We believe privacy is a right, not a feature. This policy explains exactly what data we collect, why we collect it, and the controls you have over it.
This Happens ApS ("This Happens", "we", "us") operates the This Happens platform — a local events discovery and promotion service. This policy describes how we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.
We act as the data controller for personal data collected through our platform. Our legal basis for processing is primarily: performance of a contract (delivering our service to you), legitimate interests (improving the platform, preventing fraud), and consent (marketing communications).
Short version: We collect only what we need to run the service. We do not sell your data. You can request access, correction or deletion of your data at any time. For questions, write to privacy@thishappens.in.
We collect the minimum data necessary to provide the service. Here is a complete breakdown:
| Data type | What exactly | Why |
|---|---|---|
| Account data | Name, email address, password (hashed), profile photo, username | Creating and authenticating your account |
| Event data | Events you create, edit or bookmark; ticket links; attendance history | Delivering core app features |
| Location data | City-level location (from account settings or IP); precise GPS only if you enable map view | Showing relevant local events |
| Usage data | Pages visited, events viewed, searches, clicks, session duration | Improving recommendations and platform performance |
| Device data | Browser type, OS, device ID, IP address | Security, fraud prevention, technical support |
| Communications | Messages you send us; support tickets | Responding to your requests |
| Payment data | We do not store payment card details — transactions are handled by our payment processor (QuickPay) under their own privacy policy | Billing for Venue Partner / Featured plans |
We do not collect sensitive personal data (health, political opinions, religion, ethnicity) and we do not collect data from children under 16 without parental consent.
We use your data only for the purposes it was collected for:
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and personalising the service | Performance of contract (Art. 6(1)(b)) |
| Sending event recommendations and notifications | Performance of contract / Legitimate interests (Art. 6(1)(f)) |
| Sending marketing emails and digests | Consent (Art. 6(1)(a)) — opt-in only, withdraw any time |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) |
| Security, fraud detection and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance and responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
We never use your data for automated decision-making that produces legal or similarly significant effects on you without human review.
We retain personal data only as long as necessary for the purpose it was collected, or as required by law:
| Data type | Retention period |
|---|---|
| Account data | Until you delete your account, then 30 days before permanent erasure |
| Event and activity data | Duration of account, or 3 years from last activity if inactive |
| Usage and analytics data | 24 months, then anonymised or deleted |
| Support communications | 3 years from resolution |
| Billing and payment records | 7 years (Danish bookkeeping requirements) |
| Security and fraud logs | 90 days, unless required for an active investigation |
After these periods, data is permanently and irreversibly deleted or anonymised so it can no longer be linked to you.
As a data subject under the GDPR, you have the following rights. You can exercise any of them at any time by contacting privacy@thishappens.in. We will respond within 30 days.
Request a copy of all personal data we hold about you, including what it is, how we use it and who we share it with.
Ask us to correct any inaccurate or incomplete personal data we hold about you.
Request deletion of your personal data. We will erase it unless we are required to keep it by law. See the section below for how to submit a deletion request.
Ask us to restrict processing of your data in certain circumstances — for example, while you contest its accuracy.
Receive a copy of your data in a structured, machine-readable format (JSON or CSV) and transfer it to another service.
Object to processing based on legitimate interests, including profiling for recommendations or direct marketing.
You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk if you believe we are not handling your data correctly.
You can always request the deletion of your personal data. We take this right seriously and will permanently erase your account and all associated data within 30 days of your request.
Send us an email with the subject line "Data Deletion Request" from the email address linked to your account. We will confirm receipt within 48 hours and complete the deletion within 30 days. You will receive a confirmation when the deletion is complete.
Email us to delete my data →Note: Certain data may be retained after deletion where required by law (e.g. billing records for 7 years under Danish bookkeeping law). This data will be isolated and used solely for legal compliance — it will not be used for any other purpose and will be deleted as soon as the legal retention period expires.
We use cookies and similar technologies to operate the platform, remember your preferences and understand how people use This Happens.
| Category | Purpose | Can be declined? |
|---|---|---|
| Essential | Session management, authentication, security | No — required for the service to function |
| Functional | Remembering your city, language and display preferences | Yes — via cookie settings |
| Analytics | Aggregated usage statistics to improve the platform | Yes — via cookie settings or browser opt-out |
| Marketing | Understanding which campaigns brought you to This Happens | Yes — opt-in only |
You can manage your cookie preferences at any time via your account settings or your browser settings. Declining non-essential cookies will not affect your ability to use the platform.
This Happens is not directed at children under 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent. If you believe a child under 16 has provided us with personal data, please contact us at privacy@thishappens.in and we will delete the data promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and by posting a notice on the platform at least 14 days before the changes take effect.
Your continued use of This Happens after the effective date of any changes constitutes acceptance of the revised policy. If you do not agree with the changes, you may delete your account before the effective date.
Previous versions of this policy are available upon request by emailing privacy@thishappens.in.
For any privacy-related questions, requests or complaints, please contact our Data Protection Officer:
| Company | This Happens ApS |
| Address | Refshalevej 163, 1432 Copenhagen, Denmark |
| privacy@thishappens.in | |
| Response time | We respond to all privacy requests within 30 days as required by GDPR |
| Supervisory authority | Datatilsynet (Danish Data Protection Authority) — datatilsynet.dk |