Preamble & Mutual Assent
Preamble
This Privacy Policy and Data Processing Agreement (the "Policy") constitutes a legally binding and enforceable instrument between the natural person accessing, downloading, registering for, or otherwise utilising the B'local mobile application and its associated services (the "User", " Data Subject" or "You") and BL PLATFORM S.L., a limited liability company duly organised and existing under the laws of the Kingdom of Spain, with registered domicile in Barcelona, acting in its capacity as Data Controller (the "Controller", "Company", "We" or " Us").
By affirmatively interacting with the B'local mobile application, its application programming interfaces, software development kits, and supporting backend infrastructure (collectively, the "Services"), the User unequivocally stipulates to having read, fully understood, and freely consented to the data processing methodologies set out herein. Where the User does not concur with any provision, clause or technical mechanism, the User's exclusive remedy is the immediate cessation of use of the Services and the deletion of the application from all User-controlled hardware.
This Policy is drafted in compliance with, and shall be construed by reference to: (i) Regulation (EU) 2016/679 of the European Parliament and of the Council ("GDPR"); (ii) the United Kingdom GDPR and the Data Protection Act 2018 ("UK GDPR"); (iii) the Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"); (iv) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); (v) the South African Protection of Personal Information Act, 4 of 2013 ("POPIA"); (vi) the Nigeria Data Protection Act 2023 ("NDPA"); (vii) the Kenya Data Protection Act, 2019; (viii) the Brazilian General Data Protection Law (Lei 13.709/2018, "LGPD"); (ix) the Canadian PIPEDA and Québec Law 25; (x) the Swiss Federal Act on Data Protection ("FADP"); (xi) the comprehensive privacy statutes of the United States States identified in Article XV; (xii) the Singapore Personal Data Protection Act, the Indian Digital Personal Data Protection Act 2023, the Japanese APPI, the South Korean PIPA and the Australian Privacy Act 1988; and (xiii) any further mandatory local laws of the User's jurisdiction, the more protective provision prevailing in the event of conflict.
Article I
Defined Terms
For the purposes of this Policy, the capitalised terms below shall bear the ascribed meanings:
Any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR and equivalent provisions under POPIA, NDPA and CCPA/CPRA.
Any operation performed upon Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, disclosure, erasure or destruction.
BL PLATFORM S.L., the entity which alone or jointly determines the purposes and means of the Processing.
Any natural or legal person which Processes Personal Data on behalf of the Controller pursuant to a written data processing agreement compliant with Article 28 GDPR.
Non-physiological, algorithmic patterns of human-device interaction (touch coordinates, swipe cadence, gyroscope vectors) processed solely for fraud and bot mitigation.
Metadata accompanying a network request, including IP address, signed Request Fingerprint headers, device manufacturer, operating system version and locale.
Volatile in-memory state used for transient location overrides, purged from RAM upon application termination and not persisted to disk.
Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, data concerning health or a person's sex life or sexual orientation.
Article II
Identity of the Data Controller & DPO
Pursuant to Article 4(7) GDPR and parallel international frameworks, BL PLATFORM S.L. acts as the primary Data Controller. The Company maintains its principal place of business and registered corporate domicile in Barcelona, Spain.
Controller: BL Platform S.L.
Registered Office: Carrer de Lepant, 270, 08013 Barcelona, Spain
NIF: B88709738
Privacy & Data Protection Enquiries: support@blocalapp.com
Data Protection Officer / Privacy Lead: dpo@blocalapp.com
No representative is designated pursuant to Article 27 GDPR, and none is required: the Controller is established within the European Economic Area (Barcelona, Spain) and Article 27 applies only to controllers not established in the Union.
Statutory inquiries, Data Subject Access Requests ("DSARs"), erasure or portability requests, and regulatory correspondence shall be directed to the Controller.
Article II bis
Data Protection Impact Assessment & Records of Processing
The Controller has carried out a Data Protection Impact Assessment ("DPIA") pursuant to Article 35 GDPR in respect of those Processing operations which, individually or in combination, are likely to result in a high risk to the rights and freedoms of natural persons, namely: (i) behavioural interaction analysis and honey-pot telemetry (Article IX); (ii) automated threat mitigation, including the automated restriction of account access (Article X); (iii) the Processing of precise geolocation data (Article VIII); and (iv) AI-assisted challenge verification and content generation (Article XXI). The assessment additionally addresses the criteria listed in the AEPD's mandatory DPIA list adopted under Article 35(4) GDPR.
The DPIA describes the Processing operations and their purposes, assesses their necessity and proportionality, identifies the risks to Data Subjects, and records the technical and organisational measures adopted to mitigate those risks (including data minimisation, coordinate truncation, pseudonymous logging, retention limits and the human-review pathway described at Article X bis). The DPIA is reviewed at least annually, and whenever a material change occurs in the nature, scope, context or purposes of the Processing. A copy is available to the AEPD, or to any other competent supervisory authority, on request.
The Controller likewise maintains a Record of Processing Activities under Article 30 GDPR; a public-facing extract of that register is reproduced at Annex I to this Policy.
Article III
Territorial & Material Scope
This Policy applies extraterritorially to the Processing of Personal Data of all Users of the Services, irrespective of the User's place of residence, and irrespective of whether the Processing itself takes place within the European Economic Area. The Controller asserts compliance with the extraterritorial reach provisions of GDPR Article 3, POPIA section 3, NDPA section 2, and CCPA §1798.140.
Article IV
Categories of Personal Data Processed
The Controller, observing the principle of data minimisation under Article 5(1)(c) GDPR, processes the following categories of Personal Data:
Given names, surnames, date of birth (for age-gating), verified email addresses, and mobile telephone numbers required for multi-factor authentication.
Hashed and salted passwords (Argon2id), session tokens, refresh tokens, and federated identity provider sub-claims (Apple, Google).
Avatar, declared dietary preferences, opt-in flags (alcohol challenges, push notifications, marketing), preferred language and accessibility settings.
Precise location information (GPS coordinates) and coarse location signals as further detailed in Article VIII, including a permanent declared 'Home Base' and ephemeral 'Travelling Status' overrides.
Touch coordinate maps, interaction cadence, accelerometer / gyroscope vectors, and honey-pot field engagements as detailed in Article IX.
Device manufacturer, model, OS version, app version, language, time zone, IP address, ASN, and signed X-Request-Fingerprint header values.
Reviews, photographs, ratings and challenge submissions published or uploaded by the User. Public reviews and replies are visible to other Users and to the relevant venue; there is no private in-app messaging channel attached to reviews or replies. The User may report a review or reply to the Controller for moderation, and business-account holders may reply to reviews of their own venue. Where a User chooses to upload photos, utilize AI Photo verification, or record AI Voice notes, the Application requests explicit OS-level permission to access the device Camera, Photo Library, or Microphone respectively. The device Camera is also used, with explicit OS-level permission, to scan QR codes for the purpose of synchronising challenges between friends so that they may complete them together, and (for business users) to scan venue freebies or event guest-list QR codes. Images and audio are processed exclusively for the intended upload, challenge verification, QR scan or business redemption. The Controller does not background-scan the User's photo roll or continuously monitor microphone input.
Reward redemptions, leaderboard rank, accrued points, and (where applicable) anonymised payment confirmations and subscription statuses for the Explorer Plan or Discover Plan. In-app subscriptions are purchased and billed through Apple In-App Purchase for iOS users and Google Play Billing for Android users; business-user payments are processed by Stripe, Inc.
Risk scores, fraud probability, recommended venues and inferred interests, generated by automated processing as set out in Article XXI.
Identifiers of recommendations and events that have been displayed to the User on their device, persisted exclusively within the local AsyncStorage of the User's handset (capped at the most recent one thousand (1,000) identifiers per category) for the sole purpose of prioritising previously-unseen content. These identifiers are not transmitted to the Controller's backend, are not linked to the User's account server-side, and are erased upon application uninstallation or User-initiated cache clearance.
For Users who opt to access the Services without creating a registered account ('Continue as Guest'), the Controller generates a randomized, anonymous unique identifier (UID) via Firebase Authentication together with a minimal placeholder record. No names, email addresses, or third-party federated identifiers are collected, and the anonymous identifier is not linked to any real-world identity. On sign-out, the local guest session is cleared from the device. The anonymous account and its associated records are deleted on the User's request, on conversion of the guest session into a registered account, or on account deletion, and are in no case retained beyond the period necessary to provide the guest browsing experience. A Guest User may exercise the rights described in Articles XIV to XVI by contacting the Controller and identifying the device or session concerned.
Where a User connects with friends to complete challenges together, the Controller processes the User's display name as visible to those friends. The User may edit the display name shown to friends at any time. The Controller does not share email addresses, telephone numbers or precise location coordinates with friends; only the name chosen for the friend-group context and the challenge-sync state are transmitted.
The Controller maintains a record of whether a User has been selected as eligible for a trip award or similar high-value reward. If a selected User does not accept the award within seven (7) calendar days, eligibility is automatically revoked and transferred to the next eligible User. This processing is necessary to operate the reward allocation mechanics and to ensure fairness in the gamification programme.
The Controller does not intentionally Process Sensitive / Special Category Data within the meaning of Article 9 GDPR, save where strictly necessary and supported by an Article 9(2) lawful basis, in particular explicit consent.
Article IV bis
Business-User Content Uploads (Vibe Playlist, Events, Freebies & Guest Lists)
Users authenticated under a verified business account ("Business Users") may, within the business dashboard, voluntarily upload additional content and use camera-based redemption tools for the purpose of enriching the public profile of their venue and operating events. Such uploads and scans are Processed under Article 6(1)(b) GDPR (performance of the business-account contract) and are subject to the following safeguards:
Up to five (5) audio files in MP3 format, selected by the Business User and transmitted to the Controller's object storage (Firebase Storage) for streaming snippet playback within the venue's recommendation page. Files are scanned for size and MIME-type conformity. The Business User warrants that they hold the necessary rights and/or licences (including, where applicable, public-performance and master-recording rights) in respect of each uploaded track.
A textual title, description, cover image and an external ticket link describing an event promoted by the Business User. Images are compressed client-side prior to upload to minimise bandwidth and storage footprint. Each posting is written into a per-business events register together with a server-generated retention timestamp. The Controller does not operate an internal ticketing system; ticket purchases are handled exclusively by the third-party destination linked by the Business User.
Event postings are automatically and irreversibly deleted by Firestore's native TTL policy one (1) calendar month after the event date or posting date, whichever is later. No human intervention is required and no copy is retained for analytical purposes after deletion.
Business Users may use the device Camera, with explicit OS-level permission, to scan QR codes presented by End-Users for the purpose of redeeming freebies or validating event guest-list entries. Scan results are processed in real time, recorded against the relevant Business User's account for redemption logging, and are not used for advertising or profiling of End-Users.
End-Users consuming a venue's profile may be exposed to short, looping audio snippets of the Business User's Vibe Playlist. Such playback is performed locally on the End-User's handset; no audio data is transmitted from the End-User to the Controller in connection with this feature.
Article IV ter
Business-User Analytics
Business Users receive aggregated analytics to help them understand the performance of their venue and events on the Services. These metrics are derived from End-User interactions and are presented to the Business User in a non-identifiable, aggregated form. The following analytics are collected:
The number of challenges linked to the Business User's venue that have been completed by End-Users. This count is attributed to the venue and is used solely for performance reporting and reward mechanics.
The number of reviews received and the number of times End-Users have saved the venue or an event to their personal list. Review averages are calculated from published ratings. These metrics are shown to the Business User in the dashboard.
For each event posted by a Business User, the Services track the number of views, saves and the average review rating associated with that event.
Business Users may filter analytics by preset periods (today, yesterday, last 7 days, last month) or by a custom date range. Filtering is performed client-side against data already held in the Business User's account; no additional Personal Data is collected to enable this feature.
The Controller does not share the identities of individual End-Users with Business Users unless the End-User has voluntarily published identifiable content (for example, a public review with a display name).
Article V
Purposes of Processing
Personal Data is Processed exclusively for the following enumerated purposes:
- Provision, maintenance and improvement of the Services;
- Account creation, authentication, identity verification, and sending transactional communications (e.g., reward purchase confirmations) via email;
- Personalisation of recommendations, challenges and rewards;
- Operation of the gamification, points, leaderboard and trip-award eligibility infrastructure, including the seven-day acceptance window and automatic transfer of unclaimed eligibility to the next eligible User;
- Synchronisation of challenges between friends via QR-code scanning, using only the User's chosen display name in the friend context;
- Publication, moderation, reporting and reply functionality in respect of reviews and other public content, with no private in-app messaging attached to reviews or replies;
- Provision of aggregated analytics to verified Business Users regarding their venue and event performance, including challenge completions, reviews, saves, views and review averages;
- Redemption of venue freebies and validation of event guest-list entries through QR-code scanning by Business Users;
- Detection, prevention and investigation of fraud, abuse and security incidents;
- Compliance with legal, regulatory, accounting and tax obligations;
- Establishment, exercise or defence of legal claims;
- Processing account-deletion requests submitted through the Controller's website, including verification of the requester and communication of the outcome;
- With separate opt-in consent: direct marketing and product research.
Article V bis
Privacy Policy Addendum: Gamification Data
When you participate in B'local challenges and rewards, the Controller collects and processes additional Personal Data to operate the gamification infrastructure and to ensure fairness across the rewards programme. The categories described below are Processed under the statutory bases set out in Article VI and retained in accordance with Article XIII.
The Controller records completed challenges, earned credits, and successful paid referrals to update your leaderboard status, calculate qualifying credits, and determine eligibility for high-value trip rewards.
A log of rewards you have claimed is retained to enforce category-specific cooldown periods (e.g., 24 hours for food, 30 days for certain trip sub-types), prevent duplicate claims, and ensure fair allocation of limited inventory.
If a challenge requires you to visit a specific physical venue, the Controller may temporarily use your precise location data (with your explicit OS-level permission) solely to verify completion. Location is not retained for profiling, advertising, or longitudinal tracking beyond the immediate verification window.
When you become eligible for a trip reward or similar high-value prize, the Controller records the eligibility timestamp. If you do not redeem the reward within seven (7) calendar days, your position on the leaderboard is forfeited, eligibility is transferred to the next eligible User, and you must complete one (1) challenge the following week to rejoin the leaderboard.
Your data is kept secure, is used only for the operation of the rewards programme and related anti-fraud controls, and is never sold to third parties.
Article VI
Statutory Bases for Processing (GDPR Art. 6)
Article VI bis
Diagnostics, Error Monitoring, Session Replay & Product Analytics
6bis.1 Nature and purpose. The Controller operates a crash- and error-diagnostics service (Sentry, processed in the Federal Republic of Germany) together with a limited sample — not exceeding ten per cent (10%) — of screen-session recordings and any in-app feedback text the User chooses to submit. Session recordings are captured with all text, input fields, images and vector content masked at source so that free-text content is not transmitted. This Processing is undertaken exclusively to detect defects, diagnose crashes, understand which features are used, and prioritise remediation and improvement of the Services. The data is not sold, is not used for advertising, and is not used to build a marketing or cross-context profile of the User.
6bis.2 Legal basis. This Processing is carried out on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR and equivalent provisions under the UK GDPR, LGPD, POPIA, NDPA and other applicable frameworks) in the security, stability, reliability and continuous improvement of the Services. The Controller has carried out and documented a balancing test (a "legitimate interests assessment") which concludes that this interest is not overridden by the interests or fundamental rights and freedoms of the User, having regard to the diagnostic-only purpose, the source-level masking, the pseudonymous nature of the identifiers used, the short retention period, and the User's ability to object and disable the Processing at any time.
6bis.3 Right to object and to disable. The User may object to this Processing and switch it off at any time, with immediate effect and without detriment to the availability of the core Services, from within the application at Profile → Privacy. Where the User does so, the diagnostics and session-replay software development kits are disabled on that device and no further diagnostic data is collected. The Controller records the User's current preference (enabled or disabled), together with the date on which it was last changed and the version of this Policy then in force, as evidence of compliance with the accountability principle.
6bis.4 Jurisdiction-specific consent requirements. The Controller acknowledges that the law of certain jurisdictions — including European Economic Area Member States under Article 5(3) of Directive 2002/58/EC (as transposed) — may require the User's prior consent for diagnostic and session-replay Processing of this kind. A User in any such jurisdiction who does not wish this Processing to take place may disable it at any time, before or after it begins, at Profile → Privacy, and the Controller will give effect to that choice immediately and retain a record of it. The Controller keeps the basis and mechanism for this Processing under review and will move to a prior-consent model for the relevant jurisdictions where required to do so.
Article VI ter
Layered Notice (LOPDGDD Art. 11) & Records of Consent and Preference (GDPR Art. 7(1))
6ter.1 First-layer information. In accordance with Article 11 of Spanish Organic Law 3/2018 (LOPDGDD), basic information is provided to the User at the point of collection, on a single screen presented during registration, in concise and plain language. That first-layer notice identifies: (i) the identity of the Controller and the contact details of the Data Protection Officer; (ii) the categories of data collected and the purposes for which they are Processed; (iii) the legal bases relied upon; (iv) the existence of the rights of access, rectification, erasure, restriction, portability, objection and the right to lodge a complaint with the AEPD; and (v) a direct, prominent hyperlink to this complete Policy, which constitutes the second information layer. Consent to optional Processing is not obtained through the first-layer notice alone.
6ter.2 Records of consent and preference. Where the Controller relies on the User's consent for a particular Processing purpose (for example marketing communications, push-notification categories, or referral attribution), it records, as evidence of compliance with Article 7(1) GDPR: the purpose to which the consent or refusal relates; the action taken and the resulting state; the date and time of the action; the version identifiers of this Policy and of the Terms then in force; and the surface through which the action was taken (for example onboarding, in-app privacy settings, or an unsubscribe link). For the diagnostics and session-replay Processing described in Article VI bis, which is carried out on the basis of legitimate interest, the Controller records the User's current preference (enabled or disabled) together with the date it was last changed.
6ter.3 Withdrawal and objection. A consent may be withdrawn, and an objection to legitimate-interest Processing may be raised, at any time from within the application, with the same ease as the setting was given and without detriment to the availability of the core Services. Withdrawal or objection takes effect promptly and without retroactive prejudice to the lawfulness of Processing carried out before it.
Article VII
Minimum Age (Adults Only, 18+)
The Services are rated and offered exclusively to adults and are not directed at, nor available to, any person under the age of eighteen (18) years, or such higher age of majority or lawful drinking age as applies in the User's jurisdiction of residence. The Controller does not knowingly collect or Process the Personal Data of any person under that age. Where the digital age of consent under a particular law is lower than eighteen (for example fourteen (14) under Article 7 of Spanish Organic Law 3/2018 (LOPDGDD), or sixteen (16) under Article 8 GDPR), that lower threshold is not relied upon, because the product itself is age-restricted to adults. Upon verified notification that a person under the applicable adult threshold has registered, the Controller will expeditiously delete the account and all associated Personal Data and, where required, notify a parent or guardian.
Article VIII
Precise Location & Geolocation Protocols
The Services collect precise location information (GPS coordinates) from the User's mobile device in order to provide the most accurate recommendations for the city the User is currently in, to suggest nearby venues (such as clubs, cafés, restaurants and cultural sites), and to ensure that localized content, challenges and rewards are relevant to the User's current physical position. The Controller employs a tiered hierarchy designed to privilege User autonomy and enforce privacy-by-design:
- Persistent Domicile (Home Base): The User's permanently declared geographic residence, stored in our database to bootstrap recommendations on first launch.
- Precise Hardware Telemetry (GPS): Subject to explicit, revocable OS-level authorisation. Precise GPS coordinates are read on demand and never silently polled in the background. The User retains the right to revoke this permission at any time through the device's system settings, although revocation may degrade or disable location-dependent features.
- Ephemeral Session Overrides (Travelling Status): The User may manually declare a temporary location which takes absolute priority over GPS telemetry. Stored in volatile memory only and purged on application termination.
Camera (NSCameraUsageDescription): "Used only while a scanning screen is open — to scan a friend's QR code to sync challenges, to verify a challenge by QR code or AI Photo, to scan landmarks in the AR feature, and, for business accounts, to scan customer reward and guest-list codes. No video is recorded or stored."
Microphone (NSMicrophoneUsageDescription): "Used only when you choose the AI Voice method to verify a challenge — you record a short voice note that is checked and then discarded. The microphone is never accessed in the background."
Photo Library (NSPhotoLibraryUsageDescription): "Used only when you choose to add a photo — for example to a favourite place, a review, or, for business accounts, a venue profile or event listing. Only the photo you select is accessed."
Location (NSLocationWhenInUseUsageDescription): "Used only while the app is open, to show nearby recommendations, events and challenges, to measure distance, and as a fallback for AR landmark scanning. Location is never accessed in the background."
Article IX
Behavioural Biometrics & Honey-Pots
To preserve infrastructural integrity, the Controller deploys hidden cryptographic honey-pot fields within authentication matrices and records the timing and spatial coordinates of the User's last ten (10) screen interactions. This data is processed locally where possible and cross-referenced with backend heuristics to differentiate bona fide human operation from automated scripts. No biometric template uniquely identifying a natural person within the meaning of Article 9 GDPR is generated, stored or shared.
Article IX bis
Device Biometric Unlock (Face ID / Touch ID / Android Biometrics)
Where the User enables it, the Application uses the biometric authentication mechanism of the operating system — Face ID, Touch ID or the Android biometric prompt — solely as a local gate to unlock the Application or the business console. The biometric comparison is performed entirely by the operating system within the secure hardware of the device. The Controller receives only a pass/fail result and at no time obtains, transmits, stores or has the capacity to reconstruct the User's fingerprint, facial geometry or any other biometric identifier.
Accordingly, no biometric data and no biometric template within the meaning of Article 9(1) GDPR, section 1 of POPIA, Article 30 of the NDPA or comparable provisions is created or Processed by the Controller in connection with this feature. The User may disable biometric unlock at any time in the Application's security settings or in operating-system settings, in which case the Application reverts to passcode or credential authentication.
Article X
Automated Threat Mitigation
The Services are governed by an automated cybersecurity framework designed to protect the platform from denial-of-service, brute-force, sybil and account-takeover incursions.
Detection & Human-Reviewed Enforcement
Detection of security events (e.g. brute-force, root/jailbreak, emulator or man-in-the-middle indicators) is automated. Upon a high-severity event, a server function ( processSecurityAlert) records the event and routes an alert to the Controller's Security Operations Centre. Account-affecting enforcement — revocation of authentication tokens, suspension of account access and addition of a device identifier to a blocklist — is not applied automatically; it is decided and carried out by an authorised member of the Controller's security team through an internal administration console, following review of the underlying signals. This design deliberately keeps a human in the loop before any measure producing legal effects concerning the User is taken.
Article X bis
Restricted-Access Notice (Blocked-User Modal)
Where the Controller's security team, acting on the automated alerts described in Article X, determines that an account or device must be subjected to access restriction, the mobile application will render a full-screen, non-dismissible notice (the "Restricted-Access Notice") indicating that the User's access to the Services has been suspended. The notice:
- does not reveal the specific signals or telemetry that triggered the restriction, in order to preserve the integrity of the anti-fraud system;
- offers a "Close Application" control which, on Android devices, gracefully terminates the application process;
- offers a "Contact Support" control which opens a pre-addressed message to support@blocalapp.com and permits the User to lodge an appeal, request human review of the automated decision (Article 22(3) GDPR), or submit a Data Subject Access Request;
- advises the User of their right to obtain meaningful information about the logic involved, to contest the restriction, and to lodge a complaint with the competent supervisory authority.
- an appeal received at support@blocalapp.com is logged as a formal Article 22(3) review request and acknowledged within two (2) business days;
- the file is assigned to a competent member of staff who is not the author of, and has authority to overturn, the automated decision; the reviewer examines the underlying signals, the User's submissions and any exculpatory evidence;
- a reasoned outcome is communicated to the User within fifteen (15) calendar days of the appeal, extendable once by a further fifteen (15) days for complex cases, with reasons for the extension notified before the initial deadline expires;
- where the automated decision is not upheld, access is restored and the associated blocklist entries and derived security records are corrected or deleted;
- every review is recorded (request, reviewer, evidence considered, outcome, date) and the record is retained as evidence of compliance and is available to the Data Protection Officer and, on request, to the AEPD;
- the Data Protection Officer monitors adherence to these service levels and reviews upheld and overturned decisions periodically in order to correct systematic error in the automated logic.
The Restricted-Access Notice does not, in itself, Process additional Personal Data beyond that which is already held in connection with the User's account.
Article XI bis
Rate Limiting & Abuse Controls
The Controller applies request rate-limiting across the entirety of its callable backend functions and public HTTP endpoints, including webhooks. The mechanism is implemented by means of short-lived counters keyed, in respect of authenticated calls, on the User's pseudonymous account identifier (UID) and, in respect of unauthenticated calls (including webhook deliveries), on the originating IP address. Where a defined threshold is exceeded within a rolling window, the corresponding request is rejected with an HTTP 429 Too Many Requests status or, for callable functions, an equivalent resource-exhausted error.
The processing of the UID and IP address for this purpose is grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in preventing automated abuse, credential-stuffing, denial-of-service and webhook-replay incidents. Counter records are retained only for the duration of the relevant window and are not used for marketing, profiling or any purpose unrelated to abuse mitigation.
Article XI ter
Business Users as Separate Controllers & Article 28 Data Processing Agreement
Where a business account holder (a venue, restaurant, bar, shop or event promoter — a "Business User") Processes Personal Data of its own staff or customers by means of the Services, the Business User acts as an independent Data Controller in respect of that data and the Controller acts as its Processor within the meaning of Article 4(8) GDPR.
That relationship is governed by a binding Data Processing Agreement ("DPA") satisfying the mandatory content of Article 28(3) GDPR, which the Business User must accept as a condition of onboarding and which is presented as a distinct, separately accepted contractual instrument — not merely as a paragraph of this consumer-facing Policy. The DPA sets out, at minimum: the subject-matter, duration, nature and purpose of the Processing; the categories of Data Subject and of Personal Data; the obligation to Process only on documented instructions; confidentiality undertakings; the technical and organisational security measures applied; the conditions for engaging sub-processors and the general written authorisation regime; assistance with Data Subject rights, security, breach notification and impact assessments; the obligations on deletion or return of data at the end of the relationship; and the audit and information rights of the Business User.
The Business User remains responsible for the lawfulness of the Processing it instructs, for informing its own staff and customers, and for establishing an appropriate legal basis for that Processing. A copy of the DPA accepted by the Business User is retained by the Controller for the duration of the relationship and for the applicable limitation period thereafter.
Article XII
International Data Transfers
Where Personal Data is transferred outside the EEA, UK or other adequacy jurisdiction, the Controller relies upon: (i) European Commission adequacy decisions; (ii) the European Commission's Standard Contractual Clauses (Module 1–4) of 4 June 2021, supplemented by a Transfer Impact Assessment; (iii) the EU-US Data Privacy Framework where the recipient is certified; or (iv) the User's explicit, informed consent under Article 49(1)(a) GDPR. For African Users, equivalent transfer mechanisms under POPIA section 72 and NDPA section 41 are applied.
12.1 Transfer Register. The following table identifies, for each principal Sub-Processor, the jurisdiction in which Processing takes place and the transfer mechanism relied upon:
| Sub-Processor | Country / Region | Transfer Mechanism |
|---|---|---|
| Google Cloud Platform / Firebase | EU (primary); US where activated | SCCs (2021) + EU-US Data Privacy Framework; Transfer Impact Assessment |
| Sentry (Functional Software, Inc. / Sentry GmbH) | EU — Germany | No transfer outside the EEA; intra-EEA Processing under Art. 28 GDPR agreement |
| OpenAI, L.L.C. | United States | EU-US Data Privacy Framework and/or SCCs, with Zero Data Retention / non-training addendum |
| Apple Inc. (IAP, Push, Sign-In, Geocoding) | United States / EU | EU-US Data Privacy Framework; SCCs where applicable |
| Google LLC (Play Billing, Places, Maps, FCM) | United States / EU | EU-US Data Privacy Framework; SCCs where applicable |
| Stripe, Inc. / Stripe Payments Europe Ltd. | United States / Ireland (EU) | SCCs (2021); EU entity for EEA business Users |
| RevenueCat, Inc. | United States | SCCs (2021) + Transfer Impact Assessment |
| Expo, Inc. (EAS, push relay, OTA updates) | United States | SCCs (2021) + Transfer Impact Assessment |
| Discord Inc. (internal security-operations alert channel) | United States | SCCs (2021) + Transfer Impact Assessment; data-minimised alert payloads only (no email, name or device model; IP truncated) |
| ipify.org (legacy client IP lookup) | United States | No personal data of the Controller transmitted; dependency being retired |
Article XIII
Retention Periods
Retained for the duration of the account plus thirty (30) days following deletion request.
Deletion initiated in-app at Profile → Delete Account is executed as an immediate hard deletion of the account and its dependent records, with revocation of all authentication and push tokens. Only a minimal audit record (pseudonymous identifier, timestamp, confirmation of completion) is retained, for twelve (12) months, as evidence of compliance.
Requests submitted through the website are retained for the period necessary to verify the requester, perform the deletion and confirm completion, and for an additional statutory period where required by law.
Twelve (12) months for security investigation purposes.
One-time verification and login passcodes are held only for the short validity window during which they can be used, are invalidated on use or on issue of a replacement, and the record is deleted on successful verification. Unused code records are purged by a scheduled clean-up job. Passcodes are not retained after verification.
Retained for twenty-four (24) months from the date of the incident, or until the expiry of the limitation period applicable to the specific claim where longer, after which they are automatically purged by a scheduled time-to-live job. No security record is retained indefinitely.
Ordinary session events (for example application open or sign-out) are not recorded as security events. Where a genuine security event is logged, the record identifies the User by pseudonymous account identifier only — email addresses are not stored in security logs — and the originating network address is captured server-side from the request context and truncated (IPv4 to /24; IPv6 to /48) before storage.
Maximum ninety (90) days, then irreversibly aggregated.
Six (6) years pursuant to Spanish Commercial Code Article 30.
Retained for the duration of the relevant award cycle plus seven (7) days, after which unclaimed eligibility is transferred to the next eligible User and the original record is deleted or aggregated.
Automatically deleted one (1) calendar month after the event date or posting date, whichever is later.
Retained for six (6) months for redemption reconciliation and dispute resolution, then deleted.
Statutory minimum under General Tax Law 58/2003.
Until withdrawal, plus a record of the withdrawal itself.
Records of the granting, amendment and withdrawal of consent, and of the User's current diagnostics/analytics preference (Article VI ter), are retained for the life of the account and for three (3) years following its closure, as evidence of compliance with Article 7(1) GDPR and the accountability principle.
Appeal files and review outcomes are retained for twenty-four (24) months from the date of the decision.
security_logs, securityIncidents, redemptions (business scan logs), viewLogs (venue and event view telemetry), userSecrets (unused verification/login codes), behavioural biometric vectors, event postings, trip-award eligibility records and expired access blocks. Each job is idempotent, is monitored for successful completion, and writes an execution record which the Data Protection Officer reviews. Where a record must exceptionally be preserved beyond its ordinary period (for example because it is subject to a legal hold, an ongoing investigation or a pending claim), the preservation is documented, is limited to what is strictly necessary, and terminates automatically on expiry of the hold. Article XIV
Rights of EU/EEA & UK Data Subjects
Pursuant to Articles 15–22 GDPR and the UK GDPR, the User is entitled to exercise:
- The right of access to their Personal Data;
- The right to rectification of inaccurate or incomplete data;
- The right to erasure ("right to be forgotten");
- The right to restriction of Processing;
- The right to data portability in a structured, commonly-used, machine-readable format;
- The right to object to Processing based on legitimate interest;
- The right not to be subject to solely automated decisions producing legal effects;
- The right to withdraw consent at any time without retroactive effect;
- The right to lodge a complaint with the competent supervisory authority — in Spain, the Agencia Española de Protección de Datos ( www.aepd.es ).
Exercise of the right to erasure. Deletion is available by two routes: (i) in-app, at Profile → Delete Account, which upon confirmation performs an immediate hard deletion of the User's account and its dependent records and revokes all authentication sessions and push tokens; and (ii)through the website, by submitting a deletion request which is verified and actioned by the Controller. In both cases, a backend routine triggered on account deletion removes the User's primary profile and business documents together with their subcollections and propagates the erasure to records derived from or referencing the account elsewhere in the database — including reviews, view and save logs, challenge-completion logs, reward-purchase and manual-redemption records, favourite-place entries, security-event logs, submitted reports, deletion-request and application records, server-side verification secrets, and rate-limiting counters. Only a minimal request and audit record is retained for compliance purposes as set out at Article XIII.
Requests are honoured free of charge within thirty (30) calendar days, extendable by sixty (60) days where necessary.
Article XV
United States — CCPA / CPRA & State Privacy Laws
California residents enjoy, in addition to the rights enumerated above: (a) the right to know the categories and specific pieces of Personal Information collected; (b) the right to delete Personal Information; (c) the right to correct inaccurate Personal Information; (d) the right to opt-out of the sale or sharing of Personal Information (the Controller does neither); (e) the right to limit use of Sensitive Personal Information; and (f) the right to non-discrimination for exercising these rights.
15.1 Other US State Laws. Equivalent rights are extended to residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana and Kentucky, and to residents of other US States as their respective comprehensive privacy statutes enter into force.
15.2 Opt-Out Preference Signals. The Controller honours the Global Privacy Control (GPC) and comparable browser or device opt-out preference signals as a valid request to opt out of sale or sharing in jurisdictions that so require.
15.3 Consumer Health Data. The Controller does not knowingly collect "consumer health data" within the meaning of the Washington My Health My Data Act, the Nevada consumer-health-data law or the Connecticut amendments, does not derive health inferences from dietary preferences or venue activity for any purpose beyond filtering content at the User's request, and does not sell any such data.
15.4 Nevada. Nevada residents may direct the Controller not to make any covered sale of their covered information by contacting dpo@blocalapp.com; the Controller does not engage in such sales.
15.5 Shine the Light (Cal. Civ. Code §1798.83). The Controller does not disclose Personal Information to third parties for those third parties' own direct-marketing purposes.
Article XV bis
Brazil, Canada & Other Americas
Brazil (LGPD — Lei 13.709/2018): Users may exercise the rights set out in Articles 17 to 22 LGPD, including confirmation of Processing, access, correction, anonymisation or deletion, portability, information about sharing, and revocation of consent, and may petition the Autoridade Nacional de Proteção de Dados (ANPD). The legal bases relied upon correspond to those in Article VI of this Policy.
Canada (PIPEDA & Québec Law 25): Users may withdraw consent (subject to legal or contractual restrictions), access and correct their Personal Information, request portability, and complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec. The Controller reports data breaches presenting a real risk of significant harm as required by those laws.
Article XVI
African Jurisdictions — POPIA, NDPA & Equivalents
South Africa (POPIA): Users are entitled to the rights set out in sections 23–25 of POPIA and may lodge complaints with the Information Regulator ( inforegulator.org.za ).
Nigeria (NDPA 2023): Users may exercise rights under sections 34–37 of the NDPA and refer complaints to the Nigeria Data Protection Commission.
Kenya (DPA 2019): Users may exercise rights under Part V of the Kenya Data Protection Act and refer complaints to the Office of the Data Protection Commissioner.
Ghana (Data Protection Act 843/2012): Users may exercise rights before the Data Protection Commission. Other African Jurisdictions: equivalent protections under the data-protection laws of Uganda, Rwanda, Tanzania, Zambia, Zimbabwe and Angola, under Egyptian Law 151/2020 and Moroccan Law 09-08, and under the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) are honoured where applicable.
Article XVI bis
Asia-Pacific & Middle East
The Controller gives effect to the substance of the following regimes for Users to whom they apply, and Users may in each case complain to the named authority:
Consent, purpose-limitation, access and correction rights and data-breach notification to the Personal Data Protection Commission; the Do Not Call provisions are honoured for marketing.
Notice-and-consent, the rights of access, correction, erasure and grievance redress of a Data Principal, and referral to the Data Protection Board of India.
Opt-in for third-party provision and for cross-border transfer, disclosure and correction rights, and referral to the Personal Information Protection Commission.
Separate consent per purpose, strict consent for cross-border transfer, and referral to the Personal Information Protection Commission.
Australian Privacy Principle 8 accountability for overseas disclosures and notification of eligible data breaches to the Office of the Australian Information Commissioner.
Consent, transfer restrictions and data-subject rights before the UAE Data Office and the Saudi Data & AI Authority (SDAIA) respectively.
The Controller does not target the Services at, or offer them within, mainland China. Where the PIPL nonetheless applies, the Controller will obtain separate consent, carry out a personal-information protection impact assessment, appoint a local representative, and use a lawful cross-border transfer mechanism before commencing the relevant Processing.
Article XVI ter
Other Jurisdictions & Interaction with Local Law
This Policy is intended to meet the substance of the principal data-protection regimes worldwide, including (without limitation) the GDPR and UK GDPR; the Spanish LOPDGDD; the Swiss FADP; the California CCPA/CPRA and the comprehensive privacy statutes of other United States States as they enter force; the Brazilian LGPD; the Canadian PIPEDA and Québec Law 25; the South African POPIA; the Nigerian NDPA; the Kenyan DPA; the Ghanaian Data Protection Act; the Singapore PDPA; the Indian Digital Personal Data Protection Act 2023; the Japanese APPI; the South Korean PIPA; the Australian Privacy Act; and the UAE and Saudi PDPLs.
Where the mandatory law of the User's jurisdiction affords the User a right, a protection or a remedy that is greater than, or additional to, those set out in this Policy, that mandatory law prevails to the extent of the difference, and nothing in this Policy shall be read as a waiver of it. Where such law requires the designation of a local representative, the registration of a data-processing activity, a specific cross-border transfer mechanism, or a distinct form of consent, the Controller undertakes to put that measure in place before, or upon, commencing the relevant Processing in that jurisdiction. Complaints may in every case be addressed to the Controller at dpo@blocalapp.com and, in addition, to the User's local supervisory or data-protection authority.
Article XVII
Technical & Organisational Security Measures
The Controller has implemented appropriate measures pursuant to Article 32 GDPR, including:
- AES-256 encryption at rest;
- TLS 1.3 encryption in transit, with HSTS preloading;
- Managed identity-provider credential hashing with per-user salt; the Controller never receives or stores plaintext passwords;
- One-time verification codes (login, PIN reset, redemption codes) generated with a cryptographically secure random number generator and stored only as a one-way SHA-256 digest, with short expiry, attempt limits and per-account rate limiting;
- Behavioural PIN stored solely as a SHA-256 digest computed on-device;
- Encrypted (AES-256) storage of push-notification tokens;
- Database access rules enforcing per-record ownership: a User's profile document is readable only by that User (and authorised staff) and cannot be enumerated; review authorship is bound to the authenticated account; aggregate configuration is writable by administrators only;
- Media uploads restricted to image content types and a maximum size of 8 MB;
- Operational security alerts to the internal SOC channel are data-minimised and exclude email addresses and device identifiers (see Articles XI and XII); account-affecting enforcement is subject to human review (Article X);
- Role-based access control with least-privilege provisioning;
- Server-side per-identifier and per-IP rate limiting on sensitive endpoints;
- Stripe and RevenueCat webhooks verified by cryptographic signature / bearer secret before processing;
- Periodic penetration testing and continuous vulnerability & dependency monitoring;
- Documented Incident Response Plan and Business Continuity Plan;
- Mandatory data protection training for all personnel.
Article XVIII
Personal Data Breach Notification
In the event of a Personal Data breach likely to result in a risk to the rights and freedoms of natural persons, the Controller shall notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk, affected Users shall be notified directly without undue delay pursuant to Article 34 GDPR.
Article XIX bis
On-Device Content Personalisation Cache ("Unseen First")
In furtherance of the principles of data minimisation (Article 5(1)(c) GDPR) and privacy-by-design (Article 25 GDPR), the Services implement a client-side personalisation mechanism, colloquially denominated the "Unseen First" logic, which operates exclusively within the local storage environment of the User's handset and does not entail any additional server-side Processing of Personal Data.
AsyncStorage): one enumerating the identifiers of recommendations previously rendered on-screen, and a second enumerating the identifiers of events previously rendered on-screen. Each register is capped at one thousand (1,000) entries on a first-in-first-out basis to preserve device performance and storage economy.19bis.2 Operational Logic. Upon each fetch operation, the application partitions the candidate content set into "unseen" and "seen" sub-collections, randomises the ordering within each sub-collection, and concatenates them such that previously-unviewed items are prioritised in the User's feed. Where the locally-cached content set is composed entirely of previously-seen identifiers, the fifteen (15) minute in-memory cache is bypassed and a fresh request is dispatched to the backend in order to surface novel content.
19bis.3 Data Locality & Non-Transmission. The identifiers comprising the Unseen First register are never transmitted to, persisted by, or otherwise made available to the Controller's backend infrastructure, Sub-Processors or any third party. They remain at all times under the exclusive custody of the User's device and outside the technical reach of the Controller.
19bis.4 User Control & Erasure. The User may, at any time and without justification, extinguish the Unseen First register by (i) clearing the application's local data through the operating system settings; (ii) uninstalling the application; or (iii) invoking the in-app "Clear Cache" functionality where exposed. Such action will reset the personalisation logic and cause previously-viewed content to be eligible for re-surfacing.
generateCityBundle) executes the underlying Firestore queries concurrently by means of Promise.all(), thereby reducing latency and the energy footprint of each request. This optimisation alters neither the categories of Personal Data Processed nor the lawful bases enumerated in Article VI.19bis.6 Lawful Basis. To the extent that the Unseen First register constitutes Processing within the meaning of Article 4(2) GDPR, such Processing is grounded in the Controller's legitimate interest (Article 6(1)(f) GDPR) in providing a non-repetitive, content-fresh User experience, which interest is not overridden by the rights and freedoms of the User given the strictly on-device, pseudonymous and User-controllable nature of the mechanism.
Article XIX ter
Local Caches, Persistent Preferences & Batched Telemetry
In furtherance of data minimisation, performance and battery-economy objectives, the mobile application maintains a series of additional local caches within the device's persistent key-value store (AsyncStorage), orchestrated by a client-side state-management layer (Zustand). These caches operate as a read-through copy of data that already lawfully resides within the User's account and do not give rise to any new category of Personal Data.
Locally mirrors the User's declared dietary preferences, vibe preferences, language, notification toggles and 2FA settings, synchronised from Firestore via a single background snapshot listener attached to the User's own document.
Locally mirrors the publicly-available list of cities for which the Services are activated; refreshed automatically every twenty-four (24) hours.
Locally mirrors the identifiers of recommendations and events that the User has personally bookmarked, so that bookmark indicators can be rendered without re-querying the backend on every screen.
19ter.4 Batched Analytics Writes. View-count and save-count telemetry generated by the User's interactions (e.g. viewing a venue or event) is buffered on the device and dispatched to the backend in atomic batches once a small threshold of events is reached. The pending-event buffer is written to the device's persistent key-value store so that events survive application termination; each buffered entry comprises the event type, the identifier of the venue or event concerned, a timestamp and the User's pseudonymous account identifier. Buffered entries are cleared once transmitted, and on sign-out or cache purge. Each underlying view is still recorded individually server-side so that dashboard accuracy is preserved; only the network-transport layer is optimised.
19ter.5 User Control. The User may extinguish any of the above caches at any time by clearing the application's local data, uninstalling the application, or signing out, which triggers a programmatic reset of the local stores.
Article XIX quater
Outbound Link Confirmation ("Leaving App" Notice)
Where a User activates a control which would cause the operating system to open a third-party destination outside the Services (including, without limitation, third-party booking systems, event ticketing pages, Apple Maps, Google Maps, the Controller's public website for the purposes of consulting the present Policy or the Terms & Conditions, or the business-onboarding portal), the mobile application first renders a branded, modal "Leaving Application" notice. The notice identifies the third-party destination, informs the User that they are about to be redirected outside the Controller's environment, and requires affirmative confirmation before the redirection is performed.
The Controller is not responsible for, and this Policy does not apply to, the data-processing practices of any third-party destination so accessed. The Controller does not track the User's activity on these external destinations or engage in cross-site tracking when traversing outbound links. Users are encouraged to consult the privacy policy of the recipient service prior to confirming the redirection.
Article XIX quinquies
On-Device City Catalogue Cache & Offline Availability
AsyncStorage) within the operating-system sandbox allocated to the Application. Only one city's Catalogue is retained at a time; selecting a different city replaces the previously stored Catalogue in its entirety. The Application does not maintain a multi-city or multi-region store, does not impose a fixed storage budget, and does not run a least-recently-used eviction routine.Article XX
Direct Marketing Communications
Direct marketing communications are dispatched only following the User's explicit, freely given, specific, informed and unambiguous opt-in. Each communication includes a one-click unsubscribe mechanism in conformity with Article 21(3) GDPR and Article 22 LSSI. Withdrawal of consent does not affect the lawfulness of Processing prior to such withdrawal.
Article XX bis
Partner Promotions & Advertising
20bis.1 Contextual Advertising
To help provide the User with the best local recommendations, the Application may display promotional content, partner offers and advertisements (such as ride-sharing discounts or travel services). The Controller operates a strictly contextual advertising system: the advertisements displayed are determined solely by the User's current activity within the Application — namely the specific City or Continent then being viewed.
20bis.2 No Cross-App Tracking Profile
The Controller does not combine the User's activity across other companies' applications or websites into an advertising profile, does not present an App Tracking Transparency prompt, does not access the User's Identifier for Advertisers (IDFA) or Android Advertising ID within the Application, and does not share any such identifier with data brokers. The Application does not embed a third-party advertising or behavioural-tracking software development kit.
20bis.3 Data Sharing with Partners
When the User views an advertisement within the Application, the Controller does not share personal identifying information — including name, email address, telephone number or precise GPS coordinates — with the third-party advertiser.
20bis.4 Third-Party Links
Should the User elect to click a promotional offer or advertisement, the User may be redirected to a third-party website or application (for example, the Uber or Airalo app). Once the User leaves the Application, their interactions are governed by the privacy policies and terms of service of those third parties. The Controller encourages the User to review such policies before completing any transaction.
20bis.5 Install Attribution (SKAdNetwork / Privacy Sandbox)
The Controller advertises the Application on third-party platforms and measures the effectiveness of that advertising by means of the privacy-preserving, on-platform attribution frameworks provided by Apple (SKAdNetwork / AdAttributionKit) and Google (Privacy Sandbox Attribution). These frameworks return to the Controller only aggregated, delayed and noise-injected conversion signals. They do not transmit to the Controller the User's identity, the User's advertising identifier, or the User's activity in other applications, and the Controller does not receive or assemble a cross-context advertising profile from them. Where an advertising platform (for example a social or video network on which the Application is promoted) carries out its own attribution, that Processing is carried out by that platform as an independent controller under its own policies; the Controller does not embed that platform's tracking software development kit in the Application. If the Controller introduces such a software development kit in future, it will update this Policy and the applicable app-store privacy disclosures, and will obtain consent where required, before deployment.
Article XXI
Automated Decision-Making & Artificial Intelligence
The Controller employs algorithmic systems and Artificial Intelligence (AI) for fraud scoring, recommendation generation and eligibility validation in the gamification framework. AI is additionally used for challenge verification through three methods — AI Photo (analysis of a photograph taken or uploaded by the User to confirm the challenge was performed), AI Voice (analysis of a short voice recording captured via the device Microphone) and AI Answer (evaluation of a written response submitted by the User) — and for generating the historical and factual narration presented in the AR feature once a building, monument or landmark has been scanned. Media submitted for verification is processed for that purpose only, is not used to train third-party foundation models, and is retained in accordance with Article IX. Decisions producing legal effects or significantly affecting the User (notably, the Auto-Kill protocol) are subject to human review on request. The User is entitled to obtain meaningful information about the logic involved, as well as the significance and envisaged consequences of such Processing, pursuant to Article 22 GDPR. The Controller commits to compliance with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) as its provisions enter into force.
Article XXI bis
How Recommendations, Events & Challenges Are Ordered
The order in which venues, events and challenges appear to the User is determined by a combination of the following main parameters:
- proximity to the User's current or selected location;
- the dietary preferences and atmosphere ("vibe") preferences the User has declared, and the categories the User has chosen for the navigation bar;
- whether the item has already been shown to the User on the current device — previously-unseen items are prioritised (Article XIX bis);
- how recently the item was created or updated;
- aggregate popularity, save-count and average rating on the Services;
- whether the venue is currently open, based on its published opening hours and the device's local time.
The User can influence this ordering by changing their declared preferences, their location and their category selections, and by hiding individual venues. Ordering is not based on any payment by a venue or event organiser for placement or prominence, and there is no paid ranking. A separate, disclosed fee may be charged to a business for the right to publish an event listing, but that fee does not affect the position of the listing relative to other content.
Article XXII
Limitation of Liability
22.1 Inherent Fallibility. Notwithstanding the implementation of AES-256 encryption, TLS transit protocols and automated threat frameworks, the User acknowledges that no digital architecture is wholly impervious to zero-day exploits or cyber-kinetic events.
22.2 Maximum Cap. To the maximum extent permissible under applicable mandatory law, and without prejudice to non-waivable consumer rights, the Controller's cumulative liability arising out of or in connection with this Policy shall be capped at the greater of (i) the total consideration paid by the User to the Controller in the twelve (12) months preceding the event giving rise to liability, or (ii) Fifty Euros (€50.00).
Article XXIII
Amendments to this Policy
The Controller reserves the right to amend, alter or supplement this Policy at any time. Material amendments shall be communicated via in-app notification at least thirty (30) days prior to entry into force. Continued use of the Services following such notice constitutes binding ratification of the revised instrument.
Article XXIV
Governing Law & Jurisdiction
This Policy shall be governed by and construed in accordance with the laws of the Kingdom of Spain. The Courts of Barcelona shall have exclusive jurisdiction over any dispute arising from or in connection with this Policy, without prejudice to the User's non-waivable right to bring proceedings in the courts of their place of residence pursuant to Regulation (EU) 1215/2012 (Brussels I bis) or equivalent local consumer protection statutes.
Article XXV
Contact & Complaints
Privacy & Data Protection Enquiries: support@blocalapp.com
Postal Address: BL PLATFORM S.L., Barcelona, Spain
Spanish supervisory authority — Agencia Española de Protección de Datos: www.aepd.es
Annex I
Register of Processing Activities (GDPR Art. 30)
This Annex I is incorporated into, and forms an integral and operative part of, this Policy. It constitutes the Controller's record of processing activities maintained pursuant to Article 30 of Regulation (EU) 2016/679 ("GDPR") and, so far as applicable, section 17 of the Protection of Personal Information Act 4 of 2013 (South Africa) and section 39 of the Nigeria Data Protection Act 2023. It is published in the interests of transparency under Articles 12, 13 and 14 GDPR and is intended to furnish the Data Subject with an exhaustive, module-by-module description of (i) the categories of personal data processed, (ii) the operations performed upon such data, (iii) the determinate purposes served, (iv) the statutory basis relied upon, and (v) the applicable conservation period.
Where any provision of this Annex conflicts with the body of the Policy, the provision affording the Data Subject the greater degree of protection shall prevail. Defined terms bear the meanings ascribed to them in Article I. References to "AsyncStorage", "Firestore", "Firebase Auth", "RevenueCat", "Stripe", the transactional email provider, "Expo", "Google Cloud Vision" and "OpenAI" are references to the technical components and sub-processors identified in Articles XI and XII, whose engagement is governed by written data processing agreements incorporating the Standard Contractual Clauses where required.
A · Account Constitution, Onboarding & Profile Configuration
Processing operations undertaken during the constitution of a User account and the elicitation of the declarative preferences upon which the personalisation layer of the App is predicated.
Age Attestation & Terms Assent
- Categories of data.
- Declared age, timestamp of assent to the Terms and Conditions, and the boolean state of the honesty attestation control.
- Processing operations.
- Persisted to the publicUsers collection keyed to the authenticated UID under the fields 'age' and 'termsAcceptedAt'.
- Determinate purpose.
- To enforce the minimum age eligibility threshold governing access to the App and to constitute durable, time-stamped evidence that the Terms were accepted at a determinate moment.
- Lawful basis.
- Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR (compliance with age-verification and record-keeping obligations); Art. 7(1) GDPR (demonstrability of consent).
- Conservation.
- Duration of the account plus the applicable limitation period for contractual claims.
Electronic Mail Verification (One-Time Passcode)
- Categories of data.
- Electronic mail address; six-digit one-time passcode; verification status flag.
- Processing operations.
- The address is transmitted to the 'requestOtp' Cloud Function, which dispatches the passcode by electronic mail; the passcode submitted by the User is validated by the 'verifyOtp' Cloud Function, whereupon 'isEmailVerified' is set to true. The passcode record is held only for the short window during which the code can be used and is subject to a dispatch throttle and a failed-attempt lock-out.
- Determinate purpose.
- To authenticate control of the declared mailbox, to prevent the enrolment of fictitious identities, and to establish a reliable channel for service and security communications.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (legitimate interest in account security).
- Conservation.
- The passcode record is deleted on successful verification and is invalidated on issue of a replacement; unused records are removed by a scheduled clean-up job. The verification flag is retained for the life of the account.
Dietary Preference Elicitation
- Categories of data.
- Declared dietary orientation (vegan, vegetarian, halal, pescatarian, gluten-free, or none).
- Processing operations.
- Recorded in the 'foodPreference' field of the publicUsers document and applied as an automatic filtration predicate over the recommendation corpus.
- Determinate purpose.
- To tailor recommendations to the User's declared dietary requirements.
- Lawful basis.
- Art. 6(1)(a) GDPR (consent). The Controller does not solicit, and does not infer, religious or philosophical conviction from such declaration; the datum is treated as a culinary filter only and is not processed as a special category of data under Art. 9 GDPR.
- Conservation.
- Until amended or erased by the User, or until account closure.
Aesthetic ('Vibe') Preference Elicitation
- Categories of data.
- Array of declared atmospheric preferences (e.g. modern, vintage, chill).
- Processing operations.
- Stored in the 'vibePreference' field of the publicUsers document and mirrored to on-device AsyncStorage for immediate application at cold start.
- Determinate purpose.
- To personalise the ordering and presentation of the recommendation feed.
- Lawful basis.
- Art. 6(1)(a) GDPR (consent).
- Conservation.
- Until amended or erased by the User; local mirror cleared upon uninstallation or cache purge.
Locale, Base Territory & Referral Attribution
- Categories of data.
- Language code; base country and ISO country code; base city and city identifier; centroid coordinates of the selected city; optional referral code.
- Processing operations.
- Written to publicUsers as 'language', 'baseCountry', 'baseCountryCode', 'baseCity', 'baseCityId', 'baseCityLat', 'baseCityLng' and, where supplied, 'referredByCode'; the application locale is reconfigured accordingly.
- Determinate purpose.
- To localise the interface, to fix the territorial frame of reference for local content, and to attribute referrals within the invitation programme.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(a) GDPR in respect of referral attribution.
- Conservation.
- Duration of the account.
Navigation Bar Curation
- Categories of data.
- Up to six supplementary category selections (e.g. beaches, shopping, clubs).
- Processing operations.
- Persisted as the 'navbarCategories' array on the publicUsers document.
- Determinate purpose.
- To permit the User to curate the primary navigation surface of the App.
- Lawful basis.
- Art. 6(1)(a) GDPR (consent).
- Conservation.
- Until amended or erased by the User.
Onboarding Progression Flags
- Categories of data.
- Boolean completion markers ('@hasOnboarded', 'onboardingComplete', 'isNewUser') and tutorial-seen keys.
- Processing operations.
- Held in device-local AsyncStorage and, where relevant to server-side routing, on the publicUsers document.
- Determinate purpose.
- To sequence the first-run experience and to suppress the repetition of instructional overlays.
- Lawful basis.
- Art. 6(1)(f) GDPR (legitimate interest in coherent user experience).
- Conservation.
- Until uninstallation, cache purge or account closure.
B · Authentication, Session Integrity & Anti-Fraud Controls
Operations directed to the establishment and preservation of authenticated sessions and to the detection and suppression of automated, fraudulent or otherwise illegitimate access.
Credential Authentication & Federated Sign-In
- Categories of data.
- Electronic mail address; password (transmitted to, and held exclusively by, the identity provider in salted and hashed form); forename and surname; identity-provider payloads emitted by Apple and Google; session identifiers and provider metadata.
- Processing operations.
- Credentials are surrendered directly to Firebase Authentication; the resulting profile is materialised in the publicUsers collection. Federated tokens are parsed and refreshed by the authentication utilities. The Controller does not at any time receive, store or have the capacity to reconstruct a plaintext password.
- Determinate purpose.
- To authenticate the User, to constitute the account, and to maintain session continuity.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (security of processing, Art. 32 GDPR).
- Conservation.
- Duration of the account; session artefacts expire upon revocation, logout or token expiry.
Behavioural Biometrics & Honey-Pot Instrumentation
- Categories of data.
- Touch coordinates and inter-event timings; interaction cadence; values entered into concealed decoy fields.
- Processing operations.
- Interaction telemetry is evaluated heuristically at the point of authentication; anomalous cadence or any completion of a decoy field causes a security event to be recorded by way of the 'logSecurityEvent' routine.
- Determinate purpose.
- To distinguish human interaction from scripted or emulated interaction and thereby to defeat credential stuffing, enumeration and brute-force attack.
- Lawful basis.
- Art. 6(1)(f) GDPR (overriding legitimate interest in the integrity of the Service). Such telemetry is not used for unique identification of a natural person and accordingly does not constitute biometric data within Art. 9(1) GDPR.
- Conservation.
- Ephemeral in the ordinary case; security events retained for the audit period specified in Article XIII.
Two-Step Verification & Session Stamping
- Categories of data.
- Six-digit login passcode; session metadata.
- Processing operations.
- The passcode is validated server-side by the 'verifyOtp' Cloud Function; upon validation a new session is stamped by the 'stampNewSession' routine and prior sessions may be invalidated.
- Determinate purpose.
- To impose a second authentication factor and to enforce concurrency limits upon sessions.
- Lawful basis.
- Art. 6(1)(f) GDPR; Art. 32 GDPR.
- Conservation.
- Passcodes expire on use; session records retained until expiry or revocation.
Device Request Fingerprinting
- Categories of data.
- Operating system version, device model, coarse hardware and software characteristics, request timestamp.
- Processing operations.
- Reduced to a one-way hashed signature by the RequestFingerprint utility and appended to privileged requests.
- Determinate purpose.
- To detect emulation, request forgery and application-programming-interface abuse, and to attribute abusive traffic without recourse to direct identifiers.
- Lawful basis.
- Art. 6(1)(f) GDPR (fraud prevention, expressly recognised at Recital 47 GDPR).
- Conservation.
- Retained in the security audit trail for the period specified in Article XIII.
Security Event Logging & Restricted-Access Enforcement
- Categories of data.
- Contextual usage data, warning classifications, network address context, authentication failure counts.
- Processing operations.
- Structured events are dispatched by the SecurityLogger to the security_logs collection and processed server-side ('processSecurityAlert', 'processSecurityLogs'); where thresholds are exceeded, access is restricted and the restricted-access notice described at Article X bis is displayed.
- Determinate purpose.
- To constitute an audit trail, to detect malicious conduct, and to interdict abusive accounts.
- Lawful basis.
- Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR where retention is required to evidence compliance.
- Conservation.
- As specified in Article XIII; network addresses are truncated or masked where full retention is unnecessary.
Business Console Personal Identification Number
- Categories of data.
- Four-digit PIN (stored solely as a SHA-256 digest), 'pinEnabled' flag, PIN reset code and expiry, application lock state.
- Processing operations.
- The PIN is hashed on device by way of expo-crypto and only the digest is persisted to the business document. Inactivity exceeding five minutes places the console in a locked state. Reset codes are dispatched to the registered business mailbox and validated against Firestore, whereupon the digest is cleared.
- Determinate purpose.
- To prevent unauthorised access to the console by staff or third parties during a shift and to secure the device when unattended.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR; Art. 32 GDPR.
- Conservation.
- Digest retained while the PIN feature is enabled; reset codes expire upon use or lapse.
C · Geolocation, Proximity Computation & Territorial Logic
Operations involving precise or approximate geospatial data, processed strictly upon the granular permissions described at Article VIII and revocable at any time through the location-sharing settings of the App or of the operating system.
Foreground Location Acquisition
- Categories of data.
- Device latitude, longitude and fix timestamp; 'isLocationShared' flag; manually selected city coordinates in the alternative.
- Processing operations.
- Operating-system permission is solicited; where granted, a fix is obtained and written to the 'location' object of the publicUsers document. Where permission is withheld, the manually selected base city is substituted and no satellite-derived datum is processed.
- Determinate purpose.
- To surface proximate recommendations, essentials, events, challenges and rewards.
- Lawful basis.
- Art. 6(1)(a) GDPR (explicit, revocable consent at operating-system level).
- Conservation.
- Most recent fix only; superseded upon each subsequent acquisition and erased upon withdrawal of permission.
Distance, Routing & Challenge Batching
- Categories of data.
- User coordinates and target coordinates.
- Processing operations.
- Haversine and geospatial computations are performed by the location utilities to render distances and to batch challenges into geographically coherent itineraries; coordinate pairs are transmitted to external routing interfaces for walking directions and deep-linked to the User's native mapping application on request.
- Determinate purpose.
- To display distance, to spare the User unnecessary traversal of the city, and to furnish navigation to challenges, essentials, recommendations and events.
- Lawful basis.
- Art. 6(1)(a) GDPR; Art. 6(1)(b) GDPR in respect of features expressly invoked by the User.
- Conservation.
- Transient; coordinates are not retained by the Controller following computation.
Session City versus Physical Position
- Categories of data.
- Active city identifier maintained separately from the physical positional fix.
- Processing operations.
- The location store maintains the distinction between the territory the User is physically within and the territory the User has elected to browse.
- Determinate purpose.
- To permit exploratory or 'tourist' browsing of another city without the positional fix overriding the User's election.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Session-scoped; cached locally for continuity.
Challenge Verification, Polls, Syncing & Reward Eligibility
- Categories of data.
- Positional fix at the moment of verification; territorial eligibility determinations.
- Processing operations.
- The fix is compared server-side against the geofence of the challenge, poll or synchronisation event and against the territorial scope of available rewards.
- Determinate purpose.
- To verify that a real-world task was in fact performed at the requisite location, to prevent fraudulent accrual of points, and to determine which rewards may lawfully and commercially be offered.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (integrity of the gamification economy).
- Conservation.
- Verification outcome retained; the underlying coordinate is discarded once the determination is made.
Landmark Proximity & Augmented Reality Fallback
- Categories of data.
- Positional fix; landmark corpus.
- Processing operations.
- Proximity to catalogued landmarks is computed and used as a fallback identification heuristic where the machine-vision service is unable to identify the landmark from the image supplied.
- Determinate purpose.
- To furnish contextual and educational information concerning points of interest.
- Lawful basis.
- Art. 6(1)(a) GDPR; Art. 6(1)(f) GDPR.
- Conservation.
- Transient.
D · Discovery, User-Generated Content & Community Moderation
Operations concerning the discovery corpus and content voluntarily contributed by Users, including reviews, reports and content-suppression elections.
Reviews & Ratings
- Categories of data.
- Star rating, free-text narrative, author identifier and display name, venue or event identifier, timestamp.
- Processing operations.
- Written to the reviews subcollection under the relevant city, venue or event and rendered publicly within the App.
- Determinate purpose.
- To crowdsource qualitative assessment of venues and events for the benefit of other Users and of the venue.
- Lawful basis.
- Art. 6(1)(a) GDPR (voluntary publication) and Art. 6(1)(b) GDPR.
- Conservation.
- Until withdrawn by the author, removed on moderation, or the account is closed.
Reporting of Recommendations & Reviews
- Categories of data.
- Report category and narrative, reporter identifier, subject identifier, positional context where material.
- Processing operations.
- Written to the reports collection and queued for human moderation; substantiated reports may result in correction, suppression or removal.
- Determinate purpose.
- To maintain the accuracy of the venue corpus and the civility of the community.
- Lawful basis.
- Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR where removal is mandated by applicable law (including Regulation (EU) 2022/2065).
- Conservation.
- For the period necessary to adjudicate the report and to evidence the moderation decision.
Bookmarks & Hidden Venues
- Categories of data.
- Arrays of saved venue and event identifiers; arrays of suppressed venue identifiers.
- Processing operations.
- Held optimistically in local stores and synchronised to the publicUsers document.
- Determinate purpose.
- To permit the User to curate a saved list and to exclude venues from the feed.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Until amended by the User or account closure.
Filtration State & Opening-Hours Computation
- Categories of data.
- Selected categories, distance and price filters; venue operating hours; device local time.
- Processing operations.
- Filter selections are retained in a client-side store; opening status is computed locally, including in respect of venues trading past midnight.
- Determinate purpose.
- To preserve filter selections across navigation and to avoid directing Users to closed venues.
- Lawful basis.
- Art. 6(1)(f) GDPR.
- Conservation.
- Session and device-local.
Outbound Link Confirmation
- Categories of data.
- Destination uniform resource locator and the User's election to proceed.
- Processing operations.
- An interstitial notice is displayed prior to departure from the App to a third-party destination.
- Determinate purpose.
- To place the User on notice that the destination is governed by the privacy practices of a third party.
- Lawful basis.
- Art. 6(1)(f) GDPR (transparency).
- Conservation.
- Not retained.
E · Gamification, Challenge Verification & Artificial Intelligence
Operations comprising the challenge, points and rewards economy, including the algorithmic verification methods described at Article XXI. All model inference is performed by way of server-side proxy so that no credential is exposed to the client, and no automated determination produces a legal or similarly significant effect within the meaning of Art. 22(1) GDPR.
Challenge Presentation & Attempt
- Categories of data.
- Challenge corpus for the active city, positional fix, attempt state, points accrued, tooltip acknowledgement flags.
- Processing operations.
- Challenges are retrieved from the city challenges subcollection; distance to the point of commencement is computed; attempts and completions are recorded.
- Determinate purpose.
- To operate the gamified discovery mechanic and to award points fairly.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Progress history retained for the period stated in Article V bis.
AI Photographic Verification
- Categories of data.
- Photographic image captured or selected by the User (downscaled, compressed and encoded), together with the associated challenge identifier.
- Processing operations.
- The image is processed on device by the image processor to reduce payload, transmitted to the Cloud Function 'verifyPhotoWithOpenAI' and proxied to the model provider for the sole purpose of determining whether the depicted subject satisfies the challenge criterion. The provider is contractually precluded from using the image to train models.
- Determinate purpose.
- To verify completion of photographic challenges without human review of the image.
- Lawful basis.
- Art. 6(1)(a) GDPR (the User elects to submit the image) and Art. 6(1)(b) GDPR.
- Conservation.
- The image is retained only for so long as is necessary to obtain a determination and, where retained for dispute resolution, for the period stated in Article XIII; it is not used for facial identification and no biometric template is derived.
AI Voice Verification
- Categories of data.
- Short audio sample captured by the device microphone.
- Processing operations.
- Encoded and transmitted to 'verifyVoiceWithOpenAI' for transcription and comparison against the expected utterance.
- Determinate purpose.
- To verify completion of spoken challenges.
- Lawful basis.
- Art. 6(1)(a) GDPR (microphone permission is granted expressly and is revocable at operating-system level).
- Conservation.
- Discarded upon determination. The Controller does not derive, store or process a voiceprint and accordingly performs no processing of biometric data within Art. 9 GDPR.
AI Answer Verification
- Categories of data.
- Free-text answer submitted by the User.
- Processing operations.
- Transmitted to 'verifyAnswerWithOpenAI' for semantic comparison against the model answer.
- Determinate purpose.
- To adjudicate knowledge-based challenges tolerantly of phrasing.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Discarded upon determination save for the resulting completion record.
Augmented Reality Landmark Recognition & Narrative Generation
- Categories of data.
- Camera image data; recognised landmark identifier; generated descriptive text.
- Processing operations.
- Image data is compressed and dispatched to the machine-vision service; where recognition fails, positional fallback is applied; a generative model composes the historical and factual narrative displayed to the User.
- Determinate purpose.
- To operate the augmented-reality scanning feature and to furnish contextual information.
- Lawful basis.
- Art. 6(1)(a) GDPR (camera permission) and Art. 6(1)(b) GDPR.
- Conservation.
- Image data is transient and is not retained following recognition.
Peer Scanning & Challenge Synchronisation
- Categories of data.
- Quick-response code payload, participant identifiers, forename or edited friend name, synchronisation request state.
- Processing operations.
- Codes are scanned by way of the device camera and processed server-side ('processPeerScan', 'sendSyncRequest', 'respondToSyncRequest', 'disconnectFriend'); only the name is disclosed to the counterparty.
- Determinate purpose.
- To permit Users to undertake challenges jointly with a companion.
- Lawful basis.
- Art. 6(1)(a) GDPR (the scan constitutes the affirmative act of the disclosing User).
- Conservation.
- Until the connection is severed by either participant.
Rewards, Secure Code Revelation & Redemption
- Categories of data.
- Reward entitlement, encrypted reward code, redemption state and timestamp, territorial eligibility.
- Processing operations.
- Codes are held encrypted and revealed only through the privileged routines 'revealSecureCode' and 'redeemDigitalReward'; scheduled tasks purge expired rewards.
- Determinate purpose.
- To operate the rewards economy while precluding interception, duplication or premature disclosure of codes.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (prevention of fraud).
- Conservation.
- Redemption records retained as required for accounting and dispute resolution.
Leaderboards & Weekly Reset
- Categories of data.
- Points totals, ranking position, redemption window state.
- Processing operations.
- Computed server-side and reset on the weekly cadence stated in the Terms; unredeemed entitlements lapse in accordance with the redemption window.
- Determinate purpose.
- To operate competitive ranking and to allocate finite reward inventory equitably.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Historical rankings are aggregated or erased in accordance with Article XIII.
Referral Programme
- Categories of data.
- User identifier, generated referral link, deep-link parameters, attributed referrer.
- Processing operations.
- Links are generated and parsed by the referral utility; attribution is recorded on the referred User's document.
- Determinate purpose.
- To operate the invitation mechanic and to credit referrals.
- Lawful basis.
- Art. 6(1)(a) GDPR; Art. 6(1)(b) GDPR.
- Conservation.
- For the life of the account or until the programme is discontinued.
F · Communications, Notifications & Marketing
Operations concerning the dispatch of messages to the User's device or mailbox, each subject to granular and revocable election.
Push Notification Enrolment
- Categories of data.
- Notification permission status; Expo push token; per-category consent flags (transactional, social, marketing).
- Processing operations.
- The token is obtained upon grant of permission and written to publicUsers together with the 'notifications' boolean; category flags are honoured at dispatch.
- Determinate purpose.
- To notify the User of events, challenges, rewards and critical service communications.
- Lawful basis.
- Art. 6(1)(a) GDPR for marketing categories; Art. 6(1)(b) GDPR for transactional notices.
- Conservation.
- Token retained while permission subsists; erased upon revocation or account closure.
Transactional Electronic Mail
- Categories of data.
- Electronic mail address, message metadata, delivery and suppression status.
- Processing operations.
- Dispatched through the electronic mail sub-processor; delivery events are logged and suppression lists are honoured.
- Determinate purpose.
- To deliver passcodes, receipts, application outcomes and legally required notices.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR.
- Conservation.
- Delivery logs retained for the operational period stated in Article XIII.
G · Subscriptions, Payments & Entitlement Management
Operations concerning consideration payable for premium tiers. The Controller does not receive, process or store primary account numbers, card verification values or equivalent payment credentials, which are handled exclusively by the payment institutions identified at Article XI.
Consumer Subscription Purchase
- Categories of data.
- Selected plan, entitlement tier, purchase and renewal identifiers, platform receipt tokens.
- Processing operations.
- Purchases are transacted through Apple In-App Purchase or Google Play Billing and mediated by the entitlement platform; webhooks ('handleRevenueCatWebhook') update 'subscriptionTier' on the publicUsers document. Security events are logged for rate-limiting and verification.
- Determinate purpose.
- To grant, maintain and withdraw access to premium functionality in accordance with the tier purchased.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (fiscal and accounting obligations).
- Conservation.
- Entitlement records retained for the statutory accounting period.
Business Subscription & Billing Portal
- Categories of data.
- Business customer identifier, subscription identifier, billing territory, invoice metadata.
- Processing operations.
- Transacted through the payment institution; the 'stripeWebhook' function reconciles subscription state per venue; a customer portal session is generated on request; billing territory determines the applicable invoice rendering template.
- Determinate purpose.
- To administer per-venue subscriptions, to issue territorially correct invoices, and to permit self-service billing administration.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR.
- Conservation.
- Six years or such longer period as Spanish fiscal legislation requires.
H · Business-User Console (Venues, Events & Redemption)
Operations undertaken in respect of business Users, being the venues, establishments and event promoters admitted to the platform. Where a business User uploads data relating to its own staff or customers, that business User acts as controller in respect of such data and the Controller acts as processor upon the terms of Article XI.
Venue Profile & Real-Time Busyness
- Categories of data.
- Business name, category, address, busyness state, subscription tier, quick-response check-in code, online state.
- Processing operations.
- Read from and written to the businesses document; busyness state is propagated to associated recommendation documents and mirrored locally; 'isOnline' is set to false on logout.
- Determinate purpose.
- To operate the venue's public presence and to convey live occupancy to Users.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Duration of the venue's participation on the platform.
Employee Roster & Shift Attribution
- Categories of data.
- Employee display names and identifiers; the 'currentShift' array of employees presently on duty.
- Processing operations.
- Maintained in the employees subcollection and the shift array of the business or venue document.
- Determinate purpose.
- To attribute redemptions to the staff member who effected them and to enforce console locking between shifts.
- Lawful basis.
- Art. 6(1)(f) GDPR (legitimate interest of the business User in operational accountability); the business User warrants that it has informed its personnel in accordance with Art. 13 GDPR.
- Conservation.
- Until deleted by the business User or termination of participation.
Redemption Scanning (Freebies & Guest Lists)
- Categories of data.
- Camera permission status; scanned code payload or manual six-digit code; customer redemption record; ticket reference.
- Processing operations.
- The code is read by the device camera; freebie codes are validated transactionally against the customer's entitlement and marked used, with the redemption written to the venue's redemptions subcollection; ticket references are validated against the ticketing endpoint; manual codes are resolved against the manualCodes collection.
- Determinate purpose.
- To honour rewards and guest-list entitlements while precluding duplicate redemption.
- Lawful basis.
- Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (fraud prevention).
- Conservation.
- Redemption records retained for reconciliation and dispute resolution.
Event Publication
- Categories of data.
- Event name, city, country, venue, address, description, date and time, external ticket link, guest-list allocation, line-up and imagery.
- Processing operations.
- Written to the city events subcollection upon approval and published within the App; scheduled tasks purge expired events.
- Determinate purpose.
- To publish local events to Users.
- Lawful basis.
- Art. 6(1)(b) GDPR.
- Conservation.
- Events are deleted one month after occurrence in accordance with Article XIII.
Business Data Portability Export
- Categories of data.
- Identity data, settings, masked telephone number, events, recommendations, rewards, redemption history and employee roster.
- Processing operations.
- Compiled by query across the relevant collections into a structured file written to the device file system and exportable by the business User.
- Determinate purpose.
- To discharge the right to data portability under Art. 20 GDPR and equivalent statutes.
- Lawful basis.
- Art. 6(1)(c) GDPR.
- Conservation.
- The export is generated on demand and is not retained by the Controller.
I · Server-Side Infrastructure, Telemetry & Scheduled Tasks
Operations performed by privileged backend components that cannot be circumvented by a modified client, together with analytical telemetry processed for the improvement of the Service.
Privileged Cloud Functions
- Categories of data.
- Authoritative access to the collections enumerated in this Annex; webhook payloads; model inference payloads; electronic mail payloads; network addresses and fingerprints; push tokens.
- Processing operations.
- Executed with administrative privilege to validate challenge completions, adjudicate rewards, proxy model inference, dispatch mail and notifications, reconcile payments, and effect hard deletion and token revocation.
- Determinate purpose.
- To enforce server-side rules that cannot be bypassed by a modified client, to keep credentials secret, and to ensure that points, payments and deletions are effected authoritatively.
- Lawful basis.
- Art. 6(1)(b), (c) and (f) GDPR; Art. 32 GDPR.
- Conservation.
- As specified for each underlying record in this Annex and Article XIII.
Buffered Usage Analytics
- Categories of data.
- Screen views, feature interactions, interaction timestamps and pseudonymous identifiers.
- Processing operations.
- Events are buffered in memory or local storage and dispatched in batches to minimise writes; analysis is conducted in aggregate.
- Determinate purpose.
- To measure the popularity and performance of features and venues and to inform product and recommendation improvements.
- Lawful basis.
- Art. 6(1)(f) GDPR (legitimate interest in service improvement), subject to the objection right at Article XIV.
- Conservation.
- Aggregated or pseudonymised in accordance with Article XIII.
Scheduled Maintenance Tasks
- Categories of data.
- Expired events and rewards; city content bundles.
- Processing operations.
- Recurring tasks purge lapsed records and pre-generate static city bundles for efficient delivery.
- Determinate purpose.
- To give effect to retention limits and to reduce latency and query volume.
- Lawful basis.
- Art. 6(1)(c) GDPR (storage limitation, Art. 5(1)(e)); Art. 6(1)(f) GDPR.
- Conservation.
- Not applicable; the task effects erasure.
Administrative & Data-Quality Scripts
- Categories of data.
- Venue records, including opening-hours formatting.
- Processing operations.
- Executed by authorised personnel under access control to normalise and correct catalogue data.
- Determinate purpose.
- To ensure the accuracy of the venue corpus as required by Art. 5(1)(d) GDPR.
- Lawful basis.
- Art. 6(1)(f) GDPR; Art. 6(1)(c) GDPR (accuracy principle).
- Conservation.
- Not applicable.
Administrative Console Access
- Categories of data.
- All account, profile, location, transactional, security-event, moderation-report, business-application and deletion-request data described elsewhere in this Annex, consulted and edited through an internal web console.
- Processing operations.
- Authenticated members of staff, subject to role-based access control and mandatory multi-factor authentication, consult and edit records to provide customer support, adjudicate business applications and moderation reports, action data-subject and deletion requests, investigate security incidents, and dispatch operational and (where consented) marketing communications. Console sign-in and privileged actions are logged.
- Determinate purpose.
- Operation, support, safety, moderation and legal compliance of the Services.
- Lawful basis.
- Art. 6(1)(b), (c) and (f) GDPR; Art. 32 GDPR in respect of the access controls.
- Conservation.
- Console access and action logs for twelve (12) months; the underlying records per their own entries in this Annex.
J · On-Device Storage, Caching & Ephemeral State
Data held upon the User's own device. Such data does not leave the device except where expressly stated elsewhere in this Annex, and is erased upon uninstallation of the App or purge of the application cache.
Preference, Bookmark & Suppression Caches
- Categories of data.
- Dietary and aesthetic preferences, saved and hidden venue identifiers, city catalogue, active city identifier.
- Processing operations.
- Persisted in AsyncStorage and in client-side stores to render instantly at launch and to permit offline browsing.
- Determinate purpose.
- To furnish a responsive and offline-capable experience without repeated interrogation of the database.
- Lawful basis.
- Art. 6(1)(f) GDPR.
- Conservation.
- Until uninstallation or cache purge.
Session, Lock & Security State
- Categories of data.
- Session metadata, application lock boolean, security preference flags, multi-factor state.
- Processing operations.
- Held in volatile client stores and, where continuity is required, in secure device storage.
- Determinate purpose.
- To enforce locking and session expiry and to route the User to authentication where a session is revoked.
- Lawful basis.
- Art. 6(1)(f) GDPR; Art. 32 GDPR.
- Conservation.
- Session lifetime.
Interface State & Alerts
- Categories of data.
- Transient message strings and tutorial acknowledgement keys.
- Processing operations.
- Held in memory or AsyncStorage solely to render notices and to suppress repeated tutorials.
- Determinate purpose.
- Presentational only; no personal datum is transmitted.
- Lawful basis.
- Art. 6(1)(f) GDPR.
- Conservation.
- Transient.
K · Exercise of Rights, Deletion & Data Subject Requests
Operations by which the Data Subject's statutory rights are given practical effect.
Account Deletion Request
- Categories of data.
- Requesting identity, associated venue and subscription references, stated reason for deletion.
- Processing operations.
- Deletion may be effected either (i) in-app, at Profile → Delete Account, which upon confirmation triggers an immediate recursive hard deletion of the account and its dependent records together with revocation of all authentication and push tokens; or (ii) by request submitted through the website, whereupon the Controller verifies the requester, cancels any subsisting subscription and executes the same hard deletion. A minimal request and audit record is retained for compliance evidence.
- Determinate purpose.
- To give effect to Art. 17 GDPR and equivalent statutes within the applicable statutory period.
- Lawful basis.
- Art. 6(1)(c) GDPR.
- Conservation.
- A minimal record of the request and its execution is retained to evidence compliance; all other data is erased or irreversibly anonymised save where retention is mandated by fiscal, accounting or anti-fraud legislation.
Access, Rectification, Portability & Objection
- Categories of data.
- The identity of the requester and the substance of the request.
- Processing operations.
- Requests are received at the address stated in Article XXV, verified, and answered within one month, extensible by two further months where warranted by complexity.
- Determinate purpose.
- To give effect to Arts. 15, 16, 20 and 21 GDPR and to equivalent rights under CCPA/CPRA, POPIA and the NDPA.
- Lawful basis.
- Art. 6(1)(c) GDPR.
- Conservation.
- Correspondence retained to evidence compliance for the limitation period.
Declaration of completeness.
The Controller declares that this Annex reflects, to the best of its knowledge as at the effective date stated above, the totality of processing operations carried out by or on behalf of the Controller in connection with the App. No processing operation not described herein is undertaken save where (a) it is strictly necessary for the technical delivery of a Service expressly requested by the Data Subject, (b) it is required by a legal obligation to which the Controller is subject, or (c) the Data Subject has given prior, specific, informed and unambiguous consent. Any material extension of the processing described herein shall be notified in accordance with Article XXIII prior to implementation.
End of Document · BL PLATFORM S.L. · © 2026
