Datenschutzerklärung
Der Schutz deiner personenbezogenen Daten ist uns ein wichtiges Anliegen. In dieser Datenschutzerklärung erläutern wir wie wir Daten erheben, verarbeiten und nutzen wenn du die peerio App oder die Website peerio.io verwendest. Wir halten uns dabei an die Vorgaben der Datenschutz-Grundverordnung (DSGVO).
1. Verantwortlicher
Tomoveo Ltd., 8011 Paphos, Zypern
E-Mail: impressum@tomoveo.com
Vollständige Anbieterangaben im Impressum.
2. Registrierung und Nutzerkonto
Zur Nutzung der peerio App ist eine Registrierung erforderlich. Wir verarbeiten dabei: E-Mail-Adresse, Vor- und Nachname, Profilfoto, Geschlecht (mit Möglichkeit zur Nichtangabe), Angaben zur unternehmerischen Tätigkeit (Gründungsphase, Branche, Team-Aufstellung, Link zu deiner Gründeraktivität), eine Selbstbeschreibung, Spracheinstellungen sowie Zeitstempel der Registrierung, deiner Altersbestätigung und deiner Zustimmung zu diesen Bedingungen und zum Community Kodex. Der Nachname wird nicht an andere Nutzer ausgespielt.
Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO). Mit der Registrierung bestätigst du, mindestens 18 Jahre alt und unternehmerisch tätig zu sein. Im Rahmen des Onboardings fragen wir optional ab, wie du auf peerio aufmerksam geworden bist. Diese Angabe ist freiwillig, wird zur Verbesserung unserer Marketingmaßnahmen genutzt und nicht an Dritte weitergegeben. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
3. Nutzung der App
Registrierung via Apple oder Google
Du kannst dich mit deinem Apple- oder Google-Konto registrieren. In diesem Fall übermittelt Apple bzw. Google uns grundlegende Profildaten (Name, E-Mail-Adresse). Welche Daten übermittelt werden, kannst du beim jeweiligen Anbieter einsehen und steuern. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Peers und Meets
Inhalte die du in der App erstellst werden gespeichert und anderen Nutzern gemäß deinen Sichtbarkeitseinstellungen angezeigt. Peers sind Beiträge die du erstellst und in denen andere Nutzer schreiben und diskutieren können. Meets sind Treffen die du eigenverantwortlich organisierst und mit Standort und Zeitangabe für andere sichtbar machen kannst. Peers sind zeitlich begrenzt: Nach Ablauf einer in der App angegebenen Frist erscheinen sie nicht mehr in der Übersicht und auf der Karte und sind für neue Nutzer nicht mehr auffindbar. Für Teilnehmer und den Ersteller bleibt der zugehörige Chat weiter nutzbar; er wird gelöscht, wenn 90 Tage lang keine Nachricht mehr geschrieben wurde. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Anonymer Modus
Peers können anonym erstellt werden. In diesem Fall werden dein Name und dein Profilfoto anderen Nutzern nicht angezeigt, und deine Identität wird auch technisch nicht an sie übermittelt, weder an Außenstehende noch an die Teilnehmer des Peers. Innerhalb des anonymen Peers erscheinst du für alle als „Anonymus" mit einer festen Nummer. Der Beitrag bleibt intern deinem Konto zugeordnet, damit du ihn verwalten kannst. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Verbindungen
Wenn du dich mit anderen Nutzern verbindest, wird diese Verbindung gespeichert und ist Grundlage für weitere Funktionen wie Chat und Matching. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Matching
peerio nutzt ein automatisiertes Matching-System um passende Nutzer vorzuschlagen. Die Analyse basiert ausschließlich auf von dir selbst eingegebenen beruflichen Angaben. Zur Verbesserung des Matchings werden textbasierte Profilangaben mithilfe spezialisierter KI-Dienste (derzeit OpenAI, USA) in numerische Vektoren umgewandelt und gespeichert. Diese Verarbeitung dient ausschließlich der Matchingfunktion. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Das Matching-Ergebnis ist ein Vorschlag ohne verbindlichen oder rechtserheblichen Charakter im Sinne von Art. 22 DSGVO. Das Matching ist Teil der vertraglich geschuldeten Leistung und kann als Funktion nicht abgeschaltet werden. Du kannst jedoch die Datengrundlage einschränken, indem du der Auswertung deiner Verhaltensdaten widersprichst; das Matching arbeitet dann nur noch auf Grundlage deiner Profilangaben.
KI-gestützte Funktionen
Zur Klassifizierung von Peer-Inhalten setzen wir spezialisierte KI-Dienste ein (derzeit Anthropic, USA). Die Verarbeitung erfolgt auf Basis deiner eingegebenen Inhalte. Es findet keine Analyse persönlicher oder sensibler Merkmale statt. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Nachrichten, Chat und Datei-Uploads
Nachrichten sowie im Chat geteilte Dateien und Bilder werden für den Betrieb des Chat-Dienstes gespeichert. Wir haben technischen Zugang zu diesen Inhalten, werten sie jedoch nicht zu Werbe- oder Profilbildungszwecken aus. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Nutzungsverhalten
Wir erfassen Nutzungsdaten zur Verbesserung des Matchings und der App. Dazu zählen insbesondere: welchen Peers du beitrittst oder sie ansiehst, wie aktiv du dich beteiligst, welche Profile du aufrufst sowie deine Suchanfragen in der App. Aus diesen Signalen entwickeln wir ein Interessenprofil, das die Qualität deiner Vorschläge mit der Zeit verbessert. Suchanfragen speichern wir zu diesem Zweck für bis zu 90 Tage. Diese Daten werden in aggregierter oder pseudonymisierter Form ausgewertet. Soweit sie dabei keinen Personenbezug mehr aufweisen, können sie auch für Marktforschung, Investorenkommunikation sowie zur kommerziellen Verwertung genutzt werden. Du kannst der Verarbeitung deiner Verhaltensdaten für das Interessenprofil jederzeit widersprechen. Dafür gibt es in den Datenschutz-Einstellungen der App einen Schalter. Widersprichst du, werden bereits erhobene Verhaltensdaten gelöscht und keine neuen mehr erfasst; das Matching arbeitet dann nur noch auf Grundlage deiner Profilangaben. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
Mitgliedschaftsstatus
Wir speichern ob du das kostenlose Basismodell oder peerio+ nutzt sowie den jeweiligen Nutzungsstatus. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
peerio ID
Jedem Konto wird eine eindeutige peerio ID zugewiesen. Diese dient der internen Identifikation und kann vom Nutzer selbst weitergegeben werden. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Profilbild
Du kannst ein Profilbild hochladen. Dieses wird anderen Nutzern angezeigt. Zur Sicherstellung der Echtheit prüfen wir automatisiert ob das hochgeladene Bild ein echtes menschliches Gesicht zeigt. Diese Prüfung erfolgt durch spezialisierte KI-Dienste (derzeit Anthropic, USA) und dient ausschließlich der Qualitätssicherung. Es findet keine biometrische Analyse, keine Identifikation und kein Abgleich mit externen Datenbanken statt. Das Profilbild wird mit deinem Konto gespeichert und bei Kontolöschung entfernt. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Links und externe Angaben im Profil
Du kannst in deinem Profil externe Links angeben (z.B. Website oder Social-Media-Profile). Diese Angaben sind für andere Nutzer sichtbar und werden mit deinem Profil gespeichert. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Empfehlungslinks
peerio stellt einen allgemeinen Empfehlungslink bereit, den Nutzer teilen können. Dieser Link enthält keine Kennung und wird keinem einzelnen Nutzer zugeordnet. Wer wen empfohlen hat, erfassen wir nicht. Damit wir den Hinweis, peerio weiterzuempfehlen, nur aktiven Nutzern und nicht zu häufig anzeigen, zählen wir bestimmte Aktivitäten in der App, etwa angenommene Kontaktanfragen oder Meet-Teilnahmen. Dieser Zähler ist deinem Konto zugeordnet und wird nach jeder Anzeige zurückgesetzt. Er ist mit keinerlei Vorteilen oder Belohnungen verbunden und wird nicht für Werbung genutzt. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
Gerätedaten
Für den Betrieb der App und zur Fehlerbehebung verarbeiten wir technische Gerätedaten wie Geräte-ID, Betriebssystem und App-Version. Diese Daten werden nicht für Werbezwecke genutzt. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
Inaktive Konten
Bei dauerhafter Inaktivität eines Kontos sind wir berechtigt, dieses nach vorheriger E-Mail-Benachrichtigung zu deaktivieren oder zu löschen. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
Benachrichtigungseinstellungen
Du kannst in den App-Einstellungen steuern welche Push-Benachrichtigungen und E-Mail-Benachrichtigungen du erhalten möchtest. Deine Einstellungen werden gespeichert und jederzeit änderbar. Push-Benachrichtigungen werden über die Infrastruktur von Apple bzw. Google übermittelt und setzen zusätzlich deine Zustimmung auf Geräteebene voraus; sie können über deine Geräteeinstellungen deaktiviert werden. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).
Altersverifikation
peerio ist für Nutzer ab 18 Jahren. Bei der Registrierung bestätigst du, dass du mindestens 18 Jahre alt bist (Art. 8 DSGVO).
Meets auf der Karte
Du kannst Meets auf der Karte erstellen und mit Standortangabe für andere Nutzer sichtbar machen. Dabei kannst du optional Sichtbarkeitseinstellungen festlegen, z.B. nach Geschlecht; diese Einstellungen werden mit dem Meet gespeichert. Die Daten werden mit Zeitangabe und Standort gespeichert. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Für die Kartenanzeige nutzen wir Mapbox (USA). Dabei werden Kartenausschnitte von Mapbox-Servern geladen. Der eigene Gerätestandort wird nur live zur Anzeige in der Karte genutzt und nicht gespeichert. Standortangaben für Meets werden vom Nutzer manuell eingegeben und mit Koordinaten in unserer Datenbank gespeichert. Die Übermittlung an Mapbox erfolgt auf Basis von Standardvertragsklauseln (Art. 46 DSGVO).
Persönliche Fragen und Icebreaker
Du kannst deinem Profil persönliche Fragen aus einer vorgegebenen Auswahl hinzufügen und selbst beantworten. Diese Angaben sind freiwillig und für andere Nutzer sichtbar. Zusätzlich kannst du eine eigene Frage formulieren, die anderen Nutzern angezeigt wird, bevor sie dir eine Kontaktanfrage senden. Wer dir eine Anfrage schickt, kann diese Frage freiwillig beantworten; nimmst du die Anfrage an, erscheinen Frage und Antwort als erste Nachrichten im gemeinsamen Chat. Lehnst du ab, wird die Antwort gelöscht. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Blockieren
Du kannst andere Nutzer blockieren. Eine Blockierung wirkt in beide Richtungen: Ihr werdet einander nicht mehr in den Vorschlägen angezeigt, seid über die Suche nicht mehr auffindbar, könnt einander keine Nachrichten, Kontaktanfragen oder Einladungen senden, und eure Profile werden füreinander ohne Namen und Bild dargestellt. Eine bestehende Verbindung wird aufgelöst. In gemeinsamen Peers und Meets bleibt die Mitgliedschaft bestehen; die jeweils andere Person erscheint dort ohne Namen und Bild. Blockierungen speichern wir mit deinem Konto und du kannst sie jederzeit in den Einstellungen aufheben. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Sperr-Mitteilung und Stellungnahme
Wird dein Konto gesperrt, erhältst du beim nächsten Öffnen der App eine Mitteilung mit der Begründung, der zugrunde liegenden Regel des Community Kodex und dem beanstandeten Inhalt im Wortlaut. Du kannst dazu Stellung nehmen; deine Stellungnahme wird gespeichert und geprüft, und du wirst über das Ergebnis informiert. Über eine Sperrung entscheidet immer eine Person, nicht ein automatisiertes Verfahren. Rechtsgrundlage ist unser berechtigtes Interesse am Betrieb einer sicheren Plattform (Art. 6 Abs. 1 lit. f DSGVO).
Moderation, Sanktionen und Beweisaufbewahrung
Wird ein Inhalt oder ein Profil gemeldet, prüfen wir die Meldung und entscheiden über eine Maßnahme. Dabei verarbeiten wir: die Meldung mit Grund und Beschreibung, den gemeldeten Inhalt im Wortlaut, die Konten des Melders und des Gemeldeten sowie den Zeitpunkt.
Führt eine Meldung zu einer Sperre, halten wir den Vorgang fest: die interne Kontonummer, die Art der Entscheidung, den Zeitpunkt, unsere Begründung, die zugrunde liegende Regel des Community Kodex sowie den beanstandeten Inhalt im Wortlaut. Diese Angaben bleiben auch dann bestehen, wenn das betroffene Konto anschließend gelöscht wird. Name, E-Mail-Adresse, Profilbild und Profilinhalte werden dabei nicht aufbewahrt. Rechtsgrundlage ist unser berechtigtes Interesse an Rechtsverteidigung und Plattformsicherheit (Art. 6 Abs. 1 lit. f DSGVO); die Aufbewahrung trotz eines Löschverlangens stützt sich auf Art. 17 Abs. 3 lit. e DSGVO.
Wir bewahren Angaben zum Sanktionsvorgang drei Jahre zuzüglich bis zum Ende des jeweiligen Kalenderjahres auf, beanstandete Inhalte im Wortlaut zwölf Monate. Läuft ein Widerspruchs- oder Streitverfahren, ruht die Löschung bis zu dessen Abschluss. Unabhängig von einer Sanktion halten wir bei jeder Kontolöschung den Zeitpunkt fest sowie, sofern ein Abonnement bestand, die Transaktionsnummer des Zahlungsdienstleisters, das Produkt und die Laufzeit. Dies dient dem Nachweis im Fall einer Rückerstattungsstreitigkeit; diese Angaben bewahren wir sieben Jahre auf, gerechnet bis zum Ende des jeweiligen Kalenderjahres.
Kontolöschung
Du kannst dein Nutzerkonto jederzeit selbst in der App löschen. Mit der Löschung werden dein Konto und deine personenbezogenen Daten unverzüglich entfernt. Direktnachrichten werden vollständig gelöscht. Nachrichten in Peers und Meets bleiben als Platzhalter ohne Zuordnung zu dir bestehen, damit der Gesprächsverlauf für die übrigen Teilnehmer lesbar bleibt. Anonymisierte Inhalte wie Peer-Beiträge können in nicht zuordenbarer Form weiter bestehen. Ein aktives Abonnement wird durch die Kontolöschung nicht automatisch gekündigt; dieses muss separat im jeweiligen App Store beendet werden.
Ein Partnerkonto kann während der Vertragslaufzeit nicht selbst gelöscht werden; die Löschung erfolgt nach Vertragsende durch uns. Von der Löschung ausgenommen sind Angaben zu Moderationsvorgängen und zur Kontolöschung selbst; Näheres im Abschnitt „Moderation, Sanktionen und Beweisaufbewahrung".
4. Website peerio.io
Früher Zugang (Early Access)
Wir verarbeiten: Vorname, E-Mail-Adresse sowie deine Einwilligung mit Zeitstempel. Nach der Anmeldung erhältst du eine Bestätigungs-E-Mail (Double Opt-In). Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), die du jederzeit widerrufen kannst.
Buchung peerio Places
Places Partner buchen über peerio.io/peerio-places die Anzahl der gewünschten Standorte; ab einer auf der Buchungsseite angegebenen Anzahl erfolgt die Buchung auf Anfrage. Die Zahlung wird vollständig durch Stripe (Stripe Payments Europe, Ltd., Irland) abgewickelt. Rechnungsadresse, Steuernummer, Betrag und Zahlungsdaten verbleiben dort; wir erhalten sie nicht. Aus dem Buchungsvorgang übernehmen wir ausschließlich: E-Mail-Adresse, Unternehmensname, Anzahl der gebuchten Standorte sowie die Kundennummer des Zahlungsdienstleisters zur Zuordnung. Die konkreten Standorte werden erst nach der Buchung vom Partner selbst angelegt. Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Technische Bereitstellung
Beim Aufruf der Website werden technisch notwendige Zugriffsdaten verarbeitet (z.B. IP-Adresse, Zeitpunkt, Browser) auf Basis unseres berechtigten Interesses (Art. 6 Abs. 1 lit. f DSGVO).
Spam-Schutz
Zur Abwehr automatisierter Missbrauchsversuche setzen wir einen technischen Schutzmechanismus eines spezialisierten Sicherheitsdienstleisters (derzeit Cloudflare, USA) ein. Dabei können technische Zugriffsdaten übermittelt werden. Die Übermittlung ist durch Standardvertragsklauseln abgesichert. Aktiv eingegebene Daten werden nicht übermittelt.
Cookies und Cookie-Verwaltung
Wir verwenden technisch notwendige Cookies für Session-Verwaltung und Sicherheit – diese laufen immer (Art. 6 Abs. 1 lit. f DSGVO). Mit deiner Zustimmung setzen wir außerdem Statistik- und Marketing-Cookies für Analyse und Kampagnen-Messung (Art. 6 Abs. 1 lit. a DSGVO). Du kannst deine Einwilligung jederzeit über „Cookie-Einstellungen" im Footer widerrufen.
E-Mail-Kommunikation
Wir versenden transaktionale E-Mails die für den Betrieb notwendig sind, z.B. Registrierungsbestätigung, Passwort-Reset und Benachrichtigungen zu deinem Konto. Diese E-Mails werden über einen beauftragten E-Mail-Dienstleister versendet (derzeit Resend, USA; Übermittlung auf Basis von Standardvertragsklauseln gemäß Art. 46 DSGVO). Rechtsgrundlage ist die Vertragserfüllung (Art. 6 Abs. 1 lit. b DSGVO).
Newsletter und Marketing-E-Mails
Mit deiner ausdrücklichen Einwilligung versenden wir gelegentlich Newsletter und Informationen zu peerio (z.B. neue Funktionen, Community-Updates, Angebote). Der Versand erfolgt über einen spezialisierten E-Mail-Dienstleister (derzeit Resend, USA; Übermittlung auf Basis von Standardvertragsklauseln gemäß Art. 46 DSGVO). Du kannst deine Einwilligung jederzeit widerrufen, entweder über den Abmeldelink in jeder E-Mail oder per formloser Nachricht an uns. Nach dem Widerruf werden deine Daten für Marketing-Zwecke nicht weiter genutzt. Rechtsgrundlage ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO).
Analyse und Marketing-Tracking
Wir erfassen anonyme Nutzungsdaten zur Verbesserung unserer Website (Statistik) sowie Reichweitendaten zur Messung unserer Kampagnen (Marketing) – jeweils nur mit deiner Zustimmung. Für die Reichweitenmessung setzen wir nach deiner Einwilligung außerdem den Meta Pixel ein (Meta Platforms Ireland Ltd.). Ohne Zustimmung läuft ausschließlich ein anonymes, cookiefreies Analyse-Tool, das keine Personenidentifikation ermöglicht. Rechtsgrundlage für Statistik und Marketing ist deine Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), die du jederzeit widerrufen kannst.
5. Weitergabe an Dritte
Wir behandeln personenbezogene Daten vertraulich und geben sie nur weiter soweit dies für den Betrieb unserer Dienste erforderlich ist: an beauftragte Dienstleister, an Behörden wenn wir gesetzlich dazu verpflichtet sind, sowie an Rechtsanwälte, Steuerberater oder Wirtschaftsprüfer soweit nötig. Darüber hinaus sind wir berechtigt, personenbezogene Daten an verbundene Unternehmen, Tochtergesellschaften, Muttergesellschaften oder Nachfolgegesellschaften von Tomoveo Ltd. weiterzugeben, soweit dies für den Betrieb, die Weiterentwicklung oder die Verwertung der App erforderlich ist. Anonymisierte und aggregierte Daten ohne Personenbezug können ohne Einschränkung kommerziell verwertet und an Dritte weitergegeben werden.
6. Dienstleister und Drittländerübermittlungen
Für den Betrieb setzen wir spezialisierte Dienstleister ein. Mit allen bestehen Auftragsverarbeitungsverträge gemäß Art. 28 DSGVO. Dienstleister in Drittländern (insbesondere USA) werden durch Standardvertragsklauseln (Art. 46 DSGVO) geschützt.
Wir setzen folgende Kategorien von Dienstleistern ein, mit denen Auftragsverarbeitungsverträge gemäß Art. 28 DSGVO bestehen: Datenbankhosting & Authentifizierung (derzeit Supabase, Server Frankfurt/EU), Infrastruktur & Sicherheit (derzeit u.a. Cloudflare, USA), Kartendarstellung (derzeit Mapbox, USA), E-Mail-Versand (derzeit Resend, USA), KI-Verarbeitung (derzeit Anthropic & OpenAI, USA), Crash-Reporting & Fehleranalyse (derzeit Sentry, USA), Zahlungsabwicklung für peerio Places (derzeit Stripe Payments Europe, Ltd., Irland), Website-Analyse (derzeit Google, USA), Nutzerverhalten-Analyse (derzeit Microsoft Clarity, USA), Werbe-Messung (derzeit LinkedIn, Irland; Microsoft Advertising / Bing, USA; Meta Platforms Ireland Ltd., Irland/USA) sowie Code-Hosting (derzeit GitHub, USA). Für Dienstleister außerhalb der EU erfolgt die Übermittlung auf Basis von Standardvertragsklauseln (Art. 46 DSGVO). Die jeweils aktuell eingesetzten Dienstleister können auf Anfrage mitgeteilt werden.
Die Zahlungsabwicklung für App-Mitgliedschaften erfolgt ausschließlich durch Apple bzw. Google nach deren eigenen Datenschutzbestimmungen; auf diese Zahlungsdaten haben wir keinen Zugriff. Zahlungen von peerio Places Partnern werden primär über Stripe (Stripe Payments Europe, Ltd., Irland) abgewickelt; andere Zahlungsmittel sind möglich. Stripe verarbeitet Zahlungsdaten eigenständig; wir erhalten lediglich eine Bestätigung des Zahlungseingangs sowie für die Rechnungsstellung notwendige Daten. Rechnungs- und Vertragsdaten werden zur Vertragsabwicklung (Art. 6 Abs. 1 lit. b DSGVO) und zur Erfüllung gesetzlicher Aufbewahrungspflichten (Art. 6 Abs. 1 lit. c DSGVO) verarbeitet.
7. peerio Places Partner
Nach der Buchung erhält der Partner einen Zugangscode per E-Mail, mit dem er sein Partnerkonto anlegt und sein Profil selbst befüllt. Im Partnerprofil verarbeiten wir anschließend: Kontaktdaten, Unternehmensname, Standortangaben, Öffnungszeiten, Beschreibungen sowie hochgeladene Bilder und Dateien. Hinzu kommen die Vertragsdaten (gebuchte Standortanzahl, Laufzeit, Kundennummer des Zahlungsdienstleisters). Partner können zudem Links zu externen Webseiten und Social-Media-Profilen in ihrem Profil hinterlegen. Partner können außerdem Events mit Standortangabe erstellen, Nachrichten an Nutzer senden und in der Community ankündigen. Diese Daten werden zur Vertragsabwicklung (Art. 6 Abs. 1 lit. b DSGVO) und zur Erfüllung gesetzlicher Aufbewahrungspflichten (Art. 6 Abs. 1 lit. c DSGVO) verarbeitet. Personenbezogene Daten einzelner Nutzer werden nicht an Partner weitergegeben. Im Rahmen des Partner-Onboardings fragen wir optional ab, wie der Partner auf peerio aufmerksam geworden ist. Diese Angabe ist freiwillig, wird zur Verbesserung unserer Marketingmaßnahmen genutzt und nicht an Dritte weitergegeben. Rechtsgrundlage ist unser berechtigtes Interesse (Art. 6 Abs. 1 lit. f DSGVO).
8. Speicherdauer
Wir speichern deine personenbezogenen Daten grundsätzlich so lange, wie dein Nutzerkonto besteht. Löschst du dein Konto, werden deine Daten gelöscht, mit wenigen Ausnahmen aus rechtlichen oder Sicherheitsgründen.
Meldungen über Inhalte oder Profile werden nach einem Jahr gelöscht. Inaktive Peers und Meets nach 90 Tagen ohne Nachricht. Suchanfragen, Daten zum Nutzungsverhalten, abgelehnte Kontaktanfragen und Benachrichtigungen nach 90 Tagen, erledigte Beitrittsanfragen sofort nach der Entscheidung. Bilder und Dateien aus Chats werden mit dem zugehörigen Chat gelöscht; Dateien ohne zugehörige Nachricht entfernen wir automatisch.
An KI-Dienstleister übermittelte Daten werden dort nach Maßgabe der mit ihnen vereinbarten Bedingungen gelöscht und nicht zum Training ihrer Modelle verwendet. Hiervon unberührt bleibt die Nutzung von Inhalten zur Verbesserung unserer eigenen Systeme gemäß den Nutzungsbedingungen. Anonymisierte oder aggregierte Daten können darüber hinaus gespeichert bleiben. Daten aus der Early-Access-Anmeldung speichern wir bis zu einem Jahr nach Launch, Kontaktanfragen bis zur abschließenden Bearbeitung, längstens zwei Jahre. Vertragsdaten von Partnern sowie Angaben zur Kontolöschung bewahren wir sieben Jahre auf, gerechnet bis zum Ende des jeweiligen Kalenderjahres. Ergänzend gelten die im Abschnitt „Moderation, Sanktionen und Beweisaufbewahrung" genannten Fristen.
9. Deine Rechte
Dir stehen folgende Rechte zu: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung (Art. 18), Datenübertragbarkeit (Art. 20), Widerspruch gegen die Verarbeitung (Art. 21), Widerruf der Einwilligung (Art. 7 Abs. 3) sowie ein Beschwerderecht bei einer Datenschutz-Aufsichtsbehörde. Zur Ausübung genügt eine formlose Nachricht an impressum@tomoveo.com. Einen Datenexport kannst du jederzeit anfordern, solange dein Konto aktiv ist.
Zuständige Aufsichtsbehörde ist der Commissioner for Personal Data Protection, Zypern (www.dataprotection.gov.cy). Nutzer mit Wohnsitz in einem anderen EU-Mitgliedstaat oder der Schweiz können sich alternativ an die für sie zuständige lokale Datenschutzbehörde wenden.
Für Nutzer mit Wohnsitz in der Schweiz gilt ergänzend das Schweizer Datenschutzgesetz (DSG). Zuständige Aufsichtsbehörde ist der Eidgenössische Datenschutz- und Öffentlichkeitsbeauftragte (EDÖB, www.edoeb.admin.ch).
10. Sicherheit
Wir treffen angemessene technische und organisatorische Maßnahmen zum Schutz deiner Daten. Die Datenübertragung im Internet kann jedoch Sicherheitslücken aufweisen; ein lückenloser Schutz vor Zugriff durch Dritte ist nicht möglich. Im Fall einer Datenpanne erfüllen wir die gesetzlichen Meldepflichten gegenüber der zuständigen Aufsichtsbehörde und informieren betroffene Nutzer soweit gesetzlich erforderlich.
11. Social Media
Unsere Website und App enthalten Links zu unseren Profilen auf externen Plattformen. Beim Aufruf dieser Plattformen gelten ausschließlich deren eigene Datenschutzbestimmungen. Wir haben keinen Einfluss auf die Datenverarbeitung durch diese Anbieter.
12. Aktualität dieser Datenschutzerklärung
Wir behalten uns vor, diese Datenschutzerklärung jederzeit zu aktualisieren, insbesondere bei Änderungen der gesetzlichen Anforderungen oder Erweiterung unserer Dienste. Die jeweils aktuelle Fassung ist auf dieser Seite abrufbar. Bei wesentlichen Änderungen informieren wir dich per E-Mail oder In-App-Benachrichtigung.
Stand: August 2026
Privacy Policy
Protecting your personal data is important to us. This Privacy Policy explains how we collect, process, and use data when you use the peerio app or the website peerio.io. We comply with the requirements of the General Data Protection Regulation (GDPR).
1. Controller
Tomoveo Ltd., 8011 Paphos, Cyprus
Email: impressum@tomoveo.com
Full provider details in the Legal Notice.
2. Registration and User Account
Using the peerio app requires registration. We process: email address, first and last name, profile photo, gender (with the option not to state it), information about your business activity (founding stage, industry, team setup, link to your founder activity), a self-description, language settings, and timestamps of registration, your age confirmation, and your acceptance of these terms and the Community Code. Your last name is not shown to other users.
The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). By registering, you confirm that you are at least 18 years old and engaged in business activity. During onboarding, we optionally ask how you heard about peerio. This information is voluntary, used to improve our marketing, and not shared with third parties. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
3. Use of the App
Registration via Apple or Google
You can register with your Apple or Google account. In this case, Apple or Google transmits basic profile data (name, email address) to us. You can view and control what data is transmitted with the respective provider. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Peers and Meets
Content you create in the app is stored and displayed to other users according to your visibility settings. Peers are posts you create where other users can write and discuss. Meets are gatherings you organize on your own responsibility and can make visible to others with a location and time. Peers are time-limited: after a period stated in the app they no longer appear in the overview or on the map and are not discoverable by new users. For participants and the creator, the associated chat remains usable; it is deleted once no message has been sent for 90 days. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Anonymous Mode
Peers can be created anonymously. In this case your name and profile photo are not shown to other users, and your identity is not transmitted to them technically either, neither to outsiders nor to participants of the peer. Within an anonymous peer you appear to everyone as "Anonymus" with a fixed number. The post remains internally linked to your account so that you can manage it. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Connections
When you connect with other users, this connection is saved and forms the basis for further features such as chat and matching. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Matching
peerio uses an automated matching system to suggest suitable users. Analysis is based exclusively on professional information you have entered yourself. To improve matching, text-based profile information is converted into numerical vectors using specialized AI services (currently OpenAI, USA) and stored. This processing is used exclusively for the matching function. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
The matching result is a suggestion without binding or legally significant character within the meaning of Art. 22 GDPR. Matching is part of the contractually owed service and cannot be switched off as a function. You can, however, restrict the underlying data by objecting to the evaluation of your behavioral data; matching then operates solely on the basis of your profile information.
AI-Powered Features
To classify peer content, we use specialized AI services (currently Anthropic, USA). Processing is based on the content you have entered. No analysis of personal or sensitive characteristics takes place. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Messages, Chat, and File Uploads
Messages as well as files and images shared in the chat are stored for the operation of the chat service. We have technical access to this content but do not evaluate it for advertising or profiling purposes. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Usage Behavior
We collect usage data to improve matching and the app. This includes in particular: which peers you join or view, how actively you participate, which profiles you visit, and your search queries in the app. From these signals we develop an interest profile that improves the quality of your suggestions over time. Search queries are stored for this purpose for up to 90 days. This data is evaluated in aggregated or pseudonymized form. To the extent it no longer contains any personal reference, it may also be used for market research, investor communications, and commercial exploitation. You may object to the processing of your behavioral data for the interest profile at any time. A toggle for this is available in the privacy settings of the app. If you object, behavioral data already collected is deleted and no new data is recorded; matching then operates solely on the basis of your profile information. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Membership Status
We store whether you use the free basic model or peerio+ and the respective usage status. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
peerio ID
Each account is assigned a unique peerio ID. This is used for internal identification and can be shared by the user themselves. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Profile Photo
You can upload a profile photo. This is displayed to other users. To ensure authenticity, we automatically check whether the uploaded image shows a real human face. This check is performed by specialized AI services (currently Anthropic, USA) and serves quality assurance purposes only. No biometric analysis, identification, or comparison with external databases takes place. The profile photo is stored with your account and removed upon account deletion. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Links and External Information in Profile
You can add external links to your profile (e.g. website or social media profiles). This information is visible to other users and stored with your profile. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Referral Links
peerio provides a general referral link that users can share. This link contains no identifier and is not assigned to any individual user. We do not record who referred whom. So that we show the prompt to recommend peerio only to active users and not too often, we count certain activities in the app, such as accepted contact requests or meet participation. This counter is linked to your account and is reset after each prompt. It carries no benefits or rewards and is not used for advertising. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Device Data
For operating the app and troubleshooting, we process technical device data such as device ID, operating system, and app version. This data is not used for advertising purposes. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Inactive Accounts
In the event of permanent account inactivity, we are entitled to deactivate or delete the account after prior email notification. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
Notification Settings
You can control which push notifications and email notifications you wish to receive in the app settings. Your settings are saved and can be changed at any time. Push notifications are transmitted via Apple or Google infrastructure and additionally require your consent at device level; they can be disabled via your device settings. The legal basis is your consent (Art. 6(1)(a) GDPR).
Age Verification
peerio is for users aged 18 and over. During registration you confirm that you are at least 18 years old (Art. 8 GDPR).
Meets on the Map
You can create Meets on the map and make them visible to other users with a location. You can optionally set visibility settings, e.g. by gender; these settings are stored with the meet. Data is stored with time and location. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
For map display we use Mapbox (USA). Map tiles are loaded from Mapbox servers. Your device location is used only live for display within the map and is not stored. Location details for Meets are entered manually by the user and stored with coordinates in our database. Transfers to Mapbox are safeguarded by standard contractual clauses (Art. 46 GDPR).
Personal Questions and Icebreakers
You can add personal questions from a predefined selection to your profile and answer them yourself. This information is voluntary and visible to other users. You can also formulate your own question, which is shown to other users before they send you a contact request. Anyone sending you a request may answer this question voluntarily; if you accept the request, the question and answer appear as the first messages in the shared chat. If you decline, the answer is deleted. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Blocking
You can block other users. A block takes effect in both directions: you no longer appear in each other's suggestions, are not findable via search, cannot send each other messages, contact requests, or invitations, and your profiles are shown to each other without name and photo. An existing connection is dissolved. In shared peers and meets, membership remains; the other person appears there without name and photo. Blocks are stored with your account and you can lift them at any time in the settings. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Suspension Notice and Statement
If your account is suspended, the next time you open the app you receive a notice stating the reasons, the underlying rule of the Community Code, and the objected content verbatim. You can submit a statement; your statement is stored and reviewed, and you are informed of the outcome. A suspension is always decided by a person, not by an automated procedure. The legal basis is our legitimate interest in operating a safe platform (Art. 6(1)(f) GDPR).
Moderation, Sanctions, and Evidence Retention
If content or a profile is reported, we review the report and decide on a measure. In doing so we process: the report with its reason and description, the reported content verbatim, the accounts of the reporter and the reported person, and the time.
If a report leads to a suspension, we record the case: the internal account number, the type of decision, the time, our reasoning, the underlying rule of the Community Code, and the objected content verbatim. These records persist even if the account concerned is subsequently deleted. Name, email address, profile photo, and profile content are not retained. The legal basis is our legitimate interest in legal defense and platform safety (Art. 6(1)(f) GDPR); retention despite an erasure request is based on Art. 17(3)(e) GDPR.
We retain records of the sanction process for three years plus the remainder of the calendar year, and objected content verbatim for twelve months. If an appeal or dispute is pending, deletion is suspended until it concludes. Independently of any sanction, for every account deletion we record the time and, where a subscription existed, the payment provider's transaction number, the product, and the term. This serves as evidence in the event of a refund dispute; we retain this information for seven years, calculated to the end of the respective calendar year.
Account Deletion
You can delete your user account yourself in the app at any time. Upon deletion, your account and personal data are removed without delay. Direct messages are deleted in full. Messages in peers and meets remain as placeholders with no link to you, so that the conversation stays readable for the other participants. Anonymized content such as peer posts may continue to exist in non-identifiable form. An active subscription is not automatically cancelled upon account deletion; it must be terminated separately in the respective app store.
A partner account cannot be deleted by the partner during the contract term; deletion is carried out by us after the end of the contract. Records of moderation actions and of the account deletion itself are exempt from deletion; see the section "Moderation, sanctions, and evidence retention".
4. Website peerio.io
Early Access
We process: first name, email address, and your consent with timestamp. After registration you will receive a confirmation email (double opt-in). The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
peerio Places Booking
Places Partners book the number of locations they require via peerio.io/peerio-places; above a number stated on the booking page, booking takes place upon request. Payment is handled entirely by Stripe (Stripe Payments Europe, Ltd., Ireland). Billing address, tax number, amount, and payment data remain there; we do not receive them. From the booking process we take only: email address, company name, number of locations booked, and the payment provider's customer number for allocation. The specific locations are created by the partner only after booking. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Technical Provision
When accessing the website, technically necessary access data is processed (e.g. IP address, time, browser) on the basis of our legitimate interest (Art. 6(1)(f) GDPR).
Spam Protection
To defend against automated abuse attempts, we use a technical protection mechanism from a specialized security provider (currently Cloudflare, USA). Technical access data may be transmitted. The transmission is secured by standard contractual clauses. Actively entered data is not transmitted.
Cookies and Cookie Management
We use cookies on two levels:
- Technically necessary cookies: These are automatically set for session management and security. They do not require consent (Art. 6(1)(f) GDPR).
- Marketing cookies: The LinkedIn Insight Tag sets a tracking cookie for campaign measurement. You must explicitly consent to this cookie (Art. 6(1)(a) GDPR).
You can adjust your cookie settings at any time via the cookie banner and withdraw consents.
Email Communication
We send transactional emails necessary for operation, e.g. registration confirmation, password reset, and account notifications. These emails are sent via an appointed email service provider (currently Resend, USA; transmission based on standard contractual clauses pursuant to Art. 46 GDPR). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
Note: Email is not a secure transmission channel. We accept no liability for damages arising from loss, delay, falsification, or unauthorized access during transmission. We accept no responsibility for the content of attachments.
Newsletter and Marketing Emails
With your explicit consent, we occasionally send newsletters and information about peerio (e.g. new features, community updates, offers). Emails are sent via a specialized email service provider (currently Resend, USA; transmission based on standard contractual clauses pursuant to Art. 46 GDPR). You can withdraw your consent at any time, either via the unsubscribe link in each email or by informal message to us. After withdrawal, your data will no longer be used for marketing purposes. The legal basis is your consent (Art. 6(1)(a) GDPR).
Analytics and Marketing Tracking
We collect anonymous usage data to improve our website (statistics) as well as reach data to measure our campaigns (marketing) — in each case only with your consent. For reach measurement we also use the Meta Pixel (Meta Platforms Ireland Ltd.) subject to your consent. Without consent, only an anonymous, cookie-free analysis runs that does not enable personal identification. The legal basis for statistics and marketing is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. We currently use Google Analytics (USA) for statistics, Microsoft Clarity (USA) for user behavior analysis, and LinkedIn Insight Tag (Ireland) and Microsoft Advertising / Bing UET (USA) for marketing measurement.
5. Disclosure to Third Parties
We treat personal data confidentially and only share it to the extent necessary for operating our services: with appointed service providers, with authorities when legally required, and with lawyers, tax advisors, or auditors as needed. We are additionally entitled to share personal data with affiliated companies, subsidiaries, parent companies, or successor companies of Tomoveo Ltd. to the extent necessary for the operation, development, or exploitation of the app. Anonymized and aggregated data without personal reference may be commercially exploited and shared with third parties without restriction.
6. Service Providers and Third-Country Transfers
We use specialized service providers for operations. Data processing agreements pursuant to Art. 28 GDPR exist with all of them. Service providers in third countries (in particular the USA) are protected by standard contractual clauses (Art. 46 GDPR).
We use the following categories of service providers, with whom data processing agreements pursuant to Art. 28 GDPR exist: database hosting and authentication (currently Supabase, server Frankfurt/EU), infrastructure and security (currently including Cloudflare, USA), map display (currently Mapbox, USA), email delivery (currently Resend, USA), AI processing (currently Anthropic and OpenAI, USA), crash reporting and error analysis (currently Sentry, USA), payment processing for peerio Places (currently Stripe Payments Europe, Ltd., Ireland), website analytics (currently Google, USA), user behavior analysis (currently Microsoft Clarity, USA), advertising measurement (currently LinkedIn, Ireland; Microsoft Advertising / Bing, USA; Meta Platforms Ireland Ltd., Ireland/USA), and code hosting (currently GitHub, USA). For service providers outside the EU, transmission is based on standard contractual clauses (Art. 46 GDPR). The service providers currently in use can be communicated upon request.
Payment processing for app memberships is handled exclusively by Apple or Google under their own privacy policies; we have no access to this payment data. Payments from peerio Places Partners are processed primarily via Stripe (Stripe Payments Europe, Ltd., Ireland); other payment methods are available. Stripe processes payment data independently; we only receive a payment confirmation and data necessary for invoicing. Billing and contract data is processed for contract performance (Art. 6(1)(b) GDPR) and to fulfill legal retention obligations (Art. 6(1)(c) GDPR).
7. peerio Places Partners
After booking, the partner receives an access code by email with which they create their partner account and fill in their profile themselves. Within the partner profile we then process: contact details, company name, location information, opening hours, descriptions, and uploaded images and files. In addition, we process contract data (number of locations booked, term, payment provider's customer number). Partners may also add links to external websites and social media profiles in their profile. Partners can also create events with location details, send messages to users, and announce them in the community. This data is processed for contract performance (Art. 6(1)(b) GDPR) and to fulfill legal retention obligations (Art. 6(1)(c) GDPR). Personal data of individual users is not shared with partners. During partner onboarding, we optionally ask how the partner heard about peerio. This information is voluntary, used to improve our marketing, and not shared with third parties. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).
8. Retention Periods
We store your personal data for as long as your account exists. If you delete your account, your data will be deleted, with limited exceptions for legal or safety reasons.
Reports about content or profiles are deleted after one year. Inactive peers and meets after 90 days without a message. Search queries, usage behavior data, declined contact requests, and notifications after 90 days; completed join requests immediately after the decision. Images and files from chats are deleted together with the chat concerned; files with no associated message are removed automatically.
Data transmitted to AI service providers is deleted there in accordance with the terms agreed with them and is not used to train their models. This does not affect the use of content to improve our own systems in accordance with the Terms of Use. Anonymized or aggregated data may be retained beyond this. Early access registration data is stored for up to one year after launch, contact requests until final processing and no longer than two years. Partner contract data and records of account deletions are retained for seven years, calculated to the end of the respective calendar year. The periods stated in the section "Moderation, sanctions, and evidence retention" apply in addition.
9. Your Rights
You have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), right to object to processing (Art. 21), withdrawal of consent (Art. 7(3)), and the right to lodge a complaint with a data protection supervisory authority. To exercise these rights, an informal message to impressum@tomoveo.com is sufficient. You can request a data export at any time while your account is active.
The competent supervisory authority is the Commissioner for Personal Data Protection, Cyprus (www.dataprotection.gov.cy). Users resident in another EU member state or Switzerland may alternatively contact their local data protection authority.
For users resident in Switzerland, the Swiss Federal Act on Data Protection (FADP/DSG) applies in addition. The competent supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC/EDÖB, www.edoeb.admin.ch).
10. Security
We take appropriate technical and organizational measures to protect your data. However, data transmission over the internet may have security vulnerabilities; complete protection against third-party access is not possible. In the event of a data breach, we fulfill our legal reporting obligations to the competent supervisory authority and inform affected users to the extent legally required.
11. Social Media
Our website and app contain links to our profiles on external platforms. When accessing these platforms, their own privacy policies apply exclusively. We have no influence over data processing by these providers.
12. Updates to this Privacy Policy
We reserve the right to update this Privacy Policy at any time, in particular in the event of changes to legal requirements or expansion of our services. The current version is available on this page at all times. In the event of material changes, we will inform you by email or in-app notification.
As of: August 2026