Skip to main content

 

## Privacy explained briefly

Nekodanshi operates a community platform with NekoConnect. There you can create an account, design a profile and portfolio, find and follow other members, like content, discover or submit events, manage attendance details and checklists, view or – where permitted – publish classified ads, and report violations of the rules.

Some of this information may be visible publicly on the internet. This applies only to content and profile fields that have been released for this purpose. Please do not publish your exact home address, private contact details, travel plans, or data relating to other people. Content on public pages may be indexed by search engines and cached outside Nekodanshi.

NekoConnect is intended exclusively for adults. During registration, adulthood is confirmed and may be checked in a data-minimizing way if there are concrete doubts. Registration and use are not permitted under the age of 18. The full date of birth or a copy of proof is not published automatically.

Optional consents – for example for technically non-essential cookies, newsletters, public sensitive information, or external maps – are voluntary and can be withdrawn at any time for the future. Use of the basic functions may not be made dependent on consent for advertising.

If you have any questions or wish to exercise your privacy rights, you can reach us at **hey@nekodanshi.de**.

## 1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

**Nakaryu GmbH**
Franz-Liszt-Straße 3
90571 Schwaig
Germany

Email: **hey@nekodanshi.de**
Website: **https://nekodanshi.de**

Commercial register: Local Court of Nuremberg, HRB 34930

**Privacy contact:** hey@nekodanshi.de

## 2. Scope and distinction from B2B services

This privacy policy applies to the nekodanshi.de website, the NekoConnect community platform, the version installable as a Progressive Web App, and the associated account, profile, event, marketplace, interaction, and reporting functions.

Separately commissioned B2B, agency, event, walk-act, marketing, production, or consulting services are treated separately from a legal and organizational perspective. The privacy information provided by Nakaryu GmbH for such processing or the information in the specific offer or contract applies to the related processing. Mere community registration does not include such B2B services.

https://nakaryu.de/datenschutz

## 3. General legal bases

We process personal data only where there is a legal basis for doing so. Depending on the activity, the following legal bases may apply in particular:

– **Art. 6(1)(b) GDPR:** conclusion and performance of the user contract, provision of account and community functions, and handling of pre-contractual inquiries;
– **Art. 6(1)(c) GDPR:** compliance with legal obligations, in particular commercial, tax, youth protection, evidence, information, and platform-law obligations;
– **Art. 6(1)(f) GDPR:** our legitimate interests in secure, functional, and low-abuse operation; handling reports; defending against fraud and attacks; enforcing rules and claims; and developing the service as needed;
– **Art. 6(1)(a) GDPR:** voluntary consents, for example for optional cookies, maps, newsletters, or voluntary publications, insofar as processing is not already necessary for contract performance;
– **Art. 9(2)(a) GDPR:** explicit consent where voluntary information reveals special categories of personal data, such as sexual orientation or similarly sensitive information.

Consents can be withdrawn at any time with effect for the future. Processing carried out up to the time of withdrawal remains lawful.

## 4. Website access, hosting and server logs

When you access the website, the delivering server processes technically necessary data. This may include in particular:

– IP address;
– date and time of access;
– requested address and data volume transferred;
– referrer address;
– browser, operating system, device type, and language;
– status and error codes;
– security and abuse signals.

This processing is necessary to deliver the website, stabilize connections, analyze errors, and defend against attacks or abuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in secure and trouble-free operation. Where processing is necessary to provide a function you requested, Art. 6(1)(b) GDPR may also apply.

The website is hosted by the following processor:

Server logs are generally deleted after 14 days unless a security incident, suspicion of abuse, or legal obligation requires longer retention. Data relating to a specific security incident may be retained until the matter has been fully clarified and thereafter within the framework of statutory limitation periods.

## 5. Cookies, local storage and consent management

Our website and installable web app use cookies and similar storage technologies. A distinction is made between strictly necessary and optional technologies.

### 5.1 Strictly necessary technologies

Necessary technologies may be used in particular for:

– login and session management;
– protection against cross-site request forgery, spam, and abuse;
– storing language selection;
– storing your privacy and visibility settings;
– load balancing, shopping cart, or form functions, where the respective function is used;
– PWA cache, basic offline functions, and storing the decision to temporarily hide an installation notice.

Access to your device is permitted in this respect under Section 25(2) TDDDG if it is strictly necessary to provide the digital service you expressly requested. Subsequent processing of personal data takes place depending on the function under Art. 6(1)(b) or (f) GDPR.

### 5.2 Optional technologies

Analytics, comfort, map, or marketing technologies are activated only if you have previously given informed consent. The legal basis for access to your device is Section 25(1) TDDDG; for subsequent data processing, Art. 6(1)(a) GDPR.

You can change or withdraw your selection at any time.

 

## 6. Registration, user account and login

When you register, we process in particular:

– username;
– email address;
– password in hashed form;
– time and status of email confirmation;
– accepted version of the terms of use and time of acceptance;
– age group or result of age verification;
– indication whether there is a merchant or organization reference;
– technical security data and login logs.

The data are processed to set up, secure, and manage the account, to authenticate users, to provide community functions, and to communicate about essential contract- or security-related matters. The legal basis is Art. 6(1)(b) GDPR. We additionally rely on Art. 6(1)(f) GDPR for security logs and measures against abusive registrations.

Mandatory fields are marked as such. Without a username, reachable email address, password, age verification, and acceptance of the terms of use, we cannot provide an account. Consent to newsletters, advertising, or other non-essential contact is not a condition for registration.

Account data are generally stored for the duration of the user contract. After account deletion, the profile is deactivated immediately. Final deletion or anonymization takes place within `[[REVIEW: production-system retention period]]`, unless statutory retention obligations, ongoing reports, security incidents, or legal claims prevent this. Backup copies are overwritten in the regular cycle after at most `[[REVIEW: backup retention period]]`.

## 7. Minimum age and age verification

Registration and use of NekoConnect are permitted exclusively for persons who have reached the age of 18. No account may be created or used by persons under 18.

To enforce this age limit, we process a confirmation of adulthood and, where necessary due to concrete doubts, the date of birth or suitable data-minimizing proof of age. The legal basis is Art. 6(1)(b) GDPR. We additionally rely on Art. 6(1)(f) GDPR to prevent unauthorized minor accounts and protect the platform.

The full date of birth and any submitted proof are used solely for age verification and are not published automatically. Where technically possible, we store only the result “adult,” the time, and the verification method used after the check has been completed. Proof copies that are no longer required are deleted after completion of the verification.

If there are concrete doubts about adulthood or age information is contradictory, we may request additional information and suspend the account until the matter is clarified. If verification shows that a person is a minor, the account will not be activated or will be terminated. Statutory retention obligations for certain security or verification data remain unaffected.

## 8. Profiles, portfolio and public visibility

Members may voluntarily create a profile and portfolio. Depending on the information selected, we process in particular:

– display name, username, profile picture, and cover image;
– short description, biography, and portfolio content;
– categories, roles, interests, languages, and country details;
– general region or location information;
– pronouns and voluntary information about one’s identity;
– images, videos, texts, references, and project details;
– external websites and social media links;
– event, group, club, merchant, or organization reference;
– follower, like, level, and activity information.

Processing takes place to display the requested profile, improve discoverability within the community, enable networking, and provide the portfolio. The legal basis is generally Art. 6(1)(b) GDPR. For optional publications that are not necessary for account use, Art. 6(1)(a) GDPR may apply.

Before any publication, it must be clearly indicated whether a field is **private**, **visible only to logged-in members**, or **public on the internet**. Public information can be accessed without logging in, found via filters, shared, and indexed or cached by search engines. Even after deletion, copies may temporarily remain in search engine caches or with persons who previously stored or shared content lawfully.

Members may publish data and content of third parties only if they are authorized to do so. This applies in particular to photos, names, contact details, event roles, and joint projects.

### 8.1 Particularly sensitive voluntary information

Individual interests or self-disclosures – for example “LGBTQIA+” – may reveal sexual orientation or other specially protected information. Such information is always voluntary, is not public by default, and may be processed or published only on the basis of **separate explicit consent** pursuant to Art. 9(2)(a) GDPR. Consent can be withdrawn at any time by removing the information or via the designated settings.

The selection of a general creative or cultural interest must not be interpreted without further context as a statement about a sensitive personal characteristic or used for advertising profiles.

### 8.2 Visibility protection and data minimization

Even for adult members, security-relevant information should not be public by default. This applies in particular to:

– full date of birth;
– exact address, postal code, or map location;
– private phone number or email address;
– specific travel plans and regular places of stay;
– sensitive interests and self-disclosures.

For each voluntary profile field, it should be clearly visible whether it is private, visible only to logged-in members, or public. A public release can be withdrawn at any time for the future.

## 9. Search, filters, sorting, recommendations and community levels

NekoConnect enables searching and filtering by profile details, categories, interests, countries, and other visible characteristics. Lists can be sorted by recency, name, follower count, or randomly, for example. Community levels, badges, follower counts, and likes reflect activities and interactions on the platform.

Processing takes place to provide the desired search, networking, and community functions pursuant to Art. 6(1)(b) GDPR. We rely on Art. 6(1)(f) GDPR to prevent manipulation and maintain result quality.

These functions do not lead to decisions that produce legal effects concerning you or similarly significantly affect you. Where editorial or sponsored highlights are offered, they are identified as such.

Sensitive information is not used for advertising outreach. An advertising or analysis function may not be inferred solely from the sensitive interests selected by a member.

## 10. Follows, likes and other community interactions

If you follow a profile, like content, or perform another community interaction, we process your account, the type and time of the interaction, and the link to the respective profile or content. Depending on the function, the interaction may be visible to the affected member, logged-in members, or the public.

The legal basis is Art. 6(1)(b) GDPR. The data are stored until the interaction is withdrawn, the affected content is deleted, or the account is terminated, unless security or evidence obligations prevent this.

 

## 11. Events, attendance information, roles and checklists

Members can discover and submit events and – depending on the function – store attendance details, program roles, or checklists. In doing so, we process in particular:

– event title, description, date, location, links, images, and categories;
– submitting account and processing status;
– attendance or interest status;
– publicly released program or participation roles;
– contents of personal or shared checklists.

Processing takes place to provide the event and planning functions pursuant to Art. 6(1)(b) GDPR. Art. 6(1)(f) GDPR additionally applies to editorial review, abuse prevention, and documentation of changes.

Before saving, it is shown who can see an attendance entry, role, or checklist. Checklists must not contain passwords, health data, exact travel plans, or other sensitive third-party data.

Event data remain stored until deleted by the submitting member, removed by editorial action, or until the end of the specified archiving period. `[[REVIEW: define archiving and deletion periods for past events, attendance information, and checklists.]]`

## 12. Marketplace and classified ads

For classified ads, we process in particular the offering account, title, description, category, price, images, location or region, provider status, and released contact channels. The information is processed for publication and initiating contact pursuant to Art. 6(1)(b) GDPR.

As a rule, Nekodanshi is not a party to the contract, payment service provider, or shipping provider for transactions concluded between members. Payment or shipping data are processed only if expressly stated otherwise in a specific function. `[[REVIEW: confirm that no platform payment or internal shipping process is currently offered.]]`

Ads are stored until deleted, expired, or removed. Data relating to reported or unlawful ads may be retained longer under section 14.

## 13. Sharing functions, preview graphics and external links

If you select a sharing function, a preview or graphic may be created from the public content you selected and passed to the app or platform you choose. Where possible, the creation initially takes place on our systems or your device. Only when you select the external service or open its page does that provider receive the data technically required for access.

The legal basis for the provision triggered by you is Art. 6(1)(b) GDPR. The subsequent handling of data by an external service is generally the responsibility of that provider.

Profiles and pages may contain links to Discord, Instagram, TikTok, YouTube, Twitch, X, Facebook, Pinterest, Threads, LinkedIn, or other external services. A mere link does not automatically become embedded content. When you click it, the privacy information of the respective provider applies. External services may process data outside the European Economic Area.

An external Discord server is technically and legally separate from NekoConnect in terms of data protection. If we manage our own server there, we are responsible for our content, roles, and moderation decisions there within the scope of data protection responsibilities; Discord remains responsible for operating the platform under its own terms.

## 14. Reports, moderation, security and requests from authorities

In the event of a report, we process depending on the case:

– reporting account or provided contact details;
– reported account, content, and exact location;
– category, reason, and evidence;
– times, communication, and review notes;
– measures taken, reasons, and review requests;
– security logs and technically detected abuse signals;
– where applicable, information about affected or endangered persons.

Processing serves to review possible legal or rule violations, protect the community, defend against fraud, spam, grooming, harassment, doxxing, and technical attacks, and comply with legal platform and authority obligations. The legal bases are Art. 6(1)(c) and (f) GDPR. Where an activity is necessary for the performance of the user contract, Art. 6(1)(b) GDPR also applies.

Reports are accessible only to the responsible employees and necessary service providers. The affected person may be informed of the essential reasons for a measure. The identity of the reporting person is not disclosed unless this is necessary for legal defense, due to a legal obligation, or for a fair clarification of the facts.

In cases of concrete danger, serious legal violations, or statutory disclosure obligations, data may be transmitted to law enforcement, youth welfare, supervisory, or other competent authorities. Transmission takes place only on a valid legal basis and, where permitted, is documented.

Report data are stored for `[[REVIEW: standard retention period, for example 12 months after closure]]`. In cases of serious violations, repeat offenses, risks to minors, ongoing proceedings, or possible legal claims, longer retention may be necessary until the purpose no longer applies or statutory periods expire.

Moderation decisions with significant effects are not made solely by automated means. Technical systems may provide indications of spam, malware, mass registration, or comparable risks; the substantive decision is reviewed by a responsible person under the intended processes.

### 14.1 Data we do not receive directly from you

In some cases, we do not receive personal data directly from you but from other members, rights holders, event organizers, legal representatives, authorities, or publicly accessible sources. This may occur in particular for event entries, shared portfolio content, reports, rights complaints, security incidents, or proof of representation. We process only the contact, content, event, and evidence data required for the respective purpose.

The legal bases depend on the underlying activity and arise in particular from Art. 6(1)(b), (c), or (f) GDPR. Where Art. 14 GDPR applies, we inform the data subject within the statutory periods unless a statutory exception applies. Data from public sources are not used for any arbitrary new purposes or advertising profiles merely because they are public.

## 15. Maps and location functions

Members may voluntarily enter a general location or region. Where a map view is offered, no exact private address is required. Map positions should only be processed with the level of precision necessary for the function.

Google Maps is loaded only once you expressly enable the map. Provider in the European Economic Area is:

**Google Ireland Limited**
Gordon House, Barrow Street
Dublin 4, Ireland

When the map is loaded, in particular IP address, device and browser data, the page accessed, time, and location or map data may be transmitted to Google. If you are logged in to Google, Google may be able to assign usage to your account. Google may also process data in third countries, especially the United States.

The legal basis for access to your device is Section 25(1) TDDDG and for data processing Art. 6(1)(a) GDPR. You can withdraw consent via the cookie/privacy settings for the future. Without consent, the map remains blocked; the other basic functions can still be used.

Further information: https://policies.google.com/privacy?hl=de

## 16. Installable web app (PWA)

Nekodanshi can be added to the home screen as a Progressive Web App. For this purpose, the website provides a web app manifest and can use a service worker to temporarily store technically necessary files on your device. It can also store locally that an installation notice should not be shown again for a certain period.

This storage serves the installation, display, and loading functions you requested. Where it is strictly necessary, access is based on Section 25(2) TDDDG; the subsequent processing is based on Art. 6(1)(b) or (f) GDPR. A device installation can be removed via the browser or operating system settings.

 

## 17. Contact, email and service notifications

If you contact us via form, email, or another specified contact option, we process the contact data you provide, the content, time, and progress of the inquiry, and any related contract or account data.

For contract-related inquiries, the legal basis is Art. 6(1)(b) GDPR. Other inquiries are processed on the basis of Art. 6(1)(f) GDPR; our legitimate interest lies in proper handling and documentation. Business communications that must be retained by law are processed under Art. 6(1)(c) GDPR.

We may send you necessary service notifications without advertising consent, for example email confirmations, password resets, security alerts, changes to the contract, or specific moderation decisions. Promotional messages are separate from these and are sent only on their own legal basis.

Inquiries not subject to retention requirements are generally deleted no later than 2 years after final handling. Contractual or legally relevant communication may be stored until statutory retention or limitation periods expire.

 

## 18. Newsletter and promotional emails

 

If you subscribe to a newsletter, we process your email address, the time of registration and confirmation, the version of the consent text, and technical evidence data. Registration uses the double opt-in procedure. The legal basis is Art. 6(1)(a) GDPR; we additionally rely on Art. 6(1)(f) GDPR for documenting the consent.

You can unsubscribe from the newsletter at any time via the unsubscribe link or by sending a message to hey@nekodanshi.de. After withdrawal, the address is removed from the active mailing list. A limited blocking and consent record may be stored within the statutory periods to defend against unjustified claims.

 

## 20. Recipients and processors

Within Nakaryu GmbH, access is granted only to persons who need it for operations, support, moderation, security, accounting, or legal review.

Outside our company, data may be passed on – depending on the function used – in particular to the following categories of recipients:

– hosting, infrastructure, security, and backup providers;
– email, form, and support providers;
– consent and consent-management providers;
– map, analytics, or marketing providers after consent;
– legal, tax, and audit advisers;
– authorities, courts, and other bodies authorized by law;
– other members and the general public in the case of content released accordingly;
– external platforms if you select a link or sharing function.

Where service providers process data on our behalf, we conclude a contract pursuant to Art. 28 GDPR. Disclosure for their own purposes takes place only where permitted by law or where you have consented.

## 21. Transfers to third countries

We prefer processing within the European Union or the European Economic Area. For individual external services, processing in countries outside this area cannot be ruled out.

A transfer takes place only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision by the European Commission, suitable safeguards such as standard contractual clauses, or a statutory exception. Where a US recipient is validly certified under the EU-US Data Privacy Framework, the transfer may be based on the relevant adequacy decision; otherwise, other suitable safeguards are required.

## 22. Storage period

We store personal data only for as long as necessary for the respective purpose. They are then deleted or anonymized, unless statutory retention obligations, ongoing security or moderation processes, or the assertion, exercise, or defense of legal claims require further storage.

The respective periods are set out in the sections above. For data categories where no fixed period can be specified, we determine the duration in particular based on:

– continuation of the user contract;
– visibility and purpose of the content posted by the member;
– statutory retention and evidence obligations;
– risk and severity of a security or moderation incident;
– statutory limitation periods;
– technically defined backup and overwrite cycles.

Consent records may be retained until the relevant limitation periods expire. Identity or age verification documents that are no longer needed are not stored permanently solely for proof purposes.

## 23. Your rights

Subject to the statutory requirements, you have in particular the right to:

– **access** your personal data (Art. 15 GDPR);
– **rectification** of inaccurate data (Art. 16 GDPR);
– **erasure** of your data (Art. 17 GDPR);
– **restriction** of processing (Art. 18 GDPR);
– **data portability** where the statutory requirements are met (Art. 20 GDPR);
– **object** to processing under Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR);
– **withdraw** consent at any time with effect for the future (Art. 7(3) GDPR);
– **lodge a complaint** with a data protection supervisory authority (Art. 77 GDPR).

To exercise your rights, simply send a message to **hey@nekodanshi.de**. To protect your account, we may request additional information if there are reasonable doubts about your identity. We will request only the data necessary for secure identification.

### Special note on the right to object

**Where we process data on the basis of legitimate interests under Art. 6(1)(f) GDPR, you may object at any time for reasons arising from your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise, or defense of legal claims. You may object to direct marketing at any time without giving reasons.**

The competent supervisory authority for non-public entities in Bavaria is generally:

**Bavarian State Office for Data Protection Supervision (BayLDA)**
Promenade 18
91522 Ansbach
Germany
https://www.lda.bayern.de

## 24. Automated decisions

We do not currently make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Technical sorting, levels, spam notices, or security assessments are not such decisions as long as a significant measure is reviewed by a responsible person.

If a relevant automated decision-making function is introduced in the future, we will inform you in advance about the underlying logic, significance, effects, and your statutory rights.

## 25. Age limit and protection of minors

NekoConnect is intended exclusively for adult members. Protective measures include in particular:

– asking for adulthood and, in case of concrete doubts, verifying it in a data-minimizing manner;
– not activating or continuing recognized minor accounts;
– suspending and reviewing contradictory age information;
– no permanent storage of full proof of age without necessity;
– reporting and escalation options for suspected minor accounts;
– priority handling of reports concerning depictions of sexual abuse, grooming, or other risks to minors.

Despite the age limit, reports or user content may contain information about third-party minors, for example photos, event content, or indications of a risk. Such data are processed only to the extent necessary. In an acute danger, authorized representatives, protection bodies, or authorities may be involved where this is legally permitted or required.

## 26. Data security

We take appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other misuse. Depending on the level of protection required, these include in particular transport encryption, secure password storage, role and permission concepts, updates, logging of security-relevant events, backups, and procedures for handling security incidents.

No internet-based service can guarantee absolute security. Please use a unique, strong password and do not share login details with others.

## 27. Changes to this privacy policy

We update this privacy policy whenever functions, legal requirements, or data processing change. The current version is available at nekodanshi.de. We will inform you of material changes that affect an account or existing consents in an appropriate manner. Where a new consent is required, the relevant processing will only be activated after consent has been given.

Privacy Preference Center