Privacy
Privacy Policy
This policy explains how Dancing Bee collects, uses, shares, protects, and deletes personal data for the mobile app and public support website.
Policy details
Effective date: 2026-09-11. Version: 2026-09-09-support-response.1.
Controller and contact
Operator and controller: Ali Jenabidehkordi. Business address: Am Anger 10, 07743 Jena, Germany. Email: support@dancing-bee.com.
The controller determines why and how personal data is processed for the Dancing Bee mobile app and this public support website. Contact the email above with privacy questions or use the privacy-request page below.
Data we process
Required account and eligibility data includes email address, authentication data and status, user or support identifiers, legal country, age-eligibility result, roles, and accepted-policy records. A date of birth entered for the automated age check is used to determine eligibility but is not stored in the profile or audit log.
Optional profile and feature data can include name, profile details and photo, phone number or address, provider profile, events and venues, announcements, invitations, saved searches, in-app friendships and contacts, reports, notifications, media, and precise or approximate location. Dancing Bee does not import a device address book or calendar.
Operational data can include installation, device and push-notification identifiers, product interactions, email-delivery records, support or deletion-request metadata, logs, security and abuse-prevention events, and diagnostics. Cloud crash diagnostics are optional and consent-controlled; the app has no advertising identifier, advertising SDK, purchases, or payment data.
Sources
We receive data directly from you and your activity in the app or website; automatically from the app, device, and enabled service components; and from Apple or Google if you choose their sign-in service.
We may also receive data from other users or providers through invitations, friendships, events, and reports. Event and provider information comes from the person or organization that posts it to Dancing Bee. We will not claim or activate an import from external public sources, device address books, or device calendars unless that exact process is documented and disclosed first.
Purposes and lawful bases
We process data to create and secure accounts; provide event discovery, profiles, invitations, friendships, provider tools, maps, media, and notifications; answer support and privacy requests; moderate content; prevent fraud and abuse; diagnose faults; enforce the Terms; comply with law; and establish, exercise, or defend legal claims.
Where the GDPR applies, the legal bases are performance of the user contract and requested steps before it (Article 6(1)(b)); compliance with legal obligations (Article 6(1)(c)); legitimate interests in service security, fraud and abuse prevention, proportionate diagnostics, support, moderation, and legal defence after balancing affected rights (Article 6(1)(f)); and consent for expressly optional processing such as cloud crash diagnostics where required (Article 6(1)(a)). Consent can be withdrawn for future processing without affecting earlier lawful processing.
Sharing and recipients
Feature data is shown to other users only as needed for the profile, event, invitation, friendship, reporting, or provider feature you use. We may disclose necessary data to public authorities, courts, advisers, or rights holders when lawfully required or needed to protect people, enforce rights, or handle a legal claim.
Service providers support cloud hosting and storage, account authentication, databases, email and push delivery, abuse prevention, maps and location features, app distribution, diagnostics, and security monitoring. Any third party receiving personal data through Dancing Bee must provide the same or equivalent protection required by this policy and applicable law, and that protection must be verified before the provider is enabled for a public release. If a provider independently determines its own purposes, its own privacy notice also applies.
We do not sell personal data, use personal data for advertising, track people for advertising, or share personal data for cross-context behavioural advertising. Dancing Bee has no advertising or payment provider.
International transfers
When personal data is transferred from the EEA to another country, we rely on an applicable adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses and necessary supplementary measures. Information and a copy of relevant safeguards can be requested through the privacy-request page.
Security
Dancing Bee uses HTTPS/TLS in transit, operating-system protected credential storage in the app, authentication and access controls, rate limits, audit logs, and redaction of sensitive diagnostic data. Access to retained safety, legal, policy-acceptance, and audit records is restricted to the purpose that requires them.
These measures reduce risk, but no service or storage method can guarantee absolute security. Dancing Bee does not claim an independent security certification.
Retention and deletion
Account and feature data is kept while the account is open and as needed to provide the selected features. Diagnostic reports stored locally in the app are automatically removed after 30 days; turning off optional cloud diagnostics deletes unsent cloud-diagnostic reports from the device. Other operational and support records are reviewed and deleted or anonymized when their purpose and legal basis end.
After an in-app deletion confirmation, account access is disabled immediately and deletion is scheduled after a 30-day recovery period. Logging in before the scheduled date cancels deletion. The scheduled cleanup then removes the account, authentication identities, uploaded media, and user-owned product records.
The public deletion form instead creates a privacy case, reference number, and response-due date, normally one calendar month after receipt. Submitting that form alone does not disable the account or start the automated 30-day recovery period; support first verifies the request and handles the deletion case.
Safety and abuse reports, moderation decisions and appeals, legal cases, accepted-policy evidence, and minimum audit records may be retained after account deletion. The live account identifier is replaced with a pseudonymous deleted-user reference; retained privacy-request records lose the account email and free-form details.
Retention for those restricted records is determined by the time needed to resolve the case, protect users, prevent repeated abuse or fraud, comply with law, document a contract or consent, and establish, exercise, or defend legal claims. They are deleted or anonymized when the applicable purpose or legal basis ends.
Your choices and rights
Depending on applicable law, you may request access, a copy or export, correction, deletion, restriction, or portability; object to processing; withdraw consent; and complain to a data-protection authority. We may need to verify identity before acting on a request.
Optional cloud diagnostics can be turned off in the app. Country-specific notices explain the applicable authority, rights, deadlines, and local legal details for Germany and Sweden.
