Legal
Privacy Policy
Last updated: 17 August 2026
This Privacy Policy explains how Zerophia (“we”, “us”) processes personal data when you use Wasla at wasla.club (the “Service”), in line with the EU General Data Protection Regulation (GDPR) and Dutch implementation law (UAVG).
This document is provided for transparency and compliance. It is not personalised legal advice.
1. Controller
The controller is Zerophia, operator of Wasla. Privacy requests: privacy@zerophia.com. If we appoint a Data Protection Officer, contact details will be added here.
2. Categories of personal data
- Identity & account: display name, email, password hash, email verification status, role (member/host), optional avatar URL and bio.
- Host & event content: listings, venue/location, trust labels, images URLs, descriptions.
- Bookings: attendee name and email, booking status, check-in code, optional linked account, related event reference.
- Community membership: when you join a community (or attend a community event), we store your name and email so the host can message members and so we can email you about new events in that community.
- Sign-in with Google (optional): if you choose Google OAuth, we receive your Google account identifier, email, name, and profile photo from Google to create or link your Wasla account.
- Billing: Stripe customer/subscription identifiers, plan status, invoices/tax metadata. Payment card data is processed by Stripe, not stored by us in full.
- Technical / security: essential cookies, IP and request metadata as processed by our hosting/security providers (e.g. Cloudflare) for delivery and abuse prevention.
- Analytics (with consent): Google Analytics 4 measurement data such as page views, device/browser info, and approximate location, only after you accept analytics cookies.
- Communications: messages you send to support, privacy, or abuse contacts.
3. Purposes and legal bases (GDPR Art. 6)
- Contract (Art. 6(1)(b)): create/manage accounts; publish/browse events; bookings; organizer subscriptions; customer support related to the Service.
- Legal obligation (Art. 6(1)(c)): tax/VAT, accounting, responding to lawful authority requests, DSA notice handling records where required.
- Legitimate interests (Art. 6(1)(f)): securing the Service; preventing fraud, spam, and abuse; improving reliability; enforcing Terms and Community Guidelines — balanced against your rights and expectations as a user of a social events platform.
- Consent (Art. 6(1)(a)): optional analytics cookies (Google Analytics) — we ask via the cookie banner before loading analytics. Essential cookies do not rely on marketing consent (see Cookie Policy).
We do not use your data for automated decision-making that produces legal or similarly significant effects (GDPR Art. 22).
4. Special category data
Wasla is designed for Muslim social activities. Event labels (audience, alcohol, prayer notes) may relate to community preferences. Do not upload sensitive personal data about others without a lawful basis. Hosts must not require attendees to disclose health, religion of others, or other special-category data beyond what is necessary and lawful for the event context.
5. Recipients / processors
- Stripe — payments, subscriptions, Tax/VAT, Customer Portal (privacy).
- Cloudflare — hosting (Workers), CDN/security.
- Google — (a) Google Analytics 4 for optional usage analytics when you consent; (b) Google OAuth if you sign in with Google; (c) Google reCAPTCHA for abuse prevention on forms (privacy).
- Database infrastructure — storage of account, event, and booking records.
We do not sell personal data. We may disclose data to competent authorities when legally required, or to professional advisers under confidentiality.
6. International transfers
Some processors (including Google and Stripe) may process data in the United States or other countries outside the EEA/UK. Where that happens, we rely on adequacy decisions and/or Standard Contractual Clauses (or equivalent safeguards) as documented by those processors. Analytics data is sent to Google only after you consent via the cookie banner.
7. Retention
- Account data: while your account is active; after a verified deletion request we delete or anonymise it unless law requires retention.
- Bookings & financial / tax records: typically up to 7 years where accounting rules require (may be kept in anonymised or limited form).
- Analytics (GA4): retained according to Google Analytics retention settings for the property; you can withdraw consent anytime (see Cookie Policy).
- Security / abuse logs: shorter operational periods unless needed for investigations.
- Illegal-content notices (DSA): retained as needed to handle reports and demonstrate compliance.
8. Your rights (GDPR)
Under the GDPR you may request: access, rectification, erasure (“right to be forgotten”), restriction, portability, and objection to processing based on legitimate interests. Where processing is based on consent (analytics cookies), you may withdraw consent at any time without affecting earlier lawful processing.
Account deletion (erasure)
To delete your Wasla account and associated personal data, use Request account deletion on My profile (signed in), or email support@zerophia.com from the address on your account. You may also write privacy@zerophia.com.
- We verify the request (usually by confirming ownership of the account email) and aim to complete deletion or anonymisation within one month (extendable as GDPR allows for complex requests).
- Hosts should cancel any active Stripe organizer subscription first (via the billing portal) so charges stop; we can help if needed.
- Communities or events you own may be archived, anonymised, or reassigned so public listings do not keep your personal profile.
- We may retain limited data where legally required (e.g. invoices, fraud prevention, DSA notice records) or where another lawful basis applies.
Other privacy requests: privacy@zerophia.com. You may complain to the Dutch Autoriteit Persoonsgegevens (or your local EU supervisory authority).
9. Security
We use industry-standard measures appropriate to risk (hashed passwords, HTTPS, access controls, edge protections). No method is 100% secure.
10. Children
The Service is for users 16+ (or older if your country requires a higher digital consent age). We do not knowingly create accounts for younger children.
11. Changes & contact
We may update this policy; the date above will change. Contact privacy@zerophia.com / support@zerophia.com.