Privacy Policy – circled.club (Version 1.1)
Last update: 2025-10-28
1. Controller
The data controller under the EU General Data Protection Regulation (GDPR) is:
circled.club
represented by high-bau GmbH, Munich, Germany.
Official operator details are listed in the Imprint.
All data protection inquiries can be submitted through the contact form.
2. Principles of Data Processing
circled.club processes personal data only to the extent necessary to provide, secure, and improve the platform.
Processing follows the principles of lawfulness, transparency, purpose limitation, and data minimization (Art. 5 GDPR).
circled.club:
- does not collect data for advertising or tracking purposes,
- does not sell or share user data with third parties,
- uses only internal analytics to improve platform quality.
All hosting is carried out exclusively on servers located within the European Union.
3. Categories of Data Processed
- Registration data: username, email address, encrypted password
- Profile data: optional fields such as name, profile picture, description
- Usage data: technical logs (IP address, browser type, access times)
- Content data: posts, comments, messages, uploads
- Communication data: inquiries via contact form or support
- Payment data: transaction details processed by external payment providers (see Section 7)
4. Purpose of Processing
- Operating and providing the platform and its features
- Managing memberships and access levels
- Processing payments and membership subscriptions
- Ensuring IT security and preventing misuse
- Communicating with members (support, notifications, moderation)
- Improving functionality through anonymized analytics
5. Legal Bases
Processing is based on:
- Art. 6(1)(b) GDPR – performance of a user contract
- Art. 6(1)(c) GDPR – legal obligations
- Art. 6(1)(f) GDPR – legitimate interest in secure and stable operation
- Art. 6(1)(a) GDPR – consent for optional data provided voluntarily
6. Data Retention and Deletion
Data is stored only as long as necessary for the stated purposes or as required by law.
After an account is deleted, personal data will be erased or anonymized within 30 days unless retention is legally required.
7. Disclosure to Third Parties and Payment Processing
circled.club only shares data when:
- required by law,
- technically or contractually necessary (e.g., hosting or payment processing), or
- the user has given explicit consent.
For paid memberships or donations, payments are processed through GDPR-compliant providers such as PayPal and Stripe.
Payment details are transmitted directly to these providers. circled.club does not store bank or card information—only confirmation of successful transactions.
No data transfers outside the EU occur without the user’s explicit consent.
8. Data Security
circled.club uses state-of-the-art security measures (HTTPS encryption, access control, secure authentication) to protect data from loss, misuse, or unauthorized access.
9. Content Visibility and Filtering
- Members control the visibility of their content — public, limited to specific Circles, or private to selected members.
- circled.club ensures these visibility settings can be modified or deleted at any time in line with the principle of “privacy by design.”
- Automated content and community filters may be used to detect inappropriate or rule-breaking material and restrict visibility accordingly.
10. Credits System
circled.club may offer an internal Credits System that allows members to send digital support or value tokens to others.
- Credits may be used for platform services (e.g., membership upgrades).
- Verified members, after admin approval, may connect their own payment APIs (e.g., PayPal, Stripe) to convert Credits into cash.
- All payment processing is handled by the respective providers; circled.club stores no bank or card data.
11. User Rights
Under the GDPR, users have the following rights:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
Requests can be made through the contact form.
12. Cookies and Local Storage
circled.club uses only technically necessary cookies and local storage for login, session management, and security.
No tracking or advertising cookies are used.
13. External Links and Third-Party Content
Member posts may include links to external websites. circled.club is not responsible for the content or data handling of external sites.
14. Updates to this Policy
circled.club may update this Privacy Policy when required by legal or technical changes.
The current version will always be published on the platform.
15. Validity
This Privacy Policy enters into force upon publication of Version 1.1.