Buddy

Privacy policy

This is a translation of the German Datenschutzerklärung. The German version is the legally binding one.

General information

  1. This privacy policy contains detailed information about what happens to your personal data when you visit our website https://findmybuddys.com/. Personal data is any data that can be used to identify you personally. When processing your data we strictly follow the statutory provisions, in particular the General Data Protection Regulation ("GDPR"), and we attach great importance to your visit to our website being completely secure.

Controller

  1. The controller responsible under data protection law for the collection and processing of personal data on this website is:

    Name: NM Software Development UG (haftungsbeschränkt)
    Represented by: Nikolaus Alexander Klemm, Managing Director
    Street, number: Marc-Chagall-Str. 27
    Postcode, town: 04425 Taucha
    Country: Germany
    Email: management@nm-development.de
    Phone: +49 160 5419009

Data protection officer

  1. The controller's internal data protection officer is:

    Name: Nikolaus Alexander Klemm
    Street, number: Marc-Chagall-Str. 27
    Postcode, town: 04425 Taucha
    Country: Germany
    Email: niko.klemm@nm-development.de
    Phone: +49 160 5419009

    Any data subject may contact our data protection officer directly at any time with questions and suggestions about data protection.

Access data (server log files)

  1. When you visit our website we collect and automatically store, in so-called server log files, access data that your browser transmits to us automatically. This is:
    • the browser type and version of your PC
    • the operating system used by your PC
    • the date and time of the server request
    • the IP address currently used by your PC (where applicable in anonymised form)
  2. As a rule we cannot, and do not intend to, link this data to a person. This data is processed pursuant to Art. 6(1)(f) GDPR to safeguard our legitimate interest in improving the stability and functionality of our website.

Cookies

  1. To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies. These are small text files that are placed on your device. Cookies cannot run programs or transfer viruses to your computer system.
  2. Cookies that are required to carry out the electronic communication process or to provide certain functions you have requested are stored on the basis of Art. 6(1)(f) GDPR. We have a legitimate interest in storing cookies for the technically error-free and optimised provision of our services. Where other cookies (e.g. cookies to analyse your browsing behaviour) are stored, they are dealt with separately in this privacy policy.
  3. Most of the cookies we use are so-called "session cookies". They are deleted automatically at the end of your visit. Other cookies remain stored on your device until you delete them. These cookies allow us to recognise your browser on your next visit.
  4. You can set your browser so that you are informed when cookies are set and allow cookies only in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when the browser is closed. If cookies are deactivated, the functionality of this website may be limited.

Contacting us

  1. If you contact us, including by email, the data you transmit, including your contact details, is stored in order to process your enquiry or to be available for follow-up questions. This data is not passed on without your consent.
  2. Your data is processed exclusively on the basis of your consent (Art. 6(1)(a) GDPR). You may revoke consent you have already given at any time. An informal message by email is sufficient for the revocation. The lawfulness of the data processing carried out until the revocation remains unaffected by the revocation.
  3. Data you transmit remains with us until you ask us to delete it, revoke your consent to its storage, or there is no longer any need to store the data. Mandatory statutory provisions, in particular retention periods, remain unaffected.

Use and disclosure of data

  1. We will neither sell nor otherwise market to third parties the personal data you provide to us, e.g. by email (e.g. your name and address or your email address). Your personal data is processed only for correspondence with you and only for the purpose for which you provided the data to us.

    Data collected automatically when you visit our website is used only for the purposes stated above. The data is not used for any other purpose.

    We assure you that we do not otherwise pass your personal data on to third parties unless we are legally obliged to do so or you have given us your prior consent.

SSL or TLS encryption

  1. For security reasons and to protect the transmission of confidential content, such as enquiries you send to us as the site operator, our website uses SSL or TLS encryption. You can recognise an encrypted connection by the browser's address line changing from "http://" to "https://" and by the padlock symbol in your browser bar.
  2. When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Retention period

  1. Personal data communicated to us via our website is stored only until the purpose for which it was entrusted to us has been fulfilled. Where retention periods under commercial and tax law must be observed, the retention period for certain data may be up to 10 years.

The Buddy app

This section describes which data the Buddy app for iOS and Android processes, for what purpose, on which legal basis and for how long. The controller and the data protection officer are the same as above. The app is intended exclusively for adults (18 years and older). The data-subject rights in the next section apply to the app just as they do to the website.

The website itself

The website findmybuddys.com sets no cookies, uses no analytics or tracking services and embeds no third-party scripts. The website's fonts are served from our own server; the website makes no connection to third-party servers. The website is served through Cloudflare Pages (see "Hosting and recipients").

Sign-in and account

You sign in to the app exclusively with an existing Apple, Google or Microsoft account. The sign-in takes place directly between you and that provider on your device; the provider's own privacy policy governs it. Buddy receives a signed sign-in token from the provider and stores from it:

  • the provider and its user identifier, as the pseudonymous key of your Buddy account,
  • your display name from the token. If the provider sends no name (Apple never does), you may choose a name once when the account is created, or accept the suggested placeholder (e.g. "Buddy K7M4"),
  • the email address from the token. It is used solely to send you the download link of your data export (see "Your rights in the app"). With Apple this may be a "Hide My Email" relay address.

Buddy stores no password. Buddy issues its own access token for the session, which expires after 60 minutes; there is no long-lived sign-in token. Buddy sends no user data to the sign-in providers; the app only fetches their public keys, which are used to verify the tokens.

Legal basis: Art. 6(1)(b) GDPR (provision of the service you use by creating an account).

Profile

In your profile we process:

  • your date of birth, to make sure you are at least 18 years old and for the age filters of events,
  • optionally your gender, your languages and your interests, chosen from a fixed list,
  • your home area as a coarse hexagonal cell (H3 cell). Buddy stores no precise location coordinates for people, only this cell. If you let the app determine the area from your device's location, the operating system asks your permission first,
  • optionally a profile photo. On upload the image is re-encoded and reduced to at most 512 pixels on the longer side and roughly 300 KB; metadata such as EXIF or GPS tags is removed in the process. The photo is kept in private storage and is shown only to signed-in users inside the app, never through a public address,
  • your privacy settings (visibility of your activity to buddies, forwarding of buddies-only events, showing your name to other participants) and your preferred app language.

Legal bases: we process the display name, date of birth, settings and home area under Art. 6(1)(b) GDPR; the feed cannot work without the home area. Reading the device location to determine the home area is based on Art. 6(1)(a) GDPR, the consent you give in the iOS or Android location prompt; alternatively you enter the area by hand. We process the profile photo under Art. 6(1)(a) GDPR on the basis of your consent, which you give by uploading it and can withdraw at any time by removing the photo in the app.

Events, buddies and messages

When you propose an event we store the activity, the time, the hexagonal cell of the location, the visibility (public or buddies only), an optional participant limit and filters (gender, age, languages), and the list of participants. As the host you may additionally set an exact meeting place (an address, a venue or your current location). The exact meeting place is visible only to you and the current participants; everyone else sees only the cell.

Buddy requests, buddy connections, your buddy code, blocks and your participation in events are stored so the app can show and enforce them. If you share an event by link, the link contains only a random key and no data about you or the event.

Every event has a text conversation that the host and the current participants can read and write. Deleted messages are replaced by a placeholder. On your device the newest 200 messages per conversation are cached; this cache is deleted when you sign out.

Legal basis: Art. 6(1)(b) GDPR.

Reporting, blocking and support

You can report people, events and messages in the app, block people and, as a host, remove participants from your event. Reports, activity suggestions and support requests are stored as cases that contain only your pseudonymous user identifier, no name and no email address. For each case our team receives an email notification that contains only the kind of case, the chosen reason, the case number and the time, never your free text. A person decides on reports; you receive a notification once your report has been reviewed. We do not share outcomes concerning other accounts.

Legal basis: Art. 6(1)(b) GDPR for handling your request; Art. 6(1)(f) GDPR for retaining reports as evidence in cases of abuse (see "Retention in the app").

Notifications

Notifications (e.g. a new participant on your event, a change or cancellation, a new message in a conversation, a reminder, an accepted buddy request, the outcome of a report) are generated in your language and stored in the app's notification centre. If you allow push notifications in the operating system, the app additionally registers your device with Azure Notification Hubs (Microsoft). This stores your device's push token, an installation identifier and your pseudonymous user identifier. Push notifications about new messages contain the sender's name and the message text (truncated to 180 characters). The registration is removed when you sign out and when the account is deleted. Without push permission the notification centre in the app remains complete.

The push token is generated on your device and is read and registered by the app only after you allow notifications in the iOS or Android system prompt; that is the consent § 25(1) TDDDG requires. If you decline the prompt, the app registers nothing. If you later turn notifications off in the system settings, the operating system stops delivering push notifications; the registration on our side is deleted when you sign out and when the account is deleted. The legal basis for the content of the notifications is Art. 6(1)(b) GDPR.

Error and crash reports

If the app crashes or an error occurs, the app sends a report to a Sentry instance operated by us (sentry.tools.nm-development.de). No third party is involved. A report contains the kind of error, the technical trace (stack trace), the device model, the operating system version and the app version. The app sends no screenshots, no account data and no location cell; the hexagonal cell is removed from all addresses before sending. The reports are used only to find and fix errors.

Error and crash reports are deleted automatically after 90 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable app).

Data on your device

The app stores on your device a random identifier generated per installation, your language choice, the installation identifier for push notifications, your session token in the operating system's keychain, and the message cache described above. On sign-out the cache, the session and the push registration are deleted; when you uninstall the app the operating system removes all of its data.

Hosting and recipients

  • Server: The Buddy services run on a server managed by us at netcup GmbH (Karlsruhe, Germany), in a data centre in Austria (EU).
  • Microsoft Azure (Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) in the "Germany West Central" region (Frankfurt am Main): Blob Storage for profile photos and data exports, Key Vault for configuration secrets, Service Bus as the message broker between our services, and Azure Notification Hubs for push notifications, also in the "Germany West Central" region (Frankfurt am Main).
  • Cloudflare (contracting entity: Cloudflare Germany GmbH): serves this website and forwards the app's connections to our server. Cloudflare sees the caller's IP address in doing so. The basis is Cloudflare's standard data processing agreement, which is part of its terms. Where data is transferred to Cloudflare, Inc. in the USA, Cloudflare states that it relies on its certification under the EU-US Data Privacy Framework and on the EU Standard Contractual Clauses.
  • Resend as the email delivery service for the data-export link and for the team notifications about new cases. Resend states that it stores customer data, including message content and delivery logs, in the USA. A data processing agreement under Art. 28 GDPR is in force for every Resend account; transfers out of the EEA are made under the EU Standard Contractual Clauses incorporated into that agreement, and additionally under the EU-US Data Privacy Framework.
  • Apple, Google and Microsoft as sign-in providers, each as an independent controller for the sign-in process.

We do not sell data. We disclose data to authorities only when we are legally obliged to.

Transfers to third countries

All Buddy services and the Azure resources we use are located in the European Union. For sign-in: your sign-in takes place directly with the provider you choose. For users in the European Economic Area, according to the providers' published privacy policies, these are Apple Distribution International Ltd. (Ireland), Google Ireland Ltd. (Ireland) and Microsoft Ireland Operations Ltd. (Ireland). According to their own statements the providers base transfers to third countries on the following mechanisms: Apple on the EU Commission's Standard Contractual Clauses; Google on adequacy decisions, the EU-US Data Privacy Framework and Standard Contractual Clauses; Microsoft on the EU-US Data Privacy Framework and Standard Contractual Clauses. Buddy itself sends no user data to these providers. Transfers to Cloudflare, Inc. and to Resend in the USA are made under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses, as described under "Hosting and recipients".

Retention in the app

  • Account and profile data, events, buddy connections and settings: until you delete your account.
  • Data export: the download link is valid for 7 days. The export file is deleted from storage automatically 7 days after it was created. A new request replaces the previous one.
  • Reports and support cases: after you delete your account your name is removed from the case and your own support texts are deleted; the pseudonymised case is kept for about 12 months as evidence in cases of abuse and is then deleted.
  • Messages in event conversations: after you delete your account your messages remain in the group conversation so that it stays readable for the other participants; your name and your photo are removed permanently, so the messages can no longer be attributed to a person.
  • Session: an access token expires after 60 minutes, and after 24 hours at the latest. Until then a deleted account can technically still make requests; the app signs you out immediately when you delete.
  • Push registration: until you sign out or delete the account.

Your rights in the app

Under Profile → “Privacy” tab → “Safety & data” → “Account & data” you can do the following yourself:

  • Deactivate account: your profile and your events are hidden until you next sign in.
  • Export my data: you receive, at the email address of your sign-in account, a link to a file with all data our services hold about your account (Art. 15 and 20 GDPR). The link is valid for 7 days.
  • Delete account: your account is deleted irrevocably. Every service deletes its data about your account, including the profile photo and the push registration; the exceptions for reports and messages described above apply. The account is deleted immediately once you confirm in the app, and you are signed out; there is no separate confirmation message.

You can assert all further rights from the section "Rights of data subjects" with our data protection officer at any time.

Point of contact under the Digital Services Act

You can report illegal content directly in the app via "Report" or by email. Our point of contact for authorities and users under Art. 11 and 12 of Regulation (EU) 2022/2065 (Digital Services Act) is our managing director personally: Nikolaus Alexander Klemm, Managing Director, email: niko.klemm@nm-development.de, phone: +49 160 5419009. You can reach us in German and English.

Rights of data subjects

  1. With regard to the personal data concerning you, as a data subject of the data processing you have the following rights against the controller in accordance with the statutory provisions:
    1. Right to withdraw consent

      Many data processing operations are possible only with your express consent. Where the processing of your data is based on your consent, you have the right under Art. 7(3) GDPR to withdraw consent once given at any time with effect for the future. Withdrawing consent does not affect the lawfulness of the processing carried out on the basis of the consent until its withdrawal. Storage of the data for billing and accounting purposes is not affected by a withdrawal.

    2. Right of access

      Under Art. 15 GDPR you have the right to obtain from us confirmation as to whether we process personal data concerning you. Where that is the case, you have the right to access the personal data we process about you, the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients to whom your data has been or will be disclosed, the envisaged storage period or the criteria used to determine that period, the existence of a right to rectification, erasure, restriction of processing, objection to processing, and to lodge a complaint with a supervisory authority, the origin of your data where it was not collected from you by us, the existence of automated decision-making including profiling and, where applicable, meaningful information about the logic involved and the significance and envisaged consequences of such processing for you, as well as your right to be informed of the safeguards under Art. 46 GDPR that apply when your data is transferred to third countries.

    3. Right to rectification

      Under Art. 16 GDPR you have the right to obtain at any time the rectification without undue delay of inaccurate personal data concerning you and/or the completion of your incomplete data.

    4. Right to erasure

      Under Art. 17 GDPR you have the right to obtain the erasure of your personal data where one of the following grounds applies:

      1. Your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
      2. You withdraw the consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal ground for the processing.
      3. You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
      4. The personal data has been unlawfully processed.
      5. The personal data has to be erased for compliance with a legal obligation under Union or Member State law to which we are subject.
      6. The personal data has been collected in relation to the offer of information society services referred to in Art. 8(1) GDPR.

      This right does not apply, however, to the extent that processing is necessary:

      1. for exercising the right of freedom of expression and information;
      2. for compliance with a legal obligation which requires processing by Union or Member State law to which we are subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in us;
      3. for reasons of public interest in the area of public health in accordance with Art. 9(2)(h) and (i) and Art. 9(3) GDPR;
      4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89(1) GDPR, in so far as the right is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
      5. for the establishment, exercise or defence of legal claims.

      Where we have made your personal data public and are obliged pursuant to the above to erase it, we shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you as the data subject have requested the erasure by such controllers of any links to, or copy or replication of, that personal data.

    5. Right to restriction of processing

      Under Art. 18 GDPR you have the right to obtain the restriction of processing (blocking) of your personal data. To do so you may contact us at any time at the address given in the legal notice. The right to restriction of processing exists in the following cases:

      1. If you contest the accuracy of the personal data we hold about you, we usually need time to verify this. For the duration of the verification you have the right to request the restriction of the processing of your personal data.
      2. If the processing of your personal data was or is unlawful, you may request the restriction of data processing instead of erasure.
      3. If we no longer need your personal data but you need it for the exercise, defence or establishment of legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
      4. If you have objected pursuant to Art. 21(1) GDPR, a balance must be struck between your interests and ours. As long as it has not yet been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

      Where you have restricted the processing of your personal data, that data may, with the exception of storage, be processed only with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the EU or of a Member State.

    6. Right to be informed

      If you have asserted the right to rectification, erasure or restriction of processing against us, we are obliged to communicate that rectification or erasure of the data or restriction of processing to each recipient to whom your personal data has been disclosed, unless this proves impossible or involves disproportionate effort. Under Art. 19 GDPR you have the right to be informed about those recipients on request.

    7. Right not to be subject to a decision based solely on automated processing, including profiling

      Under Art. 22 GDPR you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

      This does not apply if the decision

      1. is necessary for entering into, or the performance of, a contract between you and us,
      2. is authorised by Union or Member State law to which the controller is subject and which lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
      3. is based on your explicit consent.

      However, decisions in the cases referred to in (a) to (c) may not be based on special categories of personal data under Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) applies and suitable measures to safeguard your rights and freedoms and legitimate interests are in place.

      In the cases referred to in (a) and (c) we implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

    8. Right to data portability

      Where the processing is based on your consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and is carried out by automated means, you have the right under Art. 20 GDPR to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller, or to have it transmitted to another controller, where technically feasible.

    9. Right to object

      Where we base the processing of your personal data on the balancing of interests under Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data; this also applies to profiling based on that provision. The respective legal basis on which processing is based can be found in this privacy policy. If you object, we will no longer process your personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims (objection under Art. 21(1) GDPR).

      Where your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing; this also applies to profiling to the extent that it is related to such direct marketing. If you object, your personal data will subsequently no longer be used for direct marketing purposes (objection under Art. 21(2) GDPR).

      In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.

    10. Right to lodge a complaint with the competent supervisory authority under Art. 77 GDPR

      In the event of infringements of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement. The right to lodge a complaint is without prejudice to any other administrative or judicial remedy.

      The supervisory authority responsible for us is:

      Der Sächsische Datenschutzbeauftragte (Saxon Data Protection Commissioner)

      Postfach 11 01 32
      01330 Dresden

      Devrientstraße 5
      01067 Dresden
      Germany

      Phone: +49 351 85471-101

      Email: saechsdsb@slt.sachsen.de
      Web: https://www.saechsdsb.de/

Validity and changes to this privacy policy

  1. This privacy policy is valid from 15 September 2026. We reserve the right to change this privacy policy at any time in compliance with the applicable data protection provisions. This may be necessary, for example, to comply with new statutory provisions or to take account of changes to our website or new services on our website. The version available at the time of your visit applies.
  2. Should this privacy policy be changed, we intend to announce changes to our privacy policy on this page, so that you are fully informed about which personal data we collect, how we process it and under which circumstances it may be disclosed.

©2002-2026 RECHTSDOKUMENTE (Sequiter Inc.)