keep — retained for the period the law requires.
14. Recommendations, automated decisions and AI
The Service suggests communities and events that may interest you, ranked using your stated interests, any organisation affiliation, your approximate location if you have shared it, and communities and events you already belong to. This is ordinary ranking of what to show you first. It does not produce legal effects, it does not decide anything about you, and it does not restrict what you can access.
We do not make decisions about you by automated means within the meaning of Article 22 GDPR. We do not use AI or machine-learning services to analyse your messages, photos, CVs or other content, and we do not screen applications automatically. Reports and moderation decisions are reviewed by people.
15. Cookies, analytics and tracking
We do not use advertising SDKs, and we do not use third-party analytics or usage-tracking tools in the app. We do not track you across other apps or websites, and we do not ask for permission to do so.
The app stores a sign-in token and a small amount of preference data on your device so that you stay signed in. This is essential to the Service working.
The kommunitea.app website sets no cookies. It is a set of static pages, with no accounts, no analytics and no embedded trackers, which is why you are not asked for cookie consent when you visit it.
If we ever introduce a non-essential cookie or similar technology, we will ask for your consent before it is used, and update this section first.
16. Children
The Service is not directed at children. You must be at least 18 years old to create an account, and the app is rated accordingly in the App Store and on Google Play.
We do not ask for your date of birth, so we do not verify your age — the minimum age is a condition of using the Service rather than a check the app performs. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to someone under 18 we will disable it and delete the associated personal data. If you are a parent or guardian, or you believe a child has created an account, contact us at privacy@kommunitea.app and we will act on it.
17. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Correct inaccurate data — you can edit most of it yourself in the app.
- Erase your data. You can delete your account yourself in the app under Settings → Delete account, which carries out the erasure described in section 13.
- Restrict our processing of your data in certain circumstances.
- Object to processing based on our legitimate interests, on grounds relating to your situation.
- Withdraw consent at any time, where we rely on it — for example location or notification permissions. Withdrawing consent does not affect processing carried out before you withdrew it.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. As set out in section 14, we do not make such decisions.
To exercise any of these, email privacy@kommunitea.app. We will respond within one month, and will tell you if we need longer as the GDPR permits. We may need to confirm your identity first.
You also have the right to lodge a complaint with a data protection supervisory authority — in your country of residence, your place of work, or where you believe an infringement occurred. The authority competent for us is:
- Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
- Promenade 18, 91522 Ansbach, Germany
- Postal address: Postfach 1349, 91504 Ansbach, Germany
- www.lda.bayern.de
18. Changes to this policy
We may update this policy as the Service develops. When we do, we will post the updated version on this page and change the “Last updated” date at the top. If a change materially affects how we handle your data, we will tell you within the Service before it takes effect.
19. Contact
For any question about this policy, or to exercise your rights, contact us at privacy@kommunitea.app.