Privacy Policy & GDPR Disclosures
Zilla Group operates MeetupZilla. This policy explains what personal data we collect, why we process it, our legal bases under the General Data Protection Regulation (EU) 2016/679 (GDPR), and the comprehensive rights available to you when using MeetupZilla.
1. Data Controller & Data Protection Officer
The Data Controller responsible for your personal data is Zilla Group. If you have questions regarding data protection, consent records, or wish to exercise your statutory privacy rights, you can reach our Data Protection Officer at privacy@meetupzilla.org or submit an inquiry through our contact page.
2. Information We Collect
When you use MeetupZilla, we process personal data categories according to your interaction:
- Account & Identity Data: Name, email address, password hash, unique user ID, avatar image, and verification timestamps.
- Profile & Community Data: Username, optional bio, approximate location (locality, region, country), selected topic interests, and community memberships or roles.
- Activity & Participation Data: Events organized, RSVP status, attendance records, volunteer applications, and answers submitted to organizers.
- User-Generated Content: Forum discussions, comments, and reactions authored in communities or events.
- Imported Calendar Records: External
.icscalendar events you explicitly choose to upload to preview alongside your MeetupZilla schedule. - Technical & Security Logs: IP address, browser user-agent, session identifiers, rate-limiting tokens, and security event logs required for platform integrity.
3. Legal Bases for Processing (GDPR Article 6)
We process your data only where a valid legal basis exists under Article 6 of the GDPR:
- Contractual Necessity (Article 6(1)(b)): Providing the MeetupZilla platform services in accordance with our Terms of Service, including managing accounts, event RSVPs, volunteer coordination, and publishing community discussions.
- Legitimate Interests (Article 6(1)(f)): Maintaining service security, preventing fraud, abuse, spam, and denial-of-service attacks, and ensuring the smooth technical operation of the network infrastructure.
- Consent (Article 6(1)(a)): Sending optional marketing emails, storing non-essential preference/analytics cookies, and importing personal calendar files. You have the right to withdraw consent at any time without affecting past lawful processing.
- Legal Compliance (Article 6(1)(c)): Fulfilling statutory recordkeeping, legal proceedings, or valid law enforcement requests where required by EU or Member State law.
4. Cookies, Local Storage & Consent Management
MeetupZilla employs a tiered consent architecture. We do not use third-party advertising or cross-site tracking cookies:
- Strictly Necessary: Essential session cookies, CSRF protection, and authentication credentials required for account security and platform operations.
- Functional & Preferences: Storing user UI preferences (such as light/dark theme mode and location search radius defaults) in local browser storage.
- Performance & Analytics: Privacy-preserving aggregated usage metrics to understand platform reliability and feature performance.
You can adjust or revoke your cookie choices at any time by clicking or visiting your Account Privacy settings.
5. Maps & Geolocation Processing (OpenStreetMap)
To display event locations and calculate proximity without selling your location data to commercial ad networks, MeetupZilla integrates OpenStreetMap and Nominatim. When map tiles or geosearch queries load, your browser connects directly to OpenStreetMap servers, transmitting your IP address and standard HTTP request headers solely for tile rendering and network communication under legitimate interest.
6. Data Retention & Right to Erasure (Article 17)
We retain your personal data only as long as your account remains active or as needed to provide services. When you request account deletion:
- All credentials, sessions, two-factor keys, private calendar events, notifications, volunteer application responses, and block lists are immediately hard-deleted.
- Public community discussions and comments are preserved to maintain community continuity, but the author is permanently anonymized to
Deleted member, severing all links to your identity. - Security audit logs are retained for a maximum of 90 days to 1 year solely for fraud investigation and network defense before automated purging.
7. Your Statutory Rights (GDPR Articles 15–22)
As a data subject located in the EU/EEA or UK, you enjoy the following rights:
- Right of Access (Art. 15): You have the right to obtain confirmation and copies of your personal data.
- Right to Rectification (Art. 16): You may update incomplete or inaccurate profile information anytime in your Profile Settings.
- Right to Erasure (Art. 17): You may delete your account and personal data at any time via Your Data.
- Right to Restriction of Processing (Art. 18): You can request restriction of processing where data accuracy is contested or unlawful.
- Right to Data Portability (Art. 20): You may download your personal data in both machine-readable JSON and human-readable HTML formats via Your Data.
- Right to Object (Art. 21): You may object at any time to processing based on legitimate interests or direct marketing.
- Automated Decision-Making & Profiling (Art. 22): MeetupZilla does not employ automated profiling or decision-making algorithms that produce legal effects.
8. Right to Lodge a Complaint (GDPR Article 77)
If you believe our processing of your personal data infringes data protection laws, you have the statutory right under Article 77 of the GDPR to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement (such as the Dutch Data Protection Authority / Autoriteit Persoonsgegevens).
9. Beta Program Notice
The beta interest form is currently a demonstration and does not transmit or retain your details.