The company GROUPP EUROPE SA (hereinafter “GROUPP”), a company incorporated under Belgian law, registered under number 0797.502.722, whose registered office is located at Avenue Louise 231, 1050 Brussels, Belgium, publishes and operates the Groupp mobile application (hereinafter the “ Application ”).
The Application is a search engine used to connect individuals, groups, events and venues in order to facilitate real-life meetings.
The Application is exclusively reserved for adult natural persons (18 years or older). Any minor is strictly prohibited from accessing it.
As publisher, GROUPP acts as data controller within the meaning of Article 4(7) of the GDPR. The purpose of this Policy is to inform you of how your personal data is processed and of the rights you have.
By creating an account on the Application, you confirm that you are 18 years of age or older and that you have read this Policy.
1. Definitions
Capitalized terms have the meaning set out below:
“GROUPP”: refers to GROUPP EUROPE SA, the data controller.
“Application”: refers to the Groupp mobile application (iOS and Android) and the website www.groupp.app.
“User”: refers to any adult natural person (18 years or older) who has created an Account on the Application.
“Group”: a set of Users brought together within a shared entity created on the Application.
“Personal Data”: any information that can be used to identify a natural person.
“Sensitive Data”: special categories of data referred to in Article 9 of the GDPR (religious beliefs, sexual orientation, etc.).
“DPA”: Belgian Data Protection Authority (the Belgian Data Protection Authority)
2. Data controller and age verification
Identity of the Data Controller
GROUPP EUROPE SA is the controller for all personal data processed in connection with the Application.
| Identity of the Data Controller |
| Company name: GROUPP EUROPE SA |
| Legal form: Public limited company (Société Anonyme) |
| Registered office: Avenue Louise 231, 1050 Brussels, Belgium |
| Company registration number: 0797.502.722 |
| Personal data contact: support@groupp.app |
For any questions, you may contact GROUPP at support@groupp.app or by post at the address of the registered office.
Age verification: Mechanisms and documentation
Access to the Application is strictly reserved for adults (18 years or older).
GROUPP implements the following measures:
Mandatory collection of date of birth when creating the account;
Explicit confirmation checkbox stating: “I confirm that I am 18 years of age or older and that I am an adult under the law of my country of residence”;
A clause in the GTU prohibiting access by minors;
Timestamped retention of the age declaration in the account creation logs: documentary evidence retained for the duration of the account plus the applicable limitation period.
If it is discovered that a user is a minor, GROUPP immediately suspends and deletes the account and erases all data collected.
3. Personal data collected
We only collect data that is strictly necessary for the purposes pursued:
Data you provide to us
When creating the Account (mandatory):
Username or nickname;
Email address (unverified);
Phone number (OTP);
Date of birth and confirmation of age (18 years or older): mandatory step retained as documentary evidence;
A profile photo (up to 6 photos may be added).
When creating the Profile (mandatory):
Age (automatically generated based on date of birth);
City of residence;
Gender;
Height;
Zodiac sign (automatically generated based on date of birth);
Languages spoken;
Favorite types of places;
Biography or personal description (a single emoji is sufficient).
When creating the Profile (optional — subject to your explicit consent):
Current or upcoming Destinations;
Links to social networks or any other URL;
Activities;
Groups created or joined;
Events created or attended;
Favorite cities;
Places frequented;
Dietary preferences that may reveal religious beliefs — this data constitutes Sensitive Data within the meaning of Article 9 of the GDPR and is subject to separate explicit consent;
Relationship status — which may reveal sexual orientation, this data constitutes Sensitive Data within the meaning of Article 9 of the GDPR and is subject to separate explicit consent.
When creating a Group, an Event or a Place:
Name, description, photos, date, location, activity, destination;
Contact details if you choose to display them.
When using Support:
Data provided via the in-app support system and during your exchanges with our team.
Data collected automatically
Browsing: log-ins, connection dates/times, screens visited, session duration;
Interactions: Connections, Groups, Events, filters, favorites, likes, messages;
Behavior (subject to consent): frequency, types of actions, and timing feed into the recommendation algorithm
Geographic location (if permission is granted — optional and revocable at any time).
Referral-related data
Information necessary to send the invitation.
Contact list and referral matching: where applicable, matching of your contact list with Users already present on the Application, in order to suggest a referral to you. If you join the Application using the referral code of one User while another User had also sent you a code, the latter is informed that you have joined the Application and is shown the username of the person whose code was used. When you authorize access to your phone's contact list, the Company carries out a technical comparison to identify contacts already present on the Application in order to facilitate referral referral and user connection mechanisms. Except where there is a specific technical need, the contact list as a whole is not retained permanently by the Company and is not used for commercial prospecting purposes.
If your profile is placed on the waiting list due to the lack of an available referral, your profile data is retained by the Company for a maximum period of one (1) year from completion of the profile, pending validation of access. After this period without validation, or in the event of voluntary deletion of your profile during this period, your data is deleted under the same conditions as a standard profile deletion. Expiry of this period does not restrict a new request for access in any way.
Data relating to Status and progression
number of validated referrals, progression towards the various Statuses, current Status, Status acquisition date, history of Status changes, and information necessary to prevent fraud related to the referral system.
You are responsible for data you share concerning third parties. You must ensure that the individuals concerned have been informed.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creation and management of the account; age verification | Email, phone number, username, date of birth, age declaration | Performance of the contract |
| Management of the referral system, allocation of Statuses and fraud prevention | Referral data, progression history, Status history | Performance of the contract + legitimate interest |
| Provision of the services | Profile, activity, location (if consented to), status | Performance of the contract |
| Personalization of suggestions (recommendation algorithm) | Enriched profile + behavioral data | Consent |
| User support | Identity, content of request | Performance of the contract |
| Marketing communications | Email, preferences | Consent |
| Technical operation, security | Technical data, logs | Legitimate interest |
| Evidence and retention of the age declaration | Date of birth, declaration, timestamp | Legitimate interest + legal obligation |
| Compliance with applicable legal obligations | Data relevant to the obligation | Legal obligation |
| Defense of GROUPP's rights | Relevant data | Legitimate interest |
| Retention of data in the event of a ban (traceability, defense in the event of a dispute) | User ID, moderation logs, evidence of conduct | Legitimate interest (art. 6(1)(f)) |
| Prevention, detection and reporting of CSAE-related content or conduct; cooperation with the competent authorities | Content, messages, profile and connection data relevant to the report | Legal obligation + legitimate interest (protection of minors, art. 6(1)(c) and (f) GDPR) |
Your consent may be withdrawn at any time from the consent dashboard in the settings. This does not affect the lawfulness of prior processing.
As all Users are adults, consent to profiling is fully valid with no age-related reservation.
5. Profiling and recommendation algorithm
How the algorithm works
Our algorithm cross-references your declarative data (profile) and behavioral data (usage) to suggest Groups, Events, Places and Users matching your interests.
It takes into account: your profile data, your in-app behavior (frequency, content viewed, filters used) and aggregated community trends.
Effects of profiling
This profiling personalizes the content and suggestions offered to you. It does not produce any automated decision having legal effects within the meaning of Article 22 of the GDPR.
Legal basis and right to object
This processing is based on your consent (Article 6(1)(a) of the GDPR), which may be withdrawn at any time from the consent dashboard in the settings. If withdrawn, you continue to benefit from the Services but without personalization.
As all Users are adults, consent to profiling is fully valid with no age-related reservation.
6. Access permissions
No permission is activated without your explicit agreement. These permissions can be changed at any time from your phone's or the Application's settings.
Location: to suggest nearby Groups, Events and Places. Optional and revocable.
Photo album / gallery and camera: to add photos to your Profile or to the elements you create. Optional.
Contact list: to invite contacts to join the Application. Optional.
Calendar / agenda: to save Events directly to your personal calendar. Optional.
Push notifications: manageable from the Application's settings.
Refusing or disabling certain of these permissions may limit access to certain features without blocking general use of the Application. Details of the data collected via each permission, its purpose and its legal basis are available in Article 4
7. Who receives your data?
Internally
Developers (full access under NDA) and administrators;
Support, community management and moderation (access limited to data strictly necessary for their duties).
Processors (art. 28 GDPR)
Hosting: Amazon Web Services (AWS), Paris region, European Union;
Development: technical providers under NDA and an Article 28 contract;
Other users
Your Profile information is visible to other Users according to your privacy settings. Your phone number and email address are never visible to other Users. Certain data may only be accessible to Users with whom you are connected, who are members of the same Group, or who are attending the same Event.
Apple and Google
In connection with downloading the Application, Apple and Google act as independent data controllers for data collected on their respective platforms. Please refer to their privacy policies for more information.
Competent judicial and administrative authorities.
In the event of a confirmed report of content or conduct constituting child sexual exploitation or abuse (CSAE), data strictly necessary may be transmitted to the competent authorities, in particular to the dedicated Belgian contact point for combating illegal content online (eCops, federal police) and, where applicable, to Child Focus or any equivalent authority in the jurisdiction concerned, in accordance with the “How does the Application protect minors against sexual exploitation and abuse (CSAE)?” Article of the General Terms of Use.
8. Transfers outside the European Union
Your data is hosted within the European Union (AWS, Paris region).
Certain technical providers may be established outside the European Union, in particular in the United Kingdom. In such cases, transfers are governed by Standard Contractual Clauses (European Commission Decision 2021/914), used as a safety net independently of any adequacy decision mechanism that may evolve.
All data transfers outside the European Union are subject to appropriate safeguards in accordance with Articles 46 et seq. of the GDPR.
9. Retention periods
The retention periods necessary for the purposes pursued are as follows:
| Data category | Retention period |
|---|---|
| Account and profile data (active account) | Duration of account activity |
| Profile data on the waiting list (referral) | Retained for a maximum of one (1) year from completion of the profile in the absence of access validation, then deleted; immediate deletion in the event of voluntary deletion of the profile during the waiting period. Expiry of this period does not restrict a new request for access in any way. |
| Account data in the event of inactivity | 36 months from the last login, then deletion |
| Account data in the event of voluntary deletion | Immediate and irreversible deletion of directly identifying data (email, phone number, date of birth, photos, name), subject to data retained separately in accordance with the arrangements and periods specified below (connection logs, proof of acceptance of the GTU, content of group messages, data relating to an ongoing moderation investigation or dispute). |
| Declaration and proof of age | Account duration + 36 months (limitation period): secure archiving |
| Behavioral and profiling data | Rolling 13 months, then irreversible anonymization |
| Support data (tickets) | 36 months from ticket closure |
| Proof of consent | 5 years from withdrawal or account closure |
| Prospecting data | 36 months from last contact, then deletion or renewal of consent |
| Data during the Account freeze period | The Profile is made temporarily invisible and access to associated features is suspended for the entire duration of the freeze |
| Data retained after deletion or banning of an account | |
| Connection logs (all accounts) | Rolling 12 months, then deletion |
| Moderation logs | 12 months from the decision, then deletion |
| Technical identifiers (user ID) in the event of a ban | 12 months from the ban, then deletion |
| Evidence of the conduct giving rise to the ban | 12 months, or the duration of legal/DSA proceedings if ongoing, then deletion |
| Data relating to a CSAE/CSAM report or investigation | Retained separately, for the duration of the investigation, the legal proceedings or the applicable legal obligation to cooperate, independently of the standard periods set out in this table |
| Proof of acceptance of the GTU | 36 months from account deletion |
| Content of group messages after account deletion/ban | Retained internally for 12 months (linked to an anonymous identifier), not displayed to other Users |
Once the applicable periods expire, your data is securely deleted or irreversibly anonymized.
Article 9 bis — Consequences of user actions on your data
Certain actions you take within the Application have direct, and sometimes irreversible, consequences for your personal data and that of your interactions. You are informed of this prior to each relevant action.
Disconnection between Users. When you end a Connection with another User, the history of the private conversation between you is irreversibly deleted. Certain interactions and information previously accessible may become inaccessible. If you reconnect later, a new conversation is created with no automatic recovery of the previous history.
Voluntary departure or exclusion from a Group or an Event. In the event of voluntary departure from, or exclusion from, a Group or an Event, you lose access to the content, messaging and features associated with that Group or Event. This loss of access is irreversible, even if you rejoin later.
Blocking a User. Blocking limits direct interactions between you and the blocked User. Certain content previously exchanged or shared may become inaccessible. Blocking does not guarantee complete invisibility in the Application's shared spaces (common Groups or Events).
Account Deletion. Deleting your Account results in immediate and irreversible anonymization of your profile. Specifically:
Your direct identifiers (email address, phone number, date of birth, profile photos) are deleted;
Your authentication tokens are revoked;
In group conversations (Groups, Events), the actual content of the messages you sent is retained internally, linked to an anonymous identifier rather than to your name, for a period of 12 months, for moderation and defense purposes in the event of a dispute. This internal retention does not affect the “Message deleted” display visible to other participants.
No residual technical identifier that would allow, by cross-referencing with other data, the record to be linked to your identity remains within the Application;
In group conversations (Groups, Events), your messages are replaced with the notice “Message deleted” in order to preserve continuity of the conversation for other participants;
Your avatar is replaced with a neutral gray circle and your name/first name with the notice “Deleted User”;
Your profile no longer appears in Group member lists, Event participant lists, or attendance associated with a Destination or a Place.
Certain data strictly necessary to comply with our legal obligations is retained separately in secure storage not accessible from the Application, for the periods specified in Article 9. Before actual deletion, you may retrieve your published data using the options available in the Application's settings.
Banning of the Account by the Company. In the event of a ban, your profile undergoes the same visual treatment as a voluntary deletion: gray avatar, “Deleted User” notice, removal from member, participant and attendance lists. Certain data is retained by Groupp for the periods specified in Article 9.
10. Security of your data
GROUPP implements appropriate technical and organizational measures to protect your personal data against any unauthorized access, loss, alteration or disclosure:
Encryption in transit (TLS) and at rest (AES);
Role-based access control: access limited according to permissions;
Secure hosting on AWS servers in Paris;
Confidentiality obligations for anyone accessing the data;
Secure authentication by OTP when the account is created.
In the event of a data breach, the supervisory authority is notified within 72 hours in accordance with Article 33 of the GDPR, and Users are informed without undue delay in the event of a high risk to their rights and freedoms.
11. Your rights
You have the following rights regarding your personal data:
Right of access: obtain confirmation and a copy of your personal data processed by GROUPP.
Right to rectification: correct inaccurate or incomplete information concerning you.
Right to erasure: obtain deletion of your data under the legal conditions, in particular by deleting your Account from the Application's settings. Before actual deletion, you may retrieve the data you have published using the options available in the settings.
Right to restriction: temporarily suspend the use of your data without deleting it. Note that freezing the Account, available in the Application's settings, is an option that makes your Profile invisible without deleting your data.
Right to data portability: receive your data in a structured, commonly used and machine-readable format.
Right to object: object to processing based on legitimate interest or for commercial prospecting purposes.
Right to withdraw your consent: withdraw your consent at any time from the consent dashboard in the settings. Withdrawal does not affect the lawfulness of processing carried out before such withdrawal.
These rights may be exercised by writing to the following address: support@groupp.app or GROUPP EUROPE SA, Avenue Louise 231, 1050 Brussels. We will respond within one month, which may be extended by a further two months in the event of a complex or high volume of requests.
If you disagree with how your data is processed, you may lodge a complaint with the Belgian Data Protection Authority (www.autoriteprotectiondonnees.be).
12. Cookies and trackers
The Application may use trackers (SDKs, technical identifiers) for its technical operation and usage analysis.
Trackers essential to the operation of the Application are set without prior consent, as their use is strictly necessary for the provision of the service.
Optional trackers (analytics and marketing) require your prior consent, collected via the consent dashboard accessible from the Application's settings. You may change your choices at any time.
13. Changes
GROUPP reserves the right to amend this Privacy Policy to reflect changes to the Services, legal obligations or data protection practices.
In the event of a substantial change significantly affecting your rights or the conditions under which your data is processed, you will be informed by in-app notification and/or email at least thirty (30) days before the new provisions take effect.
Continued use of the Application after the changes take effect constitutes acceptance of the revised Policy.
14. Contact
| Channel | Contact details |
|---|---|
| Personal data | support@groupp.app |
| Contact – Data protection | support@groupp.app |
| Postal mail | GROUPP EUROPE SA: Avenue Louise 231 - 1050 Brussels - Belgium |
| Website | www.groupp.app |