Legal
Privacy Policy
Last updated: 16 August 2026
This Privacy Policy explains how Zerophia (“we”, “us”) processes personal data when you use Wasla at wasla.zerophia.com (the “Service”), in line with the EU General Data Protection Regulation (GDPR) and Dutch implementation law (UAVG).
This document is provided for transparency and compliance. It is not personalised legal advice.
1. Controller
The controller is Zerophia, operator of Wasla. Privacy requests: privacy@zerophia.com. If we appoint a Data Protection Officer, contact details will be added here.
2. Categories of personal data
- Identity & account: display name, email, password hash, role (member/host), optional avatar URL and bio.
- Host & event content: listings, venue/location, trust labels, images URLs, descriptions.
- Bookings: attendee name and email, booking status, check-in code, related event reference.
- Billing: Stripe customer/subscription identifiers, plan status, invoices/tax metadata. Payment card data is processed by Stripe, not stored by us in full.
- Technical / security: essential cookies, IP and request metadata as processed by our hosting/security providers (e.g. Cloudflare) for delivery and abuse prevention.
- Communications: messages you send to support, privacy, or abuse contacts.
3. Purposes and legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): create/manage accounts; publish/browse events; bookings; organizer subscriptions; customer support related to the Service.
- Legal obligation (Art. 6(1)(c)): tax/VAT, accounting, responding to lawful authority requests, DSA notice handling records where required.
- Legitimate interests (Art. 6(1)(f)): securing the Service; preventing fraud, spam, and abuse; improving reliability; enforcing Terms and Community Guidelines — balanced against your rights and expectations as a user of a social events platform.
- Consent (Art. 6(1)(a)): only if we introduce non-essential cookies/marketing — we will ask separately. Essential cookies do not rely on marketing consent (see Cookie Policy).
We do not use your data for automated decision-making that produces legal or similarly significant effects (GDPR Art. 22).
4. Special category data
Wasla is designed for Muslim social activities. Event labels (audience, alcohol, prayer notes) may relate to community preferences. Do not upload sensitive personal data about others without a lawful basis. Hosts must not require attendees to disclose health, religion of others, or other special-category data beyond what is necessary and lawful for the event context.
5. Recipients / processors
- Stripe — payments, subscriptions, Tax/VAT, Customer Portal (privacy).
- Cloudflare — hosting (Workers), CDN/security.
- Database infrastructure — storage of account, event, and booking records.
We do not sell personal data. We may disclose data to competent authorities when legally required, or to professional advisers under confidentiality.
6. International transfers
Where processors transfer data outside the EEA/UK, we rely on adequacy decisions and/or Standard Contractual Clauses (or equivalent safeguards) as documented by those processors.
7. Retention
- Account data: while active, then deleted or anonymised on request unless law requires retention.
- Bookings & financial records: typically up to 7 years where tax/accounting rules require.
- Security / abuse logs: shorter operational periods unless needed for investigations.
- Illegal-content notices (DSA): retained as needed to handle reports and demonstrate compliance.
8. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Contact privacy@zerophia.com. We respond within one month (extendable as permitted by GDPR). You may complain to the Dutch Autoriteit Persoonsgegevens (or your local EU authority).
9. Security
We use industry-standard measures appropriate to risk (hashed passwords, HTTPS, access controls, edge protections). No method is 100% secure.
10. Children
The Service is for users 16+ (or older if your country requires a higher digital consent age). We do not knowingly create accounts for younger children.
11. Changes & contact
We may update this policy; the date above will change. Contact privacy@zerophia.com / support@zerophia.com.