
The inner circle of Copenhagen hospitality
Industry-verified members only
·
Discounts up to 50% off
·
Digital member card & events
·
A real peer community
The inner circle of Copenhagen hospitality
Copenhagen Hospitality Membership
-
Industry-verified members only
-
Discounts up to 50% off
-
Digital member card & events
-
A real peer community
PRIVACY
1. Data Controller
The data controller for personal data processed in the KREDS app is Kreds ApS, CVR 46635922, Falkonervænget 15, 1. th, 1952 Frederiksberg C, Denmark. You can reach us at hello@kreds.dk.
2. What we collect
Account data: name, email, password hash, role, workplace, profile photo, and — if you choose to provide it — a document evidencing your employment in hospitality (for example a payslip), which we use once to verify your application.
Usage data: offers claimed, RSVPs, venue visits, party size, login timestamps, device/OS info.
Location data: if you grant permission, the app reads your device's location while you are using the map, so it can centre on where you are. Your location is used on your device only — it is never sent to our servers, stored, or shared. You can decline, and the map still works.
Venue data: for venue accounts we also collect CVR, address, contact details, logo and photos.
We do not collect payment data. No purchases are made in this app, and we do not process card details through it.
3. Why we process it (legal basis)
Contract (Art. 6(1)(b)): to create and operate your account, verify your eligibility for membership, show you offers, and process venue sign-ups.
Legitimate interests (Art. 6(1)(f)): fraud prevention, service analytics, security monitoring.
Consent (Art. 6(1)(a)): optional marketing emails and non-essential cookies/analytics. You can withdraw consent at any time from the Account screen.
Legal obligation (Art. 6(1)(c)): bookkeeping records retained per Danish Bogføringsloven (5 years).
4. Who we share data with
We use the following sub-processors, each under a written Data Processing
Agreement (GDPR Art. 28):
• Supabase — database and file storage (EU region, Frankfurt).
• Resend — delivery of service emails (password resets, account notices). Processing takes place in the United States under EU Standard Contractual Clauses.
• Sentry — crash and error reporting, so we find out when the app breaks. Hosted in the EU (Frankfurt). Reports are stripped of your identity before they are sent: no user ID, no email, no request bodies, no cookies — only the error itself and the address of the failing request.
• Apple / Google — app distribution.
We never sell personal data. Employment-verification documents are stored in a private, non-public location and are readable only by KREDS administrators carrying out the approval decision.
What venues see: when you claim an offer, the venue sees your name, photo, role, workplace, member code and the size of your party — enough to confirm you are a member. They never see your email, your verification document, or your activity
at other venues.
What other members see: nothing, unless you choose to share it. Adding a friend is one-directional and blind — you enter someone's member code and they receive a request. You are shown no name, no photo and no confirmation that the code even exists until they accept.
5. International transfers
Our primary storage is in the EU. If any sub-processor transfers data outside the EEA, it's done under EU Standard Contractual Clauses plus supplementary measures where required (Schrems II).
6. How long we keep it
Active accounts: for the life of the account. When you delete your account, your personal fields are scrubbed immediately — name, email, photo, verification document, role and workplace are removed at the moment you confirm deletion. Records we are legally required to keep for accounting purposes are retained for 5 years as required by Bogføringsloven, then destroyed. Anonymised claim counts (with no link to you) may be retained so venues keep accurate historical statistics. Residual copies in encrypted backups are purged within 30 days of deletion.
7. Your rights
Under GDPR you can at any time:
• Access a copy of your data (Art. 15)
• Correct inaccurate data (Art. 16)
• Have your data erased (Art. 17)
• Restrict or object to processing (Art. 18, 21)
• Receive your data in a portable format (Art. 20)
• Withdraw consent without affecting past processing
Most of these can be exercised in-app under Account → Privacy. For anything else,
email hello@kreds.dk.
You can also lodge a complaint with the Danish Data Protection Authority (Datatilsynet, www.datatilsynet.dk).
8. Cookies and tracking (web)
The web version of KREDS only uses cookies strictly necessary for the service to work (session, CSRF). Any analytics or marketing cookies require your opt-in via the cookie banner.
9. Security
We use TLS in transit, encrypted storage at rest, row-level security policies in the database, and least-privilege access controls. In the event of a personal-data breach, Datatilsynet is notified within 72 hours per GDPR Art. 33.
10. Changes
Material changes to this policy will be communicated in-app with a new version number and, where legally required, a renewed consent prompt.
Kreds ApS · CVR 46635922 · Falkonervænget 15, 1. th, 1952 Frederiksberg C, Denmark · hello@kreds.dk



