Legal

Privacy Policy

We believe privacy is a right, not a feature. This policy explains exactly what data we collect, why we collect it, and the controls you have over it.

Last updated: 25 June 2026 · Applies to: thishappens.in and all This Happens mobile apps

📋Overview

This Happens ApS ("This Happens", "we", "us") operates the This Happens platform — a local events discovery and promotion service. This policy describes how we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.

We act as the data controller for personal data collected through our platform. Our legal basis for processing is primarily: performance of a contract (delivering our service to you), legitimate interests (improving the platform, preventing fraud), and consent (marketing communications).

Short version: We collect only what we need to run the service. We do not sell your data. You can request access, correction or deletion of your data at any time. For questions, write to privacy@thishappens.in.

🗂️What we collect

We collect the minimum data necessary to provide the service. Here is a complete breakdown:

Data typeWhat exactlyWhy
Account dataName, email address, password (hashed), profile photo, usernameCreating and authenticating your account
Event dataEvents you create, edit or bookmark; ticket links; attendance historyDelivering core app features
Location dataCity-level location (from account settings or IP); precise GPS only if you enable map viewShowing relevant local events
Usage dataPages visited, events viewed, searches, clicks, session durationImproving recommendations and platform performance
Device dataBrowser type, OS, device ID, IP addressSecurity, fraud prevention, technical support
CommunicationsMessages you send us; support ticketsResponding to your requests
Payment dataWe do not store payment card details — transactions are handled by our payment processor (QuickPay) under their own privacy policyBilling for Venue Partner / Featured plans

We do not collect sensitive personal data (health, political opinions, religion, ethnicity) and we do not collect data from children under 16 without parental consent.

⚙️How we use your data

We use your data only for the purposes it was collected for:

PurposeLegal basis (GDPR)
Providing and personalising the servicePerformance of contract (Art. 6(1)(b))
Sending event recommendations and notificationsPerformance of contract / Legitimate interests (Art. 6(1)(f))
Sending marketing emails and digestsConsent (Art. 6(1)(a)) — opt-in only, withdraw any time
Analytics and product improvementLegitimate interests (Art. 6(1)(f))
Security, fraud detection and abuse preventionLegitimate interests (Art. 6(1)(f))
Legal compliance and responding to lawful requestsLegal obligation (Art. 6(1)(c))

We never use your data for automated decision-making that produces legal or similarly significant effects on you without human review.

🔗What we share

We do not sell your personal data. We share it only in these limited circumstances:

RecipientWhat is sharedWhy
Venue / event organiserYour name and email only if you purchase a ticket directly through their linkFulfilling your ticket purchase
Service providersInfrastructure (Microsoft Azure / Google GCP), email delivery (MailGun), payments (QuickPay)Operating the platform — all under data processing agreements
Advertising partnersAggregated, anonymised audience segments only — never individual identitiesEnabling city- and category-level ad targeting
Legal authoritiesOnly when required by law, court order, or to protect safetyLegal obligation
Business transferIn the event of a merger or acquisition, user data may transfer — you will be notified in advanceBusiness continuity

All third-party service providers are contractually bound to process your data only on our behalf and in accordance with GDPR.

How long we keep your data

We retain personal data only as long as necessary for the purpose it was collected, or as required by law:

Data typeRetention period
Account dataUntil you delete your account, then 30 days before permanent erasure
Event and activity dataDuration of account, or 3 years from last activity if inactive
Usage and analytics data24 months, then anonymised or deleted
Support communications3 years from resolution
Billing and payment records7 years (Danish bookkeeping requirements)
Security and fraud logs90 days, unless required for an active investigation

After these periods, data is permanently and irreversibly deleted or anonymised so it can no longer be linked to you.

⚖️Your GDPR rights

As a data subject under the GDPR, you have the following rights. You can exercise any of them at any time by contacting privacy@thishappens.in. We will respond within 30 days.

Art. 15Right to access

Request a copy of all personal data we hold about you, including what it is, how we use it and who we share it with.

Art. 16Right to rectification

Ask us to correct any inaccurate or incomplete personal data we hold about you.

Art. 17Right to erasure

Request deletion of your personal data. We will erase it unless we are required to keep it by law. See the section below for how to submit a deletion request.

Art. 18Right to restriction

Ask us to restrict processing of your data in certain circumstances — for example, while you contest its accuracy.

Art. 20Right to portability

Receive a copy of your data in a structured, machine-readable format (JSON or CSV) and transfer it to another service.

Art. 21Right to object

Object to processing based on legitimate interests, including profiling for recommendations or direct marketing.

You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk if you believe we are not handling your data correctly.

🗑️Request data deletion

You can always request the deletion of your personal data. We take this right seriously and will permanently erase your account and all associated data within 30 days of your request.

🗑️

Request account & data deletion

Send us an email with the subject line "Data Deletion Request" from the email address linked to your account. We will confirm receipt within 48 hours and complete the deletion within 30 days. You will receive a confirmation when the deletion is complete.

Email us to delete my data →

Note: Certain data may be retained after deletion where required by law (e.g. billing records for 7 years under Danish bookkeeping law). This data will be isolated and used solely for legal compliance — it will not be used for any other purpose and will be deleted as soon as the legal retention period expires.

🍪Cookies

We use cookies and similar technologies to operate the platform, remember your preferences and understand how people use This Happens.

CategoryPurposeCan be declined?
EssentialSession management, authentication, securityNo — required for the service to function
FunctionalRemembering your city, language and display preferencesYes — via cookie settings
AnalyticsAggregated usage statistics to improve the platformYes — via cookie settings or browser opt-out
MarketingUnderstanding which campaigns brought you to This HappensYes — opt-in only

You can manage your cookie preferences at any time via your account settings or your browser settings. Declining non-essential cookies will not affect your ability to use the platform.

👶Children's privacy

This Happens is not directed at children under 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent. If you believe a child under 16 has provided us with personal data, please contact us at privacy@thishappens.in and we will delete the data promptly.

📝Policy changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (to the address on your account) and by posting a notice on the platform at least 14 days before the changes take effect.

Your continued use of This Happens after the effective date of any changes constitutes acceptance of the revised policy. If you do not agree with the changes, you may delete your account before the effective date.

Previous versions of this policy are available upon request by emailing privacy@thishappens.in.

✉️Contact us

For any privacy-related questions, requests or complaints, please contact our Data Protection Officer:

CompanyThis Happens ApS
AddressRefshalevej 163, 1432 Copenhagen, Denmark
Emailprivacy@thishappens.in
Response timeWe respond to all privacy requests within 30 days as required by GDPR
Supervisory authorityDatatilsynet (Danish Data Protection Authority) — datatilsynet.dk