Skip to content

Privacy Policy

Viewing Version 2.4 (Effective date: 06.08.2026)

Table of Contents

  • 1. Controller and Contact
  • 2. Data Protection Officer
  • 3. General Information, Definitions, Principles
  • 4. Competent Supervisory Authority
  • 5. Definitions
  • 6. Processing Activities
  • 6.1 Provision of the App and Server Log Files
  • 6.2 Registration and Authentication (incl. Collection of Date of Birth)
  • 6.3 Age Verification and Anti-Circumvention Measure
  • 6.4 User Profile and Gallery
  • 6.5 Creation and Management of Events
  • 6.6 Sending of Invitation Links
  • 6.7 Group and Private Chat (TLS-Encrypted)
  • 6.8 Media Upload and Storage
  • 6.9 Event Modules (Polls, Expenses, Gift Pools, To-Do, Moodboard, Games)
  • 6.10 Push Notifications
  • 6.11 Reporting, Moderation and Blocking Functions
  • 6.12 Address Autocomplete (Google Places API)
  • 6.13 Premium Features and In-App Purchases
  • 6.14 Telemetry, Diagnostics, Crash Reports
  • 6.15 Product Analytics
  • 6.16 Transactional Emails (Resend)
  • 6.17 Contact and Support
  • 6.18 Build, Update and Push Infrastructure (Expo / EAS)
  • 6.19 Guest Responses via Invitation Links (Website)
  • 6.20 Ticket Documents (Crew Backup)
  • 6.21 Birthday Reminder
  • 7. Cookies and Comparable Technologies (§ 25 TDDDG)
  • 8. Integrated Third-Party Providers and Processors
  • 9. Third-Country Transfers
  • 10. Overview of Storage Periods
  • 11. Rights of Data Subjects
  • 12. Automated Decisions, Profiling, AI
  • 13. Data Security and Technical and Organizational Measures
  • 14. Protection of Minors and Privacy by Default
  • 15. Currency and Amendment of this Privacy Policy
  • 16. Date and Versioning

1. Controller and Contact

The controller within the meaning of Art. 4(7) of Regulation (EU) 2016/679 ("GDPR") and of other national data protection laws of the Member States as well as other data protection provisions is:
Quzet Labs UG (haftungsbeschränkt)
Krenklstraße 5, 84034 Landshut, Deutschland
Managing Director with power of representation: Adrian Tecleanu
Commercial register: Amtsgericht Landshut, HRB 15328
VAT ID: DE461632802
Phone: +49 1522 7653629
General email: support@avygo.app
Data protection email: privacy@avygo.app

2. Data Protection Officer

We have not appointed a data protection officer, as the statutory requirements for an appointment under Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) are not met. In the event of a material change in our processing activities or a relevant increase in the number of employees, we will reassess the obligation to appoint one.
Please direct data protection inquiries directly to the contact details set out in Section 1, preferably to privacy@avygo.app. The responsible contact person for data protection matters is the Managing Director, Mr. Adrian Tecleanu.

3. General Information, Definitions, Principles

(1) We take the protection of your personal data very seriously. We process your personal data exclusively on the basis of statutory provisions, in particular the GDPR, the BDSG (German Federal Data Protection Act) and the TDDDG (German Telecommunications Digital Services Data Protection Act).
(2) This Privacy Policy applies to the processing of personal data in connection with our mobile application "Avygo" for iOS and Android and our web application at avygo.app (hereinafter jointly the "App" or the "Service").
(3) We process your personal data in accordance with the principles of lawfulness, data minimisation, purpose limitation, storage limitation, accuracy, integrity and confidentiality (Art. 5 GDPR).

4. Competent Supervisory Authority

The data protection supervisory authority competent for the controller is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Deutschland
Phone: +49 (0) 981 180093-0
Email: poststelle@lda.bayern.de
Web: https://www.lda.bayern.de/ /> You may lodge a complaint with the supervisory authority at any time (Art. 77 GDPR). Such a complaint may also be lodged with the supervisory authority of the Member State of your habitual residence or place of work.

5. Definitions

Unless otherwise stated, the definitions of Art. 4 GDPR apply. In particular:

  • "personal data" means any information relating to an identified or identifiable natural person;
  • "processing" means any operation performed on personal data (e.g. collection, storage, transmission, erasure);
  • "controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing;
  • "processor" means a natural or legal person which processes personal data on behalf of the controller (Art. 28 GDPR);
  • "third country" means a state outside the European Economic Area (EEA);
  • "consent" means any freely given, informed and unambiguous indication of the data subject's wishes.

6. Processing Activities

Below we describe, for each function of the App, which data we process for which purposes, on which legal basis, how long we store it and to which recipients we transfer it, where applicable. A consolidated overview of the third-party providers can be found in Section 8, and of the storage periods in Section 10.

6.1 Provision of the App and Server Log Files

Processing activity:
When you access and use the App, technical data is automatically transmitted to our servers (hosted by Supabase) and stored in log files.
Data categories:

  • IP address, anonymised to a form truncated by the last octet after 24 hours, provided no security incident has occurred
  • Date and time of access
  • Device type, operating system and version
  • App version
  • Language and region settings
  • HTTP status codes, volumes of data transferred
  • Functions and endpoints accessed (in technical form)

Purpose:

  • Provision of the App's functions
  • Ensuring the stability and security of the systems
  • Detection, containment and remediation of malfunctions
  • Protection against attacks (e.g. denial of service)

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract) for the provision of the App
  • Art. 6(1)(f) GDPR (legitimate interest) for the security and stability of the systems

Storage period:
Log files are generally deleted or anonymised automatically after 30 days. In the event of security-relevant incidents, individual entries may be retained for longer until the incident has been resolved, but no longer than 90 days.
Recipients:
Supabase (processor, EU region).

6.2 Registration and Authentication

Processing activity:
To create a user account, we process the data required for registration and authentication. Three sign-in methods are available:

  • Email with magic link: entry of the email address, dispatch of a one-time confirmation link;
  • Sign in with Apple: anonymised Apple ID, optionally first and last name (provided by Apple) and an obfuscated email address, if chosen by the user;
  • Sign in with Google: Google account ID, name, email address and profile picture, to the extent shared by the user.

Data categories:

  • Email address
  • Identifier of the third-party provider (Apple, Google), where SSO is used
  • Name and, where applicable, profile picture (if shared by the user)
  • Authentication tokens and session IDs
  • Time of sign-in, device and security information (for abuse detection)
  • Full date of birth (day/month/year) for age verification pursuant to § 3 of the Terms of Service (AGB); see additionally Section 6.3
  • Version of the Terms of Service accepted and of the Privacy Policy taken note of, per user (versioning identifier)

Purpose:

  • Creation and authentication of the user account
  • Protection of the account against unauthorised access
  • Restoration of access
  • Fulfilment of age verification pursuant to § 24a JuSchG (German Youth Protection Act) / Art. 28 DSA
  • Proof of consents given (versioning)

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract)
  • Art. 6(1)(c) GDPR in conjunction with § 24a JuSchG (legal obligation) for age verification
  • Art. 6(1)(f) GDPR (legitimate interest) for account security and version documentation

Storage period:
Sign-in data and the date of birth are stored for the duration of the existence of the user account. After account deletion, they are removed in accordance with Section 10; statutory retention obligations remain unaffected.
Recipients:

  • Supabase (authentication, processor, EU region)
  • Apple Inc. or Google LLC (in the case of SSO; independent controllers within the scope of their SSO service)
  • Plus Five Five, Inc. d/b/a Resend (dispatch of the magic link — see Section 6.16)

6.3 Age Verification and Anti-Circumvention Measure

Processing activity:
To ensure the legally required minimum age of 16 years (§ 3 of the Terms of Service), we verify age via the entry of the full date of birth before completion of registration. In addition, we use a technical anti-circumvention procedure to prevent repeated registration attempts using false age information.
Data categories:

  • Full date of birth (day/month/year) — stored with the user account
  • Hashed identifier (SHA-256, with server-side salt) derived from the email address, device identifier and year of birth — only in the event of a rejected registration due to failure to meet the age threshold, for a maximum of 90 days

Purpose:

  • Fulfilment of the legal obligation to protect minors pursuant to § 24a JuSchG
  • Fulfilment of the requirements of Art. 28 of Regulation (EU) 2022/2065 ("Digital Services Act") for "appropriate and proportionate measures" to protect minors
  • Optional: display of the birthday (day/month) in the profile — only where actively enabled by the user
  • Optional: reminder of the user's own upcoming birthday based on day and month (Section 6.21)

Legal basis:

  • Art. 6(1)(c) GDPR in conjunction with § 24a JuSchG (legal obligation)
  • Art. 6(1)(f) GDPR (legitimate interest in the protection of minors and in the effectiveness of the age threshold) — a Legitimate Interest Assessment (LIA) has been documented
  • Art. 6(1)(a) GDPR (consent) — only for the optional display of the birthday (day/month) in the profile; revocable at any time

Storage period:

  • Date of birth: until account deletion
  • Anti-circumvention hash: a maximum of 90 days from collection, followed by automatic deletion

Recipients:
Exclusively internal processing within the Supabase infrastructure (EU region). No transfer to external third parties takes place.
DPIA:
A data protection impact assessment (DPIA) pursuant to Art. 35 GDPR has been carried out and documented for this processing.
Sanction in the event of false information:
In the event of demonstrably false entry, the account and all associated personal data will be deleted without undue delay; the anonymised anti-circumvention hash is retained for 90 days to prevent renewed registration using the same identifiers.

6.4 User Profile and Gallery

Processing activity:
In your profile, you may voluntarily provide additional information about yourself and store images or videos in a personal gallery. You can control the visibility of individual gallery posts on a per-post basis (public within the App, only for shared event guests, or private). For users under the age of 18, the visibility settings are set to the most restrictive level by default (privacy by default pursuant to Art. 25 GDPR).
Data categories:

  • Display name, profile picture
  • Optional fields: biography, nickname, birthday (day/month, enabled separately), social media handles, phone number, further profile details
  • Gallery content (images, videos), descriptions, visibility status
  • Profile statistics (e.g. number of own events, where displayed)

Purpose:

  • Identification vis-à-vis other users in the App
  • Provision of the gallery functions chosen by the user
  • Personalisation of the App experience

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract) for mandatory information
  • Art. 6(1)(a) GDPR (consent) for voluntary profile data and gallery posts with extended visibility, revocable at any time
  • Art. 6(1)(f) GDPR in conjunction with Art. 25 GDPR (privacy by default) for the restrictive default setting for minors

Note on distinction:
The birthday information optionally displayed here (day and month without the year of birth) is to be distinguished from the age verification described in Section 6.3. The full date of birth pursuant to Section 6.3 is not made visible in the profile. For the reminder of your own birthday, see Section 6.21.
Storage period:
Until deletion by the user or until account deletion. Gallery posts are removed upon deletion of the respective post.
Recipients:

  • Supabase (storage of profile records, EU)
  • Cloudflare R2 (storage of media files, EU)

6.5 Creation and Management of Events

Processing activity:
In the App, you can create events, invite guests, manage acceptances/declines, edit event content (description, date, location, images) and use the event cockpit as host.
Data categories:

  • Event data: name, description, date, time, location, image
  • Guest list: identifier of the invitees, acceptance/decline status, comments/responses to questionnaires
  • Event-specific modules (see Section 6.9)

Purpose:

  • Provision of event planning and execution
  • Communication between host and guests

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract)
  • Art. 6(1)(f) GDPR (legitimate interest) for the visibility of event metadata vis-à-vis invitees

Storage period:
Event data is stored until the event is deleted by the host or until account deletion. Inactive events are archived or deleted in accordance with the lifecycle rules announced in the App.
Recipients:

  • Supabase (database, EU)
  • Other event participants (to the extent of the visibility settings)

6.6 Sending of Invitation Links

Processing activity:
If you wish to invite guests to an event, the App generates an invitation link, which you yourself copy to the clipboard of your device or forward via your device's system share menu (e.g. messenger, email). In doing so, Avygo does not access your address book and does not process any contact data of the recipients; the selection, sending and addressing are carried out exclusively by you on your device. If an invited person responds to the invitation via the Avygo website, the provisions of Section 6.19 apply in addition.
Data categories (on the provider side):

  • the invitation link generated by us (unique event identifier, no recipient identifiers)
  • Status of the invitation: not assigned, joined

Data categories (on the device side, without processing by us):
the contacts and channels already present on your device which you yourself use for forwarding.
Purpose:

  • Provision of the invitation function via shareable links
  • Assignment of joined persons to the event

Legal basis:
Art. 6(1)(b) GDPR (performance of a contract)
Storage period:
Generated invitation links are stored until their validity expires (default: 90 days) or until the invited person joins the event; if the event is deleted, the links become invalid.
Recipients:
Supabase (storage of the event and link data, EU). No transfer to third-party providers for the purpose of sending invitations takes place.

6.7 Group and Private Chat (TLS-Encrypted)

Processing activity:
The chat function (group chat per event as well as 1:1 private chat) is handled via our own backend infrastructure at Supabase (EU region Frankfurt, eu-central-1). The transmission of all chat data between your device and our servers is encrypted in transit (TLS 1.2 or higher). On the server, messages are stored encrypted at rest (encryption at rest, AES-256). End-to-end encryption does not take place; we as the provider therefore have the technical ability to access chat content. Access takes place exclusively in the cases described under "Access to chat content".
Data categories:

  • User identifier of the sender and of the chat members
  • Membership information per chat room (joining, leaving, role)
  • Chat messages (text content) and references to media attachments (see Section 6.8)
  • Metadata (timestamp, delivery and read receipts, typing indicators), to the extent required for the function
  • Push tokens for push notifications (see Section 6.10)

Purpose:

  • Provision of real-time communication between event participants
  • Delivery of messages and media and synchronisation across the user's devices
  • Handling of reported chat content in the context of moderation (see Section 6.11)
  • Ensuring the security and stability of the chat service

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract)
  • Art. 6(1)(f) GDPR (legitimate interest) for security and stability measures and for the handling of reported content

Access to chat content:
We do not carry out any inspection, analysis or automated searching of chat content without cause. Access by us takes place exclusively (i) where a chat member reports content via the reporting function and the review of the reported content so requires (Section 6.11), (ii) to the extent that we are legally obliged to do so (e.g. on the basis of an official or court order), or (iii) to the extent that this is strictly necessary in an individual case to remedy a technical malfunction. Internal access is technically and organisationally restricted to the necessary minimum (need-to-know principle, row-level security) and is logged.
Storage period:
Chat messages remain on the server until they are deleted by the user, until the respective chat or the associated event is deleted, or until the user account is deleted. Deleted content is additionally removed from backup copies as part of the regular backup cycles, at the latest after 30 days.
Note on the change compared with earlier versions:
Up to and including version 2.1 of this Privacy Policy, the chat function was handled end-to-end encrypted via the Matrix protocol (Olm/Megolm) on an externally hosted Synapse server. With the migration to the current chat infrastructure, end-to-end encryption no longer applies; the information above applies. The former hosting service provider (Etke, Sociedade Unipessoal, LDA, Portugal) is no longer used; the chat data stored there was deleted in the course of the migration.
Recipients:

  • Supabase (database and realtime transmission, processor, EU region Frankfurt) — on the basis of a data processing agreement pursuant to Art. 28 GDPR
  • Cloudflare R2 (media attachments, EU — see Section 6.8)
  • Apple Inc. / Google LLC (transmission of push notifications, see Section 6.10)

6.8 Media Upload and Storage

Processing activity:
Images, videos, audio recordings and documents that you upload in the App (profile, gallery, chat, event context) are stored in our object storage at Cloudflare R2 in the EU. Transmission is encrypted in transit (TLS); storage is encrypted at rest (see Section 6.7 and Section 13). For proof documents relating to events (ticket documents), the provisions of Section 6.20 apply additionally and in part by way of derogation.
Data categories:

  • Media files including technically necessary metadata (format, file size, upload time)
  • GPS coordinates in EXIF data are removed server-side before storage; other EXIF metadata (e.g. camera model) is processed only to the extent required for the display or transmission of the media
  • Identifier of the uploading user

Purpose:

  • Provision of the App's photo, video and document functions
  • Display to the authorised recipients in accordance with the visibility settings

Legal basis:
Art. 6(1)(b) GDPR (performance of a contract)
Storage period:
Until deletion by the user or until account deletion. In chats: until deletion of the associated message or chat; for ticket documents, the shorter period pursuant to Section 6.20 applies by way of derogation.
Recipients:
Cloudflare R2 (processor), EU.

6.9 Event Modules (Polls, Expenses, Gift Pools, To-Do, Moodboard, Games)

Processing activity:
The App provides a range of modules for event planning (surveys/polls, cost splitting/expenses, gift pools, gift lists, to-do lists, moodboards, inspirations, party games). Within these modules, content entered by the user as well as interaction data of the participating event guests are processed.
Data categories:

  • Content entered by the user (e.g. survey questions and options, expense items and amounts, wish-list items, tasks)
  • Identifiers of the participating users
  • Contributions, votes, responses, status changes
  • For gift pools: reservations, comments

Purpose:

  • Provision of the respective event modules
  • Display of interim results to the authorised event participants

Legal basis:
Art. 6(1)(b) GDPR (performance of a contract)
Storage period:
Module content is stored until the deletion of the respective event or deletion by the host or the respective owner.
Note:
The modules do not include any payment processing. Gift pools are a pure coordination aid. Any monetary or gift contributions are made outside the App and without the involvement of the provider (see also § 2(4) of the Terms of Service). Proof documents relating to events (ticket documents) are dealt with separately in Section 6.20.
Recipients:
Supabase (database), EU.

6.10 Push Notifications

Processing activity:
We send push notifications to inform you about new messages, invitations, reactions and other App events. Technical delivery takes place via the push services of the platform providers (Apple Push Notification Service – APNs, Firebase Cloud Messaging – FCM).
Data categories:

  • Push token (device-specific)
  • Recipient identifier
  • Content and trigger of the notification; for chat messages, a content preview may be transmitted, which you can deactivate in the notification settings

Purpose:
Information about App events in which you have an interest (e.g. event invitation, response to your poll). For the birthday reminder as a push notification, see Section 6.21; it is sent exclusively after express activation by the user.
Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract) for functionally essential, account-related notifications
  • Art. 6(1)(a) GDPR or § 25(1) TDDDG (consent) for push messages that are not strictly necessary, in particular optional tips or notices. You can revoke this consent at any time via the settings of your device or the Avygo App.

Storage period:
Push tokens are stored until push messages are deactivated or until the token ceases to be valid (e.g. device reset).
Recipients:

  • Apple Inc. (APNs)
  • Google LLC / Firebase (FCM)

6.11 Reporting, Moderation and Blocking Functions

Processing activity:
You can report, block or unblock other users or individual content via the functions integrated in the App. As an event host, you can additionally mute, remove or ban members of your event ("Mute"/"Kick"/"Ban"). We review reports in accordance with the rules described in our Terms of Service. When chat content is reported, we may view the reported content as well as the context immediately necessary for its assessment (see Section 6.7).
Data categories:

  • Identifier of the reporting party and of the accused party
  • Reported content (text, media, reference to post/message)
  • Reason for the report
  • Moderation decision and reasoning
  • Block/mute/kick/ban status

Purpose:

  • Protection against unlawful content and conduct or content and conduct in breach of the rules
  • Fulfilment of legal obligations (in particular § 7 et seq. DDG (German Digital Services Act), Art. 16 et seq. of Regulation (EU) 2022/2065 / DSA)
  • Preservation of evidence in the event of a complaint

Legal basis:

  • Art. 6(1)(c) GDPR (legal obligation)
  • Art. 6(1)(f) GDPR (legitimate interest in a safe platform)

Storage period:
Reports, their handling and sanctions imposed are stored for three (3) years from completion of the handling, in order to be able to detect repeated violations, defend against complaints and comply with statutory retention obligations. In the case of criminal complaints, the storage period may be longer.
Recipients:

  • Internal: Managing Director, to the extent necessary for handling
  • Law enforcement and supervisory authorities, to the extent required by law

6.12 Address Autocomplete (Google Places API)

Processing activity:
When you enter an address while creating or editing an event, the App assists you with automatic completion suggestions. For this purpose, we transmit your input to the Google Places API of Google Ireland Limited. We do not access the device's GPS/location sensor; no geolocation of your device takes place.
Data categories:

  • The characters/address fragments you enter
  • IP address of your device (technically required for the request to Google)
  • API session token for bundling several input steps

Purpose:

  • Convenient entry of an event address through real-time suggestions
  • Resolution of the entered address into a standardised address representation

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract), as the address entry is part of the event definition
  • Art. 6(1)(f) GDPR (legitimate interest) in convenient, low-error address entry

Storage period (on the provider side):
The final address selected by the user is stored with the event. Input fragments and suggestions are not stored permanently by us. Regarding the storage period on Google's side, we refer to Google's privacy policy (
https://policies.google.com/privacy).
Recipients:

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland (processor on the basis of the Google Maps Platform Data Processing Terms)
  • Where applicable, the parent company Google LLC (USA)

Third-country transfer:
A transfer to Google LLC in the USA may take place. Google LLC is certified under the EU-US Data Privacy Framework; in addition, the standard contractual clauses (SCCs) of the EU Commission apply.

6.13 Premium Features and In-App Purchases

Processing activity:
When premium features are purchased, payment processing is handled by the platform providers (Apple App Store, Google Play). The technical management of entitlements (entitlement management) is carried out by RevenueCat, Inc. as processor.
Data categories:

  • Pseudonymised app user identifier (RevenueCat-AppUserID)
  • Purchased products and entitlements: premium_monthly, premium_yearly, styling_upgrade, full_upgrade, extra_storage as well as their event-related variant (technically grouped as event_upgrades)
  • Purchase and renewal dates, status (active, expired, cancelled)
  • Platform receipts and receipt identifiers from Apple/Google

We expressly do not receive:
Payment instrument data, addresses or personal payment data. These are processed exclusively by the respective platform provider.
Purpose:

  • Management and activation of purchased premium features
  • Detection of expired or cancelled subscriptions
  • Support with inquiries regarding entitlements

Legal basis:
Art. 6(1)(b) GDPR (performance of a contract).
Storage period:
Entitlements and purchase history are stored for the duration of the active contractual relationship as well as for statutory retention periods (in particular 6 or 10 years pursuant to §§ 147 AO (German Fiscal Code), 257 HGB (German Commercial Code)), where applicable.
Recipients:

  • RevenueCat, Inc. (USA, processor, self-certified under the EU-US Data Privacy Framework; in addition, standard contractual clauses (SCCs) and a Transfer Impact Assessment are in place)
  • Apple Inc. / Google LLC (independent controllers within the scope of payment processing)

6.14 Telemetry, Diagnostics, Crash Reports

Processing activity:
To detect and remedy errors and crashes and to safeguard stability, we use Sentry (Functional Software, Inc., hosted in the EU).
Data categories:

  • Stack traces, error messages, affected endpoints
  • Device and operating system information
  • App version, build identifier
  • Session identifier (pseudonymous)
  • Sentry-specific identifiers
  • To the extent necessary to reproduce an error: anonymised context data

We remove
personal data (in particular email addresses, IP addresses, plain text from inputs) actively and consistently before transmission by means of filter rules.
Purpose:

  • Detection, reproduction and remediation of errors and crashes
  • Ensuring stable operation

Legal basis:
Art. 6(1)(f) GDPR (legitimate interest in the stability and security of the App).
Storage period:
Crash data is generally deleted automatically after 90 days.
Recipients:
Functional Software, Inc. d/b/a Sentry (EU hosting; parent company USA — self-certified under the EU-US DPF), processor.

6.15 Product Analytics

Processing activity:
To improve our App, we analyse in aggregated form how our App is used (e.g. which functions are accessed how often, which paths users take through the App, at which points users abandon). For this purpose, we use PostHog (PostHog Inc., EU cloud). This processing takes place exclusively after your express consent.
Data categories:

  • Pseudonymous user identifier (PostHog distinct ID)
  • Events (e.g. access of a function, click), timestamps
  • Device and app context (operating system version, app version, language and region settings)
  • Aggregated session metadata

We refrain
from capturing plain-text content and from recording screen content (session replay).
Purpose:

  • Detecting and remedying functional problems
  • Improving the user experience
  • Evaluating new features before and after their introduction

Legal basis:
Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent). You give your consent in the Avygo App and can revoke it there at any time with effect for the future.
Storage period:
Pseudonymous user identifiers are anonymised after 13 months of inactivity. Aggregated analyses that are no longer personal are stored for a maximum of 36 months. You can request deletion of the pseudonymous identifier at any time via privacy@avygo.app.
Recipients:
PostHog Inc. (EU hosting; parent company USA — no EU-US DPF, but standard contractual clauses (SCCs) and supplementary safeguards instead), processor.

6.16 Transactional Emails (Resend)

Processing activity:
For the delivery of functionally required emails (magic link confirmation at sign-in, confirmations of in-app purchases, security notices, responses to support inquiries, account deletion confirmations, as well as confirmations and notifications for guests who have responded via an invitation link — response confirmation, material event changes, cancellations, date confirmation following a date-finder vote, each with an unsubscribe link, see Section 6.19), we use the delivery service provider Resend (Plus Five Five, Inc., USA).
Data categories:

  • Email address of the recipient
  • Content of the respective message
  • Technical metadata (timestamp, delivery status, bounce information)

Purpose:

  • Delivery of contractually or legally required emails
  • Security and account communication
  • Proof of delivery (e.g. confirmation of the expired right of withdrawal pursuant to § 312f BGB (German Civil Code))

Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract) for functionally required emails
  • Art. 6(1)(c) GDPR (legal obligation) for confirmations on a durable medium
  • Art. 6(1)(f) GDPR (legitimate interest) for record archiving

Storage period:
Delivery logs are stored at Resend for a maximum of 30 days. Content is transmitted TLS-encrypted.
Recipients:
Plus Five Five, Inc. d/b/a Resend (USA), processor. Resend is self-certified under the EU-US Data Privacy Framework (as well as the UK extension); the third-country transfer is thus primarily covered by the adequacy decision of the EU Commission. In addition, standard contractual clauses (SCCs) (EU Commission Decision 2021/914, Module 2) and supplementary technical safeguards (transport encryption) are in place. A Transfer Impact Assessment has been carried out.

6.17 Contact and Support

Processing activity:
If you contact us by email or submit support inquiries, we process the transmitted data to respond to your inquiry.
Data categories:

  • Email address, name (if provided)
  • Content of the inquiry and all data communicated by you
  • Attachments, where applicable (screenshots, logs)

Purpose:

  • Responding to the inquiry
  • In the case of complaints: documentation and handling
  • Improving support

Legal basis:

  • Art. 6(1)(b) GDPR (pre-contractual measures / performance of a contract)
  • Art. 6(1)(f) GDPR (legitimate interest in efficient support)

Storage period:
Support correspondence is retained for up to 24 months after the matter is closed, unless longer statutory retention obligations apply.

6.18 Build, Update and Push Infrastructure (Expo / EAS)

Processing activity:
For the creation and delivery of the iOS and Android builds of our App as well as for the provision of over-the-air updates and push notifications, we use the services of Expo / EAS (provider: 650 Industries, Inc., USA). This includes in particular EAS Build (cloud-based app builds), EAS Update (delivery of app updates without a store release) and the Expo Push Notification Service (forwarding of push messages to Apple APNs or Google FCM, see additionally Section 6.10).
Data categories:
Developer identification data of our Expo account (name, email address, profile details where applicable — this concerns us as developers, not end users of the App)
Technical build information, build logs, build artifacts
Device installation identifiers (randomly generated IDs for the assignment of update requests)
Push tokens
IP address of the device (in the course of the update pull or push delivery)
Crash traces (where transmitted from the App via Expo mechanisms)
Purpose:
Provision of the App in the stores (initial build)
Delivery of over-the-air updates to devices for the timely remediation of errors or the delivery of new features
Delivery of push notifications
Stability and performance monitoring of update delivery
Legal basis:
Art. 6(1)(b) GDPR (performance of a contract) for functionally required builds, updates and account-related push notifications
Art. 6(1)(f) GDPR (legitimate interest) for the technical stability of the update infrastructure
Storage period:
Build artifacts and build logs are stored in accordance with Expo's standard retention policies; update logs typically in the range of a few weeks. After termination of the contract, Expo deletes personal data within 90 days, unless a statutory retention obligation prevents this.
Dual role of Expo:
Expo acts partly as a processor (for the core functions mentioned above) and partly as an independent controller. The latter follows from Section 2.4 of the Data Processing Addendum concluded with Expo: Expo uses aggregated and anonymised service data (in particular aggregate device and crash statistics) to improve its own service and contacts us as account holder in the context of service communications. For this, Expo is a controller in its own right; the processing takes place in accordance with Expo's privacy policy, available at https://expo.dev/privacy. /> Recipients:

  • 650 Industries, Inc. (Expo), USA

Platform providers (Apple APNs, Google FCM) for final push delivery (see Section 6.10)
Third-country transfer:
Expo is based in the USA. The transfer takes place on the basis of the EU-US Data Privacy Framework certification of 650 Industries, Inc. and additionally on the basis of the standard contractual clauses (SCCs) of the EU Commission pursuant to Implementing Decision (EU) 2021/914.

6.19 Guest Responses via Invitation Links (Website)

Processing activity:
Invited persons can respond to event invitations (accept/decline, questionnaire) or vote in date finders via an invitation link (avygo.app) even without an Avygo account. In doing so, they provide their name and email address.
Data categories:

  • Name and email address of the guest (we store the email address in encrypted form; in addition, a cryptographic hash for later account matching, see Purpose)
  • Response data: accept/decline status, date-finder votes and, where applicable, responses to additional questions from the host (e.g. accompanying persons, meal preferences, accommodation needs)
  • Selected language of the invitation page
  • Hashed IP address as well as a randomly generated browser identifier (no device fingerprinting; serves abuse detection and the differentiation of multiple guests using the same link)
  • Recognition cookie (see Section 7)

Purpose:

  • Recording and management of the guest response for the host
  • Delivery of functional notifications to the guest (see below "Guest notifications")
  • Recognition of the guest when the link is opened again (view/change response)
  • Abuse and spam detection
  • Optional later assignment of the response to an Avygo account if the guest registers with the same email address (hash matching; the plain-text address is not required for this)

Legal basis:
Art. 6(1)(b) GDPR (implementation of pre-contractual or contract-like measures at the request of the guest — responding to the invitation); for abuse detection and account matching, Art. 6(1)(f) GDPR (legitimate interest in the functionality and integrity of the Service).
Guest notifications (email):
After responding, the guest receives a confirmation email (with a link to view/change their own response). We send further emails only in the event of material changes to the event (date/time, location, cancellation) and when a date is fixed following a date-finder vote. Each email contains an unsubscribe link; after unsubscribing, no further deliveries relating to this invitation take place. No promotional content is sent. Delivery via Resend (see Section 6.16).
Storage period:
Guest responses are stored until the event or the date finder is deleted. Delivery queue entries for notifications are deleted no later than 30 days after dispatch; the invitation link used in the confirmation context is removed from the queue immediately after dispatch.
Recipients:
Supabase (storage, EU); Plus Five Five, Inc. d/b/a Resend (email dispatch, USA — see Sections 6.16 and 9); the host of the event sees the guest's name and response (but not their email address in plain text).

6.20 Ticket Documents (Crew Backup)

Processing activity:
Users can store proof documents for an event (ticket, admission ticket, booking confirmation) in order to keep them available in the App and to make them accessible to the other participants of the same event as a fallback in case the document cannot otherwise be presented at admission. The documents are processed exclusively as image files; tickets provided in PDF format are converted into an image of the first page directly on the device, and PDF files are not stored by us. Use of the function is voluntary.
Data categories:

  • Image files of the stored proof documents including technically necessary metadata (format, file size, upload time)
  • The personal data contained in the image content, in particular real names as well as order and booking numbers; these may also concern other persons
  • The detected barcode format (e.g. QR, PDF417) — not the content of the barcode
  • Visibility status of the individual document
  • Ticket status per participating person (indication of whether a proof document has been stored — without content)
  • Identifier of the storing user and assignment to the event

Purpose:

  • Provision of the stored document to the user themselves, including without an active internet connection
  • Making the document accessible to the other participants of the same event as a fallback for admission
  • Display of the ticket status within the event for coordination among the participants

Visibility and default setting:
Stored documents are by default visible to those persons who have an Avygo user account, are participants of the same event and have accepted or responded with "maybe" to that event. The user can switch each document individually to "only for me"; this setting cannot be overridden even by the host of the event. Persons who participate exclusively via an invitation link without a user account (Section 6.19) have no access. Before a document is stored for the first time, we point out in the App who can see the document. For users who have not yet reached the age of 18, visibility is set to "only for me" by default (Section 14(5)).
Irrespective of the visibility of the document, the participants of the event can see whether a person has stored a proof document; this is a pure status display without content.
Processing on the device:
Text and barcode recognition take place exclusively on the user's device; the image content is not transmitted to us for this purpose. Where ticket data is taken over from a ticket provider's website, this takes place in an in-app browser on the user's device and not via our servers; the user's access credentials for such offerings are neither collected nor stored by us.
Local copies on the device:
The user's own document is kept locally on the device so that it can be displayed without an internet connection. Documents of the other participants are preloaded locally starting 24 hours before the beginning of the event; the cache used for this is limited to 50 MB and is deleted as soon as the event is no longer active.
Legal basis:

  • Art. 6(1)(b) GDPR (performance of a contract) for the storage of the documents, their provision to the storing user and the display in accordance with the visibility setting chosen by that user
  • Art. 6(1)(f) GDPR (legitimate interest) for the default visibility setting vis-à-vis the other participants of the same event and for the status display. The legitimate interest lies in the functionality of the fallback at admission, which can fulfil its purpose only if the document is available when needed without a prior separate release. A balancing of interests (Legitimate Interest Assessment) has been carried out and documented. The following safeguards are provided: the notice before a document is stored for the first time, the possibility to switch each individual document to "only for me" at any time, the exclusion of guests without a user account, the restrictive default setting for users under 18 years of age, and the automatic deletion upon expiry of the period stated below.

Right to object:
You may object to the processing based on Art. 6(1)(f) GDPR in accordance with Art. 21 GDPR (Section 11(6)). Irrespective of this, switching a document to "only for me" and deleting it are available to you directly in the App at any time.
Data of other persons:
Proof documents may contain personal data of other persons, for example in the case of group bookings. Users may only store documents which they are entitled to use; if a document contains data of other persons without an entitlement to share it, it must be switched to "only for me".
Storage period:
By way of derogation from Section 6.8, ticket documents are deleted by us automatically, namely 7 days after the date of the event or, in the case of cancelled events, 7 days after the cancellation. The deletion takes place irrespective of whether the user has previously deleted the document themselves; prior deletion by the user is possible at any time. Local copies on the device are removed in accordance with the information above.
Recipients:

  • Cloudflare R2 (object storage for the image files, processor, EU) — as in Section 6.8
  • Supabase (storage of the associated records including visibility and ticket status, processor, EU region Frankfurt)
  • The other participants of the same event within the scope of the visibility described above; these are recipients within the meaning of Art. 4(9) GDPR, and no processing on behalf of the controller takes place in this respect

Access and deletion:
Ticket documents and the ticket status are included in the data export provided pursuant to Art. 15 and Art. 20 GDPR and are deleted upon deletion of the user account.

6.21 Birthday Reminder

Processing activity:
In the run-up to your own birthday, we point out to you in the App that you can plan a celebration. The notice is displayed within the App. At your express request, we additionally send you the reminder as a push notification; this is not activated by default.
Data categories:

  • Day and month of the date of birth provided at registration; the year of birth is not used for this function
  • Activation status of the push reminder
  • Record of the reminder last displayed or delivered

Purpose:

  • Timely notice of the possibility of planning one's own celebration
  • Avoidance of multiple deliveries of the same reminder

Legal basis:

  • Art. 6(1)(f) GDPR (legitimate interest) for the display within the App. The legitimate interest lies in offering the App's planning function at the point in time at which it can fulfil its purpose. Only the day and month of a date that is already on file are processed; no further data is collected for this purpose. A balancing of interests has been carried out and documented. You can deactivate the display at any time in the App's settings; in addition, the right to object pursuant to Art. 21 GDPR applies (Section 11(6)).
  • Art. 6(1)(a) GDPR (consent) for the additional delivery as a push notification. Consent is given through the express activation of the reminder and can be revoked at any time with effect for the future (Section 6.10).

Content and limits of the reminder:
The reminder relates exclusively to your own birthday. Birthdays of other users are neither processed nor communicated within the scope of this function. The reminder contains no advertising for paid features and no third-party offers. No profiling takes place.
Storage period:
The activation status is stored until revocation or until deletion of the user account. The record of the reminder last delivered is stored for a maximum of 12 months. The date of birth itself is not stored additionally for this function; the information in Section 6.3 applies.
Recipients:

  • Supabase (storage of the activation status and the delivery record, processor, EU region Frankfurt)
  • Where the push reminder is activated, additionally Apple Inc. (APNs) or Google LLC / Firebase (FCM) for technical delivery (Section 6.10)

No transfer to other third parties takes place.

7. Cookies and Comparable Technologies (§ 25 TDDDG)

(1) On the website avygo.app, we use exclusively technically required cookies and comparable local storage accesses. These are permitted without consent pursuant to § 25(2) no. 2 TDDDG, as they are strictly necessary for the provider of an information society service expressly requested by the user to provide that service.
(2) In the App, we use local storage (in particular react-native-mmkv, expo-secure-store) for session management, authentication and local caches. These are functionally strictly necessary and do not require consent under § 25 TDDDG. Data processing subject to consent (e.g. product analytics pursuant to Section 6.15) takes place only after consent has been given.
(3) No processing beyond this (in particular tracking) takes place on the website. Should technologies subject to consent be used in the future, we will implement a separate consent management mechanism (consent banner) for this purpose and amend this Policy.

(4) On the guest invitation pages of the website (avygo.app/i/… and avygo.app/pi/…), we use the following functionally required technologies (legal basis: § 25(2) no. 2 TDDDG — strictly necessary for the service expressly requested by the user; consent is not required):

Name Purpose Storage period Type
avygo_guest_* Recognition of the guest on the invitation page (view/change response), encrypted 90 days First-party cookie, functional
avygo_guest_fp (localStorage) Random browser identifier for differentiating multiple guests using the same invitation link and for abuse detection; no tracking, no device characteristics until deleted by the user localStorage, functional

8. Integrated Third-Party Providers and Processors

We use the following third-party providers. Data processing agreements pursuant to Art. 28 GDPR are in place with all processors. For third-country transfers, we rely — where no adequacy decision exists — on standard contractual clauses (SCCs) of the EU Commission and supplementary safeguards (in particular encryption and pseudonymisation).

Provider Registered office / Hosting Function Legal basis Third country Safeguards
Supabase Inc. EU region (Frankfurt) Database, authentication, storage, edge functions, realtime (incl. chat function, Section 6.7) Art. 6(1)(b) and (f) no (EU) Art. 28 GDPR; SCCs where a US nexus exists
Cloudflare R2 (Cloudflare, Inc.) EU Object storage for media Art. 6(1)(b) EU hosting; parent company USA Art. 28 GDPR; SCCs; EU-US DPF
PostHog Inc. EU cloud Product analytics Art. 6(1)(a) GDPR + § 25 TDDDG EU hosting; parent company USA Art. 28 GDPR; SCCs
Functional Software, Inc. (Sentry) EU region Crash and diagnostic reports Art. 6(1)(f) EU hosting; parent company USA Art. 28 GDPR; SCCs; EU-US DPF
Plus Five Five, Inc. (Resend) USA Dispatch of transactional emails (magic link, support, confirmations) Art. 6(1)(b) and (c) yes (USA) Art. 28 GDPR; SCCs
Apple Inc. USA Sign in with Apple, APNs, App Store distribution Art. 6(1)(b); independent controller in the case of SSO yes (USA) EU-US DPF; SCCs
Google LLC / Google Ireland Ltd. USA / EU (Ireland) Google Sign-In, FCM (Android), Google Play distribution, Google Places API Art. 6(1)(b) and (f) possible (USA) EU-US DPF; SCCs; Google Maps Platform DPT
RevenueCat, Inc. USA Management of in-app purchases and subscriptions Art. 6(1)(b) yes (USA) Art. 28 GDPR; SCCs; EU-US DPF
650 Industries, Inc. (Expo/EAS) USA Build service (EAS Build), over-the-air updates (EAS Update), push notification service (Expo Push) Art. 6(1)(b) and (f); partly independent controller (DPA § 2.4) yes (USA) Art. 28 GDPR (DPA signed); SCCs; EU-US DPF

The privacy policies of the providers mentioned are available via the respective providers' websites. Upon request, we will provide you with a list of current links; please send requests to privacy@avygo.app.
Note: The service provider used for the chat function up to version 2.1, Etke, Sociedade Unipessoal, LDA (Matrix Synapse hosting, Portugal), is no longer used (see Section 6.7).

9. Third-Country Transfers

(1) Where personal data is transferred to a third country (outside the European Economic Area), we ensure an adequate level of data protection within the meaning of Art. 44 et seq. GDPR through:

  • The existence of an adequacy decision of the EU Commission, in particular the EU-US Data Privacy Framework for US providers, to the extent that they are self-certified under the framework (cf. Apple, Google, Cloudflare, Sentry, RevenueCat, Expo, Resend);
  • The conclusion of standard contractual clauses (SCCs) in the version published by the EU Commission;
  • Supplementary safeguards such as encryption in transit and at rest and pseudonymisation, where possible.

(2) Even where a provider primarily hosts in the EU, a data transfer to the parent company's country (in particular the USA) may occur in individual cases, for example for support purposes or security telemetry. In these cases, we ensure compliance with the safeguards mentioned above. For US providers, we conduct Transfer Impact Assessments (TIA) and document them internally.
(3) We can provide you with a copy of the safeguards (in particular the SCCs) upon request in a form compliant with data protection requirements. Please send requests to privacy@avygo.app.

10. Overview of Storage Periods

The following overview summarises the storage periods set out in Section 6. The respective detailed information is authoritative; statutory retention periods remain unaffected.

Data category Storage period
Server logs 30 days; security-relevant entries up to 90 days
Account master data until account deletion
Date of birth (age verification) until account deletion
Anti-circumvention hash (age verification) a maximum of 90 days from collection
Incomplete registration without email confirmation 24 hours
Incomplete registration without completed onboarding 14 days
Profile and gallery content until deletion by the user or account deletion
Event and module content until deletion of the event or account deletion; lifecycle rules per module
Invitation links (open) max. 90 days or until the invited person joins
Chat messages and media until deletion by the user, deletion of the chat/event or account deletion; removal from backups no later than after 30 days
Push tokens until deactivation or token expiry
Address inputs (Google Places API) final address with the event; input fragments not stored permanently
Billing and entitlement data (RevenueCat) for the term of the contract; thereafter, where applicable, 6/10 years pursuant to §§ 147 AO, 257 HGB
Crash reports (Sentry) 90 days
Product analytics (PostHog) — pseudonymous identifier 13 months of inactivity, then anonymisation
Product analytics (PostHog) — aggregated analyses a maximum of 36 months
Transactional emails (Resend) — delivery logs a maximum of 30 days
Moderation and reporting cases 3 years after completion
Support correspondence 24 months after completion; longer where a statutory obligation applies
Inactive accounts notification after 24 months, deletion 30 days later (see § 14 of the Terms of Service)
Guest responses via invitation links (name, encrypted email, responses) until deletion of the event / date finder
Notification queue (guest emails) max. 30 days after dispatch
Guest recognition cookie 90 days
Ticket documents (Section 6.20) automatic deletion 7 days after the date of the event or 7 days after its cancellation
Ticket status (Section 6.20) until deletion of the associated document, at the latest until deletion of the event
Local copies of ticket documents on the device own document until its deletion; documents of the other participants until the end of the event (cache limited to 50 MB)
Birthday reminder (Section 6.21) — activation status until revocation or account deletion
Birthday reminder (Section 6.21) — record of the reminder last delivered a maximum of 12 months

11. Rights of Data Subjects

You have the following rights vis-à-vis us with regard to the personal data concerning you:
(1) Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether personal data concerning you is being processed, and to receive a copy of this data.
(2) Right to rectification (Art. 16 GDPR): You have the right to request the rectification of inaccurate data concerning you or the completion of incomplete data concerning you.
(3) Right to erasure (Art. 17 GDPR): You have the right to request the erasure of personal data concerning you, provided that the statutory requirements are met and no retention obligations or legitimate interests stand in the way.
(4) Right to restriction of processing (Art. 18 GDPR).
(5) Right to data portability (Art. 20 GDPR): You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format, or to request its transmission to another controller, insofar as the processing is based on consent or contract and is carried out by automated means.
(6) Right to object (Art. 21 GDPR):
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
(7) Right to withdraw consent (Art. 7(3) GDPR): Where the processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of the processing carried out up to the withdrawal.
(8) Right to lodge a complaint (Art. 77 GDPR): Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular with the supervisory authority competent for us (see Section 4) or with the supervisory authority of your place of residence or place of work.
(9) Exercising your rights: To exercise your rights, please contact privacy@avygo.app or the contact details set out in Section 1. We may ask you for suitable proof for identity verification purposes where there are reasonable doubts about your identity. We generally respond within one month of receipt of the request; in complex cases, this period may be extended by up to two further months.

12. Automated Decisions, Profiling, AI

(1) We do not make any automated individual decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR.
(2) We do not use any generative or external AI services (e.g. OpenAI, Anthropic, Google Gemini) for the processing of your personal data. Should such services be integrated in the future, we will inform you in good time and — where required — obtain corresponding consent and amend this Privacy Policy. In the event of a future integration of external AI providers, we will contractually exclude the use of your inputs for training by third-party providers.
(3) Assistive functions used within the App (e.g. the "Planning Assistant") operate on a rule-based system using your own inputs and without any connection to external AI providers.

13. Data Security and Technical and Organizational Measures

(1) We take appropriate technical and organisational measures pursuant to Art. 32 GDPR to ensure the security of your personal data. These measures take into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the varying likelihood and severity of the risks for the rights and freedoms of natural persons.
(2) In particular, we implement:

  • Transport encryption (TLS 1.2 or higher) for all connections between the App, the website and the server;
  • Encryption of stored data at rest (encryption at rest, AES-256) in the server infrastructure, including chat content;
  • Local encryption of security-relevant content on the device (expo-secure-store, encrypted MMKV storage);
  • Row-level security (RLS) for database-level permission control in the Supabase infrastructure, including the restriction of access to chat content;
  • Access restrictions on backend systems according to the need-to-know principle; internal access to communication content is logged;
  • Regular security updates and patch management;
  • Logging and monitoring of security-relevant events;
  • Backup and recovery procedures;
  • Selection of processors and their commitment to relevant security standards.

(3) Despite all due care, data transmission over the internet can never be made completely secure. Please additionally protect your access credentials and devices (screen lock, up-to-date operating system, secure networks).

14. Protection of Minors and Privacy by Default

(1) The use of Avygo is permitted for persons who have reached the age of 16. During registration, the full date of birth is requested; if it emerges that the user has not reached the age of 16, registration is prevented.
(2) In addition to self-declaration, we use a technical anti-circumvention procedure to prevent repeated registration attempts using false age information. Details are set out in Section 6.3. This measure fulfils the requirement of "appropriate and proportionate measures" to protect minors pursuant to Art. 28 of Regulation (EU) 2022/2065 ("Digital Services Act").
(3) In the event of demonstrated false entry, the account and all associated personal data are deleted without undue delay; an anonymised hash for circumvention prevention is retained for a maximum of 90 days and is then deleted automatically.
(4) For the processing of personal data in the context of age verification, a data protection impact assessment (DPIA) pursuant to Art. 35 GDPR has been carried out and documented internally.
(5) Privacy by default: For users under the age of 18, the visibility settings of the profile and the gallery are set to the most restrictive level by default (display only for shared event guests or private). The same applies to ticket documents pursuant to Section 6.20, which are set to "only for me" by default for users under the age of 18. Users can actively change these settings; we do not advertise or encourage the relaxation of these defaults.
(6) Should we become aware that data of a person under 16 years of age is being processed without valid consent of the persons holding parental responsibility, we will deactivate the account and delete the data without undue delay.
(7) We accept reports of violations of the protection of minors at privacy@avygo.app.

15. Currency and Amendment of this Privacy Policy

(1) We keep this Privacy Policy up to date. Due to the further development of the App, changed third-party providers, changes in the legal situation or new case law, an amendment may become necessary.
(2) The current version at any given time is available within the App and at https://avygo.app/datenschutz. The version of the Privacy Policy taken note of by the user is documented technically per user account (versioning identifier).
(3) We will inform you of changes in an appropriate manner (e.g. by in-app message or email to the address on file).
(4) In the event of material changes to the Privacy Policy — in particular where new processing activities are added, new third-party providers are integrated, or the purpose and legal basis of an existing processing operation are materially changed — we require the user's renewed, express agreement by way of a corresponding in-app confirmation before the changes take effect. Without this active agreement, use of the App will be suspended to the extent necessary. This re-consent mechanism complies with the requirements of the CJEU in Case C-673/17 ("Planet49").

16. Date and Versioning

This Privacy Policy has the
Date: 06.08.2026
Version: 2.4
Material change compared with version 2.3: New Section 6.20 on ticket documents (storage of proof documents for events, default visibility vis-à-vis the other participants of the same event with a document-specific option to object, recognition of text and barcode format exclusively on the device, automatic deletion 7 days after the event, and restrictive default setting for users under 18 years of age); consequential changes in Sections 6.8 and 6.9 as well as additions to the overview of storage periods (Section 10) and the protection of minors (Section 14). Furthermore, new Section 6.21 on the birthday reminder (use of the day and month of the date of birth for a notice in the App, additionally as a push notification upon express activation); consequential changes in Sections 6.3, 6.4 and 6.10.
The current and earlier versions are available at any time in the App and at https://avygo.app/datenschutz.