Privacy policy
Version:
2026-09-30Last updated:
2026-09-30
1. Who is responsible for your data
The controller of the personal data used to operate Vazely is:
- Controller:
Aitor Chicharro - Contact:
[email protected], handled by the owner
While Vazely is provided as a closed beta, free of charge and with no economic activity, the identification of the controller is the one required by Article 13 GDPR: who they are and how to contact them. The tax identification number and the address will be published in the Legal notice when the service becomes economic in nature, as explained there.
- Privacy email:
[email protected] - General contact:
[email protected] - Data protection officer: none has been appointed. None of the cases in Article 37 GDPR that require one to be appointed applies.
This policy applies to the site https://vazely.com, to Vazely accounts and to the communications related to the service.
2. What data we process
The specific data depends on how you use Vazely.
2.1 Account and security
- Internal identifier, name, email address and verification status.
- Password protected by a cryptographic function. Vazely does not need to keep the password in readable text.
- Second factor, recovery codes and temporary confirmations when they are enabled or confirmation of a sensitive action is required.
- Open sessions, IP address, browser, operating system, creation dates and last activity.
- Sign-in attempts, temporary lockouts and other data needed to prevent fraud or unauthorised access.
- Identifier of an external account and basic data provided by the provider when you choose to sign in with Google or Discord. The details are in section 2.11.
- Date of birth, which is requested when you sign up, together with a record of how it was obtained —today always declared by you— and when. It is not shown on your profile, does not travel to any public page and is not disclosed to anyone: it is used only to answer two questions, whether you may have an account and whether you may organise events.
- A record that you accepted the Terms of use and the Community guidelines, with the specific version and the date.
2.2 Profile and public identities
@handle, display name, biography, country, language, avatar and cover.- Your choice to show or hide your country and other privacy options.
- Chosen main team, where applicable.
- Teams, organisations and communities created, ownership, members, roles and notification or mute preferences.
The @handle belongs to a single namespace shared by people, teams, organisations and communities. When an identity is deleted, Vazely keeps a minimal record of the identifier to prevent someone else from adopting a name that was already known, followed or used to publish.
2.3 Social activity and content
- Posts, replies, images and other content you publish.
- Authorship, dates, tags and relationships between posts.
- Profiles you follow, requests sent or received and the status of those requests.
Likes, interactions and signals used to order or recommend content.- Visibility preferences, whether you can receive requests and whether you appear in recommendations.
- Notifications within Vazely and the associated email preferences.
- Communities you take part in, access requests and invitations, and posts you make within them.
- Discussions you open, messages, replies, votes, topics, read status and mutes.
2.4 Matches
- Matches created or managed, game, date and time, duration, in-person or online format, venue, address, level, notes, places and distribution by sides.
- Participation, invitations, joins, departures and removals.
- Chat messages and events reflecting relevant changes to the match.
- Proposed results, placements, confirmations, disputes and who reported them.
2.5 Studio, events and organisation
- Acceptance of the Studio terms, version and date of acceptance.
- Events created or managed, collaborators, permissions, dates, location, time zone, description, images and publication or cancellation status.
- Ticket types, zones, capacities, prices, taxes, promotional codes, limits and other commercial configuration of the event.
- Sensitive actions such as ownership transfers, deletions and status changes that must be recorded for security or to resolve disputes.
2.6 Orders and tickets
If you buy with an account, we link the order to that account. If you buy as a guest, we process the name, email, language, confirmation code and a secret token that lets you return to the order.
We also process:
- the event, the seller and the products included;
- amounts, currency, discounts, taxes and the fee shown;
- payment method and status, without card data while payment takes place outside Vazely;
- dates of reservation, confirmation, cancellation or refund;
- ticket holders' names, ticket codes and redemption data;
- messages needed to deliver the order and notify you of its status.
The event organiser receives the data needed to manage the sale, check the payment, issue the tickets, control access and deal with incidents. Their identity and privacy policy must be shown before purchase.
2.7 Communications, newsletter and support
- Messages you send to support and the information needed to answer them.
- Transactional emails related to the account, security, requests, events or orders.
- If you subscribe to the newsletter: email address, date and screen from which you subscribed, language of the sentence shown and technical subscription identifier.
- Record of subscription and unsubscription needed to demonstrate and respect your choice.
- Device push notification subscriptions —delivery service address, public key and technical secret— when you enable them. Vazely does not receive the content of other notifications or a general device identifier.
2.8 Technical data
- IP address used transiently to rate-limit requests and protect the service when the deployment sits behind the configured trusted infrastructure.
- Technical headers, error and security logs generated by the servers or infrastructure providers.
- Cookies and storage described in the Cookie policy.
Vazely does not currently use this data for advertising or cross-site tracking.
2.9 Data provided by other people or services
Not all information comes directly from you. It may come from:
- another person who invites you to an account, team, organisation, community, match or event;
- a buyer who gives another person's name as the holder of a ticket;
- members or organisers performing a shared action;
- a social sign-in provider that you choose to use;
- an authority, a reporter or an affected person in a moderation procedure;
- public sources when it is necessary to check an identity, a right or content.
We use that data only to process the action, provide the service, verify the information, comply with obligations or resolve the relevant incident. Where the GDPR requires individual notice and no exemption applies, we will provide the information at the first contact or within the legal time limit.
2.10 Special categories
Vazely does not request data on health, religion, ideology, trade union membership, racial or ethnic origin, sex life or sexual orientation, or other specially protected data, to create an account or personalise the service.
A person may voluntarily disclose information of that nature in a post. We will host it with the chosen visibility and the applicable safeguards, but specially protected information about third parties must not be published without a valid basis.
That information is not used to recommend anything to you. The recommender learns from a post's tags, and those that may reveal health, beliefs, ideology, trade union membership, ethnic origin or sexual orientation are discarded before they reach it. The filter is written as a list of fragments and not as a classifier, precisely so as not to build a second system that infers the categories this one exists not to infer; that is why it errs on the side of discarding too much rather than too little.
The tag stays on your post, is public and can be searched: what does not happen is that it is used to infer your interests. The legitimate interest that covers recommendations would not on its own be enough to process those categories, and there is no other basis for doing so.
2.11 If you sign in with Google or Discord
You can sign in to Vazely with your Google or Discord account, and create your account that way when registration is open. It only happens if you choose that button, and you can link or unlink those accounts whenever you want from Settings → Security → Linked accounts. No external account is linked to yours without you first confirming your password.
What data we receive. When you authorise access, the provider sends us only:
- the identifier of your account with that provider;
- your email address and whether the provider has verified it;
- your name (on Discord, your display name or your username) and the address of your profile picture;
- the technical tokens the provider issues on completing sign-in.
We only ask for the minimum permissions needed to identify you: on Google, openid, email and profile; on Discord, identify and email. We do not access your contacts, files, emails, calendar, servers, messages or any other data in those accounts.
What we use it for. Exclusively to:
- identify you when you sign in;
- create your account, if registration is open and your address does not already have one;
- link the external account to yours, and notify you by email each time one is linked;
- check that the address you use is verified, because we do not create accounts from addresses the provider has not confirmed.
The name is only used as the initial name of your profile, which you can change. The provider's picture is not published: it can only appear in your own menu until you upload an avatar. The tokens are stored encrypted alongside the link, and we do not use them to access your account with the provider or for any other purpose.
What we do not do. We do not sell this data, we do not use it for advertising or for the recommender, we do not disclose it to third parties and we do not use it to train artificial intelligence models. Vazely's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How long. For as long as the external account remains linked. When you unlink it, its identifier and its tokens are deleted; when you delete your Vazely account, all links are deleted in the same purge as the rest of the credentials. You can also revoke access from your Google account (Security → Third-party apps and services) or your Discord account (Settings → Authorised apps).
Legal basis. Performance of the contract for the use of Vazely, because it is the means of access you choose. Google and Discord, for their part, process the data of your accounts with them as independent controllers, in accordance with their own privacy policies.
3. What we use data for and on what legal basis
| Purpose | Main data | Legal basis |
|---|---|---|
| Creating the account, authenticating you and providing the social features requested | Account, session, profile, content, relationships and preferences | Performance of the contract with you |
| Maintaining security, preventing abuse, investigating incidents and protecting accounts | Sessions, IP, user-agent, attempts, confirmations and logs | Legitimate interest in protecting Vazely and its users; compliance with legal obligations where applicable |
| Publishing content and applying the chosen visibility | Profile, posts, replies, images, teams, organisations and communities | Performance of the contract and action requested by the person publishing |
| Operating communities, discussions and matches | Memberships, roles, messages, votes, places, invitations, results and preferences | Performance of the contract; legitimate interest in maintaining the integrity and security of shared activities |
| Personalising the For you section | Likes, post metadata and tags, popularity, age and affinity | Legitimate interest in offering relevant discovery, subject to the right to object |
| Checking that you meet the minimum age and that you may organise events | Date of birth and how it was obtained | Compliance with legal obligations, and performance of the contract as regards which features apply to you |
| Proving which terms you accepted and when | Version accepted and date | Compliance with legal obligations and legitimate interest in being able to demonstrate the agreement |
| Operating Studio, events and shared permissions | Identities, roles, events, acceptances and audit | Performance of the contract; legitimate interest in proving sensitive actions |
| Reserving, confirming and delivering orders or tickets | Identity of the buyer, seller, order, amounts, status and codes | Performance of the purchase contract and of the intermediation services |
| Complying with commercial, tax and consumer obligations or requests from authorities | Orders, invoicing, identity and audit | Compliance with legal obligations |
| Handling illegal content, moderation, complaints and the defence of rights | Content, reports, decisions, communications and audit | Compliance with the Digital Services Act and other obligations; legitimate interest in enforcing the rules |
| Sending communications essential to the service | Email, language, security, requests and orders | Performance of the contract, legal obligation or legitimate interest depending on the message |
| Sending the newsletter | Email, language and proof of subscription | Consent, which can be withdrawn at any time |
| Providing support and bringing or defending claims | Data provided in the enquiry and related records | Performance of the contract, legitimate interest and, where appropriate, legal compliance |
We do not make the account conditional on accepting the newsletter. Withdrawing that consent does not affect the lawfulness of the mailings sent before the withdrawal or the messages needed to operate the account or deliver an order.
Required and optional data
The email, name, password, @handle and country of the personal profile are required to create and complete an account under the current rules. The country is kept even if you decide not to show it publicly. Without the mandatory data we cannot create the account, protect access or provide the restricted features.
For a guest order, a name, an email and confirmation of that address are required. Each event may also require the holder or access data explained before purchase. A professional organiser must provide the legal and tax data required in order to sell.
The biography, images, main team, newsletter and other fields identified as optional may be left empty or turned off without preventing general use, although a specific feature may not be available without the data it needs.
4. What information is public
Depending on the type of identity and your settings, the following may be public: the @handle, display name, avatar, cover, biography, country if you choose to show it, social figures, teams, organisations, communities, events and published content. Matches hosted by a public community and their list of participants may also be public; a match's chat is limited to the members of that community.
Other users may re-share or keep what you make public. Vazely can remove its own copy or restrict access, but cannot delete copies made outside the service by third parties.
Privacy options control how things are presented within Vazely, but must not be used to publish information you have no right to disclose.
5. Recommendations and profiling
Vazely offers two home sections:
- Following, based mainly on the profiles you follow and ordered using stable time-based pagination.
- For you, which selects and orders posts using Gorse or an in-house algorithm.
When Gorse is active, the system takes into account your Likes, the posts liked by accounts with similar interactions and content tags such as language, author and hashtags. For accounts without enough signal it may fall back on related, popular or recent content, and it mixes in a small exploratory selection. It does not semantically analyse text using an artificial intelligence model.
When SQL mode is active, the order is based mainly on the number of Likes and on the age of the post: the score loses weight over time and does not use an individual taste profile. In both modes, privacy and the author's choice to appear in recommendations are applied first.
These signals are used to estimate which posts may interest you; they do not determine your access to employment, credit, insurance or other legal or similarly significant effects. Following a profile determines the content of the Following section, but is not currently fed into Gorse as an affinity signal.
Gorse is operated by Vazely and receives internal identifiers, post identifiers and interaction signals. Its developers do not receive that information merely because the software is used.
You can use the Following section as an alternative that is not based on that personal selection. You can also object to the processing of your data for recommendations by writing to [email protected]. We will assess the request under Article 21 GDPR and inform you of the outcome.
6. Who we share data with
We do not sell personal data.
We may disclose it to:
6.1 Other users and those responsible for identities
Content reaches the people who can see it according to whether it is public and the settings chosen. Those who administer a team, organisation, community, match or event may access the data needed to exercise their permissions.
6.2 Organisers and sellers
The seller and the people authorised to manage an event receive the order, attendee and ticket data needed to deliver the event and meet their obligations.
For the data of people attending an event, the organiser is the controller and Vazely the processor: it is the organiser who decides what is sold, to whom and on what terms, and who keeps the relationship with the buyer. Vazely processes that data following the organiser's instructions and within the terms of the service it provides. This allocation will be reviewed when Vazely processes payments, because it will then process data on its own behalf as well as on the organiser's.
6.3 Providers working for Vazely
| Service | Provider and location | Data and purpose |
|---|---|---|
| Hosting, database and backups | OVH (Gravelines, France) | General hosting of the service |
| Network, protection and content delivery | Cloudflare (global network) | IP, headers and traffic needed for security and delivery |
| Image storage | Cloudflare R2 (European jurisdiction) | Avatars, covers and published images |
| Email delivery | Resend (United States) | Name, email, language and message content |
| Push notification delivery | Push service chosen by the browser | Subscription address and encrypted message in order to deliver it |
| Social sign-in | Google and Discord (United States) | Only if you choose to sign in with them; see section 2.11 |
| External game catalogue | IGDB (Twitch): server queries only | Catalogue queries made from the server |
| Future payments | Not applicable yet | Not applicable while Vazely does not process online payments |
PostgreSQL, Valkey, Garage, imgproxy, Gorse and Listmonk are run within the infrastructure contracted by Vazely. They are not in themselves external recipients.
Providers may only process data following documented instructions and with the safeguards required by law, when they act as processors.
6.4 Legal obligations and transactions
We may disclose information to judges, authorities, law enforcement or competent bodies where there is a valid obligation or legal basis. It may also be necessary to share it with professional advisers or in a business reorganisation, applying confidentiality and the corresponding safeguards.
7. International transfers
Hosting, the database and backups are in France. Cloudflare —edge and image storage— operates a global network: the bucket is configured with European jurisdiction, so objects are stored in the European Union, while traffic is served from the node closest to whoever requests it, which may be outside it. Email is sent through Resend, based in the United States, and covers only the name, the address, the language and the content of the message. If you sign in with Google or Discord, both based in the United States, the sign-in passes through their servers and they return to us the data in section 2.11. If you enable push notifications, the encrypted message passes through the delivery service chosen by your browser or operating system, which may operate outside the European Economic Area; the provider receives the technical address of the subscription, but cannot read the content encrypted by Vazely.
Transfers outside the European Economic Area are covered by the European Commission's standard contractual clauses that each provider includes in its data processing agreement.
If a provider processes data outside the European Economic Area, Vazely will apply the mechanism required by the GDPR, such as an adequacy decision, standard contractual clauses and supplementary measures where necessary. You can request information about the applicable safeguards by writing to [email protected].
8. How long we keep data
We keep data only for as long as necessary for each purpose and to comply with obligations or deal with liabilities. In particular:
| Category | Criterion or period |
|---|---|
| Active account and profile | For as long as you keep the account |
| Account whose deletion you have confirmed | 30 days for recovery. After that, credentials and sessions are revoked, personal data is deleted or anonymised, and a minimal record of the identifier and @handle is kept to prevent impersonation or reassignment |
| Avatar and cover of a deleted identity | They are unlinked when the identity is deleted or purged, and their deletion from storage is attempted after the operation is confirmed |
| Linked Google or Discord accounts | For as long as they remain linked. They are deleted when unlinked and, in any case, in the account purge |
| Date of birth | For as long as you keep the account. It is asked for once and not asked again; it disappears with the account, in the same purge as everything else |
| Acceptance of the terms | For as long as you keep the account, and with the specific version, because that is the only way to know which text it refers to |
| Deleted posts and replies | indefinitely for now: the body is marked as deleted and stops being shown anywhere in the service, but is not yet removed from the database. A period is planned to be set and applied with a sweep. Except for a legal hold or a specific need for defence |
| Sessions | Up to 30 days, unless closed, revoked or deleted earlier |
| Temporary confirmations and verifications | For as long as they are valid —fifteen minutes for six-digit codes and thirty for email links— and the additional time for their technical clean-up |
| Sign-in attempts and security logs | Fifteen minutes per failed sign-in attempt, which is the lockout window; once it has passed, the record no longer counts |
| Orders, tickets and buyer data | indefinitely for now. When there are real payments, the period will be that of commercial, tax and consumer obligations and possible claims. For reference, certain commercial documents are kept for six years in Spain |
| Baskets not converted into an order | Until they expire, between five and sixty minutes depending on how the organiser configures it. The row stops having effect at that moment and is deleted when the reservation is released |
| Deleted discussions and messages | They are marked as deleted and stop being shown, except for the tombstone needed to preserve the reply structure. Their content is kept indefinitely for now, subject to the same period still to be set as deleted posts |
| Matches, places, messages and results | For as long as they are needed to show the community's history and resolve incidents. Deleted messages stop being shown but are kept indefinitely for now; when an account is purged its places are removed and its messages stop being shown |
| Newsletter | For as long as you remain subscribed. Proof of subscription and unsubscription is kept for as long as the account exists, to demonstrate and respect your choice |
| Push subscriptions | Until you disable them, the delivery service reports that they are no longer valid, or the account is purged |
| Reports and moderation decisions | one year from when the decision becomes final, taking into account the appeal period and possible legal obligations |
| Audit of sensitive actions and acceptance of terms | For as long as the account exists. The audit records ownership movements and names taken away, which is precisely what the rest of the database can no longer reconstruct |
| Support | one year from the closing of the enquiry, unless it has to be linked to a claim |
| Backups and infrastructure logs | According to the hosting provider's rotation, which will be detailed as soon as the final deployment is settled; the data is isolated and disappears with the rotation of the backup |
Where there is a claim, investigation or retention obligation, the data concerned may be blocked for the applicable period and used only for that purpose.
9. Your rights
You can request:
- access to your data and to information about its processing;
- rectification of inaccurate or incomplete data;
- erasure when it is no longer necessary or another legal ground applies;
- restriction of processing in the cases provided for by the GDPR;
- portability of the data you have provided when the processing is based on consent or the contract and is carried out by automated means;
- objection to processing based on legitimate interest, including personalised recommendations;
- withdrawal of consent for the newsletter or other processing based on it, without retroactive effect;
- not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where applicable.
You can edit many data and preferences directly from the settings. To exercise a right that is not available there, write to [email protected] stating what you are requesting. We may ask for reasonable information to verify your identity without collecting more data than necessary.
We will respond without undue delay and, normally, within one month. Exercising your rights is free of charge except for manifestly unfounded or excessive requests within the meaning of the GDPR.
If you believe the processing breaches the law, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) or with the supervisory authority corresponding to your place of residence or work.
10. Account deletion
Requesting deletion requires your password and a code sent to your email. The account is deactivated and sessions are revoked. During the following 30 days you can recover it; at the end of that period the purge described in the retention section is carried out.
Deletion cannot be completed while the account owns a team, an organisation, a community or an event that must continue to have someone responsible for it. It must first be transferred or deleted. This limitation protects members, participants, attendees and buyers and does not prevent you from exercising other data protection rights.
Deleting the account does not require deleting records that must be kept by law, third parties' orders or sufficiently anonymised data. We will tell you if a specific request is limited for any of those reasons.
11. Minors
Vazely is intended for people aged at least 14, which is the age from which Article 7 of Spanish Organic Law 3/2018 (LOPDGDD) allows a person to consent on their own to the processing of their personal data. Organising events also requires being 18.
If you are under 14 you cannot create an account. If you believe a minor under that age has created one, or if you hold parental authority or guardianship over a person between 14 and 18 and wish to exercise their rights, write to [email protected].
If we discover that an account does not meet the minimum age or that data of a minor has been processed without the necessary legal basis, we will take measures to restrict the processing and delete the relevant information. An incident can be reported to [email protected].
Attendance at an event may have a different age set by the organiser and does not change the minimum age required to create an account.
12. Security
We apply technical and organisational measures proportionate to the risk, including access control, revocable sessions, email verification, a second factor for Studio, attempt limits, separation of credentials, backups and minimisation of the data disclosed to auxiliary services.
No system is completely infallible. If you detect unauthorised access or a vulnerability, write to [email protected] and do not publish personal data or credentials in open channels.
13. Changes to this policy
We will update this policy when the purposes, providers, technologies or legal requirements change. We will publish the new version and, if the change is significant, we will communicate it by an appropriate means before it takes effect where necessary.
A privacy policy provides information about processing; it does not become general consent by continuing to use Vazely. Where a purpose requires your consent, it will be requested separately and specifically.
