Note on final review: the entries still marked in orange concern variable service providers and specific backup retention periods. They must be reconciled with the production configuration before the app store release.
1. Controller
CEA IT-Services
Owner: Can Emre Aktas
Levinstraße 153
45356 Essen, Germany
Email: datenschutz@get-link-up.app
The controller within the meaning of the General Data Protection Regulation (GDPR) is the person or organisation named above.
2. Visiting this website
Server logs
When you open the website, the web server processes technically necessary connection data. This may include IP address, date and time, the file requested, volume of data transferred, referrer, browser type, operating system and HTTP status. This processing is necessary to deliver the website, detect errors and defend against attacks. The legal basis is Art. 6 (1) (f) GDPR.
The hosting provider is netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The server is located in Germany. For the Link Up website, regular access logging in the web server is disabled. The hosting provider may process its own technical logs as part of secure infrastructure operation.
Cookies and analytics
In its present version this website sets no analytics, advertising or tracking cookies. The font files used are served locally from our own web server; loading the fonts creates no additional connection to a font provider.
Contact by email
If you contact us by email, we process your email address, the content of your message and the metadata needed to handle it. The legal basis is Art. 6 (1) (b) GDPR where a contractual or pre-contractual matter is involved, and otherwise Art. 6 (1) (f) GDPR. We delete enquiries once they are resolved, provided no statutory retention obligations apply.
Launch waitlist
On the home page you can pre-register to be notified when Link Up launches and secure three months of Premium free. For this we process your email address, the language of the sign-up page, any campaign identifier from the address bar, your IP address, the promised Premium period, and the times of sign-up, confirmation, and later redemption.
Sign-up uses a double opt-in procedure: after you submit the form we send you an email containing a confirmation link. Consent is only given once you click that link, and only then do we add you to the list. If you do not confirm, we will not write to you again. We store the IP address and timestamp in order to demonstrate consent (Art. 7 (1) GDPR).
The legal basis is your consent under Art. 6 (1) (a) GDPR. You may withdraw it at any time with future effect, via the unsubscribe link in every email or informally to support@get-link-up.app. We delete your address after withdrawal, or at the latest twelve months after the launch of Link Up. Emails are sent from our own server; addresses are not passed to a newsletter provider.
Partner bookings and Stripe Checkout
When you book a partner placement, we process the venue name and location, city, your name and business email address, an optional website, selected plan, price, language, and booking and contract status. We need this data to review the booking, provide the placement and manage the contract. The legal basis is Art. 6 (1) (b) GDPR.
The payment form is provided by Stripe. Payment and billing information is sent directly to Stripe. We do not receive a full card number, only technical identifiers and the payment, customer and subscription status. The provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe's privacy information also applies. Where data is processed outside the EEA, Stripe states that it relies on applicable safeguards such as standard contractual clauses.
3. Data processing in the app
Account and sign-in
For your Link Up account we process email address, username, an encrypted stored password, age, gender information, profile picture, account ID, creation time, and sign-in and session tokens. The password is not stored in plain text. This processing is necessary for registration, sign-in and account management (Art. 6 (1) (b) GDPR).
Profile and city membership
We process the cities you select, memberships in city groups and subgroups, join times and voluntary profile details. This data makes it possible to show relevant groups, posts, members and meetups. The legal basis is Art. 6 (1) (b) GDPR. Visible profile details may be shown to other signed-in users.
Usage and device data
For technical provision of the service we may process app version, platform, device and network information, API calls, error data, timestamps and security-relevant logs. The legal basis is Art. 6 (1) (f) GDPR. Our interest lies in secure, stable operation and in fixing faults.
Feedback
When you send feedback we process its content, your account ID, the time, and any technical details you include. We use this data to fix bugs and improve the app.
4. Posts, chats, stories and moderation
Link Up processes content you provide yourself: text messages, posts, images, stories, voice recordings, captions, comments, reactions, likes, translation requests, and time and group assignments. Public content is visible to members of the relevant area. Private subgroups are limited to people with the corresponding permission.
Stories are intended for time-limited display. Technical backups or moderation records may persist longer to the extent legally permitted. Deleted content may temporarily remain until running backups complete or until a substantiated report has been handled.
Automated image moderation
Uploaded images are automatically checked for unsafe content before publication. For this purpose, the image is transmitted to the OpenAI API. If an image is rejected, we immediately delete the uploaded file and do not store it as a post. For security records we may retain the category, risk score, a SHA-256 fingerprint, the account and group context, and the time of the event. This processing serves the provision of a safe service, enforcement of our rules, and protection of other users (Art. 6 (1) (b) and (f) GDPR).
Reports and blocks
When content or users are reported, we process the IDs of the accounts and content involved, the reason for the report, any voluntary explanation, status, handling notes and timestamps. For blocks we store the account IDs involved. This processing serves safety, enforcement of our rules and protection against abuse (Art. 6 (1) (b) and (f) GDPR).
5. Cities, meeting points and maps
Link Up is city-based. We process the city you select and any place details you add to posts or meetups. Map features may involve processing coordinates of cities, places or meetups. A precise device location is used only if you grant the corresponding operating system permission and a feature requires it.
Depending on the operating system, maps may be rendered via Apple Maps or Google Maps. This may transmit IP address, device information, map viewport and location data to the respective provider. The legal basis is your consent under Art. 6 (1) (a) GDPR where precise location sharing is required. You can withdraw the permission at any time in your device settings.
6. Push notifications
If you enable push notifications, we store an Expo push token, the account ID, the platform and the update time. Delivery involves processing via Expo and subsequently via Apple Push Notification Service or Firebase Cloud Messaging. The legal basis is your consent (Art. 6 (1) (a) GDPR). You can disable notifications in your device settings.
8. Integrated services
Translations
When you use the translation feature, the text to be translated is transmitted to MyMemory. The provider is Translated s.r.l., Via Indonesia 23, 00144 Rome, Italy. MyMemory processes the text and technical connection data to provide the requested translation. The feature is voluntary; do not use it for confidential or particularly sensitive content.
GIF search
When you use GIF search, the search term and technical connection data may be transmitted to Tenor, a Google service. Use is voluntary and serves the search function you chose. Search requests use Tenor's strictest available content-filter level.
Image moderation
Uploaded images are processed through the OpenAI API for the automated safety check described above. Processing may take place outside the European Economic Area; the transfer safeguards described in the following section apply.
Media access
Photos, videos or audio are only processed if you select them, record them, or grant the relevant device permission. Permissions can be withdrawn in the system settings. Content already uploaded must additionally be deleted in the app.
Error analysis
To detect crashes and technical errors, the app may use Sentry by Functional Software, Inc. This involves processing technical error data, app version, platform and device information. Transmission of full contact details is disabled. Processing serves our legitimate interest in secure and stable operation (Art. 6 (1) (f) GDPR).
9. Recipients and transfers
We only pass on data where it is necessary for the service, where you have consented, where a legal obligation exists, or where legitimate interests permit it. Possible recipients are:
- hosting, database and storage providers,
- Expo, Apple and Google for technical app services and push messages,
- RevenueCat and Apple or Google for premium subscriptions,
- Sentry for technical error and crash reports, where enabled,
- OpenAI for safety checks of selected image uploads,
- map, translation and GIF providers when the respective feature is used,
- advisers, authorities or courts, where legally required.
Some providers may process data outside the European Economic Area. In those cases we base the transfer on an adequacy decision, appropriate safeguards such as EU standard contractual clauses, or another permissible basis under Art. 44 et seq. GDPR.
10. Retention and deletion
We store personal data only for as long as it is required for the relevant purpose. Account data generally persists until the account is deleted. Session and security tokens expire or are revoked. Content is removed when the account or the content itself is deleted, unless legal obligations, security reasons, open reports or legal claims require limited further storage.
Subgroups are technically designed for a limited lifetime and may be archived afterwards. Purchase and billing data may be stored longer due to statutory retention obligations. Security-relevant server logs are generally deleted after 14 days. Daily backups of the database and uploads are automatically deleted or overwritten after 30 days.
You can delete your account directly in the app settings. Alternatively you can use our support page or write to datenschutz@get-link-up.app. A step-by-step description is on the account deletion page.
11. Your rights
Subject to the statutory conditions, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. You may withdraw any consent given at any time with future effect.
A message to datenschutz@get-link-up.app is enough to exercise your rights. We may request suitable proof where we cannot otherwise establish your identity with certainty.
You may also lodge a complaint with a data protection supervisory authority. Competent authorities include the one at your habitual residence, place of work, or the place of the alleged infringement. The authority responsible for the controller is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), ldi.nrw.de.
12. Minors
Registration is technically intended from the age of 13. Where the law of your country of residence requires the consent of a parent or guardian for consent to digital services, the app may only be used with that consent. Link Up is not a dating app and should be used by minors only in an age-appropriate way and with regard to personal safety.
13. Data security
We use appropriate technical and organisational measures, including encrypted transmission, hashed passwords, role-based administrative access and limited session tokens. No online service can guarantee absolute security. Please use a unique password and do not share sensitive information in public groups.
14. Changes to this policy
We update this privacy policy when features, service providers or legal requirements change. The current version is always available on this page. In the event of material changes we will additionally inform you in the app or by another suitable means.
This English version is provided for convenience. In case of discrepancies, the German version prevails.