Legal

This is an English translation. The Spanish version is the one that governs; switch the language to Spanish to read it.

Privacy policy

Version: 2026-09-30

Last updated: 2026-09-30

1. Who is responsible for your data

The controller of the personal data used to operate Vazely is:

While Vazely is provided as a closed beta, free of charge and with no economic activity, the identification of the controller is the one required by Article 13 GDPR: who they are and how to contact them. The tax identification number and the address will be published in the Legal notice when the service becomes economic in nature, as explained there.

  • Privacy email: [email protected]
  • General contact: [email protected]
  • Data protection officer: none has been appointed. None of the cases in Article 37 GDPR that require one to be appointed applies.

This policy applies to the site https://vazely.com, to Vazely accounts and to the communications related to the service.

2. What data we process

The specific data depends on how you use Vazely.

2.1 Account and security

  • Internal identifier, name, email address and verification status.
  • Password protected by a cryptographic function. Vazely does not need to keep the password in readable text.
  • Second factor, recovery codes and temporary confirmations when they are enabled or confirmation of a sensitive action is required.
  • Open sessions, IP address, browser, operating system, creation dates and last activity.
  • Sign-in attempts, temporary lockouts and other data needed to prevent fraud or unauthorised access.
  • Identifier of an external account and basic data provided by the provider when you choose to sign in with Google or Discord. The details are in section 2.11.
  • Date of birth, which is requested when you sign up, together with a record of how it was obtained —today always declared by you— and when. It is not shown on your profile, does not travel to any public page and is not disclosed to anyone: it is used only to answer two questions, whether you may have an account and whether you may organise events.
  • A record that you accepted the Terms of use and the Community guidelines, with the specific version and the date.

2.2 Profile and public identities

  • @handle, display name, biography, country, language, avatar and cover.
  • Your choice to show or hide your country and other privacy options.
  • Chosen main team, where applicable.
  • Teams, organisations and communities created, ownership, members, roles and notification or mute preferences.

The @handle belongs to a single namespace shared by people, teams, organisations and communities. When an identity is deleted, Vazely keeps a minimal record of the identifier to prevent someone else from adopting a name that was already known, followed or used to publish.

2.3 Social activity and content

  • Posts, replies, images and other content you publish.
  • Authorship, dates, tags and relationships between posts.
  • Profiles you follow, requests sent or received and the status of those requests.
  • Likes, interactions and signals used to order or recommend content.
  • Visibility preferences, whether you can receive requests and whether you appear in recommendations.
  • Notifications within Vazely and the associated email preferences.
  • Communities you take part in, access requests and invitations, and posts you make within them.
  • Discussions you open, messages, replies, votes, topics, read status and mutes.

2.4 Matches

  • Matches created or managed, game, date and time, duration, in-person or online format, venue, address, level, notes, places and distribution by sides.
  • Participation, invitations, joins, departures and removals.
  • Chat messages and events reflecting relevant changes to the match.
  • Proposed results, placements, confirmations, disputes and who reported them.

2.5 Studio, events and organisation

  • Acceptance of the Studio terms, version and date of acceptance.
  • Events created or managed, collaborators, permissions, dates, location, time zone, description, images and publication or cancellation status.
  • Ticket types, zones, capacities, prices, taxes, promotional codes, limits and other commercial configuration of the event.
  • Sensitive actions such as ownership transfers, deletions and status changes that must be recorded for security or to resolve disputes.

2.6 Orders and tickets

If you buy with an account, we link the order to that account. If you buy as a guest, we process the name, email, language, confirmation code and a secret token that lets you return to the order.

We also process:

  • the event, the seller and the products included;
  • amounts, currency, discounts, taxes and the fee shown;
  • payment method and status, without card data while payment takes place outside Vazely;
  • dates of reservation, confirmation, cancellation or refund;
  • ticket holders' names, ticket codes and redemption data;
  • messages needed to deliver the order and notify you of its status.

The event organiser receives the data needed to manage the sale, check the payment, issue the tickets, control access and deal with incidents. Their identity and privacy policy must be shown before purchase.

2.7 Communications, newsletter and support

  • Messages you send to support and the information needed to answer them.
  • Transactional emails related to the account, security, requests, events or orders.
  • If you subscribe to the newsletter: email address, date and screen from which you subscribed, language of the sentence shown and technical subscription identifier.
  • Record of subscription and unsubscription needed to demonstrate and respect your choice.
  • Device push notification subscriptions —delivery service address, public key and technical secret— when you enable them. Vazely does not receive the content of other notifications or a general device identifier.

2.8 Technical data

  • IP address used transiently to rate-limit requests and protect the service when the deployment sits behind the configured trusted infrastructure.
  • Technical headers, error and security logs generated by the servers or infrastructure providers.
  • Cookies and storage described in the Cookie policy.

Vazely does not currently use this data for advertising or cross-site tracking.

2.9 Data provided by other people or services

Not all information comes directly from you. It may come from:

  • another person who invites you to an account, team, organisation, community, match or event;
  • a buyer who gives another person's name as the holder of a ticket;
  • members or organisers performing a shared action;
  • a social sign-in provider that you choose to use;
  • an authority, a reporter or an affected person in a moderation procedure;
  • public sources when it is necessary to check an identity, a right or content.

We use that data only to process the action, provide the service, verify the information, comply with obligations or resolve the relevant incident. Where the GDPR requires individual notice and no exemption applies, we will provide the information at the first contact or within the legal time limit.

2.10 Special categories

Vazely does not request data on health, religion, ideology, trade union membership, racial or ethnic origin, sex life or sexual orientation, or other specially protected data, to create an account or personalise the service.

A person may voluntarily disclose information of that nature in a post. We will host it with the chosen visibility and the applicable safeguards, but specially protected information about third parties must not be published without a valid basis.

That information is not used to recommend anything to you. The recommender learns from a post's tags, and those that may reveal health, beliefs, ideology, trade union membership, ethnic origin or sexual orientation are discarded before they reach it. The filter is written as a list of fragments and not as a classifier, precisely so as not to build a second system that infers the categories this one exists not to infer; that is why it errs on the side of discarding too much rather than too little.

The tag stays on your post, is public and can be searched: what does not happen is that it is used to infer your interests. The legitimate interest that covers recommendations would not on its own be enough to process those categories, and there is no other basis for doing so.

2.11 If you sign in with Google or Discord

You can sign in to Vazely with your Google or Discord account, and create your account that way when registration is open. It only happens if you choose that button, and you can link or unlink those accounts whenever you want from Settings → Security → Linked accounts. No external account is linked to yours without you first confirming your password.

What data we receive. When you authorise access, the provider sends us only:

  • the identifier of your account with that provider;
  • your email address and whether the provider has verified it;
  • your name (on Discord, your display name or your username) and the address of your profile picture;
  • the technical tokens the provider issues on completing sign-in.

We only ask for the minimum permissions needed to identify you: on Google, openid, email and profile; on Discord, identify and email. We do not access your contacts, files, emails, calendar, servers, messages or any other data in those accounts.

What we use it for. Exclusively to:

  • identify you when you sign in;
  • create your account, if registration is open and your address does not already have one;
  • link the external account to yours, and notify you by email each time one is linked;
  • check that the address you use is verified, because we do not create accounts from addresses the provider has not confirmed.

The name is only used as the initial name of your profile, which you can change. The provider's picture is not published: it can only appear in your own menu until you upload an avatar. The tokens are stored encrypted alongside the link, and we do not use them to access your account with the provider or for any other purpose.

What we do not do. We do not sell this data, we do not use it for advertising or for the recommender, we do not disclose it to third parties and we do not use it to train artificial intelligence models. Vazely's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How long. For as long as the external account remains linked. When you unlink it, its identifier and its tokens are deleted; when you delete your Vazely account, all links are deleted in the same purge as the rest of the credentials. You can also revoke access from your Google account (Security → Third-party apps and services) or your Discord account (Settings → Authorised apps).

Legal basis. Performance of the contract for the use of Vazely, because it is the means of access you choose. Google and Discord, for their part, process the data of your accounts with them as independent controllers, in accordance with their own privacy policies.

3. What we use data for and on what legal basis

PurposeMain dataLegal basis
Creating the account, authenticating you and providing the social features requestedAccount, session, profile, content, relationships and preferencesPerformance of the contract with you
Maintaining security, preventing abuse, investigating incidents and protecting accountsSessions, IP, user-agent, attempts, confirmations and logsLegitimate interest in protecting Vazely and its users; compliance with legal obligations where applicable
Publishing content and applying the chosen visibilityProfile, posts, replies, images, teams, organisations and communitiesPerformance of the contract and action requested by the person publishing
Operating communities, discussions and matchesMemberships, roles, messages, votes, places, invitations, results and preferencesPerformance of the contract; legitimate interest in maintaining the integrity and security of shared activities
Personalising the For you sectionLikes, post metadata and tags, popularity, age and affinityLegitimate interest in offering relevant discovery, subject to the right to object
Checking that you meet the minimum age and that you may organise eventsDate of birth and how it was obtainedCompliance with legal obligations, and performance of the contract as regards which features apply to you
Proving which terms you accepted and whenVersion accepted and dateCompliance with legal obligations and legitimate interest in being able to demonstrate the agreement
Operating Studio, events and shared permissionsIdentities, roles, events, acceptances and auditPerformance of the contract; legitimate interest in proving sensitive actions
Reserving, confirming and delivering orders or ticketsIdentity of the buyer, seller, order, amounts, status and codesPerformance of the purchase contract and of the intermediation services
Complying with commercial, tax and consumer obligations or requests from authoritiesOrders, invoicing, identity and auditCompliance with legal obligations
Handling illegal content, moderation, complaints and the defence of rightsContent, reports, decisions, communications and auditCompliance with the Digital Services Act and other obligations; legitimate interest in enforcing the rules
Sending communications essential to the serviceEmail, language, security, requests and ordersPerformance of the contract, legal obligation or legitimate interest depending on the message
Sending the newsletterEmail, language and proof of subscriptionConsent, which can be withdrawn at any time
Providing support and bringing or defending claimsData provided in the enquiry and related recordsPerformance of the contract, legitimate interest and, where appropriate, legal compliance

We do not make the account conditional on accepting the newsletter. Withdrawing that consent does not affect the lawfulness of the mailings sent before the withdrawal or the messages needed to operate the account or deliver an order.

Required and optional data

The email, name, password, @handle and country of the personal profile are required to create and complete an account under the current rules. The country is kept even if you decide not to show it publicly. Without the mandatory data we cannot create the account, protect access or provide the restricted features.

For a guest order, a name, an email and confirmation of that address are required. Each event may also require the holder or access data explained before purchase. A professional organiser must provide the legal and tax data required in order to sell.

The biography, images, main team, newsletter and other fields identified as optional may be left empty or turned off without preventing general use, although a specific feature may not be available without the data it needs.

4. What information is public

Depending on the type of identity and your settings, the following may be public: the @handle, display name, avatar, cover, biography, country if you choose to show it, social figures, teams, organisations, communities, events and published content. Matches hosted by a public community and their list of participants may also be public; a match's chat is limited to the members of that community.

Other users may re-share or keep what you make public. Vazely can remove its own copy or restrict access, but cannot delete copies made outside the service by third parties.

Privacy options control how things are presented within Vazely, but must not be used to publish information you have no right to disclose.

5. Recommendations and profiling

Vazely offers two home sections:

  • Following, based mainly on the profiles you follow and ordered using stable time-based pagination.
  • For you, which selects and orders posts using Gorse or an in-house algorithm.

When Gorse is active, the system takes into account your Likes, the posts liked by accounts with similar interactions and content tags such as language, author and hashtags. For accounts without enough signal it may fall back on related, popular or recent content, and it mixes in a small exploratory selection. It does not semantically analyse text using an artificial intelligence model.

When SQL mode is active, the order is based mainly on the number of Likes and on the age of the post: the score loses weight over time and does not use an individual taste profile. In both modes, privacy and the author's choice to appear in recommendations are applied first.

These signals are used to estimate which posts may interest you; they do not determine your access to employment, credit, insurance or other legal or similarly significant effects. Following a profile determines the content of the Following section, but is not currently fed into Gorse as an affinity signal.

Gorse is operated by Vazely and receives internal identifiers, post identifiers and interaction signals. Its developers do not receive that information merely because the software is used.

You can use the Following section as an alternative that is not based on that personal selection. You can also object to the processing of your data for recommendations by writing to [email protected]. We will assess the request under Article 21 GDPR and inform you of the outcome.

6. Who we share data with

We do not sell personal data.

We may disclose it to:

6.1 Other users and those responsible for identities

Content reaches the people who can see it according to whether it is public and the settings chosen. Those who administer a team, organisation, community, match or event may access the data needed to exercise their permissions.

6.2 Organisers and sellers

The seller and the people authorised to manage an event receive the order, attendee and ticket data needed to deliver the event and meet their obligations.

For the data of people attending an event, the organiser is the controller and Vazely the processor: it is the organiser who decides what is sold, to whom and on what terms, and who keeps the relationship with the buyer. Vazely processes that data following the organiser's instructions and within the terms of the service it provides. This allocation will be reviewed when Vazely processes payments, because it will then process data on its own behalf as well as on the organiser's.

6.3 Providers working for Vazely

ServiceProvider and locationData and purpose
Hosting, database and backupsOVH (Gravelines, France)General hosting of the service
Network, protection and content deliveryCloudflare (global network)IP, headers and traffic needed for security and delivery
Image storageCloudflare R2 (European jurisdiction)Avatars, covers and published images
Email deliveryResend (United States)Name, email, language and message content
Push notification deliveryPush service chosen by the browserSubscription address and encrypted message in order to deliver it
Social sign-inGoogle and Discord (United States)Only if you choose to sign in with them; see section 2.11
External game catalogueIGDB (Twitch): server queries onlyCatalogue queries made from the server
Future paymentsNot applicable yetNot applicable while Vazely does not process online payments

PostgreSQL, Valkey, Garage, imgproxy, Gorse and Listmonk are run within the infrastructure contracted by Vazely. They are not in themselves external recipients.

Providers may only process data following documented instructions and with the safeguards required by law, when they act as processors.

6.4 Legal obligations and transactions

We may disclose information to judges, authorities, law enforcement or competent bodies where there is a valid obligation or legal basis. It may also be necessary to share it with professional advisers or in a business reorganisation, applying confidentiality and the corresponding safeguards.

7. International transfers

Hosting, the database and backups are in France. Cloudflare —edge and image storage— operates a global network: the bucket is configured with European jurisdiction, so objects are stored in the European Union, while traffic is served from the node closest to whoever requests it, which may be outside it. Email is sent through Resend, based in the United States, and covers only the name, the address, the language and the content of the message. If you sign in with Google or Discord, both based in the United States, the sign-in passes through their servers and they return to us the data in section 2.11. If you enable push notifications, the encrypted message passes through the delivery service chosen by your browser or operating system, which may operate outside the European Economic Area; the provider receives the technical address of the subscription, but cannot read the content encrypted by Vazely.

Transfers outside the European Economic Area are covered by the European Commission's standard contractual clauses that each provider includes in its data processing agreement.

If a provider processes data outside the European Economic Area, Vazely will apply the mechanism required by the GDPR, such as an adequacy decision, standard contractual clauses and supplementary measures where necessary. You can request information about the applicable safeguards by writing to [email protected].

8. How long we keep data

We keep data only for as long as necessary for each purpose and to comply with obligations or deal with liabilities. In particular:

CategoryCriterion or period
Active account and profileFor as long as you keep the account
Account whose deletion you have confirmed30 days for recovery. After that, credentials and sessions are revoked, personal data is deleted or anonymised, and a minimal record of the identifier and @handle is kept to prevent impersonation or reassignment
Avatar and cover of a deleted identityThey are unlinked when the identity is deleted or purged, and their deletion from storage is attempted after the operation is confirmed
Linked Google or Discord accountsFor as long as they remain linked. They are deleted when unlinked and, in any case, in the account purge
Date of birthFor as long as you keep the account. It is asked for once and not asked again; it disappears with the account, in the same purge as everything else
Acceptance of the termsFor as long as you keep the account, and with the specific version, because that is the only way to know which text it refers to
Deleted posts and repliesindefinitely for now: the body is marked as deleted and stops being shown anywhere in the service, but is not yet removed from the database. A period is planned to be set and applied with a sweep. Except for a legal hold or a specific need for defence
SessionsUp to 30 days, unless closed, revoked or deleted earlier
Temporary confirmations and verificationsFor as long as they are valid —fifteen minutes for six-digit codes and thirty for email links— and the additional time for their technical clean-up
Sign-in attempts and security logsFifteen minutes per failed sign-in attempt, which is the lockout window; once it has passed, the record no longer counts
Orders, tickets and buyer dataindefinitely for now. When there are real payments, the period will be that of commercial, tax and consumer obligations and possible claims. For reference, certain commercial documents are kept for six years in Spain
Baskets not converted into an orderUntil they expire, between five and sixty minutes depending on how the organiser configures it. The row stops having effect at that moment and is deleted when the reservation is released
Deleted discussions and messagesThey are marked as deleted and stop being shown, except for the tombstone needed to preserve the reply structure. Their content is kept indefinitely for now, subject to the same period still to be set as deleted posts
Matches, places, messages and resultsFor as long as they are needed to show the community's history and resolve incidents. Deleted messages stop being shown but are kept indefinitely for now; when an account is purged its places are removed and its messages stop being shown
NewsletterFor as long as you remain subscribed. Proof of subscription and unsubscription is kept for as long as the account exists, to demonstrate and respect your choice
Push subscriptionsUntil you disable them, the delivery service reports that they are no longer valid, or the account is purged
Reports and moderation decisionsone year from when the decision becomes final, taking into account the appeal period and possible legal obligations
Audit of sensitive actions and acceptance of termsFor as long as the account exists. The audit records ownership movements and names taken away, which is precisely what the rest of the database can no longer reconstruct
Supportone year from the closing of the enquiry, unless it has to be linked to a claim
Backups and infrastructure logsAccording to the hosting provider's rotation, which will be detailed as soon as the final deployment is settled; the data is isolated and disappears with the rotation of the backup

Where there is a claim, investigation or retention obligation, the data concerned may be blocked for the applicable period and used only for that purpose.

9. Your rights

You can request:

  • access to your data and to information about its processing;
  • rectification of inaccurate or incomplete data;
  • erasure when it is no longer necessary or another legal ground applies;
  • restriction of processing in the cases provided for by the GDPR;
  • portability of the data you have provided when the processing is based on consent or the contract and is carried out by automated means;
  • objection to processing based on legitimate interest, including personalised recommendations;
  • withdrawal of consent for the newsletter or other processing based on it, without retroactive effect;
  • not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.

You can edit many data and preferences directly from the settings. To exercise a right that is not available there, write to [email protected] stating what you are requesting. We may ask for reasonable information to verify your identity without collecting more data than necessary.

We will respond without undue delay and, normally, within one month. Exercising your rights is free of charge except for manifestly unfounded or excessive requests within the meaning of the GDPR.

If you believe the processing breaches the law, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) or with the supervisory authority corresponding to your place of residence or work.

10. Account deletion

Requesting deletion requires your password and a code sent to your email. The account is deactivated and sessions are revoked. During the following 30 days you can recover it; at the end of that period the purge described in the retention section is carried out.

Deletion cannot be completed while the account owns a team, an organisation, a community or an event that must continue to have someone responsible for it. It must first be transferred or deleted. This limitation protects members, participants, attendees and buyers and does not prevent you from exercising other data protection rights.

Deleting the account does not require deleting records that must be kept by law, third parties' orders or sufficiently anonymised data. We will tell you if a specific request is limited for any of those reasons.

11. Minors

Vazely is intended for people aged at least 14, which is the age from which Article 7 of Spanish Organic Law 3/2018 (LOPDGDD) allows a person to consent on their own to the processing of their personal data. Organising events also requires being 18.

If you are under 14 you cannot create an account. If you believe a minor under that age has created one, or if you hold parental authority or guardianship over a person between 14 and 18 and wish to exercise their rights, write to [email protected].

If we discover that an account does not meet the minimum age or that data of a minor has been processed without the necessary legal basis, we will take measures to restrict the processing and delete the relevant information. An incident can be reported to [email protected].

Attendance at an event may have a different age set by the organiser and does not change the minimum age required to create an account.

12. Security

We apply technical and organisational measures proportionate to the risk, including access control, revocable sessions, email verification, a second factor for Studio, attempt limits, separation of credentials, backups and minimisation of the data disclosed to auxiliary services.

No system is completely infallible. If you detect unauthorised access or a vulnerability, write to [email protected] and do not publish personal data or credentials in open channels.

13. Changes to this policy

We will update this policy when the purposes, providers, technologies or legal requirements change. We will publish the new version and, if the change is significant, we will communicate it by an appropriate means before it takes effect where necessary.

A privacy policy provides information about processing; it does not become general consent by continuing to use Vazely. Where a purpose requires your consent, it will be requested separately and specifically.

Privacy policy