Privacy Policy
Last updated:
1. Who we are
Speedy Socials.eu is a social networking platform operated within the European Union. We are committed to protecting the privacy and security of your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the ePrivacy Directive 2002/58/EC.
For the purposes of the GDPR, the data controller is the entity operatingSpeedy Socials. You can reach our Data Protection Officer at dpo@eubook.eu.
2. What data we collect and why
We collect only the personal data that is necessary for the specific purpose it is collected for. We do not collect data speculatively or for purposes we have not documented. Below is a summary of the data we process, why we process it, and the legal basis we rely on.
| Data category | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation, authentication, email verification, password resets, and essential service notifications. | Performance of a contract (Article 6(1)(b)) |
| Password (hashed, never stored in plaintext) | Authentication. Passwords are hashed using Argon2id before storage. We never see or store your plaintext password. | Performance of a contract (Article 6(1)(b)) |
| Username and display name | Public identity on the platform. Your display name is visible to other users. | Performance of a contract (Article 6(1)(b)) |
| Profile information (bio, avatar) | Optional public profile. You control what you share and can remove it at any time. | Consent (Article 6(1)(a)) |
| Locale preference | To display the platform in your preferred language. | Legitimate interest (Article 6(1)(f)) — providing a usable interface. |
| IP address and user agent | Security: rate limiting, fraud prevention, audit logging, and session management. Stored only where legally required and never for benign read operations. | Legitimate interest (Article 6(1)(f)) — platform security and integrity. |
| Audit and security logs | Accountability: recording who did what and when, for forensic and regulatory purposes. Append-only; not modified or deleted by application code. | Legal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f)) |
3. How we collect your data
We collect your data in the following ways:
- Data you give us directly: when you create an account, fill in your profile, or communicate with us.
- Data generated by your use of the platform: session data, security logs, and audit records.
- Technical data automatically: your IP address and browser user agent, collected for security purposes only.
- We do not use tracking pixels, third-party analytics, advertising cookies, or any form of behavioural profiling.
4. Who we share your data with
We do not sell, rent, or trade your personal data with any third party. Your data stays on our infrastructure within the European Union. We may share data only in the following limited circumstances:
- Hosting and infrastructure providers: our server hosting is within the EU and bound by data processing agreements compliant with Article 28 of the GDPR.
- Legal obligations: when required by EU or member state law, court order, or competent government authority, and only to the extent strictly necessary.
- Protection of rights: to protect the safety of our users, to enforce our Terms of Service, or to defend our legal rights, always proportionally and with audit logging.
5. How long we keep your data
We retain personal data only for as long as necessary to fulfil the purposes described above, or to comply with legal obligations. When data is no longer needed, it is securely deleted or anonymised.
| Data category | Retention period |
|---|---|
| Account data (email, password hash, username) | For the lifetime of your account, plus 30 days after a deletion request to allow for accidental deletion recovery. |
| Session data | Until session expiry (idle timeout or absolute timeout, whichever comes first). Server-side session files are destroyed, not just the cookie. |
| Audit logs | Configurable per deployment. Retained for the period required by applicable law and then securely deleted. |
| Security event logs | Same retention as audit logs. Configurable per deployment. |
| Verification and password reset tokens | Single-use and time-limited (verification: 24 hours, password reset: 1 hour). Marked as used rather than deleted to preserve an audit trail. |
6. International data transfers
Speedy Socials.eu is hosted entirely within the European Union. We do not transfer your personal data to any country outside the EU/EEA. No third-party services we use have access to your data from outside the EU.
Should this ever change (for example, if we engage a non-EU service provider), we will ensure appropriate safeguards are in place under Chapter V of the GDPR, and we will update this policy accordingly.
7. Your rights under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): you can request a copy of all personal data we hold about you.
- Right to rectification (Article 16): you can correct inaccurate or incomplete personal data.
- Right to erasure (Article 17): you can request deletion of your personal data ("right to be forgotten").
- Right to restriction of processing (Article 18): you can ask us to limit how we use your data.
- Right to data portability (Article 20): you can receive your data in a structured, machine-readable format.
- Right to object (Article 21): you can object to processing based on legitimate interests.
- Right to withdraw consent (Article 7(3)): where processing is based on consent, you can withdraw it at any time. Withdrawal is as easy as granting consent was.
To exercise any of these rights, please contact us at dpo@eubook.eu. We will respond within 30 days. If your request is complex or numerous, we may extend this by a further 60 days, in which case we will inform you.
8. Automated decision-making
Speedy Socials.eu does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. There are no algorithmic feeds, no automated content ranking, and no automated decisions about your account status. All moderation decisions are made by human reviewers.
9. Children and minors
Speedy Socials.eu is designed with child safety as a structural requirement. Users under the age of 16 (or the lower age limit permitted by their member state) must have the consent of a parent or guardian. We provide age-appropriate privacy defaults for minor accounts, restricted discoverability, and enhanced contact controls. We do not collect exact dates of birth — we store only an assurance state (see our architecture documentation for details).
10. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you through the platform (for example, via a prominent notice on your next login) and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
11. Your right to complain
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. In most cases, this will be the data protection authority of your EU member state.
We would, however, appreciate the opportunity to address your concerns first. Please contact our Data Protection Officer at dpo@eubook.eu before filing a formal complaint.
12. Contact us
If you have any questions about this Privacy Policy, about how we handle your personal data, or about exercising your data protection rights, please contact us:
EU Book.euData Protection Officer: dpo@eubook.eu