The company GROUPP EUROPE SA (hereinafter “GROUPP”), a company incorporated under Belgian law, registered under number 0797.502.722, whose registered office is located at Avenue Louise 231, 1050 Brussels, Belgium, publishes and operates the Groupp mobile application (hereinafter the “ Application ”).
The Application is a search engine used to connect individuals, groups, events and venues in order to facilitate real-life meetings.
The Application is exclusively reserved for adult natural persons (18 years or older). Any minor is strictly prohibited from accessing it.
As publisher, GROUPP acts as data controller within the meaning of Article 4(7) of the GDPR. The purpose of this Policy is to inform you of how your personal data is processed and of the rights you have.
By creating an account on the Application, you confirm that you are 18 years of age or older and that you have read this Policy.
1. Definitions
Capitalized terms have the meaning set out below:
“GROUPP”: refers to GROUPP EUROPE SA, the data controller.
“Application”: refers to the Groupp mobile application (iOS and Android) and the website www.groupp.app.
“User”: refers to any adult natural person (18 years or older) who has created an Account on the Application.
“Group”: a set of Users brought together within a shared entity created on the Application.
“Personal Data”: any information that can be used to identify a natural person.
“Sensitive Data”: special categories of data referred to in Article 9 of the GDPR (religious beliefs, sexual orientation, etc.).
“DPA”: Belgian Data Protection Authority (the Belgian Data Protection Authority)
2. Data controller and age verification
Identity of the Data Controller
GROUPP EUROPE SA is the controller for all personal data processed in connection with the Application.
| Identity of the Data Controller |
| Company name: GROUPP EUROPE SA |
| Legal form: Public limited company (Société Anonyme) |
| Registered office: Avenue Louise 231, 1050 Brussels, Belgium |
| Company registration number: 0797.502.722 |
| Personal data contact: support@groupp.app |
For any questions, you may contact GROUPP at support@groupp.app or by post at the address of the registered office.
Age verification: Mechanisms and documentation
Access to the Application is strictly reserved for adults (18 years or older).
GROUPP implements the following measures:
Mandatory collection of date of birth when creating the account;
Explicit confirmation checkbox stating: “I confirm that I am 18 years of age or older and that I am an adult under the law of my country of residence”;
A clause in the GTU prohibiting access by minors;
Timestamped retention of the age declaration in the account creation logs: documentary evidence retained for the duration of the account plus the applicable limitation period.
If it is discovered that a user is a minor, GROUPP immediately suspends and deletes the account and erases all data collected.
3. Personal data collected
We only collect data that is strictly necessary for the purposes pursued:
Data you provide to us
When creating the Account (mandatory):
Username or nickname;
Email address (unverified);
Phone number (OTP);
Date of birth and confirmation of age (18 years or older): mandatory step retained as documentary evidence;
A profile photo (up to 6 photos may be added).
When creating the Profile (mandatory):
Age (automatically generated based on date of birth);
City of residence;
Gender;
Height;
Zodiac sign (automatically generated based on date of birth);
Languages spoken;
Favorite types of places;
Biography or personal description (a single emoji is sufficient).
When creating the Profile (optional — subject to your explicit consent):
Current or upcoming Destinations;
Links to social networks or any other URL;
Activities;
Groups created or joined;
Events created or attended;
Favorite cities;
Places frequented;
Dietary preferences that may reveal religious beliefs — this data constitutes Sensitive Data within the meaning of Article 9 of the GDPR and is subject to separate explicit consent;
Relationship status — which may reveal sexual orientation, this data constitutes Sensitive Data within the meaning of Article 9 of the GDPR and is subject to separate explicit consent.
When creating a Group, an Event or a Place:
Name, description, photos, date, location, activity, destination;
Contact details if you choose to display them.
When using Support:
Data provided via the in-app support system and during your exchanges with our team.
Data collected automatically
Browsing: log-ins, connection dates/times, screens visited, session duration;
Interactions: Connections, Groups, Events, filters, favorites, likes, messages;
Behavior (subject to consent): frequency, types of actions, and timing feed into the recommendation algorithm
Geographic location (if permission is granted — optional and revocable at any time).
Referral-related data
Information necessary to send the invitation.
Contact list and referral matching: where applicable, matching of your contact list with Users already present on the Application, in order to suggest a referral to you. If you join the Application using the referral code of one User while another User had also sent you a code, the latter is informed that you have joined the Application and is shown the username of the person whose code was used. When you authorize access to your phone's contact list, the Company carries out a technical comparison to identify contacts already present on the Application in order to facilitate referral referral and user connection mechanisms. Except where there is a specific technical need, the contact list as a whole is not retained permanently by the Company and is not used for commercial prospecting purposes.
If your profile is placed on the waiting list due to the lack of an available referral, your profile data is retained by the Company for a maximum period of one (1) year from completion of the profile, pending validation of access. After this period without validation, or in the event of voluntary deletion of your profile during this period, your data is deleted under the same conditions as a standard profile deletion. Expiry of this period does not restrict a new request for access in any way.
Data relating to Status and progression
number of validated referrals, progression towards the various Statuses, current Status, Status acquisition date, history of Status changes, and information necessary to prevent fraud related to the referral system.
You are responsible for data you share concerning third parties. You must ensure that the individuals concerned have been informed.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creation and management of the account; age verification | Email, phone number, username, date of birth, age declaration | Performance of the contract |
| Management of the referral system, allocation of Statuses and fraud prevention | Referral data, progression history, Status history | Performance of the contract + legitimate interest |
| Provision of the services | Profile, activity, location (if consented to), status | Performance of the contract |
| Personalization of suggestions (recommendation algorithm) | Enriched profile + behavioral data | Consent |
| User support | Identity, content of request | Performance of the contract |
| Marketing communications | Email, preferences | Consent |
| Technical operation, security | Technical data, logs | Legitimate interest |
| Evidence and retention of the age declaration | Date of birth, declaration, timestamp | Legitimate interest + legal obligation |
| Compliance with applicable legal obligations | Data relevant to the obligation | Legal obligation |
| Defense of GROUPP's rights | Relevant data | Legitimate interest |
| Retention of data in the event of a ban (traceability, defense in the event of a dispute) | User ID, moderation logs, evidence of conduct | Legitimate interest (art. 6(1)(f)) |
| Prevention, detection and reporting of CSAE-related content or conduct; cooperation with the competent authorities | Content, messages, profile and connection data relevant to the report | Legal obligation + legitimate interest (protection of minors, art. 6(1)(c) and (f) GDPR) |
Your consent may be withdrawn at any time from the consent dashboard in the settings. This does not affect the lawfulness of prior processing.
As all Users are adults, consent to profiling is fully valid with no age-related reservation.
5. Profiling and recommendation algorithm
How the algorithm works
Our algorithm cross-references your declarative data (profile) and behavioral data (usage) to suggest Groups, Events, Places and Users matching your interests.
It takes into account: your profile data, your in-app behavior (frequency, content viewed, filters used) and aggregated community trends.
Effects of profiling
This profiling personalizes the content and suggestions offered to you. It does not produce any automated decision having legal effects within the meaning of Article 22 of the GDPR.
Legal basis and right to object
This processing is based on your consent (Article 6(1)(a) of the GDPR), which may be withdrawn at any time from the consent dashboard in the settings. If withdrawn, you continue to benefit from the Services but without personalization.
As all Users are adults, consent to profiling is fully valid with no age-related reservation.
6. Access permissions
No permission is activated without your explicit agreement. These permissions can be changed at any time from your phone's or the Application's settings.
Location: to suggest nearby Groups, Events and Places. Optional and revocable.
Photo album / gallery and camera: to add photos to your Profile or to the elements you create. Optional.
Contact list: to invite contacts to join the Application. Optional.
Calendar / agenda: to save Events directly to your personal calendar. Optional.
Push notifications: manageable from the Application's settings.
Refusing or disabling certain of these permissions may limit access to certain features without blocking general use of the Application. Details of the data collected via each permission, its purpose and its legal basis are available in Article 4
7. Who receives your data?
Internally
Developers (full access under NDA) and administrators;
Support, community management and moderation (access limited to data strictly necessary for their duties).
Processors (art. 28 GDPR)
Hosting: Amazon Web Services (AWS), Paris region, European Union;
Development: technical providers under NDA and an Article 28 contract;
Other users
Your Profile information is visible to other Users according to your privacy settings. Your phone number and email address are never visible to other Users. Certain data may only be accessible to Users with whom you are connected, who are members of the same Group, or who are attending the same Event.
Apple and Google
In connection with downloading the Application, Apple and Google act as independent data controllers for data collected on their respective platforms. Please refer to their privacy policies for more information.
Competent judicial and administrative authorities.
In the event of a confirmed report of content or conduct constituting child sexual exploitation or abuse (CSAE), data strictly necessary may be transmitted to the competent authorities, in particular to the dedicated Belgian contact point for combating illegal content online (eCops, federal police) and, where applicable, to Child Focus or any equivalent authority in the jurisdiction concerned, in accordance with the “How does the Application protect minors against sexual exploitation and abuse (CSAE)?” Article of the General Terms of Use.
8. Transfers outside the European Union
Your data is hosted within the European Union (AWS, Paris region).
Certain technical providers may be established outside the European Union, in particular in the United Kingdom. In such cases, transfers are governed by Standard Contractual Clauses (European Commission Decision 2021/914), used as a safety net independently of any adequacy decision mechanism that may evolve.
All data transfers outside the European Union are subject to appropriate safeguards in accordance with Articles 46 et seq. of the GDPR.
9. Retention periods
The retention periods necessary for the purposes pursued are as follows:
| Data category | Retention period |
|---|---|
| Account and profile data (active account) | Duration of account activity |
| Profile data on the waiting list (referral) | Retained for a maximum of one (1) year from completion of the profile in the absence of access validation, then deleted; immediate deletion in the event of voluntary deletion of the profile during the waiting period. Expiry of this period does not restrict a new request for access in any way. |
| Account data in the event of inactivity | 36 months from the last login, then deletion |
| Account data in the event of voluntary deletion | Immediate and irreversible deletion of directly identifying data (email, phone number, date of birth, photos, name), subject to data retained separately in accordance with the arrangements and periods specified below (connection logs, proof of acceptance of the GTU, content of messages and content shared in messaging, data relating to an ongoing moderation investigation or dispute). |
| Declaration and proof of age | Account duration + 36 months (limitation period): secure archiving |
| Behavioral and profiling data | Rolling 13 months, then irreversible anonymization |
| Support data (tickets) | 36 months from ticket closure |
| Proof of consent | 5 years from withdrawal or account closure |
| Prospecting data | 36 months from last contact, then deletion or renewal of consent |
| Data during the Account freeze period | The Profile is made anonymous and inaccessible, in the same manner as in the event of Account deletion, for the entire duration of the freeze |
| Data retained after deletion or banning of an account | |
| Connection logs (all accounts) | Rolling 12 months, then deletion |
| Moderation logs | 12 months from the decision, then deletion |
| Technical identifiers (user ID) in the event of a ban | 12 months from the ban, then deletion |
| Evidence of the conduct giving rise to the ban | 12 months, or the duration of legal/DSA proceedings if ongoing, then deletion |
| Data relating to a CSAE/CSAM report or investigation | Retained separately, for the duration of the investigation, the legal proceedings or the applicable legal obligation to cooperate, independently of the standard periods set out in this table |
| Proof of acceptance of the GTU | 36 months from account deletion |
| Content of messages and content shared in Messaging (private or Group/Event) after deletion or ban of an Account, or deletion of a Group | Retained for as long as at least one participant remains active on the Application; otherwise, retained for 90 days (or 12 months / duration of the investigation in the event of a dispute) then deleted. Linked to an anonymous identifier, not to the author's identity. |
| History of a discussion closed following a disconnection (User↔User or Group↔Group) | Maximum 36 months from the date of disconnection. Reappears if reconnection is accepted within this period; the counter then resets to zero in the event of a new disconnection. If no reconnection occurs within this period, permanent and irreversible deletion. |
| Content of a message individually deleted by the User | 90 days in technical backup from deletion, then permanent deletion |
Once the applicable periods expire, your data is securely deleted or irreversibly anonymized.
Article 9 bis — Consequences of user actions on your data
Certain actions you take within the Application have direct consequences for your personal data and that of your interactions. You are informed of this prior to each relevant action.
Disconnection between Users or between Groups. When you end a Connection with another User, or a Group ends a Connection with another Group, the associated discussion disappears from the Application for both parties. Its history is retained internally, in storage not accessible from the Application, for a maximum period of thirty-six (36) months from the date of disconnection.
Between two Users: if either User sends a reconnection request and the other accepts it within this 36-month period, the discussion and its history reappear in the Application and the exchange may resume. If no reconnection occurs within this period, the history is permanently and irreversibly deleted.
Between two Groups: the reconnection request is sent by the Group's Owner or an administrator, and must be accepted by the other Group within this same 36-month period. If accepted, the discussion and its history reappear only for members who were already present in the Group at the time of disconnection; any member who joined the Group after the disconnection does not have access to it. If no reconnection occurs within this period, the history is permanently and irreversibly deleted.
If a reconnection occurs and a new disconnection is subsequently decided, the 36-month retention period restarts in full from the date of this new disconnection.
The disconnection of a Group can only be decided by its Owner or a delegated administrator.
Voluntary departure or exclusion from a Group or an Event. In the event of voluntary departure from, or exclusion from, a Group or an Event, you lose access to the content, messaging and features associated with that Group or Event. If you are later reinstated, upon acceptance by the Creator, the Organizer or an administrator, you regain access to the entire history, including exchanges that took place during your absence.
Blocking between Users. Blocking is a feature reserved for relationships between two Users; a User cannot block a Group, which has a separate reporting mechanism. Blocking does not result in the deletion of any data; it only affects the accessibility of your data to the blocked User.
When you block another User, they lose all access to you: your Profile, your Activities, your posts in the News Feed, and your presence in the member lists of Groups you both belong to, where you no longer appear, to them only, other than as an anonymous avatar with no name. Other members continue to see you normally.
In a private discussion with this User, sending new messages becomes impossible for both parties, regardless of who initiated the block. The discussion only becomes active again once each User has lifted their block on the other; it then resumes exactly where it left off, with no loss of history.
In a Group discussion (within the same Group or between connected Groups), blocking does not interrupt the discussion: the blocked User continues to see all exchanges that took place before the block, which are not affected by it. However, messages sent by the person who blocked them during the blocking period appear to them under an anonymous avatar accompanied by the notice «Unauthorized message», and remain so permanently: unlike prior exchanges, these messages do not become visible or normally attributed again once unblocked.
Freezing of Profile. Freezing your Profile, whether at your own initiative or the Company's, renders your Profile anonymous and inaccessible within the Application, in the same manner as in the event of Account deletion, in accordance with the Article «What are the prerequisites for using the Services?» of the General Terms of Use. In a private discussion with another User, the exchange remains visible but closed: sending new messages is no longer possible for the duration of the freeze. In a Group discussion or between Groups, the freeze has no effect on the discussion itself, which remains fully active for other members; only your Profile appears there in anonymous form. Freezing does not result in the deletion of any data; upon unfreezing, your Profile and all your interactions return to normal.
Suspension of an Account or a Group. For the duration of a suspension, the Profile of the User or the Group concerned is treated as in the event of deletion: it becomes anonymous and inaccessible, and no longer appears in member, participant or attendance lists. In a private discussion with another User, the exchange remains visible but closed: sending new messages is no longer possible for the duration of the suspension. In a Group discussion or between Groups, the suspension has no effect on the discussion itself, which remains active for other members; only the suspended entity appears there in anonymous form. The suspension of a member within a Group does not affect the visibility or accessibility of the Group itself for other members. Unlike deletion, suspension is reversible: once lifted, full access to the Account or Group and to discussions is restored, with no loss of exchanges that took place in the meantime.
Deletion of a message. You may individually delete a message you have sent, whether in private Messaging or in Group or Event Messaging. Once deleted, this message is no longer displayed in the discussion, for you or for your interlocutors, and is replaced with a notice indicating its deletion. Its content is retained in technical backup for ninety (90) days, as with all data voluntarily deleted by Users, before permanent deletion.
Account Deletion. Deleting your Account results in the immediate anonymization of your Profile. Specifically:
Your direct identifiers (email address, phone number, date of birth, profile photos, Profile information) are deleted from the active database;
Your authentication tokens are revoked;
Your avatar is replaced with a neutral anonymous avatar and your name/first name with the notice «Deleted User»;
Your Profile no longer appears in Group member lists, Event participant lists, or attendance associated with a Destination or a Place, and becomes permanently inaccessible, including via links previously leading to it;
Messages, photos, videos, files and other content you exchanged with other Users, whether in private Messaging or in Group or Event Messaging, are not deleted merely because your Account was deleted; your identity appears there in anonymous form. Two scenarios apply depending on whether a disconnection occurred beforehand.
If no disconnection had occurred before your Account was deleted, the discussion and its content remain visible and accessible to your interlocutors for as long as they themselves remain active on the Application. If all other participants in this discussion also delete their Accounts, the discussion disappears from the Application and its retention then follows the periods specified in the Article «Retention periods» (ninety (90) days in the absence of a report, investigation or ongoing dispute, or twelve (12) months — or the duration of the proceedings if longer — otherwise).
If a disconnection had occurred before your Account was deleted, the discussion concerned had already disappeared from the Application at the time of disconnection, in accordance with the Article «Disconnection between Users or between Groups» above. Deleting your Account makes any reconnection permanently impossible: retention then no longer follows the 36-month period applicable to disconnection, but immediately switches to the periods specified in the Article «Retention periods» (90 days, or 12 months — or the duration of the proceedings — in the event of a report, investigation or ongoing dispute).
Data directly linked to your identity (profile photo, bio, preferences, personal information) deleted from the active database may temporarily remain in the Company's technical backups, solely for the purposes of incident recovery, security and system integrity, for a maximum period of ninety (90) days, after which it is permanently deleted.
Where your Account is subject to a report, investigation or moderation procedure in progress at the time of its deletion, the data strictly necessary for that investigation or procedure is retained separately, in secure storage not accessible from the Application, for the period specified in the Article «Retention periods», irrespective of the fate of the rest of your data described above.
Before actual deletion, you may retrieve your published data using the options available in the Application's settings.
Deletion of a Group. A Group can only be deleted once it no longer has any member other than its Owner; as long as other members belong to it, only their departure allows this to happen. If the Owner deletes their Account without having first designated another member as the new Owner or administrator, this role is automatically assigned to the longest-standing member of the Group still active. The Owner may at any time designate a new Owner or administrator before leaving the Group or deleting their Account. In all cases, the Profile of the Owner who deletes their Account no longer appears in the Group's member list, with only their messages remaining in the history in accordance with the Article «Account Deletion» above. Deletion of a Group results in its immediate anonymization: its avatar is replaced with a generic avatar and its name with the notice «Deleted User», and it becomes inaccessible across the entire Application. If no disconnection had occurred beforehand, discussions with other Groups remain visible to them, with their content, for as long as those other Groups remain active on the Application. If all Groups party to a discussion are deleted, that discussion disappears from the Application and its retention follows the periods specified in the Article «Retention periods». If a disconnection had occurred beforehand, retention immediately switches to these same periods, without waiting for the 36-month period applicable to disconnection to expire.
Deletion of an Event. An Event has no mechanism for transferring management to another User. If the Organizer deletes their Account, the Event is deleted for all participants, under the retention conditions specified in the Article «Retention periods».
Ban of an Account or a Group by the Company. In the event of a ban, the Profile of the User or the Group concerned undergoes the same treatment as a voluntary deletion, as described, depending on the case, in the Articles «Account Deletion» or «Deletion of a Group» above: the content of discussions remains visible to other parties, with only the banned entity becoming anonymous and inaccessible. Data necessary for the investigation, the moderation procedure or the defense of the Company's rights in the event of a dispute is retained separately for the periods specified in the Article «Retention periods».
Exception applicable in the event of seriously unlawful content. By way of exception to the principles described above, content may be subject to immediate deletion, with no continued visibility even in anonymized form, where it constitutes a serious violation of the law, in particular relating to child sexual exploitation or abuse (CSAE), within the meaning of the Article «How does the Application protect minors against sexual exploitation and abuse (CSAE)?» of the General Terms of Use, or terrorism. The determination of the unlawful nature of content and the manner of its removal are described in the Article «How do I report unlawful Content?» of the General Terms of Use: removal takes place without delay where it follows an order from a competent authority subject to a binding legal deadline, or following review by the Company's moderation teams, where applicable in consultation with its legal counsel, in other cases. Data strictly necessary for the investigation, judicial proceedings or cooperation with the competent authorities is retained separately, in secure storage not accessible from the Application, for the period specified in the Article «Retention periods».
10. Security of your data
GROUPP implements appropriate technical and organizational measures to protect your personal data against any unauthorized access, loss, alteration or disclosure:
Encryption in transit (TLS) and at rest (AES);
Role-based access control: access limited according to permissions;
Secure hosting on AWS servers in Paris;
Confidentiality obligations for anyone accessing the data;
Secure authentication by OTP when the account is created.
In the event of a data breach, the supervisory authority is notified within 72 hours in accordance with Article 33 of the GDPR, and Users are informed without undue delay in the event of a high risk to their rights and freedoms.
11. Your rights
You have the following rights regarding your personal data:
Right of access: obtain confirmation and a copy of your personal data processed by GROUPP.
Right to rectification: correct inaccurate or incomplete information concerning you.
Right to erasure: obtain deletion of your data under the legal conditions, in particular by deleting your Account from the Application's settings. Before actual deletion, you may retrieve the data you have published using the options available in the settings.
Right to restriction: temporarily suspend the use of your data without deleting it. Note that freezing the Account, available in the Application's settings, is an option that makes your Profile invisible without deleting your data.
Right to data portability: receive your data in a structured, commonly used and machine-readable format.
Right to object: object to processing based on legitimate interest or for commercial prospecting purposes.
Right to withdraw your consent: withdraw your consent at any time from the consent dashboard in the settings. Withdrawal does not affect the lawfulness of processing carried out before such withdrawal.
These rights may be exercised by writing to the following address: support@groupp.app or GROUPP EUROPE SA, Avenue Louise 231, 1050 Brussels. We will respond within one month, which may be extended by a further two months in the event of a complex or high volume of requests.
If you disagree with how your data is processed, you may lodge a complaint with the Belgian Data Protection Authority (www.autoriteprotectiondonnees.be).
12. Cookies and trackers
The Application may use trackers (SDKs, technical identifiers) for its technical operation and usage analysis.
Trackers essential to the operation of the Application are set without prior consent, as their use is strictly necessary for the provision of the service.
Optional trackers (analytics and marketing) require your prior consent, collected via the consent dashboard accessible from the Application's settings. You may change your choices at any time.
13. Changes
GROUPP reserves the right to amend this Privacy Policy to reflect changes to the Services, legal obligations or data protection practices.
In the event of a substantial change significantly affecting your rights or the conditions under which your data is processed, you will be informed by in-app notification and/or email at least thirty (30) days before the new provisions take effect.
Continued use of the Application after the changes take effect constitutes acceptance of the revised Policy.
14. Contact
| Channel | Contact details |
|---|---|
| Personal data | support@groupp.app |
| Contact – Data protection | support@groupp.app |
| Postal mail | GROUPP EUROPE SA: Avenue Louise 231 - 1050 Brussels - Belgium |
| Website | www.groupp.app |