Last updated: [EFFECTIVE DATE]
This Privacy Policy explains how [OPERATOR LEGAL NAME] ("we", "us", "our"), the operator of Twedl and the website at twedl.com (the "Service"), collects, uses, and protects personal data. It is written on the basis that we are established in the United Kingdom and that UK data protection law — the UK GDPR and the Data Protection Act 2018 — applies. Where we serve visitors in the European Economic Area, the EU GDPR may also apply.
If you have any questions, contact us at [CONTACT EMAIL] or by post at [POSTAL ADDRESS]. We are the data controller for the personal data described below. [If registered with the ICO, insert registration number here.]
1. The personal data we collect
Depending on how you use the Service, we may collect:
- Account data — your name, email address, password (stored only in hashed form), account role, and preferred language.
- Organiser profile data — where you submit events, any contact details you choose to add, such as a phone number, website, and social media links.
- Event submission data — the events you submit, including descriptions, images you upload, location and venue details, dates, and ticket or access information.
- Invitee data — where you upload a list of invitees (for example, a CSV of email addresses), we process those email addresses on your instruction. Please see section 8.
- Communications — emails and messages you send us, and records of the notifications we send you (such as email verification and event moderation updates).
- Technical and usage data — your IP address, browser and device information, and server log data, collected automatically when you use the Service.
- Cookies — see section 5.
2. Where we obtain your data
We collect most personal data directly from you when you register, complete your profile, submit an event, or contact us. We collect technical data automatically through cookies and server logs. We also import event listings from third-party sources (see section 6); those listings are business/venue information, although they may occasionally include an organiser's contact details.
3. How we use your data and our lawful bases
- To provide the Service — creating and managing your account, authenticating you, and displaying events. Lawful basis: performance of a contract.
- To moderate and keep the Service safe — reviewing submissions, preventing fraud, abuse, and misuse, and maintaining security. Lawful basis: our legitimate interests in running a trustworthy service.
- To communicate with you — sending service emails such as verification links and moderation outcomes, and responding to your enquiries. Lawful basis: performance of a contract and our legitimate interests.
- To display advertising — we may show third-party advertising (see section 5). Lawful basis: consent, where required for advertising cookies.
- To comply with the law — meeting our legal and regulatory obligations. Lawful basis: legal obligation.
We do not sell your personal data. [Confirm with solicitor whether any activity constitutes a "sale"/"share" under applicable US state laws if you have US users.]
4. Marketing
We currently send only service-related messages that are necessary to operate your account and your event submissions. If in future we send marketing communications, we will do so only where permitted by law and, where required, with your consent, and you will be able to opt out at any time.
5. Cookies and advertising
We use cookies and similar technologies for two purposes:
- Strictly necessary cookies — for example, to keep you signed in and to protect against cross-site request forgery. These are required for the Service to function.
- Advertising cookies — we may use Google AdSense to display advertising. Google and its partners may set cookies to serve and measure ads. This is subject to Google's own policies (see how Google uses information from sites that use its services).
Where advertising or other non-essential cookies are used and consent is required under UK PECR or EU ePrivacy rules, we will ask for your consent through a cookie banner and you can change your choices at any time. [Confirm the cookie-consent mechanism is in place before enabling advertising.]
6. Third parties who process data for or with us
We share personal data only where necessary, with:
- Our hosting and infrastructure provider — [HOSTING PROVIDER], who hosts the Service.
- Our email delivery provider — [EMAIL PROVIDER], used to send service emails.
- Google — where advertising is enabled, as an independent controller of advertising data.
- Mapping providers — we use OpenStreetMap and its Nominatim geocoding service to display maps and look up coordinates; your browser may contact these services when maps are shown.
- Event data sources — we import public event listings from third-party providers, including Ticketmaster's Discovery API. [Confirm compliance with each provider's API/data terms.]
- Professional advisers and authorities — where required by law or to protect our rights.
7. International transfers
Some of our providers (for example, Google) are based outside the UK/EEA, including in the United States. Where personal data is transferred internationally, we rely on an appropriate safeguard such as UK adequacy regulations, the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. [Confirm the specific mechanism for each provider.]
8. If your details were uploaded by an event organiser
Organisers may upload lists of invitees to invite people to private events. If your email address was uploaded to the Service by an organiser, that organiser is responsible for having a lawful basis to share it with us, and we process it on their instruction. If you believe your details were uploaded without your consent, contact us at [CONTACT EMAIL] and we will assist, including removing your details.
9. How long we keep your data
We keep personal data only for as long as necessary for the purposes above. Account and profile data are kept while your account is active; if you delete your account, its associated data is deleted or anonymised, except where we must retain limited information to meet legal obligations or resolve disputes. Server logs are kept for a limited period for security and diagnostics. [Insert specific retention periods once agreed.]
10. Security
We take appropriate technical and organisational measures to protect personal data, including encryption of traffic in transit (HTTPS), hashing of passwords, access controls, and moderation of submitted content. No online service is completely secure, and we cannot guarantee absolute security.
11. Your rights
Subject to the conditions in data protection law, you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased (you can delete your account at any time from your profile);
- restrict or object to certain processing;
- data portability;
- withdraw consent where processing is based on consent; and
- lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or your local supervisory authority.
To exercise any of these rights, contact us at [CONTACT EMAIL].
12. Children
The Service is not directed at children, and accounts are intended for users aged [16 / 18 — confirm] and over. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the "Last updated" date above. Material changes will be notified by appropriate means.
14. Contact
Questions or requests about this policy or your personal data can be sent to [CONTACT EMAIL] or [POSTAL ADDRESS].