Skip to content
Kaynak
Company Cliqly Contact DE

Cliqly · Legal

Privacy Policy for “Cliqly”

Last updated: August 2026

DE EN FR

1. Controller

Kaynak UG (haftungsbeschränkt)
Erfweiler Str. 12
66994 Dahn
Germany

Email: support@kaynak.eu
Phone: +49 170 5265203
Privacy contact: datenschutz@cliqly.de
VAT identification number: DE464257971

2. Scope

This Policy explains how personal data is processed in Cliqly. The EU General Data Protection Regulation (GDPR) applies to people in the EU and EEA. We also account for the Swiss Federal Act on Data Protection (FADP) for people in Switzerland. Any additional mandatory rights under the law applicable at a person’s location remain unaffected.

Cliqly is only intended for adults aged 18 or older.

3. Categories of data

Depending on use, we process:

  • account, authentication and session data, including Sign in with Apple, the email address Apple provides for Cliqly (which may be a private relay address),
  • profile data such as display name, username, bio, interests, image, role, badges, language and privacy settings,
  • follows, follow requests, blocks and invitations,
  • event data, including content, categories, location, time, host and participation status,
  • Crew memberships, roles, invitations, polls, planning signals and media,
  • messages, reactions and replies in authorised event or Crew contexts,
  • profile, Crew and event images and event photos,
  • ratings, rankings and community signals,
  • reports, moderation decisions, warnings and suspensions with required context,
  • device, push, error and security data where needed for delivery, stability and abuse prevention,
  • location data when a location feature is used and iOS permission has been granted.

The email address Apple provides for Cliqly is processed for sign-in, account association, account security and required service communications. We do not use it for advertising without a separate legal basis.

3.1 Subscription, transaction and entitlement data

When an optional subscription is purchased, restored or managed, we process the following in particular for server-side verification and access control:

  • product identifier and the subscription tier derived from it,
  • the Apple transaction identifier and original transaction identifier,
  • a pseudonymous, app-specific account-association identifier (appAccountToken) derived from the provider identifier verified by Sign in with Apple; it contains no name, email address or payment details,
  • purchase, expiry, signature and verification timestamps, the verification source (app sync or Apple server notification) and, where applicable, grace-period, refund, revocation, upgrade and renewal status,
  • the technical environment (production or test environment),
  • the identifier, type and processing result of App Store server notifications and cryptographic hashes of verified signed messages,
  • for monthly free allowances, the relevant event action, a technical operation identifier, calendar month, reservation or completion status, and the subscription tier used for the decision.

The signed JWS supplied by StoreKit or Apple is processed transiently for cryptographic verification. We do not persist the complete JWS; we store only the information required for entitlement, status, duplicate and tampering protection, together with a SHA-256 hash. We do not receive or store full payment-card, bank-account or other payment details; Apple processes those within the App Store.

3.2 Internal usage and diagnostic data

For internal product, operational and security analytics, we may analyse account-linked activities and product interactions, such as events created or attended, participation status and features used, together with counts of messages and media. We also process technical performance and diagnostic data, such as loading or execution duration, error states and feature reliability. Message and media counts show how many items exist; they are not used to analyse their content for advertising. Content may independently be processed where required for transmission, display, safety, reporting or moderation. We do not build advertising profiles from this data.

4. Purposes and legal bases

We process data to provide accounts and requested features under Article 6(1)(b) GDPR, based on consent under Article 6(1)(a), to comply with legal duties under Article 6(1)(c), and for legitimate interests under Article 6(1)(f), particularly safety, moderation, fraud prevention, service stability, legal defence and product improvement.

We process subscription and entitlement data in particular to perform the subscription contract, assign and restore purchased features, calculate usage allowances, and respond to renewals, expiry, grace periods, refunds or revocations under Article 6(1)(b) GDPR. Preventing duplicate processing, unauthorised activation, manipulation and fraud, and maintaining technical traceability serve our legitimate interests in a secure and reliable subscription service under Article 6(1)(f) GDPR. Article 6(1)(c) GDPR applies where retention or evidence is required by law.

Under Swiss law, processing follows the principles of lawfulness, proportionality, purpose limitation, transparency and data security. Consent can be withdrawn at any time with future effect.

5. Location and launch areas

Cliqly launches in Frankfurt with a 17 km radius and Geneva with a 20 km radius. The Geneva launch area may include the Swiss and supported French parts of the cross-border metropolitan region.

Device location is processed only with iOS permission and for location-based features. The publicly readable profile stores neither the precise position nor a kilometre-level location for this purpose. It contains only the centre point of the supported Cliqly launch area as a broad regional assignment. Precise device location is not persistently stored as the profile location.

Event hosts choose between an exact and approximate address. Exact meeting details are disclosed only in line with the access status shown in the app.

5.1 Optional calendar export

Only when a user expressly selects “Add to Calendar” does Cliqly request write-only iOS calendar access and create the selected event through EventKit in the device calendar. Cliqly does not read existing calendar entries, upload calendar content to the Cliqly backend or use calendar data for analytics. Whether Apple Calendar synchronises an entry through iCloud depends on the user's Apple and calendar settings. Permission can be changed at any time in iOS.

6. Visibility inside Cliqly

Profile, event, Crew and network data is displayed only as required by the relevant feature and chosen visibility settings. Private profiles and non-public content are intended only for the authorised audience. Hosts and confirmed participants may see additional event information.

7. Photos and media

Media is processed only when selected or uploaded. iOS photo permissions can be changed at any time. Uploaders and authorised hosts can delete media; other users can report it. Reported media may be preserved until review is complete.

8. Chats and retention

Event chats are restricted to hosts and confirmed participants. Regular event-chat messages are scheduled for deletion 24 hours after the event starts. Crew planning signals are normally deleted after 14 days. Content linked to an open report may be restricted and retained until moderation and applicable appeal periods are complete.

Other data is kept only as long as required for the account, feature, safety purpose, legal obligation or claim. Retention depends on the data category, purpose and any unresolved dispute or report.

Protected content notices, related decision records and appeals are normally deleted no later than 18 months after the notice was received. An appeal remains available for at least six months after the communicated decision. Open proceedings, mandatory law or specifically required legal claims may require longer, purpose-limited restriction.

The active appAccountToken mapping is needed for the life of the Cliqly account. Active subscriptions and subscriptions in an Apple grace period are not removed by the regular retention cleanup. While an account remains open, expired or revoked subscription chains and their verified transaction records are deleted 36 months after the relevant expiry or revocation date. Allowance operations are deleted 13 months after the start of the relevant calendar month. Technical receipt records for App Store server notifications, particularly the notification identifier, processing result and JWS hash, are kept for 180 days and then deleted. When an account is deleted, the account-linked token mapping, subscription chains, transaction records and allowance operations are removed from the active backend. Mandatory statutory retention duties and the preservation of specifically required legal claims remain unaffected; in that case, processing is restricted to the necessary purpose.

9. Moderation and safety

A formal content notice can also be submitted without a Cliqly account through the secure structured Cliqly notice portal.

A notice identifies the affected content, selected reason, technical references and context required for review. A formal notice of potentially illegal content must give its exact location, a substantiated explanation, any relevant legal basis and a good-faith confirmation. Receipt and material decisions are confirmed electronically where contact details are available and communication is legally permitted.

For a material decision, the affected person and, where provided for, the reporter receive the outcome, measure, material facts, contractual or legal basis, use of automated means and available redress. Removal, visibility, warning or account-restriction decisions are made by an authorised person; safety filters may only block technically or prioritise content for review. A reasoned appeal remains available for at least six months for renewed human review.

10. Notifications

Push notifications are sent only after iOS permission. Settings can be changed in Cliqly or iOS. Apple processes a device token for delivery. Notification content is minimised where feasible.

11. Service providers

We use service providers only where needed to operate and secure Cliqly, particularly:

  • Apple for Sign in with Apple, CloudKit, Apple Push Notification Service, WeatherKit, MapKit, StoreKit and related iOS services,
  • Supabase for selected authentication, role, safety, moderation and server-side backend functions, including protected storage and verification of subscription entitlements and usage allowances.

Apple independently administers App Store purchases and payments under Apple's terms and supplies us with verifiable transaction, renewal, expiry, refund and revocation information. Supabase processes data required for our backend functions on our instructions where it acts as a processor under data-protection law.

CloudKit remains the primary store for app content intended for Apple infrastructure. Publicly readable CloudKit records are limited to profile, event and aggregated community data required for discovery and display. Private profile state, legal acknowledgement state, follow relationships and non-aggregated rating details are kept privately where the feature requires them. Supabase supplements this as a server-side trust authority for account binding, roles and moderation, protected messaging and Crew access, event participation and allowances, subscription entitlements, content notices, decisions, appeals and deletion workflows.

Using Supabase may generate operational Auth, API and Edge Function logs. These may include the IP address, user agent, timestamp, requested endpoint, status or error code, technical region and request or execution duration. We use them for authentication and access protection, secure operation, abuse and error detection, and technical troubleshooting. Retention for Auth, API and Edge Function logs is governed separately by the periods applicable to the Supabase project, product, plan and configuration in use; these periods may change and are therefore not promised as a fixed number of days. The current Supabase documentation and project configuration apply. Access is restricted to personnel who need it.

Providers process data according to their function and applicable contractual and legal requirements. We select and review them so that the level of protection required for the relevant processing is maintained through contractual or legal obligations and appropriate technical and organisational measures. Cliqly does not perform cross-app or cross-website tracking for advertising or advertising measurement, disclose data to data brokers or sell personal data. We do not share data for third-party advertising or display third-party advertising. Optional subscriptions finance the operation and development of Cliqly.

12. International transfers

Where data is processed outside the EU, EEA or Switzerland, we use legally recognised safeguards where required, such as adequacy decisions or standard contractual clauses, and consider Swiss data-protection requirements.

13. Export and account deletion

Users can request an export and delete their account in the app. Deletion ends the session and initiates deletion or irreversible anonymisation of associated personal data and relationships. A later permitted registration starts a new profile without previous follows or profile data.

Deleting the Cliqly account does not cancel an Apple subscription. It must be cancelled separately in Apple's subscription management. Apple may continue to process purchase and subscription data under its own legal obligations and send subscription-status server notifications after the Cliqly account has been deleted. If a Cliqly account is later created with the same account verified through Sign in with Apple, the pseudonymous app-specific association identifier may be derived again and a still-active subscription can be reassociated only after renewed cryptographic verification; deleted profile and network data is not restored.

Limited exceptions apply where data must be restricted and retained for legal duties, unresolved reports, enforced bans, security evidence or legal claims. A minimal identifier may be retained to prevent evasion of a permanent ban.

14. Automated decisions

Cliqly uses recommendations, rankings and safety filters. It does not make solely automated decisions intended to produce legal or similarly significant effects. Human review of a material moderation decision can be requested at datenschutz@cliqly.de.

15. Your rights

Subject to applicable law, you may have rights to access, correction, deletion, restriction, portability, objection, withdrawal of consent and complaint to a supervisory authority. People in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC). People in the EU or EEA may contact the authority at their habitual residence.

Requests can be sent to datenschutz@cliqly.de. We may request proportionate identity verification to prevent unauthorised disclosure.

16. Security

We use appropriate technical and organisational measures, access controls, role checks, transport encryption and data minimisation. No system is entirely risk-free. Incidents are assessed and, where required, reported under applicable law.

17. Changes

We update this Policy when functions, providers or legal requirements materially change. The current version is available in the app and material changes will be communicated appropriately.

Kaynak UG (haftungsbeschränkt) Erfweiler Str. 12 · 66994 Dahn · Germany
© 2026 Kaynak UG (haftungsbeschränkt)
Home Privacy Policy Terms of Service Legal notice