Privacy Policy
Current version: 2026-09-26.1
Authored:
Subject to change.
Permanent link to this version · Version history
On this page
1. Who is responsible
The controller of personal data processed to operate Goeeng is:
Dániel Levente Reha, operating as an individual
1117 Budapest, Neumann János u. 1E, Hungary
Privacy contact: support@goeeng.app
Telephone: +36 30 553 9720
This policy covers the Goeeng website, app and related account, Event, ticket, Host, Venue, social and Support features. A feature's processing applies when that feature is offered and you use it. The app is intended for people aged 16 and over worldwide; Events initially take place in Hungary.
An Event organizer is separately responsible for processing it determines for running its Event and meeting its own legal duties. Payment, identity and other providers may also act as independent controllers for parts of their services. We explain relevant disclosures below. Their notices do not replace this policy.
The operator handles privacy enquiries through the contact details above. Any separately required privacy officer or representative will be identified in the relevant local notice before the processing requiring that appointment.
2. Our main commitments
- We do not sell personal data or share it for third-party advertising targeting.
- We do not use users' content to train AI models.
- We obtain separate permission before using your photos or videos in our off-app advertisements or social-media promotions.
- Marketing permission is optional and can be withdrawn. It is separate from creating an account, accepting the Terms and acknowledging this policy.
- Private chat content is end-to-end encrypted. Reporting an individual message deliberately discloses that selected evidence to authorized reviewers.
- We limit collection, employee access and retention to the relevant purpose.
3. What information we process
When you visit our website, Cloudflare processes the network information needed to deliver and protect it, such as your IP address, request and device/browser information. Our legitimate interest is providing a working, secure website. The site does not use advertising trackers or an analytics cookie. Any optional signup form explains its purpose before you submit information; an unavailable form does not send your address or add it to a list.
| Category | Examples and sources |
|---|---|
| Account and access | Information you provide: display name, handle, date of birth, email, optional avatar and bio; phone verification or Apple identity; verification, consent and Terms-version records; session and account-security facts. |
| Profile and music | Public identity, optional Artist status, verification evidence, public appearances, songs you choose for posts or albums, an optional chosen Spotify playlist, and the resulting private taste signal. |
| Social relationships | Friend requests, friendships, follows, blocks, group names and membership, invitations, reactions and mentions. Other people can create references to you through permitted invitations, mentions, gifts or reports. |
| Contacts | With permission, contact identifiers transformed into hashes on your device for account matching. Hashes remain personal data where linkable; they are not described as anonymous. Nonmatches are discarded. |
| Plans and Crews | Invitations, answers, group roles and permitted outing details you and other members provide. Structured Plan information is accessible to our service under its access controls; it is not encrypted like chat content. |
| Posts and media | Photos, videos, captions, chosen music, mentions, selected place, automatic Event tags after accepted scans, album assignments, audience settings and permitted linked placements. |
| Location and presence | Your confirmed city; coarse permitted foreground/background location contributions for crowd heat; valid-ticket attendance context; accepted Event entry/exit facts; and places you tag in posts. |
| Tickets and money | Event and tier, payer and holder, gifts/transfers/resale, orders, billing details, fee and benefit allocations, refunds, payout status and relevant provider references. Payment providers supply payment outcomes and masked payment-method facts. |
| Host, Venue and Artist review | Business/contact facts, proof links, submitted applications, authority and booking evidence, decisions, payout-readiness facts and masked destinations. Stripe holds detailed payout KYC, identity documents and bank details under its own processes. |
| Messages | Encrypted message content and attachments; delivery metadata such as sender, recipients, group membership and timestamps. A reported message is a separate disclosed evidence record. |
| Support and safety | Your correspondence, referenced objects, submitted evidence, private report snapshots, recovery answers, decisions and necessary audit facts. Optional diagnostics have a separate per-case permission. |
| Use and security | Relevant in-app presentations and actions, technical failures, device/app information, connection and security records needed to operate, measure and protect the service. |
Required account information is identified during signup. A confirmed city is needed to complete discovery setup. Optional photo, music and genre choices can be skipped. Without information needed for a particular transaction or verification, that action may be unavailable; optional choices do not become conditions for unrelated features.
We also obtain relevant facts from Event organizers, authorized staff, payment and identity providers, and permitted public Venue, Event and music sources. Verification evidence and another person's report are not public merely because they concern your account.
Closed beta signup list
The website's closed beta form keeps its own list. Joining it does not create a Goeeng account.
- What we collect: the email address you enter, when you signed up and confirmed it, and a one-time confirmation code stored only in hashed form.
- Why: to confirm your address, draw beta invitations at random and email you an invitation if you are selected.
- Legal ground: your consent. You can withdraw it at any time through the privacy contact above; we then delete your entry. Withdrawal does not affect earlier processing.
- Who processes it: Cloudflare stores the list in a database configured for EU jurisdiction. Infobip sends the confirmation email and a possible invitation. Microsoft Azure hosts the Goeeng systems our authorized staff use to look up an entry or delete it. Cloudflare Turnstile checks that a person is using the form; for that check, Cloudflare processes browser and network signals such as your IP address. Our legitimate interest is keeping automated abuse out of the list.
- How long: unconfirmed entries are deleted 7 days after their confirmation link expires. Confirmed entries are used only for the invitation draw. The whole list is deleted when the beta ends on 31 March 2027.
- No marketing: we do not use the list for marketing or add it to any other mailing list.
4. Why we use it and the legal grounds
The ground depends on the specific processing, not on blanket acceptance of this policy.
| Purpose | Principal legal ground |
|---|---|
| Create and authenticate an account; provide requested profiles, relationships, Plans, posts and messaging | Performance of our agreement with you, limited to processing necessary for those services. |
| Arrange requested tickets, gifts, transfers, resale, payments, refunds, payouts and rewards | Performance of the relevant agreement or steps you request before entering it. |
| Meet tax, accounting, consumer-protection and binding legal requirements | The applicable legal obligation. The record and retention period depend on the requirement. |
| Operate account recovery, prevent fraud and misuse, secure systems and review reports | Our legitimate interests in protecting users and the service, and relevant legal obligations where they specifically apply. We assess necessity, proportionality and effects on people, especially minors. |
| Recommend relevant content and produce permitted, limited Host insights from Goeeng activity and deliberate preferences | Our legitimate interests in a useful service and understanding Event performance, subject to privacy controls, minimization and your right to object. Providing a music association you specifically request also uses the service agreement where necessary. |
| Optional contact matching | Your consent to access and use your contacts. For the limited matching of other people's identifiers, our legitimate interest in helping users find existing contacts, with the safeguards below. Your permission is not consent on another person's behalf. |
| Optional location collection for heat | Your informed consent to the location contribution, alongside the required device permission. |
| Optional marketing, per-case diagnostics and off-app promotional use of your content | Your separate consent, which you can withdraw without affecting the lawfulness of earlier processing. |
| Closed beta signup list: confirming your email, drawing invitations and sending a possible invitation | Your consent, which you can withdraw at any time. The form's bot check relies on our legitimate interest in keeping automated abuse out of the list. |
| Establish or defend an actual legal claim | The applicable legitimate interest and, where relevant, a legal obligation or additional condition for protected data. |
We do not treat an optional feature as necessary merely because it is mentioned in the Terms. Where information reveals specially protected matters, we assess the additional legal condition before processing it; an ordinary legitimate interest alone is not enough. A support or safety report does not authorize unrestricted use of sensitive information.
Contact matching can involve identifiers belonging to people who never joined Goeeng. We use only the identifiers needed for a requested match against existing accounts. Hashing does not make them anonymous. Our limited legitimate interest is helping users find people they already know, rather than discovering or marketing to nonusers. Nonmatching identifiers are discarded during matching; we keep no nonuser contact profile and send no invitation or marketing message from an uploaded address book. You may contact us about an identifier or object to its processing even if you have no Goeeng account. Any legally required individual notice is provided separately.
Contact us to object to processing based on legitimate interests or to ask about the assessment. We stop that processing where the law requires it. You have an unconditional right to object to direct marketing, including related profiling.
5. What other people can see
Your display name, handle, bio, avatar and other designated public profile facts are discoverable. There is no account-wide private-profile setting. Date of birth, email, confirmed city and private taste records are not public profile fields.
Public Crew memberships appear on profiles. Private Crew membership is visible only to people who share the relevant membership, subject to blocking and other access restrictions. A private group's name and membership are not protected by chat-content encryption from the service itself.
For adults, the Journal's All album starts Public. For people aged 16–17, All and new custom albums start Private. You can change an album's audience. Private means you and accepted friends; it is not author-only. All caps the audience of its custom albums, and source restrictions can narrow it further.
Temporary posts from adults use Public reach unless a narrower source rule applies. For people aged 16–17, they start friends-only; publishing publicly requires an explicit choice for that post. Public content can be seen by people you do not know. Turning 18 does not automatically widen saved privacy choices.
Hosts, Event teams, Venue managers and Goeeng may curate eligible tagged media within the app. A curated placement stays linked to your post and its audience and deletion controls. Authorized Event managers can inspect the eligible curation pool for their Event, including protected Event media. This is a specific review permission, not permission for everyone to view that media or reuse it outside Goeeng. You can remove permitted curated placements or prevent further curation under the feature's controls.
For people aged 16–17, expected attendance and scan-derived friend presence start hidden until they deliberately enable sharing. That choice persists independently of Ghost. For adults without a retained hidden choice, friends can see these facts unless Ghost is active. Exact scan and arrival times are not shown socially. A place-tagged post can reveal where you chose to post from.
Relevant organizers and staff receive the information needed for their assigned Event, ticket, admission, commercial and safety duties. Access is limited to their role and current authority. Host analytics does not provide person-level audience exports. Breakdowns require at least ten distinct people and additional suppression to prevent identifying smaller groups through comparison.
6. Location, crowd heat and Ghost mode
Your confirmed city is a private discovery setting. We can suggest a city from your phone's time zone and region without treating that suggestion as a confirmed location. Travel does not silently replace your chosen city.
Map requires location permission. Refusing it leaves the other app features available. While Using permission permits foreground contributions; Always can allow background contributions, subject to the operating system. Force-quitting stops those contributions.
Coarse location, accepted scans and ticket counts contribute to crowd estimates. Location contributions are combined so the displayed heat does not point to an individual. A private home exclusion is applied on your device: we do not receive that home zone or a raw movement trail. GPS never creates a friend's presence pin.
Ghost hides expected and scan-derived friend presence until the following local noon. It may still allow anonymous heat contribution and does not change an existing post's audience or erase a place you published. You can withdraw device location permission to stop further location collection. We keep only the latest needed coarse contribution per person, for at most 15 minutes from collection. A newer update replaces it; it does not preserve a movement trail. Expired contributions stop affecting heat and are deleted.
7. Music, recommendations and analytics
Where personal profiling is enabled, your private taste signal uses deliberate song choices for posts and albums and an optional selected Spotify playlist. For people aged 16–17, optional recommendation profiling starts off and requires a separate deliberate choice. Choosing music for display alone does not enable it. Ordinary city/date discovery and explicitly followed content remain available. We do not import passive listening history, playback, browsing or raw location into that signal. Historical post and album song choices can remain taste inputs after the source post or album is removed. Deleting the account removes the internal signal. Replacing or removing a playlist changes its contribution without rewriting those earlier deliberate choices.
A selected public playlist can appear on your profile. An eligible private playlist requires its owner's Spotify authorization and is not made public. You can disconnect Spotify; its own processing follows its privacy information.
Recommendations can also use your city, follows, mutual friends, tickets, accepted attendance and optional onboarding choices. Goeeng does not sell discovery placement. We measure relevant activity within Goeeng; we do not use external browsing histories for Host insights.
Host insights and forecasts use permitted aggregates, including limited matching against deliberate taste and city. They do not expose individual music tastes, private chats, Plan answers, relationships, locations or movement histories. Pseudonymized information is still treated as personal data. Only information that can no longer reasonably identify anyone is treated as anonymous.
8. Private messages and reported evidence
Ordinary chat text, camera attachments and private reply context are end-to-end encrypted. Goeeng cannot read that content in its ordinary encrypted form. We can process delivery metadata, names and membership needed to provide chat.
Message content and service metadata have different lifetimes. Where Hungary's E-commerce Act, section 13/B requires it, we retain only the specified metadata generated or processed by the encrypted service for one year from creation. This can include service type, necessary user identifiers, use dates/start/end times, and registration or use IP addresses and ports. The duty is applied subject to applicable EU-law limits. It does not preserve message text, photos, decryption keys or a GPS trail.
A message disappears for you when its viewing session ends, and all messages have an absolute 24-hour availability limit. Once nobody remains entitled to a server copy, it is due for deletion; cleanup targets 15 minutes and retries failures without restoring access. Device replacement does not recover old message content or keys. We provide no message-content backup or recovery phrase.
If you report a message, you deliberately disclose the selected message, attachment and identifying facts for review. You are told that this evidence survives disappearance from chat. Reporting one message does not disclose the whole conversation. Only authorized Support reviewers can read that evidence; engineering or Finance access alone does not permit it.
Reported evidence is kept while the report is open and deleted 30 days after resolution. Minimal decision records have their separate period below. Recipients can make copies outside the app; Goeeng cannot erase those copies or guarantee that every device prevents screenshots.
9. Flash Room photos
Eligible adults can receive Flash Room invitations and may opt out. Participation requires a deliberate photo submission. Other participants inspect and react without seeing the author's account identity, although the image itself may be recognizable. Authorized safety review can use the relevant entry and identifying facts.
After the room ends, we ask whether you want to publish an eligible photo and keep it on your profile or choose an album. Only your explicit publication choice creates a post outside the room. Declining, dismissing or ignoring that choice does not create a temporary or kept post. The app explains its audience and that it will show your author identity before publishing.
Any published copy follows the ordinary post and album rules. Publishing is not a condition for receiving a legitimate game reward.
An unpublished photo remains privately available to you for up to 24 hours after the room ends. Other participants lose access when the room ends. If you do not publish by that deadline, we delete the unpublished photo unless it is separately held as necessary report evidence. Such evidence stays private to authorized review and follows the report-retention rule; it is not a post.
Rejected or unfinished Flash uploads are deleted within 24 hours of the first upload attempt, unless separately held as necessary report evidence. A retry never restarts that deadline. Flash participation is available only when the required safety screening is available; information about a screening provider and its processing is given before your photo is collected for that purpose.
10. Providers and other recipients
We use providers for the enabled services described below and disclose only necessary information. Their linked notices explain their own processing; Goeeng remains responsible for processing done on its instructions. Providers processing on our instructions must be covered by appropriate agreements and access limits. Some act under their own legal duties and notices for parts of a transaction.
| Provider or recipient | Intended role |
|---|---|
| Microsoft Azure | Application hosting, databases, queues, security and operational monitoring; Microsoft Entra supports authorized employee access. For the closed beta signup list: hosting the systems authorized staff use to look up and delete entries. |
| Cloudflare | Website delivery and protection, media storage and delivery, and related network services. For the closed beta signup list: list storage and the Turnstile bot check. Media and signup-list storage are configured for EU jurisdiction; this does not establish that every provider operation stays in the EU. |
| Stripe | Payment processing, saved payment methods, payouts, verification and payment compliance. Apple Pay is available through supported payment arrangements. |
| Apple | Sign in with Apple, relevant platform services and push delivery. Chat push contains sender/group identity but no message text or media. |
| Infobip | Verification and transactional SMS/email delivery, sending the closed beta confirmation email and a possible invitation, and any separately consented communications actually configured. |
| Google Places | Permitted place lookup and verification for city, Venue and Event features. |
| Spotify | Authorized music, playlist and artist-related features, subject to the permissions you grant and available provider access. |
| Organizers, authorized Event staff and other users | Information allowed by the feature, transaction, role and audience rules explained above. |
| Professional advisers and competent authorities | Necessary information for a specific legal, accounting, security or rights-protection purpose. |
Additional invoice, safety-screening or age-assurance providers are identified in the relevant feature notice before they receive your data. That notice explains the information sent, purpose, recipient role and any additional choices. A provider does not receive data simply because a planned feature is described here.
We do not give providers general permission to sell your data, target third-party advertising from it, or train AI models on your content. Selecting a provider does not authorize an incompatible secondary use.
11. International processing
EU media storage does not mean that all account, payment, communications, support or provider processing is EU-only. Relevant providers or their approved subprocessors may process data in other countries.
Where a restricted international transfer occurs, we identify a lawful mechanism, such as an applicable adequacy decision or approved contractual safeguards, and assess any additional protections needed. We do not rely on your acceptance of these Terms or this policy as blanket consent to international transfers. You may contact us for information about applicable safeguards and how to obtain a copy, with confidential information protected where appropriate.
We identify the countries and safeguards relevant to a new processing activity before it begins. You can request the information for the providers handling your data through the privacy contact above. An EU storage setting alone is not treated as authorization for access from another country.
12. How long we keep information
We apply the following purpose-specific periods. A shorter withdrawal or deletion rule applies where stated. A documented legal duty or concrete claim can require necessary records to be isolated for longer; it does not extend every record about the person. We review such holds and delete the information when their grounds end.
| Information | Retention rule |
|---|---|
| Ordinary account, profile and kept content | While needed for the active account and chosen feature, subject to individual content deletion and the account-closure process below. |
| Temporary posts | Availability ends no later than 24 hours from the first posting attempt; a viewer consumes the temporary media once. Kept posts have a different lifetime. |
| Deliberate private music taste | While the account exists, subject to applicable rights; source-post deletion alone does not remove historical taste inputs. |
| Ordinary message content | Viewing-session consumption and the absolute 24-hour limit, with the cleanup target explained in section 8. No recoverable message-content backup. |
| Disclosed message, profile, post and Flash entry report evidence | While the report is open, then 30 days after resolution. Necessary legal preservation must be separately justified and documented, not assumed for every report. |
| Per-case diagnostics | 90 days after submission, or earlier when that case's diagnostics consent is withdrawn. |
| Support correspondence and internal notes | While the account exists, except records that must be retained for a specific legal requirement or claim. |
| Formal Hungarian consumer complaint and substantive response | Three years under the applicable complaint-record requirement, including where the ordinary account closes sooner. Unrelated diagnostics and attachments do not automatically inherit this period. |
| Raw product analytics | 30 days after collection; then delete or convert to genuinely anonymous aggregates. This does not overwrite the separate retention of transaction or admission source records. |
| Identifiable admission and movement records | Detailed door records expire 90 days after Event reconciliation; person-level and device-level detail is removed. Only the minimal ticket-used fact stays with its justified transaction record. Necessary evidence for a specific dispute may be held separately. |
| Legally required encrypted-service metadata | One year from creation where section 13/B applies, limited to the statutory metadata explained in section 8 and applicable EU-law limits. This is separate from content and general security logs. |
| General security logs, including employee authentication history | 90 days after the event. Necessary evidence for a specific incident may be held separately. |
| Routine employee access logs | One year after the access. Consequential decisions and required financial records follow their own periods. |
| Minimal resolved moderation decisions and associated decision audits | Two years after final resolution. This does not retain the underlying reported media for two years. |
| Active restriction enforcement | Only necessary enforcement facts while the restriction remains active, with an annual necessity review. A continuing restriction does not keep all evidence or account content. |
| Location contributions | Only the latest needed coarse contribution, for at most 15 minutes from collection. A new update replaces it; expired contributions are deleted. No individual movement trail is kept. |
| Plan recap | Full recap for 30 days after completion or cancellation, then limited history under the Plan rules and applicable account rights. |
| Tax and invoicing records | Until the applicable tax-assessment period expires: ordinarily five years after the end of the calendar year in which the relevant return, declaration or payment was due. Statutory extensions and specific longer periods apply where required, including the separate ten-year rule for relevant income or property tax obligations covered by a double-taxation treaty. This does not retain unrelated social content. |
| Terms, consent and withdrawal proof | Minimal version, action, account reference and time while needed to demonstrate the relevant agreement or processing, then only for a justified legal obligation or claim period. No blanket permanent device or IP history. |
| Concrete fraud, debt or other legal-case evidence | While necessary for the specific investigation, obligation or claim and its applicable deadline; reviewed, restricted and deleted when the justification ends. |
| Unpublished Flash photo | At most 24 hours after the room ends, privately available to its author; a separately justified report-evidence copy follows the report-retention rule. |
| Export archive | Seven days after the prepared export becomes ready. The download notice shows the exact deadline; expired archives are deleted. |
| Closed beta signup list | Unconfirmed entries: 7 days after their confirmation link expires. Confirmed entries: until the beta ends on 31 March 2027, when the whole list is deleted. Withdrawing consent deletes your entry sooner. |
| Isolated database backups | At most 12 weeks. They are not used to restore normal access to deleted records. Erasures are reapplied before restored data serves users. |
Application and verification evidence is kept while needed to review a request, maintain the relevant authorization or deal with a specific challenge. We separate source documents from the minimum record of a decision or active grant and remove documents when their purpose ends. Closing an editor does not erase a submitted application, and a historical decision does not justify keeping all of its source documents indefinitely.
Transient messages and message-report evidence are excluded from recoverable backups and retained copies. Backups must not silently extend a promised short evidence deadline; other short-lived report media needs equivalent handling. Providers acting as independent controllers can have their own lawful retention requirements, which we identify rather than promising to override.
13. Account closure and deletion
You can request closure in the app or contact Support about your data rights. Ordinary closure first checks outstanding tickets, payments, refunds and other responsibilities. We explain the specific blocker and next step. A product closure blocker does not cancel a statutory erasure request or its response deadline; any refusal to erase particular data needs its own lawful reason.
After confirmation, your profile and personal content are hidden, ordinary sessions end and a 30-day recovery period begins. You retain limited access to explicit restoration, export and Support. Signing in does not silently restore the account. At the end of the period, ordinary account information is removed or anonymized according to the rules above.
A late financial dispute or legal obligation does not reactivate the account or preserve all social content. Only necessary records are isolated under the relevant purpose and deadline. Independent restrictions remain effective if you restore an account. Expired chats, keys and temporary media are not recovered.
Removal from active systems and expiry of isolated backups are different steps. We do not promise that every lawful financial record, other participant's copy, or independently controlled provider record disappears on day 30. Disconnecting a provider does not delete your entire account with that provider.
14. Your choices and rights
Subject to applicable conditions, you can request access, correction, deletion, restriction, an appropriate portable copy, and information about processing. You may object to legitimate-interest processing and withdraw consent for consent-based uses. You can complain to a competent supervisory authority and seek a judicial remedy.
Contact support@goeeng.app or use the relevant in-app controls. We may ask for proportionate information needed to verify a request, without collecting unnecessary identity evidence. We explain any lawful limitation, such as another person's rights or required financial retention. Internal notes are not automatically exempt from a statutory access request merely because the app does not display them.
For GDPR requests, we respond without undue delay and normally within one month. If the law allows an extension because of complexity or volume, we explain it within the first month. Applicable local rights and shorter mandatory periods remain available. Exercising rights does not waive an existing ticket or refund entitlement.
The Hungarian supervisory authority is the National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9–11; postal address 1363 Budapest, Pf. 9; telephone +36 1 391 1400; email ugyfelszolgalat@naih.hu. Its contact page explains how to make a complaint. You may also complain to another authority competent for your residence, work or the alleged issue.
Marketing can be withdrawn through its provided control or by contacting us. Security, receipt, refund and essential service messages are distinct from marketing. Withdrawing a case's diagnostics consent deletes the diagnostics already attached to that case.
15. Young people, security and automated processing
The minimum account age is 16. We do not knowingly allow younger children to hold accounts. Flash Rooms and Partner applications require 18. If we discover an underage account, we address access and unnecessary data under the applicable law and relevant safety process.
Local law may require additional age assurance or guardian authorization. A self-declared date of birth is not represented as sufficient wherever stronger checks are required. If an additional check is needed, the feature explains who performs it, what information is used, why it is necessary, and how long it is kept before collecting it. We seek only the necessary eligibility result; ordinary signup does not collect an identity-document copy or a face scan. Required guardian authorization is obtained separately from marketing permission.
We use access controls, secure communications, appropriate encryption and limited employee permissions. Security reduces risk; no service can guarantee that data will never be lost or misused. Ordinary encrypted chats remain unavailable to employees, except for the evidence a participant deliberately reports.
Software ranks content, checks eligibility, processes payments and calculates benefits. A payment provider can carry out its own fraud or compliance decisions. Before a debt notice can lead to a Host-creation restriction, an authorized person meaningfully reviews the debt, recipient, allocation, evidence and proposed restriction. They can reject or correct it. The approved deadline and payment recovery may then run automatically. We explain the reasons and provide access to human review; a provider signal alone does not make that decision.
16. Changes and local protections
We notify you of material changes and seek fresh consent where the law requires it. A future change of legal operator is identified explicitly, with updated contact details and required notice. It does not silently authorize new advertising, sale or AI-training uses.
This policy preserves additional rights under applicable local law. Those rights can include appealing a refused privacy request, acting through an authorized representative and receiving a response within a shorter statutory period. Contact us to exercise them; we explain the applicable process and any necessary verification. We do not penalize you for exercising privacy rights. Any required local notice supplements this policy before the relevant processing begins and cannot reduce mandatory protections.