Datenschutzerklärung

Der Schutz deiner personenbezogenen Daten ist uns ein wichtiges Anliegen. In dieser Datenschutzerklärung erläutern wir wie wir Daten erheben, verarbeiten und nutzen wenn du die peerio App oder die Website peerio.io verwendest. Wir halten uns dabei an die Vorgaben der Datenschutz-Grundverordnung (DSGVO).

1. Verantwortlicher

Tomoveo Ltd., 8011 Paphos, Zypern

E-Mail: [email protected]

Vollständige Anbieterangaben im Impressum.

2. Registrierung und Nutzerkonto

Zur Nutzung der peerio App ist eine Registrierung erforderlich. Wir verarbeiten dabei: E-Mail-Adresse, Vor- und Nachname, Profilfoto, Geschlecht (mit Möglichkeit zur Nichtangabe), Angaben zur unternehmerischen Tätigkeit (Gründungsphase, Branche, Team-Aufstellung, Link zu deiner Gründeraktivität), eine Selbstbeschreibung, deinen Ort, Spracheinstellungen sowie Zeitstempel der Registrierung, deiner Altersbestätigung und deiner Zustimmung zu diesen Bedingungen und zum Community Kodex. Der Nachname wird nicht an andere Nutzer ausgespielt.

Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO). Mit der Registrierung bestätigst du, mindestens 18 Jahre alt und unternehmerisch tätig zu sein. Im Rahmen des Onboardings fragen wir optional ab, wie du auf peerio aufmerksam geworden bist. Diese Angabe ist freiwillig, wird zur Verbesserung unserer Marketingmaßnahmen genutzt und nicht an Dritte weitergegeben. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).

3. Nutzung der App

Registrierung via Apple oder Google

Du kannst dich mit deinem Apple- oder Google-Konto registrieren. In diesem Fall übermittelt Apple bzw. Google uns grundlegende Profildaten (Name, E-Mail-Adresse). Welche Daten übermittelt werden, kannst du beim jeweiligen Anbieter einsehen und steuern. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Peers und Meets

Inhalte die du in der App erstellst werden gespeichert und anderen Nutzern gemäß deinen Sichtbarkeitseinstellungen angezeigt. Peers sind Beiträge die du erstellst und in denen andere Nutzer schreiben und diskutieren können. Meets sind Treffen die du eigenverantwortlich organisierst und mit Standort und Zeitangabe für andere sichtbar machen kannst. Peers sind zeitlich begrenzt: Nach Ablauf einer in der App angegebenen Frist erscheinen sie nicht mehr in der Übersicht und auf der Karte und sind für neue Nutzer nicht mehr auffindbar. Für Teilnehmer und den Ersteller bleibt der zugehörige Chat weiter nutzbar; er wird gelöscht, wenn 90 Tage lang keine Nachricht mehr geschrieben wurde. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Anonymer Modus

Peers können anonym erstellt werden. In diesem Fall werden dein Name und dein Profilfoto anderen Nutzern nicht angezeigt, und deine Identität wird auch technisch nicht an sie übermittelt, weder an Außenstehende noch an die Teilnehmer des Peers. Innerhalb des anonymen Peers erscheinst du für alle als „Anonymus" mit einer festen Nummer. Der Beitrag bleibt intern deinem Konto zugeordnet, damit du ihn verwalten kannst. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Verbindungen und peerio ID

Wenn du dich mit anderen Nutzern verbindest, wird diese Verbindung gespeichert und ist Grundlage für weitere Funktionen wie Chat und Matching. Jedem Konto wird zudem eine eindeutige peerio ID zugewiesen; sie dient der internen Identifikation und kann von dir selbst weitergegeben werden. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Matching

peerio nutzt ein automatisiertes Matching-System um passende Nutzer vorzuschlagen. Die Analyse basiert ausschließlich auf von dir selbst eingegebenen beruflichen Angaben. Zur Verbesserung des Matchings werden textbasierte Profilangaben mithilfe eines beauftragten KI-Dienstes (derzeit OpenAI Ireland Ltd., Irland) in eine maschinell auswertbare, nicht rückübersetzbare Form überführt und gespeichert. Diese Verarbeitung dient ausschließlich der Matchingfunktion. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Das Matching-Ergebnis ist ein Vorschlag ohne verbindlichen oder rechtserheblichen Charakter im Sinne von Art. 22 DSGVO. Das Matching ist Teil der vertraglich geschuldeten Leistung und kann als Funktion nicht abgeschaltet werden. Du kannst jedoch die Datengrundlage einschränken, indem du der Auswertung deiner Verhaltensdaten widersprichst; das Matching arbeitet dann nur noch auf Grundlage deiner Profilangaben.

KI-gestützte Funktionen

Beiträge werden vor der Veröffentlichung automatisiert eingeordnet und daraufhin geprüft, ob sie den Regeln des Community Kodex entsprechen. Wir setzen dafür einen beauftragten KI-Dienst ein (derzeit Anthropic, USA). Übermittelt werden die eingegebenen Inhalte sowie einzelne von uns freigegebene Beispieltexte. Es findet keine Analyse persönlicher oder sensibler Merkmale statt. Wird ein Beitrag abgelehnt, erhältst du einen Hinweis und kannst den Beitrag überarbeiten oder die Entscheidung über die im Impressum genannte Adresse überprüfen lassen. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO) sowie unser berechtigtes Interesse am Betrieb einer sicheren Plattform (Art. 6 Abs. 1 lit. f DSGVO).

Nachrichten, Chat und Datei-Uploads

Nachrichten sowie im Chat geteilte Dateien und Bilder werden für den Betrieb des Chat-Dienstes gespeichert. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Nutzungsverhalten

Wir erfassen Nutzungsdaten zur Verbesserung des Matchings und der App. Dazu zählen insbesondere: welche Peers du ansiehst, welchen du beitrittst und wie du dich dort beteiligst, welche Profile du aufrufst sowie deine Suchanfragen in der App. Aus diesen Signalen entwickeln wir ein Interessenprofil, das die Qualität deiner Vorschläge mit der Zeit verbessert. Dabei kommt ein beauftragter KI-Dienst zum Einsatz (derzeit OpenAI Ireland Ltd., Irland); übermittelt werden ausschließlich entpersonalisierte Angaben, nicht die ursprünglichen Texte. Beiträge, die du anonym erstellst, fließen nicht in dein Interessenprofil ein. Suchanfragen speichern wir zu diesem Zweck für bis zu 90 Tage. Diese Daten werden in aggregierter oder pseudonymisierter Form ausgewertet. Soweit sie dabei keinen Personenbezug mehr aufweisen, können sie auch für Marktforschung, Investorenkommunikation sowie zur kommerziellen Verwertung genutzt werden. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).

Du kannst der Verarbeitung deiner Verhaltensdaten für das Interessenprofil jederzeit widersprechen; dafür gibt es in den Datenschutz-Einstellungen der App einen Schalter. Widersprichst du, werden bereits erhobene Verhaltensdaten gelöscht und keine neuen mehr erfasst; das Matching arbeitet dann nur noch auf Grundlage deiner Profilangaben.

peerio+ und Einladungscodes

Wir speichern ob du das kostenlose Basismodell oder peerio+ nutzt sowie den jeweiligen Nutzungsstatus. Mit peerio+ erhältst du einen persönlichen Einladungscode. Löst jemand deinen Code ein, speichern wir die Einlösung mit beiden Konten und dem Zeitpunkt, damit wir die Nutzung des Codes begrenzen und Missbrauch erkennen können. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Profilbild

Du kannst ein Profilbild hochladen. Dieses wird anderen Nutzern angezeigt. Zur Sicherstellung der Echtheit wird das hochgeladene Bild automatisiert daraufhin geprüft, ob es ein menschliches Gesicht zeigt. Dafür wird es an einen beauftragten KI-Dienst übermittelt (derzeit Anthropic, USA). Es findet keine biometrische Analyse, keine Identifikation und kein Abgleich mit externen Datenbanken statt. Das Profilbild wird mit deinem Konto gespeichert und bei Kontolöschung entfernt. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Standort im Profil

Du gibst in deinem Profil einen Ort an. Gespeichert werden der Ortsname und die ungefähren Koordinaten dieses Ortes, nicht dein tatsächlicher Aufenthaltsort. Der Ort ist für andere Nutzer sichtbar. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Fotos bei Treffen

In den Chats zu Meets und Events kannst du über die Kamerafunktion Fotos aufnehmen und teilen. Solche Fotos können Personen abbilden, sind für alle Teilnehmer des jeweiligen Chats sichtbar und können von diesen gespeichert und weiterverbreitet werden. Lade nur Fotos hoch, mit deren Veröffentlichung alle abgebildeten Personen einverstanden sind. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Prüfung deiner Angaben

Den in deinem Profil angegebenen Link prüfen wir automatisiert daraufhin, ob er zu unserem Angebot passt. Dabei rufen wir die Seite ab und setzen einen beauftragten KI-Dienst ein. Gespeichert werden die Adresse, das Ergebnis und eine von dir dazu abgegebene Erklärung. Rechtsgrundlage ist unser berechtigtes Interesse am Betrieb einer passenden Community (Art. 6 Abs. 1 lit. f DSGVO).

Links und externe Angaben im Profil

Du kannst in deinem Profil externe Links angeben (z.B. Website oder Social-Media-Profile). Diese Angaben sind für andere Nutzer sichtbar und werden mit deinem Profil gespeichert. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Empfehlungslinks

peerio stellt einen allgemeinen Empfehlungslink bereit, der keine Kennung enthält und keinem einzelnen Nutzer zugeordnet wird. Damit wir den Hinweis, peerio weiterzuempfehlen, nur aktiven Nutzern und nicht zu häufig anzeigen, zählen wir bestimmte Aktivitäten in der App. Dieser Zähler ist deinem Konto zugeordnet und wird nach jeder Anzeige zurückgesetzt. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).

Gerätedaten

Für den Betrieb der App und zur Fehlerbehebung verarbeiten wir technische Gerätedaten wie Geräte-ID, Betriebssystem und App-Version. Tritt ein Fehler oder Absturz auf, wird ein technischer Fehlerbericht an einen beauftragten Dienstleister übermittelt (derzeit Sentry, USA). Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).

Inaktive Konten

Bei dauerhafter Inaktivität eines Kontos sind wir berechtigt, dieses nach vorheriger E-Mail-Benachrichtigung zu deaktivieren oder zu löschen. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).

Benachrichtigungseinstellungen

Du kannst in den App-Einstellungen steuern welche Push-Benachrichtigungen und E-Mail-Benachrichtigungen du erhalten möchtest. Deine Einstellungen werden gespeichert und jederzeit änderbar. Push-Benachrichtigungen werden über die Infrastruktur von Apple bzw. Google übermittelt und setzen zusätzlich deine Zustimmung auf Geräteebene voraus; sie können über deine Geräteeinstellungen deaktiviert werden. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).

Meets auf der Karte

Du kannst Meets auf der Karte erstellen und mit Standortangabe für andere Nutzer sichtbar machen. Dabei kannst du optional Sichtbarkeitseinstellungen festlegen, z.B. nach Geschlecht; diese Einstellungen werden mit dem Meet gespeichert. Die Daten werden mit Zeitangabe und Standort gespeichert. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Für die Kartenanzeige nutzen wir Mapbox (USA). Dabei werden Kartenausschnitte von Mapbox-Servern geladen. Der eigene Gerätestandort wird nur live zur Anzeige in der Karte genutzt und nicht gespeichert. Standortangaben für Meets werden vom Nutzer manuell eingegeben und mit Koordinaten in unserer Datenbank gespeichert.

Persönliche Fragen und Icebreaker

Du kannst deinem Profil persönliche Fragen aus einer vorgegebenen Auswahl hinzufügen und selbst beantworten. Diese Angaben sind freiwillig und für andere Nutzer sichtbar. Zusätzlich kannst du eine eigene Frage formulieren, die anderen Nutzern angezeigt wird, bevor sie dir eine Kontaktanfrage senden. Wer dir eine Anfrage schickt, kann diese Frage freiwillig beantworten; nimmst du die Anfrage an, erscheinen Frage und Antwort als erste Nachrichten im gemeinsamen Chat. Lehnst du ab, wird die Antwort gelöscht. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Blockieren

Du kannst andere Nutzer blockieren. Eine Blockierung wirkt in beide Richtungen: Ihr werdet einander nicht mehr in den Vorschlägen angezeigt, seid über die Suche nicht mehr auffindbar, könnt einander keine Nachrichten, Kontaktanfragen oder Einladungen senden, und eure Profile werden füreinander ohne Namen und Bild dargestellt. Eine bestehende Verbindung wird aufgelöst. In gemeinsamen Peers und Meets bleibt die Mitgliedschaft bestehen; die jeweils andere Person erscheint dort ohne Namen und Bild. Blockierungen speichern wir mit deinem Konto und du kannst sie jederzeit in den Einstellungen aufheben. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Sperr-Mitteilung und Stellungnahme

Wird dein Konto gesperrt, erhältst du beim nächsten Öffnen der App eine Mitteilung mit der Begründung, der zugrunde liegenden Regel des Community Kodex und dem beanstandeten Inhalt im Wortlaut. Du kannst dazu Stellung nehmen; deine Stellungnahme wird gespeichert und geprüft, und du wirst über das Ergebnis informiert. Vor einer Sperrung prüfen wir den Vorgang. Setzen wir dabei automatisierte Verfahren ein, weisen wir in der Mitteilung ausdrücklich darauf hin. Du kannst deinen Standpunkt darlegen und die Entscheidung anfechten; über eine Beschwerde entscheidet stets eine Person. Rechtsgrundlage ist unser berechtigtes Interesse am Betrieb einer sicheren Plattform (Art. 6 Abs. 1 lit. f DSGVO); soweit eine Entscheidung automatisiert ergeht, stützt sie sich auf Art. 22 Abs. 2 lit. a DSGVO.

Moderation, Sanktionen und Beweisaufbewahrung

Wird ein Inhalt oder ein Profil gemeldet, prüfen wir die Meldung und entscheiden über eine Maßnahme. Dabei verarbeiten wir: die Meldung mit Grund und Beschreibung, den gemeldeten Inhalt im Wortlaut, die Konten des Melders und des Gemeldeten sowie den Zeitpunkt.

Führt eine Meldung zu einer Sperre, halten wir den Vorgang fest: die interne Kontonummer, die Art der Entscheidung, den Zeitpunkt, unsere Begründung, die zugrunde liegende Regel des Community Kodex sowie den beanstandeten Inhalt im Wortlaut. Diese Angaben bleiben auch dann bestehen, wenn das betroffene Konto anschließend gelöscht wird. Name, E-Mail-Adresse, Profilbild und Profilinhalte werden dabei nicht aufbewahrt. Rechtsgrundlage ist unser berechtigtes Interesse an Rechtsverteidigung und Plattformsicherheit (Art. 6 Abs. 1 lit. f DSGVO); die Aufbewahrung trotz eines Löschverlangens stützt sich auf Art. 17 Abs. 3 lit. e DSGVO.

Wir bewahren Angaben zum Sanktionsvorgang drei Jahre zuzüglich bis zum Ende des jeweiligen Kalenderjahres auf, beanstandete Inhalte im Wortlaut zwölf Monate. Läuft ein Widerspruchs- oder Streitverfahren, ruht die Löschung bis zu dessen Abschluss. Unabhängig von einer Sanktion halten wir bei jeder Kontolöschung den Zeitpunkt fest sowie, sofern ein Abonnement bestand, die Transaktionsnummer des Zahlungsdienstleisters, das Produkt und die Laufzeit. Dies dient dem Nachweis im Fall einer Rückerstattungsstreitigkeit; diese Angaben bewahren wir sieben Jahre auf, gerechnet bis zum Ende des jeweiligen Kalenderjahres.

Kontolöschung

Du kannst dein Nutzerkonto jederzeit selbst in der App löschen. Alternativ kannst du die Löschung über peerio.io/konto-loeschen beantragen. Mit der Löschung werden dein Konto und deine personenbezogenen Daten unverzüglich entfernt. Direktnachrichten werden vollständig gelöscht. Nachrichten in Peers und Meets bleiben als Platzhalter ohne Zuordnung zu dir bestehen, damit der Gesprächsverlauf für die übrigen Teilnehmer lesbar bleibt. Anonymisierte Inhalte wie Peer-Beiträge können in nicht zuordenbarer Form weiter bestehen. Ein aktives Abonnement wird durch die Kontolöschung nicht automatisch gekündigt; dieses muss separat im jeweiligen App Store beendet werden.

Auch ein Partnerkonto kann jederzeit in der App gelöscht oder die Löschung über peerio.io/konto-loeschen beantragt werden. Mit der Löschung werden auch der zugehörige Standort und die dort angelegten Events entfernt; noch nicht eingelöstes Kontingent verfällt. Von der Löschung ausgenommen sind Angaben zu Moderationsvorgängen und zur Kontolöschung selbst sowie Vertrags- und Rechnungsdaten, für die gesetzliche Aufbewahrungsfristen gelten; Näheres im Abschnitt „Moderation, Sanktionen und Beweisaufbewahrung".

4. Website peerio.io

Früher Zugang (Early Access)

Wir verarbeiten: Vorname, E-Mail-Adresse sowie deine Einwilligung mit Zeitstempel. Nach der Anmeldung erhältst du eine Bestätigungs-E-Mail (Double Opt-In). Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), die du jederzeit widerrufen kannst.

Löschantrag über die Website

Über peerio.io/konto-loeschen kannst du die Löschung deines Kontos beantragen. Wir verarbeiten dazu die von dir angegebene E-Mail-Adresse und den Zeitpunkt der Anfrage sowie technische Zugriffsdaten zur Abwehr automatisierter Missbrauchsversuche. Die Angaben dienen ausschließlich der Zuordnung und Bearbeitung deines Antrags und werden nach Abschluss der Bearbeitung gelöscht. Rechtsgrundlage ist Art. 6 Abs. 1 lit. c DSGVO in Verbindung mit Art. 17 DSGVO.

Buchung peerio Places

Über das Anfrageformular auf peerio.io/peerio-places verarbeiten wir Ansprechpartner, E-Mail-Adresse, Stadt, Website und, falls angegeben, die Beschreibung des Angebots. Wir nutzen diese Angaben, um die Anfrage zu prüfen und zu beantworten (Art. 6 Abs. 1 lit. b DSGVO). Zur Abwehr automatisierter Einsendungen läuft dabei Cloudflare Turnstile; Rechtsgrundlage ist unser berechtigtes Interesse an der Sicherheit unserer Formulare (Art. 6 Abs. 1 lit. f DSGVO).

Places Partner buchen ihr Kontingent über die ihnen bereitgestellte Buchungsseite. Die Zahlung wird vollständig durch Stripe (Stripe Payments Europe, Ltd., Irland) abgewickelt. Rechnungsadresse, Steuernummer, Betrag und Zahlungsdaten verbleiben dort; wir erhalten sie nicht. Aus dem Buchungsvorgang übernehmen wir ausschließlich: E-Mail-Adresse, Unternehmensname, den gebuchten Umfang sowie die Kundennummer des Zahlungsdienstleisters zur Zuordnung. Den Standort legt der Partner nach der Freischaltung seines Kontos selbst an. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Technische Bereitstellung

Beim Aufruf der Website werden technisch notwendige Zugriffsdaten verarbeitet (z.B. IP-Adresse, Zeitpunkt, Browser) auf Basis unseres berechtigten Interesses (Art. 6 Abs. 1 lit. f DSGVO).

Spam-Schutz

Zur Abwehr automatisierter Missbrauchsversuche setzen wir einen technischen Schutzmechanismus eines spezialisierten Sicherheitsdienstleisters (derzeit Cloudflare, USA) ein. Dabei können technische Zugriffsdaten übermittelt werden. Aktiv eingegebene Daten werden nicht übermittelt.

Cookies, Analyse und Marketing

Wir verwenden technisch notwendige Cookies für Session-Verwaltung und Sicherheit; diese laufen immer (Art. 6 Abs. 1 lit. f DSGVO). Mit deiner Zustimmung erfassen wir zusätzlich Nutzungsdaten zur Verbesserung unserer Website (Statistik) sowie Reichweitendaten zur Messung unserer Kampagnen (Marketing). Für die Statistik setzen wir Google Analytics und Microsoft Clarity ein, für die Reichweitenmessung den LinkedIn Insight Tag, Microsoft Advertising (Bing UET) und den Meta Pixel (Meta Platforms Ireland Ltd.). Für die Erhebung und Übermittlung der Daten über den Meta Pixel und den LinkedIn Insight Tag sind wir gemeinsam mit dem jeweiligen Anbieter verantwortlich (Art. 26 DSGVO); die dazu geschlossenen Vereinbarungen sind auf den Websites der Anbieter einsehbar. Ohne Zustimmung läuft ausschließlich ein anonymes, cookiefreies Analyse-Tool, das keine Personenidentifikation ermöglicht. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO); du kannst sie jederzeit über „Cookie-Einstellungen" im Footer widerrufen.

E-Mail-Kommunikation

Wir versenden transaktionale E-Mails die für den Betrieb notwendig sind, z.B. Registrierungsbestätigung, Passwort-Reset und Benachrichtigungen zu deinem Konto. Diese E-Mails werden über einen beauftragten E-Mail-Dienstleister versendet (derzeit Resend, USA). Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).

Newsletter und Marketing-E-Mails

Mit deiner ausdrücklichen Einwilligung versenden wir gelegentlich Newsletter und Informationen zu peerio (z.B. neue Funktionen, Community-Updates, Angebote). Der Versand erfolgt über einen spezialisierten E-Mail-Dienstleister (derzeit Resend, USA). Du kannst deine Einwilligung jederzeit widerrufen, entweder über den Abmeldelink in jeder E-Mail oder per formloser Nachricht an uns. Nach dem Widerruf werden deine Daten für Marketing-Zwecke nicht weiter genutzt. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).

Fragst du bei uns an, nutzen wir deine Kontaktdaten, um die Anfrage zu beantworten und dir ein passendes Angebot zu machen (Art. 6 Abs. 1 lit. b DSGVO). Können wir dein Anliegen zu diesem Zeitpunkt nicht erfüllen, speichern wir deine Angaben, um dich zu benachrichtigen, sobald es passt. Rechtsgrundlage ist die Bearbeitung deiner Anfrage sowie unser berechtigtes Interesse daran, Interessenten nachzufassen (Art. 6 Abs. 1 lit. b und lit. f DSGVO); du kannst dem jederzeit widersprechen. Nach einer Buchung informieren wir dich per E-Mail über eigene ähnliche Angebote; Rechtsgrundlage ist unser berechtigtes Interesse an Direktwerbung (Art. 6 Abs. 1 lit. f DSGVO i.V.m. § 7 Abs. 3 UWG). Du kannst dem jederzeit über den Abmeldelink in jeder E-Mail oder formlos an uns widersprechen.

5. Weitergabe an Dritte

Wir behandeln personenbezogene Daten vertraulich und geben sie nur weiter soweit dies für den Betrieb unserer Dienste erforderlich ist: an beauftragte Dienstleister, an Behörden wenn wir gesetzlich dazu verpflichtet sind, sowie an Rechtsanwälte, Steuerberater oder Wirtschaftsprüfer soweit nötig. Darüber hinaus können wir personenbezogene Daten an verbundene Unternehmen, Tochtergesellschaften, Muttergesellschaften oder Nachfolgegesellschaften von Tomoveo Ltd. weitergeben, soweit dies für den Betrieb, die Weiterentwicklung oder die Verwertung der App erforderlich ist. Anonymisierte und aggregierte Daten ohne Personenbezug können ohne Einschränkung kommerziell verwertet und an Dritte weitergegeben werden.

6. Dienstleister und Drittländerübermittlungen

Für den Betrieb setzen wir spezialisierte Dienstleister ein. Mit allen bestehen Auftragsverarbeitungsverträge gemäß Art. 28 DSGVO. Dienstleister in Drittländern (insbesondere USA) werden durch Standardvertragsklauseln (Art. 46 DSGVO) geschützt.

Wir setzen folgende Kategorien von Dienstleistern ein, mit denen Auftragsverarbeitungsverträge gemäß Art. 28 DSGVO bestehen: Datenbankhosting & Authentifizierung (derzeit Supabase, Server Frankfurt/EU), Infrastruktur & Sicherheit (derzeit u.a. Cloudflare, USA), Kartendarstellung (derzeit Mapbox, USA), Ortsdaten (GeoNames, CC BY 4.0), E-Mail-Versand (derzeit Resend, USA), KI-Verarbeitung (derzeit Anthropic, USA und OpenAI Ireland Ltd., Irland), Crash-Reporting & Fehleranalyse (derzeit Sentry, USA), Zahlungsabwicklung für peerio Places (derzeit Stripe Payments Europe, Ltd., Irland), Website-Analyse (derzeit Google, USA), Nutzerverhalten-Analyse (derzeit Microsoft Clarity, USA), Werbe-Messung (derzeit LinkedIn, Irland; Microsoft Advertising / Bing, USA; Meta Platforms Ireland Ltd., Irland/USA), Code-Hosting (derzeit GitHub, USA), Bereitstellung und Aktualisierung der App (derzeit Expo, USA) sowie Zustellung von Push-Benachrichtigungen (derzeit Apple, USA und Google Firebase Cloud Messaging, USA).

Die jeweils aktuell eingesetzten Dienstleister können auf Anfrage mitgeteilt werden.

Die Zahlungsabwicklung für App-Mitgliedschaften erfolgt ausschließlich durch Apple bzw. Google nach deren eigenen Datenschutzbestimmungen; auf diese Zahlungsdaten haben wir keinen Zugriff. Zahlungen von peerio Places Partnern werden primär über Stripe (Stripe Payments Europe, Ltd., Irland) abgewickelt; andere Zahlungsmittel sind möglich. Stripe verarbeitet Zahlungsdaten eigenständig; wir erhalten lediglich eine Bestätigung des Zahlungseingangs sowie für die Rechnungsstellung notwendige Daten. Rechnungs- und Vertragsdaten werden zur Vertragsabwicklung (Art. 6 Abs. 1 lit. b DSGVO) und zur Erfüllung gesetzlicher Aufbewahrungspflichten (Art. 6 Abs. 1 lit. c DSGVO) verarbeitet.

7. peerio Places Partner

Nach Prüfung der Anfrage erhält der Partner einen Zugangscode per E-Mail, mit dem er sein Partnerkonto anlegt und sein Profil selbst befüllt. Im Partnerprofil verarbeiten wir anschließend: Kontaktdaten, Unternehmensname, Standortangaben, Beschreibungen sowie hochgeladene Bilder und Dateien. Hinzu kommen die Vertragsdaten (gebuchter Umfang, Kundennummer des Zahlungsdienstleisters). Partner können zudem Links zu externen Webseiten und Social-Media-Profilen in ihrem Profil hinterlegen. Partner können außerdem Events mit Standortangabe erstellen, Nachrichten an Nutzer senden und in der Community ankündigen. Erhebt ein Partner ein Entgelt für sein Event, wickelt er dieses selbst ab; wir sind daran nicht beteiligt und erhalten keine Zahlungsdaten. Diese Daten werden zur Vertragsabwicklung (Art. 6 Abs. 1 lit. b DSGVO) und zur Erfüllung gesetzlicher Aufbewahrungspflichten (Art. 6 Abs. 1 lit. c DSGVO) verarbeitet. Personenbezogene Daten einzelner Nutzer werden nicht an Partner weitergegeben. Ausgenommen sind Teilnehmer an einem Event des Partners: Für sein eigenes Event sieht der Partner den angezeigten Namen und das Profilbild der Teilnehmer, damit er das Treffen vorbereiten kann. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO). Auch beim Partner-Onboarding fragen wir optional ab, wie der Partner auf peerio aufmerksam geworden ist; es gilt das in Abschnitt 2 Beschriebene.

8. Speicherdauer

Wir speichern deine personenbezogenen Daten grundsätzlich so lange, wie dein Nutzerkonto besteht. Löschst du dein Konto, werden deine Daten gelöscht, mit wenigen Ausnahmen aus rechtlichen oder Sicherheitsgründen.

Meldungen über Inhalte oder Profile werden nach einem Jahr gelöscht. Inaktive Peers und Meets nach 90 Tagen ohne Nachricht. Suchanfragen, Daten zum Nutzungsverhalten, abgelehnte Kontaktanfragen und Benachrichtigungen nach 90 Tagen, erledigte Beitrittsanfragen sofort nach der Entscheidung. Das aus diesen Daten gebildete Interessenprofil wird gelöscht, sobald du der Auswertung deiner Verhaltensdaten widersprichst, spätestens mit der Löschung deines Kontos. Bilder und Dateien aus Chats werden mit dem zugehörigen Chat gelöscht; Dateien ohne zugehörige Nachricht entfernen wir automatisch.

An KI-Dienstleister übermittelte Daten werden dort nach Maßgabe der mit ihnen vereinbarten Bedingungen gelöscht und nicht zum Training ihrer Modelle verwendet. Hiervon unberührt bleibt die Nutzung von Inhalten zur Verbesserung unserer eigenen Systeme gemäß den Nutzungsbedingungen. Anonymisierte oder aggregierte Daten können darüber hinaus gespeichert bleiben. Daten aus der Early-Access-Anmeldung speichern wir bis zu einem Jahr nach Launch, Kontaktanfragen bis zur abschließenden Bearbeitung, längstens zwei Jahre. Vertragsdaten von Partnern sowie Angaben zur Kontolöschung bewahren wir sieben Jahre auf, gerechnet bis zum Ende des jeweiligen Kalenderjahres. Ergänzend gelten die im Abschnitt „Moderation, Sanktionen und Beweisaufbewahrung" genannten Fristen.

9. Deine Rechte

Dir stehen folgende Rechte zu: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch gegen die Verarbeitung (Art. 21), Widerruf der Einwilligung (Art. 7 Abs. 3) sowie ein Beschwerderecht bei einer Datenschutz-Aufsichtsbehörde. Zur Ausübung genügt eine formlose Nachricht an [email protected]. Einen Datenexport kannst du jederzeit anfordern, solange dein Konto aktiv ist.

Zuständige Aufsichtsbehörde ist der Commissioner for Personal Data Protection, Zypern (www.dataprotection.gov.cy). Nutzer mit Wohnsitz in einem anderen EU-Mitgliedstaat oder der Schweiz können sich alternativ an die für sie zuständige lokale Datenschutzbehörde wenden.

Für Nutzer mit Wohnsitz in der Schweiz gilt ergänzend das Schweizer Datenschutzgesetz (DSG). Zuständige Aufsichtsbehörde ist der Eidgenössische Datenschutz- und Öffentlichkeitsbeauftragte (EDÖB, www.edoeb.admin.ch).

10. Sicherheit

Wir treffen angemessene technische und organisatorische Maßnahmen zum Schutz deiner Daten. Die Datenübertragung im Internet kann jedoch Sicherheitslücken aufweisen; ein lückenloser Schutz vor Zugriff durch Dritte ist nicht möglich. Im Fall einer Datenpanne erfüllen wir die gesetzlichen Meldepflichten gegenüber der zuständigen Aufsichtsbehörde und informieren betroffene Nutzer soweit gesetzlich erforderlich.

11. Externe Links

Unsere Website und App enthalten Links zu unseren Profilen auf externen Plattformen. Auch Nutzer und peerio Places Partner können in ihren Profilen Links zu eigenen Webseiten und externen Plattformen hinterlegen. Rufst du einen solchen Link auf, gelten ausschließlich die Datenschutzbestimmungen des jeweiligen Anbieters. Wir haben keinen Einfluss auf die dortige Datenverarbeitung.

12. Aktualität dieser Datenschutzerklärung

Wir behalten uns vor, diese Datenschutzerklärung jederzeit zu aktualisieren, insbesondere bei Änderungen der gesetzlichen Anforderungen oder Erweiterung unserer Dienste. Die jeweils aktuelle Fassung ist auf dieser Seite abrufbar. Bei wesentlichen Änderungen informieren wir dich über eine Benachrichtigung in der App und gegebenenfalls zusätzlich per E-Mail.

Stand: August 2026

Privacy Policy

Protecting your personal data is important to us. This Privacy Policy explains how we collect, process, and use data when you use the peerio app or the website peerio.io. We comply with the requirements of the General Data Protection Regulation (GDPR).

1. Controller

Tomoveo Ltd., 8011 Paphos, Cyprus

Email: [email protected]

Full provider details in the Legal Notice.

2. Registration and User Account

Using the peerio app requires registration. We process: email address, first and last name, profile photo, gender (with the option not to state it), information about your business activity (founding stage, industry, team setup, link to your founder activity), a self-description, your location, language settings, and timestamps of registration, your age confirmation, and your acceptance of these terms and the Community Code. Your last name is not shown to other users.

The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). By registering, you confirm that you are at least 18 years old and engaged in business activity. During onboarding, we optionally ask how you heard about peerio. This information is voluntary, used to improve our marketing, and not shared with third parties. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

3. Use of the App

Registration via Apple or Google

You can register with your Apple or Google account. In this case, Apple or Google transmits basic profile data (name, email address) to us. You can view and control what data is transmitted with the respective provider. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Peers and Meets

Content you create in the app is stored and displayed to other users according to your visibility settings. Peers are posts you create where other users can write and discuss. Meets are gatherings you organize on your own responsibility and can make visible to others with a location and time. Peers are time-limited: after a period stated in the app they no longer appear in the overview or on the map and are not discoverable by new users. For participants and the creator, the associated chat remains usable; it is deleted once no message has been sent for 90 days. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Anonymous Mode

Peers can be created anonymously. In this case your name and profile photo are not shown to other users, and your identity is not transmitted to them technically either, neither to outsiders nor to participants of the peer. Within an anonymous peer you appear to everyone as "Anonymus" with a fixed number. The post remains internally linked to your account so that you can manage it. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Connections and peerio ID

When you connect with other users, this connection is saved and forms the basis for further features such as chat and matching. Each account is also assigned a unique peerio ID; it is used for internal identification and can be shared by you. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Matching

peerio uses an automated matching system to suggest suitable users. Analysis is based exclusively on professional information you have entered yourself. To improve matching, text-based profile information is converted into a machine-readable form that cannot be converted back into text using an appointed AI service (currently OpenAI Ireland Ltd., Ireland) and stored. This processing is used exclusively for the matching function. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

The matching result is a suggestion without binding or legally significant character within the meaning of Art. 22 GDPR. Matching is part of the contractually owed service and cannot be switched off as a function. You can, however, restrict the underlying data by objecting to the evaluation of your behavioral data; matching then operates solely on the basis of your profile information.

AI-Powered Features

Posts are automatically classified before publication and checked for compliance with the rules of the Community Code. For this we use an appointed AI service (currently Anthropic, USA). The content you enter is transmitted, together with individual sample texts released by us. No analysis of personal or sensitive characteristics takes place. If a post is rejected, you receive a notice and can revise the post or have the decision reviewed via the address stated in the Legal Notice. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in operating a safe platform (Art. 6(1)(f) GDPR).

Messages, Chat, and File Uploads

Messages as well as files and images shared in the chat are stored for the operation of the chat service. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Usage Behavior

We collect usage data to improve matching and the app. This includes in particular: which peers you view, which you join and how you participate in them, which profiles you visit, and your search queries in the app. From these signals we develop an interest profile that improves the quality of your suggestions over time. An appointed AI service is used for this (currently OpenAI Ireland Ltd., Ireland); only depersonalized information is transmitted, not the original texts. Posts you create anonymously are not included in your interest profile. Search queries are stored for this purpose for up to 90 days. This data is evaluated in aggregated or pseudonymized form. To the extent it no longer contains any personal reference, it may also be used for market research, investor communications, and commercial exploitation. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

You may object to the processing of your behavioral data for the interest profile at any time; a toggle for this is available in the privacy settings of the app. If you object, behavioral data already collected is deleted and no new data is recorded; matching then operates solely on the basis of your profile information.

peerio+ and Invitation Codes

We store whether you use the free basic model or peerio+ and the respective usage status. With peerio+ you receive a personal invitation code. If someone redeems your code, we store the redemption together with both accounts and the time, so that we can limit use of the code and detect misuse. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Profile Photo

You can upload a profile photo. This is displayed to other users. To ensure authenticity, the uploaded image is automatically checked to determine whether it shows a human face. For this purpose it is transmitted to an appointed AI service (currently Anthropic, USA). No biometric analysis, identification, or comparison with external databases takes place. The profile photo is stored with your account and removed upon account deletion. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Location in Your Profile

You provide a location in your profile. We store the place name and the approximate coordinates of that place, not your actual whereabouts. The location is visible to other users. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Photos at Gatherings

In the chats for Meets and events you can take and share photos using the camera feature. Such photos may show people, are visible to all participants of the respective chat, and can be saved and shared further by them. Only upload photos that everyone shown has agreed to have published. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Review of Your Information

We automatically check the link provided in your profile to determine whether it matches our offering. In doing so we retrieve the page and use an appointed AI service. We store the address, the result, and any statement you provide in response. The legal basis is our legitimate interest in operating a suitable community (Art. 6(1)(f) GDPR).

Links and External Information in Profile

You can add external links to your profile (e.g. website or social media profiles). This information is visible to other users and stored with your profile. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Referral Links

peerio provides a general referral link that contains no identifier and is not assigned to any individual user. So that we show the prompt to recommend peerio only to active users and not too often, we count certain activities in the app. This counter is linked to your account and is reset after each prompt. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Device Data

For operating the app and troubleshooting, we process technical device data such as device ID, operating system, and app version. If an error or crash occurs, a technical error report is transmitted to an appointed service provider (currently Sentry, USA). The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Inactive Accounts

In the event of permanent account inactivity, we are entitled to deactivate or delete the account after prior email notification. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

Notification Settings

You can control which push notifications and email notifications you wish to receive in the app settings. Your settings are saved and can be changed at any time. Push notifications are transmitted via Apple or Google infrastructure and additionally require your consent at device level; they can be disabled via your device settings. The legal basis is your consent (Art. 6(1)(a) GDPR).

Meets on the Map

You can create Meets on the map and make them visible to other users with a location. You can optionally set visibility settings, e.g. by gender; these settings are stored with the meet. Data is stored with time and location. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

For map display we use Mapbox (USA). Map tiles are loaded from Mapbox servers. Your device location is used only live for display within the map and is not stored. Location details for Meets are entered manually by the user and stored with coordinates in our database.

Personal Questions and Icebreakers

You can add personal questions from a predefined selection to your profile and answer them yourself. This information is voluntary and visible to other users. You can also formulate your own question, which is shown to other users before they send you a contact request. Anyone sending you a request may answer this question voluntarily; if you accept the request, the question and answer appear as the first messages in the shared chat. If you decline, the answer is deleted. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Blocking

You can block other users. A block takes effect in both directions: you no longer appear in each other's suggestions, are not findable via search, cannot send each other messages, contact requests, or invitations, and your profiles are shown to each other without name and photo. An existing connection is dissolved. In shared peers and meets, membership remains; the other person appears there without name and photo. Blocks are stored with your account and you can lift them at any time in the settings. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Suspension Notice and Statement

If your account is suspended, the next time you open the app you receive a notice stating the reasons, the underlying rule of the Community Code, and the objected content verbatim. You can submit a statement; your statement is stored and reviewed, and you are informed of the outcome. We review the case before a suspension. Where we use automated procedures in doing so, we state this expressly in the notice. You can present your point of view and contest the decision; complaints are always decided by a person. The legal basis is our legitimate interest in operating a safe platform (Art. 6(1)(f) GDPR); where a decision is taken by automated means, it is based on Art. 22(2)(a) GDPR.

Moderation, Sanctions, and Evidence Retention

If content or a profile is reported, we review the report and decide on a measure. In doing so we process: the report with its reason and description, the reported content verbatim, the accounts of the reporter and the reported person, and the time.

If a report leads to a suspension, we record the case: the internal account number, the type of decision, the time, our reasoning, the underlying rule of the Community Code, and the objected content verbatim. These records persist even if the account concerned is subsequently deleted. Name, email address, profile photo, and profile content are not retained. The legal basis is our legitimate interest in legal defense and platform safety (Art. 6(1)(f) GDPR); retention despite an erasure request is based on Art. 17(3)(e) GDPR.

We retain records of the sanction process for three years plus the remainder of the calendar year, and objected content verbatim for twelve months. If an appeal or dispute is pending, deletion is suspended until it concludes. Independently of any sanction, for every account deletion we record the time and, where a subscription existed, the payment provider's transaction number, the product, and the term. This serves as evidence in the event of a refund dispute; we retain this information for seven years, calculated to the end of the respective calendar year.

Account Deletion

You can delete your user account yourself in the app at any time. Alternatively, you can request deletion via peerio.io/konto-loeschen. Upon deletion, your account and personal data are removed without delay. Direct messages are deleted in full. Messages in peers and meets remain as placeholders with no link to you, so that the conversation stays readable for the other participants. Anonymized content such as peer posts may continue to exist in non-identifiable form. An active subscription is not automatically cancelled upon account deletion; it must be terminated separately in the respective app store.

A partner account can also be deleted at any time in the app, or deletion can be requested via peerio.io/konto-loeschen. Upon deletion, the associated location and the events created there are also removed; any unredeemed allowance expires. Records of moderation actions and of the account deletion itself, as well as contract and invoicing data subject to statutory retention periods, are exempt from deletion; see the section "Moderation, sanctions, and evidence retention".

4. Website peerio.io

Early Access

We process: first name, email address, and your consent with timestamp. After registration you will receive a confirmation email (double opt-in). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

Deletion Request via the Website

You can request the deletion of your account via peerio.io/konto-loeschen. For this purpose we process the email address you provide and the time of the request, as well as technical access data to prevent automated abuse. This information serves solely to identify and process your request and is deleted once processing is complete. The legal basis is Art. 6(1)(c) GDPR in conjunction with Art. 17 GDPR.

peerio Places Booking

Via the enquiry form on peerio.io/peerio-places we process the contact person, email address, city, website and, if provided, the description of the offering. We use this information to review and answer the enquiry (Art. 6(1)(b) GDPR). Cloudflare Turnstile runs on the form to prevent automated submissions; the legal basis is our legitimate interest in the security of our forms (Art. 6(1)(f) GDPR).

Places Partners book their allowance via the booking page provided to them. Payment is handled entirely by Stripe (Stripe Payments Europe, Ltd., Ireland). Billing address, tax number, amount, and payment data remain there; we do not receive them. From the booking process we take only: email address, company name, the scope booked, and the payment provider's customer number for allocation. The partner creates the location themselves after their account has been activated. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Technical Provision

When accessing the website, technically necessary access data is processed (e.g. IP address, time, browser) on the basis of our legitimate interest (Art. 6(1)(f) GDPR).

Spam Protection

To defend against automated abuse attempts, we use a technical protection mechanism from a specialized security provider (currently Cloudflare, USA). Technical access data may be transmitted. Actively entered data is not transmitted.

Cookies, Analytics, and Marketing

We use technically necessary cookies for session management and security; these always run (Art. 6(1)(f) GDPR). With your consent, we additionally collect usage data to improve our website (statistics) and reach data to measure our campaigns (marketing). For statistics we use Google Analytics and Microsoft Clarity, for reach measurement the LinkedIn Insight Tag, Microsoft Advertising (Bing UET), and the Meta Pixel (Meta Platforms Ireland Ltd.). For the collection and transmission of data via the Meta Pixel and the LinkedIn Insight Tag, we are jointly responsible with the respective provider (Art. 26 GDPR); the agreements concluded for this purpose can be viewed on the providers' websites. Without consent, only an anonymous, cookie-free analysis runs that does not enable personal identification. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time via "Cookie Settings" in the footer.

Email Communication

We send transactional emails necessary for operation, e.g. registration confirmation, password reset, and account notifications. These emails are sent via an appointed email service provider (currently Resend, USA). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Note: Email is not a secure transmission channel. We accept no liability for damages arising from loss, delay, falsification, or unauthorized access during transmission. We accept no responsibility for the content of attachments.

Newsletter and Marketing Emails

With your explicit consent, we occasionally send newsletters and information about peerio (e.g. new features, community updates, offers). Emails are sent via a specialized email service provider (currently Resend, USA). You can withdraw your consent at any time, either via the unsubscribe link in each email or by informal message to us. After withdrawal, your data will no longer be used for marketing purposes. The legal basis is your consent (Art. 6(1)(a) GDPR).

If you contact us with an enquiry, we use your contact details to respond and to make you a suitable offer (Art. 6(1)(b) GDPR). If we cannot meet your request at that time, we store your details in order to notify you once it becomes a fit. The legal basis is the handling of your enquiry and our legitimate interest in following up with interested parties (Art. 6(1)(b) and (f) GDPR); you may object at any time. After a booking, we inform you by email about our own similar offers; the legal basis is our legitimate interest in direct marketing (Art. 6(1)(f) GDPR in conjunction with Section 7(3) UWG). You may object at any time via the unsubscribe link in every email or informally.

5. Disclosure to Third Parties

We treat personal data confidentially and only share it to the extent necessary for operating our services: with appointed service providers, with authorities when legally required, and with lawyers, tax advisors, or auditors as needed. We may also share personal data with affiliated companies, subsidiaries, parent companies, or successor companies of Tomoveo Ltd. to the extent necessary for the operation, development, or exploitation of the app. Anonymized and aggregated data without personal reference may be commercially exploited and shared with third parties without restriction.

6. Service Providers and Third-Country Transfers

We use specialized service providers for operations. Data processing agreements pursuant to Art. 28 GDPR exist with all of them. Service providers in third countries (in particular the USA) are protected by standard contractual clauses (Art. 46 GDPR).

We use the following categories of service providers, with whom data processing agreements pursuant to Art. 28 GDPR exist: database hosting and authentication (currently Supabase, server Frankfurt/EU), infrastructure and security (currently including Cloudflare, USA), map display (currently Mapbox, USA), place data (GeoNames, CC BY 4.0), email delivery (currently Resend, USA), aI processing (currently Anthropic, USA and OpenAI Ireland Ltd., Ireland), crash reporting and error analysis (currently Sentry, USA), payment processing for peerio Places (currently Stripe Payments Europe, Ltd., Ireland), website analytics (currently Google, USA), user behavior analysis (currently Microsoft Clarity, USA), advertising measurement (currently LinkedIn, Ireland; Microsoft Advertising / Bing, USA; Meta Platforms Ireland Ltd., Ireland/USA), code hosting (currently GitHub, USA), provision and updating of the app (currently Expo, USA), and delivery of push notifications (currently Apple, USA and Google Firebase Cloud Messaging, USA).

The service providers currently in use can be communicated upon request.

Payment processing for app memberships is handled exclusively by Apple or Google under their own privacy policies; we have no access to this payment data. Payments from peerio Places Partners are processed primarily via Stripe (Stripe Payments Europe, Ltd., Ireland); other payment methods are available. Stripe processes payment data independently; we only receive a payment confirmation and data necessary for invoicing. Billing and contract data is processed for contract performance (Art. 6(1)(b) GDPR) and to fulfill legal retention obligations (Art. 6(1)(c) GDPR).

7. peerio Places Partners

After we have reviewed the enquiry, the partner receives an access code by email with which they create their partner account and fills in their profile themselves. Within the partner profile we then process: contact details, company name, location information, descriptions, and uploaded images and files. In addition, we process contract data (scope booked, payment provider's customer number). Partners may also add links to external websites and social media profiles in their profile. Partners can also create events with location details, send messages to users, and announce them in the community. If a partner charges a fee for their event, they handle it themselves; we are not involved and receive no payment data. This data is processed for contract performance (Art. 6(1)(b) GDPR) and to fulfill legal retention obligations (Art. 6(1)(c) GDPR). Personal data of individual users is not shared with partners. Participants in an event of the partner are excepted: for their own event, the partner sees the displayed name and profile photo of the participants so that they can prepare the meeting. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). During partner onboarding we also optionally ask how the partner heard about peerio; the description in Section 2 applies.

8. Retention Periods

We store your personal data for as long as your account exists. If you delete your account, your data will be deleted, with limited exceptions for legal or safety reasons.

Reports about content or profiles are deleted after one year. Inactive peers and meets after 90 days without a message. Search queries, usage behavior data, declined contact requests, and notifications after 90 days; completed join requests immediately after the decision. The interest profile formed from this data is deleted as soon as you object to the evaluation of your behavioral data, and at the latest when your account is deleted. Images and files from chats are deleted together with the chat concerned; files with no associated message are removed automatically.

Data transmitted to AI service providers is deleted there in accordance with the terms agreed with them and is not used to train their models. This does not affect the use of content to improve our own systems in accordance with the Terms of Use. Anonymized or aggregated data may be retained beyond this. Early access registration data is stored for up to one year after launch, contact requests until final processing and no longer than two years. Partner contract data and records of account deletions are retained for seven years, calculated to the end of the respective calendar year. The periods stated in the section "Moderation, sanctions, and evidence retention" apply in addition.

9. Your Rights

You have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), right to object to processing (Art. 21), withdrawal of consent (Art. 7(3)), and the right to lodge a complaint with a data protection supervisory authority. To exercise these rights, an informal message to [email protected] is sufficient. You can request a data export at any time while your account is active.

The competent supervisory authority is the Commissioner for Personal Data Protection, Cyprus (www.dataprotection.gov.cy). Users resident in another EU member state or Switzerland may alternatively contact their local data protection authority.

For users resident in Switzerland, the Swiss Federal Act on Data Protection (FADP/DSG) applies in addition. The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC/EDÖB, www.edoeb.admin.ch).

10. Security

We take appropriate technical and organizational measures to protect your data. However, data transmission over the internet may have security vulnerabilities; complete protection against third-party access is not possible. In the event of a data breach, we fulfill our legal reporting obligations to the competent supervisory authority and inform affected users to the extent legally required.

11. External Links

Our website and app contain links to our profiles on external platforms. Users and peerio Places Partners can also add links to their own websites and to external platforms in their profiles. If you open such a link, the privacy policy of the respective provider applies exclusively. We have no influence over data processing there.

12. Updates to this Privacy Policy

We reserve the right to update this Privacy Policy at any time, in particular in the event of changes to legal requirements or expansion of our services. The current version is available on this page at all times. In the event of material changes, we will inform you via a notification in the app and, where appropriate, additionally by email.

As of: August 2026

Cookie-Einstellungen

Was du erlaubst.

Technisch notwendig
Sicherheit, Session, Formulare. Immer aktiv.
Statistik
Anonyme Nutzungsdaten, damit wir die Seite verbessern.
Marketing
Reichweiten- und Kampagnen-Messung.