App Privacy Policy

At Xperience your privacy takes centre stage! We truly believe that your data belongs to you and nobody else, and want to put you in full control over your data. We always try to design our app and features around your privacy and always put your privacy first. 

1 - About Xperience

Xperience is a social media app and lifestyle platform that serves the purpose of matchmaking, finding new friends online as well as friendship building. Through events and activities (“Xperiences”), users can meet new people and share their own ideas for activities on the platform with other users. Through their profile, the built-in chat and sharing pictures, users can share their best moments with old and new friends, build long-term friendships and stay in touch.  

Through our Xperience Professionals (“Professionals”), users can find commercial events nearby, purchase tickets, communicate with event organizers and participate in unique events. Our Xperience Associates (“Associates”) allow users to find leisure time activities and, in particular, offers from hospitality businesses in their area, which are recommended by us, and to receive different discounts from them depending on availability. Users can also easily set one of our Associates as the location for their own Xperiences in the app.  

(Subsequently referred to as “Services” or “App”). 

2 - Controller

Xperience App & Lifestyle GmbH in establishment

Am grünen Prater 8/11, 1020 Vienna, Austria

+43 680 1444192

business@create-xperience.com 

 

Please direct any inquiries concerning data protection to privacy@create-xperience.com

3 - Applicability of this Privacy Policy

This Privacy Policy applies to the processing of personal data (hereinafter also referred to as “data”) in the context of the use of the App and the provision of the Services. This Privacy Policy does not apply to data processing in the context of commercial accounts for Professionals and Associates. For data processing in the context of our website, please visit the Privacy Policy available there. Please also see our Terms of Use.

Our Service is aimed exclusively at persons who are at least 16 (sixteen) years old. Therefore, in principle, no data of persons under 16 (sixteen) years of age will be processed. If you suspect that data of persons under 16 years of age is being processed, please inform us.

4 - Data subject to processing

We process the following data from you: 

·       Each time you use the App, we process certain automatically generated technical data (“Device Data“) to maintain the functionality of the App and to prevent and defend against targeted attacks. This includes, for example, software and hardware details as well as the IP address of your device, the time and duration of use. 

·       Your first and last name is processed to facilitate personal contact with other users. This data is collected as part of the registration process and used to create your profile and generate the first (later editable) username. This username is then also processed to facilitate personal contact with other users. This data is visible to other users. 

·       Your email address will be processed for registration or user identification during registration and then used to contact you. The e-mail address is collected during the registration process and is not visible to other users. 

·       The date you joined Xperience is shown within your profile and is visible to other users. 

·       If you provide us with your birthday*, it will be used to filter and generate suggestions. For the safety of other users and to prevent misuse, it is mandatory to enter your birthday in order to participate in activities. Your age is visible to other users. 

·       If you add a profile picture* or use the option of a short description*, these will be used to create and present your profile and to facilitate personal contact with other users. For the safety of other users and to prevent misuse, the addition of a profile picture is mandatory to participate in activities. This data is visible to other users. 

·       When you send or accept friend requests*, this information is processed to organize your relationships. This data can be used to generate suggestions about people you may know or activities that friends participate in. Your relationships are visible to other users.

·       You can create events and activities* on our Services, participate in other users’ events and activities through our Services, and visit certain locations. We process which activities have been created by you and which you have accepted or participated in to enable and organize these events and activities, and so that you and other users can see who has participated in which activity and visited which places. Your acceptances and participations are visible to other users. This data can be used to make suggestions about people you may know or activities that may be of interest to you. We also process your participation data for billing purposes with the Professional.

·       If you indicate which gender(s)* you identify with by selecting the applicable pronoun(s), this information will be processed as part of your profile and used to search for contacts and to facilitate contact with other users. This information is visible to other users. 

·       When communicating with other users via our Services, these chats* are processed to facilitate this communication. These chats can only be viewed by you and the person you are communicating with. 

·       If you have entered your place of residence*, this information will be processed within your profile and used to generate suggestions in your area. For the safety of other users and to prevent misuse, it is mandatory to specify at least the federal state in which you live in order to participate in activities. Your information about your place of residence is visible to other users. 

·       If you allow access to the current location* of your device, this will be used to generate suggestions in your area. However, your location is only processed once each time you start the App and for location-based searches. No movement tracking profile will be generated. You can manage location access at any time in the settings of your device operating system.

·       If you allow access to certain device data, such as Gallery, Camera and Calendar, photos* can be uploaded and your activities can be exported. Your shared photos are visible to other users. You can manage access to these device data at any time in the settings of your device operating system

·       If you provide your interests* or occupation*, this information will be processed within your profile and to generate suggestions, and will be used to search for contacts and facilitate contact with other users. This information is visible to other users.

·       If you want to receive notifications* from the App on your device, device tokens are created for your device and processed. These device tokens and the message content are transmitted to your respective operating system to enable these notifications.  

·       To enable the purchase of tickets via the App, we process your payment data* (for details see Section 9. below).

·       In addition, data of you may be processed if other users disclose your data in the context of our Services, such as via references, links, etc.

5 - Purpose and legal basis of processing

The data categories marked with “*” under Section 4. are voluntary information or data that is generated depending on your freely using the App and is generally not absolutely necessary for the general use of the App. All other data not marked with “*” is absolutely necessary, as we cannot provide our (basic) Services to you without it.

Absolutely necessary information will be processed to facilitate and to provide our Services and thus for the fulfillment of the contract with you pursuant to Art 6 (1) (b) GDPRBy accepting this Privacy Policy, you in addition expressly consent to the described data processing pursuant to Art 6 (1) (a) GDPR.

Voluntary information is processed for the purpose of providing the respective intended functions on the basis of your consent pursuant to Art 6 (1) (a) GDPR, which you grant by providing the respective data. You can revoke your consent at any time by sending an e-mail to privacy@create-xperience.com with effect for the future. If data provided by you in addition to the absolutely necessary information is absolutely necessary for providing additional features (for example, if you send a message using the chat function), your data will also be processed to facilitate this feature and therefore for the fulfillment of the contract pursuant to Art 6 (1) (b) GDPR.

The processing of the Device Data is based on our legitimate interest pursuant to Art 6 (1) (f) GDPR, namely, to optimize and improve the App and the Services, to increase the usability, to provide useful information about the use of our Services as well as to ensure and increase the security and stability of the App and to be able to detect and track attacks and misuse.

6 -  Messages

To notify you about events within the App (such as suggestions, alerts, or new chat messages), we send you push notifications within the App when you enable this feature. You can set, manage, and disable subscription to these notifications at any time in your operating system settings. In case of disablement, you will no longer be able to receive notifications from us. 

If you register for our newsletter, for instance within the settings of the App, or if other legal requirements exist, we process your email address to send you news and information about Xperience. By registering, you consent to the processing of your contact data for this purpose and to receive marketing communications. Your data will be processed until you withdraw your consent. 

If the legal requirements are met, we also process your contact data on the basis of our legitimate interest, namely, to stay in touch with you and maintain contact. In any case, you can refuse further mailings by sending an e-mail to privacy@create-xperience.com

In order to fulfill the contract, we will also send you messages necessary for this purpose, such as confirming your registration or for resetting your password.

7 - Place of processing and general data recipients

Your data is hosted by us on servers of Contabo GmbH, Aschauer Straße 32a, 81549 Munich, Germany within the European Union and will be processed by us only there. The hosting service provider processes your data as a processor and only in accordance with our instructions.

Since our Services serve the purpose of connecting with other users and (joint) participation in activities and events, the information, activities, and locations you provide will be displayed to other users. This transfer is carried out as part of the necessary provision of our Services for the fulfillment of the contract pursuant to Art 6 (1) (b) GDPRand is based on your consent pursuant to Art 6 (1) (a) GDPR, which you can adjust and withdraw at any time in the settings by deleting voluntary information.

Within the registration for commercial Xperiences, the data provided by you or further required by you will be transferred to the respective Professional for this purpose. This transfer is carried out for the fulfillment of thecontract pursuant to Art 6 (1) (b) GDPR and is based on your consent pursuant to Art 6 (1) (a) GDPR. We have no control over the further processing by the Professional; hence, please also consider the Professional’s conditions and statements regarding the processing of your data.

If you disclose in the context of the App that you are located at the place of an Associate, your data will also be transferred to this Associate. This transfer is based on your consent pursuant to Art 6 (1) (a) GDPR

8 - Transfer to third countries general

We store your personal data only on servers within the European Union. Only if it is technically unavoidable, the data that is absolutely necessary for this purpose is transmitted to third countries. 

This applies, for instance, to the transfer of Device Tokens when sending notifications to your device, provided these are activated. When using an iOS device, such a Device Token is transferred to Apple or, when using an Android device, to Google. You can disable the notification and thus the transfer of the Device Token at any time in your operating system settings. This transfer is based on your consent pursuant to Art 6 (1) (a) GDPR

If we further transfer data to third parties (e.g., Professionals, Associates, Google), we oblige them to transfer personal data to third countries only if an adequate level of data protection is guaranteed there, standard contractual clauses have been concluded, binding internal data protection regulations exist or other adequate guarantees exist, or if you have consented to this transfer. 

9 - Payments

We use the payment service provider Stripe Payments Europe Limited, The One Building, Lower Grand Canal St, Dublin 2, Ireland (“Stripe”) to process payments for tickets purchased through the App for events by Professionals. 

For payment processing, the data necessary for the administration of the electronic commerce platform and for the processing of payment transactions are transferred to Stripe as a processor, such as cardholder name, email address, unique customer identifier, order ID, bank details, payment card data, card expiration date, CVC code, date/time/amount of transaction, merchant name/ID, location.  

Stripe also processes your personal data as a controller for fraud prevention and control purposes, as well as for compliance with (financial) legal obligations, product improvement and product provision.  

This processing and transfer are carried out for the provision of the feature “event booking/ticket purchase” and thus for the fulfillment of the contract pursuant to Art 6 (1) (b) GDPR and based on your consent pursuant to Art 6 (1) (a) GDPR.

Stripe may also transfer data outside the European Economic Area to the extent necessary to provide their services. Stripe ensures that if data is transferred to a country for which there is no adequacy decision, adequate security measures are in place and appropriate safeguards are provided. 

For more information about Stripe’s processing of your data, please see Stripe’s privacy policy

10 -  Sign in via 3rd Parties

You can also register and sign in to our Services via 3rd party (“Sign in with Apple”, “Sign in via Google”) if you wish to do so and have made the appropriate settings with the third-party services. 

“Sign in with Apple” is a service provided by Apple Distribution International Ltd, Hollyhill Industrial Estate Hollyhill, Cork, Ireland (“Apple”). This links your Apple account to our Service, generates an ID for you and provides us with your name and email address. Information on the processing of your data by Apple can be found at https://www.apple.com/privacy. You can determine the form and scope of the data transfer by Apple by making the corresponding settings directly at Apple. 

“Google Sign-In” or “Sign in via Google” is a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). This links your Google account with our Service, and we receive your name, email address and, if applicable, your profile picture from Google. For more information on the processing of your data by Google, please visit https://policies.google.com/privacy.   

The processing of your data within the scope of login via 3rd party is based on your consent pursuant to Art 6 (1) (a) GDPR as well as your legal relationship with the respective provider and the settings made within the scope of the possibilities there. The use of these services is voluntary, you can alternatively create an account directly with us and thus avoid such processing.

11 - Google AdMob

We use Google AdMob to display (personalized) advertising in our Services. This is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4., Ireland (“Google”). For this purpose, certain data is transferred to Google for the purpose of personalized advertising. This includes general usage data, app usage data and advertising interactions, general information about the device and operating system (name, operating system and version, model, browser, language, region), advertisement identifier and name of the app. For more information about how Google processes your data, please visit: https://policies.google.com/privacy

12 - Google Firebase Analytics

We use Google Firebase Analytics to analyze device data and usage behaviour collected while using the app (see 4.). This is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4., Ireland (“Google”). For this purpose, certain data is transferred to Google. This includes general usage data, app usage data, general information about the device and operating system (name, operating system and version, model, language, region), and name of the app. For more information about how Google processes your data, please visit: https://firebase.google.com/terms/data-processing-terms.

By agreeing to this Privacy Policy, you also expressly consent to this processing and transfer pursuant toArt 6 (1) (a) GDPR. 

You can withdraw this consent at any time in the App by deactivating app analytics in the in-app settings. By deactivating app analytics in the App, no more data will be transferred to Google until you reactivate app analytics. 

13 - Privacy

We do not process your data for automated decision-making, including profiling in accordance with Art 22 (1) and (4) GDPR, which leads to decisions that have legal effects on you or significantly affect you in a similar way.

However, we use the data provided by you as well as location, usage, and activity data to provide contact and activity suggestions. Depending on the voluntary information you provide, which can be edited at any time (see point 4.), no information or only certain information from you will be used to provide personalized suggestions.

You can set and disable location usage by the App via your operating system settings. In case of deactivation, location-based services or suggestions can no longer be provided by us.  

By specifying the individual settings or providing your information, you expressly consent to the respective processing and transfer and can withdraw or adjust this consent at any time with effect for the future by adapting these settings or deleting individual information.

14 - Storage period and account deletion

Generally, your data is stored for the existence of your account.

You can delete your account in its entirety at any time in the App settings. We consider the deletion of your account as a withdrawal of your consent to the entire data processing, as a cancellation of all Xperiences created by you, and as a request for deletion pursuant to Art 17 GDPR. After notifying other participants of the cancellation of your Xperiences, your data will be deleted. Please note, however, that deletion may not be immediately possible for technical reasons, which is why we reserve the right to a reasonable period of time to delete the content. 

Even after deletion of the account, however, it may be necessary for us to continue to store certain data internally (not visible to other users), in particular if this is necessary due to legal obligations (such as accounting data in accordance with corporate and tax regulations) or an order of a court or an administrative authority, if this data must be stored further for the defense or assertion of legal claims, or if there is a legitimate interest of third parties or a legitimate interest on our part in their continued storage. Such a legitimate interest of a third party is, for example, the further display of the chat history with you in the chat partner’s account or including your name in notifications to other users to indicate that you, by deleting your profile, have deleted one of the activities that they are also taking part in. This data will be deleted as soon as the respective reason for storage no longer exists.  

15 - Security

Xperience always takes appropriate and state-of-the-art technical and organizational measures to protect your data in the best possible way. This currently includes, for example, the encryption of the password and the transmissions to our server as well as technically up-to-date measures against unauthorized access to our infrastructure.  

16 - Your rights

You have the right to access your stored personal data, information about their origin and recipients and the purpose of data processing at any time and, if the legal requirements are met, the right to rectification, data portability, restriction of processing and blocking or deletion of incorrect or inadmissibly processed data.  

You have the right to withdraw your consent to the processing of your personal data at any time with effect for the future. 

You also have the right to object to the processing of your personal data on the basis of our legitimate interests if grounds for doing so arise from your particular situation. You may object to the processing of your data for direct marketing purposes at any time without giving reasons. 

To exercise your above-mentioned rights, please contact us by e-mail at privacy@create-xperience.com or by postal mail at the address given under Section 2. However, you can also exercise some of your rights yourself quite simply, for example by making the appropriate settings as described above and by deleting individual details. 

If you are of the opinion that the processing of your personal data by us violates applicable law or that your data protection rights have been violated in any other way, you have the right to lodge a complaint with the competent supervisory authority. In Austria, this is the data protection authority. However, in order to avoid proceedings, we kindly ask you to contact us in advance in all cases. 

Version: 04 January 2022