Legal Center · B'local Mobile Application

Privacy Policy & Data Processing Agreement

Governing the collection, processing, transfer and safeguarding of personal data within the B'local mobile application and its supporting backend infrastructure.

Version 3.10Effective: 31 August 2026GDPR · UK · CCPA · LGPD · POPIA · NDPA · PDPA

Preamble & Mutual Assent

Preamble

This Privacy Policy and Data Processing Agreement (the "Policy") constitutes a legally binding and enforceable instrument between the natural person accessing, downloading, registering for, or otherwise utilising the B'local mobile application and its associated services (the "User", " Data Subject" or "You") and BL PLATFORM S.L., a limited liability company duly organised and existing under the laws of the Kingdom of Spain, with registered domicile in Barcelona, acting in its capacity as Data Controller (the "Controller", "Company", "We" or " Us").

By affirmatively interacting with the B'local mobile application, its application programming interfaces, software development kits, and supporting backend infrastructure (collectively, the "Services"), the User unequivocally stipulates to having read, fully understood, and freely consented to the data processing methodologies set out herein. Where the User does not concur with any provision, clause or technical mechanism, the User's exclusive remedy is the immediate cessation of use of the Services and the deletion of the application from all User-controlled hardware.

This Policy is drafted in compliance with, and shall be construed by reference to: (i) Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"); (ii) the United Kingdom GDPR and the Data Protection Act 2018 ("UK GDPR"); (iii) the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"); (iv) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (v) the South African Protection of Personal Information Act, 4 of 2013 ("POPIA"); (vi) the Nigeria Data Protection Act 2023 ("NDPA"); (vii) the Kenya Data Protection Act, 2019; (viii) the Brazilian General Data Protection Law (Lei 13.709/2018, "LGPD"); (ix) the Canadian PIPEDA and Québec Law 25; (x) the Swiss Federal Act on Data Protection ("FADP"); (xi) the comprehensive privacy statutes of the United States States identified in Article XV; (xii) the Singapore Personal Data Protection Act, the Indian Digital Personal Data Protection Act 2023, the Japanese APPI, the South Korean PIPA and the Australian Privacy Act 1988; and (xiii) any further mandatory local laws of the User's jurisdiction, the more protective provision prevailing in the event of conflict.

Article I

Defined Terms

For the purposes of this Policy, the capitalised terms below shall bear the ascribed meanings:

1.1 Personal Data

Any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR and equivalent provisions under POPIA, NDPA and CCPA/CPRA.

1.2 Processing

Any operation performed upon Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, disclosure, erasure or destruction.

1.3 Controller

BL PLATFORM S.L., the entity which alone or jointly determines the purposes and means of the Processing.

1.4 Processor / Sub-Processor

Any natural or legal person which Processes Personal Data on behalf of the Controller pursuant to a written data processing agreement compliant with Article 28 GDPR.

1.5 Behavioural Biometrics

Non-physiological, algorithmic patterns of human-device interaction (touch coordinates, swipe cadence, gyroscope vectors) processed solely for fraud and bot mitigation.

1.6 Digital Footprint

Metadata accompanying a network request, including IP address, signed Request Fingerprint headers, device manufacturer, operating system version and locale.

1.7 Ephemeral Session Storage

Volatile in-memory state used for transient location overrides, purged from RAM upon application termination and not persisted to disk.

1.8 Sensitive / Special Category Data

Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, data concerning health or a person's sex life or sexual orientation.

Article II

Identity of the Data Controller & DPO

Pursuant to Article 4(7) GDPR and parallel international frameworks, BL PLATFORM S.L. acts as the primary Data Controller. The Company maintains its principal place of business and registered corporate domicile in Barcelona, Spain.

Controller: BL Platform S.L.

Registered Office: Carrer de Lepant, 270, 08013 Barcelona, Spain

NIF: B88709738

Privacy & Data Protection Enquiries: support@blocalapp.com

Data Protection Officer / Privacy Lead: dpo@blocalapp.com

No representative is designated pursuant to Article 27 GDPR, and none is required: the Controller is established within the European Economic Area (Barcelona, Spain) and Article 27 applies only to controllers not established in the Union.

2.1 Data Protection Officer (Art. 37 GDPR / LOPDGDD Art. 34)The Controller has formally assessed whether the designation of a Data Protection Officer is mandatory under Article 37(1)(b) GDPR, having regard to the fact that the Services involve behavioural-interaction analysis, systematic security telemetry, precise location Processing and AI-assisted verification. In light of that assessment, and without conceding that the "regular and systematic monitoring of data subjects on a large scale" threshold is met, the Controller has designated a Data Protection Officer whose contact details are published above and have been notified to the Spanish supervisory authority (Agencia Española de Protección de Datos, "AEPD") in accordance with Article 37(7) GDPR and Article 34(3) LOPDGDD. The Data Protection Officer reports to the highest management level, may not be instructed as to the exercise of their tasks, and may be contacted directly and confidentially by any Data Subject in relation to any matter concerning the Processing of their Personal Data or the exercise of their rights.

Statutory inquiries, Data Subject Access Requests ("DSARs"), erasure or portability requests, and regulatory correspondence shall be directed to the Controller.

Article II bis

Data Protection Impact Assessment & Records of Processing

The Controller has carried out a Data Protection Impact Assessment ("DPIA") pursuant to Article 35 GDPR in respect of those Processing operations which, individually or in combination, are likely to result in a high risk to the rights and freedoms of natural persons, namely: (i) behavioural interaction analysis and honey-pot telemetry (Article IX); (ii) automated threat mitigation, including the automated restriction of account access (Article X); (iii) the Processing of precise geolocation data (Article VIII); and (iv) AI-assisted challenge verification and content generation (Article XXI). The assessment additionally addresses the criteria listed in the AEPD's mandatory DPIA list adopted under Article 35(4) GDPR.

The DPIA describes the Processing operations and their purposes, assesses their necessity and proportionality, identifies the risks to Data Subjects, and records the technical and organisational measures adopted to mitigate those risks (including data minimisation, coordinate truncation, pseudonymous logging, retention limits and the human-review pathway described at Article X bis). The DPIA is reviewed at least annually, and whenever a material change occurs in the nature, scope, context or purposes of the Processing. A copy is available to the AEPD, or to any other competent supervisory authority, on request.

The Controller likewise maintains a Record of Processing Activities under Article 30 GDPR; a public-facing extract of that register is reproduced at Annex I to this Policy.

Article III

Territorial & Material Scope

This Policy applies extraterritorially to the Processing of Personal Data of all Users of the Services, irrespective of the User's place of residence, and irrespective of whether the Processing itself takes place within the European Economic Area. The Controller asserts compliance with the extraterritorial reach provisions of GDPR Article 3, POPIA section 3, NDPA section 2, and CCPA §1798.140.

Article IV

Categories of Personal Data Processed

The Controller, observing the principle of data minimisation under Article 5(1)(c) GDPR, processes the following categories of Personal Data:

4.1 Identity & Contact Inputs

Given names, surnames, date of birth (for age-gating), verified email addresses, and mobile telephone numbers required for multi-factor authentication.

4.2 Authentication Credentials

Hashed and salted passwords (Argon2id), session tokens, refresh tokens, and federated identity provider sub-claims (Apple, Google).

4.3 Profile & Preferences

Avatar, declared dietary preferences, opt-in flags (alcohol challenges, push notifications, marketing), preferred language and accessibility settings.

4.4 Geolocation Data

Precise location information (GPS coordinates) and coarse location signals as further detailed in Article VIII, including a permanent declared 'Home Base' and ephemeral 'Travelling Status' overrides.

4.5 Behavioural Biometrics

Touch coordinate maps, interaction cadence, accelerometer / gyroscope vectors, and honey-pot field engagements as detailed in Article IX.

4.6 Device & Technical Data

Device manufacturer, model, OS version, app version, language, time zone, IP address, ASN, and signed X-Request-Fingerprint header values.

4.7 User-Generated Content, Media, Verification & Social Interaction Assets

Reviews, photographs, ratings and challenge submissions published or uploaded by the User. Public reviews and replies are visible to other Users and to the relevant venue; there is no private in-app messaging channel attached to reviews or replies. The User may report a review or reply to the Controller for moderation, and business-account holders may reply to reviews of their own venue. Where a User chooses to upload photos, utilize AI Photo verification, or record AI Voice notes, the Application requests explicit OS-level permission to access the device Camera, Photo Library, or Microphone respectively. The device Camera is also used, with explicit OS-level permission, to scan QR codes for the purpose of synchronising challenges between friends so that they may complete them together, and (for business users) to scan venue freebies or event guest-list QR codes. Images and audio are processed exclusively for the intended upload, challenge verification, QR scan or business redemption. The Controller does not background-scan the User's photo roll or continuously monitor microphone input.

4.8 Transactional Data

Reward redemptions, leaderboard rank, accrued points, and (where applicable) anonymised payment confirmations and subscription statuses for the Explorer Plan or Discover Plan. In-app subscriptions are purchased and billed through Apple In-App Purchase for iOS users and Google Play Billing for Android users; business-user payments are processed by Stripe, Inc.

4.9 Inferred Data

Risk scores, fraud probability, recommended venues and inferred interests, generated by automated processing as set out in Article XXI.

4.10 On-Device Viewing History

Identifiers of recommendations and events that have been displayed to the User on their device, persisted exclusively within the local AsyncStorage of the User's handset (capped at the most recent one thousand (1,000) identifiers per category) for the sole purpose of prioritising previously-unseen content. These identifiers are not transmitted to the Controller's backend, are not linked to the User's account server-side, and are erased upon application uninstallation or User-initiated cache clearance.

4.11 Guest User Identity (Anonymous UIDs)

For Users who opt to access the Services without creating a registered account ('Continue as Guest'), the Controller generates a randomized, anonymous unique identifier (UID) via Firebase Authentication together with a minimal placeholder record. No names, email addresses, or third-party federated identifiers are collected, and the anonymous identifier is not linked to any real-world identity. On sign-out, the local guest session is cleared from the device. The anonymous account and its associated records are deleted on the User's request, on conversion of the guest session into a registered account, or on account deletion, and are in no case retained beyond the period necessary to provide the guest browsing experience. A Guest User may exercise the rights described in Articles XIV to XVI by contacting the Controller and identifying the device or session concerned.

4.12 Friend Display Names & Challenge Sync

Where a User connects with friends to complete challenges together, the Controller processes the User's display name as visible to those friends. The User may edit the display name shown to friends at any time. The Controller does not share email addresses, telephone numbers or precise location coordinates with friends; only the name chosen for the friend-group context and the challenge-sync state are transmitted.

4.13 Trip-Award Eligibility Tracking

The Controller maintains a record of whether a User has been selected as eligible for a trip award or similar high-value reward. If a selected User does not accept the award within seven (7) calendar days, eligibility is automatically revoked and transferred to the next eligible User. This processing is necessary to operate the reward allocation mechanics and to ensure fairness in the gamification programme.

The Controller does not intentionally Process Sensitive / Special Category Data within the meaning of Article 9 GDPR, save where strictly necessary and supported by an Article 9(2) lawful basis, in particular explicit consent.

Article IV bis

Business-User Content Uploads (Vibe Playlist, Events, Freebies & Guest Lists)

Users authenticated under a verified business account ("Business Users") may, within the business dashboard, voluntarily upload additional content and use camera-based redemption tools for the purpose of enriching the public profile of their venue and operating events. Such uploads and scans are Processed under Article 6(1)(b) GDPR (performance of the business-account contract) and are subject to the following safeguards:

4bis.1 Vibe Playlist (Audio Tracks)

Up to five (5) audio files in MP3 format, selected by the Business User and transmitted to the Controller's object storage (Firebase Storage) for streaming snippet playback within the venue's recommendation page. Files are scanned for size and MIME-type conformity. The Business User warrants that they hold the necessary rights and/or licences (including, where applicable, public-performance and master-recording rights) in respect of each uploaded track.

4bis.2 Event Postings

A textual title, description, cover image and an external ticket link describing an event promoted by the Business User. Images are compressed client-side prior to upload to minimise bandwidth and storage footprint. Each posting is written into a per-business events register together with a server-generated retention timestamp. The Controller does not operate an internal ticketing system; ticket purchases are handled exclusively by the third-party destination linked by the Business User.

4bis.3 Time-To-Live (TTL) Erasure for Events

Event postings are automatically and irreversibly deleted by Firestore's native TTL policy one (1) calendar month after the event date or posting date, whichever is later. No human intervention is required and no copy is retained for analytical purposes after deletion.

4bis.4 Camera-Based Redemption Scans

Business Users may use the device Camera, with explicit OS-level permission, to scan QR codes presented by End-Users for the purpose of redeeming freebies or validating event guest-list entries. Scan results are processed in real time, recorded against the relevant Business User's account for redemption logging, and are not used for advertising or profiling of End-Users.

End-Users consuming a venue's profile may be exposed to short, looping audio snippets of the Business User's Vibe Playlist. Such playback is performed locally on the End-User's handset; no audio data is transmitted from the End-User to the Controller in connection with this feature.

Article IV ter

Business-User Analytics

Business Users receive aggregated analytics to help them understand the performance of their venue and events on the Services. These metrics are derived from End-User interactions and are presented to the Business User in a non-identifiable, aggregated form. The following analytics are collected:

4ter.1 Challenge Completion Attribution

The number of challenges linked to the Business User's venue that have been completed by End-Users. This count is attributed to the venue and is used solely for performance reporting and reward mechanics.

4ter.2 Review & Save Metrics

The number of reviews received and the number of times End-Users have saved the venue or an event to their personal list. Review averages are calculated from published ratings. These metrics are shown to the Business User in the dashboard.

4ter.3 Event Performance Metrics

For each event posted by a Business User, the Services track the number of views, saves and the average review rating associated with that event.

4ter.4 Date-Range Filtering

Business Users may filter analytics by preset periods (today, yesterday, last 7 days, last month) or by a custom date range. Filtering is performed client-side against data already held in the Business User's account; no additional Personal Data is collected to enable this feature.

The Controller does not share the identities of individual End-Users with Business Users unless the End-User has voluntarily published identifiable content (for example, a public review with a display name).

Article V

Purposes of Processing

Personal Data is Processed exclusively for the following enumerated purposes:

  1. Provision, maintenance and improvement of the Services;
  2. Account creation, authentication, identity verification, and sending transactional communications (e.g., reward purchase confirmations) via email;
  3. Personalisation of recommendations, challenges and rewards;
  4. Operation of the gamification, points, leaderboard and trip-award eligibility infrastructure, including the seven-day acceptance window and automatic transfer of unclaimed eligibility to the next eligible User;
  5. Synchronisation of challenges between friends via QR-code scanning, using only the User's chosen display name in the friend context;
  6. Publication, moderation, reporting and reply functionality in respect of reviews and other public content, with no private in-app messaging attached to reviews or replies;
  7. Provision of aggregated analytics to verified Business Users regarding their venue and event performance, including challenge completions, reviews, saves, views and review averages;
  8. Redemption of venue freebies and validation of event guest-list entries through QR-code scanning by Business Users;
  9. Detection, prevention and investigation of fraud, abuse and security incidents;
  10. Compliance with legal, regulatory, accounting and tax obligations;
  11. Establishment, exercise or defence of legal claims;
  12. Processing account-deletion requests submitted through the Controller's website, including verification of the requester and communication of the outcome;
  13. With separate opt-in consent: direct marketing and product research.

Article V bis

Privacy Policy Addendum: Gamification Data

When you participate in B'local challenges and rewards, the Controller collects and processes additional Personal Data to operate the gamification infrastructure and to ensure fairness across the rewards programme. The categories described below are Processed under the statutory bases set out in Article VI and retained in accordance with Article XIII.

Progress Tracking

The Controller records completed challenges, earned credits, and successful paid referrals to update your leaderboard status, calculate qualifying credits, and determine eligibility for high-value trip rewards.

Reward History

A log of rewards you have claimed is retained to enforce category-specific cooldown periods (e.g., 24 hours for food, 30 days for certain trip sub-types), prevent duplicate claims, and ensure fair allocation of limited inventory.

Location Data for Challenge Verification

If a challenge requires you to visit a specific physical venue, the Controller may temporarily use your precise location data (with your explicit OS-level permission) solely to verify completion. Location is not retained for profiling, advertising, or longitudinal tracking beyond the immediate verification window.

Seven-Day Redemption Window

When you become eligible for a trip reward or similar high-value prize, the Controller records the eligibility timestamp. If you do not redeem the reward within seven (7) calendar days, your position on the leaderboard is forfeited, eligibility is transferred to the next eligible User, and you must complete one (1) challenge the following week to rejoin the leaderboard.

Your data is kept secure, is used only for the operation of the rewards programme and related anti-fraud controls, and is never sold to third parties.

Article VI ter

Layered Notice (LOPDGDD Art. 11) & Records of Consent and Preference (GDPR Art. 7(1))

6ter.1 First-layer information. In accordance with Article 11 of Spanish Organic Law 3/2018 (LOPDGDD), basic information is provided to the User at the point of collection, on a single screen presented during registration, in concise and plain language. That first-layer notice identifies: (i) the identity of the Controller and the contact details of the Data Protection Officer; (ii) the categories of data collected and the purposes for which they are Processed; (iii) the legal bases relied upon; (iv) the existence of the rights of access, rectification, erasure, restriction, portability, objection and the right to lodge a complaint with the AEPD; and (v) a direct, prominent hyperlink to this complete Policy, which constitutes the second information layer. Consent to optional Processing is not obtained through the first-layer notice alone.

6ter.2 Records of consent and preference. Where the Controller relies on the User's consent for a particular Processing purpose (for example marketing communications, push-notification categories, or referral attribution), it records, as evidence of compliance with Article 7(1) GDPR: the purpose to which the consent or refusal relates; the action taken and the resulting state; the date and time of the action; the version identifiers of this Policy and of the Terms then in force; and the surface through which the action was taken (for example onboarding, in-app privacy settings, or an unsubscribe link). For the diagnostics and session-replay Processing described in Article VI bis, which is carried out on the basis of legitimate interest, the Controller records the User's current preference (enabled or disabled) together with the date it was last changed.

6ter.3 Withdrawal and objection. A consent may be withdrawn, and an objection to legitimate-interest Processing may be raised, at any time from within the application, with the same ease as the setting was given and without detriment to the availability of the core Services. Withdrawal or objection takes effect promptly and without retroactive prejudice to the lawfulness of Processing carried out before it.

Article VII

Minimum Age (Adults Only, 18+)

The Services are rated and offered exclusively to adults and are not directed at, nor available to, any person under the age of eighteen (18) years, or such higher age of majority or lawful drinking age as applies in the User's jurisdiction of residence. The Controller does not knowingly collect or Process the Personal Data of any person under that age. Where the digital age of consent under a particular law is lower than eighteen (for example fourteen (14) under Article 7 of Spanish Organic Law 3/2018 (LOPDGDD), or sixteen (16) under Article 8 GDPR), that lower threshold is not relied upon, because the product itself is age-restricted to adults. Upon verified notification that a person under the applicable adult threshold has registered, the Controller will expeditiously delete the account and all associated Personal Data and, where required, notify a parent or guardian.

7.1 Age Verification Gate During onboarding the User is presented with a neutral age-selection screen which is not pre-populated with any default value: the User must affirmatively select a date of birth or age before proceeding, and the control carries no suggestion, highlight or pre-selection intended to influence the answer. Where a User indicates an age below the applicable adult threshold, account creation is blocked: the flow terminates, no account is provisioned, and no Personal Data entered in the course of the aborted registration is persisted beyond the transient memory of the session. The declaration is accompanied by a truthfulness affirmation; a knowingly false declaration constitutes a breach of the Terms and grounds for immediate termination and deletion under this Article.
7.2 Age-Appropriate Design Although the Services are not offered to minors, the Controller applies the principles of the United Kingdom Age-Appropriate Design Code and comparable frameworks to any interaction with a person it reasonably believes may be a minor: it does not profile such a person, does not serve them targeted or behavioural content, and applies the most privacy-protective settings pending deletion of the account.

Article VIII

Precise Location & Geolocation Protocols

The Services collect precise location information (GPS coordinates) from the User's mobile device in order to provide the most accurate recommendations for the city the User is currently in, to suggest nearby venues (such as clubs, cafés, restaurants and cultural sites), and to ensure that localized content, challenges and rewards are relevant to the User's current physical position. The Controller employs a tiered hierarchy designed to privilege User autonomy and enforce privacy-by-design:

  • Persistent Domicile (Home Base): The User's permanently declared geographic residence, stored in our database to bootstrap recommendations on first launch.
  • Precise Hardware Telemetry (GPS): Subject to explicit, revocable OS-level authorisation. Precise GPS coordinates are read on demand and never silently polled in the background. The User retains the right to revoke this permission at any time through the device's system settings, although revocation may degrade or disable location-dependent features.
  • Ephemeral Session Overrides (Travelling Status): The User may manually declare a temporary location which takes absolute priority over GPS telemetry. Stored in volatile memory only and purged on application termination.
8.0 Foreground-Only Location Access (No Background Tracking) The application requests and declares foreground ("when in use") location permission only. No "always" or background-location entitlement is declared in the iOS application configuration or in the Android manifest, and no background location service, geofence monitor or significant-change listener is registered. Location is read exclusively (i) on demand, in response to a User action, or (ii) through a foreground position watcher that is active only while the relevant screen is visible and is torn down when the application is backgrounded or closed. Accordingly, the Controller is technically incapable of collecting the User's position while the application is not in use.
8.1 Purpose of Precise Location ProcessingThe User's precise location data is used exclusively for the following purposes: (i) automatic detection of the User's current city and surrounding region; (ii) suggestion of nearby venues, events, essentials and points of interest calibrated to real-world proximity, including the calculation and display of the distance between the User and any challenge, essential or recommendation; (iii) batching of challenges by geographic clustering, so that challenges located close to one another are grouped into a single efficient route and the User is not required to travel back and forth across the city; (iv) determination of whether the User should be served home-base challenges (in the User's declared city of residence) or touristic challenges (when the User is travelling); (v) delivery of localized content and reward opportunities, including establishing which rewards, partner offers and trip prizes may lawfully and practically be offered in the User's territory; (vi) operation of poll challenges, where responses are tied to the locality being polled; (vii) challenge synchronisation between friends completing challenges together, to confirm participants are at the same place; (viii) operation of the AR feature, where location acts as a fallback and disambiguation signal when the Google Vision landmark recognition service cannot confidently identify a scanned building or monument; and (ix) operational integrity of the challenge-verification infrastructure, including GPS-verified check-ins confirming that a challenge was genuinely completed at the required location. The Controller does not use precise location data for unsolicited behavioural profiling, cross-context advertising or any purpose beyond the provision and improvement of the Services.
8.2 Camera AccessSubject to explicit, revocable OS-level permission, the device Camera is accessed only while the relevant screen is open and only for: (i) scanning a friend's QR code in order to sync challenges and complete them together; (ii) the AR feature, to scan historical buildings, monuments and landmarks for identification and narration; (iii) challenge verification methods, namely QR-code scanning at a venue or checkpoint and AI Photo verification, where the User takes or uploads a photograph which is analysed to confirm the challenge was completed; and (iv) for business accounts, scanning End-User QR codes to redeem freebies or validate event guest-list tickets. The Camera is never activated in the background and no continuous video stream is recorded or retained.
8.3 Microphone Access Subject to explicit, revocable OS-level permission, the device Microphone is accessed solely for the AI Voice challenge-verification method, in which the User records a short spoken submission that is processed to verify challenge completion. Recording occurs only while the User actively initiates it. The Controller does not perform ambient or background listening.
8.3 bis Photo Library Access Subject to explicit, revocable OS-level permission, the device Photo Library is accessed only when the User chooses to add a photo — for example to a favourite place, to a review, or, for business accounts, to a venue profile or an event listing. Only the specific item selected by the User is read; the Controller does not enumerate, index or background-scan the photo roll, and does not access photographs the User has not expressly chosen.
8.3 ter Operating-System Permission Notices The purpose strings presented by the operating system when permission is requested are as follows, and accurately reflect the Processing described in this Article:

Camera (NSCameraUsageDescription): "Used only while a scanning screen is open — to scan a friend's QR code to sync challenges, to verify a challenge by QR code or AI Photo, to scan landmarks in the AR feature, and, for business accounts, to scan customer reward and guest-list codes. No video is recorded or stored."

Microphone (NSMicrophoneUsageDescription): "Used only when you choose the AI Voice method to verify a challenge — you record a short voice note that is checked and then discarded. The microphone is never accessed in the background."

Photo Library (NSPhotoLibraryUsageDescription): "Used only when you choose to add a photo — for example to a favourite place, a review, or, for business accounts, a venue profile or event listing. Only the photo you select is accessed."

Location (NSLocationWhenInUseUsageDescription): "Used only while the app is open, to show nearby recommendations, events and challenges, to measure distance, and as a fallback for AR landmark scanning. Location is never accessed in the background."

The Application declares foreground ("when in use") location permission only; it does not declare, and contains no code path that exercises, any "always" or background-location capability. Voice notes captured for AI Voice verification are Processed transiently for the sole purpose of verifying the challenge and are discarded immediately thereafter; no audio recording is retained by the Controller.
8.4 Third-Party Reverse Geocoding In order to convert raw GPS coordinates into a human-readable city or region name, the Services may transmit the User's coordinates to third-party geocoding services operated by Apple Inc. and/or Google LLC (the "Geocoding Sub-Processors"). These services receive the User's coordinates solely for the purpose of returning a corresponding locality identifier (city, region or country name). The Geocoding Sub-Processors do not receive the User's personal identity information (such as name, email address, telephone number or account identifier) in connection with this processing, and the Controller does not combine geocoding requests with User-identifying metadata. All geocoding transmissions are conducted over encrypted transport (TLS 1.3) and are subject to the standard contractual clauses or equivalent transfer safeguards set out in Article XII.
8.4 bis Forward Place Search (Autocomplete) & Map Rendering Where the User manually searches for a city, address or place — for example when changing their declared location or selecting a locality during onboarding — the free-text characters typed by the User, together with a randomly generated Google session token, are transmitted to the Google Places API operated by Google LLC in order to return matching place suggestions. Where a map is displayed on Android devices, map tiles and the associated API-key context are requested from the Google Maps SDK / Maps API. Neither request carries the User's name, email address or account identifier. The Controller does not retain the intermediate search strings beyond the lifetime of the search session.
8.5 Data Retention & Location History The Controller uses the User's precise coordinates primarily for real-time city detection and proximity-based feature delivery. The Controller does not maintain a permanent historical log of the User's exact GPS movements, does not construct a longitudinal location history, and does not retain raw coordinate pairs beyond the transient processing window necessary to fulfil the immediate service request. Where coordinates must be retained for operational purposes (for example, to verify a challenge check-in or to resolve a support inquiry), they are stored only for the minimum duration required by the specific use case and are thereafter deleted or irreversibly anonymised in accordance with the retention schedule set out in Article XIII.
8.6 Mandatory Geographic Obfuscation (Fuzzing Protocol) Prior to transmission to backend or Sub-Processors, latitude and longitude are programmatically truncated to a maximum precision of two (2) decimal places (~1.1 km). The User acknowledges that this deliberate degradation is a security measure preventing hyper-accurate tracking.

Article IX

Behavioural Biometrics & Honey-Pots

To preserve infrastructural integrity, the Controller deploys hidden cryptographic honey-pot fields within authentication matrices and records the timing and spatial coordinates of the User's last ten (10) screen interactions. This data is processed locally where possible and cross-referenced with backend heuristics to differentiate bona fide human operation from automated scripts. No biometric template uniquely identifying a natural person within the meaning of Article 9 GDPR is generated, stored or shared.

Article IX bis

Device Biometric Unlock (Face ID / Touch ID / Android Biometrics)

Where the User enables it, the Application uses the biometric authentication mechanism of the operating system — Face ID, Touch ID or the Android biometric prompt — solely as a local gate to unlock the Application or the business console. The biometric comparison is performed entirely by the operating system within the secure hardware of the device. The Controller receives only a pass/fail result and at no time obtains, transmits, stores or has the capacity to reconstruct the User's fingerprint, facial geometry or any other biometric identifier.

Accordingly, no biometric data and no biometric template within the meaning of Article 9(1) GDPR, section 1 of POPIA, Article 30 of the NDPA or comparable provisions is created or Processed by the Controller in connection with this feature. The User may disable biometric unlock at any time in the Application's security settings or in operating-system settings, in which case the Application reverts to passcode or credential authentication.

Article X

Automated Threat Mitigation

The Services are governed by an automated cybersecurity framework designed to protect the platform from denial-of-service, brute-force, sybil and account-takeover incursions.

Detection & Human-Reviewed Enforcement

Detection of security events (e.g. brute-force, root/jailbreak, emulator or man-in-the-middle indicators) is automated. Upon a high-severity event, a server function ( processSecurityAlert) records the event and routes an alert to the Controller's Security Operations Centre. Account-affecting enforcement — revocation of authentication tokens, suspension of account access and addition of a device identifier to a blocklist — is not applied automatically; it is decided and carried out by an authorised member of the Controller's security team through an internal administration console, following review of the underlying signals. This design deliberately keeps a human in the loop before any measure producing legal effects concerning the User is taken.

10.3 Graduated and Non-Disclosed Enforcement In addition to the overt access restriction described in Article X bis, the automated anti-abuse framework may apply graduated measures that are not signalled to the account holder, including request-rate reduction, suppression or non-delivery of outbound one-time codes and messages, and limitation of the visibility of an account's content. Such measures are applied only where necessary to frustrate automated abuse, credential-stuffing, fraud rings, evasion of a prior restriction, or coordinated manipulation of the gamification economy, and are grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in the integrity and security of the Services. They do not of themselves produce legal effects concerning the User. A User who believes an account has been wrongly limited may contact support@blocalapp.com to obtain human review under the service levels set out at Article X bis §Xbis.1, to express their point of view and to contest the measure.

Article X bis

Restricted-Access Notice (Blocked-User Modal)

Where the Controller's security team, acting on the automated alerts described in Article X, determines that an account or device must be subjected to access restriction, the mobile application will render a full-screen, non-dismissible notice (the "Restricted-Access Notice") indicating that the User's access to the Services has been suspended. The notice:

  • does not reveal the specific signals or telemetry that triggered the restriction, in order to preserve the integrity of the anti-fraud system;
  • offers a "Close Application" control which, on Android devices, gracefully terminates the application process;
  • offers a "Contact Support" control which opens a pre-addressed message to support@blocalapp.com and permits the User to lodge an appeal, request human review of the automated decision (Article 22(3) GDPR), or submit a Data Subject Access Request;
  • advises the User of their right to obtain meaningful information about the logic involved, to contest the restriction, and to lodge a complaint with the competent supervisory authority.
Xbis.1 Guaranteed Human Review (GDPR Art. 22(3)) — Internal Service Levels Where an account restriction is imposed by a solely automated decision producing legal effects or similarly significantly affecting the User, the User has the right to obtain human intervention, to express their point of view and to contest the decision. That right is operationally guaranteed, and not merely signposted, by the following documented internal service levels:
  • an appeal received at support@blocalapp.com is logged as a formal Article 22(3) review request and acknowledged within two (2) business days;
  • the file is assigned to a competent member of staff who is not the author of, and has authority to overturn, the automated decision; the reviewer examines the underlying signals, the User's submissions and any exculpatory evidence;
  • a reasoned outcome is communicated to the User within fifteen (15) calendar days of the appeal, extendable once by a further fifteen (15) days for complex cases, with reasons for the extension notified before the initial deadline expires;
  • where the automated decision is not upheld, access is restored and the associated blocklist entries and derived security records are corrected or deleted;
  • every review is recorded (request, reviewer, evidence considered, outcome, date) and the record is retained as evidence of compliance and is available to the Data Protection Officer and, on request, to the AEPD;
  • the Data Protection Officer monitors adherence to these service levels and reviews upheld and overturned decisions periodically in order to correct systematic error in the automated logic.

The Restricted-Access Notice does not, in itself, Process additional Personal Data beyond that which is already held in connection with the User's account.

Article XI

Disclosure to Third Parties & Sub-Processors

The Controller engages the following categories of Sub-Processor under Article 28 GDPR-compliant agreements:

Cloud Hosting

Google Cloud Platform / Firebase (data centres in EU; activated US regions only with SCCs).

Authentication

Firebase Authentication; Apple Sign-In; Google Sign-In.

Geocoding & Reverse Geocoding

Apple Maps Geocoding service and Google Geocoding API, used solely to convert GPS coordinates into city or region names. Coordinate data is transmitted without accompanying personal identity information.

Product Analytics

First-party event analytics (screen views, feature interactions) Processed on the Controller's own infrastructure, and the usage-analytics component of the Sentry integration below. No independent third-party analytics software development kit (including Firebase Analytics or Google Analytics) is initialised in the application. Should any such SDK be introduced in future, this Policy will be updated before deployment. This Processing is carried out on the legitimate-interest basis and subject to the objection right described at Articles VI bis and XIV.

Error Monitoring, Session Replay & In-App Feedback

Functional Software, Inc. / Sentry GmbH (Sentry), processing in the EU (Germany) region. Receives crash and error diagnostics, a sample not exceeding ten per cent (10%) of session replays recorded with all text, input fields, images and vector content masked at source, in-app feedback text voluntarily submitted by the User, and the User's pseudonymous account identifier. Carried out on the legitimate-interest basis described at Article VI bis; the User may object and disable it at any time at Profile → Privacy, whereupon the software development kit is disabled on that device.

Place Search, Mapping & Directions

Google LLC — Google Places API (receives the free-text characters typed by the User when searching for a city or address, together with a randomly generated session token); Google Maps SDK / Maps API (map tile delivery and associated API-key context on Android); and Google Directions API (receives an origin and destination coordinate pair when the User requests walking directions to a venue, challenge, essential or event). None of these services receives the User's name, email address or account identifier.

Landmark Recognition (AR)

Google LLC — Google Cloud Vision API, used by the augmented-reality feature to identify a building, monument or landmark from an image the User has actively captured. The image is transmitted for recognition only, is not retained after the result is returned, is not used for facial identification, and is not accompanied by the User's identity information.

Entitlement & Subscription Management

RevenueCat, Inc., acting as the entitlement and subscription-management processor for mobile in-app purchases. Receives purchase and entitlement identifiers, platform receipts issued by Apple or Google, the pseudonymous account identifier and, where the operating system supplies it, limited device or advertising-identifier metadata. Card data is never transmitted to RevenueCat.

Application Delivery, Over-the-Air Updates & Push Relay

Expo (Expo, Inc. / EAS). Receives Expo push tokens, over-the-air update check-in requests and associated device metadata (platform, application version, runtime version). Push notifications are relayed via Expo's servers before onward delivery to Apple Push Notification service or Firebase Cloud Messaging.

Public IP Resolution

Client IP addresses used for security logging are determined server-side from the request context. Where a legacy client build resolves its own public IP through the third-party endpoint ipify.org (United States), that endpoint receives only an unauthenticated request from the device and no account data; this dependency is being retired in favour of server-side resolution.

Push Notifications

Apple Push Notification service; Firebase Cloud Messaging.

Payments & Subscriptions

Apple In-App Purchase (Apple Media Services) for iOS user subscriptions and Google Play Billing for Android user subscriptions; Stripe, Inc. for business-user payments and subscription lifecycles. Card numbers are handled exclusively by Apple, Google or Stripe and are never stored on the Controller's servers.

Artificial Intelligence

OpenAI, L.L.C., utilized for advanced recommendation generation or content moderation via API. Payloads are transmitted securely and are subject to OpenAI's Zero Data Retention / Non-Training enterprise agreements where applicable.

Transactional & Support Email

Outbound email (verification codes, receipts, challenge outcomes, deletion-request correspondence and support replies) is queued to the Controller's backend and dispatched through the Firebase Extensions 'Trigger Email' mechanism via the Controller's configured transactional email provider (SendGrid / Twilio Inc., or equivalent SMTP provider). The provider receives the recipient email address, message content and delivery metadata, and honours suppression lists. Inbound support correspondence is handled through the Controller's mail provider.

Internal Security Operations Alerting

A private webhook channel (Discord Inc., United States) used exclusively by the Controller's Security Operations team to receive automated alerts in respect of security events (e.g. brute-force, MITM, root/jailbreak detection). Alert payloads are data-minimised: they contain the User's pseudonymised identifier, the event type and timestamp, an internal log reference, and — where relevant — an IP address truncated so that the final octets are masked. They do NOT contain the User's email address, name or device model. Payloads are not used for marketing or profiling and are accessible only to authorised security personnel; the full record (including the unmasked IP where captured server-side) remains within the Controller's own EU-region infrastructure.

Sharing within the Services. When a User connects with friends to synchronise challenges, the Controller discloses only the display name the User has chosen for that friend-group context. Email addresses, telephone numbers and precise location coordinates are not shared with friends.

The Controller does not sell Personal Data, does not share Personal Data for cross-context behavioural advertising within the meaning of CCPA/CPRA, and does not rent Personal Data to data brokers.

Article XI bis

Rate Limiting & Abuse Controls

The Controller applies request rate-limiting across the entirety of its callable backend functions and public HTTP endpoints, including webhooks. The mechanism is implemented by means of short-lived counters keyed, in respect of authenticated calls, on the User's pseudonymous account identifier (UID) and, in respect of unauthenticated calls (including webhook deliveries), on the originating IP address. Where a defined threshold is exceeded within a rolling window, the corresponding request is rejected with an HTTP 429 Too Many Requests status or, for callable functions, an equivalent resource-exhausted error.

The processing of the UID and IP address for this purpose is grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in preventing automated abuse, credential-stuffing, denial-of-service and webhook-replay incidents. Counter records are retained only for the duration of the relevant window and are not used for marketing, profiling or any purpose unrelated to abuse mitigation.

Article XI ter

Business Users as Separate Controllers & Article 28 Data Processing Agreement

Where a business account holder (a venue, restaurant, bar, shop or event promoter — a "Business User") Processes Personal Data of its own staff or customers by means of the Services, the Business User acts as an independent Data Controller in respect of that data and the Controller acts as its Processor within the meaning of Article 4(8) GDPR.

That relationship is governed by a binding Data Processing Agreement ("DPA") satisfying the mandatory content of Article 28(3) GDPR, which the Business User must accept as a condition of onboarding and which is presented as a distinct, separately accepted contractual instrument — not merely as a paragraph of this consumer-facing Policy. The DPA sets out, at minimum: the subject-matter, duration, nature and purpose of the Processing; the categories of Data Subject and of Personal Data; the obligation to Process only on documented instructions; confidentiality undertakings; the technical and organisational security measures applied; the conditions for engaging sub-processors and the general written authorisation regime; assistance with Data Subject rights, security, breach notification and impact assessments; the obligations on deletion or return of data at the end of the relationship; and the audit and information rights of the Business User.

The Business User remains responsible for the lawfulness of the Processing it instructs, for informing its own staff and customers, and for establishing an appropriate legal basis for that Processing. A copy of the DPA accepted by the Business User is retained by the Controller for the duration of the relationship and for the applicable limitation period thereafter.

Article XII

International Data Transfers

Where Personal Data is transferred outside the EEA, UK or other adequacy jurisdiction, the Controller relies upon: (i) European Commission adequacy decisions; (ii) the European Commission's Standard Contractual Clauses (Module 1–4) of 4 June 2021, supplemented by a Transfer Impact Assessment; (iii) the EU-US Data Privacy Framework where the recipient is certified; or (iv) the User's explicit, informed consent under Article 49(1)(a) GDPR. For African Users, equivalent transfer mechanisms under POPIA section 72 and NDPA section 41 are applied.

12.1 Transfer Register. The following table identifies, for each principal Sub-Processor, the jurisdiction in which Processing takes place and the transfer mechanism relied upon:

Sub-Processor Country / Region Transfer Mechanism
Google Cloud Platform / Firebase EU (primary); US where activated SCCs (2021) + EU-US Data Privacy Framework; Transfer Impact Assessment
Sentry (Functional Software, Inc. / Sentry GmbH) EU — Germany No transfer outside the EEA; intra-EEA Processing under Art. 28 GDPR agreement
OpenAI, L.L.C. United States EU-US Data Privacy Framework and/or SCCs, with Zero Data Retention / non-training addendum
Apple Inc. (IAP, Push, Sign-In, Geocoding) United States / EU EU-US Data Privacy Framework; SCCs where applicable
Google LLC (Play Billing, Places, Maps, FCM) United States / EU EU-US Data Privacy Framework; SCCs where applicable
Stripe, Inc. / Stripe Payments Europe Ltd. United States / Ireland (EU) SCCs (2021); EU entity for EEA business Users
RevenueCat, Inc. United States SCCs (2021) + Transfer Impact Assessment
Expo, Inc. (EAS, push relay, OTA updates) United States SCCs (2021) + Transfer Impact Assessment
Discord Inc. (internal security-operations alert channel) United States SCCs (2021) + Transfer Impact Assessment; data-minimised alert payloads only (no email, name or device model; IP truncated)
ipify.org (legacy client IP lookup) United States No personal data of the Controller transmitted; dependency being retired

Article XIII

Retention Periods

Active Account Data

Retained for the duration of the account plus thirty (30) days following deletion request.

Account Deletion (In-App)

Deletion initiated in-app at Profile → Delete Account is executed as an immediate hard deletion of the account and its dependent records, with revocation of all authentication and push tokens. Only a minimal audit record (pseudonymous identifier, timestamp, confirmation of completion) is retained, for twelve (12) months, as evidence of compliance.

Account Deletion Requests (Website)

Requests submitted through the website are retained for the period necessary to verify the requester, perform the deletion and confirm completion, and for an additional statutory period where required by law.

Authentication Logs

Twelve (12) months for security investigation purposes.

Email-Verification & Login Codes (userSecrets)

One-time verification and login passcodes are held only for the short validity window during which they can be used, are invalidated on use or on issue of a replacement, and the record is deleted on successful verification. Unused code records are purged by a scheduled clean-up job. Passcodes are not retained after verification.

Security Incident Records (securityIncidents)

Retained for twenty-four (24) months from the date of the incident, or until the expiry of the limitation period applicable to the specific claim where longer, after which they are automatically purged by a scheduled time-to-live job. No security record is retained indefinitely.

Routine Security Logs

Ordinary session events (for example application open or sign-out) are not recorded as security events. Where a genuine security event is logged, the record identifies the User by pseudonymous account identifier only — email addresses are not stored in security logs — and the originating network address is captured server-side from the request context and truncated (IPv4 to /24; IPv6 to /48) before storage.

Behavioural Biometric Vectors

Maximum ninety (90) days, then irreversibly aggregated.

Transactional & Reward Records

Six (6) years pursuant to Spanish Commercial Code Article 30.

Trip-Award Eligibility Records

Retained for the duration of the relevant award cycle plus seven (7) days, after which unclaimed eligibility is transferred to the next eligible User and the original record is deleted or aggregated.

Event Postings

Automatically deleted one (1) calendar month after the event date or posting date, whichever is later.

Business Scan Logs (Freebies & Guest Lists)

Retained for six (6) months for redemption reconciliation and dispute resolution, then deleted.

Tax-Relevant Records

Statutory minimum under General Tax Law 58/2003.

Marketing Consents

Until withdrawal, plus a record of the withdrawal itself.

Records of Consent & Preference

Records of the granting, amendment and withdrawal of consent, and of the User's current diagnostics/analytics preference (Article VI ter), are retained for the life of the account and for three (3) years following its closure, as evidence of compliance with Article 7(1) GDPR and the accountability principle.

Article 22(3) Human-Review Records

Appeal files and review outcomes are retained for twenty-four (24) months from the date of the decision.

13.1 Automated Enforcement of Retention Limits The retention periods set out above are not applied on a discretionary basis. They are enforced by scheduled server-side deletion jobs which run at least daily and which irreversibly delete, or irreversibly aggregate, records that have passed their cut-off. Automated purges are configured for, at minimum: security_logs, securityIncidents, redemptions (business scan logs), viewLogs (venue and event view telemetry), userSecrets (unused verification/login codes), behavioural biometric vectors, event postings, trip-award eligibility records and expired access blocks. Each job is idempotent, is monitored for successful completion, and writes an execution record which the Data Protection Officer reviews. Where a record must exceptionally be preserved beyond its ordinary period (for example because it is subject to a legal hold, an ongoing investigation or a pending claim), the preservation is documented, is limited to what is strictly necessary, and terminates automatically on expiry of the hold.

Article XIV

Rights of EU/EEA & UK Data Subjects

Pursuant to Articles 15–22 GDPR and the UK GDPR, the User is entitled to exercise:

  • The right of access to their Personal Data;
  • The right to rectification of inaccurate or incomplete data;
  • The right to erasure ("right to be forgotten");
  • The right to restriction of Processing;
  • The right to data portability in a structured, commonly-used, machine-readable format;
  • The right to object to Processing based on legitimate interest;
  • The right not to be subject to solely automated decisions producing legal effects;
  • The right to withdraw consent at any time without retroactive effect;
  • The right to lodge a complaint with the competent supervisory authority — in Spain, the Agencia Española de Protección de Datos ( www.aepd.es ).

Exercise of the right to erasure. Deletion is available by two routes: (i) in-app, at Profile → Delete Account, which upon confirmation performs an immediate hard deletion of the User's account and its dependent records and revokes all authentication sessions and push tokens; and (ii)through the website, by submitting a deletion request which is verified and actioned by the Controller. In both cases, a backend routine triggered on account deletion removes the User's primary profile and business documents together with their subcollections and propagates the erasure to records derived from or referencing the account elsewhere in the database — including reviews, view and save logs, challenge-completion logs, reward-purchase and manual-redemption records, favourite-place entries, security-event logs, submitted reports, deletion-request and application records, server-side verification secrets, and rate-limiting counters. Only a minimal request and audit record is retained for compliance purposes as set out at Article XIII.

Requests are honoured free of charge within thirty (30) calendar days, extendable by sixty (60) days where necessary.

Article XV

United States — CCPA / CPRA & State Privacy Laws

California residents enjoy, in addition to the rights enumerated above: (a) the right to know the categories and specific pieces of Personal Information collected; (b) the right to delete Personal Information; (c) the right to correct inaccurate Personal Information; (d) the right to opt-out of the sale or sharing of Personal Information (the Controller does neither); (e) the right to limit use of Sensitive Personal Information; and (f) the right to non-discrimination for exercising these rights.

15.1 Other US State Laws. Equivalent rights are extended to residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana and Kentucky, and to residents of other US States as their respective comprehensive privacy statutes enter into force.

15.2 Opt-Out Preference Signals. The Controller honours the Global Privacy Control (GPC) and comparable browser or device opt-out preference signals as a valid request to opt out of sale or sharing in jurisdictions that so require.

15.3 Consumer Health Data. The Controller does not knowingly collect "consumer health data" within the meaning of the Washington My Health My Data Act, the Nevada consumer-health-data law or the Connecticut amendments, does not derive health inferences from dietary preferences or venue activity for any purpose beyond filtering content at the User's request, and does not sell any such data.

15.4 Nevada. Nevada residents may direct the Controller not to make any covered sale of their covered information by contacting dpo@blocalapp.com; the Controller does not engage in such sales.

15.5 Shine the Light (Cal. Civ. Code §1798.83). The Controller does not disclose Personal Information to third parties for those third parties' own direct-marketing purposes.

Article XV bis

Brazil, Canada & Other Americas

Brazil (LGPD — Lei 13.709/2018): Users may exercise the rights set out in Articles 17 to 22 LGPD, including confirmation of Processing, access, correction, anonymisation or deletion, portability, information about sharing, and revocation of consent, and may petition the Autoridade Nacional de Proteção de Dados (ANPD). The legal bases relied upon correspond to those in Article VI of this Policy.

Canada (PIPEDA & Québec Law 25): Users may withdraw consent (subject to legal or contractual restrictions), access and correct their Personal Information, request portability, and complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec. The Controller reports data breaches presenting a real risk of significant harm as required by those laws.

Article XVI

African Jurisdictions — POPIA, NDPA & Equivalents

South Africa (POPIA): Users are entitled to the rights set out in sections 23–25 of POPIA and may lodge complaints with the Information Regulator ( inforegulator.org.za ).

Nigeria (NDPA 2023): Users may exercise rights under sections 34–37 of the NDPA and refer complaints to the Nigeria Data Protection Commission.

Kenya (DPA 2019): Users may exercise rights under Part V of the Kenya Data Protection Act and refer complaints to the Office of the Data Protection Commissioner.

Ghana (Data Protection Act 843/2012): Users may exercise rights before the Data Protection Commission. Other African Jurisdictions: equivalent protections under the data-protection laws of Uganda, Rwanda, Tanzania, Zambia, Zimbabwe and Angola, under Egyptian Law 151/2020 and Moroccan Law 09-08, and under the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) are honoured where applicable.

Article XVI bis

Asia-Pacific & Middle East

The Controller gives effect to the substance of the following regimes for Users to whom they apply, and Users may in each case complain to the named authority:

Singapore (PDPA)

Consent, purpose-limitation, access and correction rights and data-breach notification to the Personal Data Protection Commission; the Do Not Call provisions are honoured for marketing.

India (Digital Personal Data Protection Act 2023)

Notice-and-consent, the rights of access, correction, erasure and grievance redress of a Data Principal, and referral to the Data Protection Board of India.

Japan (APPI)

Opt-in for third-party provision and for cross-border transfer, disclosure and correction rights, and referral to the Personal Information Protection Commission.

South Korea (PIPA)

Separate consent per purpose, strict consent for cross-border transfer, and referral to the Personal Information Protection Commission.

Australia (Privacy Act 1988 / APPs)

Australian Privacy Principle 8 accountability for overseas disclosures and notification of eligible data breaches to the Office of the Australian Information Commissioner.

United Arab Emirates (PDPL, Federal Decree-Law 45/2021) & Saudi Arabia (PDPL)

Consent, transfer restrictions and data-subject rights before the UAE Data Office and the Saudi Data & AI Authority (SDAIA) respectively.

China (PIPL)

The Controller does not target the Services at, or offer them within, mainland China. Where the PIPL nonetheless applies, the Controller will obtain separate consent, carry out a personal-information protection impact assessment, appoint a local representative, and use a lawful cross-border transfer mechanism before commencing the relevant Processing.

Article XVI ter

Other Jurisdictions & Interaction with Local Law

This Policy is intended to meet the substance of the principal data-protection regimes worldwide, including (without limitation) the GDPR and UK GDPR; the Spanish LOPDGDD; the Swiss FADP; the California CCPA/CPRA and the comprehensive privacy statutes of other United States States as they enter force; the Brazilian LGPD; the Canadian PIPEDA and Québec Law 25; the South African POPIA; the Nigerian NDPA; the Kenyan DPA; the Ghanaian Data Protection Act; the Singapore PDPA; the Indian Digital Personal Data Protection Act 2023; the Japanese APPI; the South Korean PIPA; the Australian Privacy Act; and the UAE and Saudi PDPLs.

Where the mandatory law of the User's jurisdiction affords the User a right, a protection or a remedy that is greater than, or additional to, those set out in this Policy, that mandatory law prevails to the extent of the difference, and nothing in this Policy shall be read as a waiver of it. Where such law requires the designation of a local representative, the registration of a data-processing activity, a specific cross-border transfer mechanism, or a distinct form of consent, the Controller undertakes to put that measure in place before, or upon, commencing the relevant Processing in that jurisdiction. Complaints may in every case be addressed to the Controller at dpo@blocalapp.com and, in addition, to the User's local supervisory or data-protection authority.

Article XVII

Technical & Organisational Security Measures

The Controller has implemented appropriate measures pursuant to Article 32 GDPR, including:

  • AES-256 encryption at rest;
  • TLS 1.3 encryption in transit, with HSTS preloading;
  • Managed identity-provider credential hashing with per-user salt; the Controller never receives or stores plaintext passwords;
  • One-time verification codes (login, PIN reset, redemption codes) generated with a cryptographically secure random number generator and stored only as a one-way SHA-256 digest, with short expiry, attempt limits and per-account rate limiting;
  • Behavioural PIN stored solely as a SHA-256 digest computed on-device;
  • Encrypted (AES-256) storage of push-notification tokens;
  • Database access rules enforcing per-record ownership: a User's profile document is readable only by that User (and authorised staff) and cannot be enumerated; review authorship is bound to the authenticated account; aggregate configuration is writable by administrators only;
  • Media uploads restricted to image content types and a maximum size of 8 MB;
  • Operational security alerts to the internal SOC channel are data-minimised and exclude email addresses and device identifiers (see Articles XI and XII); account-affecting enforcement is subject to human review (Article X);
  • Role-based access control with least-privilege provisioning;
  • Server-side per-identifier and per-IP rate limiting on sensitive endpoints;
  • Stripe and RevenueCat webhooks verified by cryptographic signature / bearer secret before processing;
  • Periodic penetration testing and continuous vulnerability & dependency monitoring;
  • Documented Incident Response Plan and Business Continuity Plan;
  • Mandatory data protection training for all personnel.

Article XVIII

Personal Data Breach Notification

In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of natural persons, the Controller shall notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, affected Users shall be notified directly without undue delay pursuant to Article 34 GDPR.

Article XIX

Cookies, Local Storage & SDK Trackers

The mobile application does not employ HTTP cookies in the traditional browser sense, but does utilise functionally-equivalent persistent local storage, secure keychain entries, and SDK identifiers. Specifically, the Application stores authentication tokens locally using AsyncStorage (to safely persist Firebase credentials across app launches) and tracks application session state using a unique session ID persisted in the OS-level encrypted SecureStore. The local storage and identifiers used by the Application fall into two classes. Strictly-necessary storage — authentication tokens, session identifiers, the on-device city catalogue (Article XIX quinquies), and the preference and saved-item caches (Article XIX ter) — is used without consent because it is required to deliver a service the User has requested. Non-essential storage and processing — namely the diagnostics, error-monitoring and session-replay integration (Article VI bis) and any marketing tracker — is operated on the legitimate-interest basis and may be switched off by the User at any time at Profile → Privacy; any marketing tracker is activated only following the User's opt-in. Where Article 5(3) of Directive 2002/58/EC ("ePrivacy"), as transposed by Spanish Law 34/2002 (LSSI) or by the law of the User's Member State, requires prior consent for a given item, the Controller relies on consent for that item as described in Article VI bis §6bis.4.

Article XIX bis

On-Device Content Personalisation Cache ("Unseen First")

In furtherance of the principles of data minimisation (Article 5(1)(c) GDPR) and privacy-by-design (Article 25 GDPR), the Services implement a client-side personalisation mechanism, colloquially denominated the "Unseen First" logic, which operates exclusively within the local storage environment of the User's handset and does not entail any additional server-side Processing of Personal Data.

19bis.1 Technical Architecture The mobile application maintains two discrete registers within the device's native asynchronous key-value store (AsyncStorage): one enumerating the identifiers of recommendations previously rendered on-screen, and a second enumerating the identifiers of events previously rendered on-screen. Each register is capped at one thousand (1,000) entries on a first-in-first-out basis to preserve device performance and storage economy.

19bis.2 Operational Logic. Upon each fetch operation, the application partitions the candidate content set into "unseen" and "seen" sub-collections, randomises the ordering within each sub-collection, and concatenates them such that previously-unviewed items are prioritised in the User's feed. Where the locally-cached content set is composed entirely of previously-seen identifiers, the fifteen (15) minute in-memory cache is bypassed and a fresh request is dispatched to the backend in order to surface novel content.

19bis.3 Data Locality & Non-Transmission. The identifiers comprising the Unseen First register are never transmitted to, persisted by, or otherwise made available to the Controller's backend infrastructure, Sub-Processors or any third party. They remain at all times under the exclusive custody of the User's device and outside the technical reach of the Controller.

19bis.4 User Control & Erasure. The User may, at any time and without justification, extinguish the Unseen First register by (i) clearing the application's local data through the operating system settings; (ii) uninstalling the application; or (iii) invoking the in-app "Clear Cache" functionality where exposed. Such action will reset the personalisation logic and cause previously-viewed content to be eligible for re-surfacing.

19bis.5 Backend Performance OptimisationIn parallel, the backend bundle-generation routine (generateCityBundle) executes the underlying Firestore queries concurrently by means of Promise.all(), thereby reducing latency and the energy footprint of each request. This optimisation alters neither the categories of Personal Data Processed nor the lawful bases enumerated in Article VI.

19bis.6 Lawful Basis. To the extent that the Unseen First register constitutes Processing within the meaning of Article 4(2) GDPR, such Processing is grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in providing a non-repetitive, content-fresh User experience, which interest is not overridden by the rights and freedoms of the User given the strictly on-device, pseudonymous and User-controllable nature of the mechanism.

Article XIX ter

Local Caches, Persistent Preferences & Batched Telemetry

In furtherance of data minimisation, performance and battery-economy objectives, the mobile application maintains a series of additional local caches within the device's persistent key-value store (AsyncStorage), orchestrated by a client-side state-management layer (Zustand). These caches operate as a read-through copy of data that already lawfully resides within the User's account and do not give rise to any new category of Personal Data.

19ter.1 User Preferences Cache

Locally mirrors the User's declared dietary preferences, vibe preferences, language, notification toggles and 2FA settings, synchronised from Firestore via a single background snapshot listener attached to the User's own document.

19ter.2 Cities Cache

Locally mirrors the publicly-available list of cities for which the Services are activated; refreshed automatically every twenty-four (24) hours.

19ter.3 Saved-Items Cache

Locally mirrors the identifiers of recommendations and events that the User has personally bookmarked, so that bookmark indicators can be rendered without re-querying the backend on every screen.

19ter.4 Batched Analytics Writes. View-count and save-count telemetry generated by the User's interactions (e.g. viewing a venue or event) is buffered on the device and dispatched to the backend in atomic batches once a small threshold of events is reached. The pending-event buffer is written to the device's persistent key-value store so that events survive application termination; each buffered entry comprises the event type, the identifier of the venue or event concerned, a timestamp and the User's pseudonymous account identifier. Buffered entries are cleared once transmitted, and on sign-out or cache purge. Each underlying view is still recorded individually server-side so that dashboard accuracy is preserved; only the network-transport layer is optimised.

19ter.5 User Control. The User may extinguish any of the above caches at any time by clearing the application's local data, uninstalling the application, or signing out, which triggers a programmatic reset of the local stores.

Article XIX quinquies

On-Device City Catalogue Cache & Offline Availability

19quinquies.1 Purpose and ContentTo reduce latency, data usage and battery consumption, and to permit limited offline browsing, the Application stores on the User's device a copy of the public content catalogue for the single city the User is currently viewing (the "City Catalogue"). The City Catalogue comprises non-personal operational data only: venue and point-of-interest listings, localised events, challenge definitions, reward definitions and travel-essentials entries for that city. It contains no User account data, no User-generated content and no identifiers of the User.
19quinquies.2 Storage Mechanism The City Catalogue is retrieved as a single pre-generated file from the Controller's content-delivery storage and is held in the Application's private asynchronous key-value store ( AsyncStorage) within the operating-system sandbox allocated to the Application. Only one city's Catalogue is retained at a time; selecting a different city replaces the previously stored Catalogue in its entirety. The Application does not maintain a multi-city or multi-region store, does not impose a fixed storage budget, and does not run a least-recently-used eviction routine.
19quinquies.3 Refresh and ExpiryThe Application checks the catalogue version for the active city no more than once every five (5) minutes and forces a refresh where the stored copy is more than twenty-four (24) hours old. A superseded Catalogue is discarded on refresh.
19quinquies.4 User ControlThe User may erase the stored City Catalogue at any time by signing out, by clearing the Application's storage in operating-system settings, or by uninstalling the Application. Erasure resets offline availability and has no effect on the User's account or on any server-side record.
19quinquies.5 Lawful BasisTo the extent the storage of non-personal operational data on the device constitutes Processing, it is grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in providing a performant and partially offline-capable service, an interest not overridden by the User's interests given the strictly non-personal, single-city and User-erasable nature of the cache. Where local law treats the storage of information on terminal equipment as requiring consent (Article 5(3) of Directive 2002/58/EC), such storage is strictly necessary for the delivery of the content-browsing service the User has requested and falls within the exemption for that purpose.

Article XX

Direct Marketing Communications

Direct marketing communications are dispatched only following the User's explicit, freely given, specific, informed and unambiguous opt-in. Each communication includes a one-click unsubscribe mechanism in conformity with Article 21(3) GDPR and Article 22 LSSI. Withdrawal of consent does not affect the lawfulness of Processing prior to such withdrawal.

Article XX bis

Partner Promotions & Advertising

20bis.1 Contextual Advertising

To help provide the User with the best local recommendations, the Application may display promotional content, partner offers and advertisements (such as ride-sharing discounts or travel services). The Controller operates a strictly contextual advertising system: the advertisements displayed are determined solely by the User's current activity within the Application — namely the specific City or Continent then being viewed.

20bis.2 No Cross-App Tracking Profile

The Controller does not combine the User's activity across other companies' applications or websites into an advertising profile, does not present an App Tracking Transparency prompt, does not access the User's Identifier for Advertisers (IDFA) or Android Advertising ID within the Application, and does not share any such identifier with data brokers. The Application does not embed a third-party advertising or behavioural-tracking software development kit.

20bis.3 Data Sharing with Partners

When the User views an advertisement within the Application, the Controller does not share personal identifying information — including name, email address, telephone number or precise GPS coordinates — with the third-party advertiser.

20bis.4 Third-Party Links

Should the User elect to click a promotional offer or advertisement, the User may be redirected to a third-party website or application (for example, the Uber or Airalo app). Once the User leaves the Application, their interactions are governed by the privacy policies and terms of service of those third parties. The Controller encourages the User to review such policies before completing any transaction.

20bis.5 Install Attribution (SKAdNetwork / Privacy Sandbox)

The Controller advertises the Application on third-party platforms and measures the effectiveness of that advertising by means of the privacy-preserving, on-platform attribution frameworks provided by Apple (SKAdNetwork / AdAttributionKit) and Google (Privacy Sandbox Attribution). These frameworks return to the Controller only aggregated, delayed and noise-injected conversion signals. They do not transmit to the Controller the User's identity, the User's advertising identifier, or the User's activity in other applications, and the Controller does not receive or assemble a cross-context advertising profile from them. Where an advertising platform (for example a social or video network on which the Application is promoted) carries out its own attribution, that Processing is carried out by that platform as an independent controller under its own policies; the Controller does not embed that platform's tracking software development kit in the Application. If the Controller introduces such a software development kit in future, it will update this Policy and the applicable app-store privacy disclosures, and will obtain consent where required, before deployment.

Article XXI

Automated Decision-Making & Artificial Intelligence

The Controller employs algorithmic systems and Artificial Intelligence (AI) for fraud scoring, recommendation generation and eligibility validation in the gamification framework. AI is additionally used for challenge verification through three methods — AI Photo (analysis of a photograph taken or uploaded by the User to confirm the challenge was performed), AI Voice (analysis of a short voice recording captured via the device Microphone) and AI Answer (evaluation of a written response submitted by the User) — and for generating the historical and factual narration presented in the AR feature once a building, monument or landmark has been scanned. Media submitted for verification is processed for that purpose only, is not used to train third-party foundation models, and is retained in accordance with Article IX. Decisions producing legal effects or significantly affecting the User (notably, the Auto-Kill protocol) are subject to human review on request. The User is entitled to obtain meaningful information about the logic involved, as well as the significance and envisaged consequences of such Processing, pursuant to Article 22 GDPR. The Controller commits to compliance with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) as its provisions enter into force.

Article XXI bis

How Recommendations, Events & Challenges Are Ordered

The order in which venues, events and challenges appear to the User is determined by a combination of the following main parameters:

  • proximity to the User's current or selected location;
  • the dietary preferences and atmosphere ("vibe") preferences the User has declared, and the categories the User has chosen for the navigation bar;
  • whether the item has already been shown to the User on the current device — previously-unseen items are prioritised (Article XIX bis);
  • how recently the item was created or updated;
  • aggregate popularity, save-count and average rating on the Services;
  • whether the venue is currently open, based on its published opening hours and the device's local time.

The User can influence this ordering by changing their declared preferences, their location and their category selections, and by hiding individual venues. Ordering is not based on any payment by a venue or event organiser for placement or prominence, and there is no paid ranking. A separate, disclosed fee may be charged to a business for the right to publish an event listing, but that fee does not affect the position of the listing relative to other content.

Article XXII

Limitation of Liability

22.1 Inherent Fallibility. Notwithstanding the implementation of AES-256 encryption, TLS transit protocols and automated threat frameworks, the User acknowledges that no digital architecture is wholly impervious to zero-day exploits or cyber-kinetic events.

22.2 Maximum Cap. To the maximum extent permissible under applicable mandatory law, and without prejudice to non-waivable consumer rights, the Controller's cumulative liability arising out of or in connection with this Policy shall be capped at the greater of (i) the total consideration paid by the User to the Controller in the twelve (12) months preceding the event giving rise to liability, or (ii) Fifty Euros (€50.00).

Article XXIII

Amendments to this Policy

The Controller reserves the right to amend, alter or supplement this Policy at any time. Material amendments shall be communicated via in-app notification at least thirty (30) days prior to entry into force. Continued use of the Services following such notice constitutes binding ratification of the revised instrument.

Article XXIV

Governing Law & Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of the Kingdom of Spain. The Courts of Barcelona shall have exclusive jurisdiction over any dispute arising from or in connection with this Policy, without prejudice to the User's non-waivable right to bring proceedings in the courts of their place of residence pursuant to Regulation (EU) 1215/2012 (Brussels I bis) or equivalent local consumer protection statutes.

Article XXV

Contact & Complaints

Privacy & Data Protection Enquiries: support@blocalapp.com

Postal Address: BL PLATFORM S.L., Barcelona, Spain

Spanish supervisory authority — Agencia Española de Protección de Datos: www.aepd.es

Annex I

Register of Processing Activities (GDPR Art. 30)

This Annex I is incorporated into, and forms an integral and operative part of, this Policy. It constitutes the Controller's record of processing activities maintained pursuant to Article 30 of Regulation (EU) 2016/679 ("GDPR") and, so far as applicable, section 17 of the Protection of Personal Information Act 4 of 2013 (South Africa) and section 39 of the Nigeria Data Protection Act 2023. It is published in the interests of transparency under Articles 12, 13 and 14 GDPR and is intended to furnish the Data Subject with an exhaustive, module-by-module description of (i) the categories of personal data processed, (ii) the operations performed upon such data, (iii) the determinate purposes served, (iv) the statutory basis relied upon, and (v) the applicable conservation period.

Where any provision of this Annex conflicts with the body of the Policy, the provision affording the Data Subject the greater degree of protection shall prevail. Defined terms bear the meanings ascribed to them in Article I. References to "AsyncStorage", "Firestore", "Firebase Auth", "RevenueCat", "Stripe", the transactional email provider, "Expo", "Google Cloud Vision" and "OpenAI" are references to the technical components and sub-processors identified in Articles XI and XII, whose engagement is governed by written data processing agreements incorporating the Standard Contractual Clauses where required.

A · Account Constitution, Onboarding & Profile Configuration

Processing operations undertaken during the constitution of a User account and the elicitation of the declarative preferences upon which the personalisation layer of the App is predicated.

Age Attestation & Terms Assent

Categories of data.
Declared age, timestamp of assent to the Terms and Conditions, and the boolean state of the honesty attestation control.
Processing operations.
Persisted to the publicUsers collection keyed to the authenticated UID under the fields 'age' and 'termsAcceptedAt'.
Determinate purpose.
To enforce the minimum age eligibility threshold governing access to the App and to constitute durable, time-stamped evidence that the Terms were accepted at a determinate moment.
Lawful basis.
Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (compliance with age-verification and record-keeping obligations); Art. 7(1) GDPR (demonstrability of consent).
Conservation.
Duration of the account plus the applicable limitation period for contractual claims.

Electronic Mail Verification (One-Time Passcode)

Categories of data.
Electronic mail address; six-digit one-time passcode; verification status flag.
Processing operations.
The address is transmitted to the 'requestOtp' Cloud Function, which dispatches the passcode by electronic mail; the passcode submitted by the User is validated by the 'verifyOtp' Cloud Function, whereupon 'isEmailVerified' is set to true. The passcode record is held only for the short window during which the code can be used and is subject to a dispatch throttle and a failed-attempt lock-out.
Determinate purpose.
To authenticate control of the declared mailbox, to prevent the enrolment of fictitious identities, and to establish a reliable channel for service and security communications.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (legitimate interest in account security).
Conservation.
The passcode record is deleted on successful verification and is invalidated on issue of a replacement; unused records are removed by a scheduled clean-up job. The verification flag is retained for the life of the account.

Dietary Preference Elicitation

Categories of data.
Declared dietary orientation (vegan, vegetarian, halal, pescatarian, gluten-free, or none).
Processing operations.
Recorded in the 'foodPreference' field of the publicUsers document and applied as an automatic filtration predicate over the recommendation corpus.
Determinate purpose.
To tailor recommendations to the User's declared dietary requirements.
Lawful basis.
Art. 6(1)(a) GDPR (consent). The Controller does not solicit, and does not infer, religious or philosophical conviction from such declaration; the datum is treated as a culinary filter only and is not processed as a special category of data under Art. 9 GDPR.
Conservation.
Until amended or erased by the User, or until account closure.

Aesthetic ('Vibe') Preference Elicitation

Categories of data.
Array of declared atmospheric preferences (e.g. modern, vintage, chill).
Processing operations.
Stored in the 'vibePreference' field of the publicUsers document and mirrored to on-device AsyncStorage for immediate application at cold start.
Determinate purpose.
To personalise the ordering and presentation of the recommendation feed.
Lawful basis.
Art. 6(1)(a) GDPR (consent).
Conservation.
Until amended or erased by the User; local mirror cleared upon uninstallation or cache purge.

Locale, Base Territory & Referral Attribution

Categories of data.
Language code; base country and ISO country code; base city and city identifier; centroid coordinates of the selected city; optional referral code.
Processing operations.
Written to publicUsers as 'language', 'baseCountry', 'baseCountryCode', 'baseCity', 'baseCityId', 'baseCityLat', 'baseCityLng' and, where supplied, 'referredByCode'; the application locale is reconfigured accordingly.
Determinate purpose.
To localise the interface, to fix the territorial frame of reference for local content, and to attribute referrals within the invitation programme.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(a) GDPR in respect of referral attribution.
Conservation.
Duration of the account.

Navigation Bar Curation

Categories of data.
Up to six supplementary category selections (e.g. beaches, shopping, clubs).
Processing operations.
Persisted as the 'navbarCategories' array on the publicUsers document.
Determinate purpose.
To permit the User to curate the primary navigation surface of the App.
Lawful basis.
Art. 6(1)(a) GDPR (consent).
Conservation.
Until amended or erased by the User.

Onboarding Progression Flags

Categories of data.
Boolean completion markers ('@hasOnboarded', 'onboardingComplete', 'isNewUser') and tutorial-seen keys.
Processing operations.
Held in device-local AsyncStorage and, where relevant to server-side routing, on the publicUsers document.
Determinate purpose.
To sequence the first-run experience and to suppress the repetition of instructional overlays.
Lawful basis.
Art. 6(1)(f) GDPR (legitimate interest in coherent user experience).
Conservation.
Until uninstallation, cache purge or account closure.

B · Authentication, Session Integrity & Anti-Fraud Controls

Operations directed to the establishment and preservation of authenticated sessions and to the detection and suppression of automated, fraudulent or otherwise illegitimate access.

Credential Authentication & Federated Sign-In

Categories of data.
Electronic mail address; password (transmitted to, and held exclusively by, the identity provider in salted and hashed form); forename and surname; identity-provider payloads emitted by Apple and Google; session identifiers and provider metadata.
Processing operations.
Credentials are surrendered directly to Firebase Authentication; the resulting profile is materialised in the publicUsers collection. Federated tokens are parsed and refreshed by the authentication utilities. The Controller does not at any time receive, store or have the capacity to reconstruct a plaintext password.
Determinate purpose.
To authenticate the User, to constitute the account, and to maintain session continuity.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (security of processing, Art. 32 GDPR).
Conservation.
Duration of the account; session artefacts expire upon revocation, logout or token expiry.

Behavioural Biometrics & Honey-Pot Instrumentation

Categories of data.
Touch coordinates and inter-event timings; interaction cadence; values entered into concealed decoy fields.
Processing operations.
Interaction telemetry is evaluated heuristically at the point of authentication; anomalous cadence or any completion of a decoy field causes a security event to be recorded by way of the 'logSecurityEvent' routine.
Determinate purpose.
To distinguish human interaction from scripted or emulated interaction and thereby to defeat credential stuffing, enumeration and brute-force attack.
Lawful basis.
Art. 6(1)(f) GDPR (overriding legitimate interest in the integrity of the Service). Such telemetry is not used for unique identification of a natural person and accordingly does not constitute biometric data within Art. 9(1) GDPR.
Conservation.
Ephemeral in the ordinary case; security events retained for the audit period specified in Article XIII.

Two-Step Verification & Session Stamping

Categories of data.
Six-digit login passcode; session metadata.
Processing operations.
The passcode is validated server-side by the 'verifyOtp' Cloud Function; upon validation a new session is stamped by the 'stampNewSession' routine and prior sessions may be invalidated.
Determinate purpose.
To impose a second authentication factor and to enforce concurrency limits upon sessions.
Lawful basis.
Art. 6(1)(f) GDPR; Art. 32 GDPR.
Conservation.
Passcodes expire on use; session records retained until expiry or revocation.

Device Request Fingerprinting

Categories of data.
Operating system version, device model, coarse hardware and software characteristics, request timestamp.
Processing operations.
Reduced to a one-way hashed signature by the RequestFingerprint utility and appended to privileged requests.
Determinate purpose.
To detect emulation, request forgery and application-programming-interface abuse, and to attribute abusive traffic without recourse to direct identifiers.
Lawful basis.
Art. 6(1)(f) GDPR (fraud prevention, expressly recognised at Recital 47 GDPR).
Conservation.
Retained in the security audit trail for the period specified in Article XIII.

Security Event Logging & Restricted-Access Enforcement

Categories of data.
Contextual usage data, warning classifications, network address context, authentication failure counts.
Processing operations.
Structured events are dispatched by the SecurityLogger to the security_logs collection and processed server-side ('processSecurityAlert', 'processSecurityLogs'); where thresholds are exceeded, access is restricted and the restricted-access notice described at Article X bis is displayed.
Determinate purpose.
To constitute an audit trail, to detect malicious conduct, and to interdict abusive accounts.
Lawful basis.
Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR where retention is required to evidence compliance.
Conservation.
As specified in Article XIII; network addresses are truncated or masked where full retention is unnecessary.

Business Console Personal Identification Number

Categories of data.
Four-digit PIN (stored solely as a SHA-256 digest), 'pinEnabled' flag, PIN reset code and expiry, application lock state.
Processing operations.
The PIN is hashed on device by way of expo-crypto and only the digest is persisted to the business document. Inactivity exceeding five minutes places the console in a locked state. Reset codes are dispatched to the registered business mailbox and validated against Firestore, whereupon the digest is cleared.
Determinate purpose.
To prevent unauthorised access to the console by staff or third parties during a shift and to secure the device when unattended.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR; Art. 32 GDPR.
Conservation.
Digest retained while the PIN feature is enabled; reset codes expire upon use or lapse.

C · Geolocation, Proximity Computation & Territorial Logic

Operations involving precise or approximate geospatial data, processed strictly upon the granular permissions described at Article VIII and revocable at any time through the location-sharing settings of the App or of the operating system.

Foreground Location Acquisition

Categories of data.
Device latitude, longitude and fix timestamp; 'isLocationShared' flag; manually selected city coordinates in the alternative.
Processing operations.
Operating-system permission is solicited; where granted, a fix is obtained and written to the 'location' object of the publicUsers document. Where permission is withheld, the manually selected base city is substituted and no satellite-derived datum is processed.
Determinate purpose.
To surface proximate recommendations, essentials, events, challenges and rewards.
Lawful basis.
Art. 6(1)(a) GDPR (explicit, revocable consent at operating-system level).
Conservation.
Most recent fix only; superseded upon each subsequent acquisition and erased upon withdrawal of permission.

Distance, Routing & Challenge Batching

Categories of data.
User coordinates and target coordinates.
Processing operations.
Haversine and geospatial computations are performed by the location utilities to render distances and to batch challenges into geographically coherent itineraries; coordinate pairs are transmitted to external routing interfaces for walking directions and deep-linked to the User's native mapping application on request.
Determinate purpose.
To display distance, to spare the User unnecessary traversal of the city, and to furnish navigation to challenges, essentials, recommendations and events.
Lawful basis.
Art. 6(1)(a) GDPR; Art. 6(1)(b) GDPR in respect of features expressly invoked by the User.
Conservation.
Transient; coordinates are not retained by the Controller following computation.

Session City versus Physical Position

Categories of data.
Active city identifier maintained separately from the physical positional fix.
Processing operations.
The location store maintains the distinction between the territory the User is physically within and the territory the User has elected to browse.
Determinate purpose.
To permit exploratory or 'tourist' browsing of another city without the positional fix overriding the User's election.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Session-scoped; cached locally for continuity.

Challenge Verification, Polls, Syncing & Reward Eligibility

Categories of data.
Positional fix at the moment of verification; territorial eligibility determinations.
Processing operations.
The fix is compared server-side against the geofence of the challenge, poll or synchronisation event and against the territorial scope of available rewards.
Determinate purpose.
To verify that a real-world task was in fact performed at the requisite location, to prevent fraudulent accrual of points, and to determine which rewards may lawfully and commercially be offered.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (integrity of the gamification economy).
Conservation.
Verification outcome retained; the underlying coordinate is discarded once the determination is made.

Landmark Proximity & Augmented Reality Fallback

Categories of data.
Positional fix; landmark corpus.
Processing operations.
Proximity to catalogued landmarks is computed and used as a fallback identification heuristic where the machine-vision service is unable to identify the landmark from the image supplied.
Determinate purpose.
To furnish contextual and educational information concerning points of interest.
Lawful basis.
Art. 6(1)(a) GDPR; Art. 6(1)(f) GDPR.
Conservation.
Transient.

D · Discovery, User-Generated Content & Community Moderation

Operations concerning the discovery corpus and content voluntarily contributed by Users, including reviews, reports and content-suppression elections.

Reviews & Ratings

Categories of data.
Star rating, free-text narrative, author identifier and display name, venue or event identifier, timestamp.
Processing operations.
Written to the reviews subcollection under the relevant city, venue or event and rendered publicly within the App.
Determinate purpose.
To crowdsource qualitative assessment of venues and events for the benefit of other Users and of the venue.
Lawful basis.
Art. 6(1)(a) GDPR (voluntary publication) and Art. 6(1)(b) GDPR.
Conservation.
Until withdrawn by the author, removed on moderation, or the account is closed.

Reporting of Recommendations & Reviews

Categories of data.
Report category and narrative, reporter identifier, subject identifier, positional context where material.
Processing operations.
Written to the reports collection and queued for human moderation; substantiated reports may result in correction, suppression or removal.
Determinate purpose.
To maintain the accuracy of the venue corpus and the civility of the community.
Lawful basis.
Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR where removal is mandated by applicable law (including Regulation (EU) 2022/2065).
Conservation.
For the period necessary to adjudicate the report and to evidence the moderation decision.

Bookmarks & Hidden Venues

Categories of data.
Arrays of saved venue and event identifiers; arrays of suppressed venue identifiers.
Processing operations.
Held optimistically in local stores and synchronised to the publicUsers document.
Determinate purpose.
To permit the User to curate a saved list and to exclude venues from the feed.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Until amended by the User or account closure.

Filtration State & Opening-Hours Computation

Categories of data.
Selected categories, distance and price filters; venue operating hours; device local time.
Processing operations.
Filter selections are retained in a client-side store; opening status is computed locally, including in respect of venues trading past midnight.
Determinate purpose.
To preserve filter selections across navigation and to avoid directing Users to closed venues.
Lawful basis.
Art. 6(1)(f) GDPR.
Conservation.
Session and device-local.

Outbound Link Confirmation

Categories of data.
Destination uniform resource locator and the User's election to proceed.
Processing operations.
An interstitial notice is displayed prior to departure from the App to a third-party destination.
Determinate purpose.
To place the User on notice that the destination is governed by the privacy practices of a third party.
Lawful basis.
Art. 6(1)(f) GDPR (transparency).
Conservation.
Not retained.

E · Gamification, Challenge Verification & Artificial Intelligence

Operations comprising the challenge, points and rewards economy, including the algorithmic verification methods described at Article XXI. All model inference is performed by way of server-side proxy so that no credential is exposed to the client, and no automated determination produces a legal or similarly significant effect within the meaning of Art. 22(1) GDPR.

Challenge Presentation & Attempt

Categories of data.
Challenge corpus for the active city, positional fix, attempt state, points accrued, tooltip acknowledgement flags.
Processing operations.
Challenges are retrieved from the city challenges subcollection; distance to the point of commencement is computed; attempts and completions are recorded.
Determinate purpose.
To operate the gamified discovery mechanic and to award points fairly.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Progress history retained for the period stated in Article V bis.

AI Photographic Verification

Categories of data.
Photographic image captured or selected by the User (downscaled, compressed and encoded), together with the associated challenge identifier.
Processing operations.
The image is processed on device by the image processor to reduce payload, transmitted to the Cloud Function 'verifyPhotoWithOpenAI' and proxied to the model provider for the sole purpose of determining whether the depicted subject satisfies the challenge criterion. The provider is contractually precluded from using the image to train models.
Determinate purpose.
To verify completion of photographic challenges without human review of the image.
Lawful basis.
Art. 6(1)(a) GDPR (the User elects to submit the image) and Art. 6(1)(b) GDPR.
Conservation.
The image is retained only for so long as is necessary to obtain a determination and, where retained for dispute resolution, for the period stated in Article XIII; it is not used for facial identification and no biometric template is derived.

AI Voice Verification

Categories of data.
Short audio sample captured by the device microphone.
Processing operations.
Encoded and transmitted to 'verifyVoiceWithOpenAI' for transcription and comparison against the expected utterance.
Determinate purpose.
To verify completion of spoken challenges.
Lawful basis.
Art. 6(1)(a) GDPR (microphone permission is granted expressly and is revocable at operating-system level).
Conservation.
Discarded upon determination. The Controller does not derive, store or process a voiceprint and accordingly performs no processing of biometric data within Art. 9 GDPR.

AI Answer Verification

Categories of data.
Free-text answer submitted by the User.
Processing operations.
Transmitted to 'verifyAnswerWithOpenAI' for semantic comparison against the model answer.
Determinate purpose.
To adjudicate knowledge-based challenges tolerantly of phrasing.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Discarded upon determination save for the resulting completion record.

Augmented Reality Landmark Recognition & Narrative Generation

Categories of data.
Camera image data; recognised landmark identifier; generated descriptive text.
Processing operations.
Image data is compressed and dispatched to the machine-vision service; where recognition fails, positional fallback is applied; a generative model composes the historical and factual narrative displayed to the User.
Determinate purpose.
To operate the augmented-reality scanning feature and to furnish contextual information.
Lawful basis.
Art. 6(1)(a) GDPR (camera permission) and Art. 6(1)(b) GDPR.
Conservation.
Image data is transient and is not retained following recognition.

Peer Scanning & Challenge Synchronisation

Categories of data.
Quick-response code payload, participant identifiers, forename or edited friend name, synchronisation request state.
Processing operations.
Codes are scanned by way of the device camera and processed server-side ('processPeerScan', 'sendSyncRequest', 'respondToSyncRequest', 'disconnectFriend'); only the name is disclosed to the counterparty.
Determinate purpose.
To permit Users to undertake challenges jointly with a companion.
Lawful basis.
Art. 6(1)(a) GDPR (the scan constitutes the affirmative act of the disclosing User).
Conservation.
Until the connection is severed by either participant.

Rewards, Secure Code Revelation & Redemption

Categories of data.
Reward entitlement, encrypted reward code, redemption state and timestamp, territorial eligibility.
Processing operations.
Codes are held encrypted and revealed only through the privileged routines 'revealSecureCode' and 'redeemDigitalReward'; scheduled tasks purge expired rewards.
Determinate purpose.
To operate the rewards economy while precluding interception, duplication or premature disclosure of codes.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (prevention of fraud).
Conservation.
Redemption records retained as required for accounting and dispute resolution.

Leaderboards & Weekly Reset

Categories of data.
Points totals, ranking position, redemption window state.
Processing operations.
Computed server-side and reset on the weekly cadence stated in the Terms; unredeemed entitlements lapse in accordance with the redemption window.
Determinate purpose.
To operate competitive ranking and to allocate finite reward inventory equitably.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Historical rankings are aggregated or erased in accordance with Article XIII.

Referral Programme

Categories of data.
User identifier, generated referral link, deep-link parameters, attributed referrer.
Processing operations.
Links are generated and parsed by the referral utility; attribution is recorded on the referred User's document.
Determinate purpose.
To operate the invitation mechanic and to credit referrals.
Lawful basis.
Art. 6(1)(a) GDPR; Art. 6(1)(b) GDPR.
Conservation.
For the life of the account or until the programme is discontinued.

F · Communications, Notifications & Marketing

Operations concerning the dispatch of messages to the User's device or mailbox, each subject to granular and revocable election.

Push Notification Enrolment

Categories of data.
Notification permission status; Expo push token; per-category consent flags (transactional, social, marketing).
Processing operations.
The token is obtained upon grant of permission and written to publicUsers together with the 'notifications' boolean; category flags are honoured at dispatch.
Determinate purpose.
To notify the User of events, challenges, rewards and critical service communications.
Lawful basis.
Art. 6(1)(a) GDPR for marketing categories; Art. 6(1)(b) GDPR for transactional notices.
Conservation.
Token retained while permission subsists; erased upon revocation or account closure.

Transactional Electronic Mail

Categories of data.
Electronic mail address, message metadata, delivery and suppression status.
Processing operations.
Dispatched through the electronic mail sub-processor; delivery events are logged and suppression lists are honoured.
Determinate purpose.
To deliver passcodes, receipts, application outcomes and legally required notices.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR.
Conservation.
Delivery logs retained for the operational period stated in Article XIII.

G · Subscriptions, Payments & Entitlement Management

Operations concerning consideration payable for premium tiers. The Controller does not receive, process or store primary account numbers, card verification values or equivalent payment credentials, which are handled exclusively by the payment institutions identified at Article XI.

Consumer Subscription Purchase

Categories of data.
Selected plan, entitlement tier, purchase and renewal identifiers, platform receipt tokens.
Processing operations.
Purchases are transacted through Apple In-App Purchase or Google Play Billing and mediated by the entitlement platform; webhooks ('handleRevenueCatWebhook') update 'subscriptionTier' on the publicUsers document. Security events are logged for rate-limiting and verification.
Determinate purpose.
To grant, maintain and withdraw access to premium functionality in accordance with the tier purchased.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (fiscal and accounting obligations).
Conservation.
Entitlement records retained for the statutory accounting period.

Business Subscription & Billing Portal

Categories of data.
Business customer identifier, subscription identifier, billing territory, invoice metadata.
Processing operations.
Transacted through the payment institution; the 'stripeWebhook' function reconciles subscription state per venue; a customer portal session is generated on request; billing territory determines the applicable invoice rendering template.
Determinate purpose.
To administer per-venue subscriptions, to issue territorially correct invoices, and to permit self-service billing administration.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR.
Conservation.
Six years or such longer period as Spanish fiscal legislation requires.

H · Business-User Console (Venues, Events & Redemption)

Operations undertaken in respect of business Users, being the venues, establishments and event promoters admitted to the platform. Where a business User uploads data relating to its own staff or customers, that business User acts as controller in respect of such data and the Controller acts as processor upon the terms of Article XI.

Venue Profile & Real-Time Busyness

Categories of data.
Business name, category, address, busyness state, subscription tier, quick-response check-in code, online state.
Processing operations.
Read from and written to the businesses document; busyness state is propagated to associated recommendation documents and mirrored locally; 'isOnline' is set to false on logout.
Determinate purpose.
To operate the venue's public presence and to convey live occupancy to Users.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Duration of the venue's participation on the platform.

Employee Roster & Shift Attribution

Categories of data.
Employee display names and identifiers; the 'currentShift' array of employees presently on duty.
Processing operations.
Maintained in the employees subcollection and the shift array of the business or venue document.
Determinate purpose.
To attribute redemptions to the staff member who effected them and to enforce console locking between shifts.
Lawful basis.
Art. 6(1)(f) GDPR (legitimate interest of the business User in operational accountability); the business User warrants that it has informed its personnel in accordance with Art. 13 GDPR.
Conservation.
Until deleted by the business User or termination of participation.

Redemption Scanning (Freebies & Guest Lists)

Categories of data.
Camera permission status; scanned code payload or manual six-digit code; customer redemption record; ticket reference.
Processing operations.
The code is read by the device camera; freebie codes are validated transactionally against the customer's entitlement and marked used, with the redemption written to the venue's redemptions subcollection; ticket references are validated against the ticketing endpoint; manual codes are resolved against the manualCodes collection.
Determinate purpose.
To honour rewards and guest-list entitlements while precluding duplicate redemption.
Lawful basis.
Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (fraud prevention).
Conservation.
Redemption records retained for reconciliation and dispute resolution.

Event Publication

Categories of data.
Event name, city, country, venue, address, description, date and time, external ticket link, guest-list allocation, line-up and imagery.
Processing operations.
Written to the city events subcollection upon approval and published within the App; scheduled tasks purge expired events.
Determinate purpose.
To publish local events to Users.
Lawful basis.
Art. 6(1)(b) GDPR.
Conservation.
Events are deleted one month after occurrence in accordance with Article XIII.

Business Data Portability Export

Categories of data.
Identity data, settings, masked telephone number, events, recommendations, rewards, redemption history and employee roster.
Processing operations.
Compiled by query across the relevant collections into a structured file written to the device file system and exportable by the business User.
Determinate purpose.
To discharge the right to data portability under Art. 20 GDPR and equivalent statutes.
Lawful basis.
Art. 6(1)(c) GDPR.
Conservation.
The export is generated on demand and is not retained by the Controller.

I · Server-Side Infrastructure, Telemetry & Scheduled Tasks

Operations performed by privileged backend components that cannot be circumvented by a modified client, together with analytical telemetry processed for the improvement of the Service.

Privileged Cloud Functions

Categories of data.
Authoritative access to the collections enumerated in this Annex; webhook payloads; model inference payloads; electronic mail payloads; network addresses and fingerprints; push tokens.
Processing operations.
Executed with administrative privilege to validate challenge completions, adjudicate rewards, proxy model inference, dispatch mail and notifications, reconcile payments, and effect hard deletion and token revocation.
Determinate purpose.
To enforce server-side rules that cannot be bypassed by a modified client, to keep credentials secret, and to ensure that points, payments and deletions are effected authoritatively.
Lawful basis.
Art. 6(1)(b), (c) and (f) GDPR; Art. 32 GDPR.
Conservation.
As specified for each underlying record in this Annex and Article XIII.

Buffered Usage Analytics

Categories of data.
Screen views, feature interactions, interaction timestamps and pseudonymous identifiers.
Processing operations.
Events are buffered in memory or local storage and dispatched in batches to minimise writes; analysis is conducted in aggregate.
Determinate purpose.
To measure the popularity and performance of features and venues and to inform product and recommendation improvements.
Lawful basis.
Art. 6(1)(f) GDPR (legitimate interest in service improvement), subject to the objection right at Article XIV.
Conservation.
Aggregated or pseudonymised in accordance with Article XIII.

Scheduled Maintenance Tasks

Categories of data.
Expired events and rewards; city content bundles.
Processing operations.
Recurring tasks purge lapsed records and pre-generate static city bundles for efficient delivery.
Determinate purpose.
To give effect to retention limits and to reduce latency and query volume.
Lawful basis.
Art. 6(1)(c) GDPR (storage limitation, Art. 5(1)(e)); Art. 6(1)(f) GDPR.
Conservation.
Not applicable; the task effects erasure.

Administrative & Data-Quality Scripts

Categories of data.
Venue records, including opening-hours formatting.
Processing operations.
Executed by authorised personnel under access control to normalise and correct catalogue data.
Determinate purpose.
To ensure the accuracy of the venue corpus as required by Art. 5(1)(d) GDPR.
Lawful basis.
Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR (accuracy principle).
Conservation.
Not applicable.

Administrative Console Access

Categories of data.
All account, profile, location, transactional, security-event, moderation-report, business-application and deletion-request data described elsewhere in this Annex, consulted and edited through an internal web console.
Processing operations.
Authenticated members of staff, subject to role-based access control and mandatory multi-factor authentication, consult and edit records to provide customer support, adjudicate business applications and moderation reports, action data-subject and deletion requests, investigate security incidents, and dispatch operational and (where consented) marketing communications. Console sign-in and privileged actions are logged.
Determinate purpose.
Operation, support, safety, moderation and legal compliance of the Services.
Lawful basis.
Art. 6(1)(b), (c) and (f) GDPR; Art. 32 GDPR in respect of the access controls.
Conservation.
Console access and action logs for twelve (12) months; the underlying records per their own entries in this Annex.

J · On-Device Storage, Caching & Ephemeral State

Data held upon the User's own device. Such data does not leave the device except where expressly stated elsewhere in this Annex, and is erased upon uninstallation of the App or purge of the application cache.

Preference, Bookmark & Suppression Caches

Categories of data.
Dietary and aesthetic preferences, saved and hidden venue identifiers, city catalogue, active city identifier.
Processing operations.
Persisted in AsyncStorage and in client-side stores to render instantly at launch and to permit offline browsing.
Determinate purpose.
To furnish a responsive and offline-capable experience without repeated interrogation of the database.
Lawful basis.
Art. 6(1)(f) GDPR.
Conservation.
Until uninstallation or cache purge.

Session, Lock & Security State

Categories of data.
Session metadata, application lock boolean, security preference flags, multi-factor state.
Processing operations.
Held in volatile client stores and, where continuity is required, in secure device storage.
Determinate purpose.
To enforce locking and session expiry and to route the User to authentication where a session is revoked.
Lawful basis.
Art. 6(1)(f) GDPR; Art. 32 GDPR.
Conservation.
Session lifetime.

Interface State & Alerts

Categories of data.
Transient message strings and tutorial acknowledgement keys.
Processing operations.
Held in memory or AsyncStorage solely to render notices and to suppress repeated tutorials.
Determinate purpose.
Presentational only; no personal datum is transmitted.
Lawful basis.
Art. 6(1)(f) GDPR.
Conservation.
Transient.

K · Exercise of Rights, Deletion & Data Subject Requests

Operations by which the Data Subject's statutory rights are given practical effect.

Account Deletion Request

Categories of data.
Requesting identity, associated venue and subscription references, stated reason for deletion.
Processing operations.
Deletion may be effected either (i) in-app, at Profile → Delete Account, which upon confirmation triggers an immediate recursive hard deletion of the account and its dependent records together with revocation of all authentication and push tokens; or (ii) by request submitted through the website, whereupon the Controller verifies the requester, cancels any subsisting subscription and executes the same hard deletion. A minimal request and audit record is retained for compliance evidence.
Determinate purpose.
To give effect to Art. 17 GDPR and equivalent statutes within the applicable statutory period.
Lawful basis.
Art. 6(1)(c) GDPR.
Conservation.
A minimal record of the request and its execution is retained to evidence compliance; all other data is erased or irreversibly anonymised save where retention is mandated by fiscal, accounting or anti-fraud legislation.

Access, Rectification, Portability & Objection

Categories of data.
The identity of the requester and the substance of the request.
Processing operations.
Requests are received at the address stated in Article XXV, verified, and answered within one month, extensible by two further months where warranted by complexity.
Determinate purpose.
To give effect to Arts. 15, 16, 20 and 21 GDPR and to equivalent rights under CCPA/CPRA, POPIA and the NDPA.
Lawful basis.
Art. 6(1)(c) GDPR.
Conservation.
Correspondence retained to evidence compliance for the limitation period.

Declaration of completeness.

The Controller declares that this Annex reflects, to the best of its knowledge as at the effective date stated above, the totality of processing operations carried out by or on behalf of the Controller in connection with the App. No processing operation not described herein is undertaken save where (a) it is strictly necessary for the technical delivery of a Service expressly requested by the Data Subject, (b) it is required by a legal obligation to which the Controller is subject, or (c) the Data Subject has given prior, specific, informed and unambiguous consent. Any material extension of the processing described herein shall be notified in accordance with Article XXIII prior to implementation.

End of Document · BL PLATFORM S.L. · © 2026