NOKTÜRN.
Data protection

Privacy Policy (GDPR)

Version 1.1 · Last updated: 24 July 2026 · Governing law: EU General Data Protection Regulation (GDPR) and German Federal Data Protection Act (BDSG).

Important legal notice. This document is a working template prepared for the Noktürn platform operator (see Impressum). Before going live commercially, it must be reviewed by a qualified data protection specialist (e.g., a Datenschutzbeauftragter or IT lawyer) for your specific processing activities. Noktürn cannot provide legal advice.

1. Data Controller

The Data Controller (Verantwortlicher) responsible for the processing of personal data on this website within the meaning of Art. 4(7) and Art. 13(1)(a) GDPR is:

David Kungang Aminkeng

Schloßstraße 42, 51061 Köln, Germany

Email: noktuern@gmx.net

Phone: +49 221 42323396

1a. Server log files

Every request to this website is logged by our hosting provider in short-lived server log files. This processing is necessary to operate, secure and troubleshoot the service (Art. 6(1)(c) and (f) GDPR; Art. 13(1)(c) and (e) GDPR). Typical log entries include:

  • anonymised or truncated IP address of the requesting device,
  • date and time of the request,
  • the URL requested and HTTP status code returned,
  • user-agent string (browser/OS) and referring URL, if any.

Server log files are used only for operational security, abuse prevention and technical error analysis. They are stored on our behalf by our hosting provider (see “Hosting & subprocessors” below) and are deleted or aggregated after at most 30 days, unless a specific entry is retained longer for a documented security incident.

1b. International data transfers

Where personal data is transferred to processors outside the European Economic Area (EEA), such transfers are protected by the safeguards required under Art. 13(1)(f) and Chapter V GDPR:

  • USA — Stripe Inc. and Google LLC (Google Translate) are certified under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023). Additional Standard Contractual Clauses (SCCs) apply where the framework does not cover a specific data flow.
  • Other third countries — if any further transfer becomes necessary, we rely on Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where appropriate, supplementary technical measures such as encryption and pseudonymisation.

You have the right to request a copy of the applicable safeguards by contacting the Data Controller at the address above.

1c. Google Translate

This website offers an optional Google Translate widget (operated by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Google Translate is only loaded after you have explicitly consented via our cookie banner or by actively choosing a non-English language.

  • Purpose: translate the visible page content into your preferred language.
  • Legal basis: your consent, Art. 6(1)(a) GDPR and § 25(1) TTDSG.
  • Data processed: IP address, the text to be translated, browser and device information, and a googtrans cookie storing your chosen language.
  • Recipient / transfer: Google LLC, USA (EU-US Data Privacy Framework, SCCs where applicable).
  • Retention: processed solely for the translation request; the googtrans cookie is stored on your device until you clear it.
  • Withdrawal: you can revoke consent at any time by rejecting optional cookies in our cookie banner and clearing site data. Further information: policies.google.com/privacy.

2. What personal data we collect

2.1 Account data

  • Email address, password (hashed), display name.
  • Optional profile data (organizer name, public display name, bio, social links).

2.2 Event submission data

  • Event title, description, dates, venue, address, city, country.
  • Organizer contact details (e.g., email/phone) used for verification and public display where you choose to publish them.
  • Uploaded images, links, and any free-text content you provide.

2.3 Ticket purchase and payment data

  • Billing name, billing address, email, country (for invoice and tax records).
  • Payment data (card number, account details) are collected and processed directly by Stripe Payments Europe Ltd.; Noktürn does not store complete card data.
  • Transaction IDs, order amount, ticket tier, event, and purchase timestamp.

2.4 Usage and analytics data

  • IP address (shortened/anonymized where possible), browser type, device type, operating system, and referrer URL.
  • Pages visited, clicks, search queries, and interactions with events.
  • Event view → ticket selection → purchase conversion events, used to understand drop-off points and improve the site.

2.5 Communications and support data

  • Emails, contact form submissions, and customer support requests.
  • Report/flag submissions and moderation audit records.

2.6 Cookies and similar technologies

We use strictly necessary cookies to operate the site (login session, language preference, cookie consent). Analytics and marketing cookies are only set after your explicit opt-in via the cookie banner. You can withdraw consent at any time in your browser settings.

3. Purposes and lawful bases of processing

We process personal data only where there is a lawful basis:

  • Art. 6(1)(a) GDPR — consent: newsletter sign-ups, optional analytics cookies, marketing communications, and certain optional profile fields.
  • Art. 6(1)(b) GDPR — contract performance: account creation, event submission, ticket purchase and delivery, and organizer payouts.
  • Art. 6(1)(c) GDPR — legal obligation: tax and invoice retention (§ 147 AO), commercial law requirements, and responding to valid legal requests.
  • Art. 6(1)(f) GDPR — legitimate interest: website security, fraud prevention, spam/misuse detection, content moderation, technical error analysis, and improving the platform.

4. How we use your data

  • To operate the event directory and allow visitors to discover events by region, city, category, and date.
  • To broker ticket sales between Buyers and Organizers and to facilitate QR ticket delivery and redemption.
  • To verify organizer contact details (email/phone verification) before publishing paid listings or high-visibility events.
  • To process payments, issue receipts/commission statements, and comply with tax/accounting rules.
  • To moderate user-generated content, investigate reports, and enforce our Terms and UGC rules.
  • To send service-related emails (order confirmations, ticket reminders, security alerts) and, with consent, marketing emails.
  • To analyze aggregated usage and improve the user experience and conversion flow.

5. Recipients of personal data

  • Organizers: when you buy a ticket, the Organizer receives the minimum data needed to fulfill admission (name, email, ticket tier, event). When you submit an event, the data you choose to display publicly is visible to all visitors.
  • Stripe Payments Europe Ltd.: payment processing, fraud prevention, and chargeback handling.
  • Hosting and platform providers: Lovable Cloud (Supabase) for database, authentication, and storage; Lovable hosting for the frontend application.
  • Analytics providers: only after consent, and configured with IP anonymization where technically possible.
  • Authorities and courts: where required by law or to enforce our rights (e.g., fraud investigations).

6. International transfers

Core data is stored in the EU by Lovable Cloud/Supabase. Payment data is processed by Stripe, which applies EU-standard contractual clauses (SCCs) and adequacy decisions for transfers outside the EEA. We do not transfer data outside the EEA for purposes other than those listed in this policy. Any future transfer will rely on GDPR Chapter V safeguards (SCCs, adequacy decisions, or binding corporate rules).

7. Retention and deletion

7.1 Account and profile data

Kept while your account is active. If you delete your account, we delete or anonymize personal data within 90 days, except where a longer retention period is required by law.

7.2 Event listings and user-generated content

You choose how long your listing stays online. After the selected duration, the listing moves to the Dustbin for 30 days, then is permanently deleted. You may delete or permanently erase content earlier from your dashboard.

7.3 Purchase and invoice data

Kept for 10 years after the end of the relevant calendar year to comply with German commercial and tax law (§ 147 AO / GoBD).

7.4 Analytics and log data

Anonymized or deleted after 26 months unless a longer retention is justified for security or fraud prevention.

7.5 Report and moderation data

Retained for up to 3 years after resolution for legal defense and audit purposes, then anonymized.

8. Your rights under GDPR

You have the following rights, which you can exercise free of charge:

  • Right of access (Art. 15 GDPR): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16 GDPR): correct inaccurate or incomplete data via your dashboard or by contacting us.
  • Right to erasure (Art. 17 GDPR): request deletion of your data, subject to legal retention obligations.
  • Right to restriction of processing (Art. 18 GDPR): request that we temporarily stop processing certain data.
  • Right to data portability (Art. 20 GDPR): receive your data in a structured, machine-readable format (JSON) from your dashboard.
  • Right to object (Art. 21 GDPR): object to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent (Art. 7(3) GDPR): withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
  • Right to lodge a complaint (Art. 77 GDPR): file a complaint with your local supervisory authority, e.g., the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) or the supervisory authority of your country of residence.

To exercise your rights, log in to your dashboard or contact us at noktuern@gmx.net. We will respond within one month, which may be extended by two months for complex requests.

9. Automated decision-making and profiling

We do not use automated decision-making that produces legal effects or similarly significantly affects you. Content moderation decisions made in the moderator queue are reviewed by a human before permanent action.

10. Data security

We apply appropriate technical and organizational measures to protect your data:

  • TLS/SSL encryption for all data in transit; encrypted storage at rest.
  • Row-Level Security (RLS) in the database so users can only access their own data, and public views expose only non-sensitive fields.
  • Passwords are hashed (bcrypt). Password resets require email verification.
  • Stripe handles all payment card data in a PCI-DSS compliant environment.
  • Regular access reviews, least-privilege roles, and audit logging for moderation and security events.

11. Cookies and consent

We distinguish between necessary and optional cookies. Necessary cookies are required for the website to function and cannot be disabled without breaking core features (e.g., login, language selection). Optional cookies (analytics, marketing) require your explicit consent and can be withdrawn at any time.

12. Children

The platform is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us and we will delete it promptly.

13. Changes to this Privacy Policy

We may update this policy to reflect changes in law, processing, or features. We will publish the new version on this page with an updated "last updated" date. Material changes will be notified by email or by a prominent notice on the website.

14. Contact for data protection questions

For questions, rights requests, or complaints about data protection, contact:

David Kungang Aminkeng

Schloßstraße 42, 51061 Köln, Germany

Email: noktuern@gmx.net

Phone: +49 221 42323396

You may also contact us via the Contact page.

Related legal pages: Terms & UGC, Ticket Broker AGB, Security & Trust, Impressum.